Controlled payment account access

Invite CMS Max to Authorize.Net Safely

Create a named support user with the permissions, duration, and owner the work actually requires.

Authorize.Net allows account owners and administrators to add and manage users without sharing the merchant owner password. Use this process only after CMS Max has requested access for a defined task, and confirm the current recipient, role, permissions, and removal date before sending the invitation.

  • Named user
  • Least privilege
  • Activation + MFA
  • Review and removal

Current support boundary

Account access should be specific, attributable, and temporary when the work is temporary.

Do not share the account owner password, MFA code, API Transaction Key, or another person's login. Create a separate user, grant only the necessary permissions, verify the activation, and remove or reduce access when the task is complete.

01

Confirm the request

Verify the CMS Max contact, business purpose, systems involved, required permissions, start date, and expected end date through an established channel.

02

Choose least privilege

Authorize.Net roles can carry broad defaults. Select the narrowest role and permissions that support the approved work.

03

Keep merchant ownership

A merchant account owner should approve, review, and revoke access and retain the audit record.

Operational controls

Prepare the invitation before opening Manage Users.

The current Authorize.Net experience uses Manage Users, identity confirmation, and an activation email. Menu names may differ in the classic interface.

01

Recipient

Use `info@cmsmax.com` only when CMS Max has explicitly confirmed that address for the engagement.

02

Identity

Use a clear first name, last name, title, phone, and login identity so the account is recognizable later.

03

Role

Do not select Account Administrator by habit. Confirm whether transaction, configuration, reporting, or other permissions are actually required.

04

Notifications

Enable only the account and transaction notifications needed for the approved support responsibility.

05

Activation

Authorize.Net sends an activation email and the current new experience documents a 24-hour activation window.

06

Review

Record the merchant approver, invitation date, permissions, activation status, support case, and access review or removal date.

Implementation workflow

Invite, verify, document, and close the access lifecycle.

The user is not finished when the email is sent; activation, MFA, access verification, and later removal are part of the same control.

  1. 01

    Approve

    Confirm the task, recipient, role, permissions, notifications, duration, merchant owner, and support case.

  2. 02

    Add user

    In the current interface, open Account, Manage Users, choose Add New User, and enter the approved details.

  3. 03

    Verify

    Complete the merchant identity check using the one-time PIN without sharing that PIN with another party.

  4. 04

    Activate

    Have the named recipient complete the Authorize.Net activation and MFA setup, then verify only the approved areas are available.

  5. 05

    Review and remove

    Recheck access after the work, reduce or delete the user when no longer needed, and preserve the change record.

Clear responsibility

The merchant remains the access owner.

CMS Max can state what work requires; only the authorized merchant should approve account privileges and identity verification.

Merchant account owner
Approves the business need, user, role, permissions, notifications, duration, review, and removal.
CMS Max project owner
Confirms the requested recipient, scope, minimum access, expected task, and completion signal.
Invited user
Activates the individual account, protects MFA, uses access only for approved work, and reports completion or incidents.
Merchant security or finance
Reviews sensitive privileges, transaction visibility, separation of duties, audit records, and recurring access.

Current references

Use the provider account and documentation as the live source.

Authorize.Net publishes current steps for the new Merchant Interface and separate help for classic User Administration.

Authorize.Net access FAQ

Resolve the practical questions before production.

Access decisions should be confirmed for the specific engagement and merchant account.

Should I share my Authorize.Net owner password with CMS Max?

No. Create a separate named user with approved permissions. Never send the owner password, MFA code, or another person's credentials.

Which email address should I invite?

Use the address CMS Max confirms for the current engagement. The historic public instruction used info@cmsmax.com, but do not assume a recipient without confirmation.

Does CMS Max always need the Account Administrator role?

No. Select the least privilege needed for the approved work. Broad administrative access should require a specific business reason and merchant approval.

How long does the activation link remain valid?

Authorize.Net currently documents a 24-hour activation window for the new Merchant Interface. Resend it from Manage Users if needed rather than sharing credentials.

What should happen when the support task ends?

Verify completion, reduce or remove access, record the action, and review whether any API credentials or settings changed during the engagement.

Security requires operations

Request the exact access checklist for your engagement.

CMS Max can confirm the recipient, purpose, minimum role, permissions, expected duration, activation owner, and completion signal before the merchant sends an invitation.

Building Relationships with Web Developers and Marketing Agencies that want better results

The world's fastest and most SEO friendly website code.