# User Access

> Learn how to manage user access in GHL Customer Care. Control permissions, roles, and account types at both agency and sub-account levels for secure collaboration.

- Source: https://docs.ghlcustomercare.com/docs/settings/user-settings/user-access
- Section: Settings / User Settings
- Reading time: 4 min
- Images: 5, each explained below
- Modified on Tue, 21 Apr at 7:12 AM

---
Managing who has access to your GHL Customer Care account(s) is crucial for security, efficiency, and accountability. This article explains how to set up and control user access both at the _agency level_ (across all your client accounts) and at the _sub-account / team level_ (within a specific client account). It also describes what user attributes and permissions you can configure.

---

## **Agency Team Management**

### **Who this is for**

This section applies if you’re an agency owner or admin and need to grant access to employees or client personnel across multiple client accounts.

### **How to access**

1.  Go to **Settings** from the side navigation menu while in _**Agency View**_.
    
2.  Select **Team**.
    

![How to access (image 1 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053848101/original/7MBqFQXCwOa0oL5_VRLY6PsI2PCJ8DNr_w.png)

**How to access (image 1 of 5)**

This screenshot appears in the "How to access" section of "User Access". The text alongside this image reads: Go to Settings from the side navigation menu while in Agency View. Select Team. Immediately after, the guide continues: From here, you can add new users, edit existing ones, or delete users.
- Where to go: Go to Settings from the side navigation menu while in Agency View. Select Team.
- Controls: Settings, Agency View, Team
- Next: From here, you can add new users, edit existing ones, or delete users.

Full procedure:

1. Go to Settings from the side navigation menu while in Agency View.
2. Select Team.

### **What you can do**

From here, you can add new users, edit existing ones, or delete users.

When adding or editing a user, you can modify the following:

-   **Personal logo** (for user profile)
    
-   **First name**
    
-   **Last name**
    
-   **Email address** (this is used as the login email)
    
-   **Phone number**
    
-   **Password**
    
-   **Permissions** (see the _[Agency | Managing user roles & permissions](https://docs.ghlcustomercare.com/docs/settings/user-settings/how-to-manage-agency-user-roles-and-permissions-in-ghl-customer-care)_ article for the details)
    
-   **User Type** — two choices:
    
    -   _Agency_: user can access **all** client accounts under the agency
        
    -   _Account_: user can access **only selected** client accounts
        
-   **Account assignment**:
    
    -   If _Agency_ type is chosen, you specify which client accounts the user gets notifications for
        
    -   If _Account_ type is selected, you choose which specific client accounts the user can access
        

![What you can do (image 2 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053848139/original/hRsNQpuuzMaFVFoL5aZPy4vskz-zOmlovA.png)

**What you can do (image 2 of 5)**

This screenshot appears in the "What you can do" section of "User Access". The text alongside this image reads: Personal logo (for user profile) First name Last name Email address (this is used as the login email) Phone number Password Permissions (see the Agency | Managing user roles & permissions article for the details) User Type — two choices: Account assignment. This part of the guide covers 10 fields, listed below. Immediately after, the guide continues: The ability to Login As another user is permission-gated per admin. When Enable Login As is turned off for a user, the option is hidden.
- What to fill in: Personal logo (for user profile) First name Last name Email address (this is used as the login email) Phone number Password Permissions (see the Agency | Managing user roles & permissions article for the details) User Type — two choices: Account assignment:
- Fields: Personal logo (for user profile), First name, Last name, Email address (this is used as the login email), Phone number, Password, User Type — two choices:, Agency: user can access all client accounts under the agency, Account: user can access only selected client accounts, Account assignment:
- Controls: Personal logo, First name, Last name, Email address, Phone number, Password, Permissions, User Type, all, only selected, Account assignment
- Next: The ability to Login As another user is permission-gated per admin. When Enable Login As is turned off for a user, the option is hidden.

Example values (illustrative, not read from the screenshot):

- First name: Priya
- Last name: Raman
- Email address (this is used as the login email): priya.raman@northgatedental.com
- Phone number: +1 312 847 1928

Full procedure:

1. Personal logo (for user profile)
2. First name
3. Last name
4. Email address (this is used as the login email)
5. Phone number
6. Password
7. Permissions (see the Agency | Managing user roles & permissions article for the details)
8. User Type — two choices:
9. Account assignment:

### **Login As Permission**

The ability to Login As another user is permission-gated per admin. When Enable Login As is turned off for a user, the option is hidden. 

Agency Settings › Team › Edit user › Roles & Permissions › User Management.

![Login As Permission (image 3 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155059906927/original/MIfVnPji6W2VAb8kRrLjGSPRLMgafw5MFw.png)

**Login As Permission (image 3 of 5)**

This screenshot appears in the "Login As Permission" section of "User Access". The text alongside this image reads: Agency Settings › Team › Edit user › Roles & Permissions › User Management. Immediately after, the guide continues: Used by clients or team members within a specific client’s GHL Customer Care account. Any user added here will also be visible under Agency Team Management.
- What this covers: Agency Settings › Team › Edit user › Roles & Permissions › User Management.
- Next: Used by clients or team members within a specific client’s GHL Customer Care account. Any user added here will also be visible under Agency Team Management.

---

## **Team Management (Sub-Account Level)**

### **Who this is for**

Used by clients or team members within a specific client’s GHL Customer Care account. Any user added here will also be visible under Agency Team Management.

### **How to access**

1.  Switch to the relevant **sub-account.**
    
2.  In the side navigation, go to **Settings**.
    
3.  Click **My Staff**.
    

![How to access (image 4 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053848187/original/DLD3bPcptQTP7IzAkixZlZmeMC5krBG06A.png)

**How to access (image 4 of 5)**

This screenshot appears in the "How to access" section of "User Access". The text alongside this image reads: Switch to the relevant sub-account. In the side navigation, go to Settings. Click My Staff. Immediately after, the guide continues: As with agency-level user management, here you can add, delete, or edit users. For each user, you can modify.
- What to click: Switch to the relevant sub-account. In the side navigation, go to Settings. Click My Staff.
- Controls: sub-account., Settings, My Staff
- Next: As with agency-level user management, here you can add, delete, or edit users. For each user, you can modify:

Full procedure:

1. Switch to the relevant sub-account.
2. In the side navigation, go to Settings.
3. Click My Staff.

### **What you can do**

As with agency-level user management, here you can add, delete, or edit users. For each user, you can modify:

-   **Personal logo**
    
-   **First name**
    
-   **Last name**
    
-   **Email (login)**
    
-   **Phone number**
    
-   **Password**
    
-   **Permissions** (again, see _[User Roles, Permissions and Assigned data : Subaccount](https://docs.ghlcustomercare.com/docs/settings/user-settings/sub-account-user-roles-permissions-and-assigned-data)_)
    

![What you can do (image 5 of 5)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155053848950/original/W5U4OkU4oDAG5Bk1sG_l_wNBqL7fr-vsKA.png)

**What you can do (image 5 of 5)**

This screenshot appears in the "What you can do" section of "User Access". The text alongside this image reads: Personal logo First name Last name Email (login) Phone number Password Permissions (again, see User Roles, Permissions and Assigned data: Subaccount). This part of the guide covers 6 fields, listed below. Immediately after, the guide continues: Automatic personal booking calendar creation for newly added sub-account users depends on the agency-level Preloaded Example Data setting in Settings > Company.
- What this covers: Personal logo First name Last name Email (login) Phone number Password Permissions (again, see User Roles, Permissions and Assigned data: Subaccount)
- Fields: Personal logo, First name, Last name, Email (login), Phone number, Password
- Controls: Personal logo, First name, Last name, Email (login), Phone number, Password, Permissions, Preloaded Example Data, Settings > Company
- Next: Automatic personal booking calendar creation for newly added sub-account users depends on the agency-level Preloaded Example Data setting in Settings > Company.

Example values (illustrative, not read from the screenshot):

- First name: Priya
- Last name: Raman
- Email (login): priya.raman@northgatedental.com
- Phone number: +1 312 847 1928

Full procedure:

1. Personal logo
2. First name
3. Last name
4. Email (login)
5. Phone number
6. Password
7. Permissions (again, see User Roles, Permissions and Assigned data: Subaccount)

Automatic personal booking calendar creation for newly added sub-account users depends on the agency-level **Preloaded Example Data** setting in **Settings > Company**.

---

## **Permissions & Roles Overview**

(If you’re not already familiar with how permission settings work, this section helps you understand what control you have.)

You can fine-tune what a user can do by assigning roles or permission scopes. These determine what parts of GHL Customer Care the user can access (e.g. marketing tools, settings, campaigns), what actions they can perform (view, edit, delete), and which accounts their access applies to.

---

## **Email change verification (multi-channel OTP)**

Changing a user’s login email is a sensitive update. GHL Customer Care now supports multi-channel OTP verification so you can confirm identity even if the existing email is inaccessible.

**Available verification methods**

-   **Email OTP**
    
-   **Phone (SMS) OTP**
    
-   **TOTP (Authenticator app)**
    

The verification options shown depend on the user’s verified 2FA methods.

### **When you change your own email**

-   The system prompts you to verify using another available 2FA method (for example, **SMS** or **Authenticator app**).
-   If no other verified method is available, you are prompted to set up an authenticator app. 
    

### **When an admin changes another user’s email**

-   The system shows all available verification methods for that user (Email, SMS, and/or Authenticator app).
    

---

## **Best Practices**

-   **Least Privilege Principle**: Give users only the permissions they need. Avoid giving full agency access unless absolutely necessary.
    
-   **Use Account-type users** when you want someone to have limited access (e.g. sales or support assistant for one client).
    
-   **Track changes**: Maintain clear records of who has what access and when changes are made (helps with audits or troubleshooting).
    
-   **Review access periodically**: People’s roles change, so prune permissions or remove users who no longer need them.
    

---

## **Frequently Asked Questions**

**Q: What’s the difference between “Agency” user type vs “Account” user type?**  
An **Agency** user type grants access across all client accounts under your agency. An **Account** user type restricts access to only the client accounts you explicitly select.

**Q: If I add a user under “My Staff” in a sub‐account, will they appear in Agency Team Management?**  
Yes — all users added in sub-accounts (“My Staff”) are also visible under the Agency’s Team list.

**Q: Can I set different permission levels for different users?**  
Absolutely. The permissions settings let you control precisely which features and actions each user can use.

**Q: How do I change someone’s access later if their role changes?**  
Go to the relevant user record (either in Agency Team or My Staff), edit their user type, assigned accounts, or permissions as needed.

---

## **Related Articles**

-   [Admin Vs. User Roles and Permission Scopes](https://docs.ghlcustomercare.com/docs/settings/user-settings/admin-vs-user-roles-and-permission-scopes) 
    
-   [User Roles, Permissions and Assigned Data: Subaccount](https://docs.ghlcustomercare.com/docs/settings/user-settings/sub-account-user-roles-permissions-and-assigned-data)
    
-   [How to Create a User or Admin to Manage Multiple HL Locations Without Giving Them Agency Access?](https://docs.ghlcustomercare.com/docs/settings/user-settings/how-to-create-a-user-or-admin-to-manage-multiple-hl-locations-without-giving-the)
    
-   [Agency | Managing user roles & permissions](https://docs.ghlcustomercare.com/docs/settings/user-settings/how-to-manage-agency-user-roles-and-permissions-in-ghl-customer-care)
    
-   [Login As User (Agency Admin Only)](https://docs.ghlcustomercare.com/docs/settings/agency-settings-2/login-as-user-agency-admin-only)

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com