Skip to content
Settings

Sub-account: User Roles, Permissions and Assigned data

Learn how to manage sub-account user roles and granular permissions in GHL Customer Care. Assign access, restrict visibility, and control tools such as Workflows.

4 min read980 words7 explained imagesUpdated Fri, 4 Sep at 9:08 AM
View as markdownOpen in ClaudeOpen in ChatGPT
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.
On this page
  1. Key Benefits of Sub-account Roles & Permissions
  2. How to Set Up Sub-Account Roles & Permissions
  3. Restrict Visibility with “Only Assigned Data”
  4. Assigning Roles & Permissions
  5. Copy Permissions Between Users
  6. Module-Specific Granular Permissions
  7. Frequently Asked Questions
  8. Related Articles

This article will show you how to manage user roles and permissions at the sub-account level in GHL Customer Care. You’ll learn how to control what your users can access, assign custom visibility rules, and configure powerful granular permissions for modules like Voice AI, Calendars, and Workflows.

If you're here looking for Agency's user roles and permission management, click here.


TABLE OF CONTENTS


What are User Roles and Permissions?

Sub-account user roles and permissions determine what features a user can access within a specific location in GHL Customer Care. Whether you're giving a sales rep limited visibility or assigning full admin access to a team lead, user roles ensure the right people see and control the right parts of your account. Each user is assigned one of two roles, Admin or User, and can be further customized using granular permissions and visibility toggles like Only Assigned Data. You can also copy permissions from one user to another and restrict visibility on a per-module basis.


Key Benefits of Sub-account Roles & Permissions

  • Data Security: Restrict contacts, pipelines, and campaigns to approved staff only.

  • Cleaner Interface: Hide unused menus so team members navigate faster.

  • Accountability: Attribute every action to a specific user for airtight audit trails.

  • Faster Onboarding: Clone proven role templates instead of rebuilding settings from scratch.


How to Set Up Sub-Account Roles & Permissions

Configuring roles and permissions ensures that each team member sees and controls only what they need to. Follow these steps to get started.

Step 1: Go to Settings › My Staff

Step 1: Go to Settings › My Staff (image 1 of 7) What this shows Navigate to the sub-account you want to manage. What this shows Illustrates the "Step 1: Go to Settings › My Staff" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Step 1: Go to Settings › My Staff" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Navigate to the sub-account you want to manage. Under Settings, click My Staff. Immediately after, the guide continues: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Image 1 of 7 Where to goNavigate to the sub-account you want to manage. Under Settings, click My Staff.
Buttons and menus referenced SettingsMy Staff
Next stepClick the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.

Step 2: Choose a User or Create a New One

Click the Edit (pencil) icon next to an existing user or select + Add Employee to create a new profile.

Step 2: Choose a User or Create a New One (image 2 of 7) What this shows Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. What this shows Illustrates the "Step 2: Choose a User or Create a New One" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Step 2: Choose a User or Create a New One" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Immediately after, the guide continues: Click Roles and Permissions tab on the left. Then in the Role dropdown, choose. Image 2 of 7 What to chooseClick the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Buttons and menus referenced Edit+ Add Employee
Next stepClick Roles and Permissions tab on the left. Then in the Role dropdown, choose:

Step 3: Assign a Role: Admin or User

Click Roles and Permissions tab on the left. Then in the Role dropdown, choose:

  • Admin: full access to all modules and settings in the sub-account
  • User: restricted access; granular permissions apply
Step 3: Assign a Role: Admin or User (image 3 of 7) What this shows Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply What this shows Illustrates the "Step 3: Assign a Role: Admin or User" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Step 3: Assign a Role: Admin or User" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc. Image 3 of 7 What this coversAdmin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply
Fields in this part of the guide User: restricted access; granular permissions apply
Buttons and menus referenced Roles and Permissions tab
Next stepUse the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.
All 2 steps in this procedure
  1. Admin: full access to all modules and settings in the sub-account
  2. User: restricted access; granular permissions apply

Step 4: Enable/Disable Modules as Needed

Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.

Step 4: Enable/Disable Modules as Needed (image 4 of 7) What this shows Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows… What this shows Illustrates the "Step 4: Enable/Disable Modules as Needed" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Step 4: Enable/Disable Modules as Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc. Immediately after, the guide continues: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them. Image 4 of 7 What this coversUse the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc. Next stepToggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.


Step 5: Set 'Only Assigned Data' if Needed

Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.

Step 5: Set 'Only Assigned Data' if Needed (image 5 of 7) What this shows Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them. What this shows Illustrates the "Step 5: Set 'Only Assigned Data' if Needed" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Step 5: Set 'Only Assigned Data' if Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them. Immediately after, the guide continues: Click Update or Save to apply the new permission configuration. Image 5 of 7 What to chooseToggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
Buttons and menus referenced Only Assigned Data
Next stepClick Update or Save to apply the new permission configuration.

Step 6: Save Your Changes

Click Update or Save to apply the new permission configuration.


Restrict Visibility with “Only Assigned Data”

Limiting access based on assigned data helps protect sensitive information while empowering users to focus only on their own work. When you turn Only Assigned Data ON, the user will only see:

  • Contacts assigned to them

  • Opportunities where they’re the owner

  • Appointments or tasks linked to their name

Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.

Restrict Visibility with “Only Assigned Data” (image 6 of 7) What this shows Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’… What this shows Illustrates the "Restrict Visibility with “Only Assigned Data”" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Restrict Visibility with “Only Assigned Data”" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients. This part of the guide covers 3 fields, listed below. Immediately after, the guide continues: User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers. Image 6 of 7 What this coversExample Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.
Fields in this part of the guide Contacts assigned to themOpportunities where they’re the ownerAppointments or tasks linked to their name
Buttons and menus referenced Only Assigned Data
Next stepUser roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.
Example values
Appointments or tasks linked to their name
Priya Raman

Illustrative values showing the expected format. They are not read from the screenshot.

All 3 steps in this procedure
  1. Contacts assigned to them
  2. Opportunities where they’re the owner
  3. Appointments or tasks linked to their name

Assigning Roles & Permissions

User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.

  • Admin: Full control over all tools, settings, and data inside the sub-account
  • User: Limited access based on permissions; can be restricted to assigned data only

For more info on this topic, check out Admin vs User Permissions


Copy Permissions Between Users

To save time when onboarding new users, you can clone an existing permission set.

  1. Go to Settings › My Staff

  2. Click the Edit (pencil) icon next to an existing user or select + Add Employee to create a new profile.

  3. Select the Roles and Permissions tab

  4. Click Copy Permissions button in the top right

  5. Use the Copy Permissions dropdown to choose a source user

  6. Click Copy to apply those exact settings

Copy Permissions Between Users (image 7 of 7) What this shows Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. What this shows Illustrates the "Copy Permissions Between Users" section of "Sub-account: User Roles, Permissions and Assigned data". This screenshot appears in the "Copy Permissions Between Users" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those…. This part of the guide covers 12 fields, listed below. Immediately after, the guide continues: Module-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a…. Image 7 of 7 Where to goGo to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those exact settings
Fields in this part of the guide AI Agents (Managed Agents, Voice, Chat)AI StudioAccount SettingsAccount ToolsAutomation (includes Workflows)BlogsCalendarsCertificatesCommunitiesContactsConversationsForms
Buttons and menus referenced Settings › My StaffEdit+ Add EmployeeRoles andPermissionsCopy PermissionsCopyModule-Specific Granular PermissionsAI Agents ()AI Studio
Next stepModule-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a sub-account. This is ideal for managing large teams, limiting sensitive actions, and reducing the risk of accidental changes. Export data: Controls who can export dashboard widget data. Use this to limit downloads and reduce accidental sharing of reporting data. Granular Permissions are available for the following areas:
All 6 steps in this procedure
  1. Go to Settings › My Staff
  2. Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
  3. Select the Roles and Permissions tab
  4. Click Copy Permissions button in the top right
  5. Use the Copy Permissions dropdown to choose a source user
  6. Click Copy to apply those exact settings

Frequently Asked Questions

Q: What happens if I disable a module for a user but it’s used in a workflow?
The user won’t see or interact with the module, but workflows will still run. Make sure someone else retains full access to manage those automations.

Q: Can I assign different permissions for each calendar?
Yes, calendar permissions are now granular. You can allow booking access to specific calendars or give full management rights.

Q: Can I bulk assign permissions across users?
Not. You can use the Copy Permissions feature one-by-one, or request bulk provisioning through our roadmap.

Q: What’s the difference between Admin at the agency level and Admin at the sub-account level?
Agency Admins control all sub-accounts, SaaS products, and billing. Sub-account Admins only control a specific location.

Q: Can a user manage multiple locations without being an agency admin?
Yes. You can use Account Admins to manage several sub-accounts without giving them full agency access.


Was this guide helpful?

Related guides