Client Permissions Model
A clear breakdown of the three roles in Outercite for agencies: agency admin, account manager, and client viewer, and what each one can access.
Outercite uses a three-tier role model designed for agency workflows. Your team gets the access they need to do their job. Your clients get a read-only view of their own data. Nobody sees anything they should not.
What you'll learn
- The three roles and what each one can do
- How to assign roles when inviting team members or clients
- Which permissions protect client data from cross-workspace exposure
The three roles at a glance
| Permission | Agency admin | Account manager | Client viewer |
|---|---|---|---|
| Access parent org settings | Yes | No | No |
| View portfolio health (all clients) | Yes | No | No |
| Create and archive workspaces | Yes | No | No |
| Manage billing | Yes | No | No |
| Invite users to any workspace | Yes | No | No |
| Add/edit/delete keywords | Yes | Yes | No |
| Add/edit competitors | Yes | Yes | No |
| Run audits | Yes | Yes | No |
| Configure alerts | Yes | Yes | No |
| Schedule reports | Yes | Yes | No |
| View citation data | Yes | Yes | Yes |
| Download reports | Yes | Yes | Yes |
| Access other workspaces | Yes | Assigned only | No |
Role 1: Agency admin
The agency admin role is for people who manage the agency account as a whole. This is typically a director, operations lead, or technical owner.
Agency admins can see everything: the parent org dashboard, every client workspace, billing, and team management. There is no workspace they cannot enter. This role should be given to a small number of trusted people.
Check your plan for any seat limits on the agency admin role. Regardless of limits, treat this role as you would admin access to any critical system: assign it narrowly.
Agency admins can delete client workspaces and their citation history. Contact support promptly if a workspace needs recovery, as recovery may not always be possible. Reserve the admin role for people who genuinely need parent-org access.
Role 2: Account manager
Account managers are the day-to-day operators. This is the right role for most of your delivery team: SEO specialists, content strategists, and client services managers.
You assign an account manager to one or more specific workspaces. They cannot see or enter any workspace they are not assigned to. Within their assigned workspaces, they have full editorial control: adding keywords, updating competitor lists, running audits, and scheduling reports.
Account managers do not see the portfolio health view (that is an agency admin feature) and they cannot create new workspaces. They work within the boundaries you set.
Assigning an account manager to a workspace
- From the parent org, open Team
- Find the team member (or invite them if they are new)
- Click Manage access
- Toggle on each workspace they should have access to
- Save
You can adjust workspace assignments at any time. Removing access takes effect immediately: the next time that person refreshes, the workspace disappears from their switcher.
Role 3: Client viewer
The client viewer role is for your clients. It gives read-only access to a single workspace.
A client viewer can:
- See citation rate, visibility score, and share of voice for their brand
- View per-engine citation breakdowns (across the six tracked AI engines: ChatGPT, Claude, Perplexity, Google AI, Grok, and DeepSeek)
- Download reports
- View their keyword list (but not edit it)
A client viewer cannot:
- Edit anything in the workspace
- See any other workspace
- Access billing or team settings
- See the agency's branding configuration
If you want a client to see their data without creating a login for them, use a shared portal link instead. Shared portals are read-only and branded with your agency identity. See White-Label Reports for details.
When to use a login vs a shared portal
Use a client viewer login when:
- The client wants ongoing, self-service access to their data
- You want the client to receive alert emails directly
- The client is sophisticated and will navigate the workspace themselves
Use a shared portal link when:
- You want to send a one-off or periodic snapshot
- The client does not need (or want) a product login
- You want full control over what they see and when
Permissions are enforced at the data layer
The role boundaries in Outercite are not just UI restrictions. A client viewer's session token is scoped to their workspace at the API level. Even if someone with a client viewer login attempted to query another workspace's data directly, the request would be rejected.
This matters for agencies managing clients who are competitors of each other. You can onboard two businesses in the same category, give each a client viewer login, and be confident neither can access the other's citation data or keyword list.
Changing a user's role
To change someone's role:
- Go to Team in the parent org (agency admin only)
- Find the user
- Click the role badge next to their name
- Select the new role from the dropdown
- Confirm
Role changes take effect on the user's next page load. If they are currently logged in, their permissions update within a few seconds.
Try this in Outercite
Go to /agency and open Team to review your current role assignments. If you have team members on the account manager role who should only see certain clients, now is a good time to audit their workspace access.
Related
Parent Orgs vs Workspaces
Onboard a New Client
White-Label Reports
Creating Your First Workspace
White-Label Reports
Learn what Outercite lets you brand as your own, what stays transparent by design, and why the verification pipeline is never hidden from clients.
Agency Billing Model
How Outercite bills agencies on wholesale keyword tiers, how one invoice covers all clients, and how you set your own retail pricing to build margin.
