Skip to main content

Office 365 Email Signature Permissions: Graph Scopes and Roles

Every permission in a WiseStamp + Office 365 deployment: Microsoft Graph scopes (ReadWriteItem, User.Read.All), WiseStamp roles and admin sign-in methods.

WiseStamp for IT › Microsoft 365 › Step 8 of 12 — Permissions Reference



Part 1 — Microsoft permissions WiseStamp requests

WiseStamp requests narrowly scoped permissions, each tied to a specific capability. WiseStamp states it does not read or store email content.

Permission

Where granted

What it allows

Why WiseStamp needs it

ReadWriteItem

Outlook Add-In

Read and write the current email/calendar item: read details, modify content, add/remove attachments, save changes

To insert the signature at the end of the email being composed. WiseStamp states it does not read or save email content.

User.Read.All

Microsoft Entra ID directory integration

Read profile information for all users: names, email addresses, job titles, roles, departments; list all users

To import employees, synchronize employee details, automate add/remove based on directory status, and support signature deployment.

GroupMember.Read.All

Security Group sync (Enterprise)

Read the membership of groups

To read the designated Security Group’s membership and scope managed employees to that group.

Notes for security reviewers

  • ReadWriteItem is the standard Outlook add-in permission scope. It technically permits reading message content; WiseStamp’s stated policy is that it uses this only to append the signature and does not read or store content. WiseStamp references its Security and Compliance material for detail.

  • User.Read.All is directory-wide read. If you need to limit which users are actually imported, use selective sync (by department/OU) or Security Group sync rather than reducing the granted scope — the permission scope itself is directory-wide.

  • WiseStamp’s stated compliance posture includes SOC 2 Type II, ISO 27001, GDPR, and HIPAA, with TLS in-transit encryption. (See the Data Security material in the knowledge base.)


Part 2 — WiseStamp account roles

WiseStamp roles control what your own team members can do inside the WiseStamp app. Each account user has exactly one role. Roles & permissions management is a Platform/Enterprise capability (admin seat caps vary by plan — see Office 365 IT Admin Guide).

Administrative roles

Role

Description

Permissions summary

Account Owner

Chief account manager. An account has exactly one owner.

Unlimited access.

Admin

Assists the Owner with all aspects of account management.

Access to all components, but cannot perform billing operations.

Organization Manager

Responsible for organization maintenance.

Access to all components except account details. Can be scoped to all organizations or specific organizations.

Specialist roles

More limited roles intended for specialists with specific functions in the account:

Role

Description

Permissions summary

Marketer

Advertising / promotions management.

Access to Campaigns, Analytics, and all aspects of signature design.

HR

Employee management.

Access to employee details, group management, and signature assignments.

Designer

Signature creation, composition, and layout.

Access to signature editing functions, company data, and employee data.

IT

Management of employees and company organizations.

Access to all employee and organization management operations.

Scope assignment

For all roles except Admin, when assigning the role you choose whether the user has access to all organizations or specific organizations. Users with an Admin role are automatically assigned to all company organizations.

Assigning a role

From the employee list: Employees > [three-dot icon on the row] > Assign role, then set scope and Save (an invitation email is sent). From the account user list: Profile icon > Account users > Add user, enter name/email, select role, set scope, Save.

Modifying or removing a role

  • Modify: Profile > Account users > hover the row > Edit > change role > Save.

  • Transfer ownership: Profile > Account users > open the target user > Edit > set role to Account Owner > Save.

  • Remove: from Employees (Remove [role] permissions) or from Account users (Delete).

Admins do not consume seats

You can designate admins to manage the account without them occupying an active employee seat. Seats are consumed by Active employees (people receiving signatures), not by admin roles. See Ongoing Admin Guide.


Part 3 — Sign-in methods (admin access)

Admins can sign into WiseStamp via:

  • Email address + password

  • Continue with Google

  • Continue with Facebook

  • SSO (SAML 2.0) — Platform/Enterprise; see SSO with Entra ID (SAML)

Employees do not sign into the main WiseStamp account. They receive signatures automatically and use the Employee Hub.

Related articles


Did this answer your question?