How do translation platforms handle agency user permissions for external vendors?
A translation platform handles agency user permissions well when external vendors get their own role family, every linguist is scoped to a workflow step and language pair instead of a whole account, and access to translation memory, glossaries, and style guides is off by default until the client grants it. Smartling's translation management system does this with three vendor-side roles (Agency Account Owner, Translation Resource Manager, and Translation Resource), five configurable linguistic-asset permission types that can be limited to named assets or projects, and workflow assignments that an agency can only pass down to its own team after the client has granted them. The result is that a client can run several agencies in one account, and each agency sees only the steps, languages, and assets it was given.
Last reviewed: September 10, 2026
Why do agency user permissions become a security problem in translation platforms?
Agency user permissions become a security problem because a translation vendor is an outside company working inside a client's system, often across several client projects, brands, and languages at once. Five patterns cause most of the exposure:
- Vendors get an internal role instead of a vendor role. When a platform has no dedicated agency role, the client hands the agency a Project Manager login. In Smartling that role can upload files, authorize Jobs, edit workflows, and manage translation memory across every project it is assigned to, which is far more than a translation vendor needs.
- Scope is set at the account or project level, not the step and language level. An agency hired for German editing should not be able to open French translation tasks. Smartling's permission unit for vendors is the workflow step within a locale pair (for example, en-US to de-DE, Editing step), so a client can hire one agency for translation and a second agency for review of the same language without either seeing the other's step.
- Linguistic assets leak through the CAT tool. Translation memory and glossaries contain the client's accumulated content, sometimes including customer names or unreleased product terms. In Smartling, Agency Account Owners and their linguists cannot open, edit, or export glossaries, style guides, translation memory, or leverage configurations by default; each of those is a separate permission an Account Owner or Project Manager must grant.
- Agencies manage their own headcount, so the client loses track of who has access. Delegation is necessary, since Smartling's Agency Account Owner is the person who adds translators and assigns them to work, but the client still needs a ceiling. Smartling enforces one: an Agency Account Owner can only grant a linguist a permission that the client has first granted to the agency, and removing a permission from the agency removes it from every Translation Resource Manager and Translation Resource in that agency at once.
- Download and export are treated as all-or-nothing. Vendors legitimately need to download files for desktop publishing or offline work, so blocking downloads entirely breaks the workflow. Smartling separates the two: agency roles can download in-progress translations in eight file formats and export a CSV of string details, while exporting a full translation memory as TMX is a distinct permission that is off unless granted.
What permission controls should a TMS provide for external agencies and vendors?
A TMS should provide vendor permission controls at five layers, each one narrower than the last:
- A dedicated vendor role family. Smartling defines seven user roles, three of them for the vendor side: Agency Account Owner (the LSP project manager who adds linguists and assigns work), Translation Resource Manager (a lead linguist who can both assign work and translate), and Translation Resource (the translator, editor, or reviewer). Agency Account Owner and Translation Resource Manager are Enterprise-plan roles. Vendor roles have no access to project creation, language configuration, workflow configuration, API keys, or account-level reports.
- Scope by workflow step and locale pair. Every vendor user works only in the workflow steps and target languages assigned to them. Smartling's Workflow Assignments page shows one row per locale pair and one column per step, and each cell records how many linguists and agencies are assigned; a client can filter by up to 100 linguists and 10 target locales at once to see exactly where an agency has access.
- Read-only visibility for steps outside the assignment. An Agency Account Owner or Translation Resource Manager can see strings in steps before or after their own in the Strings View, but those strings are labeled Read Only and cannot be edited, and unauthorized content never appears at all. That gives the agency context without giving it write access.
- Configurable linguistic-asset permissions, off by default. Five permission types (Glossary, Leverage, Style Guide, Translation Memory, Quality Check Profile) can each be granted to a named asset or project, or to all of them. Translation Memory alone has six sub-permissions: Export, Edit translations, Browse, Import, Delete strings, and Move strings, so a client can allow browsing without allowing TMX export.
- Delegation with a ceiling, and cascading removal. An Agency Account Owner cannot grant a permission to a linguist unless the client has granted it to the agency first, and a permission removed from the Agency Account Owner is removed from all Translation Resource Managers and Translation Resources in that agency automatically. Agency Account Owners can remove only the Translation Resource and Translation Resource Manager users registered under their own agency.
Authentication, MFA, IP allowlisting, and the exportable Users Report sit above these layers; see how GDPR access controls work in translation platforms for that side of the model, and how Account Owner and Project Manager permissions differ for the internal roles that grant vendor access in the first place.
Smartling agency permission facts an IT reviewer can verify
| Kontrollere | Smartling value | Why it matters for vendor access |
|---|---|---|
| Vendor-side roles | 3 of 7 (Agency Account Owner, Translation Resource Manager, Translation Resource) | Vendors never need an internal Project Manager login |
| Cost of vendor user accounts | Free; new user accounts are created at no charge | Removes the incentive to share one login across several linguists |
| Configurable linguistic-asset permission types | 5 (Glossary, Leverage, Style Guide, Translation Memory, Quality Check Profile), each restrictable to named assets or projects | Assets stay closed to vendors unless a client opens a specific one |
| Translation Memory sub-permissions | 6 (Export, Edit translations, Browse, Import, Delete strings, Move strings) | Browse can be granted without Export or Delete |
| Default asset access for Agency Account Owners | None; glossaries, style guides, translation memory, and leverage are closed until granted | Least privilege is the starting point, not a configuration task |
| Permission delegation rule | Agency can grant a linguist only what the client granted the agency; removal cascades to the whole agency | One client action revokes an entire vendor's asset access |
| File formats agency roles can download for in-progress Jobs | 8 (.docx, .pptx, .xlsx, .idml, .indd, .srt, .json, .xliff), on Edit, Review, or Hold steps | Enables DTP and offline post-processing without granting file management |
| Workflow Assignments page filters | Up to 100 linguists and 10 target locales per filter; step type, provider, and SLS-managed filters | Answers "where does this agency have access" in one view |
| Content history visibility | All 7 roles can view string history; Strings View History filter covers action, date range, and user | Every vendor edit is attributable to a named user |
Source: Smartling Help Center articles Introduction to User Roles, Default User Permissions, Configurable Permissions for Agency Owners, Translation Resource Managers & Translation Resources, Download Your Team's Translations, Manage Workflow Assignments, and Strings View for Agency Account Owners & Translation Resource Managers, as published September 2026.
How do you set up agency user permissions in a translation platform?
Setting up vendor permissions in Smartling is a five-step exercise that the client's Account Owner completes once per agency, after which the agency manages its own people inside the ceiling the client has set.
- Add the agency as an agency, not as users — Ask your Smartling Customer Success Manager to add the vendor's Agency Account Owner; the agency then appears under Team > Agencies with its own profile and Permissions tab. Do not invite agency staff as Project Managers or Requesters, because those internal roles carry file-upload and Job-creation rights a vendor should not hold.
- Assign the agency to workflow steps by locale pair — From Team > Workflow Assignments, select the workflow, switch to the Agencies tab, and check the agency in each locale-pair-by-step cell it should work in. Assigning only the Editing column for en-US to ja-JP means the agency's linguists can neither open the Translation step nor any other language.
- Grant linguistic-asset permissions one asset at a time — In the agency profile's Permissions tab, click Add Permission, choose a type such as Glossary or Translation Memory, pick the named asset or project, and tick only the sub-permissions needed. For most agencies that is Browse a Translation Memory, Add/Edit Glossary Terms, and View All Quality Check Profile Settings; leave Export a Translation Memory unchecked unless the contract calls for it.
- Let the agency staff its own team within that ceiling — The Agency Account Owner invites its Translation Resources and Translation Resource Managers, selecting their language pairs and workflow steps at invite time, and can pass down only the permissions the client granted the agency. An invite is not complete until the user has at least one workflow assignment, so unscoped vendor accounts cannot exist.
- Revoke at the right level when the engagement changes — To end one linguist's access, the agency or the client removes that user; to end a vendor's access to an asset, remove the permission from the Agency Account Owner and it cascades to every linguist in the agency; to end the engagement, remove the agency's workflow assignments (content currently assigned to a user must be reassigned first). Removed users lose access immediately while their activity history is retained.
This permission model fits teams that...
- Work with two or more translation agencies, or an agency plus freelancers, in the same account and need each vendor limited to its own steps and languages.
- Translate sensitive product, legal, or pre-release content where translation memory and glossary contents are themselves confidential.
- Have IT or procurement requirements that vendors never hold an administrative role in a client system.
- Localize e-commerce catalogs, mobile apps, or marketing campaigns where different vendors own different locales or different steps (translation versus in-country review) of the same content.
- Want agencies to manage their own linguist roster without the client approving every individual invitation.
- Need internal stakeholders such as legal or regional marketing to see translations without editing or downloading them; Smartling's Content Viewer role is view-only and can be scoped by project.
When vendor permission depth may not be the right priority
- You need permissions that expire on a date or that lock content per web page, file, or folder. Smartling scopes vendor access by project, workflow step, and locale pair, with content assignment at the Job and string level; it does not use file-folder or per-URL permission trees, so teams that require those units should model their projects around them instead.
- Your real question is how the internal team should be structured. The Account Owner versus Project Manager split is a different decision, covered in Account Owner vs. Project Manager permissions in a TMS.
- You are the agency, not the client, and want to know how to run client work day to day: the Jobs Dashboard, client Review steps, and Word Count invoicing are covered in how agencies and LSPs manage client work in a TMS.
- You are still choosing which vendor to hire. Vetting, rate structures, and SLAs are a procurement question; see how to choose and manage a translation vendor.
- Your vendor works entirely offline and delivers files by email. Vendor permissions only matter once the vendor works inside the platform.
Evaluation checklist: questions to ask about agency permissions before you choose a TMS
Does the platform have a vendor role family, or do agencies get an internal role?
Ask for the published permission grid. Smartling's Default User Permissions article lists every function by role and shows that Agency Account Owner, Translation Resource Manager, and Translation Resource users cannot create projects, add languages, configure workflows, manage API keys, or run account-level reports.
What is the unit of scope for a vendor: account, project, or workflow step plus language?
The narrower the unit, the more vendors you can run in one account. Smartling assigns agencies per locale pair per workflow step, and the Workflow Assignments page shows those assignments as a grid you can filter by linguist, locale, and step type.
Are translation memory and glossaries closed to vendors by default?
They should be. In Smartling, Agency Account Owners have no access to glossaries, style guides, translation memory, or leverage until an Account Owner or Project Manager grants one of five permission types, each of which can be limited to a named asset.
Can a vendor browse the translation memory without exporting it?
Look for sub-permissions. Smartling's Translation Memory permission separates Browse, Edit translations, Export, Import, Delete strings, and Move strings, so TMX export can stay off while search stays on.
Can the agency grant its linguists more than the client granted the agency?
The answer must be no. In Smartling an Agency Account Owner can grant a permission only after receiving it, and a permission removed from the agency is removed from all of its linguists automatically.
What can vendor users download or export?
Confirm the list. Smartling agency roles can download in-progress translations in eight formats (.docx, .pptx, .xlsx, .idml, .indd, .srt, .json, .xliff) and export a CSV of string details; offline export and import of a Job's translations is available only if the Account Owner or Project Manager has enabled offline work.
Can a vendor see content it is not assigned to?
Some visibility helps quality; write access does not. Smartling's Strings View shows Agency Account Owners and Translation Resource Managers strings in earlier and later steps labeled Read Only, and never shows content that has not been authorized.
How is a vendor's activity audited?
Every one of Smartling's seven roles can view a string's history, and the Strings View History filter isolates actions by user and date range. Account-wide login and role reporting comes from the Users Report, covered in GDPR access controls in translation platforms.
Which certifications back the permission model?
Ask for SOC 2, ISO 27001, and sector certifications; Smartling's full set is covered in which enterprise localization platforms security teams trust.
How Smartling scopes agency and vendor user permissions
Smartling's translation management system gives external vendors their own three roles rather than a cut-down internal login. The Agency Account Owner is the LSP project manager: added by the client's Customer Success Manager, visible under Team > Agencies, responsible for adding the agency's translators and reviewers and assigning them to workflow tasks, and the client's contact for rates and invoicing. The Translation Resource Manager is a lead linguist who can assign work to other linguists in steps and languages they also hold, and translate themselves. The Translation Resource is the translator, editor, or reviewer who sees only the workflow steps and languages assigned to them. New user accounts are free, so there is no cost reason to share a login.
By default, none of the three vendor roles can create or clone projects, add or delete languages, upload or delete files, create Jobs or automation rules, configure workflows, manage API keys, or run account-level reports such as Processed Words or Content Velocity. What they can do is enter and edit translations, submit content to the next step, manage and comment on Issues, view content history, add or download Job Attachments, see fuzzy-match estimates, and pull Word Count reports for their own work. Agency Account Owners and Translation Resource Managers can additionally assign content, edit workflow task due dates, and remove Translation Resources registered under their own agency, but not users outside it.
Linguistic assets are closed to vendors until opened. An Account Owner or Project Manager grants one of five permission types (Glossary, Leverage, Style Guide, Translation Memory, Quality Check Profile) from the agency profile's Permissions tab, optionally limited to a named glossary, translation memory, or project. Translation Memory permissions split into Export, Edit translations, Browse, Import, Delete strings, and Move strings; Glossary permissions split into adding or editing terms and bulk-updating from a file; Quality Check Profile permissions include a read-only View All Settings option that Smartling recommends enabling so linguists can see the checks their work is measured against. An Agency Account Owner can pass a permission to its team only after receiving it, and removing it from the agency removes it from every Translation Resource Manager and Translation Resource in that agency in one action.
Scope is set per locale pair and workflow step on the Workflow Assignments page, where the client checks an agency into individual cells of a locale-by-step grid and can filter by up to 100 linguists, 10 target locales, step type, translation provider, and whether the step is managed by Smartling Language Services. Agency users can then see strings in adjacent steps in the Strings View, labeled Read Only, and can download in-progress translations on Edit, Review, or Hold steps in .docx, .pptx, .xlsx, .idml, .indd, .srt, .json, and .xliff formats, plus a CSV of string details, for desktop publishing or offline work; exporting a translation memory as TMX remains a separately granted permission. For teams that also need internal stakeholders to observe without touching translations, the Content Viewer role provides view-only access to source and target strings, scoped by project, with no download or Issue participation.
Relaterede spørgsmål
- Which translation platforms offer the best role-based access controls and audit trails for GDPR compliance?
- How do Account Owner and Project Manager permissions differ in a translation platform?
- Which translation management systems work best for agencies and LSPs managing client work?
- Hvilke virksomhedslokaliseringsplatforme har sikkerhedsteams tillid til?
Klar til at se Smartling i aktion?
Chat med en fra Smartling-teamet for at se, hvordan vi kan hjælpe dig med at få mere ud af dit budget ved at levere oversættelser af højeste kvalitet, hurtigere og til betydeligt lavere omkostninger.