Skip to Main Content
Categories Control Center
Created by Guest
Created on May 4, 2026

Per customer Contol Center Access

How: Manage control center access to specific environment/customer. When access is requested, one should have to specify which customer(s) it is for.

Why: To ensure no unintended access to other clients' Control Center is granted.

For Who: For partners to be able grant portal access to third parties (translation agencies, web partners, etc) without compromising the security of the setup.

Impact: Possibly massive implications if the wrong person can access a Control Center they should not. Data loss, compromised user right (for other users too), leaked configs (including possible secrets), theft of extension source code among other things.

Additional context: Warning as in this article https://community.inriver.com/hc/en-us/articles/12757566323612-Requesting-Control-Center-Access. An issue with the warning is that the third party themself or another partner/customer would have gone that route, while the partner in question (me) might just have created a account with read-level access a long time ago. The partner in question also has no way of knowing beforehand when creating a third party account that it might have control center access.

  • Attach files