Intern
What you actually do
Day one: everyone is admin, sacred pipelines get edited at 11pm — write three roles. List what each can edit. Do not add users. Audit the current list. Offboarding is same day. This is governance, not IT fussiness.
Every location user is admin because onboarding was in a hurry. Someone edits the sacred pipeline at 11pm. HQ finds out at QBR. Offboarding is a hope that they 'don't log in anymore.'
Read it once, then stop negotiating with it. GHL permissions and roles for operators is a wiring job: roles → lock → audit → offboard. Objects, then edges, then one test conversion. You do not need a new tool to start. You need the first writer to land on one contact this week.
Operators do not have a GHL permissions and roles problem because they lack GoHighLevel. They have it because everyone is admin. Sacred pipelines get edited at 11pm.
Wire these objects first: Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions.
Then these edges, in order: Role assignment → edit rights listed; default is not admin · Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit · Monthly user audit → 15 minutes; leavers removed · Offboard → access removed the day they leave; not 'later'
Done looks like a test you can repeat: Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else.
Start here: Roles match jobs, not personalities
Operators already have GoHighLevel. The leak is not a missing feature. Everyone is admin. Sacred pipelines get edited at 11pm. Software did not cause it. A missing write-in did: the person exists in one tool and not in the pipeline.
Here is how you actually wire it. Name the objects: Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions. Then connect these edges, in order: Role assignment → edit rights listed; default is not admin · Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit · Monthly user audit → 15 minutes; leavers removed · Offboard → access removed the day they leave; not 'later'. If you skip an edge, the next one is decoration. If you add a GoHighLevel feature first, you usually skip an edge without noticing.
Prove it with a test, not a screenshot. Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else. How you know it worked on the board: Local admin is rare (default is not admin). If that number is a vibe, do not add traffic.
What to do this week, and only this week: Roles match jobs, not personalities An intern can run the objects page and one test conversion. A CEO should protect that from a second priority.
Intern
Day one: everyone is admin, sacred pipelines get edited at 11pm — write three roles. List what each can edit. Do not add users. Audit the current list. Offboarding is same day. This is governance, not IT fussiness.
Operator
You already feel everyone is admin. sacred pipelines get edited at 11pm. Everyone is admin. Sacred pipelines get edited at 11pm. Protect one sequence for 90 days. The four moves are roles → lock → audit → offboard. The edges are Role assignment → edit rights listed; default is not admin then Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit. Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness.
CEO
This is a money leak, not a preference about tools. Every location user is admin because onboarding was in a hurry. Until local admin is a number you will defend, buying more traffic or more seats makes the leak more expensive. Refuse a second database: Role assignment → edit rights listed; default is not admin.
Before
Tuesday. Someone among operators. Everyone is admin. Sacred pipelines get edited at 11pm. GoHighLevel is open. A colleague asks where a person sits. The answer is a screenshot, a Slack thread, or “I think they’re interested.” The writer (form, calendar, shop, or phone) and the pipeline are two databases.
After
Same Tuesday, after write-in exists. Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness. Role assignment → edit rights listed; default is not admin The next move is written. That is the difference between a login and a system.
Keep it this plain. A person in operators already paid for GoHighLevel. Everyone is admin. Sacred pipelines get edited at 11pm. They add a page, a form, a calendar. None of it writes into a spec. By Friday the calendar has ghosts and the pipeline still looks like the snapshot.
The fix is not a better template. Roles match jobs. Prove write-in: Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else. This week is one move: Roles match jobs, not personalities If that feels too small, that is the point. Operators fail by starting at move four.
The leak
Every location user is admin because onboarding was in a hurry. Someone edits the sacred pipeline at 11pm. HQ finds out at QBR. Offboarding is a hope that they 'don't log in anymore.'
The system
Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness.
Write three roles: HQ admin, location manager, front desk / closer. For each, what they can edit. If the answer is 'everything', you do not have a franchise system — you have a shared login.
Lock pipelines, folding in GHL's user permissions and (if you use it) snapshot restrictions. Then a monthly 15-minute audit: who has access, who left. The leak is almost always a user who should not be admin.
Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness.
Everyone is admin; sacred pipelines get edited at 11pm. Roles match jobs, not personalities, and locations cannot edit locked pipelines. User audit exists. Offboarding removes access the same day. Write three roles — HQ admin, location manager, front desk/closer — and if the answer is 'everything', you do not have a franchise system, you have a shared login.
Wire GHL permissions and, if you use them, snapshot restrictions. Test with a location user. Monthly 15-minute audit: who has access, who left. The leak is almost always a user who should not be admin. Contractors get expiry dates. Shared logins are banned — they make offboarding fiction. Conversations access is part of the role, not an afterthought.
Two databases: a 'who's in GHL' spreadsheet that is stale, and the actual user list. The intern runs the user list against HR/leaver list. They do not grant admin 'just for training'. Training uses the real role. If they cannot learn without admin, the role is wrong or the sacred objects are not locked — fix those, do not promote everyone. 11pm edits of stages are how Monday reporting dies.
Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions.
Role assignment → edit rights listed; default is not admin
Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit
Monthly user audit → 15 minutes; leavers removed
Offboard → access removed the day they leave; not 'later'
Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else.
Day one: everyone is admin, sacred pipelines get edited at 11pm — write three roles. List what each can edit. Do not add users. Audit the current list. Offboarding is same day. This is governance, not IT fussiness.
Three written roles. Edit rights listed.
Sacred pipelines and HQ assets cannot be edited locally.
Monthly user list. 15 minutes. Removals happen.
Access removed the day they leave. Not 'later.'
On one line, for operators: Everyone is admin. Sacred pipelines get edited at 11pm. Add who gets hurt (calendar, cash, inbox, or reputation). If two people write different sentences, you do not agree yet — stop and agree.
Why: Teams skip this and jump into settings. Then every person is fixing a different problem with the same login.
Done when: One sentence. Shared. No adjectives required.
Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions.
Why: If objects aren't named, software invents a second database.
Done when: A stranger can list them.
Three written roles. Edit rights listed. Then wire: Role assignment → edit rights listed; default is not admin
Why: Operators cannot skip this edge. Everyone is admin; sacred pipelines get edited at 11pm. If it is not true, GoHighLevel is already a second database.
Done when: Role assignment → edit rights listed; default is not admin is true on a test.
Sacred pipelines and HQ assets cannot be edited locally. Then wire: Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit
Why: Operators skip this and the leak returns as a private language. Wire GHL permissions and, if you use them, snapshot restrictions. Spec tags, fields, and states have to be the same objects the next workflow will read.
Done when: Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit is true on a test.
Monthly user list. 15 minutes. Removals happen. Then wire: Monthly user audit → 15 minutes; leavers removed
Why: Operators feel this as Everyone is admin. Sacred pipelines get edited at 11pm. Two databases: a 'who's in GHL' spreadsheet that is stale, and the actual user list.
Done when: Monthly user audit → 15 minutes; leavers removed is true on a test.
Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else.
Why: Calendar full + pipeline empty means two databases.
Done when: One test conversion, one contact, right stage/state.
Every Monday, look at Local admin (Default is not admin), then sacred edit (Test with a location user). Write one action or write “hold.” A dashboard with no action is theatre.
Why: What gets reviewed gets run. What only lives in a tool gets ignored the week someone is busy.
Done when: Three numbers. One owner. Fifteen minutes. Actions attach.
Roles match jobs, not personalities
Why: Operators fail by starting at move four. Interns fail by making a 40-item checklist. CEOs fail by adding a second priority. One proven write-in beats an elegant plan.
Done when: The move is true, or you can name the blocker in one sentence.
Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions.
If objects aren't named, software invents a second database.
Everyone is admin. Sacred pipelines get edited at 11pm.
Three written roles. Edit rights listed. Then wire: Role assignment → edit rights listed; default is not admin
Operators cannot skip this edge. Everyone is admin; sacred pipelines get edited at 11pm. If it is not true, GoHighLevel is already a second database.
On GoHighLevel, this means the data model matches how operators actually work — not the snapshot demo. Edge: Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit
Sacred pipelines and HQ assets cannot be edited locally. Then wire: Sacred pipeline / HQ calendar / snapshot objects → location role cannot edit
Operators skip this and the leak returns as a private language. Wire GHL permissions and, if you use them, snapshot restrictions. Spec tags, fields, and states have to be the same objects the next workflow will read.
Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness.
Monthly user list. 15 minutes. Removals happen. Then wire: Monthly user audit → 15 minutes; leavers removed
Operators feel this as Everyone is admin. Sacred pipelines get edited at 11pm. Two databases: a 'who's in GHL' spreadsheet that is stale, and the actual user list.
Roles match jobs, not personalities
Because the login already exists. Every location user is admin because onboarding was in a hurry. Someone edits the sacred pipeline at 11pm. A new feature on a missing spec is a second database. Finish this edge first: Role assignment → edit rights listed; default is not admin.
Day one: everyone is admin, sacred pipelines get edited at 11pm — write three roles. List what each can edit. Do not add users. Audit the current list. Offboarding is same day. This is governance, not IT fussiness. Workflows on unnamed objects fire on folklore. Name contact (or profile), stage or state, and the writer (form, calendar, metric) before any on-switch.
A test conversion creates or updates one person, on the right stage or state, with the fields the next sequence will read. Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else. If you merge after the test, identity is wrong — fix that, do not add a dedupe automation.
If it is only in someone's head, a new hire needs a story, reporting cannot be defended, and automations fire on folklore. Writing is how two people mean the same object on Monday.
Because setup was a project, not a review. Leavers (Same day) is how you stop the leak returning dressed as a new feature. If locations can edit the sacred pieces, they will, and you will not know. Governance is the product: change log, breaking vs safe, notify, rollback. Speed-to-lead is a number. Stolen leads are visible. Otherwise culture is just drift.
More leads into a leak is a more expensive leak. Roles match jobs. Locations cannot edit locked pipelines, calendars that are HQ, or snapshots. A user list is reviewed. Offboarding removes access the day they leave. This is governance, not IT fussiness. Watch local admin before you buy traffic. If that number is folklore, acquisition is a vanity spend.
Then you only have time for the objects page and one test conversion. Roles match jobs, not personalities That is the intern version of strategy. Protect it from a second priority for seven days.
Skip this
Leaving objects unnamed because GoHighLevel is “set up”.
Do this
Roles (HQ admin, location manager, front desk/closer), locked pipelines, user list audit, offboarding same day, GHL users, snapshot restrictions.
Skip this
Building a workflow or flow before a writer lands on one contact.
Do this
Role assignment → edit rights listed; default is not admin
Skip this
Calling it done because a screenshot looks busy.
Do this
Create a location-role user (or use one). Confirm they cannot edit the locked pipeline. Confirm they can do their job (inbox, their calendar). Remove them; confirm they cannot log in. If everyone is admin, fail before you test anything else.
Skip this
Leaving “Offboard” to chance.
Do this
Access removed the day they leave. Not 'later.'
The usual miss
Calling GoHighLevel “set up” because someone logged in and imported a snapshot.
Do this instead
Three written roles. Edit rights listed. Then prove write-in: Create a location-role user (or use one).
The usual miss
Building the workflow or flow before the writer (form, calendar, shop event) lands on one contact.
Do this instead
Connect Role assignment → edit rights listed; default is not admin first. Automations on a missing writer invent a second database.
The usual miss
Adding a page, form, flow, or campaign every time last week hurt.
Do this instead
Name which edge is missing. Fix that edge. Hurt is usually a skipped write-in, not a missing asset.
The usual miss
Reporting that nobody will defend in a meeting — screenshots, vanity opens, 'interested' counts.
Do this instead
Local admin: Rare. Default is not admin. If you cannot say it out loud, it is not a scoreboard.
The usual miss
Hiring or retaining an agency to invent the spec while also running the calendar.
Do this instead
Hands on a known sequence are useful. Hands inside a missing spec pick the louder job (the calendar) and the leak stays.
Local admin
Rare
Default is not admin
Sacred edit
HQ only
Test with a location user
Leavers
Removed
Same day
This week
Roles match jobs, not personalities
Roles match jobs, not personalities
Locations cannot edit locked pipelines
User audit exists
Offboarding removes access the same day
Want the longer lesson, not the page for this niche? A snapshot is not governance ↗
Working notes
What HQ should lock, what locations can change, and how rollout actually works. Request the file. It arrives by email — not a public dump, not a drip of slogans.
Email and WhatsApp stay open. A call is for installing the system.