# Sub-account: User Roles, Permissions and Assigned data

> Learn how to manage sub-account user roles and granular permissions in GHL Customer Care. Assign access, restrict visibility, and control tools such as Workflows.

- Source: https://docs.ghlcustomercare.com/docs/settings/user-settings/sub-account-user-roles-permissions-and-assigned-data
- Section: Settings / User Settings
- Reading time: 4 min
- Images: 7, each explained below
- Modified on Fri, 4 Sep at 9:08 AM

---
This article will show you how to manage user roles and permissions at the sub-account level in GHL Customer Care. You’ll learn how to control what your users can access, assign custom visibility rules, and configure powerful granular permissions for modules like Voice AI, Calendars, and Workflows.

If you're here looking for Agency's user roles and permission management, [click here.](https://docs.ghlcustomercare.com/docs/settings/user-settings/how-to-manage-agency-user-roles-and-permissions-in-ghl-customer-care)

---

**TABLE OF CONTENTS**

-   [What are User Roles and Permissions?](#what-are-user-roles-and-permissions)
-   [Key Benefits of Sub-account Roles & Permissions](#key-benefits-of-sub-account-roles-and-permissions)
-   [How to Set Up Sub-Account Roles & Permissions](#how-to-set-up-sub-account-roles-and-permissions)
-   [Restrict Visibility with “Only Assigned Data”](#restrict-visibility-with-only-assigned-data)
-   [Assigning Roles & Permissions](#assigning-roles-and-permissions)
-   [Copy Permissions Between Users](#copy-permissions-between-users)
-   [Module-Specific Granular Permissions](#module-specific-granular-permissions)
-   [Frequently Asked Questions](#frequently-asked-questions)
-   [Related Articles](#related-articles)

---

# **What are User Roles and Permissions?**

Sub-account user roles and permissions determine what features a user can access within a specific location in GHL Customer Care. Whether you're giving a sales rep limited visibility or assigning full admin access to a team lead, user roles ensure the right people see and control the right parts of your account. Each user is assigned one of two roles, Admin or User, and can be further customized using granular permissions and visibility toggles like Only Assigned Data. You can also copy permissions from one user to another and restrict visibility on a per-module basis.

---

## **Key Benefits of Sub-account Roles & Permissions**

-   **Data Security:** Restrict contacts, pipelines, and campaigns to approved staff only.
    
-   **Cleaner Interface:** Hide unused menus so team members navigate faster.
    
-   **Accountability:** Attribute every action to a specific user for airtight audit trails.
    
-   **Faster Onboarding:** Clone proven role templates instead of rebuilding settings from scratch.
    

---

## **How to Set Up Sub-Account Roles & Permissions**

Configuring roles and permissions ensures that each team member sees and controls only what they need to. Follow these steps to get started.

#### **Step 1:** Go to Settings › My Staff

Navigate to the sub-account you want to manage. Under **Settings**, click **My Staff**.

![Step 1: Go to Settings › My Staff (image 1 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963289/original/p4fP8lIAhFT2lEBi7UnrF8o_fz9dnHnZgA.png)

**Step 1: Go to Settings › My Staff (image 1 of 7)**

This screenshot appears in the "Step 1: Go to Settings › My Staff" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Navigate to the sub-account you want to manage. Under Settings, click My Staff. Immediately after, the guide continues: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
- Where to go: Navigate to the sub-account you want to manage. Under Settings, click My Staff.
- Controls: Settings, My Staff
- Next: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.

#### **Step 2:** Choose a User or Create a New One

Click the **E****dit** (pencil) icon next to an existing user or select **\+ Add Employee** to create a new profile.

![Step 2: Choose a User or Create a New One (image 2 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963334/original/Wwqerqx4510qC8bINsWSVRVi-87m_0HbDg.png)

**Step 2: Choose a User or Create a New One (image 2 of 7)**

This screenshot appears in the "Step 2: Choose a User or Create a New One" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Immediately after, the guide continues: Click Roles and Permissions tab on the left. Then in the Role dropdown, choose.
- What to choose: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
- Controls: E, dit, + Add Employee
- Next: Click Roles and Permissions tab on the left. Then in the Role dropdown, choose:

#### **Step 3:** Assign a Role: Admin or User

Click **Roles and Permissions tab** on the left. Then in the Role dropdown, choose:

-   **Admin:** full access to all modules and settings in the sub-account
-   **User:** restricted access; granular permissions apply

![Step 3: Assign a Role: Admin or User (image 3 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963384/original/uDvV8zszaZ4p3kjieb2YpFzKGEa9DTrUeA.png)

**Step 3: Assign a Role: Admin or User (image 3 of 7)**

This screenshot appears in the "Step 3: Assign a Role: Admin or User" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.
- What this covers: Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply
- Fields: User: restricted access; granular permissions apply
- Controls: Roles and Permissions tab
- Next: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.

Full procedure:

1. Admin: full access to all modules and settings in the sub-account
2. User: restricted access; granular permissions apply

#### **Step 4:** Enable/Disable Modules as Needed

Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.

![Step 4: Enable/Disable Modules as Needed (image 4 of 7)](https://jumpshare.com/share/v1BbhE3cttFlxgyhFxzB+/Screen+Shot+2026-09-04+at+19.36.25.png)

**Step 4: Enable/Disable Modules as Needed (image 4 of 7)**

This screenshot appears in the "Step 4: Enable/Disable Modules as Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc. Immediately after, the guide continues: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
- What this covers: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.
- Next: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.

#### **Step 5:** Set 'Only Assigned Data' if Needed

Toggle **Only Assigned Data** to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.

![Step 5: Set 'Only Assigned Data' if Needed (image 5 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963468/original/IRv0FSrEO4o78isaixRcokdrc6gRU9YqDw.png)

**Step 5: Set 'Only Assigned Data' if Needed (image 5 of 7)**

This screenshot appears in the "Step 5: Set 'Only Assigned Data' if Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them. Immediately after, the guide continues: Click Update or Save to apply the new permission configuration.
- What to choose: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
- Controls: Only Assigned Data
- Next: Click Update or Save to apply the new permission configuration.

#### **Step 6:** Save Your Changes

Click **Update** or **Save** to apply the new permission configuration.

---

## **Restrict Visibility with “Only Assigned Data”**

Limiting access based on assigned data helps protect sensitive information while empowering users to focus only on their own work. When you turn **Only Assigned Data** ON, the user will only see:

-   Contacts assigned to them
    
-   Opportunities where they’re the owner
    
-   Appointments or tasks linked to their name
    

Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.

![Restrict Visibility with “Only Assigned Data” (image 6 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963481/original/6zEe36lzaY47Ujajo9Cpe8joYFHPDciuAg.jpeg)

**Restrict Visibility with “Only Assigned Data” (image 6 of 7)**

This screenshot appears in the "Restrict Visibility with “Only Assigned Data”" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients. This part of the guide covers 3 fields, listed below. Immediately after, the guide continues: User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.
- What this covers: Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.
- Fields: Contacts assigned to them, Opportunities where they’re the owner, Appointments or tasks linked to their name
- Controls: Only Assigned Data
- Next: User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.

Example values (illustrative, not read from the screenshot):

- Appointments or tasks linked to their name: Priya Raman

Full procedure:

1. Contacts assigned to them
2. Opportunities where they’re the owner
3. Appointments or tasks linked to their name

---

## **Assigning Roles & Permissions**

User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.

-   **Admin:** Full control over all tools, settings, and data inside the sub-account
-   **User:** Limited access based on permissions; can be restricted to assigned data only

For more info on this topic, check out [Admin vs User Permissions](https://docs.ghlcustomercare.com/docs/settings/user-settings/admin-vs-user-roles-and-permission-scopes)

---

## **Copy Permissions Between Users**

To save time when onboarding new users, you can clone an existing permission set.

1.  Go to **Settings › My Staff**
    
2.  Click the **E****dit** (pencil) icon next to an existing user or select **\+ Add Employee** to create a new profile.
    
3.  Select the **Roles and** **Permissions** tab
    
4.  Click **Copy Permissions** button in the top right
    
5.  Use the **Copy Permissions** dropdown to choose a source user
    
6.  Click **Copy** to apply those exact settings
    

![Copy Permissions Between Users (image 7 of 7)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155049963554/original/HM24jZg4BLEtS23DqLeTqENc0w3BkaitGA.png)

**Copy Permissions Between Users (image 7 of 7)**

This screenshot appears in the "Copy Permissions Between Users" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those…. This part of the guide covers 12 fields, listed below. Immediately after, the guide continues: Module-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a….
- Where to go: Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those exact settings
- Fields: AI Agents (Managed Agents, Voice, Chat), AI Studio, Account Settings, Account Tools, Automation (includes Workflows), Blogs, Calendars, Certificates, Communities, Contacts, Conversations, Forms
- Controls: Settings › My Staff, E, dit, + Add Employee, Roles and, Permissions, Copy Permissions, Copy, Module-Specific Granular Permissions, AI Agents (, ), AI Studio
- Next: Module-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a sub-account. This is ideal for managing large teams, limiting sensitive actions, and reducing the risk of accidental changes. Export data: Controls who can export dashboard widget data. Use this to limit downloads and reduce accidental sharing of reporting data. Granular Permissions are available for the following areas:

Full procedure:

1. Go to Settings › My Staff
2. Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
3. Select the Roles and Permissions tab
4. Click Copy Permissions button in the top right
5. Use the Copy Permissions dropdown to choose a source user
6. Click Copy to apply those exact settings

---

## **Module-Specific Granular Permissions**

GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a sub-account. This is ideal for managing large teams, limiting sensitive actions, and reducing the risk of accidental changes.

Export data: Controls who can export dashboard widget data. Use this to limit downloads and reduce accidental sharing of reporting data.

Granular Permissions are available for the following areas:

-   **AI Agents (**Managed Agents, Voice, Chat**)**
    
-   **AI Studio**
    
-   **Account Settings**
    
-   **Account Tools**
    
-   **Automation** (includes Workflows)
    
-   **Blogs**
    
-   **Calendars**
    
-   **Certificates**
    
-   **Communities**
    
-   **Contacts**
    
-   **Conversations**
    
-   **Forms**
    
-   **Funnels**
    
-   **Gokollab**
    
-   **Integrations**
    
-   **Marketing**
    
-   **Medias**
    
-   **Memberships**
    
-   **Opportunities**
    
-   **Payments**
    
-   **QR Codes**
    
-   **Quizzes**
    
-   **Dashboard**
    
-   **Reputations**
    
-   **Surveys**
    
-   **User Management**
    
-   **WordPress**
    

---

## **Frequently Asked Questions**

**Q: What happens if I disable a module for a user but it’s used in a workflow?**  
The user won’t see or interact with the module, but workflows will still run. Make sure someone else retains full access to manage those automations.

**Q: Can I assign different permissions for each calendar?**  
Yes, calendar permissions are now granular. You can allow booking access to specific calendars or give full management rights.

**Q: Can I bulk assign permissions across users?**  
Not. You can use the Copy Permissions feature one-by-one, or request bulk provisioning through our roadmap.

**Q: What’s the difference between Admin at the agency level and Admin at the sub-account level?**  
Agency Admins control all sub-accounts, SaaS products, and billing. Sub-account Admins only control a specific location.

**Q: Can a user manage multiple locations without being an agency admin?**  
Yes. You can use Account Admins to manage several sub-accounts without giving them full agency access.

---

## **Related Articles**

-   [Admin vs User Permissions](https://docs.ghlcustomercare.com/docs/settings/user-settings/admin-vs-user-roles-and-permission-scopes)
    
-   User Permissions, Assigned Data, and Owners
    
-   [Agency | Managing user roles & permissions](https://docs.ghlcustomercare.com/docs/settings/user-settings/how-to-manage-agency-user-roles-and-permissions-in-ghl-customer-care)
    
-   [Voice AI Agent Permissions](https://docs.ghlcustomercare.com/docs/ai-employee/voice-ai/managing-granular-permissions-for-voice-ai-agents)
    
-   [SaaS vs Sub-Account Permissions](https://docs.ghlcustomercare.com/docs/saas-configurator/saas-mode/saas-user-level-permissions-vs-sub-account-level-permissions)
    
-   [Workflow Folder Permissions](https://docs.ghlcustomercare.com/docs/workflows/workflow-builder/workflow-folder-permission)

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com