Understand Permissions and Delegated Access
Know what each role can do, where company billing ends and workspace data begins, and how agency delegation changes what you see.
Overview
CntX permissions operate on two layers:
- Company — billing, user administration, delegation to agencies, and shared company context.
- Workspace — editorial assets: strategy, calendar, content, campaigns, and workspace integrations.
Your company role gates admin screens. Workspace membership gates day-to-day editorial work. Agency delegation adds a third pattern: an agency user operating inside a client’s company with admin-like powers but contractual limits.
When to use
- A teammate cannot see Billing, Users, or Company context and you need to know if that is expected.
- An agency user needs to work inside a client account without owning the subscription.
- You plan who should invite users, connect integrations, or approve content.
- You troubleshoot “access denied” or missing sidebar items.
Before you start
- Know your company role (check Settings → Users or your profile).
- Confirm the active workspace and, for agencies, whether you are in a delegated client context (URL may include `delegatedCompanyId`).
- Distinguish platform users (ADMIN–VIEWER) from email-only contributors (no login) and CONTRIBUTOR platform seats.
Steps
1. Company roles at a glance
| Role | Typical capabilities |
|---|---|
| ADMIN | Invite users, manage billing, company settings, all workspaces, delegation mandates |
| MANAGER | User/team management, broader settings; may not access all billing actions |
| EDITOR | Create and edit editorial assets; limited admin settings |
| VIEWER | Read-only; company description and some context sections may be hidden |
| CONTRIBUTOR | External platform seat (Business); scoped access for collaboration—not a full editor replacement |
Only ADMIN can send company invitations. Users cannot modify their own role.
2. Workspace isolation rules
Within a workspace, users see:
- That workspace’s calendar, content, strategy, and campaigns
- Workspace-scoped integrations (WordPress, Webflow, etc.)
- Contributors and inbound email configured for that workspace
They do not automatically see sibling workspaces unless explicitly assigned. Company-level crawl usage and storage quotas still aggregate at the company boundary.
3. Delegated agency access
When a Business client grants an agency a delegation mandate:
- The client keeps their subscription, data ownership, and primary admin access.
- The agency operates with ADMIN-level capabilities inside the client company.
- The agency cannot delete a delegated client company account.
- Billing screens may reflect the client’s plan, not the agency’s gateway subscription.
Flow summary: client searches agency → sends mandate → agency accepts checkbox terms → delegation status ACCEPTED. Either party can Revoke later.
4. Owned agency accounts (contrast)
Agencies may also create owned client companies (up to 5 per agency):
- The agency is full owner; the client may have no CntX login.
- The agency manages billing and lifecycle, including deletion.
- This is different from delegation—the client is not an equal account holder.
5. What changes in the UI under delegation
When an agency user opens a delegated client:
- Sidebar Accounts or context banner indicates client mode.
- Home pre-onboarding copy may say answers qualify the client workspace, not the agency.
- Some billing actions remain client-only; agency users manage editorial execution.
If you expected billing controls but only see editorial sections, verify you are in the correct company context.
Expected result
- You can predict which settings pages each teammate reaches before inviting them.
- Agency users work inside client tenants without merging data into the agency company.
- Viewers consume content safely without mutating strategy or publishing integrations.
Tips
- Grant EDITOR broadly and reserve ADMIN for operators who own billing and user lifecycle.
- When delegating to an agency, use the in-product mandate flow—do not share passwords.
- After switching companies (agency portfolio), re-check the workspace switcher—permissions do not carry stale workspace IDs across tenants.
- Email-only contributors never appear in role matrices; they are workspace email contacts only.
Next step
Finish workspace-level setup in Complete Workspace Setup Readiness, or configure agency operations in Use Agency Mode.
Ready to try this in CntX?
Open the product and apply this guide to your workspace.