If you've just registered your business in the CARM Client Portal and now your broker is asking you to "accept the delegation request," you're at one of the most consequential setup moments in the CARM process. The access you grant shapes everything that comes after — how much visibility your broker has, which transactions they can see, who else can act on your account, and how easily you can revoke access if the relationship changes.
Most importers click "Approve" without understanding what they're approving. That's a mistake.
This article covers the CARM delegation of authority process in depth: the five available roles, the three visibility rules, how to structure access across multiple brokers, how to add internal team members, how to revoke access, and the specific mistakes that create operational and compliance risk.
The basic structure: two types of users, two types of relationships
Before getting into the mechanics, understand the framework.
The CARM Client Portal distinguishes between:
Internal users — employees of the importer's own business (yours). These are people at your company who need access to the portal. Roles: Business Account Manager (BAM), Program Account Manager (PAM), Editor, Reader.
Third-party service providers — external entities you've authorized to act on your behalf. Typically customs brokers, occasionally trade consultants. Roles: Proxy Business Account Manager (pBAM), Proxy Program Account Manager (pPAM).
The importer (you) always retains ultimate control. Delegation is a grant of access, not a transfer of authority. You can revoke delegation at any time from the "Manage business relationships" section of the portal.
The five roles explained
The CARM portal supports five distinct roles. Understanding what each one can and cannot do is critical to setting up delegation correctly.
Business Account Manager (BAM)
Who gets it: The person who first registers the business in CARM automatically becomes BAM. Typically this is the business owner, a supply chain manager, or a designated operations lead. CBSA strongly recommends assigning at least two BAMs so the business isn't locked out if one person leaves.
Access level: Full access to everything in the business account. The BAM operates at the BN9 (business number) level, which covers all of the company's program accounts (RM0001, RM0002, etc.).
What the BAM can do:
- Manage all legal entity and program information
- Assign roles to employees and approve access requests
- Delegate authority to third-party service providers
- Request rulings and submit appeals
- View all financial information, Statements of Account, invoices, and transaction history
- Make payments
- Post and manage financial security
- Enroll in or withdraw from programs like Release Prior to Payment (RPP)
Who this role is for: The person ultimately accountable for your company's customs compliance. Under Section 17 of the Customs Act (in force since January 1, 2026), the BAM is often the person personally exposed to reassessment liability — so this role should go to someone senior enough to take that responsibility seriously.
Program Account Manager (PAM)
Access level: Full access to specific program accounts (RM-level), but not the full business account.
What the PAM can do:
- Everything the BAM can do, but only within the specific program account(s) assigned
- Delegate third-party access for their specific program
- Manage employees at the program level
Who this role is for: Middle management responsible for a specific import program or division. If your company has multiple RM accounts (for different business divisions, different product lines, or different countries of operation), each PAM can manage their own program without seeing other programs' data.
Editor
Access level: Can perform specific operational tasks within a program, but cannot manage other employees' access.
What the Editor can do:
- Submit payments
- Submit ruling requests
- File Commercial Accounting Declarations (if they have the specific permission)
- View financial information within their program
What they cannot do:
- Approve access requests from other employees
- Delegate to third parties
- Modify business account information
Who this role is for: Day-to-day operational staff who handle specific customs tasks but shouldn't control account access.
Reader
Access level: View-only access to a specific program or the whole account.
What the Reader can do:
- View all information the role grants access to
- Download reports and statements
What they cannot do:
- Submit, alter, or approve anything
Who this role is for: Finance staff, bookkeepers (if they're employees), auditors, or anyone who needs visibility but shouldn't change anything.
Proxy Business Account Manager (pBAM)
Who gets it: A third-party service provider that you've designated at the business management level. Typically this is your primary customs broker.
Access level: Near-full access to the business account, with two specific exclusions.
What the pBAM cannot do:
- Access the client's sensitive information (like bank account details for payments)
- See or manage the client's employees or internal business relationships
What the pBAM can do:
- Perform operational activities in the portal for all of the importer's program accounts
- Request rulings, make payments, view SOAs, invoices, transactions
- Manage the service provider's own employees' access to the importer's business account
- Submit CADs, corrections, and adjustments
Who this role is for: Your primary customs broker. This is the right role if you want your broker to have broad operational authority across all your import programs, without giving them access to your internal employee management or bank account information.
Proxy Program Account Manager (pPAM)
Who gets it: A third-party service provider designated at the program level rather than the business level.
Access level: Near-full access to specific program accounts assigned, but not to the full business account.
Who this role is for: Secondary brokers handling a specific product line or geography, or trade consultants handling only certain programs. If you have a primary broker handling 80% of your shipments and a specialty broker for a specific chapter, the primary is your pBAM and the specialty is a pPAM.
The three visibility rules
Beyond assigning a role, you control what each service provider can see through three specific visibility attributes.
Visibility Rule 1: Submitted by the Customs Broker
When this rule is set, the service provider sees transactions they themselves submitted. This is the default and the minimum — every broker can always see their own work.
What it means in practice: If Broker A files a CAD on your behalf, Broker A can see that CAD. They cannot see CADs filed by other brokers unless you enable additional visibility.
Visibility Rule 2: Submitted by the Client
When enabled, the service provider sees transactions the importer (you) submitted directly through the CARM portal.
What it means in practice: Most importers rarely submit transactions directly — brokers do the filing. But if you've ever logged in and filed a payment, posted a security amount, or submitted a ruling request, this rule determines whether your broker can see those actions.
Why it matters: Enabling this gives your broker visibility into your direct actions. If you're handling something your broker shouldn't see (like an internal audit, an exploratory ruling request, or a communication with CBSA about a broker change), you might want this disabled.
Visibility Rule 3: Submitted by Other Business
When enabled, the service provider sees transactions submitted by other brokers or other business relationships you have.
What it means in practice: If you use multiple brokers, this is how you control whether each broker can see the others' work. If Broker A is enabled to see "Submitted by Other Business," Broker A sees the transactions Broker B filed.
Why it matters: There are scenarios where you want brokers to see each other's work (coordinating on complex shipments, ensuring consistency across product lines). There are also scenarios where you don't (brokers competing for your business, confidentiality between programs, switching brokers mid-year).
How to structure delegation for common scenarios
Here are recommended setups for the most common import business structures.
Scenario 1: Single broker, simple business
You have one broker handling all your shipments. You don't want complications.
Setup:
- Assign one or two internal BAMs (yourself, plus a backup)
- Delegate pBAM role to your broker (business management level)
- Visibility: all three rules enabled (they see everything)
- Result: Your broker has full operational authority and visibility, which simplifies their work. You retain BAM-level control to revoke anytime.
Scenario 2: Primary broker + secondary specialty broker
You use Broker A for 80% of your shipments and Broker B for a specific product line or country.
Setup:
- Internal BAM (you) at the business level
- Broker A as pBAM (business management level) with all three visibility rules enabled
- Broker B as pPAM (program level) with only "Submitted by Customs Broker" enabled (so Broker B only sees their own work)
- Result: Broker A has visibility into everything, Broker B only sees their own shipments. Broker A can coordinate when needed; Broker B doesn't see unrelated transactions.
Scenario 3: Multi-division company with separate import programs
Your company has multiple RM accounts for different divisions. Each division has its own broker.
Setup:
- Internal BAM at the business level
- Internal PAM for each division (managing their own program)
- Each division's broker as pPAM (program level) with visibility only to their program
- Result: Clean separation by division. Each broker only sees their assigned program. Divisional PAMs manage their own program's access.
Scenario 4: Non-resident importer with Canadian broker
You're a US or foreign company registered as a non-resident importer, using a Canadian broker to handle clearance.
Setup:
- Internal BAM: someone at your US office authorized to manage Canadian customs (often a logistics manager or operations director)
- Your Canadian broker as pBAM with all three visibility rules enabled
- Result: Your broker operates the portal on your behalf; you maintain oversight. Because NRI operations often run on tight documentation, full broker visibility usually makes sense.
Scenario 5: Switching brokers mid-year
You're moving from Broker A to Broker B. Both need access during the transition.
Setup during transition:
- Keep Broker A as pBAM with current visibility
- Add Broker B as pPAM initially with minimal visibility
- Once transition is complete, elevate Broker B to pBAM and reduce or remove Broker A's access
- After final transition, revoke Broker A's relationship entirely
Why: Gradual transition prevents coverage gaps while shipments are in flight. Both brokers can access what they need to during the handover without either having unnecessary access after the handover completes.
How to grant delegation in the CARM portal
The technical steps to delegate:
Step 1: Your broker initiates the request
The broker logs into their own CARM portal account and submits a business relationship request to your business. They'll typically need your 9-digit Business Number (BN9) and your RM account number to identify you in the system.
Step 2: You receive a notification
In your CARM portal, the request appears under "Manage Pending Third-Party Requests" on the home page (under "Most requested"). You can also access it via "Setup my portal" → "Manage business relationships."
Step 3: Review the details
Before accepting, click to view the request details. The broker may have included comments about what access they're asking for and why. Review this — especially for relationships with new brokers or where access levels aren't explicitly discussed.
Step 4: Select the role
Choose whether to grant pBAM (business management) or pPAM (program management). For most single-broker setups, pBAM is appropriate. For secondary brokers or specialty relationships, pPAM.
Step 5: Set visibility rules
For each of the three visibility rules, select enable or disable. Remember: "Submitted by Customs Broker" is always enabled. The other two are optional.
Step 6: Review the access summary
Before approving, the portal shows a summary of exactly what access the broker will have. Read this carefully. Verify that the role and visibility rules match what you intended. Adjustments are made here, not after.
Step 7: Approve
Click Approve. The broker is immediately notified via the CARM portal that their relationship request has been granted, and they can begin transacting on your behalf.
The CBSA Delegation of Authority (DOA) report
After completing your delegation setup, your broker can request a Delegation of Authority report from CBSA. This report confirms the current state of delegation on your account — who has access, what role, and what visibility rules.
How to use it:
Once your broker has requested and received the DOA report, ask them to share it with you. Verify that it matches what you intended to grant. If there's a discrepancy (for example, visibility rules that look different than what you selected), go back into the portal and correct it.
Important caveat: The DOA report can only be requested once by each broker. After the first request, the broker cannot re-request a fresh version directly — CBSA retains the record, but the broker's portal view is what they'll rely on going forward.
Our recommendation: Request the DOA report immediately after completing delegation setup. Treat it as verification that your intentions were captured correctly in the system.
Common mistakes in delegation
Based on CBSA guidance and industry practice, these are the mistakes that create problems.
Mistake 1: Giving every broker full pBAM with all visibility
The convenient setup is "give my broker everything." This works if you have one broker. With multiple brokers, it creates conflicts: each broker sees the others' work, which may or may not be appropriate. In competitive broker scenarios (you're evaluating whether to switch), this can be awkward.
Better approach: Designate one broker as pBAM with full visibility, others as pPAMs with limited visibility. Elevate access on an as-needed basis.
Mistake 2: Not assigning a second BAM
If your sole BAM leaves the company or becomes unavailable, you may be locked out of your own CARM portal until you go through CBSA's account recovery process. This can take weeks.
Better approach: Always assign at least two internal BAMs. Ensure both understand their responsibilities and know how to access the portal.
Mistake 3: Delegating at the business level when program-level is appropriate
If you have multiple RM accounts with different operational setups, granting full pBAM to one broker means they see everything. For companies with sensitive divisional separations, this isn't ideal.
Better approach: Use pPAM at the program level for brokers who only need access to specific programs.
Mistake 4: Not updating delegation after operational changes
Broker changes. Employee changes. Division restructurings. Any of these can leave stale delegation in place — old brokers retaining access, former employees still holding roles.
Better approach: Quarterly review of delegation. Revoke stale access. Update roles as people move.
Mistake 5: Conflating delegation with power of attorney
Delegation in the CARM portal is not a General Agency Agreement (GAA) or a legal power of attorney with your broker. It's an access grant. Your broker still needs a proper GAA under separate contract to represent you for customs purposes in a binding way.
Better approach: Ensure you have both a current GAA with your broker (legally authorizing them to act on your behalf for customs purposes) AND appropriate portal delegation. The two are complementary but legally distinct.
Mistake 6: Letting the broker drive the delegation choices
Brokers will often suggest "give us pBAM with all visibility" because it simplifies their work. This may or may not be appropriate for your business.
Better approach: Think through your operational needs before the broker submits the request. Come to the approval decision with your own view, not theirs.
Mistake 7: Not revoking access after a broker relationship ends
When you stop working with a broker, you need to actively revoke their portal access. It does not expire automatically. Until you revoke, the broker technically retains visibility into whatever you granted.
Better approach: Revocation is the first step in broker offboarding. Do it the day the relationship ends, before the new broker is even set up.
How to revoke or change delegation
Revocation is straightforward and can be done at any time.
Steps to revoke:
- Log into the CARM Client Portal as BAM or the relevant PAM
- Navigate to "Setup my portal" → "Manage business relationships"
- Find the service provider you want to revoke
- Click to edit or remove
- Confirm the revocation
The service provider is immediately notified that their access has been removed. They can no longer transact on your behalf, access your information, or see your transaction history (except for transactions they previously submitted, which they retain read access to for their own records).
Changes to role or visibility:
Same process as revocation, but instead of removing, you edit the role and visibility settings. Changes take effect immediately.
What you lose when you revoke:
You don't lose anything — all historical transactions, CADs, SOAs, and documents remain in your CARM portal. Only the broker's ability to take future actions is removed.
How delegation intersects with Section 17 liability
Section 17 of the Customs Act, as amended effective January 1, 2026, makes the importer of record jointly and severally liable with the owner for duties and taxes. Delegation of authority to a broker does not transfer this liability.
What this means:
- Your broker files CADs on your behalf using your business number
- You are named as importer of record on every CAD
- You are personally liable for classification accuracy, value for duty, and origin under Section 17
- If CBSA reassesses three years later, the liability comes to you — not the broker
Implications for delegation:
Since the broker's authority is delegated (not absolute), you retain the right and the responsibility to review their work. "Reasonable care" under customs law — the defense an importer raises against penalties — requires documented processes showing you oversaw the broker's filings. Delegation doesn't shield you from Section 17; it just means you outsourced the clicking.
In practice, this means:
- Review every CAD your broker files on your behalf (accessible in transaction history)
- Maintain documentation proving you reviewed classifications
- Ask questions when classifications look unusual
- Request copies of supporting documents (commercial invoices, certificates of origin) that the broker relied on
- Keep a paper trail that, if CBSA audits in 2028, shows you were paying attention
The broader compliance picture
Delegation is the starting point, not the ending point. Once you've granted appropriate access, the operational work begins.
Monthly:
- Review the Statement of Account on the 25th
- Reconcile against the broker's invoice
- Identify any classification discrepancies or missed preferential rates
- Respond to any flags within the correction window
Quarterly:
- Review delegation status
- Confirm access levels are still appropriate
- Verify no stale permissions remain
- Request updated DOA report if new brokers have been added
Annually:
- Broker relationship review
- Update any legal names or registration changes on CAD-relevant documents
- Refresh financial security calculations in CARM
- Review your import activity against CBSA verification priority lists for upcoming year
How ClearBorder helps
Delegation correctly sets up who can access your CARM portal. Once that's done, the ongoing work of reviewing what your broker files, reconciling against your broker's invoice, and building your Section 17 defense file is where ClearBorder comes in.
ClearBorder reads the CADs filed under your business number, flags classification discrepancies, identifies missed preferential rates, reconciles your SOA against your broker's invoice, and generates the paper trail you need under Section 17 — all based on the access your delegation granted.
You can try it on your own data for free. Upload a month's worth of CADs, your SOA, and broker invoice, and get back a full report in about 60 seconds. No signup required to generate the report.
The bottom line
Delegation of authority is not a procedural step to rush through. It determines:
- Who can act on your CARM account
- What each party can see
- How much you can revoke if relationships change
- How well you can build a Section 17 compliance record
The setup that seems most convenient (give your broker full access, approve quickly) is often the wrong setup for complex businesses. The setup that takes 20 minutes to think through — which internal roles, which broker at which level, which visibility rules — is the setup that protects you when relationships change, when CBSA audits, or when operational priorities shift.
For most single-broker, mid-volume importers, pBAM with full visibility is the right starting point. For multi-broker or multi-division businesses, the layered approach (pBAM for primary, pPAM for secondary, program-level restrictions where appropriate) is cleaner. Whatever the structure, review it quarterly and revoke access the day a relationship ends.
The broker keeps doing the work. Delegation just formalizes the access. You keep the control.
Sources and references:
- CBSA Memorandum D17-1-5: Registration, Accounting and Payment for Commercial Goods
- CARM Client Portal User Guide: Delegation of Authority in the CARM Client Portal
- Customs Act, Section 17(3) (amended January 1, 2026)
- CBSA Customs Notice 24-27: CARM October Implementation – Transition Measures
- CBSA Customs Notice 25-32: End of CARM Transition Measures and Coming Into Force of Importer of Record Changes
- CARM User Guide: How to Set Up a Delegation of Authority for a Third Party Service Provider
This article is not legal advice. For specific business situations, consult a licensed Canadian customs broker.
Try ClearBorder
Once delegation is set up, see what your broker actually files. ClearBorder pulls every CAD from your CARM portal and shows you a monthly review.