Skip to content

Access grants and account reach

Understand what an access grant does — and does not do — to who can see an account, so you can widen reach for one account without weakening anything else.

Every account is reachable through its intrinsic paths: its owner, the business unit it belongs to, and firm-level reach set by permission groups. An access grant is a deliberate, per-account exception layered on top of those paths: it lets a business unit — or one named person inside it — see a single account they could not otherwise reach.

What a grant can and cannot do

From a security standpoint, access grants are intentionally narrow:

  • Grants only add read reach. A grant lets its holder see the account; it does not make them the owner and it does not carry any of the owner's responsibilities.
  • Grants never remove access. There is no such thing as a "negative" grant. Revoking a grant only returns things to the baseline — the account's owner and its own business unit can still see it exactly as before.
  • Grants are per account. A grant applies to one account only; it never spills over to other accounts in the same business unit or owner tree.
  • Grants do not expire. A grant stays in force until someone revokes it, so review an account's grants when the reason for one no longer applies.
  • The holder can be narrowed. A business-unit grant can be tightened to one named user in that unit, and widened back to the whole unit later.

Who can manage grants

Grants are managed from the account itself: anyone who can open the account's card and whose role lets them manage its access can add, narrow, or revoke grants there. Like every change in the Backoffice, granting and revoking is recorded in the account's change history, so you can always trace who widened reach to an account and when.

Manage an account's grants

The step-by-step mechanics — adding a grant, narrowing it to one user, resetting it to the whole business unit, and revoking it — are covered in Who can reach an account. In short: open the account's card, choose Access grants from the actions menu, add or adjust grants in place, and click Revoke on a grant's row to remove it.

Note

If a whole team needs to see many accounts rather than one, an access grant is the wrong tool — adjust ownership or the team's permission group instead, and keep grants for genuine one-account exceptions.