A third party in Branch is an outside organization that a Branch customer grants access to one or more of its apps. Agencies, ad networks, consultants, and analytics providers are all third parties.
Third parties work from their own Branch account. They don’t join your team. You choose which of your apps a third party can reach and what it can do in each one, and you can end that access at any time.
This article explains what third parties are and how access works. For step-by-step instructions, see the guides linked at the end.
Note
Branch previously called third parties agencies. We rebuilt the feature with clearer per-app controls and broadened it to cover more kinds of organization.
What counts as a third party
A third party is any organization outside your company that works in your Branch app on your behalf. When a third party creates its Branch account, it identifies itself as one of six types. Typical examples:
- Agency: manages campaigns, links, and attribution setup for you
- Ad network/platform partner: verifies integrations and troubleshoots attribution
- Developer/integration partner: implements or maintains your Branch SDK and technical setup
- Measurement & analytics partner: validates data and runs analysis
- Contractor/consultant: does hands-on work under a short-term engagement
- Other: any organization that doesn’t fit the categories above
The third party chooses its own type, and the type is only a label. It doesn’t change what the third party can see or do in Branch.
Choose between a third party and a team member
Add someone as a team member when they work for your company. You add team members on Configuration > Security & Access > Team.
Connect a third party when the person works for another company that acts on your behalf. Their organization gets its own Branch account, and its own admins decide which of their people work in your app.
For an outside organization, connect a third party rather than adding people as team members. A third party gets only the permissions you grant, only in the apps you choose, and you can disable the whole organization’s access to an app in one step. Adding someone from an outside organization as a team member instead gives that person access intended for your own staff.
How third-party access works
Third-party access generally follows these stages:
- You connect a third-party organization to one of your apps and set what it can do there. Search for the organization first, and invite it if it isn’t in Branch yet.
- If the organization is new to Branch, the person you invite creates its Branch account and becomes its first admin. If the organization already has an account, your app is added to that account.
- The third party’s admins add their own teammates and assign them to your app.
- Everyone the admins assign works in your app with the permissions you granted the organization.
- You change those permissions or disable the organization’s access whenever you need to.
You can connect several third parties to the same app. Each one has its own access level, permissions, and data restrictions.
Who controls what
Control is split between you and the third party.
You control which of your apps the third-party organization can reach, what it can do in each app, which data it can see, and whether its access stays on.
The third party controls which of its own employees get access to the apps you’ve granted it, and it adds and removes those people without involving you.
This is why you grant access to an organization rather than to named individuals. Third parties often have large teams (20 or more people is not unusual) so managing every individual would create work for you, and it mirrors how third parties already assign their own people to clients. If you need to cut off one person, ask the third party to remove them. If you need to cut off everyone, disable the organization’s access.
What a third party can and can’t see
A third party sees only what you grant it:
- Only the apps you connect it to. You grant access per app. A third party that works with several Branch customers sees only the specific apps each customer has granted, and nothing about the others.
- Only the features you permit. You choose a starting access level, then adjust individual permissions across campaign execution, audiences, app configuration, reporting, and exports.
- Only the data you allow. You can further limit a third party to data tagged to it, to selected ad networks, or to selected countries.
- Never your billing details. Sensitive account information such as billing isn’t visible to third parties, regardless of the permissions you grant, and those pages are blocked even by direct URL.
For the full permission list and how to set it, see Manage Third Party Access.
Email and account requirements
Third-party users sign in with a business email address. Public email domains such as Gmail and Yahoo aren’t supported.
Branch allows one third-party account per email domain, so an organization has a single account rather than a duplicate for each person. An email address can belong to only one Branch account.
Frequently asked questions
What’s the difference between a third party and an agency?
They’re closely related but not identical. Branch used to call every organization with this kind of access an agency. Today, third party is the umbrella term and Agency is one of six types a third party can select. Ad networks, developers, consultants, and analytics providers use the same access model without being marketing agencies.
Can I control which individual people at a third party have access?
Not from your side. You grant access to the third-party organization, and that organization’s admins decide which of their employees get it. To remove one person, ask the third party to remove them. To remove everyone, disable the third party’s access.
Does a third party need a Branch account of its own?
Yes. Third parties work from their own Branch account, separate from yours. If the organization is new to Branch, the person you invite creates that account and becomes its first admin. If the organization already has a Branch account, your app is added to it.
Can one third party work with several Branch customers?
Yes. From one login, a third party reaches every app its clients have granted. Admins at the third party see all of those apps, and other users see only the apps their admin assigns them.
Next steps
- To connect and manage a third party in your app, see Manage Third Party Access.
- To set up a new third-party account after being invited, see Create Your Third Party Account.
- To work in client apps and manage your own team, see Work with Client Apps in Your Third Party Account.
