Client Sub-Accounts
Give other people limited access without sharing the account owner's password, control what they may do with permissions, and revoke access immediately when needed.
Opening the Screen
Open a client and choose the Sub-Accounts tab: {admin}/users/detail?id={client}&tab=sub-users
What Is on the Screen
Statuses
There are three: pending invitation, active and inactive. Someone pending has not accepted the account yet; someone set inactive can no longer reach the account, but the record is kept.
Permissions
There are eleven, and all of them arrive ticked. A sub-account sees only the areas that are ticked; opening a page belonging to an unticked one is refused in the client panel.
Fields
Tasks
Invite a sub-account
- Use the add button and enter the person's e-mail address.
- Untick the permissions you do not want to hand over.
- Save with the invitation box ticked. The person lands in the list as pending, and becomes active once they accept.
Resend an invitation
- Open the menu at the end of a pending row.
- Use the resend action. A fresh invitation e-mail goes out and the status stays pending.
Suspend a sub-account without deleting it
- Open the person for editing.
- Set the status to inactive and save. They drop out of the account on their next request, and their permissions and history stay on the record.
Sign in as a sub-account
- Open the person for editing.
- Use the sign-in action. The client panel opens exactly as that person sees it - the areas they have no permission for are closed there too.
Things to Watch
Permissions are not written into the session; they are read again on every request. Remove one and the sub-account loses that area on their next click - there is no need to wait for them to sign out.
The add form accepts a sub-account only when the account you are on belongs to a client and is active. On a staff account or a suspended client the save is refused and a warning is shown on screen.
A sub-account works inside the account; it cannot change who the account is. Profile details, contacts and security settings stay on the account holder's own page.
When e-mail verification is on for sign-up, a person who accepts an invitation starts unverified. They receive the activation mail and can use only Account Settings and Support until they confirm the address. Sharing the invitation link by hand does not skip that step.
Pending invitations count toward it. Once the limit is reached, the add form, the client's own Sub-Accounts page and the API refuse a new one. The limit is set under Settings → General → Clients. Invitation e-mails leave through the notification queue and arrive about a minute after the save.
Both amount to reaching the service's own control panel. Hand them only to the people actually working on the server.
Required Privileges
Reading the tab comes with the client record. Adding, editing and removing a sub-account, and resending an invitation, need USERS_OPERATION.
Related Articles
¡Gracias por sus comentarios!
Nuestro equipo de soporte está disponible las 24 horas para ayudarle con lo que no encuentre aquí.