Manage client users

Add people who log in on a client's behalf, read their login type and elevations, set the billing contact flag, and remove them.

Written for
admin
Roles
owner, admin, client-user, elevated-client-user, billing-contact
Requires
Owner or Admin; Browser session (API tokens cannot manage clients); Recent re-authentication
Feature
clients

A client user is a person who logs in to SAQ for one client: a customer employee who reports tickets, follows them, and, if elevated, works inside a project. Client users are managed on the client's Users tab, not under Settings → Members, and they do not use a seat on the plan.

Before you start

  • You need the Owner or Admin role. Client users are managed in the browser; API tokens are refused.
  • Adding, removing, or flagging a client user is an access change, so SAQ asks you to confirm your identity first.
  • The person must not already be a workspace user of this workspace, and can belong to only one client per workspace.

Add a client user

  1. Open Clients, choose the client, and open the Users tab.
  2. Enter the Email and, optionally, a Name. Without a name the part of the address before @ is used.
  3. Select Add client user.

The form's hint states the rules: "A client user belongs to exactly one client. New addresses get a magic-link login." After a successful add, SAQ confirms: "{email} added. New users log in with an emailed link until they set a password."

There is no invitation email. Tell the person to open the login page, enter their address, and choose Email me a link instead; the link is valid for 15 minutes and works once. Once logged in, they can set a password or add a passkey under Account → Security to get a full login. If the address already has a SAQ account (from another workspace), they log in as usual.

What the table shows

Column Meaning
Name, Email The person's profile.
Login Password or passkey (a full login) or Magic link (no password or passkey yet).
Elevated on The projects on which the person is an elevated client user, or .
Billing contact A checkbox. While the person has no full login it shows "usable after full login".

Elevation

Elevation is granted per project on the project's Members tab, never here. It gives the client user access to every ticket in that project billed to their client, plus Internal comments and assignments there. It only takes effect in a full-login session, which is why the Login column matters. See Manage project members for the full description and the rules about who may elevate.

Billing contact

Tick Billing contact to let this person download the client's timesheet documents in the app. A billing contact sees Documents in their sidebar and can download every document of their own client, but only in a full-login session; until then the flag is stored and shown as "usable after full login". The flag has no effect on ticket visibility. It is different from a billing recipient, which is an email address that receives the documents; see Contacts and billing recipients. See also Billing contact.

Remove a client user

Select Remove on the row, type the person's email address in the confirmation Remove {name} from this workspace, and confirm. The panel says what happens: "Their elevations, viewer grants, and assignments here are removed. Their login and other workspaces are not affected."

In detail, removal:

  • removes every elevation and viewer grant they hold in this workspace, and clears them as assignee on any ticket;
  • revokes the API tokens they minted for this workspace;
  • keeps the tickets and comments they wrote, now attributed to a pseudonym such as "Former member 3";
  • leaves their global account, and their access to other workspaces, untouched. Adding the same address again later shows their real name on new activity.

What client users see and receive

A regular client user sees only tickets they started or were added to as a viewer, reads Shared comments, and can move their own tickets to the customer-resolve state. They receive email for shared comments and state changes on those tickets. They never log time and never see estimates, rates, notes, or non-billable time. The full picture, including the elevated mode, is on Client user.

Common problems

"This person is a workspace user here." The address belongs to a workspace user of this workspace. A person cannot be both. Remove the workspace membership first, or use a different address.

"This person already belongs to a client in this workspace." Every person is a client user of at most one client per workspace. Remove them from the other client first.

The billing contact flag is ticked but they cannot see Documents. They log in by magic link. Ask them to set a password or add a passkey; the flag becomes usable on their next full login.

"Regular client users cannot create API tokens." Only elevated client users with a full login can mint tokens, and only for the projects they are elevated on.