Website members
Share one website with a developer or client: give them their own login with Manage or View only access, reset their password and remove access.
The Members tab of a website lets the account owner share that one website with other people. Each member signs in to the panel with their own username and password, sees only the websites shared with them, and never needs the owner's password. Use it for a freelancer who deploys code, an agency that maintains a WordPress site, or a client who only wants to watch traffic.
Who can add members
The Members tab appears for the account owner, and for the administrator or reseller who manages the account. Members never see it, so a member cannot invite other people.
Each member login belongs to one hosting account. An account can have up to 50 member logins. One login can be given access to several websites of the same account, with a different access level on each.
Add a member
- Open Websites, click the website and open the Members tab.
- In the Add member card, enter a Username: 3–16 characters, lowercase letters and digits, starting with a letter. Names starting with
zpand system names are reserved. - Enter an Email (optional) and a Password of at least 10 characters.
- Choose the Access: Manage or View only (see below).
- Click Add member.
Send the panel address, the username and the password to the person by a safe channel. They sign in on the normal panel sign-in page.
Give an existing member another website
Open the other website's Members tab and start typing the username: existing member logins of the account are suggested. When the name matches one, the field shows Existing team member — just choose the access. and the email and password fields disappear. Choose the Access and click Add member.
A username that already belongs to another panel user (a customer, a reseller, or a member of another account) is refused with username already exists.
Access levels
| Manage | View only | |
|---|---|---|
| See the website's tabs, status, uptime, analytics and logs | Yes | Yes |
| Issue or remove SSL, change domains, PHP version and settings on the PHP & config and Tools tabs | Yes | No |
| Purge the page cache, block IPs on the Analytics tab | Yes | No |
| WordPress tab: one-click login, updates, hardening, staging | Yes | No |
| Deploy, roll back, start/stop/restart an app on the Deploy tab | Yes | No |
| See the values of the app's environment variables and the webhook secret | Yes | No (names only, values hidden) |
| Change the app's repository and build settings, deploy key or webhook secret | No | No |
| Suspend, unsuspend or delete the website | No | No |
| Manage the website's members | No | No |
| File Manager, databases, email, DNS, FTP, cron, backups of the account | No | No |
A view-only member sees the banner You have view-only access to this website. Any attempt to change something is refused with permission denied.
Note: members work inside the owner's hosting package. A feature the package leaves out (for example logs or PHP settings) is closed to members too.
What members see
After signing in, a member's menu has only Websites, listing the websites shared with them. They can also open My account (to change their password, turn on two-factor authentication and sign out other sessions) and Tasks. The account menu shows their role as Team member.
Members do not get the dashboard, the account's resource usage, File Manager, databases, email, backups or any other page of the account. A member cannot create websites.
Change access or reset a password
On the website's Members tab, the table lists each member with their email, a 2FA badge when they use two-factor authentication, and their last sign-in (Never if they have not signed in yet).
- Change access: pick Manage or View only in the Access column. The change applies on the member's next request.
- Reset password: click the key icon. A random password is proposed; edit it if you like, then click Save. The member's current sessions are signed out and their API tokens are revoked.
Members change their own password under My account → Change password.
Remove a member
- On the Members tab, click the delete icon on the member's row.
- Confirm Remove {name} from this website?
The member loses access to this website at once. If the member has no other website of the account left, the login itself is deleted and its sessions end. Deleting a website also deletes member logins that are left with no website.
Security notes
- One login per person. Never share the owner's password: members' actions are recorded under their own name in the activity log (
member.grant,member.revokeand the actions they take). - Give the least access. Use View only for people who only need to watch traffic or read logs.
- Ask members to turn on 2FA in My account → Two-factor authentication. If the administrator sets Require two-factor authentication to Everyone, members must set it up at their next sign-in. See Two-factor authentication and account security.
- Suspension stops members. While the owner's account is suspended, members cannot open its websites.
- For file access only, an FTP account limited to the website's folder may fit better than a member. See FTP and SFTP.
Troubleshooting
| Message or problem | Cause and fix |
|---|---|
username already exists |
The name is used by another panel user. Choose a different username. |
username must be 3-16 chars, lowercase letters/digits, starting with a letter |
Fix the username format. |
password must be 8-128 characters |
Use a longer password. The form itself asks for at least 10 characters. |
an account can have at most 50 team members |
Remove member logins that are no longer used. |
role must be manage or view |
Only the two access levels exist (sent by a script or an old page). |
| A member says a website is missing | Check that they are listed on that website's Members tab and that the owner's account is not suspended. |
A member gets permission denied |
They have View only access, or the action is reserved for the owner (see the table above). |
| A member cannot sign in after a password reset | They must use the new password; all earlier sessions were ended on purpose. |
Related
- Websites and PHP
- Two-factor authentication and account security
- Website statistics
- Node.js and Python apps
- FTP and SFTP
- Guide for hosting customers