WiseStamp for IT › Microsoft 365 › Step 8 of 12 — Permissions Reference
Part 1 — Microsoft permissions WiseStamp requests
WiseStamp requests narrowly scoped permissions, each tied to a specific capability. WiseStamp states it does not read or store email content.
Permission | Where granted | What it allows | Why WiseStamp needs it |
ReadWriteItem | Outlook Add-In | Read and write the current email/calendar item: read details, modify content, add/remove attachments, save changes | To insert the signature at the end of the email being composed. WiseStamp states it does not read or save email content. |
User.Read.All | Microsoft Entra ID directory integration | Read profile information for all users: names, email addresses, job titles, roles, departments; list all users | To import employees, synchronize employee details, automate add/remove based on directory status, and support signature deployment. |
GroupMember.Read.All | Security Group sync (Enterprise) | Read the membership of groups | To read the designated Security Group’s membership and scope managed employees to that group. |
Notes for security reviewers
ReadWriteItem is the standard Outlook add-in permission scope. It technically permits reading message content; WiseStamp’s stated policy is that it uses this only to append the signature and does not read or store content. WiseStamp references its Security and Compliance material for detail.
User.Read.All is directory-wide read. If you need to limit which users are actually imported, use selective sync (by department/OU) or Security Group sync rather than reducing the granted scope — the permission scope itself is directory-wide.
WiseStamp’s stated compliance posture includes SOC 2 Type II, ISO 27001, GDPR, and HIPAA, with TLS in-transit encryption. (See the Data Security material in the knowledge base.)
Part 2 — WiseStamp account roles
WiseStamp roles control what your own team members can do inside the WiseStamp app. Each account user has exactly one role. Roles & permissions management is a Platform/Enterprise capability (admin seat caps vary by plan — see Office 365 IT Admin Guide).
Administrative roles
Role | Description | Permissions summary |
Account Owner | Chief account manager. An account has exactly one owner. | Unlimited access. |
Admin | Assists the Owner with all aspects of account management. | Access to all components, but cannot perform billing operations. |
Organization Manager | Responsible for organization maintenance. | Access to all components except account details. Can be scoped to all organizations or specific organizations. |
Specialist roles
More limited roles intended for specialists with specific functions in the account:
Role | Description | Permissions summary |
Marketer | Advertising / promotions management. | Access to Campaigns, Analytics, and all aspects of signature design. |
HR | Employee management. | Access to employee details, group management, and signature assignments. |
Designer | Signature creation, composition, and layout. | Access to signature editing functions, company data, and employee data. |
IT | Management of employees and company organizations. | Access to all employee and organization management operations. |
Scope assignment
For all roles except Admin, when assigning the role you choose whether the user has access to all organizations or specific organizations. Users with an Admin role are automatically assigned to all company organizations.
Assigning a role
From the employee list: Employees > [three-dot icon on the row] > Assign role, then set scope and Save (an invitation email is sent). From the account user list: Profile icon > Account users > Add user, enter name/email, select role, set scope, Save.
Modifying or removing a role
Modify: Profile > Account users > hover the row > Edit > change role > Save.
Transfer ownership: Profile > Account users > open the target user > Edit > set role to Account Owner > Save.
Remove: from Employees (Remove [role] permissions) or from Account users (Delete).
Admins do not consume seats
You can designate admins to manage the account without them occupying an active employee seat. Seats are consumed by Active employees (people receiving signatures), not by admin roles. See Ongoing Admin Guide.
Part 3 — Sign-in methods (admin access)
Admins can sign into WiseStamp via:
Email address + password
Continue with Google
Continue with Facebook
SSO (SAML 2.0) — Platform/Enterprise; see SSO with Entra ID (SAML)
Employees do not sign into the main WiseStamp account. They receive signatures automatically and use the Employee Hub.