
Post: HighLevel User Permissions: How to Prevent Contact Deletion
To block unauthorized contact deletion in HighLevel, create a restricted role with “Delete Contacts” and “Bulk Delete Contacts” unchecked, then assign it to every non-admin user. Navigate to Settings > Team, build the role, save it, and verify by logging into a restricted account and attempting a deletion. The blocked action confirms correct setup.
Step 1: Understand HighLevel’s Permission Hierarchy Before Touching Anything
HighLevel’s permission system runs on a tiered hierarchy — agencies sit at the top, sub-accounts below, and custom roles define what each user can do inside those sub-accounts. Every action in the platform, including contact deletion, is gated by a specific permission toggle. Understanding the hierarchy prevents unintended consequences: changing a role affects every user assigned to it, so knowing who sits on which role before you edit is non-negotiable.
The principle of least privilege applies directly here. Users get access to what they need to do their job — nothing more. For most team members, contact deletion stays off by design.
Step 2: Navigate to User Management
HighLevel offers two paths into user management depending on your admin level. Agency Admins go to Agency Settings > Roles (or Team Management) to control permissions across all sub-accounts. Sub-Account Admins navigate to the specific sub-account, then Settings (bottom left corner) > Team or Users. Both paths land you in the same place: a list of active users and their assigned roles, ready for review or modification.
Step 3: Create a New Role — Don’t Edit the Default
Creating a new restricted role — rather than editing an existing one — protects every user you don’t intend to change. Name it clearly: “Sales Rep – No Deletion” or “Marketing – View Only” communicates scope at a glance. If you must modify an existing role, click the pencil icon next to the role name. Either way, you land in the same permission editor with toggles for every feature HighLevel exposes.
Expert Take
Agencies that build purpose-specific roles from scratch almost never cause accidental lockouts. The failure pattern is always the same: an admin edits a shared “general” role to restrict one thing and inadvertently removes access to something else. Build new, purpose-specific roles and assign deliberately — the extra five minutes is cheap insurance.
Step 4: Find and Disable the Contact Deletion Toggles
Inside the role editor, scroll to the Contacts section and locate “Delete Contacts” and “Bulk Delete Contacts” — both toggles need to be off. Scan adjacent permissions carefully; some broader access settings implicitly include deletion. Uncheck both individual and bulk deletion, then confirm no other toggle re-enables what you just removed. Meticulous review here prevents the permission from slipping back in through an unexpected dependency.
Step 5: Save the Role and Reassign Users
Review every other permission in the role before you save — one misconfigured toggle can remove access to features users legitimately need. Once the configuration looks correct, click Save or Update Role. Navigate back to the Users list and reassign each affected user to the restricted role. Confirm the assignment updates before moving on.
For agencies managing multiple sub-accounts, document the role structure now: a simple record of who sits on which role prevents confusion the next time a user asks why their delete button is gone.
Related: 11 HighLevel Snapshot Best Practices for Agency Operational Excellence
Step 6: Verify With a Non-Admin Test Account
Log out of your admin account, log into a user account assigned to the restricted role, and attempt to delete a contact. The delete option is either absent entirely or returns a permissions error — either result confirms the configuration worked. Test two or three different user accounts to catch any role assignment gaps before calling it done.
Admins who skip this step often discover the misconfiguration after a support ticket arrives, not before. The test takes three minutes.
Related: 10 Undeniable Benefits of Automated HighLevel Contact Restores
Step 7: Schedule Quarterly Permission Audits
Put a recurring quarterly audit on the calendar before you close this tab. Team roles drift — people get promoted, contractors get temporary access, and new HighLevel features ship with permission toggles that need evaluation against your security posture. A quarterly review confirms every user still holds the right role and that no new toggle has silently opened deletion access.
Run each audit against a documented baseline: export or screenshot the current role configurations so the next reviewer has something to compare against, not just memory.
Related: 10 Critical Signs Your HighLevel Multi-Account Contact Strategy Is Failing HR & Recruiting Firms
Frequently Asked Questions
Can a HighLevel sub-account admin override agency-level permission restrictions?
No. Agency-level role restrictions take precedence over sub-account settings. A sub-account admin cannot grant a user permissions that exceed what the agency role allows, so locking deletion at the agency level closes the gap across every sub-account in your portfolio.
What happens to contacts deleted before these restrictions are in place?
Deleted contacts land in HighLevel’s internal trash, where they stay recoverable for a limited window. After that window closes, restoration requires a snapshot restore or a third-party backup. Implement restrictions before a deletion incident occurs — recovery after the fact is slower and less complete than prevention.
Do these role restrictions also block contact deletion through the HighLevel API?
API access operates under separate permission controls tied to API keys and connected integrations. Restricting a user role blocks deletion through the UI, but API key permissions require a separate audit to close that vector. Review both in the same session to avoid a gap between UI and API exposure.

