How to Give Your Developer Access to Your Site (Without Losing Control)
When you hire a developer to work on your client’s website, one thing is unavoidable: you have to give them access.
At a minimum, that usually means administrator access to the WordPress site. In many cases, it also includes hosting access, SFTP/FTP credentials, and sometimes database access. Handing over that level of control can feel uncomfortable — especially when client data, uptime, and security are on the line.
The good news?
With the right approach, you can give your developer what they need without putting yourself or your client at risk.
This post walks through how to think about access, the different ways to grant it, and how to choose the right level of involvement for your team.
Before You Grant Access: Key Questions to Ask
Before you create logins or send credentials, take a moment to step back and answer a few important questions.
How much do you trust the developer?
This is the most important question.
If your instinct is “not much,” that’s a signal — and not one you should ignore. A developer working on your client’s site will have deep access. If you don’t trust them, the relationship is going to be stressful for everyone involved.
A solid developer relationship is built on:
- Clear communication
- Defined responsibilities
- Mutual respect
If that foundation isn’t there, it may be time to find a different developer.
What kind of access do they actually need?
Not every project requires full hosting access.
For example:
- Content and layout changes may only require WordPress admin access
- Performance or migration work may require hosting + SFTP
- Debugging critical issues may require database access
Start with what’s necessary, not what’s easiest.
How much control do you want to keep?
Some agencies want full oversight. Others want to hand things off completely. Neither approach is wrong — but you do need to be intentional about it.
How involved do you want to be day-to-day?
The more you restrict access, the more hands-on you’ll need to be. That can be fine — or it can become a bottleneck.
Is there sensitive data in your hosting account?
Many hosting dashboards contain:
- Billing information
- Other client sites
- API keys or credentials
If that’s the case, you’ll want to be more selective about what access you grant.
Always Create a Separate Login
Regardless of the approach you choose, never share your own username and password.
Instead:
- Create a unique WordPress user for the developer
- Create a separate hosting or SFTP user if needed
This ensures:
- You maintain full control
- Access can be revoked instantly
- Activity can be traced if something goes wrong
This is a non-negotiable best practice.
Three Approaches to Giving Developer Access
There isn’t a one-size-fits-all solution. Most agencies fall into one of these three categories.
1. The Hands-Off Approach
This approach works best when:
- You fully trust the developer
- You want minimal involvement
- You value speed and autonomy
What access is granted
- WordPress administrator access
- Hosting account access (or collaborator invite)
- SFTP/SSH access
In this setup, the developer can:
- Troubleshoot issues immediately
- Run updates and backups
- Handle migrations and performance work
Pros
- Fast issue resolution
- Minimal back-and-forth
- Fewer bottlenecks
Cons
- Less visibility into day-to-day changes
- Requires high trust
For long-term partnerships, this is often the most efficient model.
2. The Oversight Approach
This is a common middle ground for agencies.
What access is granted
- WordPress administrator access
- SFTP access only (no full hosting dashboard)
- Database access if needed
Why agencies choose this
- Keeps billing and other client sites private
- Limits the blast radius of mistakes
- Maintains a layer of control
Trade-offs
- You may need to assist with hosting-level changes
- Some fixes may take longer
This approach balances security and efficiency — especially early in a working relationship.
3. The Hands-On Approach
This is the most restrictive option.
What access is granted
- WordPress administrator access only
The developer must request:
- Hosting changes
- File access
- Database updates
When this makes sense
- Short-term or trial projects
- Highly regulated environments
- Very early-stage relationships
Downsides
- Slower issue resolution
- Increased workload for you
- Higher risk during emergencies
If a site goes down and the developer can’t access files directly, every minute counts.
It’s Okay to Change Your Approach Over Time
You don’t have to start with full access.
Many agencies:
- Begin with the hands-on approach
- Move to oversight
- Eventually shift to hands-off
Trust is built through:
- Consistent communication
- Reliable work
- Clear expectations
Your access model should evolve with the relationship.
One Thing That’s Not Optional: Admin Access
No matter which approach you choose, your developer needs WordPress admin access.
If you aren’t comfortable with that:
- They won’t be able to do their job properly
- You’ll both end up frustrated
- The project will move slower and cost more
Admin access is the baseline for effective WordPress development.
Best Practices for Secure Collaboration
To keep everything running smoothly:
- Use strong, unique passwords
- Enable two-factor authentication where possible
- Remove access immediately when a project ends
- Document who has access and why
- Review user roles periodically
These small steps go a long way toward protecting your clients and your reputation.
Final Thoughts
Giving a developer access to your site isn’t about giving up control — it’s about creating a workflow that works.
The right setup:
- Protects your clients
- Supports your developer
- Reduces friction
- Makes emergencies easier to handle
If you can’t trust someone with admin access, they probably shouldn’t be working on your client’s site.
Need Help Setting This Up the Right Way?
If you’re unsure how to give access safely — or you want a developer who understands agency workflows and respects boundaries — we can help.
Contact Graybill Codeworks to talk through the best setup for your team and your clients.
