Skip to main content

How agency roles and permissions combine

What each agency role grants, how a client's ceiling combines with each agency member's own role, and the rules that always apply.

Written by Daniel

When a client connects an agency, two things decide what each person at the agency can actually do: the access the client granted (the ceiling), and that person's own role on the agency's team. This article explains how they combine.

The ceiling: what the client grants

The client picks one or more roles for the agency as a whole. This is the most anyone at the agency can do on the client's team:

Role

What it allows

Team Admin

Full team and site management, including deleting sites. No billing access.

Team Member

See all sites and create new ones.

Billing

Billing access only, no site access. Only the client team's owner can grant or remove this.

Collaborator

Access limited to the specific sites the client picks.

Roles are additive: granting Collaborator with three sites plus Billing means the agency can manage billing across the team and work on those three sites.

Each person gets the lesser of the two

Every person at the agency gets the overlap between the ceiling and what they can already do on the agency's own team. The client's grant is the maximum; a person's own role can only narrow it, never widen it.

Some examples:

Client granted the agency

Person's role at the agency

What that person gets on the client's team

Team Admin

Owner or Team Admin

Team Admin

Team Admin

Team Member

Team Member

Team Member

Team Admin

Team Member (the ceiling caps them)

Billing

Owner or Billing

Billing

Billing

Team Member

Nothing (their own role has no billing access)

Collaborator (3 sites)

Team Member

Those 3 sites

Anything

Collaborator

Nothing automatically (see below)

Collaborators at the agency: opt-in per site

People who are Collaborators on the agency's own team never get client access automatically. The agency opts them into individual client sites from that person's Site Access page. If the client granted Collaborator access with a site list, the agency can only opt people into sites on that list.

Rules that always apply

  • Team management never crosses the boundary. No one at the agency can see, invite, or remove members of the client's team, whatever the ceiling says.

  • The client's two-factor policy governs. If the client's team requires 2FA, agency staff without it have no access to that client until they enable it.

  • Direct membership wins. If someone was invited to the client's team individually, that direct membership applies instead of the agency connection, and it survives if the connection ends.

  • Changes are immediate. When the client edits the agency's access or disconnects, or the agency disconnects, access changes on the very next page load. The agency is emailed when their access changes.

  • Attribution is asymmetric on purpose. The client's Activity Log shows the agency's name; the agency's own view shows the individual who did the work. Clients never see agency staff details.

Need help?

Message us from the Console any time. Our support team responds within our one-hour SLA.

Related articles

Did this answer your question?