How to Safely Add a Developer or Support Team to Your Website

Don't share your password. Here's how to give a developer or support team their own access to WordPress, your hosting, and your domain, and how to remove it later.

The safest way to give someone access to your website is to invite them as their own user, never to share your password. In WordPress, go to Users → Add New User, enter their email, and choose the lowest role that lets them do the job. When the work ends, delete their account, and your site is back to just you.

The same idea works almost everywhere: your hosting account, your domain, Google Business Profile, and most other tools have a way to invite someone. This guide walks through each one.

Why not just share your password?

Handing over your password feels quicker, but it causes problems almost right away:

  • Security codes at 2 a.m. If your account uses two-step login, every time someone else logs in, the code gets texted to your phone or sent to your email.
  • Surprise lockouts. If they reset the password, or you do, someone gets locked out in the middle of the work.
  • No record of who did what. Every change looks like it came from you.
  • No clean way out. When the work ends, you have to change your password everywhere you used it.

Giving someone their own account fixes all four, and it takes about five minutes.

How to add someone to WordPress

You’ll need to be logged in as an Administrator.

  1. Go to Users → Add New User in your WordPress dashboard.
  2. Enter a username and their email address. Use the email address they gave you, so the account is tied to them, not you.
  3. Add their name if you’d like. It makes the user list easier to read later.
  4. Leave the password alone. WordPress creates a strong one. Make sure “Send the new user an email about their account” is checked, so they can set their own.
  5. Choose their role. See the table below. A support team doing technical work needs Administrator.
  6. Click Add New User. They’ll get an email with a link to log in.

That’s it. You never have to share your password, and you can see exactly who has access under Users.

Which role should you choose?

Give each person the lowest role that lets them do their job.

RoleWhat it can doUse it for
AdministratorEverything: plugins, themes, settings, and usersYour developer or support team, when they’re handling updates, fixes, and technical work
EditorPublish and edit any page or post, but no plugins or settingsA staff member or assistant who manages your content
AuthorWrite and publish their own postsA regular blog writer
ContributorWrite posts, but not publish themA guest writer whose posts you review first

If your site runs an online store with WooCommerce, you’ll also see a Shop Manager role, which is good for staff who handle orders and products.

Beyond WordPress: hosting, your domain, and other tools

Your hosting account. If we host your site, there’s nothing to do here: we manage the servers ourselves. If you host it yourself, most quality hosts let you add a team member with their own login. We recommend Cloudways or Rocket.net, and both make this easy.

Disclosure: if you sign up for Cloudways through our link, we may earn a commission, at no extra cost to you.

A note on GoDaddy: it’s a perfectly good place to register a domain, but we don’t support websites hosted on GoDaddy’s web hosting. If your site is hosted there, we’d recommend moving it, and we’re happy to help.

Your domain. Your domain should always stay registered to your business. To let someone manage its settings without handing over your account:

  • GoDaddy: Most people we meet have their domain here, and that’s fine. Use GoDaddy’s Delegate Access feature to invite someone. The steps are below.
  • Namecheap: Our favorite registrar. Use Namecheap’s sharing options for your domain to give someone access.
  • Cloudflare: Excellent, but it can feel overwhelming if you’re not technical. Invite people as members of your account.

Google Business Profile, Analytics, Mailchimp, and other tools. Nearly every tool you’d hand off has a way to invite someone. Look for a section called Users, Team, or People and access, and add them by email. Keep yourself as the owner.

How to give someone access to your GoDaddy account

GoDaddy is where a lot of small businesses register their domain, and it has a built-in way to give someone access without sharing your password. It’s called Delegate Access.

  1. Sign in to your GoDaddy account.
  2. Open Account Settings, then select Delegate Access. GoDaddy may ask you to sign in again.
  3. Under “People who can access my account,” select Invite to Access.
  4. Enter the person’s name and email address.
  5. Choose an access level. For most website work, Products & Domains is the right choice. It lets them manage your products and domain settings without making purchases on your account.
  6. Select Invite.

The person gets an email and accepts the invitation with their own GoDaddy account. If they don’t have one, GoDaddy will ask them to create it. Invitations expire if they aren’t accepted within a few days, so let the person know it’s coming.

Delegates can work with the products in your account, but they can’t see or change your payment methods or your password. To remove someone later, go back to Delegate Access and remove them from the list.

How to remove someone’s access

When the work ends, or someone leaves your team:

  1. Go to Users in WordPress, and hover over their name.
  2. Click Delete.
  3. When WordPress asks what to do with their content, choose “Attribute all content to” and pick your own account, so none of their pages or posts are lost.

Do the same in your hosting account, domain, and other tools. Since everyone has their own login, removing one person never affects anyone else.

How we handle access at MaintainPress

When you work with us, we never ask for your password. You invite us as a user, so you can always see exactly what we can access and remove it anytime. Our own logins are stored in an encrypted password manager, and each team member uses their own account.

New clients get a short version of this guide in their welcome email, with the email address to use when you add us.

See how Website Care works →

FAQ

Is it safe to give a developer Administrator access?

It’s safe when you trust the person or company and they have their own account. Administrator access is needed for technical work like updates and fixes. Because it’s their own login, you can see it in your user list and remove it anytime.

What if the person I’m adding doesn’t have an email address at my business?

That’s fine. Use whatever email address they give you. It’s their account, so their login emails should go to them.

How do I see who has access to my site right now?

Go to Users in your WordPress dashboard. Click Administrator above the list to see who has full access. If you don’t recognize someone, ask before deleting them, since some plugins and services create their own accounts.

Do I need to change my password after someone stops working on my site?

Not if they had their own account. Just delete it. If you ever shared your password in the past, change it now.

Jeffery Patch

Founder, Lead Geek · MaintainPress

Jeff has been building and looking after WordPress sites since 2009.

Rather hand it off?

Tell us what your site needs, and we'll recommend the right plan. Month-to-month, no contracts.