A contractor's project is finished, but the access granted for it often stays behind. The website login is only one part of that access. Hosting, deployment tools and third-party accounts may still be involved.
Good offboarding removes access the person no longer needs while preserving the work your business depends on.
List access before revoking it
Start with the project agreement and the accounts used during delivery. Include WordPress, hosting, domain management, file access, backups and connected services.
Ask which integrations use the contractor's personal account. If a scheduled task or license relies on it, transfer the dependency before removing access. Never ask someone to send passwords through ordinary chat.
The WordPress roles reference explains the platform's permissions. Offboarding needs to go beyond those roles.
Confirm ownership of the deliverables
Check that your organization can access the source files, purchased assets, configuration notes and recovery instructions it is entitled to own. Test the handover with an authorized team member.
A link that works only while the contractor is signed in is not a completed transfer.
Remove access in a controlled sequence
Assign the account changes to someone authorized to make them. Revoke unused personal access, review active sessions where supported and rotate shared secrets that were exposed.
For integrations, use a planned credential replacement and verify the connection afterward. Revoking an app credential without identifying its consumer can interrupt publishing or reporting.
Our secrets management guide helps organize that work.
Put these ideas to work.
From a specific fix to a complete website, we can help you define the scope and get it done.
Discuss my websiteCustom WordPress Web DevelopmentShare your goals. We usually reply within one business day with questions and practical next steps.
Check the site after the handover
Test the functions the contractor changed and any tasks tied to replaced credentials. Keep a short record of ownership transfers, revocations and outstanding dependencies.
If an unexplained administrator remains, follow the administrator-account review guide rather than deleting it without context.
Make the next engagement easier
Grant named, purpose-specific access with a review date at the start of the next project. Agree the handover requirements before work begins.
A WordPress maintenance arrangement should make account ownership and end-of-contract responsibilities clear, not leave them as an informal favor.
Frequently asked questions
Should I delete every account created during a project?
First identify the account's owner and dependencies. Remove unused access, but transfer legitimate services before breaking them.
Is changing the WordPress password enough?
Not when hosting, domain, file or third-party access was also granted. Review the full access list.
What should the handover record contain?
Account ownership, transferred assets, revoked access, changed shared credentials and any unresolved dependency.




