Salesforce

Default user roles in Tango portal

« Go Back

Information

 
Answer

Each Tango user can be assigned a default role or a custom role. Default roles come with a predetermined permission set. Tango Platform Admins with Organization Access can manage user roles and permissions and create additional roles with custom permission sets if necessary. See Create and edit custom roles to learn how you can create or edit custom roles.

Default user roles in Tango portal

Tango platforms come with a few default roles, such as admin, sender, standard, and more.

To see default roles:

  1. Sign in to the Tango portal.
  2. Click  Team settings > Users on the left menu.
  3. Click Role Management in the top right corner.
  4. Click any role on the left to see its details on the right. 

The following Default Roles are available in Tango. For the custom roles, see Create and edit custom roles.
 

RoleDefinition
AdminAdmins have full access and permissions to all features in Tango except Tango API Keys.
  • By default permissions for Tango API Keys for all users (including Admins) are set to Don't Allow.
  • Any Admin can change the permission to Manage to allow access to Tango API Key management.
Note: You first need to have the API keys enabled for your platform. Contact your Customer Success Manager (CSM) or success@tangocard.com to get the API keys enabled for your platform.
Sender
  • Senders can only Send rewards and access their own Order history.
  • When viewing Orders the Sender can resend reward emails to the original recipient email.
  • Senders don't have permission to view the account balance.
  • All other features are set to Don't Allow
Standard
  • Standard users can Send rewards and View account balance.
  • When viewing Orders, Standard user can resend reward emails to the original recipient email or a different email for the same recipient.
  • Standard users can Manage Groups & Accounts and Reward Templates. Only users who have Organization Access are able to interact with Organization Structure and Integration.
  • All other features are set to Don't Allow.
Support
  • Support users can only view Orders and Reward Templates in their access level. They can resend reward emails to the original recipient email.
  • All other features are set to Don't Allow.
Support Lead
  • Support Lead users can only view Orders and Reward Templates.
  • They can resend reward emails to the original recipient email or a different email for the same recipient.
  • All other features are set to Don't Allow.
CustomCustom users have specific permissions that are manually assigned by an Admin. For the custom roles, see Create and edit custom roles.

Permission level

User’s permission level determines whether or not the user has access to specific features regardless of the set permissions that come with the assigned roles. For example, you can allow the Sender role to place orders, but don’t allow Sender to see account balances. Access to each Tango function can be toggled On or Off:
 

Permission levelDefinition
Don't AllowNo access; the feature can't be used.
ViewPartial access; can be viewed but not edited.
Allow / ManageFull access; the feature is visible and can be used to its full extent.

Permission categories

Here are the available permission categories in Tango. In each category, permissions are limited based on the user's group/account access:
 

Permission CategoryDescription
Place ordersAllows users to send rewards.
Order HistoryAllows users to view rewards sent with Tango and resend reward emails.
Organization StructureAllows users to see or manage Groups, Accounts, and Users on the Tango platform.
FundingAllows users to access features related to account funding.
Reward TemplatesAllows users to access reward templates.
IntegrationsAllows users to access Tango integrations such as Salesforce and Qualtrics.
ReportsAllows users to access reports.

Place orders permissions

Allows users to send rewards. Learn how to Send Tango rewards by email or Send rewards in bulk:
 

PermissionRight of use
Place Order
  • Don't Allow: restricts users from sending rewards.
  • Allow: lets users send rewards.
Show Account Balance
  • Don't Allow: restricts users from seeing the account balance in the left panel.
  • Allow: lets users to see the account balance in the left panel

Order History permissions

Allows users to view rewards sent with Tango and resend reward emails. Learn how to View reward orders with Tango or Resend Reward Emails:
 

PermissionRight of use
Individual Order History
  • Don't Allow: Restricts users from seeing rewards they sent.
  • View: Lets users see only rewards they sent and resend the reward email message to the original recipient email.
  • Manage: Lets users see only rewards they sent and resend the reward email message to the original recipient email or a different email for the same recipient.
Order History
  • Don't Allow: Restricts users from seeing rewards sent by all users at their access level.
  • View: Lets users see rewards sent by all users at their access level and resend the reward email message to the original recipient email.
  • Manage: Lets users rewards sent by all users at their access level and resend the reward email message to the original recipient email or a different email for the same recipient.
Freeze Reward
  • Don't Allow: Restricts users from freezing and unfreezing rewards.
  • Manage: Lets users freeze and unfreeze a fully unredeemed Reward Link up to a maximum of five (5) calendar days after the reward is issued. See Freeze and unfreeze rewards.
Cancel Reward
  • Don't Allow: Restricts users from canceling rewards after it’s been issued.
  • Manage: Lets users self-cancel a reward within five days after issuing. See Cancel and reissue rewards.
Reissue Reward
  • Don't Allow: Restricts users from canceling and reissuing a reward after it’s been issued.
  • Manage: Lets users self-cancel and reissue a reward within five days after issuing. See Cancel and reissue rewards.
Reissue Expired Promo Link Reward
  • Don’t Allow: Restricts users from reissuing expired promo links to the original recipient.
  • Manage: Lets users reissue expired promo links to the original recipient.
 
Note: The Order History permissions override the Individual Order History permissions. If a user’s Individual Order History permission is set to Don't Allow but the Order History is set to Manage, the user is still able to see and resend reward emails for the rewards that have been sent by them and by other users.

Organization Structure permissions

Allows users to see or manage Groups, Accounts, and Users on the Tango platform:
 

PermissionRight of use
Groups & Accounts
  • Don't Allow: Restricts users from seeing Group and Account details.
  • View: Lets users see Group and Account details at their access level.
  • Manage: Lets users create/edit/deactivate Groups and Accounts only if they have Organization Access.
Users
  • Don't Allow: Restricts users from seeing other user information.
  • Manage: Lets users create/edit/delete users and assign Roles/Permission/Access Levels to users only if they have Organization Access.
Recipient Allowlist
  • Don't Allow: Restricts users from seeing the recipient allowlist (when in use).
  • Manage: Lets users upload/update recipient allowlists and view existing recipients.
Roles
  • Don't Allow: Restricts users from seeing roles on the platform.
  • Manage: Lets users create/edit/delete roles on the platform.
Authentication
  • Don't Allow: Restricts users from managing allowed multi-factor authentication methods for the platform
  • Manage: User can manage allowed multi-factor authentication methods for the platform.

Funding permissions

Allows users to access features related to account funding:
 

PermissionRight of use
Funding & Account Balances
  • Don't Allow: Restricts users from seeing funding and account balance information.
  • View: Lets users view account balances, funding history & download receipts at their access level.
  • Manage: Lets users register/edit/delete credit cards, add funds & view funding history at their access level.

Reward Templates permissions

Allows users to access reward templates:
 

PermissionRight of use
Reward Template
  • Don't Allow: Restricts users from seeing reward templates.
  • View: Lets users view reward templates that can be used at their access level.
  • Manage: Lets users create/edit/delete reward templates at their access level.

Integrations permissions

Allows users to access Tango integrations such as Salesforce and Qualtrics:
 

PermissionRight of use
Tango API Keys
  • Don't Allow: Restricts users from accessing Tango API Keys.
  • Manage: Lets users access and manage Tango API Keys.
Qualtrics API Keys
  • Don't Allow: Restricts users from accessing the Qualtrics integration.
  • View: Users can only view Qualtrics API keys.<
  • Manage: Lets users generate and deactivate Qualtrics API Keys in addition to being able to view them.
Qualtrics Incentives
  • Don't Allow: Restricts users from managing incentives for Qualtrics research survey respondents.
  • View: Users can only view incentives for Qualtrics research survey respondents.
  • Manage: Lets users manage incentives for Qualtrics research survey respondents. You can only view or edit the incentives connected to your accounts and groups that you have access to. If you have manage permission, you can create incentives but can only draw funds from the accounts or groups you have access to. For the incentives, you can only use ETIDs you have access to. See how to set user access level in Set user permissions and access level.

Reports permissions

Allows users to access reports:
 

PermissionRight of use
Order Reports
  • Don't Allow: Restricts users from accessing reports.
  • View: Lets users see and download previously generated reports at their access level.
  • Manage: Lets users generate and download reports at their access level.
 
Notes:
  • A user's Access Level determines whether or not they can use specific features regardless of their assigned permissions.
  • Users are only able to see and interact with features at their respective Access Level. See how you can Set user permissions and access level.
  • Only users with Organization Access are able to interact with Organization Structure and Integrations.

More resources:
 
TitleDefault user roles in Tango portal
URL NameRoleDefinitions

Powered by