Broker Relationships

CARM Delegation of Authority: How to Set Up Your Broker Without Giving Away Control

A practical guide for Canadian importers and BAMs on the delegation of authority process in the CARM Client Portal — user roles, visibility rules, multi-broker setups, and the common mistakes that hand brokers too much access.

17 min read · May 18, 2026 · by ClearBorder

If you've just registered your business in the CARM Client Portal and now your broker is asking you to "accept the delegation request," you're at one of the most consequential setup moments in the CARM process. The access you grant shapes everything that comes after — how much visibility your broker has, which transactions they can see, who else can act on your account, and how easily you can revoke access if the relationship changes.

Most importers click "Approve" without understanding what they're approving. That's a mistake.

This article covers the CARM delegation of authority process in depth: the five available roles, the three visibility rules, how to structure access across multiple brokers, how to add internal team members, how to revoke access, and the specific mistakes that create operational and compliance risk.

The basic structure: two types of users, two types of relationships

Before getting into the mechanics, understand the framework.

The CARM Client Portal distinguishes between:

Internal users — employees of the importer's own business (yours). These are people at your company who need access to the portal. Roles: Business Account Manager (BAM), Program Account Manager (PAM), Editor, Reader.

Third-party service providers — external entities you've authorized to act on your behalf. Typically customs brokers, occasionally trade consultants. Roles: Proxy Business Account Manager (pBAM), Proxy Program Account Manager (pPAM).

The importer (you) always retains ultimate control. Delegation is a grant of access, not a transfer of authority. You can revoke delegation at any time from the "Manage business relationships" section of the portal.

The five roles explained

The CARM portal supports five distinct roles. Understanding what each one can and cannot do is critical to setting up delegation correctly.

Business Account Manager (BAM)

Who gets it: The person who first registers the business in CARM automatically becomes BAM. Typically this is the business owner, a supply chain manager, or a designated operations lead. CBSA strongly recommends assigning at least two BAMs so the business isn't locked out if one person leaves.

Access level: Full access to everything in the business account. The BAM operates at the BN9 (business number) level, which covers all of the company's program accounts (RM0001, RM0002, etc.).

What the BAM can do:

Who this role is for: The person ultimately accountable for your company's customs compliance. Under Section 17 of the Customs Act (in force since January 1, 2026), the BAM is often the person personally exposed to reassessment liability — so this role should go to someone senior enough to take that responsibility seriously.

Program Account Manager (PAM)

Access level: Full access to specific program accounts (RM-level), but not the full business account.

What the PAM can do:

Who this role is for: Middle management responsible for a specific import program or division. If your company has multiple RM accounts (for different business divisions, different product lines, or different countries of operation), each PAM can manage their own program without seeing other programs' data.

Editor

Access level: Can perform specific operational tasks within a program, but cannot manage other employees' access.

What the Editor can do:

What they cannot do:

Who this role is for: Day-to-day operational staff who handle specific customs tasks but shouldn't control account access.

Reader

Access level: View-only access to a specific program or the whole account.

What the Reader can do:

What they cannot do:

Who this role is for: Finance staff, bookkeepers (if they're employees), auditors, or anyone who needs visibility but shouldn't change anything.

Proxy Business Account Manager (pBAM)

Who gets it: A third-party service provider that you've designated at the business management level. Typically this is your primary customs broker.

Access level: Near-full access to the business account, with two specific exclusions.

What the pBAM cannot do:

  1. Access the client's sensitive information (like bank account details for payments)
  2. See or manage the client's employees or internal business relationships

What the pBAM can do:

Who this role is for: Your primary customs broker. This is the right role if you want your broker to have broad operational authority across all your import programs, without giving them access to your internal employee management or bank account information.

Proxy Program Account Manager (pPAM)

Who gets it: A third-party service provider designated at the program level rather than the business level.

Access level: Near-full access to specific program accounts assigned, but not to the full business account.

Who this role is for: Secondary brokers handling a specific product line or geography, or trade consultants handling only certain programs. If you have a primary broker handling 80% of your shipments and a specialty broker for a specific chapter, the primary is your pBAM and the specialty is a pPAM.

The three visibility rules

Beyond assigning a role, you control what each service provider can see through three specific visibility attributes.

Visibility Rule 1: Submitted by the Customs Broker

When this rule is set, the service provider sees transactions they themselves submitted. This is the default and the minimum — every broker can always see their own work.

What it means in practice: If Broker A files a CAD on your behalf, Broker A can see that CAD. They cannot see CADs filed by other brokers unless you enable additional visibility.

Visibility Rule 2: Submitted by the Client

When enabled, the service provider sees transactions the importer (you) submitted directly through the CARM portal.

What it means in practice: Most importers rarely submit transactions directly — brokers do the filing. But if you've ever logged in and filed a payment, posted a security amount, or submitted a ruling request, this rule determines whether your broker can see those actions.

Why it matters: Enabling this gives your broker visibility into your direct actions. If you're handling something your broker shouldn't see (like an internal audit, an exploratory ruling request, or a communication with CBSA about a broker change), you might want this disabled.

Visibility Rule 3: Submitted by Other Business

When enabled, the service provider sees transactions submitted by other brokers or other business relationships you have.

What it means in practice: If you use multiple brokers, this is how you control whether each broker can see the others' work. If Broker A is enabled to see "Submitted by Other Business," Broker A sees the transactions Broker B filed.

Why it matters: There are scenarios where you want brokers to see each other's work (coordinating on complex shipments, ensuring consistency across product lines). There are also scenarios where you don't (brokers competing for your business, confidentiality between programs, switching brokers mid-year).

How to structure delegation for common scenarios

Here are recommended setups for the most common import business structures.

Scenario 1: Single broker, simple business

You have one broker handling all your shipments. You don't want complications.

Setup:

Scenario 2: Primary broker + secondary specialty broker

You use Broker A for 80% of your shipments and Broker B for a specific product line or country.

Setup:

Scenario 3: Multi-division company with separate import programs

Your company has multiple RM accounts for different divisions. Each division has its own broker.

Setup:

Scenario 4: Non-resident importer with Canadian broker

You're a US or foreign company registered as a non-resident importer, using a Canadian broker to handle clearance.

Setup:

Scenario 5: Switching brokers mid-year

You're moving from Broker A to Broker B. Both need access during the transition.

Setup during transition:

Why: Gradual transition prevents coverage gaps while shipments are in flight. Both brokers can access what they need to during the handover without either having unnecessary access after the handover completes.

How to grant delegation in the CARM portal

The technical steps to delegate:

Step 1: Your broker initiates the request

The broker logs into their own CARM portal account and submits a business relationship request to your business. They'll typically need your 9-digit Business Number (BN9) and your RM account number to identify you in the system.

Step 2: You receive a notification

In your CARM portal, the request appears under "Manage Pending Third-Party Requests" on the home page (under "Most requested"). You can also access it via "Setup my portal" → "Manage business relationships."

Step 3: Review the details

Before accepting, click to view the request details. The broker may have included comments about what access they're asking for and why. Review this — especially for relationships with new brokers or where access levels aren't explicitly discussed.

Step 4: Select the role

Choose whether to grant pBAM (business management) or pPAM (program management). For most single-broker setups, pBAM is appropriate. For secondary brokers or specialty relationships, pPAM.

Step 5: Set visibility rules

For each of the three visibility rules, select enable or disable. Remember: "Submitted by Customs Broker" is always enabled. The other two are optional.

Step 6: Review the access summary

Before approving, the portal shows a summary of exactly what access the broker will have. Read this carefully. Verify that the role and visibility rules match what you intended. Adjustments are made here, not after.

Step 7: Approve

Click Approve. The broker is immediately notified via the CARM portal that their relationship request has been granted, and they can begin transacting on your behalf.

The CBSA Delegation of Authority (DOA) report

After completing your delegation setup, your broker can request a Delegation of Authority report from CBSA. This report confirms the current state of delegation on your account — who has access, what role, and what visibility rules.

How to use it:

Once your broker has requested and received the DOA report, ask them to share it with you. Verify that it matches what you intended to grant. If there's a discrepancy (for example, visibility rules that look different than what you selected), go back into the portal and correct it.

Important caveat: The DOA report can only be requested once by each broker. After the first request, the broker cannot re-request a fresh version directly — CBSA retains the record, but the broker's portal view is what they'll rely on going forward.

Our recommendation: Request the DOA report immediately after completing delegation setup. Treat it as verification that your intentions were captured correctly in the system.

Common mistakes in delegation

Based on CBSA guidance and industry practice, these are the mistakes that create problems.

Mistake 1: Giving every broker full pBAM with all visibility

The convenient setup is "give my broker everything." This works if you have one broker. With multiple brokers, it creates conflicts: each broker sees the others' work, which may or may not be appropriate. In competitive broker scenarios (you're evaluating whether to switch), this can be awkward.

Better approach: Designate one broker as pBAM with full visibility, others as pPAMs with limited visibility. Elevate access on an as-needed basis.

Mistake 2: Not assigning a second BAM

If your sole BAM leaves the company or becomes unavailable, you may be locked out of your own CARM portal until you go through CBSA's account recovery process. This can take weeks.

Better approach: Always assign at least two internal BAMs. Ensure both understand their responsibilities and know how to access the portal.

Mistake 3: Delegating at the business level when program-level is appropriate

If you have multiple RM accounts with different operational setups, granting full pBAM to one broker means they see everything. For companies with sensitive divisional separations, this isn't ideal.

Better approach: Use pPAM at the program level for brokers who only need access to specific programs.

Mistake 4: Not updating delegation after operational changes

Broker changes. Employee changes. Division restructurings. Any of these can leave stale delegation in place — old brokers retaining access, former employees still holding roles.

Better approach: Quarterly review of delegation. Revoke stale access. Update roles as people move.

Mistake 5: Conflating delegation with power of attorney

Delegation in the CARM portal is not a General Agency Agreement (GAA) or a legal power of attorney with your broker. It's an access grant. Your broker still needs a proper GAA under separate contract to represent you for customs purposes in a binding way.

Better approach: Ensure you have both a current GAA with your broker (legally authorizing them to act on your behalf for customs purposes) AND appropriate portal delegation. The two are complementary but legally distinct.

Mistake 6: Letting the broker drive the delegation choices

Brokers will often suggest "give us pBAM with all visibility" because it simplifies their work. This may or may not be appropriate for your business.

Better approach: Think through your operational needs before the broker submits the request. Come to the approval decision with your own view, not theirs.

Mistake 7: Not revoking access after a broker relationship ends

When you stop working with a broker, you need to actively revoke their portal access. It does not expire automatically. Until you revoke, the broker technically retains visibility into whatever you granted.

Better approach: Revocation is the first step in broker offboarding. Do it the day the relationship ends, before the new broker is even set up.

How to revoke or change delegation

Revocation is straightforward and can be done at any time.

Steps to revoke:

  1. Log into the CARM Client Portal as BAM or the relevant PAM
  2. Navigate to "Setup my portal" → "Manage business relationships"
  3. Find the service provider you want to revoke
  4. Click to edit or remove
  5. Confirm the revocation

The service provider is immediately notified that their access has been removed. They can no longer transact on your behalf, access your information, or see your transaction history (except for transactions they previously submitted, which they retain read access to for their own records).

Changes to role or visibility:

Same process as revocation, but instead of removing, you edit the role and visibility settings. Changes take effect immediately.

What you lose when you revoke:

You don't lose anything — all historical transactions, CADs, SOAs, and documents remain in your CARM portal. Only the broker's ability to take future actions is removed.

How delegation intersects with Section 17 liability

Section 17 of the Customs Act, as amended effective January 1, 2026, makes the importer of record jointly and severally liable with the owner for duties and taxes. Delegation of authority to a broker does not transfer this liability.

What this means:

Implications for delegation:

Since the broker's authority is delegated (not absolute), you retain the right and the responsibility to review their work. "Reasonable care" under customs law — the defense an importer raises against penalties — requires documented processes showing you oversaw the broker's filings. Delegation doesn't shield you from Section 17; it just means you outsourced the clicking.

In practice, this means:

The broader compliance picture

Delegation is the starting point, not the ending point. Once you've granted appropriate access, the operational work begins.

Monthly:

Quarterly:

Annually:

How ClearBorder helps

Delegation correctly sets up who can access your CARM portal. Once that's done, the ongoing work of reviewing what your broker files, reconciling against your broker's invoice, and building your Section 17 defense file is where ClearBorder comes in.

ClearBorder reads the CADs filed under your business number, flags classification discrepancies, identifies missed preferential rates, reconciles your SOA against your broker's invoice, and generates the paper trail you need under Section 17 — all based on the access your delegation granted.

You can try it on your own data for free. Upload a month's worth of CADs, your SOA, and broker invoice, and get back a full report in about 60 seconds. No signup required to generate the report.

The bottom line

Delegation of authority is not a procedural step to rush through. It determines:

The setup that seems most convenient (give your broker full access, approve quickly) is often the wrong setup for complex businesses. The setup that takes 20 minutes to think through — which internal roles, which broker at which level, which visibility rules — is the setup that protects you when relationships change, when CBSA audits, or when operational priorities shift.

For most single-broker, mid-volume importers, pBAM with full visibility is the right starting point. For multi-broker or multi-division businesses, the layered approach (pBAM for primary, pPAM for secondary, program-level restrictions where appropriate) is cleaner. Whatever the structure, review it quarterly and revoke access the day a relationship ends.

The broker keeps doing the work. Delegation just formalizes the access. You keep the control.


Sources and references:

This article is not legal advice. For specific business situations, consult a licensed Canadian customs broker.


Try ClearBorder

Once delegation is set up, see what your broker actually files. ClearBorder pulls every CAD from your CARM portal and shows you a monthly review.

Generate your free report →