# Accounts, roles and access

Who can see what in Aisoiq: user accounts, agency roles and client assignments.

## Your account

- Profile: name, phone, avatar and email preferences.
- Password: enforced complexity: at least 8 characters with upper case, lower case, a number and a symbol.
- Sign-in: email and password, Google sign-in, or a one-time code by email. Repeated failed attempts trigger a temporary lockout.
- Notifications: choose which activity categories reach you by email, and which only appear in the activity feed.

## Roles

| Role | Scope |
| --- | --- |
| Agency Admin | Everything inside one agency: team, clients, branding, white label, billing, API keys. |
| Team Member | Only the clients they are assigned to, with the features enabled for that agency. |
| Client user | A read-focused view of their own workspace and reports. |

> **Cross-agency isolation**: Users, clients and emails are isolated per agency. A user in one agency can never read another agency's clients, even if the same business exists in both.

## Client assignments

Assign team members to specific clients from Agency → Team. Assignment controls what appears in their client switcher, their dashboards and their reports. Removing an assignment revokes access immediately without deleting any work they produced.

## Role vs assignment

It helps to keep these two ideas separate: a role decides which features a person can use (can they edit branding, can they manage the team, can they see billing), while a client assignment decides which businesses they can use those features on. A Team Member with the strongest feature permissions still sees nothing until they are assigned to at least one client.

## Common access setups

| Situation | How to set it up |
| --- | --- |
| Freelancer helping on one client only | Team Member role, assigned to that single client. |
| Full-time strategist across the whole book | Team Member role, assigned to every current and future client as they onboard. |
| Client wants to see their own reports | Create a Client user for their workspace rather than sharing an agency login. |
| Someone leaves the agency | Remove their client assignments and deactivate the account; do not just change the password. |
