How portfolios, accounts and users relate
A user joins a portfolio, and the portfolio carries the accounts. Here is which layer holds the role, the access and the plan.
Last updated: September 30, 2026
A user joins a portfolio, and the portfolio carries the accounts. Here is which layer holds the role, the access and the plan.
Last updated: September 30, 2026
The way to understand why you cannot see or change something in the panel is to know which of three layers you are standing on: the user, the portfolio and the account. This article explains how the three connect, which information lives where, and the points that are most often confused.
The chain runs one way: user → portfolio → account. A user is never attached to an account directly; they join a portfolio, and that membership decides which accounts they reach.
| Layer | What it holds |
|---|---|
| User | Name, e-mail, password and security, interface language and theme, the account to open on sign-in, the plan (for the portfolios they own) |
| Portfolio | Team and roles, account access, the access and visibility policy, conversation assignment rules, AI keys, external service connections, audit logs |
| Account | The connected channel, conversations, contacts, tags, contact fields, automations, rules, sequences, media, saved replies, business hours, time zone and language, reports |
When you cannot find a setting, look at this table first: more often than not it is being looked for on the wrong layer.
A user joins a portfolio by invitation. Two things are decided at that moment:
The two are independent. The role says what, the access says where.
⚠️ Note: the role is portfolio-wide. A person works with the same role in every account they can reach; there is no "administrator here, agent there" arrangement. If you need that distinction, put the accounts in separate portfolios.
With All accounts, the member also reaches accounts connected to the portfolio later. With Selected accounts, they reach only the accounts you ticked; a newly connected account is not added to their list by itself.
Owners and administrators sit outside this choice: by virtue of their role they always reach every account. The team screen states this with the note Owners and administrators always reach all accounts.
An account a person cannot reach behaves as if it does not exist for them:
The plan belongs to the user but is spent through the portfolio. The rule: a portfolio's account limit, team seats and features follow that portfolio's owner's plan.
What follows from this:
An agency has three people: Deniz (founder), Eren (team lead) and Sude (intern). The agency has two clients, and each client has one Instagram and one WhatsApp account.
The setup:
The result: Sude does not even know "Client B" exists, and she cannot see "Client A"'s WhatsApp account either. If Deniz connects a new account to "Client A", Eren sees it immediately (all accounts) and Sude does not (selected accounts).
You can move an account into another portfolio you own. Moving is the job of whoever owns both portfolios, and all of the account's data travels with it: contacts, conversations, automations, media, saved replies, segments, general rules and sequences. Nothing is deleted.
What changes is who can reach it. After the move, the target portfolio's team reaches the account: the owner, the administrators and the members with "All accounts" access. The "Selected accounts" choices from the source portfolio are dropped.
That has two visible consequences:
The move screen lists the records to be moved and the people whose access will change, before you confirm.
Once you can tell the three layers apart, "who sees what, and why" stops being guesswork.
Was this article helpful?