OuterciteOutercite
Core Concepts

Client Permissions Model

A clear breakdown of the three roles in Outercite for agencies: agency admin, account manager, and client viewer, and what each one can access.

Outercite uses a three-tier role model designed for agency workflows. Your team gets the access they need to do their job. Your clients get a read-only view of their own data. Nobody sees anything they should not.

What you'll learn

  • The three roles and what each one can do
  • How to assign roles when inviting team members or clients
  • Which permissions protect client data from cross-workspace exposure

The three roles at a glance

PermissionAgency adminAccount managerClient viewer
Access parent org settingsYesNoNo
View portfolio health (all clients)YesNoNo
Create and archive workspacesYesNoNo
Manage billingYesNoNo
Invite users to any workspaceYesNoNo
Add/edit/delete keywordsYesYesNo
Add/edit competitorsYesYesNo
Run auditsYesYesNo
Configure alertsYesYesNo
Schedule reportsYesYesNo
View citation dataYesYesYes
Download reportsYesYesYes
Access other workspacesYesAssigned onlyNo

Role 1: Agency admin

The agency admin role is for people who manage the agency account as a whole. This is typically a director, operations lead, or technical owner.

Agency admins can see everything: the parent org dashboard, every client workspace, billing, and team management. There is no workspace they cannot enter. This role should be given to a small number of trusted people.

Check your plan for any seat limits on the agency admin role. Regardless of limits, treat this role as you would admin access to any critical system: assign it narrowly.

Agency admins can delete client workspaces and their citation history. Contact support promptly if a workspace needs recovery, as recovery may not always be possible. Reserve the admin role for people who genuinely need parent-org access.

Role 2: Account manager

Account managers are the day-to-day operators. This is the right role for most of your delivery team: SEO specialists, content strategists, and client services managers.

You assign an account manager to one or more specific workspaces. They cannot see or enter any workspace they are not assigned to. Within their assigned workspaces, they have full editorial control: adding keywords, updating competitor lists, running audits, and scheduling reports.

Account managers do not see the portfolio health view (that is an agency admin feature) and they cannot create new workspaces. They work within the boundaries you set.

Assigning an account manager to a workspace

  1. From the parent org, open Team
  2. Find the team member (or invite them if they are new)
  3. Click Manage access
  4. Toggle on each workspace they should have access to
  5. Save

You can adjust workspace assignments at any time. Removing access takes effect immediately: the next time that person refreshes, the workspace disappears from their switcher.

Role 3: Client viewer

The client viewer role is for your clients. It gives read-only access to a single workspace.

A client viewer can:

  • See citation rate, visibility score, and share of voice for their brand
  • View per-engine citation breakdowns (across the six tracked AI engines: ChatGPT, Claude, Perplexity, Google AI, Grok, and DeepSeek)
  • Download reports
  • View their keyword list (but not edit it)

A client viewer cannot:

  • Edit anything in the workspace
  • See any other workspace
  • Access billing or team settings
  • See the agency's branding configuration

If you want a client to see their data without creating a login for them, use a shared portal link instead. Shared portals are read-only and branded with your agency identity. See White-Label Reports for details.

When to use a login vs a shared portal

Use a client viewer login when:

  • The client wants ongoing, self-service access to their data
  • You want the client to receive alert emails directly
  • The client is sophisticated and will navigate the workspace themselves

Use a shared portal link when:

  • You want to send a one-off or periodic snapshot
  • The client does not need (or want) a product login
  • You want full control over what they see and when

Permissions are enforced at the data layer

The role boundaries in Outercite are not just UI restrictions. A client viewer's session token is scoped to their workspace at the API level. Even if someone with a client viewer login attempted to query another workspace's data directly, the request would be rejected.

This matters for agencies managing clients who are competitors of each other. You can onboard two businesses in the same category, give each a client viewer login, and be confident neither can access the other's citation data or keyword list.

Changing a user's role

To change someone's role:

  1. Go to Team in the parent org (agency admin only)
  2. Find the user
  3. Click the role badge next to their name
  4. Select the new role from the dropdown
  5. Confirm

Role changes take effect on the user's next page load. If they are currently logged in, their permissions update within a few seconds.

Try this in Outercite

Go to /agency and open Team to review your current role assignments. If you have team members on the account manager role who should only see certain clients, now is a good time to audit their workspace access.

Was this helpful?