Manager and two staff reviewing a user list to decide who should have website admin access

Who Should Hold Admin Access to Your Website

Who should have website admin access is a question most Kenyan businesses have never asked, which is why most sites have too many administrators.

A developer from three years ago. A former marketing assistant. An intern who once uploaded photographs. Somebody’s cousin who helped at the start.

Deciding who should have website admin access is a ten minute exercise that closes the most common route into a Kenyan business website.

Why This Matters More Than It Sounds

Administrator access is total, which is why who should have website admin access matters more than it sounds. It can change anything, delete anything, add users, and install software.

Two risks follow. The first is deliberate, and it is rare. The second is far more common: an old account with a weak password, belonging to somebody who left, gets compromised and used as a way in. Nobody notices because nobody was watching that account.

Our post on signs your website has been hacked covers what that looks like afterwards.

Who Should Have Website Admin Access: Least Access That Works

Give everybody the smallest level of access that lets them do their job.

Most content management systems offer several levels below administrator, and almost nobody uses them.

Administrator. Complete control. Should be one or two people at most.

Editor. Can publish and edit all content, but cannot install software or add users. This suits anybody managing the site day to day.

Author or contributor. Can write and publish their own content only. Suitable for anybody adding blog posts.

No account at all. Correct for anybody who has asked twice in two years.

Deciding who should have website admin access usually means moving several people down a level rather than removing them.

Who Genuinely Needs Administrator

The business owner or a director. Somebody with authority must be able to act without depending on anyone.

One named technical person, whether internal or your agency.

That is generally the complete list. Everybody else can work perfectly well at editor level or below.

Crucially, the owner account should exist even where the owner never uses it. The point is that access does not depend entirely on a third party.

Your Developer or Agency

An agency needs administrator access to work, so it belongs on any list of who should have website admin access. That is normal and reasonable.

Three conditions make it safe. The account should be named rather than generic, so activity is attributable. It should belong to the agency rather than an individual who may leave. And it should be reviewed when the relationship ends.

Where a project finishes and no ongoing support is agreed, reduce or remove the access. This is not distrust, it is housekeeping, and a professional agency will expect it.

Shared Logins Are the Real Problem

One account called admin, with a password four people know, is the arrangement we find most often.

It fails in every direction. Nobody can tell who made a change. The password never gets changed when somebody leaves. It cannot be revoked selectively. And it is usually weak, because it has to be memorable to several people.

Give everybody their own named account. It costs nothing and it makes every other control possible.

The Offboarding Step Everybody Forgets

When somebody leaves, who should have website admin access rarely gets revisited.

Add it. On the day somebody leaves, remove or disable their website account, remove them from any hosting or registrar account, change any shared credentials they knew, and check whether notifications were routed to their email address.

That last one causes the domain expiry problem described in our post on what to do when a domain has expired, where renewal reminders go to somebody who left eighteen months ago.

Two Practical Safeguards

Enable two factor authentication on every administrator account. It is the single most effective control available, and it takes minutes.

Review the user list annually. Open it, read every account, and ask whether that person still needs that level. Remove anybody you cannot immediately identify.

Put the review beside your domain renewal check so both happen together.

Frequently Asked Questions

Who should have website admin access in a small business? Typically the owner and one technical person. Everybody else works at editor level or below.

Should my agency have administrator access? Yes while working, through a named account, reviewed when the engagement ends.

Is one shared login acceptable for a small team? No. Individual accounts cost nothing and make everything else possible.

What if I remove somebody’s access by mistake? An administrator can restore it in seconds, which is a good reason to have two.

How often should the list be reviewed? Annually at minimum, and immediately whenever somebody leaves.

What about hosting and registrar accounts? The same principle applies, and those matter more, since they control the domain itself.

Two Administrators, Named Accounts, Annual Review

Who should have website admin access is one of the cheapest security decisions available. Fewer administrators, individual named accounts, two factor authentication, and a list you actually read once a year.

At Africa Web Experts we hand over a properly configured owner account on launch day, so access never depends on us. From KES 65,000, live in seventy two hours.

👉 Request a quote from Africa Web Experts

Similar Posts