---
id: KB-CD-017
url: https://app.codecontract.io/help/credits-and-billing/who-should-be-able-to-spend
idioma: en
categoria: creditos
audiencia: administrador
nivel: intermedio
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-CD-013, KB-AD-014, KB-CD-008]
citadoPor: [KB-CD-003]
---

# Who should be able to spend

_Almost nobody decides this, and then it shows up in the breakdown. The three profiles and what to leave each._

**Responde a:** limit who can send · control spend per user · who can launch a campaign · permissions and credit consumption

Consumption is not generated by "the company": it is generated by specific people doing specific things. And since it is almost never decided who may do what from that angle, the first time someone opens the breakdown they find that 60% comes from one person who did not even know they were spending.

## The three profiles by what they can trigger

| Profile | What actions they generate | What works |
| --- | --- | --- |
| Whoever runs the day to day | Sends, reminders, uploads: high volume, low risk per action | No limits, with visibility |
| Whoever launches to many | Campaigns and bulk sends: few actions, wide reach | They should know it is one action and how many it reaches |
| Whoever switches on automations | Rules that fire by themselves, many times | Here yes: have someone review first |

> [!IMPORTANT]
> The third row is the only one genuinely worth putting a hand in front of, and not because of the action's cost — it is the same as any other — but because **it is the only one that multiplies without anyone touching it again**. A person sending consumes as they work; a misaimed rule consumes for as long as it is on, weekends included.

## What works better than a limit

1. **Let each area see its own consumption** — Seeing the figure changes behaviour more than any permission: nobody wants to be the line that stands out.
2. **Warn about what multiplies, not what adds** — A send to two hundred is one action; an hourly rule is seven hundred a month.
3. **And review who generated what monthly** — Not to point fingers: to discover the process nobody knew existed.

> [!WARNING]
> Beware the intuitive reaction of restricting whoever spends most. It is nearly always whoever works most with the outside world — the person chasing suppliers, the one sending for signature — and limiting them saves nothing: it moves the work elsewhere, usually to email, where no record remains. **If someone spends a lot and their job justifies it, the figure is not a problem: it is a description of their role.**

## When narrowing does make sense

**En corto**

- When an outsider has access and could send on your behalf.
- When an intern or temporary person is learning on real cases.
- And when an integration can trigger actions with no person behind it.

The third surprises people most on review: an integration that creates or notifies generates actions like a person, and it does not tire or take holidays.

> [!NOTE]
> Everything executed is attributed to whoever did it — person, rule or integration — so the consumption conversation can be had with data rather than impressions. It is the difference between "we spend a lot" and "this rule has run seven hundred times this month".

**Can a per-user cap be set?**

What exists is visibility and permissions over actions; the real brake is knowing who generates what.

**What if someone spends by mistake?**

It is usually a rule, not a person: look at the automatic side first.

**Should consumption be shown to the whole team?**

Their area's, yes. The company total, only to whoever decides.

## Ejemplos

**A company sees high consumption and considers limiting whoever sends most.**

- Checks the breakdown by origin and finds an hourly rule switched on two months ago

→ Adjusts the rule and leaves the top sender alone — they were the one getting the most deliveries.

**Anyone can launch actions that consume.**

- Defines who can do what

→ Spend has known owners.

**Somebody new launches a campaign by mistake.**

- Limits bulk actions to the right people

→ The big mistake stops being possible.

**Nobody knows who generated a specific consumption.**

- Checks consumption by user

→ The conversation happens with the right person.

**Broad permissions are granted to get past a problem.**

- Grants only what is needed

→ Access matches the role.

**A department asks to be able to spend on its own.**

- Separates consumption by department with its own limit

→ Each one decides within their own.
