WP OctoDocs

Roles and permissions

What each role in a workspace may do.

Every member has one role in the workspace. A role is a fixed set of permissions; there is no per-member customisation.

AdministratorUserClient
See the workspace's sitesallallonly the attached clients'
Site pages: plugins, themes, core, health, security, performance, reports, notes, regressionyesviewview
Update roundsrun, roll back, deleteviewview
Backups, restores, recoveriescreate, restore, deleteviewview
Log in to a siteyesyesno
Add, edit, delete sites; sync; sitemapyesnono
Notes and regression pagescreate, deleteviewview
Clients and packagesmanagenono
Team, invitationsmanagenono
Workspace settings, API keys, billingmanagenono

Two of the three roles are read-only on the platform by construction: user and client hold view permissions and, for the user, the site login; every change — an update round, a backup, a restore, a site's settings — is an administrator's. Selecting many sites in a list gives nobody more than they have on one site.

The difference between the two read-only roles is scope and the login: a user sees the whole fleet and may open a site's admin through the dashboard; a client sees the attached clients' sites and may not. The login was removed from the client role deliberately — it hands out an administrator session on the site itself, which is the opposite of read-only.