Skip to content
Payments

Managing Granular Permissions for Payments

Control who can view, edit, refund, export, or configure Payments in GHL Customer Care. Learn category-level permissions, recommended role presets, and setup steps to stay secure.

7 min read1,585 words9 explained imagesUpdated Tue, 14 Oct, 2025 at 9:43 AM
View as markdownOpen in ClaudeOpen in ChatGPT
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.
On this page
  1. What is Granular Payment Permissions?
  2. Key Benefits of Granular Payment Permissions
  3. What’s New & Changed in Payments Permissions
  4. Orders Permissions
  5. Subscriptions Permissions
  6. Transactions Permissions
  7. Taxes Permissions
  8. Products Permissions
  9. Payment Settings Permissions
  10. How To Set Up Granular Payment Permissions
  11. Recommended Role Presets
  12. Frequently Asked Questions
  13. Related Articles

GHL Customer Care’s granular payment permissions let you delegate payment-related tasks safely by controlling exactly who can view, create, edit, refund, export, or configure each area of Payments. This guide defines every permission category, explains common role presets, and shows how to set up access the right way. Use it to speed up onboarding while protecting revenue operations and auditability.


TABLE OF CONTENTS


What is Granular Payment Permissions?

Granular payment permissions divide the former single Payments access into focused categories—Orders, Subscriptions, Transactions, Taxes, Products, and Payment Settings—each with standardized actions. This structure gives administrators precise control so teammates get only the access needed for their jobs without exposing sensitive operations.

Granular payment permissions are role-based access controls at the Location (sub-account) level that determine which users can View, Create, Update, Delete, Export, and Configure items across the Payments module. Administrators can combine categories to tailor access for support, accounting, fulfillment, and management teams.


Key Benefits of Granular Payment Permissions

Understanding the benefits helps you decide which actions to allow per team. The goal is to reduce risk without slowing down day-to-day work.

  • Minimize risk: Restrict high-impact actions (like refunds, product deletion, or tax configuration) to trusted users only.
  • Faster onboarding: Assign just the categories and actions each role needs so new hires can start safely.
  • Cleaner audits: Narrow permissions make it easier to trace who changed what and when using Audit Logs.
  • Operational clarity: Clear categories reduce confusion about where tasks live (e.g., refunds vs. order edits).
  • Workflow control: Bulk, import, and export capabilities may be restricted based on a user’s permissions, protecting data quality.

What’s New & Changed in Payments Permissions 

Understanding what changed from the previous single Payments toggle helps admins migrate confidently and set accurate expectations for staff. These updates streamline assignment, improve auditability, and reduce the risk of granting overly broad access.

  • Permissions re‑homed: Existing capabilities such as Refund Transactions and Manage Subscriptions now live inside their dedicated categories (Transactions and Subscriptions), making it easier to grant research access without refund rights, or subscription oversight without full payments access.
  • Standardized actions: Each category now uses a consistent action set — View, Create, Update, Delete, Export, Configure — so roles are simpler to compare, train on, and audit across Payments.
  • UI‑enforced dependencies: Certain high‑impact tools depend on foundational permissions. For example, bulk product actions and CSV imports require Create/Update access, preventing accidental multi‑record changes by read‑only users.
  • Tighter control of sensitive operations: Admins can explicitly decide who may issue refunds, edit subscriptions, or adjust tax settings, increasing financial control while preserving day‑to‑day efficiency.

Orders Permissions

Orders permissions govern one‑time orders and charges created through Payment Links, checkout pages, stores, and POS. Use these for teams that process orders and need read/export access, with editing reserved for responsible owners.

Orders Permissions (image 1 of 9) What this shows Orders permissions govern one‑time orders and charges created through Payment Links, checkout pages, stores, and POS. What this shows Illustrates the "Orders Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Orders Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Orders permissions govern one‑time orders and charges created through Payment Links, checkout pages, stores, and POS. Use these for teams that process orders and need read/export access, with editing reserved for responsible owners. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Recommended role fit: Fulfillment or support teams that need to look up orders, export lists, and perform limited adjustments. Image 1 of 9 What this coversOrders permissions govern one‑time orders and charges created through Payment Links, checkout pages, stores, and POS. Use these for teams that process orders and need read/export access, with editing reserved for responsible owners.
Fields in this part of the guide Getting Started — Sell Products
Next stepRecommended role fit: Fulfillment or support teams that need to look up orders, export lists, and perform limited adjustments.
All 2 steps in this procedure
  1. Create and Share Payment Links
  2. Getting Started — Sell Products

Recommended role fit: Fulfillment or support teams that need to look up orders, export lists, and perform limited adjustments.

Contextual links (for reference)


Subscriptions Permissions

Subscriptions permissions cover recurring billing lifecycles—creating plans, assigning subscriptions to contacts, pausing/resuming, canceling, and making updates like payment method changes. Grant these to roles responsible for subscription health and churn prevention.

Subscriptions Permissions (image 2 of 9) What this shows Subscriptions permissions cover recurring billing lifecycles—creating plans, assigning subscriptions to contacts, pausing/resuming… What this shows Illustrates the "Subscriptions Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Subscriptions Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Subscriptions permissions cover recurring billing lifecycles—creating plans, assigning subscriptions to contacts, pausing/resuming, canceling, and making updates like payment method changes. Grant these to roles responsible for subscription health and churn prevention. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Recommended role fit: Finance/Billing teams and Account Managers who own subscription health and retention; grant View to support and limit Create/Update/Cancel to designated owners. Image 2 of 9 What this coversSubscriptions permissions cover recurring billing lifecycles—creating plans, assigning subscriptions to contacts, pausing/resuming, canceling, and making updates like payment method changes. Grant these to roles responsible for subscription health and churn prevention.
Fields in this part of the guide Manage Customer Cards on File
Next stepRecommended role fit: Finance/Billing teams and Account Managers who own subscription health and retention; grant View to support and limit Create/Update/Cancel to designated owners.
All 2 steps in this procedure
  1. Create or Schedule Subscriptions
  2. Manage Customer Cards on File

Recommended role fit: Finance/Billing teams and Account Managers who own subscription health and retention; grant View to support and limit Create/Update/Cancel to designated owners.

Contextual links


Transactions Permissions

Transactions permissions apply to completed payments and refunds. These are sensitive because they allow refunding money and downloading official receipts, so keep tight control and separate “view” from “refund” when possible.

Transactions Permissions (image 3 of 9) What this shows Transactions permissions apply to completed payments and refunds. What this shows Illustrates the "Transactions Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Transactions Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Transactions permissions apply to completed payments and refunds. These are sensitive because they allow refunding money and downloading official receipts, so keep tight control and separate “view” from “refund” when possible. This part of the guide covers 2 fields, listed below. Immediately after, the guide continues: Recommended role fit: Billing Support for research (View/Export/Receipts) and Controllers/Accountants for refunds; restrict refund rights to finance leads only. Image 3 of 9 What this coversTransactions permissions apply to completed payments and refunds. These are sensitive because they allow refunding money and downloading official receipts, so keep tight control and separate “view” from “refund” when possible.
Fields in this part of the guide How to Manage Refunds within the CRMRefund Workflow Trigger
Next stepRecommended role fit: Billing Support for research (View/Export/Receipts) and Controllers/Accountants for refunds; restrict refund rights to finance leads only.
All 2 steps in this procedure
  1. How to Manage Refunds within the CRM
  2. Refund Workflow Trigger

Recommended role fit: Billing Support for research (View/Export/Receipts) and Controllers/Accountants for refunds; restrict refund rights to finance leads only.

Contextual links


Taxes Permissions

Taxes permissions control who can configure or adjust tax behavior, including manual rates and automatic tax calculation features. Because tax settings impact compliance, reserve these permissions for finance owners.

Taxes Permissions (image 4 of 9) What this shows Taxes permissions control who can configure or adjust tax behavior, including manual rates and automatic tax calculation features. What this shows Illustrates the "Taxes Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Taxes Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Taxes permissions control who can configure or adjust tax behavior, including manual rates and automatic tax calculation features. Because tax settings impact compliance, reserve these permissions for finance owners. This part of the guide covers 2 fields, listed below. Immediately after, the guide continues: Recommended role fit: Accountant/Controller or Finance Admin responsible for compliance; avoid granting Configure/Delete to non‑finance users. Image 4 of 9 What this coversTaxes permissions control who can configure or adjust tax behavior, including manual rates and automatic tax calculation features. Because tax settings impact compliance, reserve these permissions for finance owners.
Fields in this part of the guide How to Add Taxes — OverviewInternational Automatic Taxes
Next stepRecommended role fit: Accountant/Controller or Finance Admin responsible for compliance; avoid granting Configure/Delete to non‑finance users.
All 2 steps in this procedure
  1. How to Add Taxes — Overview
  2. International Automatic Taxes

Recommended role fit: Accountant/Controller or Finance Admin responsible for compliance; avoid granting Configure/Delete to non‑finance users.

Contextual links


Products Permissions

Products permissions determine who can create, edit, duplicate, import/export, or delete products—changes that cascade to Payment Links, stores, and checkout pages. Limit destructive actions and require review for catalog changes.

Products Permissions (image 5 of 9) What this shows Products permissions determine who can create, edit, duplicate, import/export, or delete products—changes that cascade to Payment Links… What this shows Illustrates the "Products Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Products Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Products permissions determine who can create, edit, duplicate, import/export, or delete products—changes that cascade to Payment Links, stores, and checkout pages. Limit destructive actions and require review for catalog changes. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Recommended role fit: Store Manager or Product/Catalog Owner for day‑to‑day updates; reserve Import/Export/Delete for administrators. Image 5 of 9 What this coversProducts permissions determine who can create, edit, duplicate, import/export, or delete products—changes that cascade to Payment Links, stores, and checkout pages. Limit destructive actions and require review for catalog changes.
Fields in this part of the guide Getting Started — Sell Products
Next stepRecommended role fit: Store Manager or Product/Catalog Owner for day‑to‑day updates; reserve Import/Export/Delete for administrators.
All 2 steps in this procedure
  1. Getting Started — Sell Products
  2. Create and Share Payment Links

Recommended role fit: Store Manager or Product/Catalog Owner for day‑to‑day updates; reserve Import/Export/Delete for administrators.

Contextual links


Payment Settings Permissions

Payment Settings permissions cover global payment preferences such as receipts, subscription defaults, and payment-related notifications. These shape the customer experience and should be restricted to administrators and brand owners.

Payment Settings Permissions (image 6 of 9) What this shows Payment Settings permissions cover global payment preferences such as receipts, subscription defaults, and payment-related notifications. What this shows Illustrates the "Payment Settings Permissions" section of "Managing Granular Permissions for Payments". This screenshot appears in the "Payment Settings Permissions" section of "Managing Granular Permissions for Payments". The text alongside this image reads: Payment Settings permissions cover global payment preferences such as receipts, subscription defaults, and payment-related notifications. These shape the customer experience and should be restricted to administrators and brand owners. This part of the guide covers 2 fields, listed below. Immediately after, the guide continues: Recommended role fit: Administrators or Brand/Finance Owners who manage receipts, defaults, and notifications; keep configuration centralized. Image 6 of 9 What this coversPayment Settings permissions cover global payment preferences such as receipts, subscription defaults, and payment-related notifications. These shape the customer experience and should be restricted to administrators and brand owners.
Fields in this part of the guide User Audit Logs (for reviewing changes)Audit Logs in Funnels, Websites, and Stores
Next stepRecommended role fit: Administrators or Brand/Finance Owners who manage receipts, defaults, and notifications; keep configuration centralized.
All 2 steps in this procedure
  1. User Audit Logs (for reviewing changes)
  2. Audit Logs in Funnels, Websites, and Stores

Recommended role fit: Administrators or Brand/Finance Owners who manage receipts, defaults, and notifications; keep configuration centralized.

Contextual links


How To Set Up Granular Payment Permissions

Proper setup ensures users can complete their tasks without unnecessary risk. Follow these steps to assign only the access required and verify the results.

  1. Go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon.

    Step 1 of 6: Go to Sub-Account Settings → My Staff, locate the user, and click the… What this shows Step 1 of 6: Go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon. What this shows Shows where to go for step 1 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". This screenshot accompanies step 1 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". At this point in the walkthrough you go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon. The next step is to expand the Roles & Permissions section and select the required category. Step 1 of 6Image 7 of 9 Where to goGo to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon.
    Buttons and menus referenced Sub-AccountSettings → My StaffRoles & PermissionsSaveCopy Permissions
    Next stepExpand the Roles & Permissions section and select the required category
    All 6 steps in this procedure
    1. Go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon. this image
    2. Expand the Roles & Permissions section and select the required category
    3. For each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges.
    4. Click Save.
    5. (Optional) Click Copy Permissions to apply the same configuration to another user.
    6. Have the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction).
  2. Expand the Roles & Permissions section and select the required category

  3. For each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges.

    Step 3 of 6: For each category - Orders, Subscriptions, Transactions, Taxes… What this shows Step 3 of 6: For each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View… What this shows Shows what to choose for step 3 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". This animation accompanies step 3 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". At this point in the walkthrough you for each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges. The next step is to click Save. Step 3 of 6Image 8 of 9 What to chooseFor each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges.
    Buttons and menus referenced Sub-AccountSettings → My StaffRoles & PermissionsSaveCopy Permissions
    Next stepClick Save.
    All 6 steps in this procedure
    1. Go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon.
    2. Expand the Roles & Permissions section and select the required category
    3. For each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges. this image
    4. Click Save.
    5. (Optional) Click Copy Permissions to apply the same configuration to another user.
    6. Have the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction).
  4. Click Save.

  5. (Optional) Click Copy Permissions to apply the same configuration to another user.

    Step 5 of 6: (Optional) Click Copy Permissions to apply the same configuration to… What this shows Step 5 of 6: (Optional) Click Copy Permissions to apply the same configuration to another user. What this shows Shows what to copy for step 5 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". This screenshot accompanies step 5 of 6 in the "How To Set Up Granular Payment Permissions" section of "Managing Granular Permissions for Payments". At this point in the walkthrough you (Optional) Click Copy Permissions to apply the same configuration to another user. The next step is to have the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction). Step 5 of 6Image 9 of 9 What to copy(Optional) Click Copy Permissions to apply the same configuration to another user.
    Buttons and menus referenced Copy PermissionsSub-AccountSettings → My StaffRoles & PermissionsSave
    Next stepHave the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction).
    All 6 steps in this procedure
    1. Go to Sub-Account Settings → My Staff, locate the user, and click the pencil (edit) icon.
    2. Expand the Roles & Permissions section and select the required category
    3. For each category - Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings—toggle the actions the role needs (View, Create, Update, Delete, Export, Configure). Some bulk/import/export actions may be unavailable to users without create/update privileges.
    4. Click Save.
    5. (Optional) Click Copy Permissions to apply the same configuration to another user. this image
    6. Have the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction).
  6. Have the user sign out and back in (if needed) and validate access using a test record (e.g., open a product, view a transaction).


These presets are non-binding recommendations that map common job functions to safer permission sets. Always adapt to your organization’s policies.

Example presets (summary)

RoleSettings CategorySub Settings (actions)Remarks
Billing SupportTransactionsView, Export, Download Receipt (Refund OFF)Allow research and receipts without refund authority. Elevate temporarily if a supervised refund is required.
SubscriptionsView, Pause/Resume/CancelAvoid Create/Update/Cancel unless the team is trained to manage lifecycle changes.
OrdersView, ExportUseful for answering order status questions. Consider Update only for senior agents.
ProductsViewCatalog visibility only; no edits.
Payment Settings—Keep configuration with admins/finance.
Fulfillment / Store ManagerOrdersView, Export, Update(Create optional, Delete OFF)Supports shipping/adjustments. Keep Delete to admins.
ProductsView, Update (Create for catalog owner; Import/Export OFF; Delete OFF)Bulk/import may require Create/Update; restrict to trained owners.
TransactionsViewNo refund capability. Escalate refund requests to finance.
SubscriptionsView (optional)For context only; lifecycle changes handled by AM/Finance.
Account ManagerSubscriptionsView, Create, Update, Pause/Resume/Cancel, ExportOwns subscription health, renewals, and churn prevention; manages card updates when required.
TransactionsViewResearch billing history; no refunds.
OrdersViewContext for customer conversations.
ProductsView (optional)Read-only product context for pricing discussions.
Accountant / ControllerTransactionsView, Export, RefundRefunds restricted to finance leads; monitor via Audit Logs.
TaxesView, Configure, Update, DeleteSensitive. Limit to qualified finance staff; deleting/replacing rates requires care.
Payment SettingsConfigure, UpdateControls receipts, defaults, and payment notifications.
OrdersViewRead-only operational context.
ProductsView, Export (optional)Export for reconciliation; avoid edits unless necessary.
AdministratorAll (Orders, Subscriptions, Transactions, Taxes, Products, Payment Settings)View, Create, Update, Delete, Export, Configure(as applicable)Full control for a minimal, trained admin group. Use Delete sparingly; enforce change management and reviews.
Tip: Use Copy Permissions on the user record to replicate a tested configuration for similar roles.

Frequently Asked Questions

Q: Do permissions affect CSV imports/exports in Payments?
Yes. Import/export capabilities may be restricted based on a user’s assigned actions and role. If a user can’t see bulk tools, have an admin review their Create/Update/Export permissions for that category.

Q: Can someone research transactions without being able to refund?
Yes. Grant Transactions — View (and Export if needed) while limiting refund access to finance owners.

Q: Will disabling Products permissions break existing checkout or payment links?
No. Live checkout experiences continue to sell as configured. However, the user won’t be able to edit the underlying products or links.

Q: Where can I see who changed a product, tax setting, or payment preference?
Use Audit Logs to review user actions and changes. Agency admins can access logs at the agency level, and asset-level audit logs are available for funnels, websites, and stores.

Q: Are granular payment permissions available at the agency level?
Payments permissions are assigned at the Location level. Agency users manage users and roles at the agency scope, and those assignments can stack with or supersede location roles depending on configuration.

Q: What happens if a user reports that buttons are greyed out in Payments?
This usually indicates insufficient permissions for create/update or export in that category. Review their role configuration or temporarily test with an admin role to confirm.

Q: Do Taxes permissions include automatic calculation features?
Yes, where available. Finance owners can enable and manage automatic tax calculation. Ensure addresses are captured on the payment experience for accurate results.


Frequently asked questions

What is Granular Payment Permissions?
Granular payment permissions divide the former single Payments access into focused categories—Orders, Subscriptions, Transactions, Taxes, Products, and Payment Settings—each with standardized actions. This structure gives administrators precise control so teammates get only the access needed for their jobs without exposing sensitive operations. Granular payment permissions are role-based access controls at the Location (sub-account) level that determine which users can View, Create, Update, Delete, Export, and Configure items across the Payments module. Administrators can combine categories to tailor access for support, accounting, fulfillment, and management teams.

Was this guide helpful?

Related guides