When more than one person needs to deal with your hosting - a developer, an accountant, a colleague - the wrong answer is to share your password. Fast Hive gives you two proper mechanisms instead: contacts, for people who should receive certain emails, and sub-users, for people who need to log in. This guide explains the difference and how to set each one up.
- Contact - receives emails (invoices, support replies, domain notices). Cannot log in.
- Sub-user - has their own login, their own password and their own two-factor authentication, with permissions you choose.
Adding a contact
- Sign in and go to Manage Contacts.
- Choose Add New Contact from the selector.
- Fill in their name, email address and any other details you want recorded.
- Under Email Preferences, tick only the categories they should receive:
- General Emails - announcements and general notices.
- Invoice Emails - invoices and payment reminders. The right one for an accountant or finance team.
- Support Emails - ticket correspondence. The right one for a technical contact.
- Product Emails - provisioning and service notices, including welcome emails with login details.
- Domain Emails - renewal and expiry notices. Critically important; make sure at least one monitored address receives these.
- Click Save Changes.
Adding a sub-user
Sub-users get their own login rather than sharing yours, which means access can be revoked for one person without disrupting anyone else.
- Go to User Management.
- Enter the person's email address under Invite New User.
- Choose their permissions - either all permissions, or a specific set:
| Permission area | Grants access to | Give it to |
|---|---|---|
| Products & Services | Viewing and managing hosting, including cPanel single sign-on | Developers |
| Domains | DNS, nameservers, contact details | Whoever manages DNS - grant carefully |
| Invoices & Billing | Viewing and paying invoices | Finance |
| Support Tickets | Opening and replying to tickets | Anyone who needs to reach us |
| Affiliates | The affiliate area | Rarely needed |
- Send the invitation. They receive an email and set up their own password and two-factor authentication.
- The user appears in your list, where you can change permissions or remove them at any time.
Applying least privilege
Grant the narrowest permissions that let someone do their job. It is not about mistrust; it limits the damage if their own account is ever compromised.
| Role | Suggested access |
|---|---|
| Web developer | Sub-user: Products & Services, Support Tickets. Not billing, not domains. |
| Accountant / bookkeeper | Contact with Invoice Emails, or a sub-user with billing only. |
| Agency managing everything | Sub-user with full permissions - but keep ownership of the account yourself. |
| Contractor, short engagement | Sub-user with minimum access, removed the day the work ends. A dedicated cPanel FTP account is often enough. |
| Colleague covering your absence | Sub-user with the permissions they will actually need, reduced when you return. |
Removing access
- For a sub-user: go to User Management and remove them. Access ends immediately.
- For a contact: go to Manage Contacts, select them and delete.
- Then close the other doors: change any cPanel password they knew, delete FTP accounts created for them, remove their SSH keys, and revoke any API tokens.
Removing a sub-user does not change passwords they already knew. Treat the two as separate jobs.
Troubleshooting
| Symptom | Cause and fix |
|---|---|
| Invitation email never arrived | Check their spam folder, and confirm the address was typed correctly. Resend from User Management. |
| Sub-user cannot see a service | They lack the Products & Services permission, or access to that specific item. Adjust their permissions. |
| Contact is not receiving invoices | The Invoice Emails preference is not ticked on their contact record. |
| A colleague opened a ticket and got no reply | Tickets from unrecognised addresses are not linked to your account. Add them as a contact or sub-user first. |
| Former developer may still have access | Remove the sub-user, then change cPanel, FTP and database passwords and remove their SSH keys. Removing the login alone is not enough. |
| Need to transfer the account to someone else | A change of account ownership needs verification. Open a ticket with Accounts & Billing. |
Frequently asked questions
How many contacts and sub-users can I have?
Add as many as you genuinely need. The practical limit is your own willingness to review the list periodically.
Can a sub-user see my card details?
Stored card numbers are held by the payment gateway and are not visible in the client area. A sub-user with billing permission can see invoices and make payments, so grant it deliberately.
Does a sub-user need their own two-factor authentication?
Yes, and they should enable it. Each login is secured independently.
Can a contact open a support ticket?
A contact with support email preferences receives correspondence. To open tickets in the client area themselves, they need to be a sub-user.
Should I just share my password instead?
No. Shared passwords cannot be revoked individually, do not tell you who did what, and force a password change for everyone whenever one person leaves.
How often should I review access?
Every few months, and immediately whenever someone stops working with you.
