Security

WordPress User Roles Explained: Who Should Have Which Access

WordPress user roles explained simply: administrator, editor, author, contributor, subscriber and shop manager, plus how to give staff, agencies and freelancers the right access safely.

WordPress User Roles Explained: Who Should Have Which Access
On this page
  1. The default WordPress roles
  2. Best practices
  3. Working with developers and agencies
  4. Review users regularly
Key takeaways
  • Give each person the lowest role they need; keep administrators to a minimum.
  • Use individual accounts, strong passwords and 2FA, and never share logins.
  • Remove access when staff or agencies finish, and review users regularly.

Giving everyone administrator access is one of the most common, and riskiest, habits on business WordPress sites. User roles let you give each person exactly the access they need, and no more.

The default WordPress roles

RoleWhat they can doTypical user
AdministratorEverything: settings, plugins, themes, usersBusiness owner, trusted developer
EditorPublish and edit all content, including others'Marketing manager, content lead
AuthorWrite and publish their own postsRegular in-house writer
ContributorWrite posts but can't publishGuest writer, intern
SubscriberManage their own profile onlyRegistered site members

WooCommerce adds Shop Manager (manages products and orders without full site settings) and Customer roles.

Best practices

  • Least privilege: give the lowest role that lets someone do their job
  • Few administrators: usually the owner plus one trusted developer
  • Individual accounts: never share one login between people
  • Strong passwords and 2FA for every account with editing access
  • Remove access promptly when staff, agencies or freelancers finish

Working with developers and agencies

  • Create a separate account for them, never share yours
  • Give administrator access only for the work period if they need it
  • Keep ownership of hosting, domain and the main admin account yourself
  • Change or remove access when the project ends

To see what each account actually does once it has access, add an activity log; see WordPress activity logs explained.

Review users regularly

Check Users in your dashboard every month or two. Unknown administrator accounts can be a sign of a hack; see signs your WordPress site is hacked.

User reviews are part of the WordPress security checklist and every maintenance plan.

Need help with your website?

I'm Sameer, a freelance WordPress developer building fast, SEO-friendly websites since 2020. Tell me what you need and I'll reply with a plan and a fixed quote within 24 hours.

Found this useful? Share it:
Contact

Let's build your next website

Available for freelance projects, agency white-label work and long-term maintenance. Feel free to pass this along to your team or company.

Your details are emailed to me, then WhatsApp opens so we can chat right away.

Chat now