The WordPress roles and permissions question for a web designer has one answer: give them their own Administrator account for the length of the project, then downgrade it to Editor or delete it when the work is done. A designer building or redesigning a site has to install themes and plugins, change settings and edit menus, and only Administrator can do those things. What you should never do is hand over your own login: create a second user in Users, Add New, and keep the account tied to your email as the one that owns the site. That is the whole answer for most projects; the rest of this post covers the cases where Editor is enough, how to set the account up safely, and what to take back afterwards.
What permissions does each WordPress role actually have?
WordPress ships with five roles on a normal site (six on a multisite network). The names sound similar, but the gap between them is large: an Administrator has more than sixty capabilities and a Subscriber has one, read. The WordPress roles and capabilities documentation lists every one; this is the part that matters for a designer.
| Role | Can do | Cannot do | Right for |
|---|---|---|---|
| Administrator | Everything: themes, plugins, settings, menus, users, code, other people’s content | Nothing is off limits | A designer building, redesigning or migrating the site |
| Editor | Create, edit, publish and delete any post or page, moderate comments, manage categories, upload media | Install or change themes and plugins, change settings, add users, edit menus or widgets | A copywriter, or a designer doing content and layout only in a block theme |
| Author | Write, publish and delete their own posts, upload media | Touch pages or anyone else’s posts | A guest blogger |
| Contributor | Write and edit their own posts, which sit in review until an Editor publishes | Upload images or publish | A trial writer |
| Subscriber | Manage their own profile | Anything else | Members or commenters |
The line that catches people is menus and widgets. Those live under Appearance, which is Administrator territory, so an Editor asked to “just update the navigation” cannot. The same is true of the Site Editor in block themes: an Editor can change page content but not the template or header.
Plugins add roles of their own. WooCommerce brings Shop Manager (orders and products, no themes or plugins) and Customer. To change an existing user’s role, open Users, All Users, click Edit under their name, change Role and click Update User; the Bulk Actions menu has “Change role to” for several at once.
When is Editor enough for a designer?
When the job is content and layout inside pages that already exist. Refreshing the copy on your services page, rebuilding a page in Elementor or the block editor, adding a blog post with images, setting the SEO title on each page: an Editor can do all of it. If the brief includes any of the following, it needs Administrator: installing or updating a theme or plugin, page builder settings, header or footer changes, forms, caching or speed work, redirects, Search Console verification, or anything under Settings.
A practical test: ask the designer to list what they need to touch. If the list contains the word “plugin” anywhere, it is an Administrator job. If you are not sure whether you are hiring for a content refresh or a rebuild, custom website design vs a theme explains where that line sits.
How do you add the designer as a user safely?
- In the WordPress dashboard, go to Users, Add New (WordPress.org documents the screen) (on WordPress 6.x the button reads Add New User).
- Enter a username that is not “admin” and the designer’s own work email. Never reuse an email that is already on the site.
- Leave Send User Notification ticked so WordPress emails them a link to set their own password. Ignore the generated password the form shows you; they will replace it.
- Set Role to Administrator (or Editor for content-only work) and click Add New User.
- Ask them to turn on two-factor authentication if the site has a security plugin, and to log in only from their own machine.
If your host offers collaborator access, use it for anything server-side rather than sharing the hosting password. Hostinger, for example, lets you share your hosting plan with another Hostinger account under Profile, Account sharing, with an Admin or Collaborator role; for access to a single site only, create a separate FTP account for that site, which is also what cPanel hosts do.
What should you keep for yourself?
Three things stay with the site owner no matter who is doing the work:
- The original Administrator account, on your email, with a strong password. If a dispute ever happens, whoever holds the admin email holds the site.
- The hosting and domain accounts. A designer needs access to build, not ownership. Grant access; do not transfer the account.
- Your own list of what was added. Ask for the theme and plugin names, any paid licence keys, and where the site is backed up, before the final payment. Where WordPress backups are actually stored explains why that last one matters more than it sounds.
What do you do when the project ends?
Change the designer’s role to Editor if they will keep updating content, or delete the user if not. When you delete, WordPress asks what to do with content they created; choose Attribute all content to your own account so pages and posts are not removed with them. Then check Users once more for anything you do not recognise (some builders create service accounts), and rotate any password the designer was given directly, such as FTP or the host login.
If you keep a designer on for maintenance, Administrator is usually justified, because plugin updates are the job. The safer version is a separate Administrator account that you can suspend by resetting its password, rather than shared credentials. This is how I set up access on every WordPress project I take on, and it is the first thing I check when a client comes to me after a bad experience with a previous developer. The questions to ask before hiring a freelance web designer include exactly this one.
Frequently asked questions
Yes, if they are building, redesigning or installing anything, because only the Administrator role can manage themes, plugins, menus and settings. Give them their own Administrator account rather than your login, and downgrade or delete it when the project ends.
An Editor can create, edit and publish any post or page and manage comments and media. An Administrator can also install themes and plugins, change settings, edit menus and manage users. Editor is enough for content work; a build needs Administrator.
No. Create a separate user for them under Users, Add New, and let WordPress email them a password link. Shared logins cannot be revoked without locking yourself out, and you lose the audit trail of who changed what.
Editor, if they publish directly, or Author if they only write their own posts. Neither role can change the site’s design or plugins.
Go to Users, hover over their name and click Delete. When asked, attribute their content to your own account so nothing is lost. Then reset any hosting or FTP passwords they were given.
Partly. Editor limits them to content. For finer control, a plugin such as Members or User Role Editor lets you build a custom role, for example Editor plus menu access, without granting full Administrator rights.
