Key takeaways
- Channel permissions let someone work on your channel through their own Google Account, with no password shared and no second device to hand over. Revoking access is one click and takes effect immediately.
- The Access dropdown is not a formality. Manager is one step below you — it can invite and remove other people, including the person who granted it. Everything below Manager cannot touch the access list at all.
- The Editor family is the working role: upload, edit details, publish, swap thumbnails. The documented limits are that an Editor cannot delete published videos, cannot manage permissions and cannot reach monetisation settings.
- No role reaches the money. AdSense is a separate system tied to one payee, and nothing in the permissions list exposes banking details, tax forms or payout controls.
- Ownership is a different machine entirely: it lives on the Brand Account, not in Studio, and a new owner must hold owner access for seven days before they can be promoted to primary owner.
- Permissions are an offboarding tool more than a security tool. They limit what a careless collaborator can break; they do nothing about a stolen session cookie on your own machine.
At some point the channel stops being a one-person job. An editor needs to upload the cut so you are not the bottleneck at midnight. A designer needs to drop in a new thumbnail on the video that underperformed. Someone who is not you wants to answer the comments, or pull the analytics for a sponsor deck, or fix the captions on the back catalogue.
The default response — and it is still the most common one — is to send the password. It works instantly, it requires no reading, and it quietly hands a contractor the ability to delete every video you have made, change the channel name, and read your earnings. It also breaks the moment two-step verification asks for a code that is on your phone and not theirs.
Channel permissions exist to make that unnecessary. They are also badly understood, partly because there are two overlapping systems with the same vocabulary, and partly because the role names sound softer than the powers behind them. This is the version worked out properly: what each role can actually do, which one to hand to which job, what no role can reach, and the offboarding routine that matters more than the invite.
What channel permissions actually are
Channel permissions attach other people's Google Accounts to your channel with a defined level of access. The invited person signs in as themselves, and your channel appears as something they can switch into. They never see your password, never need your recovery codes, and never touch the phone your second factor lands on.
YouTube's own documentation is direct about the reason: granting permissions is safer than sharing sign-in details, and the levels exist so you can control who can view or update what. The list is managed in YouTube Studio under Settings, then Permissions — a single screen showing everyone who holds access, at what level, and which invitations are still pending.
Two things about that screen are worth knowing before you use it. Only the owner and Managers can see it, so a collaborator asking "who else has access to this channel?" cannot answer their own question. And it is the whole record: do not count on an audit trail to tell you, six months from now, which of three Editors changed the title on a video the night it underperformed. Keep the list short enough that the question rarely needs asking.
Access is also no longer confined to Studio. TeamYouTube announced in 2023 that Manager and Editor roles can act on the main YouTube surface as well — uploading a Short, posting in the Community tab, managing playlists, and commenting on videos as the channel. That is convenient and it is also the part people forget when they audit access: a role you granted so someone could upload a cut is also a role that can post in your name.
The six entries in the Access dropdown
YouTube's help text describes five levels of access, plus a subtitle-only role that behaves like its own category. In practice the dropdown gives you six choices, and the distances between them are uneven — the gap between Manager and Editor is enormous, while the gap between Editor and Editor (Limited) is one column of data.
| Role | Can do | Cannot do |
|---|---|---|
| Manager | Effectively everything on the channel, including inviting and removing other people | Delete the channel itself |
| Editor | Upload, edit video details, publish, change thumbnails, view channel data including revenue | Delete published videos, manage permissions, reach monetisation settings, reset or delete stream keys |
| Editor (Limited) | Everything an Editor can do | See any revenue data, including Super Chat and Super Stickers earnings |
| Subtitle Editor | Add, edit, publish and delete subtitles on eligible videos | See anything else in Studio — channel details, analytics or revenue |
| Viewer | Read channel details, analytics and revenue; view stream settings other than the key | Change anything, upload anything, or invite anyone |
| Viewer (Limited) | Everything a Viewer can do | See revenue data |
The revenue-blind variants are newer than the rest and were added for a specific, unglamorous reason. YouTube introduced them in 2020 after creators pointed out the obvious: the person cutting your videos does not need to know what you earn, and a lot of creators were choosing between oversharing and doing the uploads themselves. If you are hiring, Editor (Limited) should be your default and full Editor the exception you make deliberately.
Manager is not a middle rung
Manager can invite and remove other people's access. That includes removing the person who granted it. It is the one role where a bad hire, or a compromised collaborator account, can lock you into a support queue rather than a quick fix. Hand it to a business partner or a long-term channel manager whose loss would be a crisis anyway — not to the person covering your uploads for a month.
What no role can reach
Three things sit outside the permissions system entirely, and knowing which they are removes most of the fear from granting access.
The money. Channel permissions decide who can see revenue numbers inside Studio and Analytics. They do not decide who can touch the money. The linked AdSense account — banking details, tax forms, payout controls — is a separate system tied to one payee, and there is no channel-permission role that reaches into it. An Editor who can read your RPM to the penny still cannot change where the payment lands.
The channel's existence. Even Manager, the most powerful invited role, cannot delete the channel. Deletion belongs to the account that owns it.
Ownership. Nothing in the Studio permissions screen transfers ownership of a channel. That happens on the Brand Account, through a different flow, with its own waiting period — covered below, because a surprising number of channel sales and hand-offs fall over at exactly that step.
There is a fourth boundary worth stating, since it causes real confusion when a channel joins a network. A multi-channel network or rights manager operating through YouTube's Content Manager system is not using channel permissions at all; that is an enterprise backend for content owners, and linking a channel to it does not transfer ownership. It is a separate grant, made separately, and it should be reviewed separately from the list of humans in your Permissions tab.
Which role for which job
The rule that survives contact with reality is the boring one: give the lowest role that lets the person finish the work without asking you for anything. Everything else is a rationalisation for convenience, and convenience is what you are buying when you hand out Manager to avoid a second conversation.
| Who | Role | Why that one |
|---|---|---|
| Video editor uploading cuts | Editor (Limited) | Needs upload, details and scheduling. Does not need your earnings, and cannot delete what is already published |
| Thumbnail designer | Editor (Limited), or no access at all | Swapping a thumbnail needs Editor-level access; delivering a file does not. See below |
| Community manager | Editor (Limited) | Comments, Community posts and playlists now work on YouTube itself, not only in Studio |
| Agency or consultant reporting on performance | Viewer (Limited), or Viewer if they are advising on revenue | Read-only is genuinely enough for an audit. Most access requests are larger than the job |
| Translator or captioner | Subtitle Editor | The one role that exposes nothing else. Ideal for per-video freelancers |
| Business partner or full-time channel manager | Manager | Needs to run the channel when you are unreachable, including managing everyone else's access |
| Accountant or bookkeeper | Viewer | Wants revenue figures, not controls. Note that payout and tax details live in AdSense, not here |
Two sanity checks before you send any invite. First, write down why this person has access and when you expect it to end — a date, not a feeling. Contractor access without a removal date is how channels end up with eight people on the list and two who still work there. Second, prefer the shortest-lived grant that works: a one-off captioning job does not need a permanent Subtitle Editor seat.
The thumbnail designer question
This one deserves its own answer, because it is where the least-privilege rule and the actual workflow disagree.
Changing the thumbnail on a published video requires Editor-level access. There is no thumbnail-only role. So if you want your designer to push their own work live — see the underperformance, cut a new version, swap it, watch the next 48 hours — they need the same role as the person who can rewrite your titles and descriptions.
For most channels, they do not need that. The thumbnail workflow that survives scale is a file handoff: the designer delivers the image, you or your editor upload it, and the designer never appears on the permissions list at all. It costs about fifteen seconds per video, and it removes an entire category of risk from a relationship that is frequently short and always remote.
Where the argument flips is testing. If the designer's job is not "make a thumbnail" but "improve click-through", they need to see what happened — impressions, CTR by traffic source, and the outcome of any Test & Compare run. A designer working blind is producing decoration. At that point Editor (Limited) is the honest answer, because it gives them the data they need and none of the revenue figures they do not.
If you want the middle path, give them Viewer (Limited) so they can read performance, and keep publishing with you. And if a collaborator reports that the custom-thumbnail control is missing entirely, check their role first and the channel's own eligibility second — those are separate causes, and the rest of them are worked through in the guide to a thumbnail that will not show or update. Comparing two candidate images before either goes live does not need channel access from anyone; the free A/B comparison tool runs in the browser.
How to grant access, and what happens next
The mechanics are short. In YouTube Studio, open Settings, then Permissions, then Invite. Enter the person's email address, choose the level in the Access dropdown, and send it. The invitation arrives by email with an Accept link.
Four details decide whether that works first time:
- Use the Google Account address, not the address they prefer. The invite binds to a Google Account. The most common reason an invitation appears to vanish is that it went somewhere that is not that account — an alias, a forwarding address, a plus-address, a work inbox that redirects.
- They need a Google Account, and may be asked to create a channel. If the account has never been used with YouTube, accepting can prompt them to create a basic channel of their own first. This is normal and does not affect yours.
- Invitations expire after about 30 days. A pending entry that has aged out needs removing and re-sending, not chasing.
- Managed accounts can be blocked by their own administrator. If the invitee is on a Google Workspace account, their organisation may restrict YouTube features in ways that stop the acceptance flow. A personal account is the quick workaround; their admin is the real fix.
If the invitation was accepted but the channel does not appear for them, the usual cause is that they are signed into a different Google Account from the one you invited — several accounts in one browser profile is the normal state of affairs for anyone doing this professionally. Ask them to check the account switcher before you re-send anything. Browser extensions that modify Studio can also distort the permissions list; turning them off is worth trying before you conclude the feature is broken.
Brand Accounts, and the migration most channels never finished
Here is the source of most of the confusion in this topic. There are two access systems, they use similar words, and one of them is a survival from a product that no longer exists.
A Brand Account is the container a channel can sit in so that it is not welded to one personal Google Account. Brand Accounts have their own roles — primary owner, owner, manager, and a legacy communications manager role inherited from Google+ that cannot access YouTube at all. Channel permissions in Studio are the newer, YouTube-specific system, and they are the ones that offer Editor, Subtitle Editor and the revenue-blind variants.
YouTube's guidance is to move Brand Account user access over to channel permissions, and the migration has a trap in it: existing Brand Account users are copied across, but you have to set each person's level and send the invitation yourself. The temptation is to mirror what was there. Do not. A migration is the cheapest possible moment to demote three people, delete one, and discover that the person who "helped with the channel in 2022" still holds access.
You need to be signed in as the Brand Account's primary owner to start it. If that sentence raises a question about who the primary owner actually is, answer it today rather than during an incident.
Ownership transfer is a different machine
Selling a channel, handing one to a business partner, moving one out of an agency's control at the end of a contract — none of these are permissions changes, and treating them as one is how people end up promising a buyer something they cannot deliver.
Ownership transfer requires the channel to be on a Brand Account, and it happens on the Google Account side, not in Studio: the Brand Accounts page, then the channel, then manage permissions. The constraint that catches everyone is the waiting period. A new person must hold owner access for seven days before they can be made primary owner. It is a deliberate security delay, not a queue — it exists so that a compromised account cannot be escalated to full ownership before the real owner notices and revokes it.
Plan around it. If a handover is dated, the owner invitation goes out at least a week before, and the paperwork should say so. Do the whole flow on a desktop browser; the mobile apps do not expose the controls you need.
What permissions fix, and what they do not
It is worth being precise about the threat model here, because "use channel permissions" gets repeated as security advice and it only half is.
What they genuinely fix: shared credentials. A password that four people know cannot be rotated without a group chat, cannot be audited, and survives every departure. Permissions replace that with per-person access you can revoke individually, at a level that limits what a mistake can cost. They also mean a collaborator's compromised account is a bounded incident rather than a total one — an Editor account taken over cannot delete your library or reassign your channel.
What they do not fix: the attack that actually takes channels. Creator account takeovers overwhelmingly run on session-cookie theft delivered through a plausible business email, and a stolen session from your own machine inherits everything you can do, permissions screen included. Two-step verification does not fire, because the attacker never signs in. That mechanism, and the hardening that works against it, is the subject of the channel takeover guide — and it is the one to read if you only read one more thing after this.
Two adjacent points. Every person you invite becomes part of your channel's attack surface, so their account hygiene is now your problem: two-step verification on their Google Account is a reasonable condition of access, not an imposition. And if your channel is in the Partner Programme, two-step verification is already a requirement of the programme itself, sitting alongside the subscriber and watch-hour thresholds as one of the conditions of joining.
The other honest limit: a strike is a channel-level event. If an Editor publishes something that draws a copyright claim or a Community Guidelines strike, the consequence lands on your channel and your monetisation, not on their account. Restricting a role restricts damage to the library. It does not delegate liability.
The offboarding routine
Granting access is a five-minute job that everyone does. Removing it is a five-minute job that most people never do, which is why the average multi-person channel is carrying at least one seat that should have been closed months ago.
When someone stops working on the channel, in this order:
- Remove their access in Studio. Settings, Permissions, remove. Do it on the last day, not at the end of the month.
- Clear pending invitations that were never accepted. A stale invite to an old work address is a live grant waiting for someone to claim it.
- Reset the stream key if they ever touched live. A stream key is a credential that travels; it does not care that someone's role was removed.
- Review connected apps and third-party tools. Scheduling tools, analytics dashboards and editing suites hold their own authorisations, separate from the permissions list.
- Check what is scheduled. Anything queued by a departing Editor should be reviewed before it publishes in your name.
- Re-read the whole list once a quarter. Every name, out loud, with a reason attached. Anyone you cannot justify comes off.
Attach that quarterly pass to something you already do. If you run a periodic channel audit, the permissions list is a two-minute item at the top of it, and it is the only item on the list that can cost you the channel rather than a few per cent of CTR.
The short version
Give the lowest role that finishes the job. Default to the revenue-blind variants; there is almost never a reason for a contractor to see your earnings. Treat Manager as a partner-level decision, because it can rewrite the access list you are relying on. Remember that ownership and money live outside this system, so a permissions grant is not the thing you negotiate when you are selling or transferring a channel. And put a removal date on every grant you make, because the failure mode here is never a dramatic breach — it is accumulation.
The thumbnail case is the one worth thinking about twice, since it is the collaboration most channels add first. If your designer is delivering files, they do not need to be on the list at all. If they are being held to a click-through number, they need to see the data, and Editor (Limited) is the smallest role that gets them there honestly. Deciding which of those two jobs you are actually hiring for is more useful than any role table.
Whichever way that goes, the artwork still has to exist before anyone can upload it. Thumblore is built for the part before the permissions question — generating and iterating thumbnail concepts quickly enough that a designer or a solo creator can bring three candidates to a video instead of one. It has nothing to do with access control. It just means that when the person with the Editor role sits down to publish, the decision in front of them is which image, not whether there is one.
For the adjacent reading: the rebranding guide covers the other set of changes to a channel that look cosmetic and are not.