Sub-account: User Roles, Permissions and Assigned data
Learn how to manage sub-account user roles and granular permissions in GHL Customer Care. Assign access, restrict visibility, and control tools such as Workflows.
4 min read980 words7 explained imagesUpdated Fri, 4 Sep at 9:08 AM
Assistants need to reach this page over the internet. While it is only running on your machine, these two buttons will not be able to load it.
Each image has a one line explanation. Switch to full detail for the step it belongs to, the fields and buttons involved, examples and the whole procedure.
This article will show you how to manage user roles and permissions at the sub-account level in GHL Customer Care. You’ll learn how to control what your users can access, assign custom visibility rules, and configure powerful granular permissions for modules like Voice AI, Calendars, and Workflows.
If you're here looking for Agency's user roles and permission management, click here.
Sub-account user roles and permissions determine what features a user can access within a specific location in GHL Customer Care. Whether you're giving a sales rep limited visibility or assigning full admin access to a team lead, user roles ensure the right people see and control the right parts of your account. Each user is assigned one of two roles, Admin or User, and can be further customized using granular permissions and visibility toggles like Only Assigned Data. You can also copy permissions from one user to another and restrict visibility on a per-module basis.
Key Benefits of Sub-account Roles & Permissions
Data Security: Restrict contacts, pipelines, and campaigns to approved staff only.
Cleaner Interface: Hide unused menus so team members navigate faster.
Accountability: Attribute every action to a specific user for airtight audit trails.
Faster Onboarding: Clone proven role templates instead of rebuilding settings from scratch.
How to Set Up Sub-Account Roles & Permissions
Configuring roles and permissions ensures that each team member sees and controls only what they need to. Follow these steps to get started.
Step 1: Go to Settings › My Staff
Navigate to the sub-account you want to manage. Under Settings, click My Staff.
Step 1: Go to Settings › My Staff (image 1 of 7)What this shows Navigate to the sub-account you want to manage.What this showsIllustrates the "Step 1: Go to Settings › My Staff" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Step 1: Go to Settings › My Staff" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Navigate to the sub-account you want to manage. Under Settings, click My Staff. Immediately after, the guide continues: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.Image 1 of 7Where to goNavigate to the sub-account you want to manage. Under Settings, click My Staff.
Buttons and menus referencedSettingsMy Staff
Next stepClick the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Step 2: Choose a User or Create a New One
Click the Edit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Step 2: Choose a User or Create a New One (image 2 of 7)What this shows Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.What this showsIllustrates the "Step 2: Choose a User or Create a New One" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Step 2: Choose a User or Create a New One" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Immediately after, the guide continues: Click Roles and Permissions tab on the left. Then in the Role dropdown, choose.Image 2 of 7What to chooseClick the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Buttons and menus referencedEdit+ Add Employee
Next stepClick Roles and Permissions tab on the left. Then in the Role dropdown, choose:
Step 3: Assign a Role: Admin or User
Click Roles and Permissions tab on the left. Then in the Role dropdown, choose:
Admin: full access to all modules and settings in the sub-account
Step 3: Assign a Role: Admin or User (image 3 of 7)What this shows Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions applyWhat this showsIllustrates the "Step 3: Assign a Role: Admin or User" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Step 3: Assign a Role: Admin or User" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Admin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply. This part of the guide covers 1 field, listed below. Immediately after, the guide continues: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.Image 3 of 7What this coversAdmin: full access to all modules and settings in the sub-account User: restricted access; granular permissions apply
Fields in this part of the guideUser: restricted access; granular permissions apply
Buttons and menus referencedRoles and Permissions tab
Next stepUse the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.All 2 steps in this procedure
Admin: full access to all modules and settings in the sub-account
Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.
Step 4: Enable/Disable Modules as Needed (image 4 of 7)What this shows Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows…What this showsIllustrates the "Step 4: Enable/Disable Modules as Needed" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Step 4: Enable/Disable Modules as Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Use the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc. Immediately after, the guide continues: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.Image 4 of 7What this coversUse the checkboxes to grant or restrict access to modules like AI Agents (Managed Agents, Voice, Chat), Conversations, Workflows, Calendars, Voice AI, etc.Next stepToggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
Step 5: Set 'Only Assigned Data' if Needed
Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
Step 5: Set 'Only Assigned Data' if Needed (image 5 of 7)What this shows Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.What this showsIllustrates the "Step 5: Set 'Only Assigned Data' if Needed" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Step 5: Set 'Only Assigned Data' if Needed" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Toggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them. Immediately after, the guide continues: Click Update or Save to apply the new permission configuration.Image 5 of 7What to chooseToggle Only Assigned Data to restrict a user’s visibility to only the leads, opportunities, and data explicitly assigned to them.
Buttons and menus referencedOnly Assigned Data
Next stepClick Update or Save to apply the new permission configuration.
Step 6: Save Your Changes
Click Update or Save to apply the new permission configuration.
Restrict Visibility with “Only Assigned Data”
Limiting access based on assigned data helps protect sensitive information while empowering users to focus only on their own work. When you turn Only Assigned Data ON, the user will only see:
Contacts assigned to them
Opportunities where they’re the owner
Appointments or tasks linked to their name
Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.
Restrict Visibility with “Only Assigned Data” (image 6 of 7)What this shows Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’…What this showsIllustrates the "Restrict Visibility with “Only Assigned Data”" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Restrict Visibility with “Only Assigned Data”" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Example Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients. This part of the guide covers 3 fields, listed below. Immediately after, the guide continues: User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.Image 6 of 7What this coversExample Use-Case: Use this feature for sales reps to ensure they only see and manage their own pipeline without accessing others’ conversations or clients.
Fields in this part of the guideContacts assigned to themOpportunities where they’re the ownerAppointments or tasks linked to their name
Buttons and menus referencedOnly Assigned Data
Next stepUser roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.
Example values
Appointments or tasks linked to their name
Priya Raman
Illustrative values showing the expected format. They are not read from the screenshot.
All 3 steps in this procedure
Contacts assigned to them
Opportunities where they’re the owner
Appointments or tasks linked to their name
Assigning Roles & Permissions
User roles define high-level access, while permissions define which modules they can use. We recommend granting Admin access only to team leads, trusted employees, or internal managers.
Admin: Full control over all tools, settings, and data inside the sub-account
User: Limited access based on permissions; can be restricted to assigned data only
To save time when onboarding new users, you can clone an existing permission set.
Go to Settings › My Staff
Click the Edit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Select the Roles and Permissions tab
Click Copy Permissions button in the top right
Use the Copy Permissions dropdown to choose a source user
Click Copy to apply those exact settings
Copy Permissions Between Users (image 7 of 7)What this shows Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.What this showsIllustrates the "Copy Permissions Between Users" section of "Sub-account: User Roles, Permissions and Assigned data".This screenshot appears in the "Copy Permissions Between Users" section of "Sub-account: User Roles, Permissions and Assigned data". The text alongside this image reads: Go to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those…. This part of the guide covers 12 fields, listed below. Immediately after, the guide continues: Module-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a….Image 7 of 7Where to goGo to Settings › My Staff Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile. Select the Roles and Permissions tab Click Copy Permissions button in the top right Use the Copy Permissions dropdown to choose a source user Click Copy to apply those exact settings
Fields in this part of the guideAI Agents (Managed Agents, Voice, Chat)AI StudioAccount SettingsAccount ToolsAutomation (includes Workflows)BlogsCalendarsCertificatesCommunitiesContactsConversationsForms
Buttons and menus referencedSettings › My StaffEdit+ Add EmployeeRoles andPermissionsCopy PermissionsCopyModule-Specific Granular PermissionsAI Agents ()AI Studio
Next stepModule-Specific Granular Permissions GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a sub-account. This is ideal for managing large teams, limiting sensitive actions, and reducing the risk of accidental changes. Export data: Controls who can export dashboard widget data. Use this to limit downloads and reduce accidental sharing of reporting data. Granular Permissions are available for the following areas:All 6 steps in this procedure
Go to Settings › My Staff
Click the E dit (pencil) icon next to an existing user or select + Add Employee to create a new profile.
Select the Roles and Permissions tab
Click Copy Permissions button in the top right
Use the Copy Permissions dropdown to choose a source user
Click Copy to apply those exact settings
Module-Specific Granular Permissions
GHL Customer Care now offers detailed control over access to individual modules and their sub-features. Granular permissions allow you to give users precise access to specific tools and features inside a sub-account. This is ideal for managing large teams, limiting sensitive actions, and reducing the risk of accidental changes.
Export data: Controls who can export dashboard widget data. Use this to limit downloads and reduce accidental sharing of reporting data.
Granular Permissions are available for the following areas:
AI Agents (Managed Agents, Voice, Chat)
AI Studio
Account Settings
Account Tools
Automation (includes Workflows)
Blogs
Calendars
Certificates
Communities
Contacts
Conversations
Forms
Funnels
Gokollab
Integrations
Marketing
Medias
Memberships
Opportunities
Payments
QR Codes
Quizzes
Dashboard
Reputations
Surveys
User Management
WordPress
Frequently Asked Questions
Q: What happens if I disable a module for a user but it’s used in a workflow? The user won’t see or interact with the module, but workflows will still run. Make sure someone else retains full access to manage those automations.
Q: Can I assign different permissions for each calendar? Yes, calendar permissions are now granular. You can allow booking access to specific calendars or give full management rights.
Q: Can I bulk assign permissions across users? Not. You can use the Copy Permissions feature one-by-one, or request bulk provisioning through our roadmap.
Q: What’s the difference between Admin at the agency level and Admin at the sub-account level? Agency Admins control all sub-accounts, SaaS products, and billing. Sub-account Admins only control a specific location.
Q: Can a user manage multiple locations without being an agency admin? Yes. You can use Account Admins to manage several sub-accounts without giving them full agency access.