Product
Solutions
Compare
Resources
Get early access Talk to us
Team and client access

Nobody needs the admin password again

Granular roles scoped to individual sites or whole clients, so a junior can run approved updates without being able to delete a backup, and a client can see their own reports without seeing anyone else's portfolio.

Included on every plan. No add-on pricing.

Updated

app.wpcentrify.com/team
Team and accessExample data
Team members
9
2 contractors
Client logins
24
portal only
2FA enforced
100%
all seats
Shared passwords
0
none needed
AMAmara O.
Administrator, all sites
Full2FA on
JTJonah T.
Technician, 18 sites, approved updates only
Scoped2FA on
RCRea C. (contractor)
4 sites, expires 30 Sep
Temporary2FA on
CLHarvest Collective
Client portal, 3 own sites
Portal

What is WordPress team access management?

WordPress team access management decides who on a team can reach which WordPress sites and what they can do there, without everybody sharing one administrator password. Done well, a junior can run routine work without being able to delete a backup, and access ends cleanly when somebody leaves.

In WPCentrify each person has their own login and a role that sets what they can do in each area, such as updates, backups, security, content, SEO, enquiries and chat, from viewing to acting. Start from a ready-made role such as Web developer and SEO or Viewer, or save your own, and the dashboard shows each person only the controls they are allowed to use. Team members are never charged for.

WPCentrify team access at a glance

  • Every person has their own login. Nobody shares an administrator password.
  • Permissions set per area, from viewing to acting.
  • Ready-made roles, plus roles you save for your own team.
  • Team members are never charged for.
  • Remove a person once and their access ends everywhere, while their past actions stay in the activity log.
The problem

Shared credentials are the default and they are a liability

Most small teams run on a shared password manager entry and good intentions. It works until somebody leaves, a laptop is lost, a contractor finishes a project, or a client asks who exactly made a change on the 14th and nobody can answer.

Shared credentials also make delegation risky. Handing a junior the admin password to run a routine update means handing them the ability to delete the site, so the work stays with the person who should be doing something more valuable.

What this looks like without a platform

  • One admin account shared across four people and a contractor
  • No way to tell who made a change
  • Offboarding that means rotating passwords on thirty sites
  • Giving a client an admin login because there was no other option
How it works

How WordPress team management and access control work

Roles that map to real jobs

Owner, administrator, technician, analyst, billing and client. Each carries a sensible default permission set that you can adjust rather than build from nothing.

Scoped to sites or clients

A contractor gets access to four sites for the duration of a project. An account manager sees every site belonging to their clients and none belonging to anyone else. The same structure works for a company running its own sites, as described in WordPress management for in-house teams.

Permissions at action level

Separate the ability to run an update from the ability to approve one, restore a backup, change a policy, or invite a user. Most incidents come from someone having more power than their job requires.

Client access without WordPress access

Clients get a portal login showing uptime, reports and tickets for their own sites. They never receive a WordPress administrator account, which is better for both of you. The WordPress accounts that do exist on those sites are a separate list, handled in WordPress user management, and what each WordPress role can do is explained in our guide to WordPress user roles.

In practice

WordPress team access and accountability that survives an argument

Every action attributed

Who did what, on which site, at what time, and what the result was. Including sign-ins to client sites without shared passwords, which are recorded as sessions rather than disappearing into wp-admin.

Approval workflows

High-risk actions can require a second person's sign-off. Useful for client tiers where changes need explicit authorization.

Clean offboarding

Revoke a person once and their access disappears everywhere immediately. No password rotation across thirty sites, and the revocation itself is on the record in the audit log. When a whole client relationship ends, our checklist for offboarding a WordPress client also covers the domain, hosting, licenses and Google accounts.

SSO and SCIM

SAML single sign-on and directory provisioning so access follows your identity provider rather than a separate list.

At scale

WordPress site access management across every client

  • No charge for team seats
  • Per-site and per-client permission scoping
  • Time-limited access grants for contractors
  • Client receptionists answering their own site's live chat, with the client deciding what you can see
  • Two-factor authentication enforced across the team
  • Session recording for one-click logins
  • SAML SSO and SCIM provisioning
Answers

Questions about team and client access

What people ask before they turn this on.

No. WPCentrify never charges for team members, and client portal logins never count as team seats either.

Yes. Client users see only their own sites and only the surfaces you enable: uptime, reports, tickets. They never receive a WordPress administrator account.

Revoke them once and access ends everywhere immediately. Their historical actions remain in the audit log, correctly attributed.

Give them their own account with only the access the job needs, never a shared administrator password. In WPCentrify you add them to your workspace with a role covering the areas they work on, they sign in to each site with one click as themselves, and removing them ends their access everywhere.

Yes. WPCentrify permissions are set per area, such as updates, backups, security, content, SEO, enquiries and chat, at levels from viewing to acting. Each person sees only the controls they are allowed to use.

Early access open

Try team and client access on your own sites

Connect a site in under two minutes and see this working against something real. Free during early access.

Free during early access. Keep your data, export any time.