Managing access for a marketing team can get messy, especially when everyone uses the same login. One person might accidentally change a live campaign, while a former employee or contractor may still have access months after leaving.
Role-based access solves this problem by giving each person their own login and only the level of access they need.
In NYX, you can manage this from Settings → User Management. You can invite team members, choose their role, change their access later, or remove them when they leave.
What is role-based access?
Role-based access is a simple idea: people get access based on what they need to do for their job.
Instead of giving everyone the same level of access, you assign people to different roles. For example, a CFO may only need to view campaign results, while a performance marketer needs to create and edit campaigns.
This keeps access simple and makes it easier to manage when people join, change roles, or leave the company.
Why does access control matter?
Too much access can lead to expensive mistakes.
For example, someone might change a live campaign or budget without realising the impact. That could interrupt campaign performance and increase your customer acquisition cost.
There is also a quieter problem: old accounts.
Marketing teams often work with freelancers, agencies, interns, and contractors. It is easy to give someone access when they start and forget to remove it when their work ends.
Regularly reviewing access helps prevent both problems.
What roles are available in NYX?
NYX currently has three roles:
Role | Best for |
Viewer | People who only need to see results and reports |
Editor | People who work on campaigns and creative |
Admin | People who manage the account and users |
Every new invite starts as a Viewer. This is useful because the safest level of access is the default. You can then increase someone's access if their job requires it.
As a general rule, keep the number of Admins small. For a small marketing team, having two Admins is usually a good approach. It gives you backup without giving too many people control over user access.
How to invite someone in NYX
Adding a team member takes just a few steps.
1. Open User Management
Go to Settings and select User Management. This is where you can see and manage everyone who has access.
2. Review the current users
Before adding someone, check who already has access.
The table shows each person's name, email, role, and date joined. You can also look at the oldest accounts first to spot access that may no longer be needed.
3. Select “Invite Users”
Click + Invite Users at the top of the table. This opens the Add a user window.
4. Enter their work email
Use the person's company email rather than a personal address. This makes it easier to keep track of who has access.
5. Choose their role
The role dropdown includes Viewer, Admin, and Editor.
Choose the lowest level of access that allows the person to do their current job. Don't give someone Admin access just because they might need it later.
6. Add a note
You can add a note explaining why the person has access.
For example:
Agency partner — paid social. Review access in March.
For contractors or agencies, adding the contract end date can also make future access reviews easier.
7. Select “Next”
Click Next to continue the invite. If you select Cancel, the invite window closes without continuing.
How to change someone's role
You don't need to remove and re-invite someone when their responsibilities change.
Go to Settings → User Management and find the person in the table. Use the Role dropdown in their row to change their access.
For example, you can move someone from Editor to Admin when they take on more responsibility, or reduce an Admin to Viewer when they move to another team.
How to remove someone's access
Removing access is just as simple.
In the User Management table, find the person and select the delete icon in the Action column.
Ideally, do this on their last working day rather than waiting for a quarterly review. This is especially important for contractors and agency partners.
Which role should each person have?
Consider a five-person B2B marketing team that also works with an agency and has a CFO who regularly checks marketing spend.
A sensible setup could look like this:
Person | Main responsibility | Role |
Head of Marketing | Manages the budget and team | Admin |
Marketing Ops Manager | Manages users and workspace access | Admin |
Performance Marketer | Builds and optimises campaigns | Editor |
Creative Designer | Creates and updates ad creative | Editor |
Content Manager | Reviews performance data | Viewer |
Agency Partner | Manages paid social | Editor |
CFO | Reviews spend and results | Viewer |
This gives the team two Admins, three Editors, and two Viewers.
The CFO can review performance without editing campaigns. The agency gets the access needed for its work without needing Admin access.
For an agency or contractor, record the expected end date when you invite them. That makes it much easier to remember when their access should be reviewed.
How often should you review access?
A good rule is to review access once every quarter and whenever someone leaves the company.
Open User Management and look at each person on the list.
Ask:
“Does this person still need this level of access for their current job?”
If the answer is no, reduce their role or remove their access.
For a small team, this review should only take a few minutes.
What do you get from setting this up properly?
A clean role-based access system gives you:
Individual logins instead of shared passwords
Clear ownership of account activity
The right access for each person's job
Easier onboarding for new employees
Faster offboarding when someone leaves
Limited access for agencies and contractors
Fewer people with Admin privileges
Keep your access clean
Role-based access doesn't need to become a complicated security project.
Set it up once, give people only the access they need, and review it regularly.
The goal is simple: the right people should have the right access at the right time.
If someone has access they no longer need, fix it. If someone is new to the team, give them their own login and the appropriate role.
To get started in NYX, open Settings → User Management and review the list of users. If someone's role doesn't match their current job, update it.
Frequently Asked Questions
- What roles can you assign in NYX?
- NYX has three roles: Viewer, Editor, and Admin. New users start as Viewers, and you can change their role later from the User Management table.
- Can I change someone's role after inviting them?
- Yes. Find the person in User Management and change their role using the Role dropdown. You don't need to delete and invite them again.
- How do I remove someone from my NYX workspace?
- Go to Settings → User Management, find the person, and select the delete icon in the Action column. It's best to remove access on their last working day.
- What role should an external agency get?
- Give the agency the lowest role that allows them to do their work. In many cases, that will be Editor rather than Admin. Keep Admin access with your internal team whenever possible, and record the agency's contract end date in the note field.
- Should everyone have their own login?
- Yes. Individual logins make it clear who has access and help you manage people when they join or leave. Shared logins make both accountability and off boarding harder.
- How many Admins should a marketing team have?
- For most small teams, two Admins is a sensible setup. One Admin can create a single point of failure, while giving Admin access to too many people makes access harder to control.



