NameBright Help Center

Account Delegation: Give trusted teammates access

Account Delegation lets you safely grant another user limited access to your account so they can help manage domains and settings. It’s built for teams, agencies, and anyone who needs help with day-to-day domain work—without giving away full control of the account.

Why use Account Delegation?

  • Safer than sharing login credentials

    • Your password stays private, and access can be removed at any time.

  • Faster teamwork

    • Let a teammate handle DNS changes, forwarding, or renewals while you stay in control.

  • Control what they can do

    • Choose both the permission level (what actions they can take) and the scope (which domains/categories they can access).

  • Visibility

    • You can review access status and see an activity log of key delegation actions.

Key terms

  • Account owner: The person granting access.

  • Delegate: The person receiving access to help manage the account.

  • Permission level: Defines what the delegate can do.

  • Scope: Defines what the delegate can access (specific domains or categories).

What you can delegate

You can grant access to:

  • All domains

  • Specific domains

    • If you need to select many individual domains, there may be a selection limit (for example, up to 20); if you need more, use categories instead.

  • One or more categories

Permission levels

When you invite a delegate, you’ll pick a permission level. This controls which tools and actions they can use while in your account.

Technical (Manage DNS/Settings)

Best for teammates who need to manage DNS and domain configuration.

  • Change NameServers

  • Change host records (DNS)

  • Change privacy protection

  • Update domain casing

  • View domain history

  • Add custom notes to domain history

  • Change URL forwarding

  • View category history

Full Access (includes everything in Technical)

Best for operations work like renewals and domain management (still not billing/ownership).

  • Change auto-renew

  • Renew domains

  • Register domains

  • Change domain category

  • Restore domains

  • Category management (add/delete, rename, set default)

  • Initiate inbound transfers

Legacy Access (from the previous platform)

If access was created on the older platform, it may appear as Legacy.

  • Legacy permissions can’t be edited

  • To change what a delegate can do, you’ll need to revoke the legacy access and create a new invite using the new permission levels

What delegates can’t access

To protect account security, delegated access does not include:

  • Billing and payment methods (credit cards, invoices, etc.)

  • Account ownership controls

  • Auth codes (if your platform restricts these for delegates)

(Exact availability can vary by your account setup and your organization’s policies.)

How the invite flow works

As the account owner: invite a delegate

  • Go to your account’s delegation/access management area

  • Choose the delegate by email or username

  • Select:

    • A permission level (Technical, Full Access, or Legacy if applicable)

    • A scope (all domains, specific domains, or categories)

  • Send the invite

What happens next:

  • The delegate receives an email invitation

  • The invite remains pending until they accept

  • Invites expire after 5 days if no action is taken

As the delegate: accept or decline

From the invitation email (or your “Accounts I can access” list), you can:

  • Accept to activate access

  • Decline if you don’t recognize the request (recommended for security)

Using a delegated account (delegate experience)

Once accepted, delegates can:

  • See delegated accounts in their navigation/account switcher

  • Switch into the delegated account

  • Work only within the allowed scope and permissions

  • Exit the delegated session at any time (for example, “Exit delegated account”)

Managing, revoking, and resending access (owner)

From your delegation management page, you can:

  • View who currently has access and their permission level/scope

  • Revoke access immediately (recommended when a teammate changes roles)

  • Handle inactive invitations (expired/declined/revoked)

    • Some experiences include a Resend access option that reopens the invite using previous settings

    • If the previous setup was Legacy, you may be prompted to choose a new permission level before resending

Activity and security log

For transparency and troubleshooting, the system records key delegation actions such as:

  • Invites sent

  • Access accepted/declined

  • Access revoked/removed

  • Invite expiration (after 5 days)

Best practices

  • Use Technical for DNS-only help (lowest risk).

  • Use categories when you need to delegate access to many domains.

  • Revoke access immediately when:

    • A contractor engagement ends

    • An employee changes teams

    • You see unexpected activity

  • Delegates should only accept invites from someone they recognize.

FAQ

Can a delegate change my billing info or take ownership of my account? No—delegation is designed to avoid sharing billing and ownership controls.

What if I invited the wrong person? Revoke the invitation/access right away from your delegation management page.

Why can’t I edit a Legacy delegate’s permissions? Legacy access was created under older rules and is locked for safety and consistency. Revoke it and create a new invite using the new permission levels.

What happens if the delegate doesn’t respond? Invites expire automatically after 5 days. You can send a new invite if needed.