Skip to main content

Marketo permissions and security

The Marketo connector reconstructs source access from Marketo workspaces, roles, users, and an administrator-provided roles and permissions workbook. Setup uses the Marketo Representational State Transfer (REST) API endpoint for the connected subscription.

How permissions work​

For each Marketo workspace and supported capability, Glean creates a synthetic permission group. An asset's permission requirements depend on:

  • The workspace that contains the asset
  • The Marketo capability required for that asset type
  • Whether the asset is inside a program

During the full identity crawl, Glean reads the Marketo workspace and role catalogs, maps exported role permissions to capabilities, crawls active human users, and adds each user to the groups allowed by their role and workspace assignments.

Asset permission mapping​

The following table lists the capability required for each asset type:

Indexed assetRequired Marketo capability
ProgramAccess Marketing Activities
Smart campaignAccess Marketing Activities
EmailAccess Email
Landing pageAccess Landing Page
FormAccess Form
SnippetAccess Snippet
Email templateAccess Email Template
Landing page templateAccess Landing Page Template
Static listAccess Database

A user can find an asset in Glean only when the user's active Marketo role and workspace assignments meet all permission requirements for that asset.

note

For assets inside a program, users also need Access Marketing Activities in the same workspace.

Roles workbook​

Marketo's role-list API does not return the complete permission tree needed for this mapping. The connector therefore combines live role data with the roles and permissions .xlsx workbook uploaded during setup.

Keep the workbook synchronized with Marketo:

  • Export it from the same subscription as the connected REST API endpoint.
  • Upload it without changing its structure or contents.
  • Upload a new export after adding, renaming, or deleting a Marketo role, or changing its permissions.
  • Run or wait for a full identity crawl after replacing it.

If a live Marketo role is absent from the workbook, Glean cannot map that role to capabilities. This can cause the identity crawl to fail when an active user holds the unmapped role.

User handling​

The connector:

  • Indexes active human Marketo users as permission principals.
  • Uses each user's email address for identity resolution.
  • Excludes API-only users from Glean permission membership.
  • Excludes locked users and users whose Marketo access has expired.
  • Expands an AllZones assignment across every workspace returned by Marketo.
  • Removes stale users and memberships through full identity crawls.

Glean skips users without a resolvable email address.

Security guidance​

  • Use a dedicated API-only user and LaunchPoint custom service for Glean.
  • Grant only the permissions listed in Set up Marketo.
  • Store the client secret only in the connector configuration.
  • Keep the roles workbook private because it contains role and permission details.
  • Export and upload a new roles workbook whenever a role's permissions change. A stale workbook can retain access that Marketo no longer allows. Run or wait for a full identity crawl after the upload.
  • Reauthorize the connector after rotating the client ID or client secret.
  • Verify access with users from different workspaces and roles before broad rollout.