Roles and Permissions
Summary: Access should match a user’s current responsibilities and be reviewed throughout the participation lifecycle.
#Role model
Typical role concepts may include:
| Role | Typical responsibility |
|---|---|
| Network operator | Participation, governance, and network oversight |
| Merchant administrator | Business profile, team, and approvals |
| Campaign manager | Campaign drafting and operation |
| Analyst | Approved reporting and analysis |
| Viewer | Read-only access to a limited scope |
#Status
Pilot: Exact role names and permissions depend on the deployment. This table is not a definitive authorization matrix.
#Access lifecycle
- Request access with a business justification.
- Approve through the responsible owner.
- Assign the minimum role and scope.
- Verify access after material changes.
- Review privileged and inactive accounts regularly.
- Revoke access promptly when no longer required.
#Separation of duties
Where risk warrants it, separate:
- Campaign creation from approval.
- User administration from audit review.
- Data configuration from commercial sign-off.
#Related pages
See the merchant portal guide, security overview, and privacy guidance.

