How to Add a User to Your Website Safely: WordPress, Shopify, Wix, Squarespace and Webflow

When a developer, employee or SEO agency needs access to your website, sending them your own username and password feels quick. It also removes accountability, exposes the most powerful account and makes access difficult to revoke later.

The safer approach is to invite each person with their own account and grant only the permissions needed for the work. The exact names vary by platform, but the principle stays the same.

This guide starts with WordPress user roles, then explains how to add users or collaborators to Shopify, Wix, Squarespace and Webflow.

Quick Links

Before you invite anybody

Answer five questions first:

  1. What does the person need to do – edit copy, publish pages, install code, manage products or only review work?
  2. Do they need access to one website or the entire account?
  3. Do they need billing, domain or user-management permissions?
  4. How long should access remain active?
  5. Who will review and remove access when the work ends?

Follow the principle of least privilege: give the smallest role that lets the person complete the agreed task. You can increase access later if a genuine requirement appears.

Also make a backup before major development work, require strong unique passwords and enable two-factor authentication wherever the platform supports it.

WordPress user roles explained

A standard WordPress installation includes five site-level roles. WordPress Multisite adds a sixth. WordPress.org’s roles and capabilities documentation describes roles as collections of permitted tasks rather than a simple job-title hierarchy.

Administrator

Administrators can manage virtually every part of a single WordPress site, including users, themes, plugins, settings, pages and posts.

Use this role only when somebody genuinely needs site-wide technical control. A developer may need temporary Administrator access to install a plugin or change a template. A copywriter usually does not.

On many sites, an administrator can add another administrator. That makes the role especially sensitive.

Editor

Editors can publish and manage pages and posts, including content created by other users. They do not normally manage plugins, themes or site settings.

This is often suitable for an experienced content or marketing lead who needs to control the editorial calendar across the website.

Author

Authors can create, publish and manage their own posts. They cannot manage somebody else’s posts or site-wide settings.

Use this for a trusted contributor who publishes their own blog content without needing broader editorial control.

Contributor

Contributors can write and edit their own posts but cannot publish them. An Editor or Administrator must review and publish the work.

This is a useful default for guest writers or new team members while an approval process is in place.

Subscriber

Subscribers can manage their own profile and access content that requires a login. They cannot create or edit normal site content.

Many brochure websites do not need Subscriber accounts unless they have a membership or gated-content feature.

Super Admin

Super Admin exists on WordPress Multisite networks. It controls network-wide settings, sites, themes, plugins and users. It should be limited to the small number of people responsible for the whole network.

Plugins can create additional roles or capabilities, so your dashboard may not match this default list exactly.

How to add a user in WordPress

You need an account with permission to create users.

  1. Sign in to the WordPress dashboard.
  2. Go to Users, then Add New User.
  3. Enter a unique username and the person’s email address.
  4. Add their name if it helps other editors identify them.
  5. Leave the notification option enabled so they receive account details securely.
  6. Choose the lowest suitable role.
  7. Select Add New User.

The official WordPress Add New User guide explains each field. Menu wording can vary slightly between WordPress versions, managed hosts and security plugins.

Do not create a generic account called “agency” for several people. Named accounts make it easier to trace changes and remove one person without disrupting everybody else.

Which WordPress role should an SEO agency have?

There is no universal answer because SEO work ranges from content editing to technical implementation.

  • Contributor can draft articles for approval.
  • Author can publish only their own posts.
  • Editor can improve and publish pages and posts across the site.
  • Administrator may be needed for plugins, redirects, structured data, templates or deeper technical changes.

Ask the agency to explain the tasks that require Administrator access. If the need is temporary, raise the role for the implementation window and reduce it afterwards.

Website access is only one part of an SEO handover. Use separate named invitations for analytics, advertising and search tools too. See our guide to adding a Google Search Console user.

How to change or remove a WordPress user

Go to Users, then All Users. Open the account to change its role, or select Delete to remove it.

When deleting a user who created content, WordPress asks whether to delete their content or attribute it to another user. In most business handovers, reassign the content so published pages and posts remain available.

How to add a user to Shopify

Shopify uses user accounts and roles. Availability and user limits depend on the store plan, so check the current Shopify user-account requirements before promising an internal staff seat.

For an eligible store:

  1. In Shopify admin, go to Settings, then Users.
  2. Choose Add users.
  3. Enter the person’s email address.
  4. Assign one or more roles with the permissions they need.
  5. Send the invitation.

Shopify’s role-based access guidance explains how roles group permissions. Predefined options may include work such as online store editing, customer support, merchandising, marketing or app development.

An agency or freelancer in the Shopify Partner programme can request a collaborator account instead of taking a staff login. This is usually the cleanest route for an external specialist because the store owner approves the requested permissions and can remove the collaborator later.

Avoid granting access to orders, customers, finances or apps when the task does not require it.

How to invite a collaborator to Wix

Wix lets the owner invite collaborators with predefined or custom roles.

  1. Open the site dashboard.
  2. Go to Roles & Permissions.
  3. Select Invite Collaborators.
  4. Enter the person’s email address.
  5. Choose the appropriate role.
  6. Send the invitation.

The current Wix collaborator instructions note that invitations expire after 30 days and that collaborator allowances vary by plan. If an invitation is not accepted, cancel or resend it rather than sharing your owner account.

Wix roles cover different tasks, including website editing, blogging, marketing and billing. Use a custom role when the defaults provide more access than the work requires.

How to invite a contributor to Squarespace

Squarespace calls invited users contributors. Only an owner or administrator can normally invite them.

  1. Open the Permissions & Ownership panel.
  2. Select Invite Contributor.
  3. Enter the contributor’s name and email address.
  4. Enable only the permissions they need.
  5. Select Invite.

The person receives an email asking them to sign in or create their own Squarespace account. The Squarespace contributor guide also allows an owner to change or cancel the invitation before it is accepted.

Squarespace can combine multiple permissions for a tailored role. Administrator access gives the widest control and should be reserved for people managing the site as a whole.

How to invite a user to Webflow

Webflow separates Workspace roles from site roles. This lets an owner control both account-level actions and what a person can do on a particular website.

To invite a Workspace member from an open site:

  1. Select Share in the top bar.
  2. Enter the person’s email address.
  3. Choose a Workspace role, such as Reviewer, Content editor, Marketer or Designer where available.
  4. Review whether the role requires a paid seat.
  5. Select Invite or Pay & invite.

Owners and admins can also manage members in Workspace settings. The current Webflow invitation guide says Reviewer is a free role for viewing and commenting, while roles with editing or design capabilities can require a paid seat.

Webflow also offers a Guest route for eligible agency and freelancer Workspaces. This helps the client retain ownership while limiting the external team to selected sites and permissions.

Do not use a sandbox or comment-only link when somebody needs to publish real changes. Those options are useful for review, not implementation.

A safe agency-access checklist

Give named access

Every person should use their own email address and account. Never send the website owner’s password over email, chat or a project-management ticket.

Keep ownership with the business

The client should own the domain, website subscription, hosting, analytics, Search Console and advertising accounts. Agencies should be invited into those assets, not create an arrangement the client cannot access.

Separate billing from production

A developer who edits templates rarely needs billing permissions. A finance user rarely needs to publish pages. Split these responsibilities unless one trusted owner genuinely performs both.

Record why access was granted

Maintain a simple register containing the person, platform, role, purpose, approval date and planned review date. Review it quarterly and whenever staff or suppliers change.

Use two-factor authentication

Require it for owners, administrators and anyone with customer, payment or publishing access. Store recovery codes securely and make sure the business (not an individual contractor) controls recovery options for the owner account.

Remove access at the end

When a project or employment ends:

  1. remove or disable the named account;
  2. reassign owned content where necessary;
  3. revoke active sessions and API tokens if supported;
  4. remove access to connected analytics, advertising and search tools;
  5. rotate shared secrets that could not be avoided;
  6. confirm that the client retains current backups and ownership.

Give access without giving up control

Good access management lets specialists work while the business keeps control. Create named accounts, match each role to a task and remove access when it is no longer needed.

If you need help after access is in place, talk to our UK based SEO agency. Our SEO team can work with your platform and existing developers while you keep ownership.

Big Fat FAQs

Should I share my website administrator password?
No. Invite each person with a named account. Shared credentials remove accountability, make offboarding harder and expose the owner’s privileges.
Yes. Start with limited access, increase it when the work requires more and reduce or remove it when the task is complete.
You may lack owner permission, have reached the plan’s seat limit or still have an invitation pending. Check the platform’s user settings and plan rules.

No. Editorial work may need an Editor-style role. Administrator access is justified only for technical tasks involving site-wide settings, plugins, code or redirects.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
This field is for validation purposes and should be left unchanged.
This field is hidden when viewing the form
This field is hidden when viewing the form

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Drop files here or
Max. file size: 8 GB, Max. files: 5.