BetterShield

Give someone a role for a limited time

3 min read

Grant a WordPress role for one hour to 30 days with BetterShield Ultra. It is taken back on its own, the person is emailed, and End now ends it early.

Temporary access gives an account an extra role for a fixed time, then takes it back on its own. Use it for a developer, a contractor or a support visit, so nobody has to remember to remove them afterwards. It is on BetterShield › Ultra › Temporary access, part of BetterShield Ultra.

Grant a role

Under Grant a role for a while:

  1. In Who, search by name, username or email address, and pick the person. Choose somebody else starts again.
  2. Choose a Role. Roles the account already holds are not offered.
  3. Choose For how long: 1 hour, 4 hours, 1 day, 3 days, 1 week, 30 days, or Until a date and time. The last asks for Ends, in the site’s time zone, between an hour and 30 days from now.
  4. Read the sentence above the button. It names the person, the role and the end, and says what happens then.
  5. Press the button, which reads Grant followed by the role and the end time.

The person is emailed at once with the role, when it ends, who granted it, and the site’s sign-in address. The email holds no password and no link that signs anybody in. They sign in the way they always do, so every sign-in rule on the site still applies to them.

What a grant does, and does not do

  • It only adds. Nothing can be taken away on a timer.
  • At the end, only the added role comes off, and every session on the account ends. A role someone else added or removed in the meantime stays as they left it.
  • Never the last administrator. A grant is not taken back if that would leave the site with nobody who can manage it. Its card then says it is still in force, and the activity log records Temporary access could not be ended.
  • One grant per account. Search says when matching accounts already hold one, and leaves them out: end that grant first.

Who may grant what:

  • You need permission to change that account’s role, and cannot grant a role with permissions you do not hold yourself.
  • You cannot grant temporary access to your own account.
  • On multisite, a super admin, or an account that is not a member of the site, cannot be given a grant.

Grants in force

The Temporary access card lists each grant as the person and the role they hold, a countdown such as Ends in 2 days 4 hours, and when it ends and who granted it, on the site’s clock with the time zone named. With none, it reads Nobody holds temporary access.

ActionWhat it does
What they didOpens what that account has done since the grant started, from the activity log.
End nowAsks once more, then takes the role back and ends every session on the account at once, so they are signed out wherever they are. Nothing else about the account changes.

Good to know

  • Grants and endings appear in the activity log as Role granted and Role removed.
  • With Ask for my password before an action that removes a protection on (Settings › General), granting and ending ask for your password.
  • Granting and ending need a signed-in browser. An application password cannot hand out access.
  • If you deactivate Ultra, a grant keeps its added role until Ultra is active again to take it back. End grants first. See Install Ultra.
  • On multisite, each site has its own grants.

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield