A colleague who publishes articles does not automatically need permission to install code. The agency that built the website should not remain the only holder of its main account either. WordPress roles help divide work when they reflect real responsibilities. The aim is to limit the impact of mistakes or compromised accounts while allowing the team to do its job.
Choose permissions for the task
In a standard installation, administrators manage sensitive website functions. Editors can manage other authors’ content, while authors have a narrower scope. Plugins can change capabilities or introduce additional roles. Check the actual permissions in your installation, especially for shops. A role name is a useful guide, not a complete description of every action available.
Give each person an account
Separate accounts allow you to withdraw access without changing a password for the entire team. Use organisation-managed email addresses for critical roles. Do not leave the main administrator attached to a former contractor’s personal address. An administrator can also use a lower-privilege account for ordinary work and sign into the privileged account only when needed.
Make temporary access temporary
Before an intervention, agree what must be done and when access ends. Create a separate user instead of sharing the existing administrator password. Ask whether a test environment is enough for diagnosis. Afterwards, review new users, keys and integrations, then revoke access that no longer has a purpose. Deleting the message containing credentials does not withdraw those credentials.
A role is not account protection
Appropriate permissions do not replace a unique password or available additional authentication. Protect the email account used for password resets too. Keep a record of privileged users and review whether their responsibilities have changed. If a plugin demands administrator rights for a simple task, look for a narrower permission or ask the supplier to explain why.
Prepare for people leaving
Transfer content ownership before deleting an account and check which deletion option you select. Remove hosting, registrar, backup and external service access separately: deleting a WordPress user does not close those accounts. Record who takes responsibility for licences and notifications. The process is complete when the business can continue without depending on the departing person.
Sources and further reading
A CloudCity editorial guide informed by the documentation below. Check the official source for rules and procedures that may change.