Client Sub-Accounts

314 visitas Markdown

Give other people limited access without sharing the account owner's password, control what they may do with permissions, and revoke access immediately when needed.

Opening the Screen

Open a client and choose the Sub-Accounts tab: {admin}/users/detail?id={client}&tab=sub-users

What Is on the Screen

List Columns for full name, e-mail, last sign-in and status, with edit and remove actions at the end of each row.
Adding a sub-account A form of e-mail, label, permissions and notification preferences. Sending the invitation is optional.
Editing The person's name and e-mail are shown read-only; the label, status and permissions can be changed. The invited, accepted and last sign-in dates sit here.

Statuses

There are three: pending invitation, active and inactive. Someone pending has not accepted the account yet; someone set inactive can no longer reach the account, but the record is kept.

Permissions

There are eleven, and all of them arrive ticked. A sub-account sees only the areas that are ticked; opening a page belonging to an unticked one is refused in the client panel.

View services Opens the account's service list and the service details. On its own it is read-only.
Manage services Allows changes on a service: automatic renewal, cancellation, upgrade, add-on cancellation and billing profile. Ticking it also grants viewing.
View service passwords Makes the service's control panel password readable.
One-click sign-in to control panels Allows passing into the service's own panel without being asked for a password.
View domain names Lists the account's domain names.
Manage domain names Opens domain work such as name servers, the lock and contact details.
View invoices Opens the account's invoices and payment history.
View support requests Allows reading and answering requests raised for the account.
View affiliate account Opens the affiliate page where there is one.
View reseller account Opens the reseller page where there is one.
Place new orders Allows ordering on the account's behalf.

Fields

Email The sub-account's identity; the invitation goes to this address.
Label A short name that tells the person apart in the list.
Send Invite Sends the invitation e-mail on save. Switched off, the record is still created and the person waits without an invitation.
Permissions Ten permissions, all ticked to begin with. One button turns the whole set on or off.
Label (editing) The label of an existing sub-account.
Status Pending invitation, active or inactive.

Tasks

Invite a sub-account

  1. Use the add button and enter the person's e-mail address.
  2. Untick the permissions you do not want to hand over.
  3. Save with the invitation box ticked. The person lands in the list as pending, and becomes active once they accept.

Resend an invitation

  1. Open the menu at the end of a pending row.
  2. Use the resend action. A fresh invitation e-mail goes out and the status stays pending.

Suspend a sub-account without deleting it

  1. Open the person for editing.
  2. Set the status to inactive and save. They drop out of the account on their next request, and their permissions and history stay on the record.

Sign in as a sub-account

  1. Open the person for editing.
  2. Use the sign-in action. The client panel opens exactly as that person sees it - the areas they have no permission for are closed there too.

Things to Watch

Taking a permission away works at once

Permissions are not written into the session; they are read again on every request. Remove one and the sub-account loses that area on their next click - there is no need to wait for them to sign out.

Only an active client account can receive sub-accounts

The add form accepts a sub-account only when the account you are on belongs to a client and is active. On a staff account or a suspended client the save is refused and a warning is shown on screen.

The account's identity cannot be handed over

A sub-account works inside the account; it cannot change who the account is. Profile details, contacts and security settings stay on the account holder's own page.

Accepting an invitation does not verify the address

When e-mail verification is on for sign-up, a person who accepts an invitation starts unverified. They receive the activation mail and can use only Account Settings and Support until they confirm the address. Sharing the invitation link by hand does not skip that step.

Every client account has a sub-account limit

Pending invitations count toward it. Once the limit is reached, the add form, the client's own Sub-Accounts page and the API refuse a new one. The limit is set under Settings → General → Clients. Invitation e-mails leave through the notification queue and arrive about a minute after the save.

Passwords and one-click sign-in are strong permissions

Both amount to reaching the service's own control panel. Hand them only to the people actually working on the server.

Required Privileges

Reading the tab comes with the client record. Adding, editing and removing a sub-account, and resending an invitation, need USERS_OPERATION.

¿Le ha resultado útil?

¡Gracias por sus comentarios!

¿Todavía necesita ayuda?

Nuestro equipo de soporte está disponible las 24 horas para ayudarle con lo que no encuentre aquí.