Practical guide

Give the right person the smallest useful hosting role

Last materially reviewed 2026-09-21

Quick answerUse individual access with the permissions needed for the actual job.
What to know

Before inviting, assign access to a real job

Start with the work the person must perform: maintain an application, inspect a server, handle support or review billing. Cloudways provides team permissions that should be checked against those tasks. Avoid granting account-wide authority simply because it is easier to explain. Equally, do not make access so restrictive that routine maintenance requires sharing the owner’s password. The right boundary is the smallest supported role that makes the agreed work practical.

What to know

Keep identities individual

Use a separate identity for each collaborator and preserve a clear record of who was invited and why. Shared credentials make later investigation and offboarding harder. A fictional agency with two maintainers should not use one generic owner login for every action. Do not include passwords or recovery codes in the operating record; document the responsible person and the supported invitation or recovery process instead.

What to know

Verify the scope before accepting the handoff

Verify the selected servers, applications and permissions rather than relying on a friendly role name. Billing access, technical access and ownership are different capabilities. Confirm that the collaborator can reach the intended read-only view or permitted working area without changing unrelated settings as a test. If a needed capability is missing, identify it precisely instead of broadening access to everything or creating another account without a reason.

What to know

Review access when responsibilities change

A client departure, contractor change or internal role shift should trigger a bounded access review. Preserve continuity first, then remove permissions that are no longer needed through the authorized process. Record any service that still depends on the departing person. Team access is an ongoing operating relationship, not a checkbox completed forever at launch, and it should remain understandable to the next person maintaining the site.

Continue when useful

Next: SFTP access or platform access: choose the boundary

File access, billing access and account ownership are separate capabilities.

Open SFTP access or platform access: choose the boundary →

Sources used for this page

These records support the facts and comparisons above. Merchant-controlled records are labelled so you can separate product claims from independent evidence.

  1. Cloudways collaboration and separate application credentials — Merchant documentation · support.cloudways.com · Merchant-controlled · checked 2026-09-21
  2. Cloudways team-member permissions — Merchant documentation · support.cloudways.com · Merchant-controlled · checked 2026-09-21
  3. Cloudways team permission setup — Merchant documentation · support.cloudways.com · Merchant-controlled · checked 2026-09-21