Skip to content
All articles
July 11, 2026·4 min read

WordPress roles and access: what permissions to give a social media manager vs. an accountant

A practical guide for site owners: the minimum role to give each collaborator so you avoid damage or data leaks.

You have a WordPress site and, at some point, you're no longer the only person logging in. You want someone to publish on the blog, someone else to see orders for accounting, maybe a developer to tweak something. Most people's reflex is to hand out "access" without thinking — meaning the Administrator role for everyone. It's the most common mistake and the most expensive one.

WordPress has a roles system built for exactly this: each person gets only what they need to do their job, nothing more. A social media manager has no business in the payment settings, and an accountant doesn't need to be able to delete pages or change the theme. In this article I'll show you, concretely, which role to give each person and why.

The five standard WordPress roles, in brief

WordPress ships with five roles out of the box, from most powerful to most limited:

  • Administrator — can do absolutely anything: change the theme, install plugins, delete pages, add and remove users, touch every setting. It's the "key to the vault."
  • Editor — publishes, edits and deletes any post or page, including other people's, and manages comments. Doesn't touch settings, themes or plugins.
  • Author — writes, publishes and edits only their own posts. Can't see or change what others do.
  • Contributor — writes their own posts but can't publish them; they submit for approval. Can't upload images.
  • Subscriber — only reads and manages their own profile. Useful for restricted-content areas.

The simple rule: give the smallest role that still lets the person do their job. You can always upgrade, but damage already done is hard to undo.

Social media manager: usually Editor, sometimes Author

A social media manager or content creator needs to publish on the blog, add images, maybe update a campaign page. The Editor role covers all of that without giving access to settings, payments or the site's structure.

If you're working with someone new or external and want an extra layer of safety, start with Author: they publish only their own posts and can't touch anyone else's work. And if you want to see every post before it goes live, Contributor is ideal — they write, you approve.

What NOT to do: give them Administrator "so it's quicker." A social media account compromised through phishing becomes, with Administrator rights, an open door to the whole site. With Editor rights, the worst-case damage is one post to delete.

The accountant: the special case with no ready-made role

This is where it gets tricky, because WordPress has no "Accountant" role. An accountant usually wants to see orders, invoices and sales reports — not write posts or touch content.

If you run a WooCommerce store, there's the Shop Manager role, which can view and manage orders and reports. But be careful: Shop Manager is powerful — it can change products, prices and even some users. For an accountant who only needs to pull data, it's often too much.

The healthiest options:

  • A custom, read-only role for orders and reports, built with a role-management plugin.
  • Or, even simpler, you send them periodic exports (CSV/PDF) and give them no account in the site at all.

Often the accountant doesn't even need live access — they need clean data, on time.

Custom roles: when the standard ones don't fit

The reality is that not everyone fits neatly into one of the five roles. This is where role-management plugins (like Members or User Role Editor) come in — you can build a role that matches the person's exact need: "sees orders but can't delete them," "edits only the services pages," "sees reports but not settings."

The principle stays the same; it's called "least privilege": everyone gets strictly the permissions they need, nothing extra. It sounds like bureaucracy, but it saves you from awkward conversations when an account is hacked or a collaborator leaves on bad terms.

A practical tip: write down somewhere who has which role and why. In six months you won't remember why "Andrew" has access to orders — and a clear list is your first line of defense.

Access hygiene: a few rules that matter more than the role

The right role is half the story. The rest is discipline:

  • One account per person. Never a shared "company" login used by three people — you lose track of who did what.
  • Strong passwords and two-factor authentication (2FA), especially for Administrator accounts.
  • When someone leaves, delete or disable their account the same day, not "when I get time."
  • Keep the number of administrators to a minimum. Ideally one or two people you trust.
  • Review the user list periodically and remove accounts you no longer recognize.

At MPO Web Studio, when we deliver a site, we hand it over with roles set up cleanly and we explain exactly who should have what. If you already have a site and aren't sure who has access to what, message us on WhatsApp — we'll run a quick review together, no hassle.

Frequently asked questions

Can I give someone temporary access and then revoke it?+

Yes. You can change a user's role at any time, or disable/delete their account. For short collaborations, the cleanest approach is to create the account, give the minimum role needed, and delete it when the work is done. Don't leave "dormant" accounts active — they're forgotten security risks.

What happens if I accidentally give someone the Administrator role?+

As long as the person is trustworthy and hasn't made changes, you go into Users, change their role to a smaller one, and you're done. The problem is when the account ends up with someone malicious or gets hacked — which is why the Administrator role is handed out very carefully and as rarely as possible.

Does an accountant really need a WordPress account?+

Often no. If all they need are invoices and sales reports, it's safer to send them periodic exports (CSV or PDF) than to create an account in the site. Give live access only if they constantly need fresh data — and then with a limited, read-only role.

How do I know what permissions each role actually has?+

Each standard role has a fixed set of "capabilities" (permissions) officially documented by WordPress. If you want fine control, a role-management plugin shows you exactly what each role can do and lets you tick or remove permissions individually.

Is it risky to use plugins for custom roles?+

No, as long as you pick well-known, updated plugins with good reviews. The real risk doesn't come from the roles plugin, but from overly broad permissions given to people. A serious role-management plugin actually reduces risk, because it lets you grant exactly the right amount.

Free guide

7 mistakes that drive clients away from your website

Leave your email and get the guide right here, instantly. No spam.

By submitting, you agree to the Privacy Policy.
Free · no obligation

Want to see what your business's website could look like?

Message us on WhatsApp and we'll prepare a FREE demo website with your business name. See it first — decide after.

Request a free demo websiteWe reply on WhatsApp within minutes