Home›Blog›Agency Growth
Agency Growth

GoHighLevel User Roles and Permissions: Access Without Handing Over the Keys

It is faster to make the new hire an admin, and nothing visibly breaks — until a departing contractor exports the client's entire contact database.
GHL Nexa Team
Sep 8, 2026
8 min read

Permissions are the part of account setup everyone skips. It is faster to make the new hire an admin, and nothing visibly breaks. Then a contractor exports the contact list on their way out, a junior deletes a workflow that was running three campaigns, or a client logs in and finds they can see another client’s data.

None of these are hypothetical. This guide covers how GoHighLevel’s permission model works, what to give whom, and the mistakes that cause real damage.

The Two Levels of Access

GoHighLevel separates access into agency level and sub-account level, and confusing the two is the root of most permission problems.

Agency level

An agency user can potentially see and act across every sub-account you manage. Agency admin is the most powerful role in the system — it reaches billing, white-label settings, every client environment and the ability to create or delete sub-accounts.

Agency admin should be a very short list. Owners and perhaps one operations lead. Not account managers, not contractors, not clients, not “temporarily for this one task”.

Sub-account level

A sub-account user is scoped to one client environment. This is where most of your team and all of your clients should live. Within a sub-account you can restrict further — which contacts they see, which calendars, which pipelines, and which sections of the interface appear at all.

Roles in Practice

GoHighLevel’s built-in roles give you a starting point, and the permission toggles let you shape them. A structure that works for most agencies:

Agency owner

Full agency admin. Billing, white-label, sub-account creation. One or two people.

Operations lead

Agency-level access without billing where possible. Can create sub-accounts, deploy snapshots and manage users.

Account manager

Sub-account admin on their assigned clients only. Can build workflows, edit funnels, see all contacts in those accounts. No agency-level access.

Specialist or contractor

Sub-account user, restricted to the areas they work in. A funnel designer does not need the conversations inbox. A copywriter does not need payment settings. An ads contractor does not need the ability to export the contact database.

Client owner

Sub-account admin on their own account only, with settings they could break locked down where appropriate — billing integrations, phone number configuration, A2P registration.

Client staff

Sub-account user restricted to their own assigned contacts, their own calendar, and the conversations inbox. A technician or receptionist needs to reply to leads, not to reconfigure automations.

The Restrictions That Matter Most

Contact export

The most consequential single toggle in the platform. Anyone who can export contacts can walk out with the client’s entire customer database. Restrict it to people who genuinely need it, and be aware that for a departing contractor this is the difference between a resignation and a data breach.

“Assigned data only”

Restricting a user to contacts assigned to them serves two purposes. It protects data, and it removes noise — a salesperson who sees only their own leads works a cleaner list. For client staff this is usually the right default.

Settings access

Settings is where the damage happens. Phone numbers, custom fields, integrations, automations. A user who can edit custom fields can break every workflow referencing them — see our custom fields guide for why renaming a field matters.

Payments and billing

Anyone with payments access can see revenue and potentially redirect where money lands. Restrict tightly, including for client staff.

Workflow editing

Workflows are the machinery. Let people view them for context; restrict editing to those who understand the consequences. A workflow deleted by someone “tidying up” can silently stop a campaign.

Giving Clients Access

This is where agencies are most inconsistent. Two philosophies, both defensible:

Full access. The client is admin on their own sub-account. Transparent, and it positions the account as theirs — which matters if you are white-labelling and selling software rather than services. The risk is that clients change things and then ask why the automation stopped.

Restricted access. The client sees conversations, calendar, contacts and reporting, but not settings or workflows. Fewer accidents, but it can feel like you are holding their business hostage — and it becomes a genuine grievance if the relationship ends badly.

Most agencies land in between: client owner gets broad access with settings restricted, client staff get conversations and their own contacts. Whatever you choose, say so in the contract, along with what happens to the account if you part ways. Disputes about account ownership are miserable and entirely preventable.

Contractors and Offshore Teams

Contractors need the narrowest possible access, for the shortest possible time.

  • Scope to the specific sub-accounts they are working on — never agency level.
  • Disable contact export.
  • Restrict to the functional area they were hired for.
  • Remove access the day the engagement ends. Put it in the offboarding checklist, because nobody remembers otherwise.
  • Never share a login. One user per person, always — shared logins destroy your audit trail and make removal impossible without disrupting everyone.

Practical Hygiene

  • Audit quarterly. List every user across every sub-account and ask whether each still needs what they have. Most agencies find dormant accounts from people who left months ago.
  • Enable two-factor authentication, especially for anyone with agency-level access.
  • Offboard properly. Remove the user, rotate any API keys they had, and reassign their contacts so leads do not go unanswered.
  • Reassign before removing. Deleting a user who owns 200 contacts without reassignment means 200 leads with no owner and no notifications.
  • Document your standard roles so new team members get consistent access rather than whatever the last person copied.

Permissions and the Mobile App

Permissions set on desktop apply in the mobile app, which is worth checking rather than assuming. Restricting a field technician to their own assigned contacts makes the app genuinely more usable for them — a cleaner list, fewer irrelevant notifications — as well as safer for the client’s data.

Common Mistakes

  • Making everyone an admin because it is quicker than thinking about it.
  • Giving contractors agency-level access so they can “see how it works elsewhere”.
  • Leaving export enabled for everyone. The single highest-consequence default.
  • Shared logins. No audit trail, no clean removal.
  • Never auditing. Access accumulates; nothing removes it automatically.
  • Not agreeing account ownership in writing before the relationship sours.
  • Deleting users without reassigning their contacts.

A Starter Permission Matrix

Rather than deciding role by role each time, standardise. This matrix works for most agencies and can be adapted rather than invented.

CapabilityAgency ownerAccount managerContractorClient ownerClient staff
Agency-level accessYesNoNoNoNo
Create sub-accountsYesNoNoNoNo
BillingYesNoNoNoNo
All contacts in accountYesYesScopedYesAssigned only
Export contactsYesYesNoYesNo
Edit workflowsYesYesScopedNoNo
Settings and integrationsYesYesNoLimitedNo
Payments configurationYesLimitedNoLimitedNo
Conversations inboxYesYesScopedYesYes
ReportingYesYesScopedYesLimited

A Quarterly Access Audit

Put this in the calendar as a recurring task. It takes under an hour and prevents the failure modes that matter.

  1. List every user across the agency and every sub-account.
  2. Flag anyone who has not logged in for 60 days. Dormant accounts are either unnecessary or a sign that someone left without being offboarded.
  3. Check agency-level access. If the list has grown, ask who added whom and why.
  4. Check export permissions. This is the one to be strict about.
  5. Verify departed staff and finished contractors are gone, and that their API keys were rotated.
  6. Confirm contact ownership is current — leads assigned to someone who left are leads nobody is answering.
  7. Re-check client-side users. Client teams change without telling you.

Record the date you ran it. If a security question ever arises, being able to show a regular audit is worth a great deal.

What to Put in the Client Contract

Most access disputes are not technical problems. They are contractual ones that nobody addressed while the relationship was good.

Settle these in writing at the start:

  • Who owns the sub-account if the relationship ends — you, or the client.
  • Who owns the contact data. In almost every case this should be the client, and saying so plainly builds trust.
  • What happens at termination — is the account transferred, is a data export provided, and within what timeframe.
  • Who owns custom builds — funnels, workflows and snapshots you created. Agencies reasonably retain their own templates while handing over the client-specific configuration.
  • What level of access the client has during the engagement, so restricted access is an agreed arrangement rather than a discovery.
  • Notice period and offboarding process.

Clients rarely object to any of this when it is raised at the start. They object strongly when it is raised for the first time during a cancellation, and that is when an ordinary parting becomes a dispute worth avoiding.

Frequently Asked Questions

Can I create fully custom roles?

You work from the built-in roles and adjust the permission toggles, which in practice gives you most of what a custom role system would. Standardise your own combinations and apply them consistently.

Can a user have different permissions in different sub-accounts?

Yes. Access is granted per sub-account, so someone can be an admin on one client and restricted on another. This is how most agency teams should be structured.

Should clients get admin on their own account?

Depends on your model. Software resellers usually say yes; done-for-you service agencies usually restrict settings. Decide deliberately and put it in the contract.

How do I stop someone exporting contacts?

Disable the export permission on their user. Treat it as a deliberate grant rather than a default.

What happens to contacts when I delete a user?

Reassign first. Deleting an owner without reassignment leaves contacts unowned, which means nobody gets notified about their leads.

Spend the Twenty Minutes

Permissions are boring until the moment they are not. Setting them properly on a new sub-account takes twenty minutes; recovering from a contractor exporting a client’s database takes a great deal longer and may cost you the client.

GHL Nexa sets up role structures and access policies as part of agency builds, including the offboarding checklists that keep them clean. Get in touch if everyone in your account is currently an admin.

Ready to Implement This?

Let GHL Nexa set this up for you. Book a free 30-minute strategy call today.

SHARE THIS ARTICLE