SourCherry Help Centre

Agency | Managing User Roles & Permissions

In this article, we discuss how you, as an agency admin, can granularly manage your users' permissions across various modules.

If you are here looking for sub-account's user roles and permission management, click here.


TABLE OF CONTENTS


Getting started with user permissions


To manage users' permissions for an agency,



Assigning user type and role



Restrict access to specific sub-accounts


Agency admins can assign agency admins to specific sub-accounts and restrict them from accessing other sub-accounts to which they are not assigned. 


For example, Alex, who is an agency admin, can access only assigned sub-accounts '78th Avenue' and 'A Mailbox NYC', without compromising his access level. However, he will not be able to access 'Baker's Inn' which he is not assigned to.





Assign Permissions


Agency admins can apply granular permissions to their users. You may control the permissions at two levels:


The new permissions structure is backward compatible with the old set of permission structures and their functionalities.




What does that each permission mean,

Sub-Account Settings (Granular Permissions)


As agencies grow, you may want to delegate sub-account administration without granting full access to sensitive settings. Sub-Account Settings permissions let you control who can view, edit, or manage key areas across sub-accounts.


Where these permissions apply


When a user tries to access a restricted area or perform a restricted action, SourCherry displays contextual messaging explaining that the action is not allowed for their permission level.


Steps to Stop a User From Opening New Sub-accounts


Creating brand-new sub-accounts is not controlled by the list above. It’s an Agency-level permission.

  1. Go to Agency view → Settings → Team

  2. Open the user → Roles & Permissions

  3. Find Sub-Accounts (Agency module)

  4. Uncheck “Create Sub-Accounts” (and “Delete” if needed)

  5. Tggle Sub-Accounts = Off to hide it completely


User Management → Login As


Enable Login As controls whether an agency admin can impersonate another user via Login As.




Copy Permissions


Agency admins can copy a user’s granular permissions to another user. For example, when Bob joins the sales team, the admin can clone Alex’s permissions to Bob.


Adding Clients to a Sub-Account with Limited Access


Clients should not be added as agency-level users. Instead, they should be added directly within the sub-account associated with their business, where you can assign specific permissions and roles tailored to their needs. Adding clients at the agency level will give them unnecessary visibility across all sub-accounts—something you likely want to avoid.


Follow these steps to add a client to a sub-account and control their permissions:



User Management API support


The User Management permissions supports API-based updates when Enhanced Security is disabled. Use this option when your agency manages users through API-first workflows or high-volume operational processes.


Supported User Management permission levels:


View & Manage Users: Allows users to view, create, and edit users.

View Users: Allows users to view users only.


To enable API-based user-management updates, from Agency level go to Settings > Company > Advanced Settings and disable Enhanced Security.