Team members reach every site in your organisation. Delegated access is for everyone else: the designer rebuilding one theme, the agency looking after five client sites, the client who wants to watch their own site. They sign in as themselves and see the sites you chose and nothing else you host.
Sharing sites with someone
Open Organisation → Delegated access and press Invite someone, or open any site and press Share this site at the top of the page — that opens the same form with the site already chosen.
- Enter their email address. If they have no account yet, they get an invitation and create
one when they accept.
- Choose what they can do. The choice applies to every site you tick, and you can change it
for a single site in the list underneath.
- Search for and tick every site they should reach.
- Say why they need access. The reason is kept with the access, so a year from now you can
still tell why this person has your sites.
- Optionally, choose a day their access ends on its own.
The three roles
Viewer — sees the site, its logs and its backups, and changes nothing. Right for a client or an auditor.
Editor — the day-to-day work: deploys, clearing the cache, opening WordPress admin, changing the PHP version and downloading the files.
Manager — everything an editor does, plus backups and restores, HTTPS, the CDN and imports.
Nobody you delegate to can delete a site, move it to another account, see or pay your bills, or invite anyone else. Those stay with the account owner, whatever role you choose.
Seeing who has what
Delegated access lists one row per person: their status (active, or invited and not accepted yet), their role, the sites they hold, when they were invited and accepted, and when they last used the access. A site's own Security section lists everyone who can reach that one site.
Changing someone's access
Press Edit on their row. Tick or untick sites and change roles, then save. The save is applied as one change: sites you untick are taken away, sites you tick are added, and if anything cannot be saved nothing changes at all. Saving someone whose invitation has expired sends it again.
Taking access away
Press Revoke on their row and choose Every site or Only some sites. It takes effect on their next click in the dashboard, the API or the Zinnector® CLI, whatever they are signed in with. Two things it cannot undo: files they already downloaded, and a WordPress admin page they already have open, which stays open until that WordPress session ends.