Skip to contentNew ·Latest HighLevel feature updates, explained
Nexus Hub
SaaS operationsPublished Sep 25, 2026

How to Configure Sub-Account and User Permissions in HighLevel

A practical guide to configuring sub-account feature sets and user permissions in HighLevel to maintain tier boundaries and protect recurring revenue.

By Charles Higgins · 5 min read

An abstract geometric illustration showing layered structural shields and clean access nodes in slate blue and deep gray tones.

Operating a software-as-a-service model requires strict boundaries around feature accessibility. When clients gain access to advanced workflows, bulk messaging, or specialized tools included only in higher pricing tiers, your agency loses revenue leverage. Unintentional feature provisioning usually stems from a misunderstanding of how permission levels function within the platform.

To prevent revenue leakage and maintain operational clarity, HighLevel enforces a dual-layered permission system. By distinguishing between sub-account capability limits and individual user rights, agency owners can reliably enforce subscription tier boundaries without manual micro-management.

Understanding the Permission Hierarchy

Sub-account permissions set the absolute ceiling for what any user inside that environment can access. If a feature—such as AI automation or advanced reporting—is disabled at the sub-account level, no individual user within that account can view or use it, regardless of their assigned administrative role.

The architecture operates on three distinct governance layers:

  • Agency Level: Controls global settings, subscription plan definitions, and master feature fulfillment templates.
  • Sub-Account Level: Governs available tools, integrations, and operational modules accessible to that specific location.
  • User Level: Dictates individual staff member visibility and editing rights within the constraints set by the sub-account.

The core rule of feature management is straightforward: a user account can never possess greater access rights than the parent sub-account allows.

Modifying Sub-Account Capabilities in Agency View

When a customer purchases a specific SaaS tier, automated provisioning assigns feature sets configured in your plan builder. However, custom enterprise deals, manual plan upgrades, or temporary trial add-ons require agency administrators to alter a sub-account's master permissions directly.

To update master feature availability for an existing location:

  1. Navigate to the Agency View dashboard and select the Sub-Accounts section.
  2. Locate the specific account in your sub-account registry.
  3. Open the action menu for that account and choose the Manage Client option.
  4. Scroll to the Enable/Disable Products section to inspect active tools.
  5. Toggle specific capabilities on or off to adjust the master permissions for that location.

Changes made at the sub-account level take effect immediately, removing or exposing top-level navigation items across all user accounts tied to that location.

Configuring User-Level Access and Roles

Unlocking a feature at the sub-account level makes the tool available inside the location, but individual team members still require explicit user-level permission to see it on their sidebar menu.

To adjust individual permissions within a sub-account:

  1. Switch into the targeted sub-account environment and access the Settings menu.
  2. Select Team Management to display all active profiles linked to the location.
  3. Click Edit on the designated user profile.
  4. Expand the User Permissions menu to view individual feature toggles.
  5. Enable or disable specific items to align with the user's operational role.

Restricting user permissions is particularly useful for client accounts where staff members only need access to specific daily tools, such as conversations or calendar booking, while hiding financial settings and campaign workflows.

Operational Strategies to Protect Revenue Tiers

Relying on manual permission adjustments introduces human error over time. Establishing systematic control protocols protects your recurring revenue while minimizing administrative overhead.

  • Standardize SaaS Configurator Rules: Ensure every pricing tier in your SaaS settings precisely reflects your published feature matrix before launching prospective campaigns.
  • Audit High-Value Features Periodically: Run routine checks on premium features like automated phone systems, advanced API access, and workflow triggers to ensure active sub-accounts match their billed plan.
  • Document Tier Entitlements: Maintain clear internal documentation detailing exactly which modules belong to base, intermediate, and premium tiers so support staff do not accidentally enable unbilled features.
  • Implement Standard User Profiles: Advise clients to assign standard user roles rather than administrator rights to general staff members to prevent accidental system modifications.
Note

Troubleshooting Tip: If a user cannot view a feature despite having the user-level permission enabled, check the sub-account master settings. Features disabled at the sub-account level will override user-level permissions every time.

Need help applying this to your account?

Ask inside Nexus Hub — Charles is live Mon, Wed and Fri.

Related
About the author

Charles Higgins · Founder & Host, Nexus Hub

Charles is the founder of Pinnacle AI and a SaaSpreneur Gold Award winner. More about Charles

Feature updates

How this was researched, tested, and corrected: Nexus Hub editorial standards. Spotted an error? Report it and we will check it.

Nexus Hub is an independent community and educational resource. It is not affiliated with, endorsed by, or sponsored by HighLevel.