Contents · Clinic manual

Looking after your website · shared chapter

Staff accounts and signing in

Giving each member of staff their own account, the staff roles each kit comes with, choosing what each role can do (Pro), and the staff sign-in page.

On this page

Give everyone who works on the website their own account, with the role that fits their job. A role decides what someone can see and do. For example, front-desk staff can manage appointments but can't change the website's settings. Each kit comes with ready-made roles for its kind of business, so you don't have to set anything up.

Never share one account between several people. With their own accounts, people only see what their job needs, and you can remove one person's access without changing everyone's password.

Features marked (Pro) need a Pro or Agency licence.

The roles

Every website has the Administrator role: the owner, or whoever looks after the website. Administrators can do everything, including plugins, the licence, staff access and the email log. Keep administrator accounts to one or two people.

Your kit adds its own staff roles:

KitStaff roles
ClinicOptometrist, Front desk
ChurchPastor or church leader, Media team, Welcome team
MusicTutor, Office
SalonStylist, Front desk
GroupGroup admin, Business manager, Business staff
TutorTutor, Office
DrivingInstructor, Office
TradesEstimator, Office
VenueEvent coordinator, Events manager
CharityVolunteer coordinator, Fundraiser

Your kit's manual explains what each of its roles can do to start with.

WordPress's own roles are also there: Editor (can edit every page and post, and open Site Settings → Design & colours), Author, Contributor and Subscriber. Some kits also have a role for customers, such as Learner (Driving) or Client (Group), for people who sign in to their own account on the website. Don't give those roles to staff.

How to add a staff member

  1. Go to Clinic → Staff access. Only administrators see this screen.

  2. At the bottom, in the Staff card, choose the role in Role for the new staff member, then click Add staff member.

    The Staff card at the bottom of Staff access, with a role list showing one of the Clinic roles, an Add staff member button, the line "Adding someone opens Users → Add User with the role already chosen. They get an email to set their own password." and the list of staff, starting with the administrator
  3. WordPress opens Add User with the role already chosen. Fill in:

    • Username (required): what they type to sign in, for example alex.sample. It can't be changed later.
    • Email (required): their own work email address.
    • First Name and Last Name.
  4. Leave Send User Notification ticked, so they get an email to set their own password.

  5. Check the Role, then click Add User.

The Add User screen filled in for a sample staff member: Username alex.sample, Email alex.sample@example.com, First Name Alex, Last Name Sample, a generated strong password, Send User Notification ticked and the role already chosen (here Front desk, a Clinic role), with an Add User button

WordPress says New user created and lists them under Users.

The Users list after adding a staff member, with the message "New user created", the admin as Administrator and alex.sample, Alex Sample, with the chosen role (here Front desk)

You can also add people from Users → Add User and choose the role yourself.

How to change someone's role

  1. Go to Clinic → Staff access and scroll to the Staff card.
  2. Next to the person, choose the new role and click Change role.

Or go to Users, tick the person, choose a role in Change role to… and click Change.

When someone leaves

Remove their access on their last day.

  1. Go to Users.
  2. Point at their name and click Delete.
  3. If they wrote pages or posts, WordPress asks who should own them. Choose Attribute all content to and pick another person, then click Confirm Deletion.

Choosing exactly what each role can do (Pro)

With a Pro or Agency licence, Staff access shows a grid. Each row is something staff can do; each column is a role. Tick or untick, then click Save staff access.

The Staff access grid for Clinic, with a column for Administrator (Always everything) and one for each staff role, and rows of things staff can do grouped by area, ending with Business, then Save staff access and the Staff card at the bottom
  • The Administrator column is always everything and can't be changed.
  • Everyone with a role gets the same access, so give each person the role that fits their job.
  • Some things go together (for example, changing something needs seeing it), so those are ticked for you.
  • Staff access and the Staff list are always for administrators only.

Without Pro, the roles keep their ready-made access, and the Staff access grid shows an upgrade card instead. If a website goes back from Pro to Starter, the access you chose keeps applying; you just can't change it until Pro is active again.

The staff sign-in page

Staff sign in at your website's address followed by /wp-admin (or /wp-login.php). There's also a Staff sign-in link in the footer of every page.

The sign-in page uses your logo and brand colour. The panel on the left lists what staff look after here, today's opening hours and your phone number (in kits that have them). Back to website takes visitors back to your home page.

The staff sign-in page: on the left, a panel in the brand colour with the logo, a welcome line, what staff look after here and the phone number; on the right, Back to website, Sign in, "Use your own staff account.", Username or Email Address, Password, Remember Me, a Log In button, Lost your password? and Website by Gradespace

On a phone, the panel becomes a short banner above the form.

The staff sign-in page on a phone, with the logo and a short banner at the top and the sign-in form below

How to sign in

  1. Go to your website's address followed by /wp-admin.
  2. Type your Username or Email Address and Password.
  3. Tick Remember Me only on your own computer or phone.
  4. Click Log In.

If you've forgotten your password

  1. On the sign-in page, click Lost your password?
  2. Type your username or email address and click Get New Password.
  3. Open the email and follow the link to choose a new password. Use at least 12 characters; the strength meter helps.
The Reset your password page: "Enter your username or email and we'll email you a link.", a Username or Email Address box, a Get New Password button and a Log in link

Too many wrong passwords

To stop people guessing passwords, sign-in is locked for 15 minutes after 5 wrong tries from the same place. The page says "Too many failed sign-in attempts. Please try again in … minutes." Wait, then try again, or reset your password. The lockout gets longer for repeated attempts (up to a day).

Messages never say whether the username or the password was wrong; they just say "Incorrect username or password." That's on purpose.

Your own photo and words on the sign-in page

Go to Clinic → Settings → Business and find the Sign-in page card:

  • Sign-in page photo (optional): a photo behind the panel, darkened with your brand colour so the words stay easy to read. Use a landscape or square photo at least 1200 pixels wide. With no photo, the panel uses your brand colour.
  • Line at the bottom of the panel (optional): a small line such as your full name and area.

Click Save changes.

Hiding the "Website by Gradespace" line (Pro)

With a Pro or Agency licence you can hide the small "Website by Gradespace" line under the sign-in form.

  1. Go to Settings → Gradespace licence.
  2. In the Sign-in page card, switch on Hide the "Website by Gradespace" credit.
  3. Click Save sign-in page.
The Sign-in page card on the Licence tab: "Pro: choose whether the Gradespace credit shows under the staff sign-in form.", a switch Hide the "Website by Gradespace" credit, and a Save sign-in page button

With an Agency licence, the same screen also lets you set your own Panel heading and Panel text for the sign-in page (white label), for agencies building websites for clients.