Roles and what each can do
The five client roles, the portfolio roles and the agency roles, what each can see and change by default, and who can change a role or what it allows.
4 min readUpdated 7 October 2026
Every login has one role. The role decides which pages someone sees and what they can change, and the brand's plan decides which pages exist for that brand. There are three kinds of people: your brand's own people (client roles), members of a portfolio (who also have a portfolio role), and the agency's staff.
Client roles
These are for people at the brand. You choose one when you invite someone. What each can do by default:
| Role | Pages | Can change |
|---|---|---|
| Client Owner | Every brand page, plus the agency's contracts, commissions and invoices for the brand | Invites and removes people, sets teams, billing, connects integrations, creates targets, reports, the survey, portfolio costs |
| eCom Director | Every brand page, plus contracts, commissions and invoices | Creates and edits targets and reports, publishes reports, the survey |
| Client Manager | Every brand page, including the P&L and Intelligence | Creates, edits and publishes reports, the survey, adds portfolio costs |
| Marketing Exec | Dashboard, sales, marketing, email, customers, products, Intelligence and targets. No P&L | Creates and edits reports |
| Client Viewer | Dashboard, sales, marketing, email, customers, products, the P&L, Intelligence, targets and reports | Nothing. Read only |
Every client user can open Settings, Team to see who has access to the brand. Only people with Manage users (Client Owners by default) see the invite, teams and remove controls there.
Portfolio roles
A portfolio groups several brands. Its members also have a portfolio role: Portfolio owner, Portfolio admin or Viewer. Every member sees every active brand in it, with their client role deciding what they can do. A Portfolio owner can also invite people to the portfolio. See Portfolios and who can see them.
Agency roles
Agency staff work for the agency and see every client the agency manages while its connection is live.
| Role | What it covers by default |
|---|---|
| Agency owner | Everything, including staff costs and approving joiners and leavers |
| Director | Everything except staff costs: clients, finance, billing, people, users and integrations |
| Manager | Client pages, reports, targets and brand settings, and inviting client users. No agency finance or billing |
| Account manager | Day-to-day client work: contracts and invoices, reports, targets and client users. Client margin as a status, not money |
| CFO | Agency finance, billing, contracts, invoices, commissions and portfolio costs. No user management |
| Specialist | Client pages, reports and notes. No user management |
New staff who join by signing in with their work email start as Specialist. Whether someone is an employee or a contractor is recorded on their staff record and does not change their role.
Step by step: see someone's role
- Open your brand and go to Settings, Team (agency staff: Account, Access).
- The Role column shows each person's role.
Step by step: change what a role can do (agency owners and directors)
- Open the agency's Settings and choose Roles and permissions.
- Choose Agency Roles or Client Roles.
- Switch a permission on or off for a role. It is saved at once and applies to everyone with that role, at every client.
Managers and account managers can open the tab but their changes are refused.
Troubleshooting
"You don't have permission to view this page.": your role does not open that page. Ask your Client Owner, or your agency.
A menu item has a lock: that is the plan, not your role. Opening it shows which plan includes it.
"Failed:" when switching a permission: only the agency's owner and directors can change permissions.