#Access and roles
Who may do what in the portal is controlled by roles, managed in the portal itself under Access (Administration menu) — not in Entra ID. Entra ID only proves who someone is; SignetMail decides what that person may do.
#Roles
| Role | Can |
|---|---|
| Viewer | See signatures, rules, campaigns and statistics; use previews. |
| Editor | Everything a Viewer can, plus edit drafts, submit them for review, restore versions into drafts, and prepare campaigns (an Admin approves them). |
| Admin | Everything an Editor can, plus publish, disable/enable and delete signatures, manage rules, approve campaigns, edit organization data and logos, create sub-organizations and grant access up to the Admin role inside the scope. |
| Owner | Everything, including top-level organizations and global roles. Granted only at system level. |
The same table is shown inside the portal on the Access page ("What each role can do").
An Editor can never put anything in front of users on their own: signatures need an Admin to publish and campaigns need an Admin to approve.
#Scopes
A role can be granted at three levels:
| Scope | Applies to |
|---|---|
| Entire system | Everything. Only Owners can grant global roles. |
| Organization | That organization and all organizations below it. |
| Single signature | That one signature only. Useful for letting a department edit just its own signature. |
A person's effective role is the highest of: their global role, their role on the organization or any ancestor, and (for a signature) their role on that signature.
#Granting access
- Open Access.
- Choose the scope (entire system / organization / single signature) and, if needed, the organization or signature.
- In Grant access search for a person (UPN or name from the directory) or paste a group ID, pick the role and click Grant.
The table below shows who has which role in that scope and who granted it. Revoke removes a role (with confirmation). Both actions are recorded in the audit log.
Admins can grant roles up to Admin inside organizations they administer. Only Owners can grant Owner or global roles.
#Groups
Instead of granting roles person by person, paste the object ID of an Entra security group (Entra ID → Groups → Object Id). Every member gets the role.
This requires the sign-in token to carry group information — see Entra setup, step 6. If a person belongs to too many groups, Entra omits the list ("groups overage"); the portal then shows a warning and only roles granted directly to that person apply.
#The first Owner
The UPN(s) in PORTAL_OWNER (setting SignetMail:Portal:Owners) are Owners every time the server starts. That is how you get into a new system. Add other Owners in the portal; keep at least two people able to administer, so one absence cannot lock you out.
#Recommended setup
- 2–3 Owners/Admins (IT, a security-minded manager) at the top of the tree.
- Editors for marketing/communications on their organization or specific signatures.
- Everyone else who needs visibility: Viewer.
- Use groups for roles, so joiners and leavers are handled in Entra ID automatically.
- In Entra, set Assignment required and MFA so only intended people can even reach the portal.