WhatsApp User Permissions in HighLevel

Modified on: Tue, 22 Sep, 2026 at 7:14 AM

Granular WhatsApp user permissions give admins more control over who can make changes to WhatsApp settings in HighLevel. Instead of relying on one broad permission, admins can allow or restrict specific actions such as creating templates, editing Flows, managing phone numbers, updating the business profile, or disconnecting WhatsApp. These controls help agencies reduce unintended configuration changes while giving team members access that matches their responsibilities.


TABLE OF CONTENTS


What are WhatsApp User Permissions?


WhatsApp user permissions are granular access controls that determine which WhatsApp configuration actions an individual user can perform. They give agency and sub-account admins more precise control over sensitive WhatsApp settings without requiring them to remove a user's broader access to WhatsApp.


HighLevel provides seven individual WhatsApp permissions:

  • Create/edit WhatsApp templates

  • Delete WhatsApp templates

  • Create/edit WhatsApp Flows

  • Delete/deprecate WhatsApp Flows

  • Update WhatsApp business profile

  • Add/manage WhatsApp phone numbers

  • Disconnect WhatsApp integration


These permissions are enforced both in the HighLevel interface and through supported API requests.


Key Benefits of WhatsApp User Permissions


Granular permissions help agencies delegate WhatsApp management without giving every team member the ability to change every part of the integration. This provides more control over high-impact actions while allowing authorized users to continue working with the WhatsApp features they need.

  • More precise access control: Allow users to perform only the WhatsApp configuration actions required for their role.

  • Reduced operational mistakes: Limit template edits, Flow changes, phone-number management, profile updates, and disconnect actions to authorized users.

  • Safer delegation: Give team members access to selected WhatsApp administrative functions without automatically granting access to every setting.

  • Consistent enforcement: HighLevel applies the same permission checks to supported actions in both the user interface and API.

  • Simpler troubleshooting: Admins can quickly check WhatsApp permissions when a user cannot perform a specific configuration action.

  • Flexible role management: Agency and sub-account admins can adjust access as team responsibilities change.


Available WhatsApp Permissions


Each WhatsApp permission controls a specific type of configuration change. Separating these actions allows admins to grant access according to a user's responsibilities instead of relying on one broad permission for all WhatsApp management.


Create/edit WhatsApp Templates

Allows the user to create new WhatsApp templates and make supported changes to existing templates.


For more information about building templates, see How to Create a WhatsApp Template.


Delete WhatsApp Templates


Allows the user to delete WhatsApp templates where deletion is supported.


This permission is separate from creating or editing templates, allowing an admin to let a user maintain template content without also granting deletion access.


Create/edit WhatsApp Flows


Allows the user to create new WhatsApp Flows and make supported changes to existing Flows.


For more information about using Flows, see WhatsApp Flows for Appointment Booking.


Delete/deprecate WhatsApp Flows


Allows the user to perform supported delete or deprecate actions on WhatsApp Flows. Keeping this separate from Flow creation and editing helps protect published or existing Flows from unintended removal or deprecation.


Update WhatsApp business profile


Allows the user to update supported WhatsApp Business Profile information from HighLevel. For details about the available profile settings, see WhatsApp Business Profile Management.


Add/manage WhatsApp phone numbers


Allows the user to perform supported actions for adding and managing phone numbers connected to WhatsApp. This permission is useful when phone-number administration should be limited to specific team members while other users continue working with WhatsApp messaging features.


Disconnect WhatsApp integration


Allows the user to disconnect the WhatsApp integration from HighLevel. Because disconnecting WhatsApp can interrupt connected WhatsApp functionality, this permission can be reserved for users who are responsible for integration administration.

Note: Disconnecting the WhatsApp integration and canceling a WhatsApp subscription are separate actions. Existing subscription-cancellation requirements continue to apply unless otherwise documented.


How WhatsApp Permissions Work


WhatsApp permissions control configuration actions performed by an individual user. Understanding the difference between these granular permissions and broader WhatsApp access helps admins avoid removing more access than necessary.


The seven permissions apply to actions that change WhatsApp configuration, such as creating, editing, deleting, managing, or disconnecting supported WhatsApp resources.


Read and preview behavior continues to use the existing broader WhatsApp access permissions. For example, removing a create/edit permission should not be interpreted as automatically removing all visibility into that WhatsApp resource.


This distinction lets admins restrict configuration changes without necessarily preventing users from viewing information they still need for their role.


Default Permission Behavior


The granular WhatsApp permissions use an opt-out rollout so existing users do not unexpectedly lose access when the permissions become available. Admins can then tighten access by turning off individual permissions where needed.


All seven permissions are initially granted to the supported existing agency owner, admin, user, account admin, and account user roles included in the rollout.


This means existing customers retain their current WhatsApp management access by default. An administrator must disable individual permissions when a user should no longer perform a particular WhatsApp action.


What Happens When a User Does Not Have Permission


Permission enforcement prevents restricted users from completing the corresponding WhatsApp action even when they can otherwise access WhatsApp. This makes it easier to distinguish a deliberate access restriction from a product or configuration issue.


When a required WhatsApp permission is disabled:

  • The corresponding action is disabled in the HighLevel interface.

  • HighLevel provides contextual permission messaging or a tooltip for the restricted control.

  • Supported direct API requests for the unauthorized action are rejected with a 403 Forbidden response.


For example, a user may be able to open the WhatsApp Templates area but be unable to create or edit a template if the Create/edit WhatsApp templates permission is disabled.


If a user reports that they cannot create a template, edit a Flow, manage a phone number, update the business profile, or disconnect WhatsApp, check their WhatsApp permissions before treating the behavior as a product issue.


WhatsApp Permissions at Agency and Sub-Account Level


WhatsApp permissions can be managed from the user-management area appropriate to the user's access scope. This allows agencies to maintain broader access policies while sub-account admins control the permissions of users they manage.


Agency admins can manage WhatsApp permissions when editing applicable users from the agency user-management area.


Sub-account admins can manage the permissions of applicable staff from the sub-account user-management area.

WhatsApp permissions are user-scoped. When a permission is granted or revoked for a user, the setting applies to that user's applicable sub-account access rather than functioning as a separate WhatsApp permission profile for each individual sub-account.


For a broader explanation of agency and account access, see Manage Agency User Roles and Permissions in HighLevel and Sub-account: User Roles, Permissions and Assigned Data.


Audit Logs and WhatsApp Permission Changes


Audit logging helps agency administrators review user-access changes and understand when permissions were modified. This can be useful when investigating why a user previously had access to a WhatsApp action but can no longer perform it.


WhatsApp permission changes are published as user-related audit activity at the agency level.


To review applicable user changes, go to:


Agency View → Settings → Audit Logs


Use the available filters to narrow the results to the relevant user or user-related activity.


For more information, see Audit Logs.


WhatsApp Permissions and Reselling


WhatsApp permissions and WhatsApp reselling control different parts of the product experience. Keeping these controls separate allows admins to continue managing user access even when WhatsApp is not being offered through the agency's reseller configuration.


The WhatsApp permission toggles remain available in user management even when WhatsApp reselling is turned off.

Turning off WhatsApp reselling does not remove the WhatsApp permission controls from the user's Roles & Permissions settings.


How To Set Up WhatsApp User Permissions


Configuring individual WhatsApp permissions lets you match each user's access to their responsibilities while protecting sensitive configuration actions. Review the user's role and expected WhatsApp tasks before disabling permissions so necessary day-to-day work is not interrupted.

Agency Users

  1. Switch to Agency View.

  2. Go to Settings.


  3. Open Team or the applicable user management area.

    Please Note that Team will be renamed to Users in the upcoming release.


  4. Locate the user you want to update and click the Edit or pencil icon.


  5. Open Roles & Permissions.

  6. Locate the WhatsApp permission section.


  7. Turn each WhatsApp permission on or off based on the user's responsibilities:

    • Create/edit WhatsApp templates

    • Delete WhatsApp templates

    • Create/edit WhatsApp Flows

    • Delete/deprecate WhatsApp Flows

    • Update WhatsApp business profile

    • Add/manage WhatsApp phone numbers

    • Disconnect WhatsApp integration


  8. Review the user's remaining module and granular permissions.

  9. Save the changes.


Sub Account Users

  1. Open the applicable sub-account.

  2. Go to Settings → My Staff.

    Please Note that the My Staff will be renamed to Users in the upcoming changes.



  3. Locate the staff member you want to update and open their user settings.

  4. Open Roles & Permissions.

  5. Locate the WhatsApp permission section.



  6. Enable or disable each permission based on the actions the user should be allowed to perform.

  7. Save the changes.

Tip: If a user suddenly cannot perform a specific WhatsApp configuration action, compare that action with the seven WhatsApp permission toggles before changing broader module access.


Frequently Asked Questions


Q: Why can a user open WhatsApp Settings but not create a template?
The user may have access to WhatsApp but not the Create/edit WhatsApp templates permission. Check the user's Roles & Permissions settings and confirm that the required WhatsApp toggle is enabled.


Q: Can I allow someone to edit templates without letting them delete templates?
Yes. Template creation/editing and template deletion use separate permissions, so the two actions can be controlled independently.


Q: Can I let a user create WhatsApp Flows without allowing them to delete or deprecate existing Flows?
Yes. Create/edit WhatsApp Flows and Delete/deprecate WhatsApp Flows are separate permissions.


Q: Does removing a create or edit permission prevent the user from viewing the resource?
Not necessarily. The new granular permissions govern supported configuration changes, while read and preview paths continue to use the existing broader WhatsApp access controls.


Q: What happens if an integration tries to perform a WhatsApp action that the user is not permitted to perform?
For supported API operations protected by these permissions, unauthorized mutation requests return a 403 Forbidden response.


Q: Why is the WhatsApp permission section still visible when WhatsApp reselling is turned off?
User permissions and reselling are separate controls. The WhatsApp permission toggles remain available in user management even when WhatsApp reselling is disabled.


Q: Where can I see who changed a user's WhatsApp permissions?
Applicable permission changes are published as user-related audit activity at the agency level. Agency admins can review the relevant activity from Agency View → Settings → Audit Logs.


Q: Does the Disconnect WhatsApp permission also allow a user to cancel the WhatsApp subscription?
Disconnecting the integration and canceling a subscription are separate actions. The granular permission specifically controls supported WhatsApp disconnect actions. Follow the documented subscription-cancellation requirements when canceling service.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article