> For the complete documentation index, see [llms.txt](https://help.gleantap.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.gleantap.com/settings/add-remove-sub-users.md).

# Add / Remove Sub Users

Sub-users are teammate accounts on your Gleantap workspace. Each sub-user has a role that determines what they can do, a set of workrooms they can access, and optional guardrails like approval requirements before their campaigns go live.

This page covers the day-to-day management (adding, removing, editing) and the basics of the role system. For the full permission matrix and custom roles, see Roles & Permissions Reference.

***

## Adding a sub-user

**Step 1** — Click your initials in the top-right of the app, then click **Settings**.

<figure><img src="https://312952119-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaFKpjLzPT7iDAWD0tQXo%2Fuploads%2FaybWOu4vwgSq7MZO8FpF%2FScreenshot%202023-09-28%20at%2011.06.22%20AM.png?alt=media&#x26;token=62fc51ac-d1ea-4464-b25e-29a45e295ed1" alt=""><figcaption></figcaption></figure>

**Step 2** — Select **Sub Users** from the left-hand menu.

<figure><img src="https://312952119-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaFKpjLzPT7iDAWD0tQXo%2Fuploads%2FIVSZ981zIT0W793lF8mP%2FScreenshot%202023-09-28%20at%2011.35.27%20AM.png?alt=media&#x26;token=c096717d-544e-43a1-86e6-5478ebd9e338" alt=""><figcaption></figcaption></figure>

**Step 3** — Click **Add Sub User** in the top-right of the Sub Users page.

<figure><img src="https://312952119-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaFKpjLzPT7iDAWD0tQXo%2Fuploads%2Fft2G2DcITPerp9KeAZMZ%2FScreenshot%202023-09-28%20at%2011.36.34%20AM.png?alt=media&#x26;token=3d2e3655-3d8d-441a-9336-a4b069d061a1" alt=""><figcaption></figcaption></figure>

**Step 4** — Fill in the invite form:

| Field                                     | What it does                                                                                      |
| ----------------------------------------- | ------------------------------------------------------------------------------------------------- |
| **Name**                                  | Displayed name of the teammate                                                                    |
| **Email**                                 | Their login email; the invite email is sent here if you check "Send invite"                       |
| **Password**                              | Initial password (they can change it after first login)                                           |
| **Workroom(s)**                           | Which workrooms this user can access — required for multi-location accounts                       |
| **Role**                                  | Predefined (Admin / Workroom Admin / Marketing / Sales / Analyst) or a custom role                |
| **Voice Calling**                         | Optional — grant access to make outbound calls                                                    |
| **Require Approval on Campaigns & Flows** | Optional guardrail — see [Campaign Approval](/settings/add-remove-sub-users/campaign-approval.md) |
| **Send invite to user**                   | Emails the login link automatically                                                               |

Save the form. The user can log in immediately (or click the emailed link if you sent one).

<figure><img src="https://312952119-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaFKpjLzPT7iDAWD0tQXo%2Fuploads%2FhO7F8dRRXY7hJA4ifBuD%2FScreenshot%202023-09-28%20at%2011.37.46%20AM.png?alt=media&#x26;token=0d25ff9c-b14f-4ff8-8e7d-93d864479796" alt=""><figcaption></figcaption></figure>

***

## Predefined roles at a glance

| Role               | Access                                                                                   |
| ------------------ | ---------------------------------------------------------------------------------------- |
| **Admin**          | Full access to every workroom on the account and every setting                           |
| **Workroom Admin** | Full access to only the workrooms assigned to this user                                  |
| **Marketing**      | General section, Scorecards, and Marketing (Campaigns, Flows, Forms & Pages, Reputation) |
| **Sales**          | General section, Scorecards, and Sales (Pipeline, Appointments)                          |
| **Analyst**        | Read-only for General, Scorecards, and Marketing (can view but not edit)                 |

For the full permission matrix — exactly which actions each role can perform on each feature — see Roles & Permissions Reference.

**If none of the predefined roles fits your team's needs**, you can create a custom role with a granular permission set. See Roles & Permissions Reference → Custom roles.

***

## Multi-workroom access

If your account has multiple workrooms (see Managing Multiple Locations), you can grant a sub-user access to one, several, or all of them.

* **Admin role** — inherits access to all workrooms; the workroom picker doesn't apply.
* **Workroom Admin, Marketing, Sales, Analyst, and custom roles** — access is limited to the workrooms you select on the invite form.

To change a user's workroom access later, edit their profile and update the Workroom(s) field.

***

## Requiring approval on campaigns and flows

You can optionally require that a sub-user's campaigns and flows be approved by an admin before going live. This is useful for training junior teammates or agencies where you want a check before customer-facing sends.

Enable the **Require Approval on Campaigns & Flows** toggle when creating or editing the sub-user.

See [Campaign Approval](/settings/add-remove-sub-users/campaign-approval.md) for how the approval flow works.

***

## Editing a sub-user

To change a teammate's role, workroom access, or approval requirement:

1. Go to **Settings → Sub Users**.
2. Click the user in the list to edit their profile.
3. Change the role, workroom(s), or approval flag.
4. Click **Save**. Changes take effect immediately — no re-login required.

***

## Removing a sub-user

1. Go to **Settings → Sub Users**.
2. Find the user in the list.
3. Click the **trash icon** on the right and confirm in the pop-up.

<figure><img src="https://312952119-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FaFKpjLzPT7iDAWD0tQXo%2Fuploads%2FUqRsnTMutQot6bYxBb9r%2FScreenshot%202023-09-28%20at%2011.40.35%20AM.png?alt=media&#x26;token=164e8c46-5c60-418d-ae1e-b4ae526103d3" alt=""><figcaption></figcaption></figure>

Their account is deactivated immediately. Any campaigns, flows, or contacts they own remain in the workroom and continue to run.

***

## Login security

### Two-factor authentication (2FA)

Gleantap supports **email-based 2FA** as an account-level setting. When enabled, every user on the account receives a verification code by email on every login and must enter it before accessing the workspace.

**To enable 2FA:**

1. Click your initials in the top-right → **Settings**.
2. On the **Account Info** page, find the **Two Factor Authentication** checkbox.
3. Check the box to enable, then save.

Once turned on, 2FA applies to every user on the account — including admins and all sub-users — on their next login. There's no per-user opt-out; it's all-or-nothing at the account level.

**A few things to know before enabling:**

* Users must have access to the email address on their sub-user profile to receive the login code.
* If a teammate's inbox is slow (e.g., corporate email with strict filters), logins may take longer.
* To disable, uncheck the toggle on the same page. The change takes effect on next login for all users.

### Single Sign-On (SSO / SAML)

Not currently available. If your organization requires SSO, email <support@gleantap.com> — let us know what you need.

### Other recommendations

* Use strong per-user passwords, managed via a shared password manager.
* Remove sub-users promptly when teammates leave.
* Use the Campaign Approval guardrail for junior users.

***

## Common scenarios

### "I want to give someone read-only access"

Use the **Analyst** role — it grants view access to Marketing but blocks edits. Or create a custom role that grants view on the specific modules you want and no other actions. See Roles & Permissions Reference.

### "A sub-user needs access to a new workroom I just set up"

Edit their profile → update the Workroom(s) field to include the new workroom → Save. Access is immediate.

### "I want to see what a sub-user has done"

Individual action logs aren't exposed in the UI as a per-user activity report. If you need this, email <support@gleantap.com> with the user and time range.

### "How do I transfer campaigns and flows before removing someone?"

Campaigns, flows, and contacts stay attached to the workroom, not the individual user. Removing a sub-user doesn't delete or move any of that content — you can still access and edit it as an admin.

***

## Related pages

* [Campaign Approval](/settings/add-remove-sub-users/campaign-approval.md) — approval workflow for junior users
* Roles & Permissions Reference — full permission matrix and custom roles
* Managing Multiple Locations — how workroom access works


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.gleantap.com/settings/add-remove-sub-users.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
