Step-by-step guide

How to give agency access to WordPress

Last updated: August 2026

How to give agency access to WordPress: use WordPress user roles — the agency is added as an Editor or Administrator user with their own login. Open WordPress admin → Users → Add New, add the agency, choose the access level, and confirm. You never share a password and can remove access anytime.

Before you start

Have these ready — it's what onboarding stalls on:

Step-by-step

  1. In WordPress admin, go to Users → Add New.
  2. Enter the agency member's email and a username.
  3. Choose the role (Editor, Administrator).
  4. Create the user.
  5. They set their own password via email — no shared admin login.
Where 90% of onboardings fail: One shared admin login hands full control to everyone and leaves no trace of who edited what.

Which access level to grant

Grant the minimum the work needs. On WordPress, the levels are:

Access level / roleWhat it can do
AdministratorFull control including plugins, themes and users.
EditorPublish and manage all content. Common for content agencies.
AuthorPublish and manage their own posts.
ContributorWrite posts but not publish.
SubscriberProfile only — not for agencies.

How long it takes, and who does what

1–2 minutes to add the user; they set their own password via email.

What you (the client) do

Open WordPress admin → Users → Add New and grant the access — a few minutes.

What the agency does

Accept and confirm from their side, then start work.

How to check it worked

Access is granted when:

If it doesn't work

The most common problems and how to fix them:

Agency needs plugin/theme access

That requires Administrator. If they only manage content, Editor is safer.

Shared admin password used

Create separate users so actions are attributable and access is removable.

Why you don't share a password

Each agency member gets their own user and password — the shared admin login (which hands everyone full control and hides who changed what) is never needed.

The faster way: one link

Everything above is why agencies switch to a single link. HandItSafe requests exactly this WordPress access for you — the client approves through WordPress's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.

FAQ

Giving WordPress access — questions

Do I share my WordPress admin password?

No. Create the agency their own user at the right role.

Editor vs Administrator for an agency?

Editor to manage content; Administrator only if they must manage plugins, themes or users.

How do I remove WordPress access?

Users → delete the agency user. HandItSafe adds one-tap client removal.

Editor or Administrator for an agency?

Editor to manage content; Administrator only for plugin, theme or site-level work.

What if the agency needs to install a plugin once?

Grant Administrator temporarily, then downgrade to Editor — or do the install yourself.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.