Step-by-step guide
Last updated: August 2026
Have these ready — it's what onboarding stalls on:
Grant the minimum the work needs. On WordPress, the levels are:
| Access level / role | What it can do |
|---|---|
| Administrator | Full control including plugins, themes and users. |
| Editor | Publish and manage all content. Common for content agencies. |
| Author | Publish and manage their own posts. |
| Contributor | Write posts but not publish. |
| Subscriber | Profile only — not for agencies. |
1–2 minutes to add the user; they set their own password via email.
Open WordPress admin → Users → Add New and grant the access — a few minutes.
Accept and confirm from their side, then start work.
Access is granted when:
The most common problems and how to fix them:
That requires Administrator. If they only manage content, Editor is safer.
Create separate users so actions are attributable and access is removable.
Each agency member gets their own user and password — the shared admin login (which hands everyone full control and hides who changed what) is never needed.
Everything above is why agencies switch to a single link. HandItSafe requests exactly this WordPress access for you — the client approves through WordPress's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.
FAQ
No. Create the agency their own user at the right role.
Editor to manage content; Administrator only if they must manage plugins, themes or users.
Users → delete the agency user. HandItSafe adds one-tap client removal.
Editor to manage content; Administrator only for plugin, theme or site-level work.
Grant Administrator temporarily, then downgrade to Editor — or do the install yourself.
Keep reading
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.