Client accounts
An account is one company. It has its own websites, tracking numbers, calls, reports, plan and invoice, and its own logins. One account can never read another's data. An agency calls its accounts clients; this page uses both words, because the screen in the app does too.
This page is mostly for agencies, who hold several accounts as their business model. If you are a single company tracking your own marketing you almost certainly want exactly one account — see the note on brands and locations below — but since 15 September 2026 you are not limited to one: your plan includes a small number of them, so a business that genuinely runs more than one company can hold an account for each. How many you can have.
Partner, account, project
Three levels, and picking the wrong one is the commonest mistake here.
| Level | What it is | What it holds |
|---|---|---|
| Partner | Your agency. One per organisation. | Your client accounts, your logins, your agency tier. |
| Account | One client. A separate business you work for. | Its own plan and invoice, its own KYC, its own websites. |
| Project | One website. | The tag key, the tracking numbers, the call flow, the calls. |
Brands, locations and extra websites are PROJECTS, not accounts. If one client has three sites, or six branches, those are three or six projects inside that client's single account. They then roll up to one invoice and one set of number and call allowances, and the reports can be read together or apart.
Give each branch its own account instead and you split that client's reporting and their billing in half, and each half counts separately against your client-account cap. There is no way to merge two accounts afterwards, so this is worth getting right first time.
Creating a client
On the Clients screen. You give the client a name; we create the account, its first website and its tag key in one step.
The website is not optional, and the reason is practical: an account with no website has no tag key, so there is nothing to install and nothing the account can do. You can add tracking domains at the same time or later.
- The name is not cosmetic. It heads every report for that client and labels them in the client picker, so two identical names are refused — add a town, a branch or a brand to tell them apart. A genuine second "Smith Plumbing" is fine as "Smith Plumbing (Leeds)".
- Leaving the tracking domains empty is permissive, not restrictive. The tag runs anywhere until you list the client's domains, which means anyone who finds the key in their page source can use it and consume that client's number allowance. It is the one setting whose default is the loose one — and the client's Tracking page will list any host it has actually seen using the key.
- Currency is effectively permanent. Money is stored in minor units with no currency attached, so once a client has recorded revenue or usage we refuse to change it — switching would relabel every historical figure rather than convert it, and last month's £4,000 would silently read as €4,000.
A new client account is on the free tier, holds no tracking number, and cannot receive a call. Creating a client costs nothing, and that is the same statement read from the other side: with no subscription there is no number, so there is nothing for the tag to swap into their pages, so no call will ever arrive. Nobody can ring a number that does not exist.
This is not a first call to wait for. Until a plan is bought for that client there will not be one — no call log, no recordings, no transcripts, and no alert, because every alert trigger is a call or a number event.
What does work immediately: the tag runs, and that client's visitors, sources, campaigns and landing pages are attributed in full. So you can install the tag, show a prospective client their own traffic, and buy a plan when they say yes. Just do not install the tag and then wait for the phone to ring.
How many accounts you can have
For an agency, the cap comes from your agency tier, and it is enforced: the create is refused when you are at it, naming the tier and the allowance. Agency Start includes three client accounts, Grow ten, Pro thirty and Scale a hundred. The prices are on the agency page.
Before any of that you get one. An agency partner with no subscription is on the same free state as a single company — one account, no tracking number, the tag and attribution working — so you can set your first client up, install their tag and show them their own traffic before anything is paid for. Adding a second client is what Agency Start buys. The Clients screen says which allowance you are on and how much of it you have used.
For a single company, the cap comes from your own plan rather than an agency tier. The free tier holds one account, as it always has; every paid single-company plan currently includes three, which is enough for a business that genuinely runs a small number of separate companies without pushing anyone onto an agency tier priced for running dozens. That figure is set centrally rather than typed onto this page, so the Accounts screen is where you check it rather than this paragraph — it may change, and the screen cannot go stale the way a number written into a documentation page can.
The agency tiers are not on checkout yet, so they are set up in a conversation rather than bought with a card. That is deliberate rather than an oversight: one of the things an agency tier is sold on — white-label branding — is not built. Selling you a tier online for a feature that does not exist would be the wrong way round, so we quote the price, set the tier up by hand the same working day, and tell you what is and is not there.
What the tiers do enforce today is the client-account cap, the number and answered call allowances, how long recordings are kept, and whether API keys can be issued at all.
Removing a client frees a slot straight away. Their tracking numbers do not stop costing money on the same day, though — a released number is quarantined for 90 days before it can be reused and is billable throughout, which is explained under tracking numbers.
What a client's own people can see
Client accounts cannot read each other. Two things do that, and it is worth being precise because they work at different levels. Every query that touches one client's data is filtered to that client explicitly, and an automated cross-tenant test stands a second client account up as a control and proves it appears in nothing belonging to the first — no websites, numbers, calls or revenue. The database's own row-level security sits one level further out, between your agency and every other agency on the platform.
You can see the result yourself. The Clients screen carries a cross-account check that counts the websites, numbers, calls and conversions under your agency and reports any that point at the wrong client. It prints the row counts it examined, because a clean result over no rows is not a pass.
Within one client account, two grants are separate on purpose:
- Seeing revenue and listening to recordings are different permissions. A client stakeholder can be given the calls and the return on their spend without being able to hear their own customers' conversations, or the reverse.
- A client-side login is scoped to that client's account and nothing above it. It cannot see your client list, your other clients, or that they exist — the API answers "not found" rather than "not allowed" for anything outside their own account, because a refusal would confirm the thing being asked about.
Adding someone to one client is self-service: switch to that client, then use its own Team screen. That page invites into the account you are currently switched to, so it grants exactly one client's access — say plainly which of the two grants above they should have, because that choice decides whether they can listen to that client's call recordings. How inviting works, in full.
One email address can hold several accounts. If the person already has a Proofbell login — including on another of your clients — inviting them adds this client to what they can already reach, rather than creating a second login or disturbing the first. They choose between the accounts they can reach with the picker above their own email address.
What is not self-service is agency-wide access — a login that reaches every client the way agency staff do. There is no screen that grants that yet, so if you want to add someone at that level rather than to one client, tell us the email address and we will add them.
The Admin menu
Since 15 September 2026 there is one place for all of this: the Admin button at the foot of the sidebar. Pressing it replaces the sidebar’s list of sections with everything to do with which account or website you are looking at, and everything to do with managing either — with Back to main menu at the top to return. The admin list stays put as you move between Plans, Team and Tracking, rather than closing every time you choose something from it. It replaced two things that used to sit apart — a Website picker at the top of the sidebar and an account switcher at the foot of it — because they were two identical-looking dropdowns that looked like one control jumping between two positions depending on the page, which is not what was happening and is not worth explaining twice.
The admin list is in two groups. ACCOUNT holds the account picker — labelled Client for an agency and Account for a single company — alongside New account (or New client) and Account settings. WEBSITES holds the website picker alongside Add a website. Below both sits every Administration link: Plans, Usage, Invoices, Team, Tracking, Transcripts, Activity, API keys, Accounts (or Clients), and Docs.
Choosing a different website from the WEBSITES group moves the screens that read a single website — calls, numbers, call flows and alerts — and the tag key shown on the Overview page is that website's own, named above the snippet so it can be checked before it is pasted. Choosing a different account from the ACCOUNT group moves everything, including billing, the budget planner, reporting and data export, because a website belongs to exactly one account, so switching account discards any website choice with it.
The website picker only appears once the account you are in has more than one website, and the account picker only once your login reaches two or more accounts. New account, Account settings and Add a website are shown whether or not either picker is, because whether you may create or edit one is an authorisation question the page itself answers rather than one this menu guesses at.
Switching reloads the page, and the choice lasts until the tab is closed. It is held in the tab rather than on your login, so two browser tabs can sit on two different accounts — which is useful, and is worth knowing before you compare two numbers side by side and wonder why they disagree. It is also why the menu shows the account and website the screen is actually reading rather than the last one you chose: if an account is removed, or your access to it is withdrawn, the choice is discarded and the menu says so.
A login with access to only one account, on only one website, sees an empty ACCOUNT and WEBSITES group. That is correct rather than a fault: there is nothing to choose between, and the screens show the one account and website that login reaches.
Account settings — the account's name, timezone and currency — is its own screen, reached from the same menu. The name heads every report and labels the entry in the account picker; the timezone is what "calls by hour" and every call flow's opening hours are evaluated in; the currency is refused once anything has been billed or recorded, because money is stored in minor units with no currency attached and a switch would relabel rather than convert every historical figure.
Account numbers
Every account carries a number of its own, PB-10001 upward, allocated once when the account is created and never reused or reassigned. It appears beside the account's name in the account picker, on the Accounts (or Clients) list, in the heading of the Team page, and on Account settings.
It is not a password and it proves nothing on its own — anyone who can see your screen can see it. What it is for is telling one account from another quickly and unambiguously when a name alone will not do: two clients can share a name, but never a number. If you contact support about a specific account, giving them the account number is the fastest way to make sure they are looking at the right one, and it is fair to expect them to ask for it.
Add a website
A website — a project, in the API — is where a tag key, the tracking domains and the phone numbers actually live. An account can hold several: a second brand, a second location, a second site. Each keeps its own tag key and its own numbers, and each is reported both on its own and rolled up with the rest, while all of them share this one account's billing, team and plan allowances — adding a website costs nothing extra and buys no separate number or call allowance of its own.
Add one from Add a website in the WEBSITES group, or from the fuller Websites page reached from Administration, which lists every website on the account with its domains and number count and lets you rename any of them. A name must be unique within the account — two identically named websites cannot be told apart in the picker or on a report — and tracking domains are optional at creation, exactly as they are afterwards.
An account may hold up to 25 live websites. That cap is the same on every plan: a website is not a paid feature, it is a way of organising the numbers and calls your plan already allows, so buying a bigger plan does not raise it and the free tier is not excluded from it.
Website or account — the test is still the one above. One business with several brands or locations wants websites: they roll up to one invoice and one set of allowances, and switching between them is the WEBSITES picker. A genuinely separate company wants a second account, with its own plan, invoice and team — see how many accounts you can have.
A website cannot be removed yet. You can rename one or stop using it, but there is no delete route — so a website you no longer need still counts toward the cap and still appears in the picker. Contact us if this leaves you unable to add one you need.
Setting a new client up quickly
Two routes, and they answer different questions. Cloning starts a new client from a particular client you have already configured, call flow included. An account template starts one from a shape — either captured from a client, or one of the four we ship.
Cloning a client you have already configured
On the Clients screen. You pick a client you have already set up, name the new one, and give the new one its own answering number; you get a new client account in one action. A preview shows what will and will not be reproduced before anything is created.
What a clone reproduces:
- The pool settings — how long a number is held for a visitor, the safety factor, and whether a click-ID join is preferred over a session pool — and how many numbers each channel's pool wants.
- The conversion settings: the qualifying call length, whether conversions are pushed to the ad platforms, and how strict consent has to be.
- The timezone — the source client's, or a different one if you name one for the new client.
- A website with its own tag key, with the answering number set on it, so the new client's calls can actually connect.
The live call flow is copied, rewritten where it names a phone number, and it arrives switched off. Every place the source client's flow names a number is rewritten to the new client's own. A ring step carries the phone numbers on the source client's desks, so copying one verbatim would mean your new client's callers ringing a different business, with nothing in any report saying so. Each opening-hours step's timezone is rewritten too: a London flow left on a New York client is five hours of wrongly-recorded "out of hours" a day that nothing errors on.
Every spoken and written message is copied word for word and is not rewritten — greetings, menu prompts, the whisper the agent hears, voicemail prompts. They routinely name the business ("Thanks for calling Smith Plumbing"), and there is no way to rewrite one correctly from a company name, so guessing would put a wrong company name into a greeting a real caller hears. So the clone lists every message it copied, by step and by field, and the copied flow is saved as a draft — not published and not activated. It cannot route a call until somebody has read those messages and switched it on. That is the safety property rather than a limitation: the review is enforced by the data, not by a warning that can be read past.
What a clone does not reproduce. It reports how many of each the source client has, so you can see what is left to do rather than discover it later:
- Phone numbers. A number belongs to exactly one account. The clone says how many the new client needs and buys none — so cloning commits no monthly spend.
- Webhook endpoints. The signing secret is shown once, so there is no second copy of it to sign with.
- Ad platform and CRM connections. A connection authorises one ad account. Reusing it would push the new client's calls into the source client's Google Ads.
- Warehouse destinations and API keys. Credentials are issued, never copied.
- Users and their access. Copying memberships would give the source client's staff a login to the new client's calls, which is the one thing separation between two clients of the same agency exists to prevent.
- Calls, and conversions and revenue. They happened to another business. A clone starts empty.
Alert rules, if you ask for them
Tick Carry the source's alert rules across and they come with the clone. This is off by default and the preview lists every rule beside the address or channel it delivers to, because that is the thing worth checking: if a rule emails the source client's own manager, the copy would start telling that manager about a different company's calls, and nothing about it would look wrong afterwards.
The usual case is the opposite and is why this exists — the rule delivers to your Slack channel or your inbox, identically for every client you manage, and retyping it per client is the work cloning is for.
Copies always arrive turned off. The new client has no numbers yet and its call flow is an unpublished draft, so a live missed-call rule would fire on your first test call and tell your team that a client you have not launched is missing calls. Switching one on is a click, on a screen that shows where it delivers.
Webhook endpoints still cannot come across, and that is not an inconsistency. A rule's delivery channels can be re-encrypted for the new client because we hold them. A webhook's signing secret is different: it is shown to you exactly once and your receiver holds the only other copy, so a copied endpoint would sign with something the new client's receiver has never seen and every delivery would fail verification. Create it through the normal route, which shows you the new secret.
A clone counts against your client-account cap like any other client, and it is refused when you are at it — cloning gets no discount on the allowance. Two more things the preview will tell you: a campaign-scoped pool on the source cannot be expressed as a channel, so it is named rather than silently dropped; and if the source client has more than one website, only the first is read.
Account templates
Account templates carry the shape of a client that is already configured: how many numbers each channel's pool wants, how long a call has to run to count as a conversion, whether conversions are pushed to the ad platforms, and the timezone. Four are built in — home improvement, legal, local services and a minimal one. Healthcare, automotive and B2B are not among them. A template does not carry your tag taxonomy, report packs or alert rules.
A template can also be captured from a client you have already configured and applied to the next one. Capture deliberately leaves the numbers behind — a phone number belongs to exactly one account and must never be copied — and it reports anything it could not carry rather than copying it silently. A template carries no call flow, so this is the route for a client whose routing you intend to author yourself; cloning is the route that copies the flow as well.
Applying a template writes settings and buys no numbers: it tells you how many are still needed, and you buy those deliberately, because a number bills every month and releasing one starts a 90-day quarantine you are billed through. How templates work, in full — including the three states in the drift report and the four things templates still cannot do.
One invoice for every client
If you would rather be invoiced for your clients than have each of them pay us separately, we can put your agency on consolidated billing. You then get one invoice covering every client you manage, with a line for each of them, and you charge your clients whatever you decide.
Switching you over is ours to do — ask us — because it changes who is invoiced for every client account you hold. Everything after that is yours, on Agency billing in the app: add a card once, then put each client on a plan.
- Your invoice names every client. Each line reads as the client and their plan, so you can pass it on without reconstructing anything.
- Adding a client part-way through a month costs the part. The same when you change a client's plan, and you are credited when you remove one — worked out by Stripe, not by us.
- Usage above allowances arrives on the same invoice, itemised per client, once the period has been checked against our carrier's own figures.
- Monthly and annual clients are billed separately. Keeping every client on the same interval keeps you to one invoice; mixing them means two.
One consequence worth knowing before you ask for it: once your agency is on consolidated billing, a client account can no longer buy or change its own plan from its own Plans screen. It says so, and it says to ask you. That is deliberate — a card entered there would charge somebody who never agreed a price with us.
Reading your clients' data from your own code
API keys are built. You create them yourself, and a key can be scoped to one website, to one client, or to your whole agency — one credential that reads every client you have, now and in future. That last one is what an agency wants for its own reporting, and only an agency owner can create it. Keys are on API keys in the dashboard, and they are included from Pro upwards and on every agency tier.
The API documentation is the account of it: how a key is scoped, why the plaintext is shown once and only once, the two kinds of permission a key may never hold, the endpoints, and the per-key rate limit. It is not repeated here, because two descriptions of one credential is two chances to disagree about what it can reach.
What is not built yet
Worth knowing before you plan an onboarding process around it, because every one of these is a thing agencies reasonably assume:
- Your logo, colours and your own domain. The branding fields exist in the database and nothing renders them. A client logging in sees Proofbell.
- A margin we calculate for you. Not planned, deliberately. On consolidated billing you pay us our prices and charge your clients whatever you decide — we stay out of your pricing, and you do not have to wait for us to pay you a commission.
- Branded PDF and scheduled email reports.
- A screen for user management, or for moving a website between clients.