What clients can see
The seven per-workspace switches deciding which sections an Agency Client sees, why absent means allowed, and the two surfaces that are ungoverned.
Each Client Workspace carries seven switches, one per section, deciding what its Agency Clients see. They govern the client experience only: your own team is never filtered by them.
The rule that shapes everything else on this page: an absent setting means allowed. A workspace you have not configured shows the client everything, and an agency switches a section off rather than switching the rest on.
The seven
| Permission | What a client loses when it is off |
|---|---|
| Rank tracking | Google positions, AI Overviews and AI Overview Citations, and the whole Traffic section: Search Console, Analytics and Indexing |
| AI visibility | How their brand appears in AI assistant answers, the chat feed, AI Answer Citations, and AI Readiness |
| AI Shopping | Whether their products appear in AI shopping answers, the merchant list and the ads view |
| Content Studio | Briefs, articles, the content calendar and campaigns |
| Website audits | Technical audit results and issues |
| Reports | Shared performance reports |
| Tasks | The board of recommended actions |
Two of those cover more than their name suggests, and both are worth reading before you switch one off.
Rank tracking also governs Traffic. Search Console reports average position per query, which is exactly what this permission promises to withhold. Leaving Traffic visible would have made switching rank tracking off a false promise.
AI visibility also governs AI Readiness. It is the same subject, what assistants can see of this brand, and giving it a separate switch would have grown the set without adding a decision.
Why absent means allowed
Because the safe direction is one-way.
Every Client Workspace that existed before a permission did behaves exactly as it did, and every workspace you have not configured shows everything. So a permission added to RankX AI in future cannot silently take a section away from a client already using it.
The cost of that choice sits with you: a workspace you have not configured is fully visible. Set the permissions before the first client user logs in.
Two surfaces are deliberately ungoverned
Keyword Research and Topic Clusters have no switch. The set is closed at seven by decision rather than by oversight, and adding a switch is a product change rather than a setting.
If either is genuinely sensitive for a client, the answer today is not to invite that client to a workspace containing work you do not want shown.
A third surface, the overview landing page, is also ungoverned for a mechanical reason: a client user has to be able to land somewhere, and every redirect in the product targets it.
Switching one off removes a whole group
The permissions largely follow the product's own navigation grouping, so switching one off usually removes a whole section from the client's rail. RankX AI drops a group whose items all disappear, so a client never sees a heading over an empty list.
One group is deliberately mixed and it is not a bug: Research and Content holds Content Studio and Campaigns, which the content permission governs, beside Keyword Research and Topic Clusters, which are ungoverned. So switching content off leaves the group heading with the two research items under it, which is a coherent group rather than a stranded header.
The switch is a boundary, not a decoration
Hiding a section from the navigation is a convenience. RankX AI also guards the page, so a client typing the URL directly is refused rather than served.
That distinction is the difference between a permission and a preference, and it is why hiding a nav item is never the whole implementation.
A practical order
- Create the workspace and add the client's Websites.
- Set the seven permissions to what that client is paying for. Off is the deliberate act; leaving one alone shows it.
- Check the portal as the client will see it, before inviting anyone.
- Then invite the Agency Client users.
Where to go next
- The client portal, for what a client sees.
- Roles and permissions, for the role boundary these sit on top of.
- Client reports, which reach clients who never log in.
Roles and permissions
The four RankX AI roles, what each can do, why only one can approve an MCP connection, and why Agency Clients do not consume seats.
Per-client credit budgets
A ceiling on the shared agency wallet, not a sub-wallet. Why the wallet can be full while a client is stopped, and what uncapped and zero each mean.