WordPress multisite user permissions break down at agency scale when governance is treated as a configuration detail rather than an operational decision. The model agencies need maps to three tiers: network administrators who own the infrastructure, agency operators assigned to specific client subsites, and client users scoped to their own site only. This post gives you the configuration steps, the review cadence, and the policy documentation to make that model hold across a multi-client fleet.
A Super Admin has network-level access across every subsite on the multisite installation. They can create or delete subsites, manage network-activated plugins and themes, and view or modify any site in the fleet. A site Administrator has authority only within the specific subsite they are assigned to. For agency fleets, Super Admin status should be reserved for principals and senior technical operators. Clients and contractors should receive site-level roles only.
Add client accounts through the individual subsite’s Users menu, not through Network Admin. Accounts scoped at the site level cannot navigate to or access other subsites by default. Also ensure no client account is ever granted Super Admin status, which would give them network-wide access regardless of where the account was originally created.
Multisite is efficient for agencies managing many sites with shared infrastructure, themes, and operational overhead. Separate single sites give stronger isolation by default, because a misconfigured permission on one site cannot affect another. The right answer depends on your fleet architecture and how you want to manage multiple WordPress sites day to day. The full tradeoff breakdown is covered at /blog/how-agencies-should-decide-between-wordpress-multisite-and-a-fleet-of-single-sites/.
Quarterly is the minimum for a fleet of three or more client sites. In practice, the most important reviews happen at two moments: when a team member or contractor leaves the agency, and when a client engagement ends. If you build a permission review step into both offboarding checklists, the quarterly audit becomes a safety net rather than the primary mechanism for catching drift.
Start by confirming which tier the affected user belongs to: network-level Super Admin, or a site-level role. Then check the specific subsite’s Users menu to verify the role currently assigned. The most common cause of unexpected permission behavior is a role mismatch: a user assigned Editor expecting Administrator capabilities, or a Super Admin whose access is being restricted by a network-level setting. Review the role assignment before looking for a technical root cause.
1,000 free credits. Just describe what you need.
See It In ActionNew to WPOS? Learn what WPOS is and how agencies use it to build and operate client WordPress sites with AI agents.
Part of our guide: How to Run a WordPress Agency at Scale.