# Give someone a role for a limited time

Grant a WordPress role for one hour to 30 days with BetterShield Ultra. It is taken back on its own, the person is emailed, and End now ends it early.

Temporary access gives an account an extra role for a fixed time, then takes it back on its own. Use it for a developer, a contractor or a support visit, so nobody has to remember to remove them afterwards. It is on **BetterShield › Ultra › Temporary access**, part of BetterShield Ultra.

## Grant a role

Under **Grant a role for a while**:

1. In **Who**, search by name, username or email address, and pick the person. **Choose somebody else** starts again.
2. Choose a **Role**. Roles the account already holds are not offered.
3. Choose **For how long**: **1 hour**, **4 hours**, **1 day**, **3 days**, **1 week**, **30 days**, or **Until a date and time**. The last asks for **Ends**, in the site’s time zone, between an hour and 30 days from now.
4. Read the sentence above the button. It names the person, the role and the end, and says what happens then.
5. Press the button, which reads **Grant** followed by the role and the end time.

The person is emailed at once with the role, when it ends, who granted it, and the site’s sign-in address. The email holds no password and no link that signs anybody in. They sign in the way they always do, so every sign-in rule on the site still applies to them.

## What a grant does, and does not do

- **It only adds.** Nothing can be taken away on a timer.
- **At the end, only the added role comes off,** and every session on the account ends. A role someone else added or removed in the meantime stays as they left it.
- **Never the last administrator.** A grant is not taken back if that would leave the site with nobody who can manage it. Its card then says it is still in force, and the activity log records **Temporary access could not be ended**.
- **One grant per account.** Search says when matching accounts already hold one, and leaves them out: end that grant first.

Who may grant what:

- You need permission to change that account’s role, and cannot grant a role with permissions you do not hold yourself.
- You cannot grant temporary access to your own account.
- On multisite, a super admin, or an account that is not a member of the site, cannot be given a grant.

## Grants in force

The **Temporary access** card lists each grant as the person and the role they hold, a countdown such as **Ends in 2 days 4 hours**, and when it ends and who granted it, on the site’s clock with the time zone named. With none, it reads **Nobody holds temporary access.**

| Action | What it does |
|---|---|
| **What they did** | Opens what that account has done since the grant started, from the activity log. |
| **End now** | Asks once more, then takes the role back and ends every session on the account at once, so they are signed out wherever they are. Nothing else about the account changes. |

## Good to know

- Grants and endings appear in the [activity log](/docs/activity-log/) as **Role granted** and **Role removed**.
- With **Ask for my password before an action that removes a protection** on (**Settings › General**), granting and ending ask for your password.
- Granting and ending need a signed-in browser. An application password cannot hand out access.
- If you deactivate Ultra, a grant keeps its added role until Ultra is active again to take it back. End grants first. See [Install Ultra](/docs/install-ultra/).
- On multisite, each site has its own grants.

## Related

- [Activity log](/docs/activity-log/)
- [Sign-in policies](/docs/sign-in-policies/)
- [Login & Access](/docs/login-and-access/)
- [Install Ultra](/docs/install-ultra/)
