Roles — Client Admin vs Custom Roles

Short Description Hive9 ships with a Client Admin role and lets you create custom roles for finer-grained permission control. This article covers both.

What this article answers

  • What the Client Admin role provides.
  • How to create custom roles.
  • Where role permissions are configured.

Client Admin

Client Admin is the built-in administrator role. It has full access to all features and content in the instance:

  • All menus and screens.
  • All settings (Users, Roles, Teams, Models, Integrations, Workflows, Currency, Audit Logs).
  • All content across teams.
  • All approval, editing, and viewing capabilities.

Client Admin cannot be copied, edited, or deleted — it's a fixed system role. At least one user in your instance must always hold it.

 

Custom roles

For everyone else, you build custom roles with the specific permissions they need.

Creating a custom role

  1. Go to Settings → Roles.
  2. Click New Role.
  3. Enter a name (e.g., "Marketing Manager," "Finance Reviewer," "Regional Lead").
  4. Configure permissions across the three tabs:
    • Plan — what they can do with plans, tactics, etc.
    • Measure — what dashboards and analytics they can access.
    • Notification — what email and in-app notifications they receive.
  5. Save.

The role is immediately available to assign to users.

Common custom role patterns

  • Marketing User — full edit access to their team's content, can submit for approval but not approve, full read access to dashboards.
  • Marketing Manager — Marketing User + can approve for their team.
  • Finance Reviewer — read access to Plan, full access to Finance Budget and PRs, can approve AR Lines.
  • Read-Only Stakeholder — view-only access to everything they're scoped to.
  • Regional Lead — content visibility across multiple teams (regions), with approval rights on each.

Key permission categories

Within a custom role, the more nuanced settings include:

  • Limit content to user's teams — Yes restricts visibility to only their teams. No allows cross-team visibility.
  • Restrict to financial info only — useful for partners and agencies who need cost data but not full plan visibility.
  • Integrations section — three sub-permissions:
    • Restrict access entirely.
    • Create/Edit Integrations.
    • Edit Tactic Integration Options.
  • Snapshots — view + create/edit/delete.

Editing a custom role

  1. Settings → Roles → click the role.
  2. Click Edit (icon).
  3. Modify permissions.
  4. Save.

Edits apply to every user holding the role. If you have 50 users with the Marketing Manager role and you remove a permission, all 50 lose that permission immediately.

Deleting a custom role

  1. Settings → Roles → click the role.
  2. Click Delete (bottom-right).
  3. If the role is still assigned to one or more users, Hive9 prompts you to reassign those users to a different role.
  4. Click Continue.

Common questions

Can I copy Client Admin to create a starting point? No — Client Admin can't be copied. You'll create the custom role from scratch.

Can I have multiple Client Admins? Yes — any number of users can hold Client Admin. There just needs to be at least one.

What if a user needs slightly more than a role provides? Either expand the role (affecting all users with it), assign a different role, or create a new role tailored to their needs.

Do role changes get audit-logged? Yes — role definitions and role assignments are tracked in audit logs.
 

Related articles

Was this article helpful?

Comments

0 comments

Please sign in to leave a comment.