Skip to main content

Exchange Server Email Signature Permissions and Roles

Microsoft permissions WiseStamp requests on Exchange, the mail-flow trust created by server-side routing, and the WiseStamp roles you give your own team.

WiseStamp for IT › Exchange › Step 8 of 12 — Permissions Reference



Part 1 — Microsoft permissions WiseStamp requests

Permission

Where granted

What it allows

Why needed

ReadWriteItem

Outlook Add-In

Read/write the current item; insert/modify content; save

Insert the signature into the composed message. WiseStamp states it does not read or store email content.

User.Read.All

Entra ID directory integration

Read all users' profiles (name, email, title, dept); list users

Import employees, sync details, automate add/remove, support deployment.

GroupMember.Read.All

Security Group sync (Enterprise)

Read group membership

Scope managed employees to a named Security Group.

Server-side mail-flow trust

Server-side routing does not use a Graph permission; it establishes mail-flow trust via Exchange connectors (off-prem/hybrid): an outbound connector to *.ms.smtp.wisestamp.net and an inbound connector authenticating outbound.smtp.wisestamp.net. WiseStamp states it does not read, store, or change email content or recipients while in the mail path.

Pure on-premises routing is not supported. Employee sync is not supported for on-premises environments and no plan covers it, so there is no equivalent on-premises mail-flow trust to document. For the IP ranges used by Exchange Online and hybrid routing, see Prerequisites Checklist.

For security reviewers

  • User.Read.All is directory-wide read; narrow the managed set via selective sync / Security Group rather than expecting a reduced scope.

  • WiseStamp’s stated posture includes SOC 2 Type II, ISO 27001, GDPR, HIPAA, with TLS in transit. A SMTP penetration test and SOC 2 certificate are referenced in the Trust Center.


Part 2 — WiseStamp account roles

Roles & permissions management is a Platform/Enterprise capability. Each account user has exactly one role.

Role

Description

Permissions summary

Account Owner

Chief account manager; exactly one per account.

Unlimited access.

Admin

Assists the Owner with account management.

All components, except billing operations.

Organization Manager

Organization maintenance.

All components except account details; scoped to all or specific organizations.

Specialist roles

More limited roles intended for specialists with specific functions in the account:

Role

Description

Permissions summary

Marketer

Advertising / promotions management.

Access to Campaigns, Analytics, and all aspects of signature design.

HR

Employee management.

Access to employee details, group management, and signature assignments.

Designer

Signature creation, composition, and layout.

Access to signature editing functions, company data, and employee data.

IT

Management of employees and company organizations.

Access to all employee and organization management operations.

Scope assignment

For all roles except Admin, you choose whether the user has access to all organizations or specific organizations when assigning the role. Users with an Admin role are automatically assigned to all company organizations.

Managing roles

  • Assign: Employees > [three-dot] > Assign role (set scope, Save); or Profile > Account users > Add user.

  • Modify / transfer ownership: Profile > Account users > Edit role (set to Account Owner to transfer).

  • Remove: from Employees or Account users.

  • Admins don’t consume seats — seats are used by Active employees only.


Part 3 — Sign-in methods (admin access)

Email + password, Continue with Google, Continue with Facebook, or SSO (SAML 2.0) (Platform/Enterprise; SSO (SAML)). Employees do not sign into the main account; they use the Employee Hub.

Related articles


Did this answer your question?