SignetMail docs Open portal →

#Access and roles

Who may do what in the portal is controlled by roles, managed in the portal itself under Access (Administration menu) — not in Entra ID. Entra ID only proves who someone is; SignetMail decides what that person may do.

#Roles

Role Can
Viewer See signatures, rules, campaigns and statistics; use previews.
Editor Everything a Viewer can, plus edit drafts, submit them for review, restore versions into drafts, and prepare campaigns (an Admin approves them).
Admin Everything an Editor can, plus publish, disable/enable and delete signatures, manage rules, approve campaigns, edit organization data and logos, create sub-organizations and grant access up to the Admin role inside the scope.
Owner Everything, including top-level organizations and global roles. Granted only at system level.

The same table is shown inside the portal on the Access page ("What each role can do").

An Editor can never put anything in front of users on their own: signatures need an Admin to publish and campaigns need an Admin to approve.

#Scopes

A role can be granted at three levels:

Scope Applies to
Entire system Everything. Only Owners can grant global roles.
Organization That organization and all organizations below it.
Single signature That one signature only. Useful for letting a department edit just its own signature.

A person's effective role is the highest of: their global role, their role on the organization or any ancestor, and (for a signature) their role on that signature.

#Granting access

  1. Open Access.
  2. Choose the scope (entire system / organization / single signature) and, if needed, the organization or signature.
  3. In Grant access search for a person (UPN or name from the directory) or paste a group ID, pick the role and click Grant.

The table below shows who has which role in that scope and who granted it. Revoke removes a role (with confirmation). Both actions are recorded in the audit log.

Admins can grant roles up to Admin inside organizations they administer. Only Owners can grant Owner or global roles.

#Groups

Instead of granting roles person by person, paste the object ID of an Entra security group (Entra ID → Groups → Object Id). Every member gets the role.

This requires the sign-in token to carry group information — see Entra setup, step 6. If a person belongs to too many groups, Entra omits the list ("groups overage"); the portal then shows a warning and only roles granted directly to that person apply.

#The first Owner

The UPN(s) in PORTAL_OWNER (setting SignetMail:Portal:Owners) are Owners every time the server starts. That is how you get into a new system. Add other Owners in the portal; keep at least two people able to administer, so one absence cannot lock you out.

  • 2–3 Owners/Admins (IT, a security-minded manager) at the top of the tree.
  • Editors for marketing/communications on their organization or specific signatures.
  • Everyone else who needs visibility: Viewer.
  • Use groups for roles, so joiners and leavers are handled in Entra ID automatically.
  • In Entra, set Assignment required and MFA so only intended people can even reach the portal.
SignetMail documentation · version main