WordPress

Who can change what? Give your WordPress team the right access

Editor, author or administrator: organise access for colleagues and contractors without shared passwords or unnecessary privileges.

The CloudCity teamPublished 2 min read

A colleague who publishes articles does not automatically need permission to install code. The agency that built the website should not remain the only holder of its main account either. WordPress roles help divide work when they reflect real responsibilities. The aim is to limit the impact of mistakes or compromised accounts while allowing the team to do its job.

Choose permissions for the task

In a standard installation, administrators manage sensitive website functions. Editors can manage other authors’ content, while authors have a narrower scope. Plugins can change capabilities or introduce additional roles. Check the actual permissions in your installation, especially for shops. A role name is a useful guide, not a complete description of every action available.

Give each person an account

Separate accounts allow you to withdraw access without changing a password for the entire team. Use organisation-managed email addresses for critical roles. Do not leave the main administrator attached to a former contractor’s personal address. An administrator can also use a lower-privilege account for ordinary work and sign into the privileged account only when needed.

Make temporary access temporary

Before an intervention, agree what must be done and when access ends. Create a separate user instead of sharing the existing administrator password. Ask whether a test environment is enough for diagnosis. Afterwards, review new users, keys and integrations, then revoke access that no longer has a purpose. Deleting the message containing credentials does not withdraw those credentials.

A role is not account protection

Appropriate permissions do not replace a unique password or available additional authentication. Protect the email account used for password resets too. Keep a record of privileged users and review whether their responsibilities have changed. If a plugin demands administrator rights for a simple task, look for a narrower permission or ask the supplier to explain why.

Prepare for people leaving

Transfer content ownership before deleting an account and check which deletion option you select. Remove hosting, registrar, backup and external service access separately: deleting a WordPress user does not close those accounts. Record who takes responsibility for licences and notifications. The process is complete when the business can continue without depending on the departing person.

Sources and further reading

A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.

Back to the blog