| Answer | A role is a set of permissions assigned to a user. Roles control access to features, define responsibilities, and ensure proper delegation and security. Each Tango user has a role that determines what they can see and do. Only users with Entire organization access and Manage roles permissions can create and manage roles. These users can assign roles at the organization level or below. See Add, edit, delete users.
How a role functions depends on two key elements: the role's assigned permissions and the user's access level.
Access level
Access level defines a user’s visibility and the groups or accounts their permissions apply to. For example, a user with the Admin default role and Entire organization access can add, edit, and remove users and their access across the organization. An admin with Select accounts and groups access and the Manage users permission can manage users only within their assigned groups and accounts.
|
Access Level
|
Definition
|
|---|
|
Entire organization
|
User can apply their permissions across all current and future groups and accounts. Platform admin is a user with the Admin default role and Entire organization access.
| |
Select accounts (and groups)
|
User can apply their permissions only to specific groups/accounts.
|
Access and permission rules
Keep these rules in mind when assigning roles, permissions, and access levels:
-
Permissions do not override access level: Broad permissions (like Manage users or Order history) remain limited to the user’s assigned scope.
-
Manage roles requires Entire organization: A user with Manage roles cannot edit roles unless they have Entire organization, not just Select accounts and groups.
-
Lower-scope users cannot manage higher-scope users: This prevents privilege escalation.
-
Separate scopes stay separate: Localized admins for different accounts cannot see each other in the user directory.
Role types
Tango uses two role types to control what people can do in the platform.
|
Role type
|
Definition
|
|---|
|
Default roles
|
Default roles are predefined roles provided by Tango. Default roles:
-
Include a standard set of permissions, such as Admin, Sender, Standard, Support, and Support Lead.
-
Cannot be modified, renamed, or deleted.
-
Are useful to quickly assign common responsibilities without configuring permissions manually. See Manage default user roles in Tango.
| |
Custom roles
|
Custom roles are created to match your organization’s specific needs. Custom roles:
-
Are created by users with Entire organization access and Manage roles permissions.
-
Are fully configurable, so you can choose permissions and access levels.
-
Are helpful when default roles don’t align with your internal structure, workflows, or responsibilities. See Manage custom user roles in Tango.
|
Default roles and definitions
Default roles are Tango-provided permission sets that match common user responsibilities. Default roles cannot be edited, renamed, or deleted. To change permissions, duplicate a default role to create a custom role and then modify it. See Manage custom user roles in Tango. A user’s access level still determines where those role permissions apply.
|
Default Role
|
Definition
|
|---|
|
Admin
|
Admins have broad platform permissions. What they can manage depends on their access level:
-
Platform admin: Admin with Entire organization access. Can manage organization-level settings, users, roles, groups, accounts, rewards, and order history across the organization.
-
Limited-access admin: Admin with Select accounts and groups access. Can manage only within their assigned accounts and groups and cannot use permissions that require organization-level access.
Note:
Admins do not have access to Tango API credentials by default. API credentials must be enabled for your platform and require organization-level access before admins can use them. Contact your Customer Success Manager (CSM) or email success@tangocard.com for access.
| |
Sender
|
-
Orders and tracking:
-
Send rewards: Enabled (can place and send reward orders for accounts and groups within their assigned access level).
-
Order history: Enabled with Own orders - View access (can view order history for orders they placed themselves and resend reward emails to the original email address only).
-
Money and payments:
| |
Standard
|
| |
Support
|
-
Orders and tracking:
-
Order history: Enabled.
-
Other users' orders: Enabled with Manage access (can view, edit, and resend other users' orders, including updating delivery email addresses).
-
Delivery templates: Enabled with View access (can view existing delivery templates, but cannot create or edit them).
-
Money and payments:
| |
Support Lead
|
-
Orders and tracking:
-
Order history: Enabled.
-
Other users' orders: Enabled with Manage access (can view, edit, and resend other users' orders, including updating the delivery email address).
-
Order management settings: Enabled with Select access (can choose which order management settings apply).
-
Delivery templates: Enabled with View access (can view existing delivery templates, but cannot create or edit them).
-
Money and payments:
|
Available permissions in Tango
Use this table as a reference when creating or updating custom roles. Permissions define what users can do in each area of Tango, and a user’s access level determines where those permissions apply.
Use these permissions to grant only the access a user needs. Some permissions include View, Manage, or Select options depending on the feature.
|
Permissions
|
What's included?
|
Description
|
|---|
|
Orders and Tracking
|
Send rewards
|
Allows users to send rewards from the accounts and groups they have access to. Users may see account balances unless balances are explicitly hidden with Hide account balance from user.
| |
Order history
|
Allows users to view and, when enabled, manage orders sent through Tango. When Order history is on, you can control:
-
Own orders:
-
With View permission, you can see your own orders and resend rewards only to the original email address.
-
With Manage permission, you can edit and resend rewards, including resending to a different email address.
-
Other users' orders:
-
With View permission, you can see orders placed by other users (within your access level) and resend rewards only to the original email address.
-
With Manage permission, you can edit and resend rewards for others’ orders (within your access level), including resending to a different email address.
| |
Order management settings
|
Applies only to orders you can manage:
-
-
Freeze reward: Freeze and unfreeze a fully unredeemed Reward Link up to a maximum of 5 calendar days after the reward is issued. See Freeze and unfreeze rewards.
-
Cancel reward: Self-cancel a reward within 5 days after issuing. See Cancel and reissue rewards.
-
Cancel and reissue reward: Self-cancel and reissue a reward within 5 days after issuing. See Cancel and reissue rewards.
-
Reissue expired Promo Link reward: Lets users reissue expired promo links to the original recipient.
| |
Delivery templates
|
Controls access to reward delivery templates.
-
View: users can see and use existing templates (for example, when placing orders).
-
Manage: users can create and configure templates.
| |
Reports
|
Allows users to view, generate, and download reports based on their access level.
-
View: users can see available reports for the groups/accounts they have access to.
-
Manage: users can configure report settings (where available) and schedule or export reports within their access level.
| |
Manage filters
|
Allows users to create, edit, and manage saved filters they can use to refine views and find orders or other records more quickly. Filter visibility and results are limited by the user’s access level.
| |
Campaign management
|
Allows users to create, view, and manage reward campaigns within the accounts and groups they can access. Campaign access remains limited by the user’s assigned access level.
| |
Money and payments
|
Funding and payments
|
Controls access to payment options:
| |
Hide account balance
|
Hides account balances from the user, even if other permissions (such as Place orders or Accounts) would normally display them. This applies to all accounts the user can access.
| |
Managing your organization
|
Platform and account settings
|
Controls access to Tango’s organization‑level platform configuration. This includes settings for Login methods, SSO connections, MFA methods, and Delivery methods.
| | User management |
Controls whether a user can view and administer users in Tango.
-
Users with Entire organization access and Manage users permission can add, edit, and delete users.
-
Users without Entire organization access may be able to view but cannot add or modify users even if Manage users are enabled for them.
Disclaimer:
Local user admin is a Closed Release, available for a limited number of users and specific use cases only.
A local user admin is created by an admin or custom user with user‑management permissions and access to the full organization or specific groups/accounts. Local user admins can create and manage users only within their assigned groups or accounts, and cannot view or manage anything outside that scope. You can have one or multiple local user admins. Contact your Customer Success Manager (CSM) or email success@tangocard.com for more information.
| | Role management |
Controls whether a user can view and administer roles and permissions in Tango.
-
Users with Entire organization access and Manage roles permission can create, duplicate, edit, rename, and delete custom roles, and assign roles to users.
-
Users without Entire organization access cannot view or modify role configurations, even if Manage roles is enabled for them.
| |
Account management
|
Controls whether a user can see and/or manage the groups and accounts they have access to in Tango.
-
View: users can see account and group details (such as account names and balances, unless balance is hidden) but cannot change settings.
-
Manage users can create new accounts (requires Org Access) and update certain account settings, but cannot edit account names or account groups in the portal.
| |
Integrations and API
|
Integrations
|
Controls whether users can view and manage connected integrations, such as Qualtrics, Slack, Salesforce, and HubSpot.
-
View: users can see existing integration settings and activity.
-
Manage: users can connect, configure, update, and disconnect integrations within their access level.
| |
Qualtrics incentives
|
Controls access to Qualtrics incentive configurations used to send rewards through Qualtrics workflows.
-
View: users can review incentive settings, linked accounts, and incentive activity.
-
Manage: users can create, edit, enable, disable, and update Qualtrics incentive configurations.
| |
Qualtrics API credentials
|
Controls access to API credentials used for Qualtrics integrations.
-
View: users can view existing Qualtrics API credential details.
-
Manage: users can generate, update, rotate, and deactivate Qualtrics API credentials.
| |
Tango API credentials
|
Controls access to organization-level Tango API credentials.
-
View: users can view existing Tango API credential details.
-
Manage: users can generate, update, rotate, and deactivate Tango API credentials.
Note: Tango API credentials require Entire organization access and must be enabled for your platform.
|
More resources:
|
|
|---|