Adding a WordPress user, and which role to give them

Everyone who works on the site should have an account of their own. This is not paperwork: it is how you know who did what, and how you take someone’s access away without changing the password for everybody.

Creating the account

1 In the WordPress dashboard, open Users and then Add New.
2 Type the username. Think about it: WordPress will not let you change it later through the interface.
3 Type the e-mail. It has to be unique on the site, and it is where password resets go.
4 Let WordPress generate the password, or use our password generator.
5 Choose the role. That is the decision that matters, and it is explained right below.
6 Tick the notification e-mail so the person can set their own password.

The roles, and what each can do

Role Can Give it to
Administrator Everything, including installing plugins, changing the theme, and creating or deleting users. You, and nobody else without a real need.
Editor Write, edit and publish their own and other people’s content, and manage comments. Whoever owns the content of the site.
Author Write and publish their own posts, and delete their own. People who write regularly and have earned trust.
Contributor Write posts but not publish them. Somebody has to approve. Outside contributors, interns, anything that needs review.
Subscriber Read, and manage their own profile. Nothing else. Anyone who only needs to be registered.
An Administrator can install plugins, and whoever installs plugins can do anything. Handing that role to more people than you need is the shortest path to losing a site. If someone only needs to publish, give them Editor.
Never share one account between people. When something goes wrong, and it will, you need to know who touched it. And when a person leaves, you delete one account instead of changing everybody’s password.

When someone leaves

Changing the password is not enough. Delete the account, or drop it to Subscriber. On deletion WordPress asks what to do with that person’s content: choose attribute it to another user, or you lose it. It is one of the few WordPress prompts where the wrong answer deletes content for good.

Not the same as hosting accounts

WordPress users live inside the site and have nothing to do with cPanel or with My MozOut. They are three separate account systems with three separate passwords. To give someone access to the hosting account, the road is a different one: managing sub-accounts.

And once you have real users, it is worth guarding the door: three steps in order of effect.

Left with no administrator on the site at all? We can create one from the server.

Open a support ticket

SEE ALSO

Password generator

WordPress hosting

Support Policy

RECOMMENDED PRODUCT

WordPress hosting

One-click install, updates handled, and speed that holds up.

See plans
  • 0 Users Found This Useful
Was this answer helpful?