Team members work inside your workspace; client contacts only ever see portals. The two are separate systems, so a teammate can never be accidentally exposed as a client user.
The roles
Four roles cover almost every agency structure. Permissions are cumulative — each role includes everything below it.
Everything, plus billing, plan changes, domains, and workspace deletion. One owner at a time.
All clients, portals, invoices, branding, and team management. No plan or workspace deletion.
Projects, tasks, files, and feedback on the clients they're assigned to. No invoice sending by default.
Assigned projects and tasks only. No client list, no billing, no portal settings.
Invite a teammate
Add people from Settings → Team. Pick the role first, then choose which clients they can reach.
- Invites expire after 14 days
- Seats are counted per active teammate, not per invite
- Change a role at any time without re-inviting
Scope access to clients
Members and contractors see only the clients you assign. Everything else — including the client list itself — is hidden from their navigation.
Contractors and freelancers
Contractors get a deliberately narrow view: their tasks, the files attached to them, and the internal threads they're mentioned in. Nothing commercial.
- No access to invoices, revenue, or client billing details
- Cannot invite client contacts or change portal settings
- Internal notes are visible only where they're @mentioned
- Access ends the moment you remove them from the project
Offboarding and ownership transfer
Removing someone revokes access immediately but keeps their work history intact. Reassign their open tasks first so nothing goes quietly unowned.
- Transfer ownership before the owner leaves the agency
- Removed teammates free their seat on the next billing cycle
- Re-inviting someone restores their history