Access and permissions
Which permission each Marketing screen needs, who may see and change what, and the rules that keep people from approving their own work.
On this page (15)
Permissions by screen
| Screen | Menu | Permission needed |
|---|---|---|
| Marketing Dashboard | Marketing > Dashboard | marketing.view |
| Campaigns | Marketing > Campaigns > Campaigns | View: marketing.view + marketing.campaign.view; New: marketing.campaign.edit |
| Campaign record | Campaigns > click a campaign | marketing.campaign.view |
| Ad Campaigns | Marketing > Campaigns > Ad Campaigns | marketing.campaign.view / marketing.campaign.edit |
| Lead Campaigns | Marketing > Campaigns > Lead Campaigns | marketing.campaign.view / marketing.campaign.edit |
| Ad Sets | Marketing > Campaigns > Ad Sets | marketing.campaign.view / marketing.campaign.edit |
| Creatives | Marketing > Campaigns > Creatives | marketing.campaign.view / marketing.campaign.edit |
| Delivery & Spend | Marketing > Campaigns > Delivery & Spend | marketing.campaign.view / marketing.campaign.edit |
| Ad Accounts | Marketing > Campaigns > Ad Accounts | View: marketing.campaign.view; change: marketing.campaign.edit (route) AND marketing.configure (service) |
| Audiences | Marketing > Audiences > Audiences | View: marketing.view + marketing.audience.view; New: marketing.campaign.edit (route) AND marketing.audience.edit (service) |
| Audience record | Audiences > click an audience | marketing.audience.view; actions marketing.audience.edit |
| Consent | Marketing > Audiences > Consent | View: marketing.consent.view; Record: marketing.consent.edit |
| Rules | Marketing > Automation > Rules | marketing.automation.view; changes marketing.automation.edit |
| Customer Journeys | Marketing > Automation > Customer Journeys | marketing.automation.view; changes marketing.automation.edit |
| Journey builder | Customer Journeys > New / open | marketing.automation.edit to save / run |
| Triggers | Marketing > Automation > Triggers | marketing.automation.view |
| Scheduled Actions | Marketing > Automation > Scheduled Actions | marketing.automation.view |
| Campaign ROI | Marketing > Analytics > Campaign ROI | marketing.analytics.view |
| Attribution | Marketing > Analytics > Attribution | marketing.analytics.view |
| Conversion Tracking | Marketing > Analytics > Conversion Tracking | marketing.analytics.view |
| Marketing Settings | Marketing > Configuration > Marketing Settings | View: marketing.view; Save and Scan: marketing.configure |
| Marketing app configuration | Administration > Workspace > Apps > Marketing > Features / Fields | Company administrator |
| Marketing screens inside Omnichannel | Omnichannel > Campaigns / Automation / Analytics / Configuration | Same marketing.* codes as in the Marketing menu |
| AI assistant - Marketing tools | AI assistant (chat) | marketing.analytics.view / marketing.consent.view |
Campaigns
| Rule | What the system does |
|---|---|
| View without edit | Refused 403 'You do not have permission for this action.' (screen still shows New - note) |
| Company isolation on registers | B does not list it; PATCH/DELETE -> 'Record not found.' |
Ad Accounts
| Rule | What the system does |
|---|---|
| Ad accounts need configure | Refused 'You do not have permission for this action.' |
| Token never leaves the server | access_token is '' and has_access_token true; the token is never in any response or export |
Consent
| Rule | What the system does |
|---|---|
| View-only cannot record | Refused 'You do not have permission for this action.' |
| No marketing to opted-out (PDPL) | Email action logged 'skipped: Opted out' (if email consent also out); broadcast skips them with the reason. Nobody opted out is ever messaged |
| Consent history is evidence | History shows every change with actor name and evidence; there is no delete on consent |
Rules
| Rule | What the system does |
|---|---|
| Automation edit is separate | All refused 'You do not have permission for this action.' |
Audiences
| Rule | What the system does |
|---|---|
| Audience edit permission | Refused 'You do not have permission for this action.' |
All Marketing screens
| Rule | What the system does |
|---|---|
| Viewer sees, cannot change | Dashboard and Settings open; Campaigns, Audiences, Consent, Rules, ROI answer 403 'You do not have permission for this action.' and show the error line |
Menu
| Rule | What the system does |
|---|---|
| Menu follows permissions | Each sees only the menu entries of their code (+ Dashboard / Settings need marketing.view) |
Analytics
| Rule | What the system does |
|---|---|
| Analytics needs its own code | Refused 403; the campaign record still opens (marketing.campaign.view) |
Marketing Settings
| Rule | What the system does |
|---|---|
| Settings need configure | Both refused 'You do not have permission for this action.' |
All
| Rule | What the system does |
|---|---|
| Company isolation | B sees none of A's campaigns, audiences, consent, rules, journeys, ROI; a user not in A calling A's URL gets 404 'Record not found.' |
Marketing manager role
| Rule | What the system does |
|---|---|
| Shipped role | Can do everything in Marketing including Settings and ad accounts |
Omnichannel agent / supervisor roles
| Rule | What the system does |
|---|---|
| Consent read only | Agent can read consent but not record; supervisor can read rules but not change them |
Audit
| Rule | What the system does |
|---|---|
| Changes are audited | Audit log has marketing.campaigns.saved, marketing.consent.opted_in, marketing.rule.saved, marketing.journey.saved, marketing.settings.saved with your name |
Ad platform data
| Rule | What the system does |
|---|---|
| Only hashes leave | Payload holds SHA-256 of lower-case email and digits-only phone; never plain email/phone |