Third-party partners often manage campaigns, links, and reporting on your behalf. In Branch, these partners work from their own third-party account, and you control which of your apps they can reach and what they can do in each one.
This guide covers how to connect a third party to your app, set its access level and permissions, restrict the data it can see, and disable its access when a partnership ends.
For what third parties are and how access works, see Third Party Overview.
Note
Third parties were previously called agencies. If you’ve used agency access in Branch before, this is the same idea, rebuilt.
About third-party access
Here’s how third-party access works end to end:
- You invite a third-party organization to your app, not an individual person.
- The person you invite creates the third party’s Branch account and becomes its first admin.
- That admin adds their own teammates and assigns them to your app.
- Everyone they assign gets the permissions you granted the organization.
- You can change those permissions or disable access at any time.
Two details matter throughout:
- Access is per app: Connecting a third party to one app gives it nothing in your other apps. To give the same third party access to a second app, repeat these steps from that app.
- A third party can only see what you grant: A partner that works with several Branch customers can reach only the apps it’s been granted.
Remove access for one person
You grant access to a third-party organization, not to individual people, so you can’t remove one person’s access from your side. Everyone the third party assigns to your app gets the permissions you granted the organization.
- To cut off one person, ask your contact at the third party to remove them or unassign them from your app.
- To cut off the whole organization, disable its access. See Disable a third party’s access.
Before you begin
To connect a third party to your app, you first need to:
- Get admin access to the app in Branch.
- Find the third party’s name, or the business email of the person you work with there. Public email domains such as Gmail and Yahoo aren’t supported.
Connect a third party to your app
- Go to Configuration > Security & Access in Branch.
- Select the Third Party tab.
- Select Connect a third party.
- Search by third-party name or email. For privacy, Branch doesn’t list every third party, so you have to search.
- Select Manage on the organization you want, or select Invite new third party if it isn’t listed.
- Enter the Third Party Name and Third party representative email if you’re inviting a new third party.
- Select an Access level, then adjust individual permissions and data restrictions.
- Confirm the invitation.
Branch emails the invitation from “Branch Alerts.” The third party appears in the Third Party list with the date invited and who invited it. Once the person you invited creates their account, the status shows Active.
Your contact receives instructions for creating their account. If they have questions about setup, point them to Create Your Third Party Account.
Note
The person you invite becomes the first admin of the third party’s Branch account. They then add their own teammates and assign them to your app, so choose a contact who can manage that.
Set the access level and permissions
You set access when you first connect a third party, and you can change it at any time afterward.
- Go to Configuration > Security & Access > Third Party in Branch.
- Select the ⋮ menu for the third party, then select Manage permissions.
- Select an Access level.
- Adjust individual permissions.
- Select Save permissions.
The access level sets a starting point that you can fine-tune below it.
| Access level | What it means |
|---|---|
| Full access | This third party has full access to the app, including settings, integrations, and user access. |
| Limited access | This third party can view and edit selected features based on assigned permissions. |
| View only | This third party can view data and settings but cannot make changes. |
| Custom | Customize access for this third party by selecting specific permissions. |
Each feature has up to two checkboxes.
| Selected | What the third party can do |
|---|---|
| Edit | Everything in the feature, including creating and managing |
| View | Read-only |
| Neither | Nothing — the feature is hidden from them |
Reporting permissions are view-only. Exporting has a single Allow exports option. Select Grant full access on a category to turn on everything in it at once.
Caution
Some permissions may already be turned on when you open this page. Review every category before saving rather than assuming a category is off.
| Category | Permission | What it controls |
|---|---|---|
| Campaign execution | Links | Create and manage short links for this app. |
| Campaign execution | Link templates | Create and manage saved link templates for consistent link creation. |
| Campaign execution | Channels & ad partners | Configure ad partners and postbacks. |
| Audience & engagement | Engagement audiences | Create, manage, and export audience groups. |
| Audience & engagement | Mobile Discovery | Access and manage Mobile Discovery settings and data. |
| App configuration | App settings | View or modify app-level configuration. |
| App configuration | Fraud rules | Create and manage fraud detection rules. |
| Reporting & insights | Summary reporting | Access high-level performance reporting. |
| Reporting & insights | Fraud reporting | Access fraud-related reporting. |
| Reporting & insights | Revenue data | Access revenue metrics and reporting. |
| Reporting & insights | Sensitive data | Access user identifiers and other sensitive fields. |
| Exporting | Export data | Allow exporting data from reports and pages the third party can view. |
Features a third party doesn’t have permission for don’t appear in its navigation, and it can’t reach them by URL either.
Tip
Grant the minimum access the third party needs. You can expand permissions later as its responsibilities grow.
Restrict the data a third party can see
The Data restrictions section of Manage permissions limits what a third party sees, separately from its feature permissions. Select Limit to choose what it can see, or Show all to remove the restriction.
| Restriction | What it does |
|---|---|
| Only show data relevant to this third party | The third party sees only events tagged to it. |
| Limit to selected ad networks | The third party sees only data from the ad networks you select. |
| Limit to selected countries | The third party sees only data from the countries you select. |
Assets a third party creates in your app, such as Branch Links, are tagged to it. That tagging drives the first restriction.
Caution
“Only show data relevant to this third party” hides everything the third party isn’t tagged on, including links and campaigns your own team created. Use it when the third party works only with its own assets.
Disable a third party’s access
Disable a third party when a partnership ends or you need to cut off access quickly:
- Go to Configuration > Security & Access > Third Party in Branch.
- Select the ⋮ menu for the third party.
- Select Disable access.
Access ends immediately for everyone at that third party. Disabling doesn’t delete anything: links, audiences, and other assets the third party created stay in place and keep working, and data already tracked is unaffected. Because access is scoped per app, disabling here doesn’t affect any other app the third party works on, including your own other apps.
Follow security best practices
- Grant the minimum access a third party needs, and review connected third parties periodically.
- Disable access as soon as a partnership ends.
- Remember that third-party users sign in with a business email address. Public email domains such as Gmail and Yahoo aren’t supported.
- Sensitive account information, such as your billing details, isn’t visible to third parties.
For anything you can’t resolve from the Third Party tab, contact support@branch.io.
