Skip to content
  • There are no suggestions because the search field is empty.

How do I restrict a user's access to specific sub-accounts?

Restrict sub-account access

By default, a user with the Switch to sub accounts permission can reach every sub-account in your organization. Sub-account access lets you scope an individual user to a chosen subset instead.

Follow these steps to restrict a user:

  1. Navigate to User Management Log in to the Kreditz portal and open the User Management section.
  2. Find the user in the list. Click the action menu (three-dot icon) on their row, then select Sub-account access.
  3. Restrict the accounts In the Manage sub-account access modal, tick Restrict to specific sub-accounts. The list of available sub-accounts becomes active — tick the ones this user should be able to reach, then click Update.

The user is now restricted to the selected sub-accounts. They can access those, and only those, when they sign in.

Returning a user to all sub-accounts

  1. Reopen the Sub-account access modal for that user.
  2. Untick Restrict to specific sub-accounts.
  3. Click Update.

The user is back to default behavior, with access to all sub-accounts.

Accounts column overview

Once the feature is enabled, the user list shows an Accounts column with a fraction for each user:

  • 9/9 — the user has access to all sub-accounts (no restriction set).
  • 2/9 — the user is restricted to 2 of 9 sub-accounts.
  • 0/9 — the user is restricted, but every sub-account they were granted access to has since been deactivated. Worth reviewing.
  • Dash (—) — the user's role does not include the Switch to sub accounts permission, so they're pinned to your main account and this scoping doesn't apply to them.

What a restricted user sees

  • The sub-account switcher at the top of the page lists only the sub-accounts they've been granted.
  • If their default landing account isn't in their allow-list, they're automatically taken to the first sub-account they do have access to — they won't be locked out at sign-in.

Things to know

  • Permission required. Only users in a role with User management → manage can configure sub-account access for others. Administrators have this permission by default.
  • You can only grant what you have. If your own access is restricted to a subset of sub-accounts, you can only grant others access within that same subset.
  • Deactivated sub-accounts. A deactivated sub-account disappears from the list of options. If a user already had access to it, that record is kept — access is automatically restored if the sub-account is reactivated.
  • Audit log. Every change to a user's sub-account access is recorded in your event log, including who made the change and when.