PantheonGet Early Access

Zalo Official Account: Roles & Permissions

TL;DR

A business presence on Zalo is an Official Account (OA). An Advertising Profile needs no license but can only run ads; a verified OA requires a Vietnamese business registration license and unlocks messaging, broadcasts, chatbot and ZNS. Zalo publishes an unusually clear six-role model, and the OA owner authorizes its own app directly — a brand can hold its own tokens, so a partner is optional.

On this page

Advertising Profile vs verified OA

A business presence on Zalo is a Zalo Official Account (OA). Zalo distinguishes an Advertising Profile, available to entities without a business license and limited to running ads, from a verified (authenticated) OA, which requires a Vietnamese Business Registration License and unlocks messaging, broadcasts, posts, chatbot and voice features along with a verification checkmark (Zalo OA).

Verification must be completed within about 14 days of creating the OA, with document review typically returning in two to three working days.

Six named roles

Zalo OA has an explicitly named, granular role model — unusually well-documented for the region. Its admin management guide defines:

  • Administrator (Quản trị viên) — the superuser who manages the admin list and can delete the OA.
  • Content editor — info, menu, posts, broadcast, analytics, chat.
  • Analyst — statistics only.
  • Customer care — chat and calls.
  • Advertiser — ads only.
  • Package & link manager — packages and app-linking.

Admins are invited by phone number and confirm in the Zalo app; an OA supports up to 100 admins, and Zalo explicitly recommends granting agencies a limited role rather than Administrator.

Who holds the API keys

Programmatic access to the OA and Zalo Notification Service (ZNS) runs through an app registered on Zalo For Developers. The OA administrator authorizes an app (AppID) — increasingly via a Zalo Cloud Account (ZCA) — which issues a short-lived OA Access Token (one hour) renewed by a single-use Refresh Token (three months) and authenticated by an App Secret.

Because the OA owner grants and can revoke this authorization directly, a brand can hold its own credentials; a partner or BSP is optional rather than mandatory.

Verification is the feature gate

The verified/unverified split is the central governance gate: an unverified Advertising Profile can only run ads, while a verified OA unlocks the full communication feature set and eligibility to register ZNS.

ZNS itself adds two more requirements — the brand name must be authenticated with Zalo, and each ZNS template must be pre-registered before sending.

Frequently asked questions

What is the difference between a Zalo Advertising Profile and a verified OA?

An Advertising Profile needs no business license but can only run ads — no messaging, broadcast or chatbot. A verified Official Account requires a Vietnamese business registration license and unlocks the full communication feature set plus ZNS eligibility.

What roles does a Zalo Official Account support?

Six named roles: Administrator, Content editor, Analyst, Customer care, Advertiser, and Package & link manager. Admins are invited by phone number, up to 100 per OA, and Zalo recommends giving agencies a limited role rather than Administrator.

Does a Zalo business need a third-party provider?

No. The OA administrator authorizes an app (AppID) directly — increasingly through a Zalo Cloud Account — and can hold and revoke its own OA access token. A partner or BSP is optional, though common for foreign brands.

Related

Business Messaging: Access, Roles & Permissions Across Platforms

Every major messaging platform gates business access differently. The single most important difference is who holds the technical keys: some platforms (Apple, Google RCS, KakaoTalk, Viber) require an approved intermediary you cannot bypass, while others (Telegram, LINE, WhatsApp, Zalo) let a business hold its own API credentials. Role models range from granular named matrices (WhatsApp, LINE, Zalo) to almost none (Telegram, where possessing the token is control). Asian platforms additionally gate account creation on a registered legal entity.

Read →

KakaoTalk Business Messaging: Access, Roles & Permissions

Business messaging on KakaoTalk runs through a KakaoTalk Channel upgraded to a Business Channel by registering a Korean business license and passing verification. Its defining governance fact is that brands generally cannot self-serve the business-message API — sending requires a Kakao-issued sender key held through a Kakao-authorized agency. Roles split across a channel (Master/Manager) and a developer app (Owner/Editor/Message Editor/Viewer), and messaging splits into transactional AlimTalk and marketing FriendTalk.

Read →

Viber Business Account: Access & Permissions

On Viber (Rakuten Viber), business presence centers on a verified Business Account and the Viber Business Messages service. Every business account must be approved by Viber and pass brand verification, and Business Messages is applied for and operated through an official partner (BSP). Viber publishes no named multi-role hierarchy — the documented model is minimal: a bot administrator, with authorization effectively resting on a secret token, and team management pushed onto the partner platform.

Read →

What is a Unified Inbox?

A unified inbox consolidates conversations from multiple communication channels — messengers, email, and more — into a single interface, so you can triage, read, and reply across all of them without switching apps and without losing track of who said what.

Read →

Share this page

Last updated