WeCom permission management roles include creator, super admin, and sub-admin.
a) By default, the creator is the user who registers a WeCom account. A company can only have one creator.
b) The creator has the highest level of permission.
c) The creator role can be transferred but cannot be deleted.
d) A single WeChat account can have up to 5 creator roles for different companies.
There are two types of super admin: internal admin and external admin. A company can have multiple super admins with the highest management permission.
b) Internal super admins must be in the Contacts. If a member is removed from the Contacts, their admin role will also be removed.
c) External super admins (delegated operators) are primarily external technical support personnel of a company and do not need to be in the Contacts.
d) Super admin roles can be removed.
a) They are mainly responsible for the permission management within their authority.
b) Sub-admins in the admin group can assign permissions for specific contacts or apps to other sub-admins.
c) Sub-admins can only manage or set permissions for the specific areas they are assigned.
a) The creator and super admins have management permission for all contacts of the company.
b) Hierarchical administrators can only manage the corresponding portion of the Contacts. The scope for sending app messages and performing other operations must be within the permissions defined by the hierarchical administrator’s management scope.
a) App permissions are divided into message sending permissions and management permissions. By default, users with management permission have the permission to send messages. The creator and super admins have management permission for all apps of a company.
b) Sub-admins can be assigned the message sending or management permission for specific apps.
a) Device management permissions are divided into permissions for binding new hardware devices and managing hardware.
b) The creator and super admins have management permission for all hardware devices of a company.
c) Sub-admins can be assigned the permissions for binding new devices or managing specific hardware.
After setting up, hierarchical administrators will be able to manage the features of the security management module in the Admin Console (including basic and advanced features); however, they are not currently eligible to purchase advanced security features.
Note: The hierarchical administrators can’t configured security management permissions until their management scope covers all company members.
a)Admin group: A group of admins who have the same permissions for Contacts and apps. An admin can be in an admin group or belong to no admin group.
b)Creator: Internal and external super admins can only belong to a super admin group. A super admin group is created by the system by default with the highest level of permissions.
1. A sub-admin has the permission to manage all company members, but when setting the app owner, the admin receives a message “Beyond the admin scope. Unable to edit.”
Please check if offboarded members are within the admin scope of the original app owner, and ask the super admin to remove them and try again.
2. Sub-admins cannot see the option to edit Contacts on mobile.
(1). Please check if the sub-admin is accessing the Contacts page within their admin scope. If not, the editing entry will not be displayed.
For example, if the department paths include A, B, and C and the sub-admin’s admin scope is C, the editing entry will not be displayed if the sub-admin is accessing Department B in the Contacts. They need to enter the page for Department C.
(2). Log out of WeCom and log back in to see if the issue is resolved.
1. What are the permissions of a WeCom creator and how to transfer the creator role
2. How to add, set, and change admins in WeCom
3. How to configure Contacts permissions for sub-admins
4. How to set up an agency operating service provider