Understanding Agency and Sub-Account User Roles
Understanding User Roles and Permissions
Your CRM platform uses a tiered permission system, separating agency-level controls from sub-account-level access. This structure helps you manage who can perform specific actions within your agency's main account and its individual client or business sub-accounts.
Permission Overview
Permissions are grouped by the level at which they are available: Agency-Only, Sub-Account-Only, or Available in Both. The following list provides a high-level overview of common permissions and their typical scope.
- Agency-Only Permissions: These are managed at the top agency level.
- Create, edit, or delete sub-accounts.
- Manage SaaS mode and reselling configurations.
- Control agency-level billing and branding.
- Adjust white-label settings like custom domains, logos, and colors.
- Configure agency-wide settings for company information and rebilling.
- Sub-Account-Only Permissions: These apply only within a specific sub-account.
- Manage pipelines and opportunities.
- Handle conversations (SMS, email, chat).
- Use the funnel and website builder.
- Manage contacts and smart lists.
- Configure reputation management tools.
- Permissions Available in Both Scopes: These can be managed at either level, but the scope of control differs.
- User Management: Admins can add or edit users, but only within their assigned level (agency or sub-account).
- Workflows & Campaigns
- Dashboard Reporting
- Global Integrations (e.g., for email, SMS, and calendar services).
- Calendars & Appointment Settings
- Media Library
- Snapshot Management
- Audit Logs
If a specific permission is not listed for a sub-account role, it typically inherits the default capabilities from the broader agency-level role it is based on.
Managing User Roles
To change a user's role, navigate to Settings, then select My Staff. Click the edit (pencil) icon next to the user's name. Scroll to and expand the User Roles section to assign or modify their agency and sub-account permissions.
Frequently Asked Questions
If a permission exists at both levels, does the Agency Admin override the Sub-Account Admin?
Yes. Agency Admins have global authority. For permissions like user management, reporting, or media library access, an Agency Admin's actions apply across all sub-accounts. A Sub-Account Admin's control is limited to users, data, and settings within their specifically assigned sub-account.
What if a user has both an Agency role and a Sub-Account role?
The user will operate with two separate permission scopes. They will have agency-wide access granted by their Agency role, plus additional, specific access within the sub-account from their Sub-Account role. Permissions are additive and do not cancel each other out. In any case of overlap, the broader agency-level permissions take precedence.
Do all Agency Admins have the "Login As" feature?
No. The "Login As" feature is controlled by a specific Enable Login As permission at the agency level. If this permission is disabled for a particular admin user, the Login As option will not be visible or available to them in the interface.