Starting 2026-09-27, the permissions that you give a sub-account apply to all service pages in the client area. A sub-account that has only View Products & Services can open your service pages, but it cannot make changes.


What you must do

If a sub-account must make changes to your services, give it the Manage Products & Services permission:

  1. Sign in to the client area as the account owner.
  2. Open the Contacts/Sub-Accounts page.
  3. Select the sub-account.
  4. Tick View Products & Services and Manage Products & Services.
  5. Click Save Changes.

If you do nothing, your sub-accounts can still see your services. The buttons that make changes are not shown to them until you give them the Manage permission.


What each permission does

PermissionWhat the sub-account can do
View Products & ServicesOpen service pages: recipients, filtering rules, forwards, statistics, SMTP senders, delegated admins, API keys, and inbound users.
Manage Products & ServicesMake changes on those pages. For example, it can add or remove recipients, change filtering rules, import lists, create API keys, and reactivate a service. The sub-account also needs View Products & Services.
Perform Single Sign-On to a Service ConsoleOpen the PhishProtection portal and the Message Log Viewer. The sub-account also needs View Products & Services.
View & Pay InvoicesOpen and change payment methods.

The SMTP Credentials page shows your SMTP passwords. To open it, a sub-account needs View Products & Services and Manage Products & Services.


What a sub-account sees without permission

When a sub-account opens a page or makes a change that it does not have permission for, it sees a message such as:

Your sub-account does not have permission to make changes to products and services on this account. Please contact the account owner.

Only the account owner can change the permissions of a sub-account.


Give sub-accounts only to people you trust

A sub-account can view all of your services, or view and change all of them. You cannot limit a sub-account to some services. Give a sub-account only to a person that you trust with your account.

An API key belongs to your account, not to the sub-account that created it. If you remove a sub-account, the API keys that it created continue to work. Delete the keys on the Customer API Key Manager page if you do not need them.


To add a sub-account, see Create a Sub-Account in DuoCircle Portal. Questions? Contact support.