---
title: Configuring on-line marketing permissions
related:
  - https://docs.kentico.com/k82/managing-users/configuring-permissions.md
  - https://docs.kentico.com/k82/managing-users/ui-personalization.md
  - https://docs.kentico.com/k82/securing-websites.md
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

You can control access to on-line marketing features through:

- [Permissions](https://docs.kentico.com/k82/managing-users/configuring-permissions.md)
- [UI personalization](https://docs.kentico.com/k82/managing-users/ui-personalization.md)

The system only allows users to perform on-line marketing actions if they belong to roles with permissions for individual on-line marketing modules.

1. Create on-line marketing roles for your website.
2. Configure the permissions of the roles.
3. Assign individual users to the appropriate roles.

You can configure module permissions for roles in the **Permissions** application.

![Configuring permissions for the On-line marketing module](https://docs.kentico.com/docsassets/k82/configuring-on-line-marketing-permissions/permissions_application.png "Configuring permissions for the On-line marketing module")

## On-line marketing

You can set the following permissions for the **On-line marketing** module.

| Permission | Description                                                                                             |
| ---------- | ------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view data in the On-line marketing category applications.       |
| Manage     | Allows members of the selected roles to manage the data in the On-line marketing category applications. |

## Web analytics

Configure the permissions for [Web analytics](https://docs.kentico.com/k82/on-line-marketing-features/web-analytics.md) (including [conversion](https://docs.kentico.com/k82/on-line-marketing-features/web-analytics/logging-conversions-on-your-website.md) and [campaign](https://docs.kentico.com/k82/on-line-marketing-features/web-analytics/tracking-campaigns.md) management) through the **Web analytics** module.

| Permission         | Description                                                                                                                                                                                                                             |
| ------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read               | Allows members of the selected roles to view web analytics reports in the Web analytics application.<br>Users also need the Read permission to access the analytics reports anywhere else in the UI, for example in _Pages -> Reports_. |
| Save reports       | Allows members of the selected roles to save web analytics reports. The saved reports can be viewed in the _Reporting_ application.                                                                                                     |
| Manage data        | Allows members of the selected roles to manage the data logged for various statistics (i.e. delete or generate sample data for statistics).                                                                                             |
| Manage campaigns   | Allows members of the selected roles to create and delete campaign tracking objects and edit their properties, including goals.                                                                                                         |
| Manage conversions | Allows members of the selected roles to create, edit and delete conversions.                                                                                                                                                            |

## Contact management

You can configure four basic types of permissions for the **Contact management** module.

| Permission    | Description                                                                                                                                                                                                                                                            |
| ------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read          | Allows members of the selected roles to access the corresponding part of the on‑line marketing interface and view any data there.                                                                                                                                      |
| Read global   | Allows members of the selected roles to view global objects of the given type.<br>**Note**: Global data is only available if the website's settings allow global data (configure in **Settings -> On‑line marketing -> Contact management -> Global data & merging**). |
| Modify        | Allows members of the selected roles to create, edit or delete objects of the given type.                                                                                                                                                                              |
| Modify global | Allows members of the selected roles to create, edit or delete global objects of the given type.                                                                                                                                                                       |

The permissions are available for the following contact management objects:

- **Contacts** - allow users to view or manage [contacts](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/working-with-contacts.md) and their settings.
- **Accounts** - allow users to view and manage [accounts](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/working-with-contacts/organizing-contacts-into-accounts.md).
- **Contact groups** - allow users to view and management [contact groups](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/contact-segmentation.md).
- **Configuration** - allow users to view and manage account statuses, [contact statuses](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/working-with-contacts/assigning-statuses-to-contacts.md) and [contact roles](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/working-with-contacts/organizing-contacts-into-accounts.md).
- **Activities** - allow users to view or manage the [activity log](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/tracking-contact-activities.md). There are no global permissions for activities, since the system always logs activities for a specific site.

> **Note:** **Note**: Only users with the Global administrator [privilege level](https://docs.kentico.com/k82/managing-users/user-management.md) may configure _Read global_ and _Modify global_ type permissions.

## Scoring

Configure the permissions for [Contact scoring](https://docs.kentico.com/k82/on-line-marketing-features/contact-management/scoring-contacts.md) through the **Scoring** module.

| Permission | Description                                                                                                                              |
| ---------- | ---------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view the settings of scores and their rules, as well as the score points of individual contacts. |
| Manage     | Allows members of the selected roles to create, edit and delete scores and their rules. Also authorizes users to recalculate scores.     |

## Email marketing

Configure permissions for [Email marketing](https://docs.kentico.com/k82/on-line-marketing-features/email-marketing.md) actions through the **Email marketing** module.

| Permission                | Description                                                                                           |
| ------------------------- | ----------------------------------------------------------------------------------------------------- |
| Read                      | Allows members of the selected roles to view all data in the _Email marketing_ application interface. |
| Destroy                   | Allows members of the selected roles to delete the version history of email campaign objects.         |
| Configure email campaigns | Allows members of the selected roles to configure the settings of all email campaigns on the site.    |
| Author campaign emails    | Allows members of the selected roles to create and edit emails within email campaigns.                |
| Manage subscribers        | Allows members of the selected roles to add and remove email campaign subscribers.                    |
| Manage templates          | Allows members of the selected roles to create, edit and delete email campaign templates.             |

> **Note:** **Subscribing contact groups to email campaigns**
>
> **Note**: Users need the **Read contact groups** permission for the **Contact management** module to be able to subscribe contact groups to email campaigns.

## Marketing automation

Configure permissions for [Marketing automation](https://docs.kentico.com/k82/on-line-marketing-features/marketing-automation.md) through the **On-line marketing** module.

| Permission            | Description                                                                                                                                                                                                                                         |
| --------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Manage                | Allows members of the selected roles to:<br>Create, configure, and delete automation processes<br>Design the steps of automation processes<br>Move contacts within any process to the previous and next step (regardless of step security settings) |
| Start process         | Allows members of the selected roles to start automation processes for contacts and contact groups.                                                                                                                                                 |
| Remove process        | Allows members of the selected roles to cancel instances of automation processes running for contacts.                                                                                                                                              |
| Move to specific step | Allows members of the selected roles to move contacts to any step within automation processes (regardless of step security settings).                                                                                                               |

> **Note:** **Note**: Users need the **Read contacts** permission for the **Contact management** module to be able to view and manage instances of automation processes running for contacts.

## A/B and MVT testing

Configure permissions for [optimization testing](https://docs.kentico.com/k82/on-line-marketing-features/optimization-testing.md) through the **A/B testing** and **MVT testing** modules.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| ---------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view all parts of the A/B or MVT testing management interface and the corresponding reports.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| Manage     | Allows members of the selected roles to:<br>Create, edit, and delete tests<br>Manage test variants (page variants for A/B tests; web part, zone and widget variants for MVT tests)<br>**Note**: For websites that use both MVT testing and [workflows](https://docs.kentico.com/k82/managing-website-content/configuring-the-environment-for-content-editors/configuring-workflows.md), define editor roles without the **MVT testing -> Manage** permission if you wish to strictly enforce the workflow publishing process. Variants of editor widgets are not included by workflow scopes, so even unapproved changes can be directly visible on the live website. |

### Editing A/B testing page variants:

- Because every A/B testing page variant is represented by a pagein the content tree, the standard page permissions apply. The system checks all permissions configured for the **Content** module (creating, modifying and deleting pages).
- Users need the **Design web site** permission for the **Design** module to edit page variants on the **Design** tab of the **Pages** application.

### Managing MVT object variants:

- Users need the **Design web site** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
- To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k82/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.

> **Note:** **Note**: Users need permissions for the [Web analytics](#web-analytics) module to be able to access A/B and MVT testing reports.

## Content personalization

Configure permissions for [Content personalization](https://docs.kentico.com/k82/on-line-marketing-features/content-personalization.md) through the **Content personalization** module.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Read       | Allows members of the selected roles to view the following in the **Pages** application administration interface:<br>The content of personalization variants<br>The properties of personalization variants<br>Variant lists<br>No special permissions are required to view personalized content on the live site.                                                                                                                                                                                                                                                                                                             |
| Manage     | Allows members of the selected roles to create, edit and delete personalization variants of objects.<br>**Note**: For websites that use both content personalization and [workflow](https://docs.kentico.com/k82/managing-website-content/configuring-the-environment-for-content-editors/configuring-workflows.md), define editor roles without the **Content personalization -> Manage** permission if you wish to strictly enforce the workflow publishing process. Personalization variants of editor widgets are not included within the scope of workflow, so changes can have an immediate effect on the live website. |

> **Note:** **Note**
>
> Users need the **Design web site** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
>
> To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k82/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.

## Personas

Configure permissions [Personas](https://docs.kentico.com/k82/on-line-marketing-features/content-personalization/personas.md) through the **Personas** module.

| Permission | Description                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| Read       | Allows members of the selected roles to view the content of the **Personas** application.<br>To view the content of personalization variants, members of the selected roles need [Content personalization](#content-personalization) permissions.<br>No special permissions are required to view personalized content on the live site.                                                                                              |
| Modify     | Allows members of the selected roles to create, edit and delete personas in the **Personas** application.<br>Note that to be able to tag pages with personas in the **Page** application, members of the selected roles need the the **Browse tree**, **Read**and **Modify Content** [permissions](https://docs.kentico.com/k82/managing-users/configuring-permissions/configuring-page-permissions/permissions-for-all-content.md). |

> **Note:** **Note**
>
> Users need the **Design web site** permission for the **Design** module to manage the variants of web parts and zones on the **Design** tab of the **Pages** application.
>
> To work with variants of editor widgets on the **Pages** application **Page** tab, the **Modify** permission for the **Content** module is required. The [security settings of specific widgets](https://docs.kentico.com/k82/developing-websites/preparing-widgets-for-users/configuring-permissions-for-widgets.md) also apply.
