utm_source, utm_medium, utm_campaign,
utm_term, utm_content — on a member’s seat. For a locked parameter, that member may only use a
value that is already approved; they can never coin a new one.
Locks apply to the member role only. Owners and admins are never locked, and a viewer cannot
create links in the first place. See Members and roles.
Setting a lock
Locks are set on the Members page, https://app.utmkit.co/members, by anyone who may manage members. A member’s row carries “Locked to approved values:” with one checkbox per parameter; tick the ones to lock. An owner’s or admin’s row shows no checkboxes, because there is nothing to lock. The change takes effect at once: any page the member has open reconnects with the new locks in force. It is recorded in the activity log with the list before and after. When a member’s role changes to owner, admin or viewer, their locks are cleared in the same change, and a seat demoted to member starts unlocked.What a locked member sees
1
In the console link form
A locked parameter is not a text box. It is a choice among the approved values, with “leave
empty” first. If nothing is approved for that parameter yet, the field says so and cannot be typed
into.
2
Everywhere else
In the assistant, through the API or through an MCP tool, a value outside the library is refused
with one sentence: utm_source ‘facebook’ is locked for you in this workspace: you may only use an
approved value. The approved values are: ‘newsletter’, ‘partner’. If the parameter has no
approved value at all, the sentence says to leave it out or ask an administrator to approve one.
What the lock checks
The lock is checked on the final values a link would carry, so nothing gets around it:- A value the member typed.
- A value filled in from a preset.
- A
utm_campaignderived from a campaign’s name, when the member typed none.
utm_source predates the library, as long as they leave that value
alone. Clearing a locked parameter is always allowed; an empty value adds nothing to the taxonomy.
Locks constrain link writes only. A locked member still sees everything an unlocked member sees:
the report, the exports, the rules. A member’s own API token carries their locks, so a request
with it is refused exactly as the person would be.