Brevo

Brevo permissions: who can send to your whole base?

Diagram: a user allowed to send reaches the entire contact base because Brevo has no per-list scope
Summary

Brevo's permissions apply to features (Campaigns, Contacts, Automations), not to data. You decide whether someone can send, never to whom. The result: any user allowed to send can select any list, "All contacts" included, and nothing validates the send before it goes out. This article covers the mechanism, the risk, and the fixes, both native and beyond.

A new team member joins on Monday. On Tuesday, they prepare their first Brevo campaign, open the recipient picker, tick "All contacts" out of reflex and click Send. Forty thousand people receive an email that wasn't ready. Nobody meant any harm, and yet the damage is done.

The problem is structural, not a matter of discipline. In Brevo, permission to send a campaign says nothing about which contacts you're allowed to target. Whoever can send can send to everyone. Let's look at what Brevo permissions actually control, why the whole base stays one click away, what it costs, and how to frame who sends to whom.

Key takeaways

  • Brevo permissions are feature-level, not list-level: no setting restricts a user to specific segments or lists (Brevo, 2026).
  • 58% of employees admit sending a work email to the wrong person (Tessian): human error is the rule, not the exception.
  • Brevo has no approval-before-send: no native "a member prepares, an admin approves" circuit for marketing campaigns.
  • Sending to the whole base hurts everyone's deliverability: above 0.3% complaints, Gmail and Yahoo degrade inbox placement (Google, 2024).

What do Brevo permissions actually control?

They control access to features, not to contacts. An admin enables modules per user (Campaigns, Contacts, Automations, Transactional) and, for campaigns, a scope per folder. No permission limits which lists or segments a user can target (Brevo, User permissions and permission levels, 2026).

Granularity therefore stops at the feature and the campaign folder; it never descends to the list or the record. As soon as a colleague can create and send a campaign, they see every list in the account in the recipient picker, including the "All contacts" option.

The free account is single-user: multi-user access and granular permission settings appear only on higher paid plans, and reusable predefined roles are an Enterprise-plan feature. Because plan names and seat counts change regularly, confirm the details on Brevo's pricing page. We also summarize Brevo permissions without the Enterprise plan.

The "Campaigns" permission doesn't know your lists The "Campaigns" permission doesn't know your lists Send right enabled ✓ Newsletter Prospects VIP customers All contacts
A single send permission opens access to every list, "All contacts" included.

In other words: in Brevo, permissions are set per product module and, for campaigns, per folder, never per list or segment (Brevo, 2026). The moment a user can send a campaign, they can point it at any list in the account, including the entire base.

From our audits

In the shared Brevo accounts we review, the problem is almost never a malicious user. It's a rushed colleague, an intern or a contractor: someone who has the right to send and for whom "All contacts" is simply the first box on the list.

Why can anyone reach the whole base?

Because nothing stops them, and human error is common. In a Tessian survey, 58% of employees admit having sent a work email to the wrong person (Tessian, The Psychology of Human Error). Brevo installs no guardrail between that reflex and your entire base: no per-user list restriction, no "All contacts" box you can hide.

Above all, an approval step is missing. Brevo offers a preview and a test before sending, and an internal compliance review for SMS, but no team circuit where a member prepares and an admin approves before it goes out. True approval workflows come from third-party tools placed above the account.

The only truly native levers are blunt. The first: don't grant send rights at all. The second: physically separate databases into sub-accounts, an Enterprise-plan capability that multiplies the accounts you administer. Between the two, nothing bounds the scope of a send.

The trap

"We're careful" is not a control. As long as the "All contacts" box stays one click away for every person allowed to send, an accidental blast to the whole base becomes only a matter of time.

What does a send to the whole base really cost you?

It costs deliverability, to all your teams, not just the person who sent it. Since February 2024, Gmail and Yahoo require bulk senders to keep the spam-complaint rate below 0.3%, that's three complaints per thousand emails, and Google recommends staying under 0.1% (Google, Email Sender Guidelines, 2024). A large, untargeted send spikes complaints all at once.

The starting margin is already thin. In 2026, roughly 15% of legitimate marketing email never reaches the inbox, for a global inbox placement at 84.5% (Validity, $42 Million a Day, Q2 2026). Burning your reputation with a send to the whole base eats into an already reduced margin.

The risk goes beyond marketing. Nearly six data breaches in ten involve human error (Verizon, Data Breach Investigations Report, 2025), and sending to the wrong recipient consistently ranks among the top recorded errors. An entire base sent by mistake is also a potential GDPR incident.

Segment instead of blasting everyone Segment instead of blasting everyone Segmented vs. non-segmented campaigns, same senders Opens Clicks Unsubscribes Spam complaints +14.3% +101% −9.4% −3.9% Opens and clicks: more. Unsubscribes and complaints: fewer. All favor segmentation.
Performance gap of segmented vs. non-segmented campaigns, same senders. Source: Mailchimp.

Conversely, targeting pays. With the same senders, segmented campaigns see 100.95% more clicks and 9.37% fewer unsubscribes than non-segmented sends (Mailchimp, Effects of List Segmentation). On top of the risk, a send to the whole base is also the worst performer.

Good to know

Sending to the whole base is also a frequency problem: the same contact ends up getting everything, all the time. We dig into that side in "Brevo for teams: why your campaigns spiral out of control".

How do you limit who can send, and to whom?

Start by restricting the right to send, then add the scope Brevo doesn't handle. Because native permissions don't descend to the list, the only immediate native fix is to grant sending only to the people who need it. The rest, per-list scope and approval before sending, is handled on top of the account.

1

Audit who can send

Review your users and remove the Campaigns module from anyone who doesn't need to launch a send. It's the only genuinely effective native lock.

2

Isolate sensitive bases

If two teams must never cross, sub-accounts physically separate contacts. Effective, but heavy to administer and reserved for the Enterprise plan.

3

Add approval before sending

A member prepares, an admin approves before it goes out. Absent natively from Brevo; it's the net that prevents an accidental blast to the whole base.

4

Scope access by list

Define who can send to which lists, and enforce that rule automatically rather than relying on everyone's vigilance.

The first two steps are native. The last two require a governance layer on top of Brevo. The full method, with the setup order, is detailed in our complete guide to multi-team Brevo governance. The same logic applies on the Mailchimp side, where roles are also global and without per-audience scope.

In practice

Approval before sending and per-list scope, Sendgate adds them to Brevo.

Sendgate sits on top of your existing Brevo account, with no migration. Each team only reaches its own lists, sends go through an approval step before they leave, and "All contacts" stops being one click away for everyone. You finally decide who sends to whom.

Try it free →

Email sending governance · Not affiliated with the brands mentioned

The takeaway

Brevo compartmentalizes features, never data. A user allowed to send can target any list, "All contacts" included, and without prior validation. The limit sits in the permission model, not in your teams.

The fix comes in two moves: natively restrict the right to send, then add what's missing on top: a per-list scope and an approval step. That's exactly the gap a governance layer fills.

Frequently asked questions

Can you restrict a Brevo user to specific lists?
No. Brevo permissions are set per feature (Campaigns, Contacts…) and per campaign folder, never per list or segment. Any user allowed to send can select any list, "All contacts" included. Scoping a user to specific lists requires a governance layer placed on top of the account.
Does Brevo have an approval-before-send workflow?
Not for marketing campaigns. Brevo offers a pre-send preview and test, and an internal compliance review for SMS, but no "a member prepares, an admin approves before it goes out" circuit. True approval workflows come from third-party tools placed above the account.
Which plan includes user permissions?
The free account is single-user. Multi-user access and granular permission settings appear on higher paid plans, and reusable predefined roles are an Enterprise-plan feature. Because plan names and seat counts change regularly, confirm the details on Brevo's pricing page.
Do sub-accounts solve the problem?
Partly. Sub-accounts physically separate databases, so a send cannot reach contacts in another sub-account. But it's an Enterprise-plan capability that multiplies the accounts you administer, and it still adds neither per-list scope within an account nor an approval step before sending.

Sources

  1. Brevo, User permissions and permission levels in Brevo, retrieved 2026-07-04. help.brevo.com
  2. Tessian, The Psychology of Human Error (misdirected email), retrieved 2026-07-04. tessian.com
  3. Verizon, 2025 Data Breach Investigations Report, retrieved 2026-07-04. verizon.com
  4. Google, Email Sender Guidelines, retrieved 2026-07-04. support.google.com
  5. Validity, $42 Million a Day: The Real Cost of Election Season on Email (global inbox placement at 84.5% in Q2 2026), retrieved 2026-08-03. validity.com
  6. Mailchimp, Effects of List Segmentation on Email Marketing Stats, retrieved 2026-07-04. mailchimp.com
Jean Rubens

Jean Rubens

Co-founder, Sendgate

Jean is a co-founder of Sendgate. He writes about email sending governance for teams: access compartmentalization, per-list scope and approval before sending across shared sending accounts.