Autopilotby Internet Solutions

WordPress User Roles for a Blog Team: Who Gets What Access

October 9, 20268 min readSEO & content marketing
WordPress User Roles for a Blog Team: Who Gets What Access

Short answer: WordPress has five standard roles: Administrator, Editor, Author, Contributor and Subscriber. For a blog team, give Administrator only to one or two people who manage the site, Editor to whoever runs the content, Author to trusted writers who publish their own posts, and Contributor to guest or new writers whose drafts need review. Give tools and integrations their own user with the lowest role that works and an application password, and remove accounts as soon as someone leaves.

As a blog grows, more people need access: writers, an editor, a freelance designer, an agency, an SEO consultant, a publishing tool. The easy route is to make everyone an administrator. It is also the riskiest. Every admin account can install plugins, change settings and delete content, and every extra admin is another password that can be stolen. WordPress roles exist to avoid exactly this. Here is how to use them for a typical business blog.

The five standard roles in plain terms

WordPress defines roles as bundles of capabilities. The official roles and capabilities documentation lists every permission in detail. In practice, the roles break down like this:

Role What they can do Typical person
Administrator Everything: plugins, themes, settings, users, all content Site owner, developer
Editor Publish, edit and delete any post or page, moderate comments, manage categories Content lead, managing editor
Author Write, publish, edit and delete their own posts, upload images Regular trusted writer
Contributor Write and edit their own drafts, but not publish or upload files Guest writer, new freelancer
Subscriber Manage their own profile and read Members, commenters

On a multisite network there is also a Super Admin, who manages the whole network. Most single business blogs do not need it.

Keep administrators to a minimum

An administrator can do anything, including things that break the site or open security holes: installing a plugin from an unknown source, changing the site address, adding new admins, editing theme files. For that reason, the number of admin accounts should be as small as possible.

When a developer or agency needs temporary admin access for a specific job, create an account for them, and remove it or downgrade it when the job is done.

Roles also protect you from honest mistakes, not only from attackers. A writer who accidentally clicks “Update” on a plugin, or a freelancer who changes the permalink settings while looking for something else, can take a site offline or break every URL. Limiting who can reach those screens is the simplest way to make sure such accidents cannot happen in the first place.

Editors run the content

The Editor role is the right choice for whoever is responsible for what the blog publishes. An editor can review and publish other people’s drafts, fix any post, manage categories and tags and moderate comments. What they cannot do is install plugins, change themes or manage users, which keeps the technical side of the site out of reach.

This is usually enough for a content lead or a marketing manager. If they occasionally need something only an admin can do, such as a new plugin for tables, they ask the admin. That small friction is a useful safety check.

Authors and contributors for writers

The difference between Author and Contributor is one important permission: publishing.

The inability to upload images can be inconvenient for contributors. Common solutions are to have the editor add images during review, or to promote reliable writers to Author once they have earned trust. Avoid giving everyone Editor just to solve the image problem; editors can change and delete everyone’s posts.

Contributors are also a good starting role for anyone new to your blog’s style. Reviewing their first few drafts lets the editor give feedback on tone, structure and internal links before anything goes live, and promotion to Author becomes a clear sign of trust once the work is consistently ready to publish without changes.

Agencies, freelancers and consultants

External people need access for different reasons, and the role should match the job, not the size of the company:

Every person should have their own account. Shared logins make it impossible to see who changed what, and they cannot be removed for one person without affecting everyone.

Accounts for tools and integrations

Publishing tools, social sharing services, backup services and other integrations often connect to WordPress through its REST API. They need an account, but not necessarily a powerful one.

  1. Create a dedicated user for each tool. Name it after the tool so it is obvious in the user list and in post history.
  2. Give it the lowest role that works. A tool that publishes posts usually needs Author or Editor. It rarely needs Administrator.
  3. Use an application password. WordPress can generate application passwords for a user in their profile. They work only for API access, not for logging into the dashboard, and can be revoked individually without changing the user’s main password.
  4. Revoke when you stop using the tool. Delete the application password or the whole user.

Connections that use a dedicated user and an application password are easier to audit and safer to remove than ones that use the owner’s account.

Custom roles and when you need them

Sometimes the standard roles do not fit. You might want writers who can upload images but not publish, or an SEO role that can edit meta fields but not content. Role management plugins let you create custom roles or adjust capabilities.

Use this sparingly. Every customisation is something to remember and document, and a mistake can give someone more access than intended. For most small teams, the five standard roles plus a clear review process are enough. If you do customise, write down what each custom role can do and why it exists.

Whatever roles you choose, keep a short written note of who has which account and why. A shared document with names, roles, the date access was given and the reason is enough. It makes reviews quick, and it helps the next person who takes over the site understand what each account is for instead of being afraid to remove anything.

Reviewing and cleaning up accounts

User lists grow quietly. Former employees, old freelancers, test accounts and long-forgotten integrations stay active for years. A short review a few times a year keeps the list under control:

Reassigning content when someone leaves also affects bylines. If author archives and bios are visible on your blog, decide whether posts should stay under the original writer’s name, which is usually more honest, or move to a general team account.

A simple setup for a small blog team

Putting it together, a typical small business blog might look like this:

It takes a few minutes to set up and saves a lot of trouble later.

How AI Blog Autopilot fits in

AI Blog Autopilot connects to WordPress in one click: you click Connect and approve it in WordPress, and it publishes articles with FAQ, tags and SEO meta at the hour you choose. Approval of articles before publishing can be switched on at any time, and agency plans add team and client approval. See the pricing page for details.

Related reading

The bottom line

WordPress roles let you give everyone the access they need and nothing more. Keep administrators to one or two people with strong logins, let an editor run the content, use Author for trusted writers and Contributor for drafts that need review, and give each tool its own low-privilege user with an application password. Review the user list a few times a year, reassign content when people leave, and remove access you no longer need.

FAQ

What WordPress role should a blog writer have?

Use Author for trusted writers who publish their own posts, and Contributor for guest or new writers whose drafts need review before publishing. Editors are for people who manage everyone’s content.

How many administrators should a WordPress site have?

As few as possible, usually one or two. Administrators can install plugins, change settings and manage users, so each extra admin account increases risk.

What role does a publishing tool need in WordPress?

Usually Author or Editor, depending on what it does. Create a dedicated user for the tool and connect it with an application password, which can be revoked without affecting other logins.

What happens to posts when I delete a WordPress user?

WordPress asks whether to delete their content or attribute it to another user. Choosing another user keeps the posts on the site. Deleting the content removes their posts too.

Can a contributor upload images in WordPress?

Not by default. Contributors can write drafts but cannot upload media. An editor can add images during review, or you can promote trusted writers to Author.

#Agencies#Editorial workflow#Publishing setup#WordPress
Your blog could write itself too.Your blog writes itself. Your socials post themselves.
Start free

More from the blog

All articles →
Internet Solutions

More from our team

Built by Internet Solutions. Try the rest of our products — each one saves you time in a different way.

internet-solutions.net ↗
AI Blog Autopilot
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.