WiseStamp for IT › Exchange › Step 8 of 12 — Permissions Reference
Part 1 — Microsoft permissions WiseStamp requests
Permission | Where granted | What it allows | Why needed |
ReadWriteItem | Outlook Add-In | Read/write the current item; insert/modify content; save | Insert the signature into the composed message. WiseStamp states it does not read or store email content. |
User.Read.All | Entra ID directory integration | Read all users' profiles (name, email, title, dept); list users | Import employees, sync details, automate add/remove, support deployment. |
GroupMember.Read.All | Security Group sync (Enterprise) | Read group membership | Scope managed employees to a named Security Group. |
Server-side mail-flow trust
Server-side routing does not use a Graph permission; it establishes mail-flow trust via Exchange connectors (off-prem/hybrid): an outbound connector to *.ms.smtp.wisestamp.net and an inbound connector authenticating outbound.smtp.wisestamp.net. WiseStamp states it does not read, store, or change email content or recipients while in the mail path.
Pure on-premises routing is not supported. Employee sync is not supported for on-premises environments and no plan covers it, so there is no equivalent on-premises mail-flow trust to document. For the IP ranges used by Exchange Online and hybrid routing, see Prerequisites Checklist.
For security reviewers
User.Read.All is directory-wide read; narrow the managed set via selective sync / Security Group rather than expecting a reduced scope.
WiseStamp’s stated posture includes SOC 2 Type II, ISO 27001, GDPR, HIPAA, with TLS in transit. A SMTP penetration test and SOC 2 certificate are referenced in the Trust Center.
Part 2 — WiseStamp account roles
Roles & permissions management is a Platform/Enterprise capability. Each account user has exactly one role.
Role | Description | Permissions summary |
Account Owner | Chief account manager; exactly one per account. | Unlimited access. |
Admin | Assists the Owner with account management. | All components, except billing operations. |
Organization Manager | Organization maintenance. | All components except account details; scoped to all or specific organizations. |
Specialist roles
More limited roles intended for specialists with specific functions in the account:
Role | Description | Permissions summary |
Marketer | Advertising / promotions management. | Access to Campaigns, Analytics, and all aspects of signature design. |
HR | Employee management. | Access to employee details, group management, and signature assignments. |
Designer | Signature creation, composition, and layout. | Access to signature editing functions, company data, and employee data. |
IT | Management of employees and company organizations. | Access to all employee and organization management operations. |
Scope assignment
For all roles except Admin, you choose whether the user has access to all organizations or specific organizations when assigning the role. Users with an Admin role are automatically assigned to all company organizations.
Managing roles
Assign: Employees > [three-dot] > Assign role (set scope, Save); or Profile > Account users > Add user.
Modify / transfer ownership: Profile > Account users > Edit role (set to Account Owner to transfer).
Remove: from Employees or Account users.
Admins don’t consume seats — seats are used by Active employees only.
Part 3 — Sign-in methods (admin access)
Email + password, Continue with Google, Continue with Facebook, or SSO (SAML 2.0) (Platform/Enterprise; SSO (SAML)). Employees do not sign into the main account; they use the Employee Hub.