Skip to content

Users, roles and permissions

Create the accounts your buyers, suppliers and affiliates sign in with, pick the right role, and understand what each one can see.

Settings3 min readUpdated

This article shows how to create and manage the user accounts in your workspace. Read it before your first campaign, because a buyer must exist as a user before you can attach it to a campaign.

Roles

A role decides what a user can see and do. Pick it when you create the account.

Role Typically
Admin Your own team. Full access to campaigns, leads, buyers, suppliers, analytics, and settings.
Buyer A company that receives and pays for leads
Supplier A partner that posts leads into your campaigns
Traffic Source An affiliate channel under your own internal supplier
Developer Technical access for someone building an integration

Roles are not campaign-specific. A Buyer user is created once here, then attached to each campaign where it should buy. Pricing, delivery, caps, and schedules are all configured on that campaign attachment, not on the user account.

Prerequisites

  • Admin access
  • The person's email address, and agreement on which role they need

Create a user

  1. Open Manage Users from the sidebar.
  2. Add a user, or send an invitation if you want them to set their own password.
  3. Enter their details and select the Role.
  4. Choose the Campaigns they should have access to.
  5. Set their email notification preferences.
  6. Save.

An invited user receives an email with a link, sets their own password, and the account activates with the role you chose. Pending invitations are listed so you can chase or resend one.

API keys

A supplier posts leads with an API key rather than a password. Generate the key from that user's settings.

The key is shown once. Copy it then, because you cannot read it back afterwards, only replace it. Share it only with the party that submits the leads, and never in a shared ticket or chat.

Two-factor authentication

Users can secure their account with a code from an authenticator app, backed by recovery codes for when the phone is not to hand. Your workspace can require it for everyone, in which case users are prompted to set it up at their next sign-in.

What a role cannot override

Two things sit outside roles and are worth knowing before you debug an access problem.

Features. Your subscription plan decides which parts of the platform exist for your workspace at all. If a whole page is missing for every admin, that is a plan question rather than a permissions question. See Subscriptions and billing.

Data scope. A buyer only ever sees leads sold to it. A traffic source only sees its own conversions. That is not something a role setting relaxes.

Expected result

Each person signs in with their own account, sees exactly the campaigns and pages their role allows, and buyer accounts are available to attach on the campaign Buyers tab.

Troubleshooting

  • A buyer is not selectable on a campaign. The Buyer user does not exist yet. Create it under Manage Users first.
  • An invitation never arrived. Check the spam folder, confirm the address, then resend from the pending invitations list.
  • A two-factor code is rejected. The device clock has drifted. Sync it, or use a recovery code.
  • A whole page is missing for an admin. That is the subscription plan, not the role.
  • An API key stopped working. It was regenerated, or it belongs to a different account than the one posting. Generate a fresh one and re-share it.
  • A user sees fewer leads than expected. Check their campaign access, then their role's data scope. A buyer only ever sees its own leads.

Frequently asked questions

Both, in that order. Create the Buyer user account first, then attach that buyer inside each campaign where it should buy. Pricing, delivery, caps and schedules live on the campaign attachment.

Yes. Attach the same buyer user to as many campaigns as you need. Each attachment has its own pricing, delivery method, caps and schedule.

Generate it from that user's settings. It is shown once, so copy it immediately. You cannot read it back later, only replace it.

Not if it is missing for every admin. Which parts of the platform exist at all is decided by your subscription plan, not by roles.

Yes. Turn it on for the workspace and users are prompted to set it up at their next sign in, using an authenticator app with recovery codes as a backup.
Back to Help Center

Comments

No comments yet — be the first to share your thoughts.

Leave a comment

Comments are reviewed before they’re published.