Skip to main content

Roles and Permissions Matrix

Roles group the permissions an Author (or admin, or analyst) needs to do their job. Assigning a role decides who can build Editions, who can approve and send a Broadcast, who can read reports, and who can change account-wide settings. Use this matrix as a planning reference when you set people up; the exact role names and available toggles are configured per account, so (confirm the exact role names in your account).

Reference

The table shows typical capabilities by role. A check means the role normally has that permission; a dash means it usually does not. Your account may split or rename these roles.

ActionAuthorApproverAnalystAdmin
Create and edit Editions in a Folder
Manage Folders (create, rename, move)Limited
Send or schedule a Broadcast
Manage subscriber lists and audiencesLimited
View Broadcast and engagement reports
Export report dataLimited
Edit account-wide suppression list
Manage users, roles, and SSO settings
Manage API keys and integrations

Values above are representative examples — treat them as a starting point, not a guarantee of what a given role can do in your account.

Notes

  • Least privilege. Give each person the narrowest role that lets them work. Analysts rarely need send rights; most Authors do not need admin access.
  • Folder scope. Permissions are often scoped to a Folder, so the same person can be an Author in one Folder and read-only in another.
  • Approval gates. Where a review step is required, an Author builds the Edition but only an Approver or Admin can release the Broadcast.
  • Administration is sensitive. Editing the account-wide suppression list, users, SSO, or API keys should stay with a small number of Admins.
  • SSO and provisioning. If your account uses SSO (for example with Microsoft Entra ID), roles may be mapped from your identity provider's groups rather than set here (confirm the exact steps in your account).

Canonical terms: Author, Edition, Folder (Project Folder), Broadcast. See the Glossary.