Admin access: who should be able to do what
In the early days of a membership site, it is usually just you. Then you hire a virtual assistant to handle support, a bookkeeper to reconcile payments, a video editor to upload lessons, and a couple of volunteers to keep the forum tidy. The quickest way to get everyone working is to share your admin login, or to make everyone a full administrator. Most owners do exactly that, and most never go back to fix it.
The trouble is that full admin access lets someone export your entire member list, issue refunds, change payment settings and delete content. That is a lot of trust to hand out by default, and it multiplies the damage from one stolen password or one honest mistake. Sorting it out takes an afternoon.
The principle of least privilege, in plain terms
Security professionals call it least privilege: each person gets the access they need to do their job, and nothing more. It is not about distrusting your team. It has practical benefits for everyone:
- Mistakes stay small. A support assistant who cannot delete courses cannot delete one by accident.
- Breaches stay small. If a moderator’s password is stolen, the intruder gets moderation tools, not your payment settings.
- Accountability is clear. When everyone has their own login and a defined role, you can see who changed what.
- People feel less exposed. Many staff are relieved not to have access to things they would never want to be blamed for.
Map roles before you assign permissions
Before touching any settings, list the jobs people actually do. Here is an example for a hypothetical business coaching program with a small team:
- Owner: everything, including billing settings, payment connections and managing other admins.
- Operations assistant: view and edit member accounts, reset passwords, change membership levels, answer support. No access to payment settings or exports.
- Bookkeeper: read-only access to payment and subscription reports. No ability to edit members or content.
- Coaches: create and edit content in their own courses, see progress for their own students.
- Community moderators: approve, edit and remove posts, warn or suspend forum accounts. No access to billing or member contact details beyond what is visible in the community. If you rely on volunteers here, the advice on recruiting community champions and volunteer moderators pairs well with this.
Once you know the roles, look at what your membership platform allows. Many offer several built-in admin roles or let you choose permissions individually. Where the fit is not perfect, choose the option with less access and grant more only when a real need appears.
One person, one login
Shared logins undermine everything else. If three people use the same account, you cannot remove one of them without disrupting the other two, you cannot tell who made a change, and the password inevitably ends up in chat messages and notebooks.
Give every person their own account, protected by a strong, unique password and, wherever possible, a second login step such as a code from an authenticator app. If your platform keeps an activity log, check that it records admin actions and glance at it occasionally.
The permissions to guard most closely
Some powers are far more dangerous than others. Keep these in as few hands as possible, ideally just yours and one trusted deputy:
- Exporting member data. A full export of names and emails is the most valuable thing an intruder can take.
- Payment and payout settings. Changing where money goes, or connecting a different payment account.
- Refunds and billing changes. Useful for support, but worth limiting or reviewing.
- Emailing every member. One mistaken or malicious message to the whole list is hard to undo.
- Logging in as a member. Handy for support, but it lets staff see private messages and details.
- Managing other admins. Anyone who can create admins can give themselves any power.
- Deleting content in bulk. Editing is fine for many roles; mass deletion is not.
Onboarding and offboarding
Access problems usually come from the edges: someone was given too much on day one, or kept access long after they left. A short checklist for each moment keeps things tidy.
When someone joins, give them a named account with the role you mapped, note what you granted and why, and walk them through anything sensitive they can see.
When someone leaves, work through a checklist like this one on their last day:
Disable their membership site admin account. Remove them from the email service, payment processor, hosting, domain registrar, community tools and shared drives. Change any passwords they knew that are shared, such as a social media account. Remove their devices from any two-factor setups. Transfer ownership of files, courses or recurring reports they managed. Confirm that no forwarding rules or connected apps they created are still active.
Review access regularly, beyond the platform
Your membership platform is only one of the places that matter. The same thinking applies to your domain registrar, hosting, email service, payment processor, social accounts and wherever your backups are stored. Every few months, make a simple list of who can get into each one and at what level. Remove anyone who no longer needs access, and question anyone with more than their role requires.
Your next steps
- List everyone who currently has admin access to your site and every related service.
- Write down the roles your team actually performs and what each one needs.
- Replace any shared logins with individual accounts.
- Reduce each person’s permissions to match their role.
- Restrict exports, payment settings and admin management to the smallest possible group.
- Save your offboarding checklist and set a recurring reminder to review access.
0 Comments