WordPress user roles permissions are a built-in access control system that determines exactly what each person on your team can see, edit, and change on your website. If you are building or managing a WordPress site — the platform behind most South African business websites — understanding how roles work is the difference between a smoothly run team and a security incident waiting to happen. For a broader look at choosing the right platform, see our guide to website builders in South Africa.
South African businesses have an additional reason to get this right. Under POPIA section 19, every responsible party — any business that collects or processes personal information — must take "appropriate, reasonable technical and organisational measures" to prevent unlawful access to that information. A WordPress site that captures contact forms, enquiries, or customer orders holds personal information. Controlling who can access, export, or modify that data is not optional; it is a compliance obligation. The most practical implementation is getting your WordPress user roles permissions right from day one.
Quick Answer
WordPress user roles permissions are assigned access levels that control what each user can do on your site. WordPress has six default roles — Super Admin, Administrator, Editor, Author, Contributor, and Subscriber — each granting a specific set of capabilities. WooCommerce adds Shop Manager and Customer roles.
Best practice is the Principle of Least Privilege: give every team member the minimum role that lets them do their job, and review access quarterly. This matters doubly in South Africa, where POPIA section 19 requires reasonable technical measures to prevent unauthorised access to personal information your site processes.
In This Guide
Not sure how your site is set up?
Send us your WordPress URL and we will review your user configuration — free consultation, no obligation.
Get a Free Site ReviewWhat WordPress User Roles Permissions Control
A WordPress user role is a named bundle of capabilities — specific actions a user account is permitted to perform. Understanding your site's WordPress user roles and capabilities is the foundation of safe access control: WordPress separates permissions into granular tasks (publish_posts, manage_options, install_plugins, edit_users, and so on), groups them into roles, and assigns the whole bundle to each user account. What a user inherits from their role is all they can do — nothing more.
This matters because capabilities have very different risk profiles. The ability to write a draft post is low-risk. The ability to install a plugin or export the entire user database is high-risk. A well-structured role assignment means a compromised or careless account can only do damage proportional to its role, not yours.
Single site vs Multisite: On a standard single-site WordPress install, roles are site-specific and the Administrator is the highest role. On a WordPress Multisite network, the Super Admin role operates across all sites in the network — single-site operators will not encounter it in normal use.
The Six Default WordPress Roles at a Glance
WordPress ships with six pre-defined roles, documented on the official WordPress Roles and Capabilities page (last updated September 2026). The table below summarises what each role can and cannot do, and where it fits in a typical South African business team.
| Role | Key Capabilities | Cannot Do | SA Business Use Case |
|---|---|---|---|
| Administrator | Everything: install plugins/themes, manage users, edit settings, export data, publish all content | Network-wide settings (single-site limitation) | Site owner; lead developer (own account) |
| Editor | Publish and manage all posts and pages, moderate comments, manage categories, upload media | Install plugins/themes, manage users, change site settings | Marketing manager, content lead, agency content team |
| Author | Publish and manage own posts, upload media, edit own published posts | Edit others' posts, manage categories, access settings | In-house copywriter, staff blogger who publishes directly |
| Contributor | Write and manage own draft posts (cannot publish or upload media) | Publish posts, upload images, edit others' content | Freelance writer submitting drafts for review |
| Subscriber | Read site content, manage own profile only | Create or edit any content; access dashboard beyond profile | Registered member, newsletter subscriber, blog commenter requiring login |
| Super Admin | All capabilities across all sites in a Multisite network | N/A — top level | Multisite networks only (e.g. franchise group with separate sub-sites per branch) |
Key distinction — Author vs Contributor: An Author can publish immediately. A Contributor submits drafts that an Editor or Administrator must approve and publish. If you want a freelance writer's work reviewed before it goes live, Contributor is the correct role — Author gives them a live publish button with no gate.
WooCommerce Roles: Shop Manager and Customer
Installing WooCommerce adds two additional roles to your WordPress site automatically, documented by WooCommerce's own role and security guide. These roles are specifically designed for the demands of running an online store.
Shop Manager is the operational role for staff who run the store day-to-day. A Shop Manager can manage orders, issue refunds, create and edit products, view reports, and access customer orders and account information. They also retain full WordPress editor capabilities, meaning they can manage all content on the site.
What they cannot do is install or edit plugins and themes, modify user roles, or access the broader WordPress settings panel. This is the correct role for an operations manager, fulfilment staff member, or store administrator who needs full commercial access without the ability to change the site's technical configuration.
Customer is assigned automatically when a shopper creates an account on your WooCommerce store. Customers can edit their own account details and view their current and past orders. They have no dashboard access beyond their own account area. If your site allows guest checkout, most buyers will not end up with a Customer account at all.
Important: A Shop Manager can view customer orders and personal details — names, addresses, contact numbers. This is personal information under POPIA. Apply the same access-minimisation logic here as anywhere else: only assign the Shop Manager role to staff who genuinely need it for their work.
Which Role Should Each Team Member Have?
The right approach to WordPress role management is the Principle of Least Privilege: every user gets the minimum capability set their job actually requires. The table below maps common SA business scenarios to the correct role, with the reasoning behind each assignment.
| Team Member / Scenario | Correct Role | Why |
|---|---|---|
| Business owner / site owner | Administrator | Needs full control. Should be the primary admin account — ideally the only permanent one. |
| Freelance developer / web agency (active project) | Administrator (separate account) | Needs plugin, theme, and settings access. Never share the owner's account — create a named account for the contractor so you can remove it when the project ends without losing your own access. |
| Freelance developer / web agency (project complete) | Remove account or downgrade to Subscriber | Ongoing admin access after a project closes is one of the most common unnecessary risks on SA business sites. Revoke or delete promptly. |
| Marketing manager / content lead | Editor | Needs to manage all published content, approve drafts, update pages. Does not need plugin access or user management. |
| In-house copywriter who publishes own posts | Author | Publishes own work directly. Cannot edit or delete others' posts, so cannot inadvertently affect pages they should not touch. |
| Freelance writer submitting drafts | Contributor | Cannot publish — all content goes to an approval queue. Cannot upload media, which limits exposure if the account is misused. |
| Virtual assistant (VA) — content only | Author or Contributor | Author if the VA publishes directly; Contributor if an internal team member reviews first. Do not give VA accounts Editor access unless they are managing all site content. |
| WooCommerce store operations staff | Shop Manager | Manages orders, products, and refunds without access to WordPress settings or plugin management. |
| Bookkeeper reviewing WooCommerce reports only | Shop Manager (or custom role) | If they only need report access and not product/order management, consider a custom role with reduced capabilities. |
| Newsletter subscriber / registered member | Subscriber | Read-only access. Correct default for membership sites, gated content, or comment systems that require login. |
Practical rule for SA businesses managing multiple contractors: Create a named account for every contractor or agency — never use a shared login. When a contract ends, remove the account entirely rather than leaving it dormant. A dormant admin account is an open door; removing it takes under a minute.
How to Assign and Change Roles in WordPress
Changing a user's WordPress role requires Administrator access. The capability to do so is called promote_users, which is restricted to Administrators (and Super Admins on Multisite). Here is how to do it:
- Go to Users → All Users in your WordPress admin dashboard.
- Click the user's name to open their profile, or hover over their name to see the quick-edit options.
- Find the "Role" dropdown in the user profile. Select the appropriate role from the list.
- Click "Update User" to save the change.
To invite a new user: go to Users → Add New User, enter a unique username and the new user's email address, set their role, and click "Add New User." WordPress sends them an email with a link to set their password.
To change the default role assigned to all new registrations, go to Settings → General and find the "New User Default Role" dropdown. For most business sites, Subscriber is the safest default.
Good: You move a web developer's account from Administrator to Subscriber (or delete it entirely) on the day their project deliverable is accepted. You note the change in your internal handover log alongside the date.
Bad: You add an agency as an Administrator during the redesign and never revoke access after go-live. Six months later, the agency's own team changes and someone you have never met still has full admin access to your site and every contact form submission in it.
Extending Roles with Plugins
The default WordPress roles cover most business needs, but some situations call for a custom configuration — a bookkeeper who should see WooCommerce reports but not manage products, or a photographer who should upload to the media library without being a full Author. Custom roles are the answer.
WordPress provides PHP functions (add_role() and add_cap()) for developers to create and modify roles programmatically. If you are not managing custom code, two plugins handle this with a graphical interface:
- User Role Editor — the most widely installed option, with 700,000+ active installations across the WordPress ecosystem. It gives you a checkbox grid of every capability for every role, lets you create and clone roles, and can assign multiple roles to one user account. The free version covers most business needs; a Pro tier adds admin menu restrictions and front-end visibility controls.
- Members (now maintained by the MemberPress team) — 300,000+ active installations. Beyond role editing, it lets you restrict specific posts, pages, or sections to chosen roles, which is useful if you run a subscription model or gated resource library.
Before making any WordPress user role configuration changes on a live site, test on a staging environment — especially if you are removing capabilities from an existing role, since that affects every user in that role immediately. Your WordPress hosting setup should include a staging option; most reputable SA hosts provide one.
Need the right role structure for your team from day one?
Tell us about your team and site setup and we will map the correct roles and configure them for you as part of a new build or site audit.
Discuss Your Site SetupWhy WordPress Role Management Matters Under POPIA
Configuring WordPress user roles permissions correctly is a direct implementation of POPIA's security safeguard requirement. Under POPIA section 19, every responsible party — any South African business that processes personal information — must take "appropriate, reasonable technical and organisational measures to prevent loss of, damage to or unauthorised destruction of personal information, and unlawful access to or processing of personal information."
A WordPress site that captures contact form submissions, customer orders, enquiry data, or newsletter sign-ups is processing personal information. WordPress user access control — which staff account holds which WordPress user permissions — is a technical safeguard under this requirement.
A well-structured role assignment limits which staff can view, export, or delete that data. An over-privileged configuration — VAs with Editor access who can export all comments and form entries, or agency contractors who were never removed — is an identifiable gap in your technical safeguards.
This does not mean you need a legal opinion to set up WordPress user roles. It means the security best practice (minimum access per person, quarterly reviews, immediate revocation on role change) aligns exactly with what POPIA expects from a responsible party taking reasonable steps. Keep a log of who has what role and when changes are made — a WordPress activity log plugin automates this and creates the kind of paper trail that demonstrates accountability.
POPIA compliance checklist for WordPress user roles permissions: (1) No dormant admin accounts — remove access the day a contractor relationship ends. (2) Quarterly review — check who has each role and whether it still matches their job. (3) Minimum access — assign the lowest role that covers the user's actual tasks. (4) Audit trail — use an activity log plugin to record login events and role changes. These four steps are your reasonable technical safeguards under section 19.
Why South African Businesses Choose Growth Pulse Media for WordPress Web Design
Growth Pulse Media builds and manages WordPress sites for South African businesses from our Johannesburg base. Our team has built and operated a large SA ecommerce business before moving into agency work — which means we have been on the operator side of the decisions this post covers. When we configure a WordPress site, user roles are part of the handover documentation: every client receives a clear record of who has what access, why, and what to do when it changes.
We execute all work in-house, work with a limited client load for senior attention on every project, and handle the full technical stack — from WordPress build and web design through to ongoing maintenance and security reviews. If you are looking at a new WordPress build or want your existing site audited for over-privileged access and security gaps, our team does both. No obligation — we respond within 24 hours.
Who This Is NOT For
Not for you if you are a solo operator who is your own admin. If you run the site yourself with no team members and no contractors, role management is not a live issue. You are the one Administrator and the setup is inherently simple. Come back to this guide when you bring in your first content person or developer.
Not for you if you are on WordPress.com's free or personal plan. The free WordPress.com tier restricts plugin installation entirely and the role system is controlled differently from a self-hosted WordPress.org site. This guide applies to self-hosted WordPress (WordPress.org), which is what the vast majority of business and ecommerce sites run. See our WordPress.com vs WordPress.org comparison if you are unsure which you have.
Not for you if you want a fully managed team access system. WordPress roles are a solid foundation, but they are not an enterprise IAM (Identity and Access Management) system. If your business requires row-level data access, fine-grained API permissions, or multi-factor authentication enforced at the role level, you need a specialist developer to implement custom access control — the built-in role system will not cover it alone.
Not for you if your site is on a different CMS. This guide is specific to WordPress and WooCommerce. Wix, Squarespace, Webflow, and Shopify each have their own collaborator or staff account systems with different role structures. The principles (least privilege, quarterly audits, separate accounts per contractor) transfer, but the specific screens and roles do not.
Want someone to set this up correctly the first time?
Share your current WordPress setup and we will review your user roles and flag any access gaps — free consultation, no obligation.
Request a Free Role AuditFrequently Asked Questions
What is the difference between an Editor and an Administrator in WordPress?
An Editor can create, publish, and manage all posts and pages on the site, moderate comments, and manage content categories — but cannot install or configure plugins, change themes, manage site settings, or add and remove other users. An Administrator has all of those additional capabilities. An Editor is the correct role for a content or marketing manager; Administrator should be reserved for the site owner and any technical staff who need settings access.
Can I give a freelance developer Admin access temporarily?
Yes — and this is the correct approach. Create a separate, named WordPress account for the developer with Administrator access; do not share the site owner's login credentials. When the project ends, delete the developer's account or downgrade it to Subscriber immediately. Keeping a contractor on Admin indefinitely after a project closes is one of the most common access control gaps on SA business sites.
What WordPress user roles does WooCommerce add?
WooCommerce automatically adds two roles when it is installed: Shop Manager and Customer. Shop Manager is the operational role for store staff — it allows managing orders, products, refunds, and reports, but blocks access to WordPress plugin management, themes, and user administration. Customer is assigned automatically to shoppers who register an account; they can view their own orders and update their profile, with no dashboard access beyond that.
How does WordPress role management relate to POPIA compliance?
POPIA section 19 requires South African businesses that process personal information to take "appropriate, reasonable technical and organisational measures" to prevent unauthorised access. A WordPress site that captures form submissions, customer orders, or contact details holds personal information. Restricting which staff accounts can view, export, or modify that data — through correct role assignment — is a direct implementation of this requirement. Quarterly access reviews and removing dormant accounts are the practical steps that demonstrate accountability under the Act.
How do I create a custom WordPress user role?
For most businesses, the simplest route is a plugin. User Role Editor (700,000+ active installs, free on WordPress.org) lets you create a new role, clone an existing one as a starting point, and check or uncheck individual capabilities through a graphical interface. The Members plugin offers the same capability editor plus the ability to restrict specific content to certain roles. If you are comfortable with PHP, WordPress's built-in add_role() and add_cap() functions do the same thing in code — test any changes on a staging site before applying to production.
Ready to Build a Properly Configured WordPress Site?
Growth Pulse Media builds WordPress sites for South African businesses with the full technical stack handled in-house — from role configuration and security hardening to SEO and ongoing support. Senior attention on every project, limited client load, and all work done locally in Johannesburg. No obligation — we will get back to you within 24 hours.
Talk to Us About Your Site

