Manage Agency User Roles and Permissions in HighLevel

Modified on: Tue, 6 Oct, 2026 at 10:47 PM

Managing agency user permissions helps you give users the access they need without exposing unnecessary accounts, modules, or sensitive settings. HighLevel lets Agency Admins control user type, role, sub-account access, module visibility, and granular actions from one permission-management area.

If you need to manage users who work only inside a specific sub-account, see Manage Sub-Account User Roles & Permissions.


TABLE OF CONTENTS


What Are Agency User Roles and Permissions?

Agency user roles and permissions determine which HighLevel accounts, modules, settings, and actions a user can access.

Access is controlled through several layers:

  • User Type: Determines the scope in which the user operates.

  • Role: Determines the user's authority within that scope.

  • Sub-Account Assignment: Determines which sub-accounts an Account-type user can access.

  • Module Permissions: Control whether an entire feature or module is available.

  • Granular Permissions: Control supported actions within a module.

Use the least amount of access required for each user's responsibilities. For users who need selected client accounts without agency-wide access, use the Account user type and assign only the required sub-accounts.


User Type and Role

User Type determines where a user can operate, while Role determines their authority within that scope.

User Type

  • Agency: Use for users who require agency-level access.

  • Account: Use for users who should access only selected sub-accounts.

When Account is selected, assign only the sub-accounts the user needs.


Role

  • Admin: Provides administrative capabilities within the user's applicable access scope.

  • User: Provides access according to the permissions configured for that user.



Restrict Access to Specific Sub-Accounts

Use an Account-type user when someone needs access to specific client accounts without receiving agency-wide access.

  1. From Agency View, go to Settings → Users.

  2. Edit the applicable user.

  3. Open Roles & Permissions.

  4. Set User Type to Account.

  5. Select the sub-accounts the user should be able to access.

  6. Choose the appropriate Role.

  7. Configure the required module and granular permissions.

  8. Save the changes.

The user can access only the sub-accounts assigned to them.


Create and Delete Sub-Accounts

Creating or deleting a sub-account is controlled separately from permissions that govern what a user can do inside an existing sub-account.

  1. From Agency View, go to Settings → Users.

  2. Edit the applicable user.

  3. Open Roles & Permissions.

  4. Locate the Sub-Accounts Agency module.

  5. Clear Create Sub-Accounts if the user should not create new sub-accounts.

  6. Clear Delete if the user should not delete sub-accounts.

  7. If the user should not access the Sub-Accounts module, turn off the entire module.

  8. Save the changes.



Module and Granular Permissions

Module and granular permissions work together to control what a user can access and what actions they can perform.

  • Module permissions: Turn off an entire module when the user should not access that feature.

  • Granular permissions: Control individual supported actions within an enabled module.

If a module is disabled, the user cannot access functionality contained within that module.

Forms, Surveys, Quizzes, and QR Codes

Forms, Surveys, Quizzes, and QR Codes support user-level permission controls. Use the module toggle and the available View & manage permission to control access.

Affiliate Manager Payout Permission

The Pay Affiliate Manager Payout permission controls whether an eligible admin can process affiliate payouts.

  • Agency Admins: The permission is enabled by default and can be enabled or disabled.

  • Agency Users: Users cannot process affiliate payouts.

When this permission is disabled, payout actions are hidden in Affiliate Manager.

Available Permission Areas

Available permission areas can include the following modules and functions. The exact controls shown depend on the user's type, role, and available features.

Permission AreaControls
AI AgentsSupported AI Agents, training, logs, summaries, and related functionality.
Account SettingsBusiness information, domains, branding, time zone, and supported account settings.
Account ToolsSupported imports, exports, redirects, and administrative tools.
AutomationWorkflows, triggers, automation activity, and logs.
BlogsBlog posts, categories, authors, and settings.
CalendarsCalendars, availability, assignments, appointment types, and scheduling settings.
CertificatesSupported course-completion certificates.
CommunitiesGroups, posts, members, and moderation functions.
ContactsContact creation, editing, deletion, import, export, and supported actions.
ConversationsInbox, messaging, calling, email, SMS, and supported social communication features.
DashboardDashboard access and supported dashboard actions.
FormsForms and form submissions.
FunnelsSupported funnel and website assets.
GoKollabSupported GoKollab functionality.
IntegrationsSupported third-party integrations.
LaunchpadSupported onboarding and quick-start tools.
MarketingCampaigns, Social Planner, templates, and supported scheduling features.
MediaImages, videos, and files in the media library.
MembershipsCourses, lessons, offers, access levels, learners, and related functionality.
OpportunitiesPipelines, stages, opportunities, values, and statuses.
OrdersSupported order records.
PaymentsPayments, invoices, refunds, receipts, and related financial records.
Payment SettingsPayment gateways, taxes, receipts, dunning, and payment-related settings.
ProductsProducts, prices, and supported product variations.
QR CodesQR-code creation and management.
QuizzesSupported quizzes.
ReputationReviews, listings, responses, and supported reputation tools.
SubscriptionsRecurring plans, subscriber status, and cancellations.
Sub-Account TransfersEligible transfer functionality when the required role and permission are present.
SurveysSurveys and responses.
TaxesSupported tax rates and rules.
TransactionsSupported transactions, charges, refunds, and payouts.
WordPressSupported WordPress connections and site-management functionality.

Sub-Account Settings Permissions

Sub-Account Settings permissions provide additional control over administrative areas that can affect client configuration, billing, and other sensitive settings.


  • Sub-Accounts List Page: Controls supported access to the sub-account list and related management actions.

  • Manage Client Page – Basic Details: Controls supported client-level configuration.

  • Sub-Account Billing: Restricts supported billing and financial actions.

  • Sub-Account Company Settings: Restricts access to supported high-impact company settings.

If a user attempts an action their permissions do not allow, HighLevel displays messaging indicating that their permission level does not allow the action.


User Management and Login As

User Management permissions control supported user-administration actions, including whether an eligible Agency Admin can use Login As.

Enable Login As

The Enable Login As permission controls whether an eligible Agency Admin can impersonate another user.

  • Default: Enabled.

  • When disabled: The Login As option is hidden for that admin.

  • Location: Agency View → Settings → Users → Edit User → Roles & Permissions → User Management.

The redesigned Users experience also provides clearer guidance for owner-role handling and ownership transfer when those options are available.



Copy Permissions

Agency Admins can copy an existing user's granular permission configuration to another user instead of configuring each permission individually.

Before copying permissions, confirm that the destination user's role, responsibilities, and account scope are appropriate for the copied configuration.


Add Clients With Limited Sub-Account Access

Clients who need access only to their own business can be created as Account-type users and assigned only to the applicable sub-account. This prevents agency-wide access while allowing their role, module permissions, and data visibility to be configured.

  1. From Agency View, go to Settings → Users.

  2. Click + Add User.

  3. Enter the client’s name, email address, and required user information.

  4. Open Roles & Permissions.

  5. Set User Type to Account.

  6. Select only the client’s applicable sub-account.

  7. Choose the appropriate Role.

  8. Configure the modules and individual permissions the client should be able to access.

  9. Enable Only Assigned Data when supported record visibility should be limited to records assigned to that user.

  10. Click Save.


Dashboard Export Permission

Dashboard permissions can be managed separately from general account access.

  • Dashboard → Export data: Allows the user to export supported dashboard widget data.


Sub-Account Transfer Permission

Sub-account transfers can affect ownership, access, billing, integrations, and other account resources. Grant transfer permissions only to authorized users.

  • By default, the Agency Owner can request or complete eligible sub-account transfers.

  • The Agency Owner can grant transfer permissions to specific Agency Admins.

  • Agency Admins without the required permission cannot submit or approve transfer requests.

A sub-account transfer moves the entire eligible sub-account between agencies rather than transferring only selected data.



User Management API Support

API-based User Management workflows can be affected by the Enhanced Security setting.

  • View & Manage Users: Allows supported viewing, creation, and editing of users.

  • View Users: Allows supported viewing of users without broader user-management access.

When Enhanced Security is enabled, affected API-based User Management operations are restricted.

If your agency requires an affected API-based User Management workflow:

  1. Go to Agency View → Settings → Company → Advanced Settings.

  2. Locate Enhanced Security.

  3. Disable the setting only when the required workflow depends on the affected API operations.



Important: Disabling Enhanced Security can increase account security risk. Keep it enabled unless your agency specifically requires an affected API-based workflow.



Set Up Agency User Roles and Permissions

Configure the user's access scope first, then refine individual permissions.



  1. From Agency View, go to Settings → Users.

  2. Select the applicable user and open the user for editing.

  3. Select Roles & Permissions.

  4. Choose the appropriate User Type:

    • Agency: Use when the user requires agency-level access.

    • Account: Use when the user should access selected sub-accounts only.



  1. Choose the appropriate Role.

  2. If the User Type is Account, select the sub-accounts the user should be able to access.

  3. Turn off modules the user does not need.

  4. Configure the available granular permissions within enabled modules.

  5. Review sensitive permissions separately.

  6. Save the user's configuration.




Sensitive permissions to review include:

  • Creating or deleting sub-accounts

  • Sub-Account Settings

  • User Management

  • Login As

  • Dashboard exports

  • Sub-Account Transfers

Review user permissions periodically and update them when responsibilities change.


Frequently Asked Questions

Q: What is the difference between User Type and Role?

User Type determines the scope in which the user operates, while Role determines their authority within that scope.

Q: Can I give someone access to multiple sub-accounts without giving them agency-wide access?

Yes. Set the user's User Type to Account and assign the specific sub-accounts they should be able to access.

Q: Why can a user open a sub-account but still be blocked from certain settings?

Sub-account assignment determines whether the user can enter the account. Module and granular permissions determine what they can access or do after entering it.

Q: Is Only Assigned Data the same as turning off a module?

No. Module permissions determine whether a user can access a feature. Only Assigned Data limits supported record visibility based on assignment.

Q: Can every Agency Admin transfer a sub-account?

No. By default, the Agency Owner can request or complete eligible transfers. Transfer permission can be granted to specific Agency Admins.

Q: Why can't my API update User Management permissions?

Enhanced Security can restrict affected API-based User Management operations. Review the security implications before changing this setting.

Q: Should I add a client as an agency-level user?

If the client only needs access to their own business account, add them as a user within the appropriate sub-account to avoid unnecessary agency-level visibility.


Related Articles



Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article