Nubocoder Agency Manager

Nubocoder Agency Manager

Details
View on WordPress

When a developer or marketer joins an agency, they need an account on every client site. When they leave, every one of those accounts must go. Doing it site by site is slow and one forgotten account is a security risk.

Agency Manager keeps your team in one place and applies it to your client sites:

  • Define team members and teams (for example Developers or Marketing), each with the role it gets on client sites.
  • Give access to one or many people on one, several or all sites, with a review of every change before anything is sent.
  • Change roles, suspend, restore or remove accounts in bulk.
  • Retire a member: every account is removed or suspended, and sites that do not answer are retried until it is done. Their content goes to an agency service account.
  • See who has access to what in the access matrix, including accounts whose role was changed on the site and administrators not managed by the agency.
  • Follow every change site by site, retry failures and read the tamper-evident activity log.

Each client site needs the companion plugin Nubocoder Agency Manager Client.

Security

  • Every request to a client site is signed with a key pair dedicated to that site, is valid for five minutes and cannot be replayed. Responses are signed too.
  • Site keys are encrypted in the database with the NBAM_ENCRYPTION_KEY constant.
  • Client sites only let the agency change accounts it created; the site owner decides what the agency may do and can disconnect at any time.
  • Removing access and granting administrator roles ask for your password again. The owner is emailed about critical actions.
  • Dedicated capabilities, optional mandatory two-factor authentication and an emergency button that revokes every key.

Install the hub on a dedicated WordPress site with few plugins, not on the public website of the agency.

External services

This plugin does not use any third-party service. It only talks to the client sites that you add in Agency Manager Sites, which run the companion plugin Nubocoder Agency Manager Client. Nothing is sent until you add a site and its owner pastes the connection key on that site.

  • When a client site connects, it sends its address, its REST endpoint, its public key and the client plugin version.
  • To show and apply access, the hub sends signed requests to each connected site: the login, email, first and last name and role of the team members you give access to, and the role changes, suspensions and removals you confirm.
  • Client sites answer with their WordPress and PHP versions, their name and address, their roles and number of users, and the login, email, role and post count of the accounts the agency manages there, plus the login, email and role of their administrators, so they appear in the access matrix.
  • When you disconnect a site or use Revoke all, the hub tells that site to forget the connection.

The data stays between your hub and your client sites. The hub also sends emails about critical actions through wp_mail() of your own site.

Third-party libraries

The plugin includes Action Scheduler (https://actionscheduler.org/, GPLv3 or later) to run jobs in the background. The full source, including composer.json, is part of the plugin.

Details

Plugin code:
nubocoder-agency-manager
Plugin version:
0.1.1
Outdated:
No
WP version:
6.9 or higher
PHP version:
8.1 or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-10
Rating:
Times rated:
0
access-management
agency
multiple-sites
team
users