Overview
Permissions decide what each person can see and do in CX Platform. They control everything from logging in, to viewing sensitive data, to editing settings that affect how your communications go out the door.
Getting permissions right matters for two reasons. The first is access — making sure your team can do their jobs without chasing someone for help. The second is protection — keeping sensitive data, restricted documents, and configuration changes in the hands of people who should have them.
This guide walks you through the different ways permissions can be assigned, the administrator roles that unlock self-service management, and a full breakdown of what each permission actually does.
Before you start
You'll need at least one Tenant Administrator set up before any of this can be self-managed. If that hasn't happened yet, contact your ChandlerCX representative — they'll get the first admin in place, and from there your team can take over.
The two administrator roles
Two roles control who can manage permissions in your tenant. They sit at different levels of authority, and it's worth knowing which one fits each person before you start assigning anything.
Which one should you assign?
Use Tenant Administrator for the small group running your platform. Use Tenant User Administrator for domain leads or team managers who only need to handle user access for their own part of the business.
Assign a Tenant Administrator
- Go to Tenant settings and click your tenant.
- Open the Users tab and find the user who needs admin privileges.
- Click Edit next to their name.
- Under Tenant Roles, tick Tenant administrator.
- Click Save.
That's it — the user now has full administrator access and can manage users, tenant details, IP whitelisting, and user types.
Assign a Tenant User Administrator
- Go to Tenant settings and click your tenant.
- Open the Users tab, find the user, and click Edit.
- Under Tenant Roles, tick Tenant user administrator.
- In the Allowed domains list that appears, tick every domain this person should be able to manage users for.
- Click Save.
The user can now manage other users within their allowed domains. Anyone outside those domains stays off-limits.
Edit permissions for a single user
This is the right approach when you're onboarding someone new, adjusting access for a role change, or tightening up what one person can see.
- In Tenant settings, click your tenant.
- Open the Users tab and search for the user you want to update.
- Click Edit next to their name.
- Click the Permissions tab.
- Tick or untick the permissions you want to change, working through each module as needed.
- Click Save.
You'll be taken back to the user's permissions page with the new settings applied straight away.
Edit permissions for a batch of users
If you're updating the same permissions across a group of people — say, after a new module goes live or a team restructure — batch editing saves you opening each user one by one.
Before you start, it helps to know there are three ways to apply changes in bulk. They behave very differently, so pick carefully:
Heads up
Set User To These Permissions overwrites everything. If a user has permissions you forget to tick, they'll lose them. When in doubt, use Add Permissions Only or Remove Permissions Only instead.
Run a batch update
- In Tenant settings, click the tenant you want to update users in.
- Click Edit permissions of a batch of users.
- Under Permissions set type, choose Add Permissions Only, Remove Permissions Only, or Set User To These Permissions.
- Under Select users, paste or type the email addresses of the users you want to update — one per line.
- Under Select permissions, expand each module by clicking the dropdown arrow and tick the permissions you want to apply.
- Click Update All Users.
You'll be redirected to the Users page once the update is done. The same flow works for all three modes — only the result changes.
Permissions by module
Each module has its own set of permissions. Exactly which ones appear depends on what your tenant is licensed for, but here's the full picture across all modules so you know what you're ticking when you see it.
Good to know
Personally Identifiable Information (PII) covers things like names, addresses, dates of birth, and government IDs. Permissions that grant access to PII or restricted documents should be assigned carefully.
SFTP Server
Send Module
Receive Module
Generate Module
Chandler Verify
Supermatch
Send permissions by Application Category
The Send module takes things one step further with Role-Based Access Control (RBAC). Every Application in Send belongs to a Category, and permissions can be assigned per Category to different roles. That way you can give the marketing team full access to newsletters without ever letting them near customer statements.
Here's an example of how Applications might be grouped into Categories:
The permissions available per Category
About restricted documents
Restricted documents are documents within an Application that only certain users can view. A common example — contact centre staff can view all standard customer monthly statements, but are blocked from viewing the CEO's or Directors' statements. Only the Contact Centre Manager has permission to view those. The is restricted flag is assigned to a field during Application setup, and once applied it covers every document in that Application.
Example: how Categories shape real-world access
Where to set Category permissions
- In the Send module, go to Edit Settings.
- Open the Categories section.
- Click Edit next to the Category you want to update.
- Tick the permissions you want to grant to each role group, then save your changes.
User Types
User Types are labels that describe what kind of user someone is — Admin, Operations, Contact Centre, and so on. They don't grant permissions on their own, but they're a handy way to group people by function and they show up across reporting and user management.
Every tenant starts with three defaults: Admin, Operations, and Contact Centre. You can add your own types, reorder them, or remove ones you don't need.
Add a new User Type
- In Tenant settings, click your tenant and open the User Types tab.
- Click in the blank Type Name field at the top of the list.
- Enter a name and a short description.
- Click Add.
A confirmation message appears, and the new type shows up at the bottom of the list.
Reorder User Types
- On the User Types tab, click the drag icon to the left of the order number for the type you want to move.
- Hold and drag it up or down to its new position.
A message confirms the move, and the new order is saved automatically.
Delete a User Type
- Find the type you want to remove and click Delete.
- In the confirmation prompt, click Delete again.
Heads up
Deleting a User Type can't be undone. Check that no active users are assigned to it before you remove it.
What's next
Once your administrator roles are sorted and you're comfortable with how permissions are structured, you can move on to fine-tuning Category permissions in Send, setting up User Types that match how your teams are organised, or onboarding new users into the right access groups from day one.