Merchant account access

How Do I Add an Authorized Contact to a Merchant Account?

Use the payment provider's official dashboard or verified support channel. Give the person an individual profile, grant only the access needed for their role, and confirm that the invitation and permissions work as intended.

Start with the role

Define what the contact needs to do

Providers use different terms, including team member, secondary user, administrator, and authorized representative. These roles are not automatically equivalent. Decide whether the person needs dashboard access, permission to contact support, access to one location, reporting access, or another specific capability.

Support contact

May be allowed to discuss account matters with provider support. Confirm exactly which information the provider can disclose.

Operations user

May need transaction, refund, customer, catalog, or device functions. Select only the tools required for assigned work.

Reporting user

May need statements, exports, or reconciliation data without permission to change account or payment settings.

Access administrator

Can manage users or roles on some platforms. Reserve this power for people responsible for account security.

Secure setup

Add the contact through an authorized workflow

1. Sign in directly

Open the provider's official dashboard or app using your own account. Do not use an unexpected email link or share the account owner's password.

2. Create an individual profile

Enter the person's current business contact information in the provider's user, team, or authorized-contact area. Each person should have a distinct login or profile when the platform supports it.

3. Assign the narrowest role

Choose the minimum permissions and only the accounts or locations needed. Review sensitive powers such as refunds, bank changes, user management, exports, and API-key access separately.

4. Send and confirm the invitation

Have the contact accept the provider-generated invitation, set up their own authentication, and verify access without exchanging passwords or one-time codes.

Provider roles vary: a label such as administrator or authorized representative can carry different authority on different platforms. Read the provider's current permission description before saving.

Permission review

Check high-impact access before approval

Money movement

Confirm whether the role can issue refunds, send payments, change payout settings, or view balances.

Account changes

Review access to business details, bank information, owners, locations, and other users.

Sensitive data

Limit exports, customer data, reports, developer credentials, and security settings to legitimate duties.

Support authority

Verify whether the user can discuss account-specific information or request changes through support.

Document who approved the role, the business reason, the assigned locations or accounts, and the date access should be reviewed.

Verify and maintain

Confirm access and keep the roster current

After the invitation

  • Confirm the invitation went to the intended person
  • Require the provider's available multi-factor authentication
  • Test only the tasks the role should perform
  • Confirm unrelated accounts and locations are unavailable
  • Save an internal approval record without storing passwords

Ongoing review

  • Review active users and permissions regularly
  • Update access when responsibilities change
  • Remove access promptly when it is no longer needed
  • Investigate unexpected invitations or role changes
  • Use provider audit or security history when available

Common questions

Authorized contact FAQ

Should I share the owner's login?

No. Use a separate user or contact profile when the provider supports it so permissions, authentication, and activity remain attributable.

Is an authorized contact the same as an administrator?

Not necessarily. Provider labels and capabilities differ. Review the exact permissions shown by the platform before assigning a role.

Who can add the contact?

The account owner or a user with the provider's required user-management permission generally must create or approve the profile.

What if there is no user-management option?

Use the provider's verified support channel and request its current process. Do not send passwords, full account numbers, or secret keys through a general form.

Last editorial review: August 12, 2026. Reviewed against current official Square, Stripe, and PayPal documentation for authorized representatives, team roles, invitations, and permissions.

Next step

Write down the required tasks before assigning access

Choose the provider role that grants only those tasks, send an individual invitation, and verify the resulting permissions.

Contact Payments Max

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US