Skip to content
Settings

Admin Vs. User Roles and Permission Scopes

Learn the differences between Admin and User roles in GHL Customer Care. Explore agency vs sub-account permission scopes with a clear quick-reference matrix.

1 min read293 words2 explained imagesUpdated Wed, 6 May at 2:20 PM
View as markdownOpen in ClaudeOpen in ChatGPT
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.
On this page
  1. Sub-Account Level User Roles
  2. Quick-Reference Permission Matrix.
  3. Frequently Asked Questions


The following is a table outlining permissions of sub-account level roles.

Sub-Account Level User Roles

Sub-Account Level User Roles (image 1 of 2) What this shows The following is a table outlining permissions of sub-account level roles. What this shows Illustrates the "Sub-Account Level User Roles" section of "Admin Vs. User Roles and Permission Scopes". This screenshot appears in the "Sub-Account Level User Roles" section of "Admin Vs. User Roles and Permission Scopes". The text alongside this image reads: The following is a table outlining permissions of sub-account level roles. Immediately after, the guide continues: Agency-Only Sub-Account-Only Available in Both Create / Edit / Delete Sub-Accounts Pipelines & Opportunities User Management (Admins can add/edit users within their level) Manage SaaS Mode & Reselling Workflows / Campaigns Dashboard…. Image 1 of 2 What this coversThe following is a table outlining permissions of sub-account level roles. Next stepAgency-Only Sub-Account-Only Available in Both Create / Edit / Delete Sub-Accounts Pipelines & Opportunities User Management (Admins can add/edit users within their level) Manage SaaS Mode & Reselling Workflows / Campaigns Dashboard Reporting Global Integrations (Mailgun, Twilio Rebilling, Google API, etc.) Calendars & Appointment Settings Media Library Snapshot Management Conversations (SMS, Email, Chat) Audit Logs Agency-Level Billing & Branding Contact Management & Smart Lists Agency Settings (Company Info, Rebilling Settings) Reputation Management White-Label Settings (Custom Domains, Logos, Colors) Funnel & Website Builder

Quick-Reference Permission Matrix.

Agency-Only

Sub-Account-Only

Available in Both

Create / Edit / Delete Sub-Accounts

Pipelines & Opportunities

User Management (Admins can add/edit users within their level)

Manage SaaS Mode & Reselling

Workflows / Campaigns

Dashboard Reporting

Global Integrations (Mailgun, Twilio Rebilling, Google API, etc.)

Calendars & Appointment Settings

Media Library

Snapshot Management

Conversations (SMS, Email, Chat)

Audit Logs

Agency-Level Billing & Branding

Contact Management & Smart Lists

Agency Settings (Company Info, Rebilling Settings)

Reputation Management

White-Label Settings (Custom Domains, Logos, Colors)

Funnel & Website Builder

Note: If a permission is not listed, assume it inherits the broader role’s default capabilities at its respective level.

Admins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles"

Quick-Reference Permission Matrix. (image 2 of 2) What this shows Admins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles" What this shows Illustrates the "Quick-Reference Permission Matrix." section of "Admin Vs. User Roles and Permission Scopes". This screenshot appears in the "Quick-Reference Permission Matrix." section of "Admin Vs. User Roles and Permission Scopes". The text alongside this image reads: Admins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles". The navigation path used here is Settings > My Staff > Edit. Immediately after, the guide continues: Q. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins? Path: Settings > My Staff > EditImage 2 of 2 What this coversAdmins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles"
Buttons and menus referenced Agency-OnlySub-Account-OnlyAvailable in Both
Next stepQ. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins?

Frequently Asked Questions

Q. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins?

Yes. Agency Admins hold global authority. For permissions like user management, reporting, or media library, Agency Admin actions apply across all sub-accounts, while Sub-Account Admins manage only within their assigned sub-account.

Q. What happens if a user is added at the Agency level and then also given access to a Sub-Account?

The user will have two role scopes: agency-wide access from their Agency role, plus sub-account-specific access from their Sub-Account role. Permissions don’t cancel out—they stack, with the broader Agency permissions always taking precedence.

Q. Do all Agency Admins have “Login As”?
No. “Login As” is controlled by the Enable Login As permission at the agency level. If it’s disabled for an admin, the Login As option is hidden for that user.

Was this guide helpful?

Related guides