The Account Layer has its own permission model, separate from the existing workspace-level permissions (Org Controller, Project Controller, Team Member, etc.). This article explains the two Account Layer permissions available and what each can do.
The two Account Layer permissions
There are only two permissions at the Account Layer:
Permission | Can access Account Layer? | Can manage account-level items? |
Account Admin | Yes | Yes — full create, edit, delete |
Account User | No | No |
Everyone in your Sitemate Start account is an Account User by default. Account Admin is granted by your Sitemate Customer Success Manager.
What an Account Admin can do
An Account Admin has full access to the Account Layer. Specifically, they can:
View all users across every workspace in the Sitemate Start account.
Create, edit, and archive Account Templates.
Create, edit, and archive Account Lists.
Note: To become an Account Admin - the user must be an Org Controller across all workspaces in the account.
What an Account User can do
Account User is the default for everyone in the Sitemate Start account. Account Users:
Cannot access the Account Layer at all.
Cannot see the Account Layer in their Workspace Switcher.
Can continue using their workspaces as normal, with their existing workspace-level permissions (Org Controller, Project Controller, Team Member, etc.).
Will see Account Templates and Account Lists once they've been pulled into a workspace — but cannot edit their structure.
Account Layer permissions vs workspace permissions
Account Layer permissions and workspace permissions are completely independent. A user's Account Layer permission does not affect their workspace permission and vice versa.
Scenario | Workspace permission | Account Layer permission |
Standard org controller running one workspace | Org Controller | Account User |
Sitemate Start admin who manages templates across workspaces | Org Controller | Account Admin |
Standard project/team contributor | Project/Team Controller/Member | Account User |
In other words: being an Org Controller in a workspace does not automatically make you an Account Admin.
Notes / Tips
Always have at least two Account Admins per Sitemate Start account, so access is never blocked if one person is unavailable.
Account Admin is a powerful permission. Anyone with Account Admin can change templates that affect every workspace in the account — review who has it periodically.
Account Admins must be assigned manually.
