Course 10 · Lesson 2 of 7

Give teammates the least privilege they need

Choose between account and workspace access and the Manager, Editor, and Viewer roles, so each person can do their job and nothing wider.

Lesson 2 of 7 in Run an Agency or Multi-Client Practice

Why this matters

In a multi-client practice, access control is part of the service you sell. A contractor who writes for one client should not see the other nineteen, and a junior teammate should not activate a plan, change a client's targets, or publish for a client without review. Roles decide who can change a client's plan, evidence, and integrations, and who has to ask first. Getting them right keeps human judgment in the Plan and Execute steps, and lets you answer plainly when a client asks who can touch their account.

When to use it

When you invite anyone, when a person's responsibilities change, when a contractor's engagement ends, and as a quarterly review of every workspace.

Before you start

  • Your own role. The Team settings tab is visible to owners and managers. Only the account owner can invite or remove account teammates; only a workspace owner can invite workspace collaborators.
  • Each person's job in one sentence: approve and ship work, prepare work for review, or only read.

Do this

  1. 1Open Settings → Team. It manages account-wide teammates separately from people who can access only the selected workspace.
  2. 2For people who work across your practice, use Invite teammate and choose an Account role: Teammate or Account manager. Account teammates can access every workspace. Each active teammate or pending invitation uses one paid seat, and a badge shows seats used.
  3. 3For a contractor or someone at the client, use Invite workspace collaborator instead (offered on agency accounts). It grants access to this workspace only. Choose Manager, Editor, or Viewer, then Invite collaborator, and send the link it creates.
  4. 4Match the role to the job. Managers can approve requests, activate plans, change targets, publish, manage integrations, and add or delete Research sources. Editors can edit client data and read Research, but plan activation, target changes, manual publishing, and suggested changes go to a manager as a request. Viewers cannot change anything. An account Teammate works as an Editor in every workspace.
  5. 5Decide Pending requests on the same page, where editors route privileged actions. Add a Decision note, then Approve or Deny.
  6. 6When staffing changes, Revoke unused invitations; the account owner can Remove an account teammate. The page lists workspace collaborators but offers no control to change or remove them, so choose their role carefully when you invite.

What you should see

Each person appears with a role badge, and Workspace access marks the billing owner. When someone attempts an action outside their role, the app refuses it with a plain message (they lack permission, or manager approval is required) instead of failing silently. Pending requests show who asked, when, and what.

How to judge it

For every person in every workspace you can state their role and the job it covers. No contractor holds account-wide access, nobody who only reads holds Editor or Manager, and Pending requests holds nothing you will not decide this week.

What it does not mean

Least privilege is not the lowest role for everyone. An editor who must ask for every routine change will work around the system, which is a workflow failure, not security. Roles also do not replace review: a manager can still approve the wrong change, which is why the decision note matters.

Try it in Signal & Science

Open Clients, choose one client, and write down who needs access to it and the smallest role each person needs.

Open in Signal & Science

Put it to work

Know what to do next.Know whether it worked.

Signal & Science keeps the evidence, the plan, and the results in one place, so each lesson here becomes a working habit in your own workspace.