Access and permissions

Which permission each Marketing screen needs, who may see and change what, and the rules that keep people from approving their own work.

On this page (15)

Permissions by screen

ScreenMenuPermission needed
Marketing DashboardMarketing > Dashboardmarketing.view
CampaignsMarketing > Campaigns > CampaignsView: marketing.view + marketing.campaign.view; New: marketing.campaign.edit
Campaign recordCampaigns > click a campaignmarketing.campaign.view
Ad CampaignsMarketing > Campaigns > Ad Campaignsmarketing.campaign.view / marketing.campaign.edit
Lead CampaignsMarketing > Campaigns > Lead Campaignsmarketing.campaign.view / marketing.campaign.edit
Ad SetsMarketing > Campaigns > Ad Setsmarketing.campaign.view / marketing.campaign.edit
CreativesMarketing > Campaigns > Creativesmarketing.campaign.view / marketing.campaign.edit
Delivery & SpendMarketing > Campaigns > Delivery & Spendmarketing.campaign.view / marketing.campaign.edit
Ad AccountsMarketing > Campaigns > Ad AccountsView: marketing.campaign.view; change: marketing.campaign.edit (route) AND marketing.configure (service)
AudiencesMarketing > Audiences > AudiencesView: marketing.view + marketing.audience.view; New: marketing.campaign.edit (route) AND marketing.audience.edit (service)
Audience recordAudiences > click an audiencemarketing.audience.view; actions marketing.audience.edit
ConsentMarketing > Audiences > ConsentView: marketing.consent.view; Record: marketing.consent.edit
RulesMarketing > Automation > Rulesmarketing.automation.view; changes marketing.automation.edit
Customer JourneysMarketing > Automation > Customer Journeysmarketing.automation.view; changes marketing.automation.edit
Journey builderCustomer Journeys > New / openmarketing.automation.edit to save / run
TriggersMarketing > Automation > Triggersmarketing.automation.view
Scheduled ActionsMarketing > Automation > Scheduled Actionsmarketing.automation.view
Campaign ROIMarketing > Analytics > Campaign ROImarketing.analytics.view
AttributionMarketing > Analytics > Attributionmarketing.analytics.view
Conversion TrackingMarketing > Analytics > Conversion Trackingmarketing.analytics.view
Marketing SettingsMarketing > Configuration > Marketing SettingsView: marketing.view; Save and Scan: marketing.configure
Marketing app configurationAdministration > Workspace > Apps > Marketing > Features / FieldsCompany administrator
Marketing screens inside OmnichannelOmnichannel > Campaigns / Automation / Analytics / ConfigurationSame marketing.* codes as in the Marketing menu
AI assistant - Marketing toolsAI assistant (chat)marketing.analytics.view / marketing.consent.view

Campaigns

RuleWhat the system does
View without editRefused 403 'You do not have permission for this action.' (screen still shows New - note)
Company isolation on registersB does not list it; PATCH/DELETE -> 'Record not found.'

Ad Accounts

RuleWhat the system does
Ad accounts need configureRefused 'You do not have permission for this action.'
Token never leaves the serveraccess_token is '' and has_access_token true; the token is never in any response or export
RuleWhat the system does
View-only cannot recordRefused 'You do not have permission for this action.'
No marketing to opted-out (PDPL)Email action logged 'skipped: Opted out' (if email consent also out); broadcast skips them with the reason. Nobody opted out is ever messaged
Consent history is evidenceHistory shows every change with actor name and evidence; there is no delete on consent

Rules

RuleWhat the system does
Automation edit is separateAll refused 'You do not have permission for this action.'

Audiences

RuleWhat the system does
Audience edit permissionRefused 'You do not have permission for this action.'

All Marketing screens

RuleWhat the system does
Viewer sees, cannot changeDashboard and Settings open; Campaigns, Audiences, Consent, Rules, ROI answer 403 'You do not have permission for this action.' and show the error line

Menu

RuleWhat the system does
Menu follows permissionsEach sees only the menu entries of their code (+ Dashboard / Settings need marketing.view)

Analytics

RuleWhat the system does
Analytics needs its own codeRefused 403; the campaign record still opens (marketing.campaign.view)

Marketing Settings

RuleWhat the system does
Settings need configureBoth refused 'You do not have permission for this action.'

All

RuleWhat the system does
Company isolationB sees none of A's campaigns, audiences, consent, rules, journeys, ROI; a user not in A calling A's URL gets 404 'Record not found.'

Marketing manager role

RuleWhat the system does
Shipped roleCan do everything in Marketing including Settings and ad accounts

Omnichannel agent / supervisor roles

RuleWhat the system does
Consent read onlyAgent can read consent but not record; supervisor can read rules but not change them

Audit

RuleWhat the system does
Changes are auditedAudit log has marketing.campaigns.saved, marketing.consent.opted_in, marketing.rule.saved, marketing.journey.saved, marketing.settings.saved with your name

Ad platform data

RuleWhat the system does
Only hashes leavePayload holds SHA-256 of lower-case email and digits-only phone; never plain email/phone