wordpress

How to add a user or admin to your WordPress site

Go to Users, then Add New, enter an email and pick a role. See which role fits a web person, a writer or an employee, and how to remove old accounts safely.

Somebody is waiting on a login. It might be a new web person, a writer who needs to post on Monday, or an employee who has been borrowing your password and typing over your name. Before you add admin user to WordPress for any of them, decide what the person will actually do there, because that choice matters more than where the button is. The clicking takes about two minutes: Users, then Add New, then their own email address and a role. The role is what keeps a writer from changing your plugins and keeps a contractor's account from outliving the contract. And the other half of the job is the old accounts already sitting in your list, which can be cleaned up in about ten minutes with your content intact. This walks through both halves in the order you will meet them.

Key Takeaways

Give each person their own login

Create an account with their own username and email address instead of sharing yours, so you can see who changed what and remove one person without touching anyone else.

Pick the role by the work

Contributor drafts without publishing, Author publishes their own posts, Editor manages all posts and pages, and Administrator is for whoever must manage plugins, themes, settings and users.

Keep Administrators few

An Administrator can manage users, plugins, themes, settings and content, so give that role only for the work that needs it and review it when the work ends.

Reassign before you delete

When you delete a user, WordPress asks whether to delete their posts and links or use "Attribute all posts and links to" another user, so the content can stay.

A WordPress login is only WordPress

Hosting, your domain, email and analytics have their own access lists, so check those separately when someone joins or leaves.

Get a new person into WordPress with their own login

Start with the short version, then the part that needs a decision. You must be signed in as an Administrator to add anyone. From your dashboard, go to Users, then Add New. WordPress requires a username and a unique email address, and the form also takes a first name, last name, website, password and role. Pick the role, then click Add New User.

Before you save, check three things. First, the email belongs to the person, since that is where their account details go. Second, the password is strong; WordPress shows strength feedback as you type. Third, the role matches the job. The form has an option labeled "Send Password?" that emails the person their login details, and WordPress renames screens and labels from time to time, so look for the option that sends the account details to the new user.

If the person will also need access to your Google accounts, the steps live in separate posts: adding a user to Google Analytics and Search Console and adding a manager to a Google Business Profile.

A brass key hanging on its own hook beside a blank paper tag on a wooden board.
One key per person means you can take one back without changing every lock.

Choose a role that fits the job and keeps you in control

Job titles do not appear anywhere in WordPress. There is no "web designer" role and no "marketing agency" role. WordPress.org documents six roles: Super Admin, Administrator, Editor, Author, Contributor and Subscriber. On a single site, Administrator is the highest one. Super Admin only matters on a Multisite network, which is a group of sites run from one installation.

WordPress roles and the work each one fits
RoleWhat it can do, per WordPress.orgA good fit for
AdministratorAll administration features on one site, including users, settings, plugins, themes and updatesThe person who runs the site and must change how it works
EditorPublish and manage posts and pages, including other users' content; moderate comments; manage categories; upload filesAn in-house person who runs the whole blog and page content
AuthorPublish and manage their own posts; upload filesA writer you trust to publish without review
ContributorWrite and manage their own posts, but cannot publish themA new or occasional writer whose drafts you review
SubscriberManage only their own profileA member or customer account
Super AdminAll capabilities across a Multisite networkOnly a network owner, if you run one
RoleAdministrator
What it can do, per WordPress.orgAll administration features on one site, including users, settings, plugins, themes and updates
A good fit forThe person who runs the site and must change how it works
RoleEditor
What it can do, per WordPress.orgPublish and manage posts and pages, including other users' content; moderate comments; manage categories; upload files
A good fit forAn in-house person who runs the whole blog and page content
RoleAuthor
What it can do, per WordPress.orgPublish and manage their own posts; upload files
A good fit forA writer you trust to publish without review
RoleContributor
What it can do, per WordPress.orgWrite and manage their own posts, but cannot publish them
A good fit forA new or occasional writer whose drafts you review
RoleSubscriber
What it can do, per WordPress.orgManage only their own profile
A good fit forA member or customer account
RoleSuper Admin
What it can do, per WordPress.orgAll capabilities across a Multisite network
A good fit forOnly a network owner, if you run one

Match the person to the work, and pick the narrowest role that still lets them do it. A writer who sends drafts for you to approve is a Contributor. A writer you trust to publish is an Author. An employee who keeps all your pages and posts up to date is an Editor. An Editor cannot install or manage plugins, so someone who needs that is a different conversation.

What to give a web designer or developer

A web person is the case where Administrator can be the right call. Plugins, themes and settings are Administrator work, and WordPress has no lighter role that covers them. Give that role for the project, with their own account and their own email address, and put a reminder on your calendar to review it when the work ends. If they only need to change page text, Editor is enough. Ask what they will be changing before you choose.

Why a shared login is the wrong shortcut

Handing over your own username and password is faster for about a day. After that you cannot tell who published what, you cannot remove one person without changing the password for everyone, and every person who knows it can do everything you can. WordPress's hardening guidance recommends strong passwords and two-step authentication. Two-step login is usually added through a security plugin or a hosting feature, so ask your host or web person which one your site uses.

A closed laptop beside a small stack of unmarked index cards held by a wooden clothespin.
Decide what the person will do first. The role follows from that.

Remove an old account without losing your content

Deleting a user does not automatically delete everything they wrote. Go to Users, find the account, choose Delete and confirm. WordPress then asks what to do with the posts and links that user owns. You can delete them, or you can choose "Attribute all posts and links to" and pick another user. Reassigning keeps the content and changes only the author name on it.

Pick reassignment whenever the content is still part of your website. Before you confirm, look at what that person owned: posts, pages, media, scheduled content, and any tool that connects to the site through their account. The account you are signed in with cannot delete itself, so you will remove your own account only by signing in as someone else.

If you are not sure whether to delete or just reduce access, change the role instead. Setting a former contractor to Subscriber removes their ability to change anything while leaving every post in place. You can delete the account later, once you have checked what it owned.

A tidy row of wooden drawers with one drawer pulled open and empty on a workshop bench.
Empty the drawer into another one before you remove it.

Clean up your user list in ten minutes

You can do this today without a developer. Open Users, then All Users, and you will see everyone who can sign in. The goal is a short list where every account belongs to a person you can name, in the narrowest role that person needs. The routine below closes the biggest gaps first.

Check every Administrator first

Filter the list to Administrator and write down each username, email and who the person is. Ask of each one whether they still work with you and whether they still need to change plugins, themes or settings. An Administrator who only writes posts should be an Editor or Author. WordPress's role documentation lists what each role can do, so you can check a doubtful account against it. Keep the number of Administrators small, and keep at least one you control.

Deal with the accounts nobody uses

For each account you cannot place, or that belongs to a past contractor, employee or agency, either lower the role or delete it with reassignment, as above. Do not delete the only account that can manage the site. If a name or email in the list looks unfamiliar, treat it as a possible break-in and change your own password too. For a broader review of accounts, plugins and settings, a website security audit covers it.

Look at Application Passwords

An Application Password is not a second login for a person. WordPress describes it as a revocable credential for an application or script that connects to your site, and it is not meant for signing in to the dashboard. If you stopped using a tool that connected to your site, revoke its Application Password from that user's profile.

The ten-minute cleanup

  1. 1

    Minutes 1 to 2

    Open Users, then All Users, and list every Administrator.

  2. 2

    Minutes 3 to 5

    Lower the role of anyone who only writes or edits content.

  3. 3

    Minutes 6 to 8

    Delete accounts nobody uses, choosing "Attribute all posts and links to" when the content stays.

  4. 4

    Minutes 9 to 10

    Revoke Application Passwords for tools you no longer use, and write down who holds each Administrator role.

Know what a WordPress login does not reach

A WordPress role controls what a person can do inside WordPress, and nothing else. Your hosting account, your domain registrar, your business email and your analytics each have their own list of people. When a web person starts, ask which of those they need. When one leaves, check each list separately. A handoff can go wrong right there: the WordPress account is removed while the hosting login still works. The Google side has its own steps in adding a user to Google Analytics and Search Console.

WordPress.com is a different product from a self-hosted WordPress site. WordPress.com publishes its own list of user roles, which includes a Viewer role, and it has its own ownership and plan rules. If your site address ends in wordpress.com, follow WordPress.com's help instead of the steps above.

You can do almost everything on this page yourself. Help makes sense when you are locked out, when nobody knows who the original Administrator was, when accounts appear that nobody can explain, when you run a Multisite network, or when a former vendor still holds hosting or plugin access you cannot remove.

A padlock resting open on a stack of three plain folders beside a pair of brass keys.
The site login is one lock among several. Check the others when someone leaves.

Which WordPress role fits?

Pick an answer to begin.

1. A writer sends drafts and you approve each one before it goes live. Which role fits?

2. You delete a former employee's account. What does WordPress offer for their posts and links?

3. What is an Application Password for?

Frequently Asked Questions About add admin user to wordpress

How do I add an admin user to WordPress?

Sign in as an Administrator, go to Users, then Add New, enter a username and a unique email address, choose Administrator in the role list and click Add New User. Use Administrator only for a person who must manage plugins, themes, settings or users.

What role should I give a WordPress writer?

Use Contributor if the writer should submit drafts for you to review. Use Author if the writer should publish and manage their own posts.

Can I give someone WordPress access without sharing my password?

Yes. Create an individual account for them with their own username and email address. That also lets you remove their access later without changing your own password.

What happens when I delete a WordPress user?

WordPress asks what to do with their posts and links. You can delete them, or choose "Attribute all posts and links to" and give them to another user so the content stays on your site.

Can an Editor install plugins?

No. The standard Editor role can manage posts and pages but does not include installing or managing plugins. That work belongs to an Administrator.

Is WordPress.com the same as a self-hosted WordPress site?

No. WordPress.com has its own roles, including Viewer, and its own ownership and plan rules. Follow WordPress.com's help for a site hosted there.

What This Means for You

Adding a person to WordPress takes two minutes once you know the role. Give each person their own account, choose the narrowest role that lets them do the work, and keep Administrator for the few who must change plugins, themes, settings or users. When someone leaves, lower the role or delete the account with their content reassigned, and check hosting, domain, email and analytics too.

The payoff is a site where you can name every person who can change it. A writer cannot break your plugins, a contractor's login ends when the contract does, and a handoff takes an afternoon instead of a scramble.

If you would rather hand this off, Web Leveling can review your users, roles and connected accounts as part of our website maintenance work, and tell you plainly what can be removed. We work with small and medium businesses across the country and overseas. Contact us about your WordPress user list and we will go through it with you.

Terms

WordPress access words in this post

Tap a term to see what it means.

Administrator. The highest role on a single WordPress site, with access to all administration features including users, settings, plugins, themes and updates.

Role. A named set of permissions that decides what a signed-in person can do on the site.

Contributor. A role that can write and manage their own posts but cannot publish them.

Reassign. Giving a deleted user's posts and links to another user so the content stays on the site.

Application Password. A revocable credential that lets an application or script connect to a site, separate from a person's own login.

Multisite. A WordPress setup where one installation runs a network of sites, with Super Admin as the network-wide role.