Members and roles
Open Members in the sidebar to see who is in your workspace, their role, which sites they can reach, and whether they use two-factor authentication. Pending invitations are listed below the members.
Only the Owner can invite, change roles and remove people. Members whose role allows it can view the list.
Roles
A role is a set of permissions. MagicWP provides these roles:
- Owner: you. Everything, including members, billing details and deleting or transferring sites. Ownership cannot be given away by a role.
- Admin: runs the sites and sees billing and support, but cannot create, delete or transfer sites, or change the plan.
- Developer: works on the sites (WordPress, PHP, caching, backups, database, staging) and support, without billing or domains.
- Billing: sees the plan and invoices and pays invoices. No site access.
- Customer: sees a site and can open WordPress admin with Magic Login. Useful for clients.
The table shows what each role can do by default.
| Permission | Owner | Admin | Developer | Billing | Customer |
|---|---|---|---|---|---|
Create sites (counts against the plan) (sites.create) | ✓ | ||||
See subscription, plan, limits and invoices (billing.view) | ✓ | ✓ | ✓ | ||
Pay invoices with their own card (billing.pay) | ✓ | ✓ | |||
Subscribe, change plan, addons, coupons, cancel (billing.manage) | ✓ | ||||
See the workspace's tickets (support.view) | ✓ | ✓ | ✓ | ||
Open and reply to tickets (support.manage) | ✓ | ✓ | ✓ | ||
See the workspace activity log (activity.view) | ✓ | ✓ | ✓ | ||
See members and pending invitations (members.view) | ✓ | ✓ | |||
See the site, its metrics, activity and settings (site.view) | ✓ | ✓ | ✓ | ✓ | |
Edit the site's label and notes (site.notes) | ✓ | ✓ | ✓ | ||
Restart, fix, maintenance mode, flush caches (site.power) | ✓ | ✓ | ✓ | ||
Reset, restore backups, overwrite from another site or staging (site.restore) | ✓ | ✓ | ✓ | ||
Create and extend staging (site.staging) | ✓ | ✓ | ✓ | ||
Delete the site (site.delete) | ✓ | ||||
Transfer the site out of the workspace (site.transfer) | ✓ | ||||
Magic login as a WordPress administrator (wp.login) | ✓ | ✓ | ✓ | ✓ | |
Install, activate, deactivate and delete plugins and themes (wp.extensions) | ✓ | ✓ | ✓ | ||
Apply updates and change auto-updates (wp.updates) | ✓ | ✓ | ✓ | ||
WordPress settings, debug and salts (wp.settings) | ✓ | ✓ | ✓ | ||
Manage WordPress users (wp.users) | ✓ | ✓ | ✓ | ||
PHP settings, caching and Redis (site.performance) | ✓ | ✓ | ✓ | ||
Domains and Cloudflare (domains.manage) | ✓ | ✓ | |||
Manage redirects (redirects.manage) | ✓ | ✓ | ✓ | ||
Email provider settings (holds API keys) (email.manage) | ✓ | ✓ | ✓ | ||
Create, download, rename and delete backups (backups.manage) | ✓ | ✓ | ✓ | ||
See and change SFTP credentials (credentials.sftp) | ✓ | ✓ | ✓ | ||
See and change database credentials, phpMyAdmin (credentials.database) | ✓ | ✓ | ✓ | ||
Optimize, clean up, change prefix, search-replace (database.manage) | ✓ | ✓ | ✓ |
Some permissions mean full control of a site
Opening WordPress admin, managing WordPress users, and reading the SFTP or database credentials each give a person complete control of that site. Give them only to people you trust with the site itself.
All sites, or only some
When you invite someone or change their access, choose:
- All sites in the workspace: the role applies to every site, including sites created later.
- Only chosen sites: the role applies to the sites you tick, and nothing else in the workspace. A staging copy follows its live site.
With only chosen sites, workspace permissions (billing, support, members, activity, creating sites) are left out, even if the role has them.
Change someone's role
In Members, click Change role next to the person, pick the role and the sites, and save. The change applies on their very next action in the dashboard and to their API tokens. They don't need to sign in again.
Remove someone
Click Remove next to the person and confirm. They lose access to your workspace at once, and their API tokens for it are revoked. Their own workspace is not affected.
Removing someone does not change passwords they have already seen. When the person could see credentials, MagicWP lists the sites where you should rotate them: the SFTP and database passwords, WordPress admin passwords, and email provider keys.
When a member leaves
Members can leave your workspace themselves from My access. Their access and API tokens end the same way, and the next time you open Members you see the same list of sites whose credentials to rotate. Dismiss it once you're done.