The practical answer
IRIS uses organization roles to describe the filing business and individual roles to describe authorized people. Build the roster around real business authority, application maintenance, and day-to-day filing support, then verify the required participant counts.
A software developer, an application administrator, and a person answering a filing question are not necessarily the same person. This guide helps an organization applying or updating access in September 2026 assign the appropriate people without confusing job titles with IRS roles.
Separate the business's role from the person's role
At the organization level, an Issuer transmits its own information returns, a Transmitter sends returns for businesses including others, and a Software Developer creates software that interfaces with IRIS A2A. The application does not allow Issuer and Transmitter to be selected together. Publication 5903, Application Details.
At the individual level, the roster uses Responsible Official, Authorized Delegate, and Contact. A person's title in your company does not automatically select the right application role. An IT administrator might support sign-in problems without having authority to act as an RO.
Write two separate statements: what the organization will do, and what each person needs to do. This prevents a common planning mistake where “our software person” is assigned every role even though the work includes executive authority, account maintenance, and operational response.
For direct A2A, check the identifier arrangement as well. Publication 5718 requires the Issuer role's transmitter and issuer identifiers to match the EIN on the application; it directs a sole proprietor filing under an SSN to select Transmitter. A broad description such as “our own returns” does not resolve that special case. Publication 5718, section 1.3.2 and TCC role table.
Check the business-structure exception carefully
Under current IRM 3.42.9.7, the general requirement is at least two ROs and two Contacts. For a sole proprietor, S-corporation, or single-member LLC/disregarded entity, it specifies one RO and at least one Contact. Up to two ADs are optional; the contact maximum is 250. Current IRS role-count rules.
Use the correct business structure in the application. Do not choose an exception merely because only one employee is available. If your legal structure or the live application behavior is unclear, resolve that with the IRS before finalizing the roster.
The December 2024 tutorial has inconsistent older wording on its authorized-users page. This guide uses the current IRM for counts and the S-corporation exception. The IRS's December 2024 working-group update also documents the introduction of the S-corporation selection.
Record readiness and coverage for each person
Build a row for each individual with their proposed role, business authority or operational responsibility, sign-in readiness, and availability. Keep sensitive personal information out of the general roster. Link to the controlled collection process when application details still need to be gathered.
For every recurring activity, identify a responsible person and a continuity plan. Who updates a business phone number? Who coordinates a change in Responsible Officials? Who answers a transmission question when the main payroll contact is absent? Make the plan consistent with the permissions each role actually has.
Do not solve coverage gaps by sharing an account. A second worker should use their own authorized access appropriate to their responsibilities. This also makes a staff handoff easier because the organization can distinguish one person's access from another's.
Worked example: maintenance and authority are different jobs
Fictional example. Summit Example Corporation has two executives with responsibility for the business, an operations manager who maintains filing access, and a payroll specialist who handles return questions. The company is not using one of the single-RO exceptions.
| Person | Proposed application role | Operational task |
|---|---|---|
| Executive A | RO and Contact | Initial review/signature and escalation |
| Executive B | RO | Initial review/signature and RO continuity |
| Operations manager | AD | Permitted updates after completion |
| Payroll specialist | Contact | Daily filing questions |
When Executive B later leaves, the operations manager cannot use AD authority to replace that RO. The company routes the change to an appropriate RO and verifies the resulting application state. That permission boundary should be documented before the handoff becomes urgent.
The example demonstrates role design. It does not establish that a real individual qualifies or that the illustrated application has been approved.
Review the roster at application and staff changes
Before the initial submission, confirm that the listed ROs can perform their required steps. After approval, check that every operational contact can reach the workflow they need and knows how to escalate a problem. Keep the application roster and the internal responsibility sheet aligned.
When someone changes jobs, review what they actually owned: application administration, return preparation, transmission support, or filing-outcome follow-up. Transfer the work and update the appropriate authorization separately. A successor inheriting a task does not automatically inherit access.
Record the date the roster was checked, what changed, and which follow-up remains. A periodic review can help catch drift, but a known staff change should trigger action when it occurs. Use the companion maintenance guide for a fuller handoff checklist.
Three responsibility lanes in an IRIS access roster
Read the workflow as text
- Business authority: RO. Own the initial application and decisions requiring RO authority.
- Account administration: AD. Maintain permitted details after completion; route RO changes to an RO.
- Filing support: Contact. Handle operational questions using authorized individual access.
- Coordinator cross-check. Match each task to a permitted role, available person, and continuity plan.
Put this guide to work
IRIS participant roster and responsibility matrix
Save the editable text worksheet and use it with your own records. Keep completed copies in your secure working files.
Download the worksheet TXTCommon questions
Is a Software Developer the same as an Authorized Delegate?
No. Software Developer is an organization role describing the software business. Authorized Delegate is an individual role for permitted application maintenance.
Can a Contact change the application?
The Contact role alone does not provide application access. Assign maintenance work to an appropriately authorized RO or AD.
Can an Authorized Delegate replace a Responsible Official?
No. The current authority rules reserve RO management to an RO. Build that dependency into staff-handoff planning.
Can one person be both an RO and a Contact?
Yes, the roles can be combined as permitted by the application. Keep the duties clear in the internal roster even when the same individual performs them.
Should we select a single-person business structure for convenience?
No. Select the organization's actual structure and satisfy the applicable participation rule. Resolve uncertainty about the structure or live application with the IRS.
Official sources and scope
Sources checked September 5, 2026. Use the edition for the tax year and filing method you are working with; later instructions may change thresholds, fields, or procedures.
- IRS IRM 3.42.9.7, effective January 1, 2026
Current individual authorities, participant counts, exceptions, and role combinations.
- IRS Publication 5903, Rev. December 2024
Organization-role distinctions and application context; current IRM used for inconsistent participant limits.
- IRS IRIS working-group meeting, December 11, 2024
S-corporation business-structure selection introduced December 9, 2024.
- IRS Publication 5718, processing year 2026
A2A Issuer identifier matching and sole-proprietor SSN role distinction.