Limiting someone to one brand — brand access, done right.
Hold a teammate to specific brands — perfect for agencies separating clients. Set it when you invite, change it any time, and trust that it's enforced on the server, not just hidden.
If you run more than one brand — an agency with several clients, say — you often want a teammate to work on one of them and not the rest. That's brand access: the list of brands a teammate is allowed to touch.
What brand access does
Each teammate has a set of brands they can act on. There are two states:
- All brands (the default) — leave their brand list empty and they can work on every brand you have, now and any you add later.
- Specific brands — pick one or more, and they're held to exactly those. The rest of your brands are invisible and off-limits to them.
Brand access limits where a role applies. It doesn't change what the person can do — a scoped Editor is still an Editor, just on their brands only.
Setting it when you invite
The invite form has a Brands picker. Tick the brands this person should have and send. Leave it untouched to give them everything. Whatever you choose becomes their starting brand access.
Changing it later
On the Team page, each member's row opens a brand-access drawer. Add or remove brands there and it applies immediately — no re-invite. Clear the list entirely to give someone access to all brands again. Only Admins and the Owner can change brand access.
What a scoped teammate sees
A scoped teammate simply doesn't see the brands they're not on. Their brand switcher shows only their brands, their briefs and competitors are only for those brands, and there's no "locked" brand teasing them from the corner of the screen.
Brand access is enforced on the server, not just hidden in the app. A scoped teammate can't reach another brand's data even by editing a URL — the request is refused. It's a genuine permission, safe to use for client separation.
Roles vs brand access
The two settings answer different questions, and they stack:
- Role — what they can do (read, edit, manage the team…). See roles & permissions.
- Brand access — which brands that role applies to.
So a "Viewer, Client A only" can read everything about Client A and nothing else. An "Editor, Clients A and B" can create and edit for those two brands, but can't see Client C. The Owner is always unrestricted across every brand.
If you're managing several brands, it's worth reading managing multiple brands alongside this.