In short: Your Maintena world is organised in a simple chain: team members manage client accounts, and each client account owns one or more sites. Roles decide who can see and do what, so the right people have access and nobody sees data that is not theirs.
What it is
Accounts & Access is the structure that holds everything together. Every monitor, report and alert in Maintena hangs off this foundation, so it is worth a few minutes to understand how the pieces fit.
There are three building blocks:
- Team members are the people who log in. In an agency or in-house team, these are the staff who look after your clients.
- Client accounts are the accounts you manage. Each one belongs to a customer (or an internal department) and holds their billing and settings.
- Sites are the WordPress installs Maintena watches. Every site lives under a client account.
Put simply: a team member manages one or more client accounts, and each client account owns one or more sites. Everything Maintena monitors traces back up that chain.
On top of this sits a roles system that decides who can see and do what, and a set of quiet safeguards that keep one account's data from ever showing up in another.
How it works
The ownership chain
Team member → Client account → Site
(login) (customer) (WordPress install)
A team member can look after many client accounts. A client account can own many sites. A site always belongs to exactly one client account, which is how Maintena knows whose data it is.
Roles: who sees and does what
Access is decided by roles. Each person is given a role, and the role sets what they can open and change. Maintena ships with three:
| Role | Who it is for | What they can see |
|---|---|---|
| Administrator | The platform owner and Maintena team | Everything across every account |
| Account manager | Your team members who look after clients | The client accounts and sites in their remit |
| Client | The customer who owns an account | Only their own account, sites and reports |
Roles are built from permissions, small on/off switches like "view sites", "edit sites" or "manage users". You can create your own roles from these switches and tune exactly what each one allows, so access grows with your team rather than being fixed in stone.
A person's role travels with them everywhere in Maintena. Change someone from account manager to administrator and their view widens straight away, with no data to move or re-import. The same is true in reverse, so tightening access is just as quick.
Two kinds of permission are worth knowing apart:
- A menu permission lets someone open a section, for example the Sites list.
- A see-everything permission lifts the usual boundary so a person can view the whole fleet, not just their own rows. Account managers are set up with this so they can work across the clients they support.
Keeping accounts separate
The most important job here is making sure one customer never sees another's data. Maintena handles this automatically at the data layer, so it is not something a team member can forget to switch on.
- Every request is filtered to the account it belongs to. If you try to open something that is not yours, Maintena simply reports it as not found, rather than confirming it exists.
- Web addresses do not expose plain, guessable ID numbers. Links are scrambled, so nobody can go fishing by editing a URL.
- Customer contact details, including business and residential addresses, are stored encrypted, so they are unreadable even to someone who reached the raw data.
Viewing an account for support
Where enabled, a Maintena administrator can securely view your account exactly as you see it. This is used to help with support, so we can see the same screens you do while sorting out a question. When it is active, a clear banner shows that a view-as session is in progress, and it can be ended in one click. This ability is granted deliberately and can be removed, so it is never on by accident.
What you need to do
For most customers there is nothing to configure here. Your account is created for you, the safeguards above are always on, and your Success Manager sets up roles to match your team. If you do manage a team and client accounts yourself, here is how each piece comes to exist.
- Create client accounts. Your customers can sign up themselves, which creates their login and account and walks them through onboarding. You can also create a client account for them from the admin area, setting a password and logo in one step.
- Add sites to an account. Each site is added under its client account. The number of sites an account may hold depends on its plan, so if you hit the limit, that is the moment to review the plan. See Billing & Subscriptions for what each plan includes.
- Add team members. Give a colleague a login with the account-manager role so they can help look after clients.
- Assign clients to a manager. Point each client account at the team member who owns the relationship, and set how many accounts that person can comfortably carry.
- Shape your roles. Use the role settings to create or adjust roles from the permission switches, so each person sees exactly what they should. The administrator role is protected and cannot be removed.
Good to know
- One login per client account. Today each client account has a single owner login. Sharing wider access to one account is on the roadmap below.
- Setup is self-contained. Access control does not depend on any outside service or extra paid tool, so there is no third-party account to connect just to manage who sees what.
- If someone sees "unauthorized" by mistake. Right after a role or permission change, access updates can take a moment to settle. If a teammate who should have access is briefly blocked, a quick sign-out and back in, or a short wait, resolves it.
- Sites stay with their account. A customer cannot move a site to a different account or exceed their plan's site allowance. Those rules are enforced for you.
On the roadmap
A few things are planned but not available yet, so we would rather be upfront than have you expect them today:
- Multiple logins per account. Inviting several teammates to share one client account is not built yet. For now, an account has one owner login.
- Two-factor authentication and single sign-on. Sign-in is by email and password today. Extra sign-in security is planned.
- Self-service account deletion. Deleting a client account is not yet a button in the app. If you need an account removed, your Success Manager will handle it for you. See Support Tickets to raise the request.