# Admin Vs. User Roles and Permission Scopes

> Learn the differences between Admin and User roles in GHL Customer Care. Explore agency vs sub-account permission scopes with a clear quick-reference matrix.

- Source: https://docs.ghlcustomercare.com/docs/settings/user-settings/admin-vs-user-roles-and-permission-scopes
- Section: Settings / User Settings
- Reading time: 1 min
- Images: 2, each explained below
- Modified on Wed, 6 May at 2:20 PM

---
The following is a table outlining permissions of sub-account level roles.

### **Sub-Account Level User Roles**

![Sub-Account Level User Roles (image 1 of 2)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155018238155/original/mcE4xdl46E3pyAgBhVD9qRWDvOg8gfscqg.png)

**Sub-Account Level User Roles (image 1 of 2)**

This screenshot appears in the "Sub-Account Level User Roles" section of "Admin Vs. User Roles and Permission Scopes". The text alongside this image reads: The following is a table outlining permissions of sub-account level roles. Immediately after, the guide continues: Agency-Only Sub-Account-Only Available in Both Create / Edit / Delete Sub-Accounts Pipelines & Opportunities User Management (Admins can add/edit users within their level) Manage SaaS Mode & Reselling Workflows / Campaigns Dashboard….
- What this covers: The following is a table outlining permissions of sub-account level roles.
- Next: Agency-Only Sub-Account-Only Available in Both Create / Edit / Delete Sub-Accounts Pipelines & Opportunities User Management (Admins can add/edit users within their level) Manage SaaS Mode & Reselling Workflows / Campaigns Dashboard Reporting Global Integrations (Mailgun, Twilio Rebilling, Google API, etc.) Calendars & Appointment Settings Media Library Snapshot Management Conversations (SMS, Email, Chat) Audit Logs Agency-Level Billing & Branding Contact Management & Smart Lists Agency Settings (Company Info, Rebilling Settings) Reputation Management White-Label Settings (Custom Domains, Logos, Colors) Funnel & Website Builder

---

## **Quick-Reference Permission Matrix.  
**

<table style="width: 100%"><tbody><tr><td style="width: 33.3333%; text-align: center"><p class="p1"><strong dir="ltr">Agency-Only</strong></p></td><td style="width: 33.3333%; text-align: center"><p class="p1"><strong dir="ltr">Sub-Account-Only</strong></p></td><td style="width: 33.3333%; text-align: center"><p class="p1"><strong dir="ltr">Available in Both</strong></p></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Create / Edit / Delete Sub-Accounts</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Pipelines &amp; Opportunities</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">User Management (Admins can add/edit users within their level)</p></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Manage SaaS Mode &amp; Reselling</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Workflows / Campaigns</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Dashboard Reporting</p></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Global Integrations (Mailgun, Twilio Rebilling, Google API, etc.)</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Calendars &amp; Appointment Settings</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Media Library</p></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Snapshot Management</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Conversations (SMS, Email, Chat)</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr"><a href="/docs/settings/agency-settings-2/audit-logs">Audit Logs</a></p></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Agency-Level Billing &amp; Branding</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Contact Management &amp; Smart Lists</p></td><td style="width: 33.3333%; text-align: center"></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Agency Settings (Company Info, Rebilling Settings)</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Reputation Management</p></td><td style="width: 33.3333%; text-align: center"></td></tr><tr><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">White-Label Settings (Custom Domains, Logos, Colors)</p></td><td style="width: 33.3333%; text-align: center"><p class="p1" dir="ltr">Funnel &amp; Website Builder</p></td><td style="width: 33.3333%; text-align: center"></td></tr></tbody></table>

**Note:** If a permission is not listed, assume it inherits the broader role’s default capabilities at its respective level.

Admins can change the role of a particular user by going to **Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles"**

![Quick-Reference Permission Matrix. (image 2 of 2)](https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/155018238329/original/SO6U66a5eqB-L00Pot42Kknck7OO6w0K8Q.png)

**Quick-Reference Permission Matrix. (image 2 of 2)**

This screenshot appears in the "Quick-Reference Permission Matrix." section of "Admin Vs. User Roles and Permission Scopes". The text alongside this image reads: Admins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles". The navigation path used here is Settings > My Staff > Edit. Immediately after, the guide continues: Q. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins?

- Path: Settings > My Staff > Edit
- What this covers: Admins can change the role of a particular user by going to Settings > My Staff > Edit (pencil icon) > Scroll to and expand "User Roles"
- Controls: Agency-Only, Sub-Account-Only, Available in Both
- Next: Q. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins?

---

## **Frequently Asked Questions**

**Q. If a permission is available at both Agency and Sub-Account levels, does the Agency Admin override Sub-Account Admins?**

Yes. Agency Admins hold global authority. For permissions like user management, reporting, or media library, Agency Admin actions apply across all sub-accounts, while Sub-Account Admins manage only within their assigned sub-account.

**Q. What happens if a user is added at the Agency level and then also given access to a Sub-Account?**

The user will have **two role scopes**: agency-wide access from their Agency role, plus sub-account-specific access from their Sub-Account role. Permissions don’t cancel out—they stack, with the broader Agency permissions always taking precedence.

**Q. Do all Agency Admins have “Login As”?****No**. “Login As” is controlled by the Enable Login As **permission at the agency level**. If it’s disabled for an admin, the Login As option is hidden for that user.

---

Documentation for GHL Customer Care. Support: support@ghlcustomercare.com