A new colleague needs to update the website. The quickest solution seems to be sending them the login everyone else uses. Months later, several people have used the same account and nobody can easily tell who made a particular change. Access is part of website maintenance because the people involved don't stay the same. Staff arrive, contractors finish projects and responsibilities move. The website's accounts should reflect those changes deliberately.
Match access to the actual job
Begin with the task the person needs to perform. Writing an article, managing orders and changing technical settings are different responsibilities. Ask the site administrator to assign an appropriate role and verify that it allows the required work.
Avoid treating the most powerful account as the default answer to every access problem. If an editor can't complete a task, investigate the specific requirement. The solution may be a different workflow or a carefully chosen permission rather than unrestricted access.
Use individual accounts where the system supports them. They make it easier to review access and understand activity. Keep account recovery details under the control of the appropriate person or business, with an agreed process for changes.
Remember the accounts outside WordPress
The website may depend on hosting, a domain registrar, email delivery, analytics, payment services and premium software. A staff member's departure can affect any of those accounts even if their WordPress user is removed correctly.
Maintain an account map showing ownership, operational contacts and the approved access method. Don't place passwords or secret keys in that map. It should direct authorised people to the secure system used to manage them.
Review notification addresses too. An important renewal or security message should not keep going to someone who no longer works with the business. Changing the visible website contact address doesn't necessarily change those account-level settings.
Give temporary access an end point
When a contractor needs access, agree its purpose and review date. The person approving the work should know which systems are involved and how access will be withdrawn once the task is complete.
Keep a record of the work and the accounts created for it. This is especially useful when several suppliers are involved. Without that record, an unfamiliar administrator account can remain on the site simply because nobody knows whether it is still needed.
Don't remove uncertain access blindly. Confirm the account's role and any operational dependencies with the responsible provider, then follow an orderly process. The goal is controlled access without accidentally interrupting a service the business still uses.
Plan departures as a handover
Before an authorised person leaves, transfer the information needed to continue their website responsibilities. Identify content ownership, outstanding tasks and any services tied to their account. The technical administrator should review the consequences of removing or changing the account before acting.
Shared credentials, where they exist, may require a coordinated replacement process. Connected systems can depend on particular access details, so the change should be managed by someone who understands those relationships. Avoid turning an access review into an unplanned outage.
An ongoing support arrangement can help keep the technical side organised. If discussing WordPress maintenance support with BugShield, explain who edits the site and which suppliers need access. Agree who approves account changes and how requests are verified.
Make the review a normal event
Add website access to the business's joining, role-change and leaving processes. Also review it when an agency project ends or a service is replaced. These are natural moments to check whether the existing permissions still make sense.
For a small team, the review may be brief. Confirm the active people, their roles and the business-owned recovery routes. Record questions that need a provider's help rather than leaving them as assumptions.
Good access management should make ordinary work clearer. People know which account to use, the business knows who is authorised and the maintainer has a reliable way to coordinate changes. That is far easier to manage than a shared login whose history nobody can reconstruct.