Managing User Access in Your CRM
Understanding User Access Management
Controlling who can access your CRM is essential for maintaining security, operational efficiency, and clear accountability. This guide explains how to manage user access at both the agency level (across all client accounts) and the sub-account level (within specific client accounts), including the various user attributes and permissions you can configure.
Agency Team Management
Who Should Use This
This section is for agency owners or administrators who need to grant access to employees or client personnel across multiple client accounts.
How to Access
Navigate to Settings from the side menu while in Agency View, then select Team.
What You Can Do
From the Team section, you can add new users, edit existing users, or remove users. When adding or editing a user, you can configure:
- Personal logo (for user profile)
- First name
- Last name
- Email address (used for login)
- Phone number
- Password
- Permissions (refer to the user roles and permissions article for details)
- User Type — choose between:
- Agency: User can access all client accounts under the agency
- Account: User can access only selected client accounts
- Account assignment:
- If Agency type is selected, specify which client accounts the user receives notifications for
- If Account type is selected, choose the specific client accounts the user can access
Login As Permission
The ability to log in as another user is controlled by permissions. When Enable Login As is turned off for a user, the option is hidden. This setting is found under Agency Settings › Team › Edit user › Roles & Permissions › User Management.
Team Management (Sub-Account Level)
Who Should Use This
This is used by clients or team members within a specific client’s CRM account. Users added here will also appear in Agency Team Management.
How to Access
Switch to the relevant sub-account. In the side navigation, go to Settings, then click My Staff.
What You Can Do
Similar to agency-level management, you can add, edit, or delete users. For each user, you can modify:
- Personal logo
- First name
- Last name
- Email (login)
- Phone number
- Password
- Permissions (refer to the user roles and permissions article for sub-accounts)
- Assigned data
Automatic personal booking calendar creation for new sub-account users depends on the agency-level Preloaded Example Data setting in Settings > Company.
Permissions & Roles Overview
You can precisely control what a user can do by assigning roles or permission scopes. These determine which parts of the CRM the user can access (such as marketing tools, settings, or campaigns), what actions they can perform (view, edit, delete), and which accounts their access applies to.
Email Change Verification (Multi-Channel OTP)
Changing a user’s login email is a sensitive action. The CRM supports multi-channel OTP verification to confirm identity even if the existing email is inaccessible.
Available Verification Methods
- Email OTP
- Phone (SMS) OTP
- TOTP (Authenticator app)
The verification options shown depend on the user’s verified two-factor authentication methods.
When You Change Your Own Email
The system prompts you to verify using another available two-factor method (such as SMS or an authenticator app). If no other verified method is available, you are prompted to set up an authenticator app.
When an Admin Changes Another User’s Email
The system displays all available verification methods for that user (Email, SMS, and/or Authenticator app).
Best Practices
- Least Privilege Principle: Grant users only the permissions they need. Avoid providing full agency access unless absolutely necessary. Use Account-type users for limited access roles.
- Track Changes: Maintain clear records of user access and modifications to assist with audits or troubleshooting.
- Review Access Periodically: Regularly update permissions or remove users who no longer require access as roles change.
Frequently Asked Questions
Q: What’s the difference between “Agency” user type and “Account” user type?
A: An Agency user type provides access to all client accounts under your agency. An Account user type limits access to only the client accounts you explicitly select.
Q: If I add a user under “My Staff” in a sub-account, will they appear in Agency Team Management?
A: Yes — all users added in sub-accounts (“My Staff”) are also visible under the Agency’s Team list.
Q: Can I set different permission levels for different users?
A: Yes. The permissions settings allow you to control exactly which features and actions each user can use.
Q: How do I change someone’s access later if their role changes?
A: Go to the relevant user record (in Agency Team or My Staff), and edit their user type, assigned accounts, or permissions as needed.