Starting 2026-10-03, the permissions that you give a sub-account apply to all service pages in the client area. A sub-account that has only View Products & Services can open your service pages, but it cannot make changes.
What you must do
If a sub-account must make changes to your services, give it the Manage Products & Services permission:
- Sign in to the client area as the account owner.
- Open the Contacts/Sub-Accounts page.
- Select the sub-account.
- Tick View Products & Services and Manage Products & Services.
- Click Save Changes.
If you do nothing, your sub-accounts can still see your services. The buttons that make changes are not shown to them until you give them the Manage permission.
What each permission does
| Permission | What the sub-account can do |
|---|---|
| View Products & Services | Open service pages: recipients, filtering rules, forwards, statistics, SMTP senders, delegated admins, API keys, and inbound users. |
| Manage Products & Services | Make changes on those pages. For example, it can add or remove recipients, change filtering rules, import lists, create API keys, and reactivate a service. The sub-account also needs View Products & Services. |
| Perform Single Sign-On to a Service Console | Open the PhishProtection portal and the Message Log Viewer. The sub-account also needs View Products & Services. |
| View & Pay Invoices | Open and change payment methods. |
The SMTP Credentials page shows your SMTP passwords. To open it, a sub-account needs View Products & Services and Manage Products & Services.
What a sub-account sees without permission
When a sub-account opens a page or makes a change that it does not have permission for, it sees a message such as:
Your sub-account does not have permission to make changes to products and services on this account. Please contact the account owner.
Only the account owner can change the permissions of a sub-account.
Give sub-accounts only to people you trust
A sub-account can view all of your services, or view and change all of them. You cannot limit a sub-account to some services. Give a sub-account only to a person that you trust with your account.
An API key belongs to your account, not to the sub-account that created it. If you remove a sub-account, the API keys that it created continue to work. Delete the keys on the Customer API Key Manager page if you do not need them.
To add, change or remove sub-accounts, see Manage contacts and sub-accounts in DuoCircle Portal. Questions? Contact support.