# Website members

> Share one website with a developer or client: give them their own login with Manage or View only access, reset their password and remove access.

Source: https://zopanel.net/docs/site-members  
Updated: 2026-10-09

The **Members** tab of a website lets the account owner share that one website with other people. Each member signs in to the panel with their own username and password, sees only the websites shared with them, and never needs the owner's password. Use it for a freelancer who deploys code, an agency that maintains a WordPress site, or a client who only wants to watch traffic.

## Who can add members

The **Members** tab appears for the account owner, and for the administrator or reseller who manages the account. Members never see it, so a member cannot invite other people.

Each member login belongs to one hosting account. An account can have up to **50** member logins. One login can be given access to several websites of the same account, with a different access level on each.

## Add a member

1. Open **Websites**, click the website and open the **Members** tab.
2. In the **Add member** card, enter a **Username**: 3–16 characters, lowercase letters and digits, starting with a letter. Names starting with `zp` and system names are reserved.
3. Enter an **Email** (optional) and a **Password** of at least 10 characters.
4. Choose the **Access**: **Manage** or **View only** (see below).
5. Click **Add member**.

Send the panel address, the username and the password to the person by a safe channel. They sign in on the normal panel sign-in page.

### Give an existing member another website

Open the other website's **Members** tab and start typing the username: existing member logins of the account are suggested. When the name matches one, the field shows **Existing team member — just choose the access.** and the email and password fields disappear. Choose the **Access** and click **Add member**.

A username that already belongs to another panel user (a customer, a reseller, or a member of another account) is refused with `username already exists`.

## Access levels

| | **Manage** | **View only** |
| --- | --- | --- |
| See the website's tabs, status, uptime, analytics and logs | Yes | Yes |
| Issue or remove SSL, change domains, PHP version and settings on the **PHP & config** and **Tools** tabs | Yes | No |
| Purge the page cache, block IPs on the **Analytics** tab | Yes | No |
| WordPress tab: one-click login, updates, hardening, staging | Yes | No |
| Deploy, roll back, start/stop/restart an app on the **Deploy** tab | Yes | No |
| See the values of the app's environment variables and the webhook secret | Yes | No (names only, values hidden) |
| Change the app's repository and build settings, deploy key or webhook secret | No | No |
| Suspend, unsuspend or delete the website | No | No |
| Manage the website's members | No | No |
| File Manager, databases, email, DNS, FTP, cron, backups of the account | No | No |

A view-only member sees the banner **You have view-only access to this website.** Any attempt to change something is refused with `permission denied`.

**Note:** members work inside the owner's hosting package. A feature the package leaves out (for example logs or PHP settings) is closed to members too.

## What members see

After signing in, a member's menu has only **Websites**, listing the websites shared with them. They can also open **My account** (to change their password, turn on two-factor authentication and sign out other sessions) and **Tasks**. The account menu shows their role as **Team member**.

Members do not get the dashboard, the account's resource usage, File Manager, databases, email, backups or any other page of the account. A member cannot create websites.

## Change access or reset a password

On the website's **Members** tab, the table lists each member with their email, a **2FA** badge when they use two-factor authentication, and their last sign-in (**Never** if they have not signed in yet).

- **Change access:** pick **Manage** or **View only** in the **Access** column. The change applies on the member's next request.
- **Reset password:** click the key icon. A random password is proposed; edit it if you like, then click **Save**. The member's current sessions are signed out and their API tokens are revoked.

Members change their own password under **My account → Change password**.

## Remove a member

1. On the **Members** tab, click the delete icon on the member's row.
2. Confirm **Remove {name} from this website?**

The member loses access to this website at once. If the member has no other website of the account left, the login itself is deleted and its sessions end. Deleting a website also deletes member logins that are left with no website.

## Security notes

- **One login per person.** Never share the owner's password: members' actions are recorded under their own name in the activity log (`member.grant`, `member.revoke` and the actions they take).
- **Give the least access.** Use **View only** for people who only need to watch traffic or read logs.
- **Ask members to turn on 2FA** in **My account → Two-factor authentication**. If the administrator sets **Require two-factor authentication** to **Everyone**, members must set it up at their next sign-in. See [Two-factor authentication and account security](/docs/two-factor).
- **Suspension stops members.** While the owner's account is suspended, members cannot open its websites.
- **For file access only**, an FTP account limited to the website's folder may fit better than a member. See [FTP and SFTP](/docs/ftp-sftp).

## Troubleshooting

| Message or problem | Cause and fix |
| --- | --- |
| `username already exists` | The name is used by another panel user. Choose a different username. |
| `username must be 3-16 chars, lowercase letters/digits, starting with a letter` | Fix the username format. |
| `password must be 8-128 characters` | Use a longer password. The form itself asks for at least 10 characters. |
| `an account can have at most 50 team members` | Remove member logins that are no longer used. |
| `role must be manage or view` | Only the two access levels exist (sent by a script or an old page). |
| A member says a website is missing | Check that they are listed on that website's **Members** tab and that the owner's account is not suspended. |
| A member gets `permission denied` | They have **View only** access, or the action is reserved for the owner (see the table above). |
| A member cannot sign in after a password reset | They must use the new password; all earlier sessions were ended on purpose. |

## Related

- [Websites and PHP](/docs/hosting)
- [Two-factor authentication and account security](/docs/two-factor)
- [Website statistics](/docs/site-statistics)
- [Node.js and Python apps](/docs/apps-node-python)
- [FTP and SFTP](/docs/ftp-sftp)
- [Guide for hosting customers](/docs/customer-guide)
