---
title: Configuring on-line marketing permissions
related:
  - https://docs.kentico.com/k10/managing-users/configuring-permissions.md
  - https://docs.kentico.com/k10/managing-users/ui-personalization.md
  - https://docs.kentico.com/k10/securing-websites.md
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

You can control access to on-line marketing features through:

- [Permissions](https://docs.kentico.com/k10/managing-users/configuring-permissions.md)
- [UI personalization](https://docs.kentico.com/k10/managing-users/ui-personalization.md)

The system only allows users to perform on-line marketing actions if they belong to roles with permissions for individual on-line marketing modules.

1. Create global on-line marketing roles.
2. Configure the permissions of the global roles.
3. Assign individual users to the appropriate roles.

You can configure module permissions for roles in the **Permissions** application.

![Configuring permissions for the On-line marketing module](https://docs.kentico.com/docsassets/k10/configuring-on-line-marketing-permissions/permissions_application.png "Configuring permissions for the On-line marketing module")

## On-line marketing

You can set the following permissions for the **On-line marketing** module.

| Permission | Description                                                                                                        |
| ---------- | ------------------------------------------------------------------------------------------------------------------ |
| Read       | Allows members of the selected roles to view data in some of the _On-line marketing_ application categories.       |
| Manage     | Allows members of the selected roles to manage the data in some of the _On-line marketing_ application categories. |

Parts of the system, where these permissions apply, are (and their UI):

- _Marketing overview_ application
- Activities
  - _Contact management_ application -> editing a contact -> _Activities_ tab
  - _Contact management_ application -> _Activity_ _log_ tab
  - _Contact management_ application -> _Configuration_ -> _Activity types_ and _Macro rules_ tabs

    > **Info:** To access these applications and tabs, you also need the **Read** and **Read configuration** [Contact management permissions](#contact-management).
- Parts of marketing automation
  - _Contact management_ application -> editing a contact -> _Processes_ tab

    > **Info:** To access this application and tab, you also need the **Read** [Contact management permission](#contact-management) and the **Read processes** [Marketing automation permission](#marketing-automation).
- Parts of contact management
  - _Contact management_ application -> _Pending contacts_ tab
  - _Contact management_ application -> _On-line users_ tab
  - _My pending contacts_ application

    > **Info:** To access these applications and tabs, you also need the **Read** [Contact management permission](#contact-management).

## Activities

Configure the permissions for [activity log](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/tracking-contact-activities.md) through the **Activities** module.

| Permission        | Description                                                                            |
| ----------------- | -------------------------------------------------------------------------------------- |
| Read activities   | Allows members of the selected roles to view activities in the activity log.           |
| Modify activities | Allows members of the selected roles to edit or delete activities in the activity log. |

## Banners

Configure the permissions for [Banners](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/banners.md) through the **Banner management** module.

| Permission    | Description                                                                                                     |
| ------------- | --------------------------------------------------------------------------------------------------------------- |
| Read          | Allows members of the selected roles to view banners and their categories on a specific site.                   |
| Modify        | Allows members of the selected roles to create, edit or delete banners and their categories on a specific site. |
| Global read   | Allows members of the selected roles to view global banners and their global categories.                        |
| Global modify | Allows members of the selected roles to create, edit or delete global banners and their global categories.      |

## Contact management

You can configure four basic types of permissions for the **Contact management** module.

| Permission           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read                 | Allows members of the selected roles to view [contacts](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts.md), [contact groups](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/segmenting-contacts-into-contact-groups.md), and [contact accounts](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts/organizing-contacts-into-accounts.md).                                                                                      |
| Modify               | Allows members of the selected roles to create, edit and delete contacts, contact groups, and contact accounts.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Read configuration   | Allows members of the selected roles to view [account statuses](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts/organizing-contacts-into-accounts.md#assigning-statuses-to-accounts), [contact statuses](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts/assigning-statuses-to-contacts.md), and [contact roles](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts/organizing-contacts-into-accounts.md). |
| Modify configuration | Allows members of the selected roles to create, edit and delete account statuses, contact statuses, and contact roles.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |

## Scoring

Configure the permissions for [Contact scoring](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/scoring-contacts.md) through the **Scoring** module.

| Permission | Description                                                                                                                              |
| ---------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view the settings of scores and their rules, as well as the score points of individual contacts. |
| Manage     | Allows members of the selected roles to create, edit and delete scores and their rules. Also authorizes users to recalculate scores.     |

## Content personalization

Configure the permissions for [Content personalization](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/content-personalization.md) through the **Content personalization** module.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view the following in the **Pages** application administration interface:<br>The content of personalization variants<br>The properties of personalization variants<br>Variant lists<br>No special permissions are required to view personalized content on the live site.                                                                                                                                                                                                                                                                                                             |
| Manage     | Allows members of the selected roles to create, edit and delete personalization variants of objects.<br>**Note**: For websites that use both content personalization and [workflow](https://docs.kentico.com/k10/managing-website-content/configuring-the-environment-for-content-editors/configuring-workflows.md), define editor roles without the **Content personalization -> Manage** permission if you wish to strictly enforce the workflow publishing process. Personalization variants of editor widgets are not included within the scope of workflow, so changes can have an immediate effect on the live website. |

> **Note:** **Note**
>
> Users need the **Design website** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
>
> To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k10/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.

## Email marketing

Configure the permissions for [Email marketing](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/email-marketing.md) actions through the **Email marketing** module.

| Permission              | Description                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ----------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read                    | Allows members of the selected roles to view all data in the _Email marketing_ application interface.                                                                                                                                                                                                                                                                                                                         |
| Destroy                 | Allows members of the selected roles to delete the version history of newsletter and email campaign objects.                                                                                                                                                                                                                                                                                                                  |
| Configure email feeds   | Allows members of the selected roles to configure the settings of all newsletters and email campaigns on the site.                                                                                                                                                                                                                                                                                                            |
| Author marketing emails | Allows members of the selected roles to create and edit marketing emails within newsletters and email campaigns.                                                                                                                                                                                                                                                                                                              |
| Manage recipients       | Allows members of the selected roles to add and remove email feed recipients ([contacts](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/working-with-contacts.md) and [contact groups](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/contact-management/segmenting-contacts-into-contact-groups.md)). |
| Manage templates        | Allows members of the selected roles to create, edit and delete email feed templates.                                                                                                                                                                                                                                                                                                                                         |

## Marketing automation

Configure the permissions for [Marketing automation](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/marketing-automation.md) through the **On-line marketing** module.

| Permission            | Description                                                                                                                                                                                                                                        |
| --------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read processes        | Allows members of the selected roles to view automation processes.                                                                                                                                                                                 |
| Manage processes      | Allows members of the selected roles to:<br>Create, configure and delete automation processes<br>Design the steps of automation processes<br>Move contacts within any process to the previous and next step (regardless of step security settings) |
| Start process         | Allows members of the selected roles to start automation processes for contacts and contact groups.                                                                                                                                                |
| Remove process        | Allows members of the selected roles to cancel instances of automation processes running for contacts.                                                                                                                                             |
| Move to specific step | Allows members of the selected roles to move contacts to any step within automation processes (regardless of step security settings).                                                                                                              |

> **Note:** **Note**: Users need the **Read**  permission for the **Contact management** module to be able to view and manage instances of automation processes running for contacts.

## A/B and MVT testing

Configure the permissions for [optimization testing](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/optimization-testing.md) through the **A/B testing** and **MVT testing** modules.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view all parts of the A/B or MVT testing management interface and the corresponding reports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| Manage     | Allows members of the selected roles to:<br>Create, edit and delete tests<br>Manage test variants (page variants for A/B tests; web part, zone and widget variants for MVT tests)<br>**Note**: For websites that use both MVT testing and [workflows](https://docs.kentico.com/k10/managing-website-content/configuring-the-environment-for-content-editors/configuring-workflows.md), define editor roles without the **MVT testing -> Manage** permission if you wish to strictly enforce the workflow publishing process. Variants of editor widgets are not included by workflow scopes, so even unapproved changes can be directly visible on the live website. |

### Editing A/B testing page variants:

- Because every A/B testing page variant is represented by a page in the content tree, the standard page permissions apply. The system checks all permissions configured for the **Content** module (creating, modifying and deleting pages).
- Users need the **Design website** permission for the **Design** module to edit page variants on the **Design** tab of the **Pages** application.

### Managing MVT object variants:

- Users need the **Design website** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
- To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k10/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.

> **Note:** **Note**: Users need permissions for the [Web analytics](#web-analytics) module to be able to access A/B and MVT testing reports.

## Personas

Configure the permissions for [Personas](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/personas.md) through the **Personas** module.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ---------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view the content of the **Personas** application.<br>To view the content of personalization variants, members of the selected roles need [Content personalization](#content-personalization) permissions.<br>No special permissions are required to view personalized content on the live site.                                                                                                      |
| Modify     | Allows members of the selected roles to create, edit and delete personas in the **Personas** application.<br>**Note** that to be able to tag pages with personas in the **Pages** application, members of the selected roles need the **Browse tree**, **Read**and **Modify\*\*\*\*Content** [permissions](https://docs.kentico.com/k10/managing-users/configuring-permissions/configuring-page-permissions/permissions-for-all-content.md). |

> **Note:** **Note**
>
> Users need the **Design website** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
>
> To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k10/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.

## Web analytics

Configure the permissions for [Web analytics](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/web-analytics.md) (including [conversion](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/web-analytics/logging-custom-conversions-on-your-website.md) and [campaign](https://docs.kentico.com/k10/on-line-marketing-features/managing-your-on-line-marketing-features/campaigns.md) management) through the **Web analytics** module.

| Permission         | Description                                                                                                                                                                                                                             |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read               | Allows members of the selected roles to view web analytics reports in the Web analytics application.<br>Users also need the Read permission to access the analytics reports anywhere else in the UI, for example in _Pages -> Reports_. |
| Save reports       | Allows members of the selected roles to save web analytics reports. The saved reports can be viewed in the _Reporting_ application.                                                                                                     |
| Manage data        | Allows members of the selected roles to manage the data logged for various statistics (i.e. delete or generate sample data for statistics).                                                                                             |
| Manage campaigns   | Allows members of the selected roles to create and delete campaign tracking objects and edit their properties, including goals.                                                                                                         |
| Manage conversions | Allows members of the selected roles to create, edit and delete conversions.                                                                                                                                                            |
