IOSOR Learn

Who may send, approve, or export

Split send, approve, and export so finance month-end CSV cannot fire production SMS. Bind Live promotion to runway and compliance gates.

Three verbs drive prepaid messaging risk: send, approve, and export. Send submits live SMS and debits the wallet.

IOSOR expects an explicit split. Export sits with finance and product reporting. Approve sits with launch and compliance owners who watch runway greens.

Map three verbs to three owners

Write a one-page matrix: person or group → Send / Approve / Export. Prefer separate seats even when the team is small. If one human must wear two hats temporarily, document the dual role and a sunset date — never invent a permanent god seat.

Send covers production submit APIs, console blast tools, and automation identities that can leave the pilot lane. Approve covers campaign go-live, template promotion, and any button that flips a draft into Live.

Finance export must not inherit send

Month-end export at 02:00 is a finance job. The seat that downloads the ledger must not also hold production send. If finance needs to verify a corridor spend, give them export and read-only status views — not a blast console.

Test the split after every role change: log in as the export seat and confirm Send is hidden or denied. If the UI still shows Send, the matrix is a slide, not a control. When partners demand “one admin for everything,” answer with prepaid honesty: export that can send is how quiet hours and STOP handling get bypassed by accident. Split the verbs or delay Live.

Approve stays in front of runway and compliance

Approve is not a courtesy checkbox. It binds to day-1 runway greens and production compliance gates. The person who approves a campaign into Live must see webhook heartbeat freshness, messaging readiness, and compliance status — not only a marketing calendar. Do not let export owners approve Live flips “because they already have admin.” Approval without runway evidence creates tickets that a funded wallet cannot close. If runway is red, approve must refuse even when the wallet is green.

Kill the shared super-admin before first Live

A single password shared across finance, eng, and ops collapses the three verbs. Rotate to named seats before the first production send. Automation identities that send must have a human owner listed next to Send — not “shared bot.” Partner white-label admins follow the same rule: tenant export roles stay off the send path so surface gates and compliance language stay honest.

Related ops paths

Start with IOSOR

Audit your active team seats in the IOSOR console and map each user strictly to Send, Approve, or Export. Immediately revoke production send privileges from any finance or accounting profile that requires ledger export access. Set temporary dual-role exemptions with an explicit sunset date if your team is currently constrained, ensuring no shared super-admin accounts exist before hitting the live submission gate.

IOSOR takeaway

Broad access permissions introduce severe operational risk when month-end reporting seats hold live dispatch capabilities. Separating the three core verbs ensures that a routine 02:00 ledger download cannot accidentally trigger production SMS blasts or bypass compliance approvals.

Do restrict finance and accounting seats to export and read-only status views while binding approve rights strictly to team leads who monitor webhook health and compliance gates. Don't rely on a shared super-admin account or leave automated sending scripts without a named human owner.

Was this guide helpful?

Related guides

  • Who may send vs API key rotation hygiene

    People roles decide who may send. API key rotation and sandbox cutover stay under Developers — do not merge seat grants with secret lifecycle.

  • An export role must not send

    Least privilege on prepaid: audit and GDPR export access is not a campaign send seat. Keep report roles read-only on the live messaging path.