Users and roles
Understand access levels, add people to your team and manage your own password.
On this page
Each person should have their own account. Your role decides which menus, records and buttons you can use. A missing control may be a permission limit rather than a problem with the site.
What each role can doLink to this section
These are the usual built-in roles. Your agency can customize them, so ask an administrator if your access differs.
| Role | What it does | Tip |
|---|---|---|
| Admin | Manages content, publishing, accounts and site settings. | Give this access only to people responsible for the site. |
| Editor | Reads and updates pages and reusable content, manages media, edits forms and reads submissions where enabled. | Creating pages and publishing are not included by default; your site may grant them separately. |
| SEO Manager | Reads pages and updates their SEO fields and site-wide SEO defaults. | This role does not normally edit page bodies or publish them. |
| Publisher | With the blog enabled, manages and publishes posts, categories, tags and blog settings. | Blog access does not automatically grant page or account management. |
| Author | With the blog enabled, creates and edits their own posts and uses existing categories and tags. | A publisher normally publishes their finished drafts. |
A person can have more than one role. Avoid adding administrator access just to expose one missing button; ask your agency for the access the person actually needs.
Add or invite someoneLink to this section
An administrator manages accounts through Users. If you cannot see Users or Create new, ask an administrator to handle this.
- Open Users and choose the create button beside the list title.
- Enter the person's name and the sign-in details requested on your site. Use their own email address.
- Assign the roles they need and set an initial password that follows the rules shown.
- Save the account. If your site uses invitations instead, follow the process agreed at handover.
Give the new person the Admin address and their sign-in instructions securely. Do not assume that saving an account automatically sends an invitation. Ask your agency whether password-reset emails are configured so the person can set their own password. Confirm that they can sign in and see the right sections.
Change your own passwordLink to this section
- Open Account, the person icon at the top right.
- Choose Change Password.
- Enter the same new password in New Password and Confirm Password.
- Save your changes. If you opened the password fields by mistake, choose Cancel before saving other account details.
Choose a long, unique password and keep it in a password manager. The usual rules require at least eight characters, an uppercase letter and a number. Follow any checklist shown on your site.
Some sites include password tools:
| Tool | What it does | Tip |
|---|---|---|
| Show/hide control | Reveals or hides what you typed. | Hide it when someone else can see your screen. |
| Generate control | Creates a random password, fills both password fields and copies it. | Store the generated password securely before leaving. |
| Rules checklist | Shows whether the password meets the required rules. | Meeting the rules does not guarantee a hard-to-guess password. |
| Strength warning | Flags a password that may be easy to guess. | Choose a stronger password even if saving is allowed. |
Forgotten passwordLink to this section
- On the sign-in screen, choose Forgot password?.
- Enter the detail the form asks for. On the demo this is Username. Your own site may ask for an email address.
- Choose Submit, then follow the reset instructions sent to the email address linked to your account.
If no message arrives, check spam and ask an administrator to confirm your username and account email. Your agency may need to check email delivery. An administrator should help you regain access rather than share another person's account.
Check afterwardsLink to this section
For a new account, check sign-in and access to the intended sections. After a password change, make sure your password manager has the new value. Never put passwords in page content or routine support messages.