When a client connects an agency, two things decide what each person at the agency can actually do: the access the client granted (the ceiling), and that person's own role on the agency's team. This article explains how they combine.
The ceiling: what the client grants
The client picks one or more roles for the agency as a whole. This is the most anyone at the agency can do on the client's team:
Role | What it allows |
Team Admin | Full team and site management, including deleting sites. No billing access. |
Team Member | See all sites and create new ones. |
Billing | Billing access only, no site access. Only the client team's owner can grant or remove this. |
Collaborator | Access limited to the specific sites the client picks. |
Roles are additive: granting Collaborator with three sites plus Billing means the agency can manage billing across the team and work on those three sites.
Each person gets the lesser of the two
Every person at the agency gets the overlap between the ceiling and what they can already do on the agency's own team. The client's grant is the maximum; a person's own role can only narrow it, never widen it.
Some examples:
Client granted the agency | Person's role at the agency | What that person gets on the client's team |
Team Admin | Owner or Team Admin | Team Admin |
Team Admin | Team Member | Team Member |
Team Member | Team Admin | Team Member (the ceiling caps them) |
Billing | Owner or Billing | Billing |
Billing | Team Member | Nothing (their own role has no billing access) |
Collaborator (3 sites) | Team Member | Those 3 sites |
Anything | Collaborator | Nothing automatically (see below) |
Collaborators at the agency: opt-in per site
People who are Collaborators on the agency's own team never get client access automatically. The agency opts them into individual client sites from that person's Site Access page. If the client granted Collaborator access with a site list, the agency can only opt people into sites on that list.
Rules that always apply
Team management never crosses the boundary. No one at the agency can see, invite, or remove members of the client's team, whatever the ceiling says.
The client's two-factor policy governs. If the client's team requires 2FA, agency staff without it have no access to that client until they enable it.
Direct membership wins. If someone was invited to the client's team individually, that direct membership applies instead of the agency connection, and it survives if the connection ends.
Changes are immediate. When the client edits the agency's access or disconnects, or the agency disconnects, access changes on the very next page load. The agency is emailed when their access changes.
Attribution is asymmetric on purpose. The client's Activity Log shows the agency's name; the agency's own view shows the individual who did the work. Clients never see agency staff details.
Need help?
Message us from the Console any time. Our support team responds within our one-hour SLA.
Related articles