Confirm the request
Verify the CMS Max contact, business purpose, systems involved, required permissions, start date, and expected end date through an established channel.
Our website uses cookies. By continuing to use our site, you agree to our use of cookies in accordance with our Privacy Policy.
Controlled payment account access
Create a named support user with the permissions, duration, and owner the work actually requires.
Authorize.Net allows account owners and administrators to add and manage users without sharing the merchant owner password. Use this process only after CMS Max has requested access for a defined task, and confirm the current recipient, role, permissions, and removal date before sending the invitation.
Current support boundary
Do not share the account owner password, MFA code, API Transaction Key, or another person's login. Create a separate user, grant only the necessary permissions, verify the activation, and remove or reduce access when the task is complete.
Verify the CMS Max contact, business purpose, systems involved, required permissions, start date, and expected end date through an established channel.
Authorize.Net roles can carry broad defaults. Select the narrowest role and permissions that support the approved work.
A merchant account owner should approve, review, and revoke access and retain the audit record.
Operational controls
The current Authorize.Net experience uses Manage Users, identity confirmation, and an activation email. Menu names may differ in the classic interface.
Use `info@cmsmax.com` only when CMS Max has explicitly confirmed that address for the engagement.
Use a clear first name, last name, title, phone, and login identity so the account is recognizable later.
Do not select Account Administrator by habit. Confirm whether transaction, configuration, reporting, or other permissions are actually required.
Enable only the account and transaction notifications needed for the approved support responsibility.
Authorize.Net sends an activation email and the current new experience documents a 24-hour activation window.
Record the merchant approver, invitation date, permissions, activation status, support case, and access review or removal date.
Implementation workflow
The user is not finished when the email is sent; activation, MFA, access verification, and later removal are part of the same control.
Confirm the task, recipient, role, permissions, notifications, duration, merchant owner, and support case.
In the current interface, open Account, Manage Users, choose Add New User, and enter the approved details.
Complete the merchant identity check using the one-time PIN without sharing that PIN with another party.
Have the named recipient complete the Authorize.Net activation and MFA setup, then verify only the approved areas are available.
Recheck access after the work, reduce or delete the user when no longer needed, and preserve the change record.
Clear responsibility
CMS Max can state what work requires; only the authorized merchant should approve account privileges and identity verification.
Current references
Authorize.Net publishes current steps for the new Merchant Interface and separate help for classic User Administration.
Authorize.Net access FAQ
Access decisions should be confirmed for the specific engagement and merchant account.
No. Create a separate named user with approved permissions. Never send the owner password, MFA code, or another person's credentials.
Use the address CMS Max confirms for the current engagement. The historic public instruction used info@cmsmax.com, but do not assume a recipient without confirmation.
No. Select the least privilege needed for the approved work. Broad administrative access should require a specific business reason and merchant approval.
Authorize.Net currently documents a 24-hour activation window for the new Merchant Interface. Resend it from Manage Users if needed rather than sharing credentials.
Verify completion, reduce or remove access, record the action, and review whether any API credentials or settings changed during the engagement.
Security requires operations
CMS Max can confirm the recipient, purpose, minimum role, permissions, expected duration, activation owner, and completion signal before the merchant sends an invitation.
The world's fastest and most SEO friendly website code.