The short version
A Site Admin controls access to their site.
An Account Admin controls who exists in the account.
Most questions about what a Site Admin can or cannot do come back to that one distinction.
What a Site Admin can do
On any site where they hold the Site Admin permission level, a Site Admin can:
- Open that site’s Permissions page and see who has access.
- Grant a site permission to an existing user or an existing group.
- Change the permission level of someone who already has access to the site — for example, moving a user from View to Contribute.
- Remove a user’s or group’s access to the site.
- Add or remove permission modules for users and groups on that site.
What a Site Admin cannot do
These actions are reserved for Account Admins, because they affect the whole account rather than a single site:
- Invite or create new users.
- Add someone to a group, or remove them from one.
- Browse or search the account-wide list of users.
A Site Admin’s authority stops at the edge of their site. Adding a person to a group changes that person’s access everywhere the group is used — including sites the Site Admin does not administer — so it sits with the Account Admin.
The error you will see
On the Permissions page, the Add user and Add user to group options both work by adding a person to a group. Because that is an account-level action, a Site Admin who opens them will see: You cannot perform this action.
What to do instead
- Ask an Account Admin to add the person to the group
Once they are a member, they pick up every site permission that group already holds — no further action needed from the Site Admin.
- Or ask an Account Admin to grant the person direct access to the site
Useful when the access is specific to one person and does not warrant a group.
- Then manage their level yourself
Once the person or group has access to your site, changing their permission level, adjusting their modules, or removing their access is all within Site Admin reach.