User Roles and Permissions
Overview
Each user is assigned a role that determines their level of access in Campaign Manager. Roles fall into two broad scopes:
- Platform-level roles apply across the whole platform. Users with a platform-level role can work across ad accounts, depending on their permissions.
- Ad account-level roles apply to a specific ad account. Users with an ad account-level role can work only within the ad accounts they are assigned to.
Within each scope, roles range from full edit access to read-only access. Read-only (view-only) roles are useful for users who need to monitor performance and review reporting without making changes.
The exact set of available roles depends on which Campaign Manager surface you use:
- Standalone Campaign Manager: the full Campaign Manager portal.
- Widgetized Campaign Manager: Campaign Manager components embedded into your own portal, where roles are passed in through the SSO URL.
Read-only roles
Two read-only roles are available so you can grant monitoring and reporting access without granting edit permissions:
- Platform Viewer (Read Only): can view platform-level information across ad accounts, but cannot create or change any settings. This role is limited to monitoring and reporting.
- Ad Account Viewer (Read Only): can view information within an assigned ad account, but cannot create or change any settings. This role is limited to monitoring and reporting.
Users with a read-only role can navigate the relevant dashboards and reports, but actions that create, edit, or delete entities (such as campaigns, budgets, bids, or wallet settings) are not available to them.
Roles in Standalone Campaign Manager
The following roles are available in the standalone Campaign Manager portal.
| Role | Scope | Access level |
|---|---|---|
| Platform Admin | Platform | Full access to platform-level settings and all ad accounts |
| Platform Manager | Platform | Manage platform-level settings and ad accounts |
| Platform Viewer (Read Only) | Platform | View-only access across the platform; monitoring and reporting only |
| Ad Account Admin | Ad account | Full access within assigned ad accounts |
| Ad Account Manager | Ad account | Manage campaigns and settings within assigned ad accounts |
| Ad Account Viewer (Read Only) | Ad account | View-only access within assigned ad accounts; monitoring and reporting only |
Roles in Widgetized Campaign Manager
The following roles are available in the widgetized Campaign Manager. In the widgetized experience, the user's role is passed in through the SSO URL (see SSO behavior below).
| Role | Scope | Access level |
|---|---|---|
| AD_ACCOUNT_MANAGER | Ad account | Manage campaigns and settings within assigned ad accounts |
| AD_ACCOUNT_AGENCY | Ad accounts | View performance and manage campaigns across assigned ad accounts; no access to unassigned linked accounts. |
| AD_ACCOUNT_VIEWER | Ad account | View-only access within assigned ad accounts; monitoring and reporting only |
| AD_MANAGER_ACCOUNT_OWNER | Ad manager account | Full access to the Ad Manager Account and all linked ad accounts, including inherited authority across its managed accounts. |
| AD_MANAGER_ACCOUNT_USER | Ad manager account | Manage campaigns across the ad accounts linked to the Ad Manager Account. |
SSO behavior for roles
In the widgetized Campaign Manager, a user's role is provided through the SSO URL when the user is signed in. This means you assign roles as part of your SSO integration rather than managing them separately inside the portal.
- The role value (for example,
PLATFORM_VIEWERorAD_ACCOUNT_VIEWER) is passed as a parameter in the SSO URL. - The role passed through SSO determines what the user can see and do for that session.
- Read-only roles can be granted the same way, so you can provision monitoring-only access through your existing SSO flow.
For details on configuring single sign-on and credentials, see the SSO & MFA and API and SSO Credential Management pages.
Where role settings appear
Role and permission information now lives on this page. The product overview and campaign management pages link here instead of describing roles directly, so there is a single source of truth for roles and permissions.
FAQ
What is the difference between a platform role and an ad account role?
A platform role applies across the whole platform and can work across ad accounts, depending on its permissions. An ad account role applies only to the specific ad accounts the user is assigned to.
What can a read-only user do?
A user with a read-only role (Platform Viewer or Ad Account Viewer) can view dashboards and reporting within their scope, but cannot create, edit, or delete any settings or entities. These roles are intended for monitoring and reporting.
How are roles assigned in the widgetized Campaign Manager?
Roles are passed in through the SSO URL when the user signs in. The role value provided in the SSO URL determines the user's access for that session.
Can a single user have more than one role?
This page documents the currently released roles and access model. Multi-role assignment is not part of the current documented scope.
Updated 18 days ago