Short Description Hive9 ships with a Client Admin role and lets you create custom roles for finer-grained permission control. This article covers both.
What this article answers
- What the Client Admin role provides.
- How to create custom roles.
- Where role permissions are configured.
Client Admin
Client Admin is the built-in administrator role. It has full access to all features and content in the instance:
- All menus and screens.
- All settings (Users, Roles, Teams, Models, Integrations, Workflows, Currency, Audit Logs).
- All content across teams.
- All approval, editing, and viewing capabilities.
Client Admin cannot be copied, edited, or deleted — it's a fixed system role. At least one user in your instance must always hold it.
Custom roles
For everyone else, you build custom roles with the specific permissions they need.
Creating a custom role
- Go to Settings → Roles.
- Click New Role.
- Enter a name (e.g., "Marketing Manager," "Finance Reviewer," "Regional Lead").
- Configure permissions across the three tabs:
- Plan — what they can do with plans, tactics, etc.
- Measure — what dashboards and analytics they can access.
- Notification — what email and in-app notifications they receive.
- Save.
The role is immediately available to assign to users.
Common custom role patterns
- Marketing User — full edit access to their team's content, can submit for approval but not approve, full read access to dashboards.
- Marketing Manager — Marketing User + can approve for their team.
- Finance Reviewer — read access to Plan, full access to Finance Budget and PRs, can approve AR Lines.
- Read-Only Stakeholder — view-only access to everything they're scoped to.
- Regional Lead — content visibility across multiple teams (regions), with approval rights on each.
Key permission categories
Within a custom role, the more nuanced settings include:
- Limit content to user's teams — Yes restricts visibility to only their teams. No allows cross-team visibility.
- Restrict to financial info only — useful for partners and agencies who need cost data but not full plan visibility.
-
Integrations section — three sub-permissions:
- Restrict access entirely.
- Create/Edit Integrations.
- Edit Tactic Integration Options.
- Snapshots — view + create/edit/delete.
Editing a custom role
- Settings → Roles → click the role.
- Click Edit (icon).
- Modify permissions.
- Save.
Edits apply to every user holding the role. If you have 50 users with the Marketing Manager role and you remove a permission, all 50 lose that permission immediately.
Deleting a custom role
- Settings → Roles → click the role.
- Click Delete (bottom-right).
- If the role is still assigned to one or more users, Hive9 prompts you to reassign those users to a different role.
- Click Continue.
Common questions
Can I copy Client Admin to create a starting point? No — Client Admin can't be copied. You'll create the custom role from scratch.
Can I have multiple Client Admins? Yes — any number of users can hold Client Admin. There just needs to be at least one.
What if a user needs slightly more than a role provides? Either expand the role (affecting all users with it), assign a different role, or create a new role tailored to their needs.
Do role changes get audit-logged? Yes — role definitions and role assignments are tracked in audit logs.
Comments
Please sign in to leave a comment.