Skip to content

Security & access

GoDaddy delegate access: give a developer the permissions they need

Set up delegated access, verify the actual work it permits, and preserve client ownership through handover.

By Besthostlab Sources checked
An owner hands a developer a limited access key while keeping the master key.

GoDaddy delegate access lets an owner give another person access through that person’s own GoDaddy account. Use it to let a developer work on the required products while the client retains account ownership and recovery access.

The invitation is only the beginning. Before scheduling a migration or launch, confirm that the delegate has accepted it and can perform the intended work with the selected permissions.

Choose the permission level deliberately

GoDaddy’s permission guide distinguishes product and domain access, access with purchasing ability, domain-only access, and an account connection without current product access. Domain folder permissions further control management and transfer actions.

Work requiredPermission question
Manage DNS for a domainCan access be limited to the relevant domain and management actions?
Work in hosting or a product panelDoes product access cover this product and the required operation?
Buy or renew a serviceHas the owner expressly authorized spending through stored payment methods?
Prepare for future workIs an account connection sufficient until operational access is needed?

The provider’s guide also lists actions delegates cannot perform, including changing account credentials or payment methods and accepting incoming domain transfers. If a blocked action is owner-only, arrange for the owner to complete that action instead of sharing the main password.

Send and accept the invitation

Follow the official invitation steps: open Delegate Access, choose Invite to Access under people who can access the account, enter the person’s name and email, select the appropriate level, and send the invitation.

The recipient needs a GoDaddy account and must accept the invitation. Confirm the intended account identity, especially when an agency has several staff accounts. A forwarded email or a pending invitation does not prove that the right person has access.

Keep a record of who requested the access and what work it covers. Protect both accounts with appropriate multifactor authentication and independent recovery details.

Verify access before the maintenance window

Have the delegate open the owner’s account context and the actual product they need. Confirm the relevant domain is visible and that the necessary management screen opens. Read-only inspection is enough to establish access; do not change DNS merely as a permission check.

If access fails, distinguish an unaccepted invitation, wrong signed-in account, missing domain-folder permission, and an unsupported or owner-only operation. Ask support about the specific blocked action rather than repeatedly sending broader invitations.

Do not grant purchasing or transfer authority simply to make every possible button available. Expand access only when the agreed task requires it.

Separate GoDaddy access from website access

A hosting control panel and a WordPress administrator are different identities. So are database users, SFTP credentials, external DNS accounts, and Microsoft 365 roles. List the systems required for the job and provide a named, limited account where each system supports one.

For a website migration, establish who can export data, change DNS, and approve the live switch. A developer with WordPress access alone may not be able to complete the whole move.

Close out access at handover

At completion, remove or reduce delegated access as agreed and review any separate accounts or credentials created during the work. Revoking one invitation does not necessarily invalidate an application password or transfer key created elsewhere.

Confirm the client can log in independently, find renewal notices, retrieve backups, and contact support. Leave an owner for ongoing updates and incident response. Effective delegation is access that works during the project and a clear way to end it afterward.