📢 AnnouncementXponent JOBill ExplainerPayment ReminderCommunications Control, and Batch Communications Engine August 2026 (26.2) Release Notes are now available.

BCE User Roles and Permissions

Prev Next

Batch Communications Engine (BCE) uses a role-based security model to control access to application features and operational functions. Security roles define the actions users can perform and the information they can access within BCE.

The BCE role model provides clear separation of responsibilities across communication design, administration, execution, and viewing activities, enabling secure and efficient management of batch communications.
The BCE role model comprises of:

  • Admin

  • Configurer

  • Importer

  • Exporter

  • Viewer

By default, any new user is provisioned as a Viewer. Changes to a user’s role assignments must be requested through the Channel Operations team or the BCE development team; end users cannot self-manage roles.

Cumulative Role Privileges

BCE role permissions are cumulative. If a user is assigned more than one role, their effective permissions are the union of all privileges granted by each assigned role. For example, a user with both Importer and Exporter roles will be able to perform both profile import and export actions in addition to their baseline Viewer access.

Role Definitions

Admin

  • Full administrative access across the BCE application.

  • Authorized to perform all configuration, operational, and data actions without restriction.

  • Only users with Admin access can edit individual profile records.

Configurer

  • Authorized to edit and delete the following configuration objects:

    • Campaigns

    • Segments

    • Subscriptions

  • Not permitted to edit profile records.

Importer

  • Authorized to import profile data into BCE (for example, via supported profile import workflows).

  • Intended for operational users responsible for loading or refreshing customer data.

Exporter

  • Authorized to export profile data from BCE.

  • Intended for tightly controlled scenarios where profile data extraction is required (e.g., analytics, external processing).

Viewer

  • Read-only role.

  • May log in and view campaigns, segments, subscriptions, and profiles, but cannot create, edit, delete, import, or export any BCE data.

This expanded role model strengthens security, supports the principle of least privilege, and provides clearer separation of duties across administrative, operational, and analytical functions within BCE.

The User Profile Card displays all roles assigned to the logged-in user. Depending on the user's permissions, the card can show one or multiple role badges, providing a quick view of the user's access levels within the application.

For example, a user assigned both Administrator and Configurer roles will see both role labels displayed on the profile card.