Manage Agency access to a child workspace
Understand Agency-covered billing, grant only explicit operational access, and keep each child workspace's data and protected settings isolated.
Sign in to your company workspace to use the related controls.
What this section includes
- Agency-covered billing
- Separate tenant data
- Explicit grants
- Role-based access
- Granular permissions
- Revocation
- Access-event history
- Aggregate reports
Start-to-finish instructions
Confirm billing coverage
The parent Agency account is the billing account. An authorized child workspace is covered and is not subscribed separately by default.
Confirm the privacy boundary
Billing coverage does not let the Agency see child data. Each child remains a separate tenant.
Choose the minimum grant
Select only required operational permissions. Customer data, invoices, messages, and private records stay hidden unless their section is granted.
Check the Agency role
Agency owners and admins remain limited by the child grant. Support users have an additional non-financial role cap.
Enter child context
Confirm the workspace indicator before viewing permitted records.
Review access history
Use Recent Agency access to review every allowed or denied child-context request without exposing record contents.
Revoke or suspend
Remove access immediately without deleting or disabling the child company.
Review Agency reports
Use only aggregate counts for children that explicitly grant reports.view.
What success looks like
- The child Billing page says Agency covered and does not offer a second subscription.
- Access is denied before an explicit active grant.
- Revocation invalidates an existing child context on its next request.
- Every allowed or denied child-context request creates an append-only access event.
- Billing, ownership, security, recovery, roles, and platform administration remain blocked in child context.
Common problems
- A child with an existing direct subscription is marked for Super Admin reconciliation and is not changed automatically.
- Live Agency billing activation remains disabled until final Agency rules are approved.
- Unknown routes fail closed in Agency child context.
- Agency Support cannot access invoices, messages, or edit customer, lead, or estimate records even when the child grants those sections; assign Agency Admin only when that broader role is intended.
