Zapier client access for solution partners: setup, limits, and June security changes
How to set up Zapier client access for solution partners: Pro vs Team/Enterprise, email constraints, and connection ownership after the June security update.
Zapier's client access feature lets solution partners get super-admin style access to a client’s Zapier account (on eligible plans), so they can build and maintain Zaps without constantly asking the client to screen-share or transfer ownership. For Professional (Pro) accounts, it’s typically the fastest, cleanest way to work—but it has some specific setup constraints and important limitations, especially for Team and Enterprise accounts.
Photo by Christopher Gower on Unsplash
What “client access” means (and who it’s for)
Client access is designed for solution partners supporting clients on Professional (Pro) accounts. It gives the partner elevated access in the client’s Zapier account so they can:
view and edit existing Zaps
create new Zaps
help manage app connections
maintain workflows as the client’s needs evolve
If the client is on Team or Enterprise, expect a different onboarding path (more on that below).
How the client access link works
At a high level, the client access flow looks like this:
The client (account owner/admin) generates or shares an access invite link.
The partner accepts the invite and is added to the client’s Zapier account with elevated permissions.
The partner works inside the client account (building, editing, troubleshooting), without needing to “own” everything personally.
What happens on Team/Enterprise accounts
In many cases, the client access link is only available for Pro accounts. If a Team or Enterprise client tries to use the Pro-only link, they may see an error (for example, a 404). For Team/Enterprise clients, the common workaround is:
the client adds the partner as a regular user in their Zapier account (with appropriate role/permissions)
This creates two separate onboarding processes (Pro vs Team/Enterprise), so plan for that in your SOPs.
Setup constraints partners should know (email + domain rules)
Client access typically requires one email to be associated with a solution partner’s access.
Practical implications:
You’ll usually want a dedicated, role-based email like zapieraccess@yourcompany.com.
The email’s domain may need to match the owner user’s email domain on the partner side.
If multiple operators on your team need access, you’ll need a process for sharing access internally (for example, shared mailbox + internal documentation) rather than inviting many different emails.
What clients can revoke or transfer when the engagement ends
Clients should retain control. When the engagement ends, the client should be able to:
remove partner access
transfer Zaps as needed
Important nuance: app connections don’t always transfer the same way Zaps do. Even if Zaps move, connections may remain private to the original connector, expire, or need to be re-authorized depending on the setup.
The June security change: Zaps may stop running if you don’t own the app connection
Zapier rolled out an additional security layer in mid-June. The key behavioral change to understand:
If a Zap is configured to use an app connection that the Zap owner/editor doesn’t have access to, the Zap may not run.
Why this matters for partners:
It increases the risk of “silent failures” when ownership and connection permissions are mismatched.
It makes it more important to standardize who owns connections and how shared access is granted.
Client access is one path that can reduce friction here—because the partner is working inside the client environment with appropriate permissions.
Implementation checklist (partner ops)
Use this checklist to roll out client access consistently.
Before you request access
Confirm the client’s Zapier plan: Professional vs Team/Enterprise
Decide which partner email will be used for access (recommend: role-based mailbox)
Define internal SOP: where to store client account notes, how to hand off between operators, and how to document app connection ownership
When you set up access (Pro)
Have the client send the client access invite link
Accept using the dedicated partner email
Verify you can view and edit existing Zaps
Verify you can create a new Zap and connect required apps
When you set up access (Team/Enterprise)
Ask the client to add the partner email as a user
Confirm the assigned role has the permissions you need
Verify access to the relevant folders/products (Zaps, Tables, Interfaces, etc.)
After access is live
Audit critical Zaps: identify which app connections they use and who owns those connections
Document re-auth steps for key apps (what to do if a connection expires)
Set a quarterly review reminder to clean up access for old clients
FAQ
Can multiple people at the partner company use client access?
Often, client access is tied to one email, so the cleanest approach is usually a shared, role-based mailbox (plus internal process). If you need multiple separate logins, you may need a Team/Enterprise-style user-add flow (or alternate SOPs). Connex can help you design the right access architecture for your team.
What if the client removes our access?
Assume this is possible at any time. Make sure you:
document what you built
keep a lightweight “handover” note ready
design workflows so the client can keep operating without your login
Are app connections transferred automatically when Zaps are transferred?
Not always. Treat app connections as a separate asset with their own security/ownership rules. Plan for re-authorization during offboarding or account transitions.
How has the June security change affected solution partners?
Create a standard policy for connection ownership, and do a quick audit of your top client Zaps. If Zap ownership and connection access are misaligned, fix it now—the enforcement change is already live.
Get help setting up your Zapier client access governance
If you want help setting up a clean, repeatable Zapier governance process for client accounts—including access, ownership, and security—book a free consulting call with Connex. We help solution partners get the access model right from day one—so you’re not scrambling when a client offboards or a security policy changes.
How to normalize upstream status labels so your customer service phone bot gives clear, consistent scheduling updates instead of confusing internal labels.
TripWorks Polaris waiver automation reduces manual checks when TripWorks emails a generic waiver link. Use notifications, email parsing, and a dashboard.