Merchant account access
How Do I Add an Authorized Contact to a Merchant Account?
Use the payment provider's official dashboard or verified support channel. Give the person an individual profile, grant only the access needed for their role, and confirm that the invitation and permissions work as intended.
Start with the role
Define what the contact needs to do
Providers use different terms, including team member, secondary user, administrator, and authorized representative. These roles are not automatically equivalent. Decide whether the person needs dashboard access, permission to contact support, access to one location, reporting access, or another specific capability.
Support contact
May be allowed to discuss account matters with provider support. Confirm exactly which information the provider can disclose.
Operations user
May need transaction, refund, customer, catalog, or device functions. Select only the tools required for assigned work.
Reporting user
May need statements, exports, or reconciliation data without permission to change account or payment settings.
Access administrator
Can manage users or roles on some platforms. Reserve this power for people responsible for account security.
Secure setup
Add the contact through an authorized workflow
1. Sign in directly
Open the provider's official dashboard or app using your own account. Do not use an unexpected email link or share the account owner's password.
2. Create an individual profile
Enter the person's current business contact information in the provider's user, team, or authorized-contact area. Each person should have a distinct login or profile when the platform supports it.
3. Assign the narrowest role
Choose the minimum permissions and only the accounts or locations needed. Review sensitive powers such as refunds, bank changes, user management, exports, and API-key access separately.
4. Send and confirm the invitation
Have the contact accept the provider-generated invitation, set up their own authentication, and verify access without exchanging passwords or one-time codes.
Permission review
Check high-impact access before approval
Money movement
Confirm whether the role can issue refunds, send payments, change payout settings, or view balances.
Account changes
Review access to business details, bank information, owners, locations, and other users.
Sensitive data
Limit exports, customer data, reports, developer credentials, and security settings to legitimate duties.
Support authority
Verify whether the user can discuss account-specific information or request changes through support.
Document who approved the role, the business reason, the assigned locations or accounts, and the date access should be reviewed.
Verify and maintain
Confirm access and keep the roster current
After the invitation
- Confirm the invitation went to the intended person
- Require the provider's available multi-factor authentication
- Test only the tasks the role should perform
- Confirm unrelated accounts and locations are unavailable
- Save an internal approval record without storing passwords
Ongoing review
- Review active users and permissions regularly
- Update access when responsibilities change
- Remove access promptly when it is no longer needed
- Investigate unexpected invitations or role changes
- Use provider audit or security history when available
Common questions
Authorized contact FAQ
Should I share the owner's login?
No. Use a separate user or contact profile when the provider supports it so permissions, authentication, and activity remain attributable.
Is an authorized contact the same as an administrator?
Not necessarily. Provider labels and capabilities differ. Review the exact permissions shown by the platform before assigning a role.
Who can add the contact?
The account owner or a user with the provider's required user-management permission generally must create or approve the profile.
What if there is no user-management option?
Use the provider's verified support channel and request its current process. Do not send passwords, full account numbers, or secret keys through a general form.
Last editorial review: August 12, 2026. Reviewed against current official Square, Stripe, and PayPal documentation for authorized representatives, team roles, invitations, and permissions.
Next step
Write down the required tasks before assigning access
Choose the provider role that grants only those tasks, send an individual invitation, and verify the resulting permissions.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US