Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
  1. Home
  2. Blog
  3. Freelance Developers Need Access to Client Servers and WordPress Admins. How Do We Grant It Safely and Take It Back Afterwards?
Problems We Solve

Freelance Developers Need Access to Client Servers and WordPress Admins. How Do We Grant It Safely and Take It Back Afterwards?

Web design agencies share client server and admin logins with freelance developers and rarely take them back. We build access granted and removed per job.

Updated 3 min readBy SpiderHunts Technologies

Free estimateNo obligation

Get a free estimate

Tell us what you need. A senior engineer reads every enquiry.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →

Quick answer — TL;DR

Web design studios rely on freelance developers, who need access to client hosting, FTP or SSH, WordPress admin and sometimes DNS. That access is often shared as a password in chat and never removed. We build per-job access: named accounts or keys created for each freelancer and job, credentials shared through a password manager, a record of who holds what, and removal when the job ends.

A password in a Slack message

A freelance developer is booked to add a feature to a client site. The project manager sends the SFTP details and the WordPress admin login in a direct message. It is the same admin login the studio uses, created at launch. The freelancer does the job and moves on to other clients.

A year later, the studio realises that several freelancers still have working access to a number of client servers and admin accounts. Nobody knows exactly who. Changing the shared passwords means updating every tool and person that uses them, so it keeps being put off.

Why freelancer access sprawls

  • Shared logins are quicker than creating named accounts for each person.
  • Credentials are sent in chat or email, where they stay forever.
  • Nobody records which freelancer was given access to which client.
  • Jobs end quietly, with no step for removing access.
  • Changing a shared password breaks things for everyone else using it.

Access is granted in a hurry and removed never, because granting has a deadline and removing does not.

Why it matters

A former freelancer with working access is a security risk, even if they would never misuse it, because their own devices and accounts could be compromised. If a client site is hacked, the studio cannot say who had access. Clients increasingly ask agencies how they control access to their systems, and "we share a password" is not an answer that reassures anyone.

The per-job access we build

  1. Each client site's access points are recorded: hosting panel, SFTP or SSH, database, WordPress admin, DNS and any third-party services.
  2. When a freelancer is booked on a job, named access is created for them: their own WordPress user with an appropriate role, their own SSH key or SFTP user where the host supports it.
  3. Any credentials that must be shared are shared through a team password manager, such as 1Password or Bitwarden, in a vault for that job, never in chat.
  4. An access record lists every freelancer, what they hold on which client site, and the job it was for.
  5. When the job is marked complete, a removal checklist is generated, and where platforms allow it, accounts are disabled automatically through APIs or scripts.
  6. Shared legacy logins are replaced over time with named accounts, starting with the sites that have had the most freelancer access.
Access pointOld wayNew way
WordPress adminShared admin loginNamed user per freelancer, removed after the job
SFTP or SSHShared passwordPersonal key or user, revoked after
Hosting panelStudio owner's loginOnly when essential, via password manager
DatabaseShared credentialsTemporary user where the host allows
DNSRarely neededStudio staff only

What access your contracts with clients and freelancers allow is for you and your adviser. The system makes sure that whatever is allowed is recorded and taken back.

The next freelancer booking

A freelancer is booked for a feature on a client site. The system creates their WordPress user and SSH access, and shares the database details through a job vault. When the project manager marks the job complete, the accounts are disabled and the vault is closed. The access record shows exactly who had access, to what, and when it ended.

Is freelancer access under control at your studio?

  • Freelancers are given shared logins to client sites.
  • Credentials are sent in Slack, WhatsApp or email.
  • Nobody can list which freelancers have access to which sites.
  • Access is rarely removed when jobs end.
  • Changing shared passwords has been put off because it breaks things.

FAQ

Frequently asked questions

The questions readers ask us after this guide.

Still have a question?

Ask us directly — a senior engineer will get back to you.

Ask about your project

Does every host support named SFTP or SSH users?

Many do, but not all. Where a host does not, we use the password manager and change the shared credential after the job.

Do freelancers need to use our password manager?

They get access to a vault for the job, which most password managers allow for guests. It is simple for them.

Can it remove access automatically?

For WordPress and many hosts, yes, through APIs or scripts. Others are listed for a person to remove.

Does this cover our own staff too?

Yes. The same record and process work for employees, which helps when someone leaves.

What does the cost depend on?

How many client sites and hosting setups you manage, and how many can be automated.

Keep reading

More on Problems We Solve

Start here

Tell us where your web projects get stuck

Describe how a website project runs at your studio, from signed proposal to launch and the maintenance plan afterwards, and which tools you use, such as Figma, WordPress, Basecamp, ManageWP or Xero. We will tell you what we would build and what we would leave alone, and if a plugin or a setting you already have would solve it, we will say so.

  1. You tell us what you needTwo minutes on the form, or a message on WhatsApp.
  2. A senior engineer reviews itAnd comes back with questions, a realistic range and an honest view on fit.
  3. Free 30-minute scoping callWe talk through scope, options and a realistic estimate — with no obligation.
Free estimateNo obligation

Talk to someone who builds this

Send a short brief and we will come back with an honest view and a realistic range.

Takes under a minute. We never share your details.

  • Free consultation
  • No commitment
  • NDA on request

Prefer to talk? Book a free 30-minute call →