Recent searches

in

How do Partners access their Client Organizations?

Last modified: September 9th, 2026

On this page

Everyone who works on a Client Organization reaches it through a Permission Group, the same as in any other Organization. The Owners of your Partner Organization get access automatically, through the Partner Permission Group. You add anyone else on your team yourself.

The Partner Permission Group#

When you first create a Client Organization, CloudCannon automatically adds a Partner Permission Group to it, and populates that group with the members of the Owners Permission Group in your Partner Organization. It is one of the Default Permission Groups, and sits at the top of the Groups tab named Partner. The group exists because the Client Organization is linked to your Partner Organization, and CloudCannon removes it if that link is ever broken.

Every time you update the members in your Partner Organization's Owners Permission Group, CloudCannon will also update the membership of the Partner Permission Group in every Client Organization you manage. Unlike other Permission Groups, you cannot edit or delete the Partner Permission Group from the Client Organization's Team page.

Keep your Partner Organization's Owners group membership as small as possible to prevent unneeded access to every Client Organization you manage.

As a member of the Partner Permission Group, you are granted the same permissions as the Owners Permission Group in the Client Organization. This means you can:

  • Create and configure Sites, Projects, and Custom Domains.
  • Edit, save, and publish content on every Site.
  • Add Team Members to the Client Organization, and manage its Permission Groups.
  • Change Organization settings, including its branding, and create and delete API Keys.
  • Manage the client's Subscription Plan, payment methods, and invoices.

You can also take the actions that no other Permission Group can be granted, however much access it is given:

  • Configure SAML on the Single Sign-On page under Org Settings, available on our Enterprise Plan.
  • Set a date after which Team Members must use MFA, on the Multi-Factor Authentication page under Org Settings, available on our Team or Enterprise Plan.
  • Export the access review for the Client Organization from the Members tab on the Team page under Org Settings.
  • Use View As mode to see the Client Organization as one of its Team Members.
  • Add Team Members to, and remove them from, the Client Organization's Owners Permission Group. This is how you hand a Client Organization over to your client.
  • Delete the Client Organization.

Everyone in the Client Organization who can read Permission Group members can see who is in the Partner Permission Group, and no one in the Client Organization can change it.

A screenshot of the Groups tab on the Team page of a Client Organization shows the Partner group at the top of the list, above the Owners, Developers, Technical Editors, Editors, and Billing groups, each labeled a Default Permission Group.

Members of your Partner Organization appear on the Members tab alongside the client's own Team Members, marked as not counting toward billing.

A screenshot of the Members tab on the Team page of a Client Organization shows a member of the Partner Permission Group labeled Partner, not counted toward billing, alongside the client's own Team Members in the Editors and Billing Permission Groups.

Inviting other Partner Organization members#

To add more Team Members from your Partner Organization to the Client Organization, you can invite them to any Default Permission Group the same way you would in your own Organization. The one exception is the Partner group, which CloudCannon manages for you. If the Client Organization is on our Team or Enterprise Plan, you can also invite them to a Custom Permission Group.

A screenshot of the Invite Team Members modal in a Client Organization shows fields for an email address and a Permission Group, above the Add members button.

Members of your Partner Organization added this way do not count toward the number of Team Members included in the Client Organization's Subscription Plan. This way you can add as many people as you need to manage it without increasing the invoice with Add-Ons, as long as those Team Members remain a member of your Partner Organization.

Any actions a Partner takes in the Client Organization, such as saving changes to files, updating CloudCannon settings, or publishing changes to a Site, will appear in the Activity tabs on the Site Dashboard and Organization Home, like any other Team Member.

Client Organization Owners#

When you create a Client Organization, CloudCannon also adds you to the Owners Permission Group for the Client Organization. That means you start out in both the Partner and Owners groups. While you are the only member of the Owners group, you cannot leave it, because every Organization must have at least one Owner.

Once the Owners group has another member, you can leave it without reducing your access, because the Partner group already grants everything the Owners group does. For more information, please read our documentation on leaving a Permission Group.

Leaving the Owners group is not the same as leaving the Client Organization. CloudCannon mirrors your Partner group membership from your Partner Organization, so you cannot remove yourself from a Client Organization while you are one of your Partner Organization's Owners. To end your access, either leave your Partner Organization's Owners group, which also removes you from every other Client Organization you manage, or detach the Client Organization.

For how to give your client control of a Client Organization, and what detaching changes, please read our documentation on handing over or detaching a Client Organization.

Related Resources

Open in a new tab