> For the complete documentation index, see [llms.txt](https://docs.peakcommerce.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.peakcommerce.com/product/using-peakcommerce/profiles-and-permissions/portal-action-permissions.md).

# Portal Action Permissions

Beyond navigation visibility and View/Edit access, a profile controls which **portal actions** its users can perform — the self-service and CSR-assisted operations exposed in the customer, partner, and CSR portals, such as changing a plan, cancelling one, or revoking a scheduled cancellation.

## Change Plan vs Cancel Plan

Changing a plan and cancelling a plan are **separate permissions**, so you can grant one without the other:

| Who                   | Permission                             | Allows                                                      |
| --------------------- | -------------------------------------- | ----------------------------------------------------------- |
| **Customer**          | **Change My Plan**                     | The customer upgrades or downgrades their own subscription. |
| **Customer**          | **Cancel My Plan**                     | The customer cancels their own subscription.                |
| **Partner** (own)     | Change / Cancel My Plan                | A partner acting on their own subscription.                 |
| **Partner** (managed) | Change / Cancel Customer Subscriptions | A partner acting for the customers they manage.             |
| **CSR**               | Change / Cancel Customer Subscriptions | A CSR acting on a customer's behalf.                        |

Because they're independent, you can, for example, offer a profile that can **cancel** but not change plan (route upgrades through a CSR), or one that can **change** plan but must send cancellations to a retention flow.

> Previously this was a single combined "manage subscription" grant. Existing profiles were **automatically split** into the separate Change and Cancel permissions, so no access was lost — you simply have finer control now.

## The third grant: Revoke Scheduled Cancellation

Undoing a scheduled cancellation is a **third, independent permission** — being able to cancel does not imply being able to un-cancel, and vice versa:

| Who          | Permission                                   | Allows                                                                                                         |
| ------------ | -------------------------------------------- | -------------------------------------------------------------------------------------------------------------- |
| **Customer** | **Revoke Scheduled Cancellation**            | The customer un-cancels their own subscription while the cancellation's effective date is still in the future. |
| **CSR**      | **Revoke Customer's Scheduled Cancellation** | A CSR revoking a customer's scheduled cancellation from the agent console.                                     |
| **Sales**    | **Revoke Customer's Scheduled Cancellation** | A sales rep doing the same for the accounts they work.                                                         |

> **Unlike Change and Cancel, this grant isn't on/off — it has three levels.** Change and Cancel are binary: you have the action or you don't. Revoke Scheduled Cancellation is graded **none / view / manage**:
>
> * **None** (the default on every profile) — no revoke-specific UI at all; the subscription card shows only the standard pending-cancellation banner.
> * **View** — the user sees the **cancellation-scheduled banner**, including *why* a revoke is currently blocked (an unpaid invoice, an unreadable billing state), but gets no button.
> * **Manage** — the user also gets the **Revoke Cancellation** button.
>
> View-without-manage is genuinely useful: it lets a rep (or a read-only customer role) **see the scheduled state and its blockers** — enough to explain the situation on a call or chase down an unpaid invoice — **without the power to execute the revoke**, which stays with the profiles you've deliberately granted manage.

Two things to remember when wiring it up:

* **The permission is the second of two gates.** The retention journey's *Allow revoking a scheduled cancellation* setting must also be enabled — the permission alone shows nothing if the journey doesn't offer the action. See the [Customer Retention Journey](/product/customer-self-service/subscription-management/customer-retention-journey.md).
* **The default is none everywhere** — customer, CSR, and sales profiles all start without it, so rolling out revoke is an explicit decision per profile, not something that arrives silently with an upgrade.

Set these on a profile from the **user menu** (your name, bottom-left) → **Settings → Profiles**. They sit alongside the [permission levels and record access](/product/using-peakcommerce/profiles-and-permissions/access-levels-for-permissions.md) (visibility, View/Edit, and record scope) that govern the rest of the platform.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.peakcommerce.com/product/using-peakcommerce/profiles-and-permissions/portal-action-permissions.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
