Start with the responsibility
Decide what the person needs to do before choosing their access: edit content, publish changes, manage leads, work on billing or help with account administration. Site permissions and account permissions answer different questions.
Use the team's invitation controls for the selected account or site. Check the recipient and intended scope before sending the invitation. After acceptance, review the person's membership and available role controls.
Separate editing from publishing
A person who can draft content does not necessarily need to publish it. Billing and people management can also be separate responsibilities. Choose the narrowest existing role or available permission arrangement that supports the person's actual work.
If a control is missing or an action is refused, confirm the selected site and the member's access before repeating the request. Visibility in the interface is not the only check; actions are authorized on the server.
Review access over time
Use the available activity and access history when checking administrative changes. The history you can see depends on your role and the records available to that account.
For agency work, distinguish the agency workspace from a separately owned client account. A client-site handoff removes agency access unless the new owner grants it again. Review that change with the client before relying on continued access after handoff.