๐Ÿ” Roles and permissions

This page explains who can do what in the CMS for campaigns. It also covers optional approvals and audit trails.

Me

Written by the Merlin Cloud team

Updated 21 August 2025


Roles at a glance

  • Admin
    Full control inside your organisation. Creates and manages campaigns, devices, locations, members, and settings.

  • Manager
    Day-to-day operator. Creates and manages campaigns and devices. No access to organisation user management.

  • Viewer
    Read only. Can browse campaigns, versions, previews, analytics, and device status.

  • Author (experience developer)
    Builds Experiences and Experience Releases. Can see release code metadata such as GitHub repo and branch. Client organisations cannot see these details.

Campaign permissions matrix

Capability

Admin

Manager

Viewer

Author

View campaigns and versions

โœ…

โœ…

โœ…

โž–

Create campaign

โœ…

โœ…

โŒ

โž–

Edit campaign content

โœ…

โœ…

โŒ

โž–

Validate and resolve required fields

โœ…

โœ…

โŒ

โž–

Duplicate a campaign

โœ…

โœ…

โŒ

โž–

Schedule start date and targets

โœ…

โœ…

โŒ

โž–

Publish a campaign

โœ…

โœ…

โŒ

โž–

Archive or restore

โœ…

โœ…

โŒ

โž–

Share preview links

โœ…

โœ…

โœ…

โž–

View change log and diffs

โœ…

โœ…

โœ…

โž–

Export data and reports

โœ…

โœ…

โœ…

โž–

Manage devices and device actions

โœ…

โœ…

โŒ

โž–

Manage locations and translation preferences

โœ…

โœ…

โŒ

โž–

Manage organisation members and roles

โœ…

โŒ

โŒ

โŒ

Create Experiences and Releases

โŒ

โŒ

โŒ

โœ…

View Git repo and branch on releases

โŒ

โŒ

โŒ

โœ…

Legend: โœ… allowed โ€ข โŒ not allowed โ€ข โž– not applicable

Approvals

  • Standard: No approval workflow is required to publish.

  • Enterprise option: A multi step approval flow is available on request. You can require specific reviewers before publish. Contact support to enable.

Notifications

  • By default Admins and Managers receive dashboard notifications for schedule created, publish, failure, and rollback events.

  • Viewers can see the status in the UI but do not receive action notifications.

Audit trail

  • The CMS records who changed what and when, including content edits, target changes, schedule edits, publishes, and restores.

  • Admins and Managers can view the audit log. Viewers have read access to version history and diffs.

Security notes

  • Experience release source code links are visible to Authors only. Client organisations cannot see repo or branch details.

  • Use role scoping to limit risk in production. Grant Manager where possible and reserve Admin for a small set of owners.


Related articles

๐Ÿ” Roles and permissions ยท Merlin Cloud