Account Delegation: Give trusted teammates access
Account Delegation lets you safely grant another user limited access to your account so they can help manage domains and settings. It’s built for teams, agencies, and anyone who needs help with day-to-day domain work—without giving away full control of the account.
Why use Account Delegation?
Safer than sharing login credentials
Your password stays private, and access can be removed at any time.
Faster teamwork
Let a teammate handle DNS changes, forwarding, or renewals while you stay in control.
Control what they can do
Choose both the permission level (what actions they can take) and the scope (which domains/categories they can access).
Visibility
You can review access status and see an activity log of key delegation actions.
Key terms
Account owner: The person granting access.
Delegate: The person receiving access to help manage the account.
Permission level: Defines what the delegate can do.
Scope: Defines what the delegate can access (specific domains or categories).
What you can delegate
You can grant access to:
All domains
Specific domains
If you need to select many individual domains, there may be a selection limit (for example, up to 20); if you need more, use categories instead.
One or more categories
Permission levels
When you invite a delegate, you’ll pick a permission level. This controls which tools and actions they can use while in your account.
Technical (Manage DNS/Settings)
Best for teammates who need to manage DNS and domain configuration.
Change NameServers
Change host records (DNS)
Change privacy protection
Update domain casing
View domain history
Add custom notes to domain history
Change URL forwarding
View category history
Full Access (includes everything in Technical)
Best for operations work like renewals and domain management (still not billing/ownership).
Change auto-renew
Renew domains
Register domains
Change domain category
Restore domains
Category management (add/delete, rename, set default)
Initiate inbound transfers
Legacy Access (from the previous platform)
If access was created on the older platform, it may appear as Legacy.
Legacy permissions can’t be edited
To change what a delegate can do, you’ll need to revoke the legacy access and create a new invite using the new permission levels
What delegates can’t access
To protect account security, delegated access does not include:
Billing and payment methods (credit cards, invoices, etc.)
Account ownership controls
Auth codes (if your platform restricts these for delegates)
(Exact availability can vary by your account setup and your organization’s policies.)
How the invite flow works
As the account owner: invite a delegate
Go to your account’s delegation/access management area
Choose the delegate by email or username
Select:
A permission level (Technical, Full Access, or Legacy if applicable)
A scope (all domains, specific domains, or categories)
Send the invite
What happens next:
The delegate receives an email invitation
The invite remains pending until they accept
Invites expire after 5 days if no action is taken
As the delegate: accept or decline
From the invitation email (or your “Accounts I can access” list), you can:
Accept to activate access
Decline if you don’t recognize the request (recommended for security)
Using a delegated account (delegate experience)
Once accepted, delegates can:
See delegated accounts in their navigation/account switcher
Switch into the delegated account
Work only within the allowed scope and permissions
Exit the delegated session at any time (for example, “Exit delegated account”)
Managing, revoking, and resending access (owner)
From your delegation management page, you can:
View who currently has access and their permission level/scope
Revoke access immediately (recommended when a teammate changes roles)
Handle inactive invitations (expired/declined/revoked)
Some experiences include a Resend access option that reopens the invite using previous settings
If the previous setup was Legacy, you may be prompted to choose a new permission level before resending
Activity and security log
For transparency and troubleshooting, the system records key delegation actions such as:
Invites sent
Access accepted/declined
Access revoked/removed
Invite expiration (after 5 days)
Best practices
Use Technical for DNS-only help (lowest risk).
Use categories when you need to delegate access to many domains.
Revoke access immediately when:
A contractor engagement ends
An employee changes teams
You see unexpected activity
Delegates should only accept invites from someone they recognize.
FAQ
Can a delegate change my billing info or take ownership of my account? No—delegation is designed to avoid sharing billing and ownership controls.
What if I invited the wrong person? Revoke the invitation/access right away from your delegation management page.
Why can’t I edit a Legacy delegate’s permissions? Legacy access was created under older rules and is locked for safety and consistency. Revoke it and create a new invite using the new permission levels.
What happens if the delegate doesn’t respond? Invites expire automatically after 5 days. You can send a new invite if needed.