Team roles and permissions

Everyone at your agency has an agency role. The role decides what they can do across your book of business: manage settings, move money, run campaigns and PR, or just look. This article explains the five roles, how the Member role is narrowed to specific clients, and how all of...

Last updated

Everyone at your agency has an agency role. The role decides what they can do across your book of business: manage settings, move money, run campaigns and PR, or just look. This article explains the five roles, how the Member role is narrowed to specific clients, and how all of this is different from the client access ladder.

The five roles

Each role is a fixed bundle of permissions. You assign one role per teammate.

Owner

The Owner has every permission, including the two that no one else has: transferring ownership of the agency to another teammate, and (where applicable) agency billing. There is exactly one Owner at a time. The Owner also does everything an Admin does.

Admin

Admins run the agency day to day: manage the team, add and edit client records, move money (top up the central wallet, allocate to clients, reclaim unused allocations), and manage campaigns and PR orders for every client. The one thing an Admin cannot do is transfer ownership.

Manager

Manager is the hands-on operator role across your whole client roster. A Manager can create and edit campaigns, place PR orders, and configure conversion tracking for any client. A Manager cannot touch agency settings, the team, or funding. This is the role for someone who runs the work but does not handle the money or the org.

Member

A Member works exactly like a Manager, but only for the specific clients you assign to them. Everything else in the workspace is invisible to a Member. This is the role for a seat that should be scoped to a named set of accounts. See the next section.

Analyst

An Analyst sees every client but can change nothing. This is the reporting seat: good for a stakeholder, a strategist, or a client-services lead who needs the numbers but should not be editing campaigns or moving money.

What each role can do

  • Role: Owner. Agency settings, clients, and funding: Yes, plus ownership transfer. Campaigns and PR: Yes. Which clients: All
  • Role: Admin. Agency settings, clients, and funding: Yes. Campaigns and PR: Yes. Which clients: All
  • Role: Manager. Agency settings, clients, and funding: No. Campaigns and PR: Yes. Which clients: All
  • Role: Member. Agency settings, clients, and funding: No. Campaigns and PR: Yes. Which clients: Assigned only
  • Role: Analyst. Agency settings, clients, and funding: No. Campaigns and PR: No, view only. Which clients: All

The Member role is scoped per client

Member is the only client-scoped role. When you set a teammate to Member, their edit page shows a checklist of your active clients. Check the ones they should work on.

  • A Member sees and manages only their assigned clients. Every other client, the cross-client Overview rows for other clients, and agency settings are simply not there for them.
  • Assignments are a Member concept. If you later change a Member to any other role, their assignments are cleared, because the other roles are not client-scoped: they already apply to all clients or to none.

For the step-by-step of assigning clients, see Inviting and managing team members.

Team roles are not the client access ladder

This is the single most important distinction to keep straight. There are two different permission systems, and they answer two different questions.

  • Team roles (this article) answer: *what can my staff do?* They apply to the people who work at your agency.
  • The client access ladder answers: *what can the client's own login do on an account we created for them?* It applies to your client, not your staff. Its four levels are view-only, Editor, Manager, and Funder. See Client access levels.

They share the word "Manager" but mean different things: an agency Manager is a role for your teammate, while a client Manager is a capability level on a client's login. The two never interact. Changing a teammate's role does nothing to any client's access, and changing a client's access level does nothing to your team.

Two caps sit on top of every role

Even when a teammate's role would allow an action, two account-level caps can still block it:

  • A read-only client link. If a client linked to you read-only, the whole account is view-only for everyone at your agency, including the Owner. No role overrides a read-only link. See Sharing your management ID.
  • The client's capability level (on managed accounts). This caps the client's own login, not your team, but it is worth remembering it is a separate gate on the same account.

Still need help?

Ask Maren about billing, campaign setup, or anything not covered.