Managing Users and Roles in Enhance

How to invite additional users to your Enhance account, assign roles, and remove access when no longer needed.

Web Hosting Updated 19 July 2026

Enhance lets you invite additional users to your hosting account and assign them a role. This is useful for giving a developer or colleague access without sharing your own login credentials.

Viewing Users

Go to Users in the left sidebar. The page shows all users on your account with their name, email, role, whether 2FA is enabled, and the date they were added.

Inviting a User

  1. Click Invite user.
  2. Enter the person's full name and email address.
  3. Select a role.
  4. Send the invitation. They will receive an email to set up their account.

Roles

The Owner role is assigned to the primary account holder. The Owner has unrestricted permissions and cannot be deleted. If you need to add a user with limited access, contact support - additional roles may be available depending on your plan.

Removing a User

Click the menu icon next to a user and select Delete. The Owner account cannot be deleted.

Choose Access Deliberately

Invite the person using their own work email address and give them only the access required for the job. A developer may need website files and databases but should not automatically receive billing or account-owner access. Never create one shared login for an agency or team: separate accounts make it possible to remove one person without changing everybody else's password.

Before sending an invitation, confirm the email address verbally or through a trusted channel. An invitation sent to the wrong address may give an unrelated person access to your hosting. Ask the recipient to set a unique password and enable two-factor authentication before beginning work.

Review Access After the Work

Check the Users page when a project finishes, a supplier changes, or a colleague leaves. Remove access that is no longer needed rather than leaving dormant accounts in place. If you remove a developer, also review any separate SFTP, SSH, mailbox, WordPress and database credentials they used; deleting their Enhance user does not necessarily revoke credentials created inside an individual website.

If you do not recognise a user or see an unexpected change, remove access where safe, reset the Owner password, confirm two-factor authentication and contact support with the relevant email address and approximate time.

Security tip: Each user should have 2FA enabled on their account. The 2FA column on the Users page shows at a glance who has it set up.