How do I restrict a user's access to specific sub-accounts?
Restrict sub-account access
By default, a user with the Switch to sub accounts permission can reach every sub-account in your organization. Sub-account access lets you scope an individual user to a chosen subset instead.
Follow these steps to restrict a user:
- Navigate to User Management Log in to the Kreditz portal and open the User Management section.
- Find the user in the list. Click the action menu (three-dot icon) on their row, then select Sub-account access.
- Restrict the accounts In the Manage sub-account access modal, tick Restrict to specific sub-accounts. The list of available sub-accounts becomes active — tick the ones this user should be able to reach, then click Update.
The user is now restricted to the selected sub-accounts. They can access those, and only those, when they sign in.
Returning a user to all sub-accounts
- Reopen the Sub-account access modal for that user.
- Untick Restrict to specific sub-accounts.
- Click Update.
The user is back to default behavior, with access to all sub-accounts.
Accounts column overview
Once the feature is enabled, the user list shows an Accounts column with a fraction for each user:
- 9/9 — the user has access to all sub-accounts (no restriction set).
- 2/9 — the user is restricted to 2 of 9 sub-accounts.
- 0/9 — the user is restricted, but every sub-account they were granted access to has since been deactivated. Worth reviewing.
- Dash (—) — the user's role does not include the Switch to sub accounts permission, so they're pinned to your main account and this scoping doesn't apply to them.
What a restricted user sees
- The sub-account switcher at the top of the page lists only the sub-accounts they've been granted.
- If their default landing account isn't in their allow-list, they're automatically taken to the first sub-account they do have access to — they won't be locked out at sign-in.
Things to know
- Permission required. Only users in a role with User management → manage can configure sub-account access for others. Administrators have this permission by default.
- You can only grant what you have. If your own access is restricted to a subset of sub-accounts, you can only grant others access within that same subset.
- Deactivated sub-accounts. A deactivated sub-account disappears from the list of options. If a user already had access to it, that record is kept — access is automatically restored if the sub-account is reactivated.
- Audit log. Every change to a user's sub-account access is recorded in your event log, including who made the change and when.