Skip to content
PageSpeed 100 as the delivery default
Betrieb

Running a Website as a Team: Roles, Rights, Cover

Credentials shared by messenger, prices changed without a check: how small firms set roles, rights, four-eyes review and holiday cover for a website.

14 min read TeamRollenZugriffsrechteRedaktion

As long as one person looks after the website, responsibility is undisputed — it is simply written down nowhere. The moment a second person joins, that changes abruptly: credentials travel through the business by messenger, a price suddenly reads differently and nobody remembers who touched it last, and when the office manager is on holiday the opening hours stay wrong right through the bank holidays. This article organises the way a small team works on its own website: which roles a small business actually needs, which changes deserve a second pair of eyes, how personal logins, holiday cover and offboarding work in practice — and what data protection law adds to the picture.

Roles, rights and cover in the teamWho may change what — and who checks it before it is publishedSources: BSI, Bitkom, GDPRPermissions in a small businessPricesText and imagesLegal pagesContract, domainOwnershipAdministrationEditingView onlychangewith approvalview onlyno accessWhen logins are shared48 %of companies traceincidents back totheir own staff15 % with defined procedures81 % with none at allFour-eyes principle for prices, legal pages and job adsDraftEditingReviewAdministrationApprovalOwnershipPublishedwith date and namePersonal logins instead of a shared account, second factor for ownership, offboarding on the last working dayBSI: 25 characters, two typesRole names and the scope of rights are a suggestion for small businesses with up to 25 logins.

From the second person onwards, the risk moves inside

For small firms, having a website is long since routine rather than a special project. 94 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) of the skilled-trades businesses surveyed run their own website; the study is based on a telephone survey of 504 (Bitkom, Digitalisation of the Skilled Trades 2025) firms with at least one employee, weighted to be representative, conducted in summer 2025. Official statistics paint the same picture: in Bavaria, 92 per cent (Bavarian State Office for Statistics) of companies with ten or more employees had a website in 2025, and 95 per cent (Federal Statistical Office of Germany) of companies in Germany had a fixed internet connection. So the site exists. What is usually unresolved is who touches it day to day — and with which rights.

The problems that follow rarely come from outside. They come from missing order on the inside, and they look the same in almost every business. First, the shared account: one username, one password, handed on to everyone who ever had to change something. Second, the missing audit trail: the page shows a different price than it did two days ago, but it can no longer be reconstructed who changed it and why. Third, the missing cover: the one person who knows the login is on holiday, and for two weeks nothing changes — including the things that urgently need changing.

Where this article draws the line

This is about teamwork, not about technical hardening and not about contract questions. How to keep the technical attack surface of a site small is covered in the article on the attack surface of a website. Who owns the domain, the content and the accounts, and how to clarify that before signing, is covered in the article on checking a website provider's contract and access. Both topics touch this one at exactly two points: the logins, and the question of who is allowed to hold the contract.

That businesses underestimate the topic shows up in two further figures from the same study: 71 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) attach great importance to IT security, yet only 15 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) have clearly defined procedures for an emergency, and 81 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) have nothing structured in place at all. The gap between intention and procedure is precisely the gap that roles and rights close. Anyone who has already settled the maintenance rhythm — described in the maintenance routine for small firms — only has to answer one remaining question: who is allowed to change which part of it.

Four roles a small business actually needs

Role models fail in small businesses for largely the same reason: they are too fine-grained. Ten roles for five people end with everyone using the same login anyway. In practice four roles are enough, because they answer four different questions: who is liable, who administers, who writes, who observes. Everything beyond that is refinement that can be added later, once the business genuinely grows.

Ownership

One named person from the management. This role holds the contract, the domain and the billing data, grants and revokes access, and is the final authority on legal pages and prices. It is not shared; at most it is formally transferred.

Administration

Creates pages, orders the navigation, looks after structure and settings, sets up logins as instructed and reviews changes before publication. May organise, but may not dispose of the contract, the domain or the invoices.

Editing

Changes content: text, images, references, opening hours, articles. The everyday life of the website lives in this role. It needs no access to payment data, domain settings or legal pages in order to do good work.

View only

Sees drafts and reports, changes nothing. It sounds superfluous and is not: tax advisers, trainers, seasonal helpers or an external consultant often need insight and precisely no write access.

The cut follows a principle that the German Federal Office for Information Security sets out in module ORP.4 of its IT-Grundschutz Compendium: users and components must be unambiguously identified and authenticated, and it must be defined which information and services they may use, as well as how rights are granted, revoked and controlled (BSI IT-Grundschutz Compendium). Translated into everyday operations that means: every person has their own login, every login has exactly one role, and for every role it is written down what it may do.

RoleChanges independentlyNeeds approvalNo access
OwnershipEverything, including legal pages, prices, loginsNothing — is the approval itselfNo restriction
AdministrationStructure, navigation, new pages, settingsPrices, legal pages, job adsContract, domain control, payment data
EditingText, images, references, opening hours, articlesPrices, service descriptions, legal pagesUser management, contract, invoices
View onlyNothingNot applicableAll write functions

Two points in this table matter more than they look. First: ownership belongs to a person, not to a shared mailbox. A mailbox cannot make a declaration of intent, cannot confirm a two-factor login and cannot demonstrate, in a dispute, who wanted a domain transferred. Second: the editing role needs more rights than it is usually granted. Anyone who may only report opening hours by email instead of changing them produces exactly the delay described in the article on keeping opening hours reliably current.

Which changes deserve a second pair of eyes

Applying a four-eyes principle to everything is the surest way to abolish it: if even a misplaced comma needs approval, everyone involved will route around the process within weeks. What works is a hard split between routine edits that go live immediately and binding statements where a mistake costs money, trust or a legal warning. The second group is smaller than people assume — four categories usually cover it.

  • Prices, flat rates and terms: every figure a customer can read as an offer. Which details are mandatory and where competition law has a say is described in the article on prices and advertising claims.
  • Service descriptions and commitments: response times, service areas, warranty promises in the legal sense, certifications. Changing the scope changes the offer — and with it the basis of every later discussion.
  • Legal pages: imprint, privacy policy, right of withdrawal, terms and conditions. These pages are rarely changed and then mostly under time pressure. The article on imprint and privacy policy sets out the mandatory details.
  • Job ads: they contain pay information, working hours and wording that must be free of discrimination. How a solid careers page is built is described in the article on the careers page for skilled staff.
  • Everything else goes live without approval: spelling, swapping an image, a new paragraph on a service page, a project photo, a blog article. Here, waiting costs more than a mistake does.
  • A stated exception: for works holidays, emergencies and service disruptions the editing role may change approval-bound content too — followed by a note to the ownership role the same day.

The two-class rule

Class one is information that describes something: opening hours, contacts, photos, text about the work. It goes live without asking. Class two is information that promises something: prices, deadlines, scope of service, legal pages, job ads. It needs a second person. Draw that line cleanly once and there is no case-by-case discussion left.

The four-eyes principle only works if the approval leaves a trace. It is not enough for someone to glance over a shoulder. A note with date, name and what was checked is enough — in the simplest case in the same overview that also holds the maintenance rhythm. In our projects an approval of this kind for a price block rarely takes longer than five minutes (project experience), provided the second person knows what to look at: figure, unit of reference, validity period, additional costs.

Personal logins instead of a shared account

The shared account is convenient, and it is the root of almost every later problem. It makes every change anonymous, it makes revoking a single login impossible, it makes two-factor authentication impractical, and it turns the password into an object that gets passed around — by messenger, on a note, called across the office. Personal logins cost ten minutes of setup once and defuse all four problems at the same time.

SituationWith a shared accountWith personal logins
A temp changes a priceNo way to tell who it wasName and time are in the change history
A person leaves the businessChange the password for everyone, inform everyone againOne login is deactivated, nothing else changes
Two-factor authenticationThe second factor sits with one person, everyone else phonesEvery person has their own second factor
Office manager on holidayThe password is handed on and often not changed afterwardsThe cover has their own login with a matching role
Answering who had accessThe circle of authorised people is unclearPermissions are documented and can be evidenced

For the passwords themselves there is a clear official recommendation that replaces the old reflex towards cryptic abbreviations. The German Federal Office for Information Security names two equivalent routes: either short and complex with 8 to 12 characters (Federal Office for Information Security) from four character types, or long and less complex with 20 to 25 characters (Federal Office for Information Security) from two character types. For WLAN encryption using WPA2 or WPA3 the same recommendation names at least 20 characters (Federal Office for Information Security). In addition, the BSI advises using a separate password for every login, using a password manager to keep track of them, and using a second factor wherever it is offered — a login with a second factor offers a higher level of security than username and password alone (Federal Office for Information Security).

The three rules worth pinning up

First: length beats complexity. A sequence of four unusual words is easier to remember and harder to guess than an eight-character abbreviation with special characters. Second: a password belongs to a person, not to a device and not to a department — it is passed on neither by messenger nor by email. Third: the login that carries ownership gets a second factor, even if no other login has one yet. That is the login on which domain, contract and every other account depend.

One practical addition: define how a login is requested in the first place. In small firms a single line in the onboarding plan is enough — website login, editing role, set up on, set up by. Without that step logins appear on the side, and later nobody can say how many there are. That there is ground to make up here also shows in the finding that 76 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) of firms see a growing need for digital skills among their staff, while only 43 per cent (Bitkom, Digitalisation of the Skilled Trades 2025) invest specifically in matching training.

Offboarding: the routine when staff change

The most uncomfortable part of access management is the departure. It gets postponed because it disappears in the bustle of the last working day, and because nobody wants to show distrust towards someone who is leaving. The figures still speak plainly: in the Bitkom study on economic protection, 87 per cent (Bitkom, Economic Protection 2025) of the companies surveyed said they had been affected by data theft, espionage or sabotage in the past twelve months; the estimated total damage was 289.2 billion euros (Bitkom, Economic Protection 2025). 48 per cent (Bitkom, Economic Protection 2025) of companies traced cases back to their own staff — for 25 per cent (Bitkom, Economic Protection 2025) these were current or former employees acting unintentionally, for 23 per cent (Bitkom, Economic Protection 2025) acting deliberately. The survey covered 1,002 (Bitkom, Economic Protection 2025) companies with ten or more employees from mid-April to mid-June 2025.

So the larger share is unintentional. That is good news, because a culture of suspicion does not help against it — a checklist does. Five steps are enough, and they belong in the same place as handing back the keys and the company phone.

  1. Deactivate the login, do not delete it immediately. On the last working day the login is blocked. It is deleted once it is clear whether drafts or content hang off it — and then it really is deleted.
  2. Check the roles that move with the person. Whoever held administration leaves a gap. That role is reassigned the same day, not at some point soon.
  3. Rotate shared secrets. If there was still a common password after all — for a mailbox, a directory listing, a review portal — it is changed before the person leaves the building.
  4. Move the second factor. Phone numbers and authenticator apps that point to a private device are transferred to the successor or to a company device.
  5. Document it. A date, a name, a signature. In case of doubt this line is the evidence that the business had its permissions under control.

Timing decides the outcome. A login still active three months after someone left is no longer a residual risk but an open door for anyone who knows or has guessed the password — and after a change of staff that can be several people. What works well is tying offboarding to an appointment nobody forgets anyway: handing back the key.

Cover for holidays and sick leave

Cover is the point where most role models fail in practice. They are designed for normal operation, and normal operation is exactly the state in which nobody needs cover. It is needed in the week before Christmas, when the one person with the login is in bed with flu and the works holidays are still not on the site.

A cover arrangement that is only set up once cover is needed is not an arrangement — it is an emergency with a password being handed over.

Practical rule from website projects with small teams

What works is standing cover: a second person who permanently has their own login with the same role and rarely uses it in normal operation. So the login does not rust shut, it should carry a real task every few months — the cover looks after the references once a quarter, say, or enters the bank holidays for the coming quarter. A login that has been used before is available when it counts; a login nobody has ever opened often fails at the forgotten two-factor setup.

Ownership follows a different logic. It is not covered but prepared: credentials and second factor are deposited so that a second person from the management can reach them in an emergency — for example in a sealed envelope in the company safe, whose opening is documented. It is unspectacular, and in many businesses it is the only point at which the question of a two-week absence of the management is answered at all.

The editorial plan on a single page

Roles and rights settle who may. The editorial plan settles who should — and by when. Only both together produce working collaboration, because the most common cause of outdated content is not a missing right but a missing owner. The plan belongs on one page, because anything longer stops being read. Five columns are enough: what, who, how often, cover, deadline.

TaskOwner (role)RhythmCoverDeadline
Opening hours, bank holidays, works holidaysEditingmonthlysecond editorby the 5th of the month
Answering enquiries from the formEditingevery working dayAdministrationwithin 24 hours
References and project photosEditingquarterlyAdministrationin the first month of the quarter
Prices and scope of serviceAdministration with approvalon changeOwnershipbefore publication
Reviewing legal pagesOwnershipyearlynot applicablein January
Reviewing logins and rolesOwnershiptwice a yearnot applicableJanuary and July

The last line is missing most often and pays off most. A twice-yearly look at the list of logins takes a few minutes and answers three questions: are there accounts belonging to people who are no longer here? Does anyone hold a role they no longer need for their current job? Is cover missing anywhere? In our projects this pass regularly finds at least one (project experience) login on the first run that can no longer be attributed to anyone.

Deadlines without names are wishes

Enquiries are answered promptly — that is not a deadline, it is a statement of intent. Enquiries are answered by the editing role within 24 hours on working days, and by administration during holidays — that is one. The difference only shows up during sick leave: with the second wording, somebody knows that they are the one meant.

Data protection: access only for those who need it

As soon as personal data is processed via the website — and that begins with the contact form — assigning rights is not merely organisation but obligation. Article 32 of the General Data Protection Regulation requires appropriate technical and organisational measures, taking into account the state of the art, the costs of implementation and the likelihood and severity of the risk; it explicitly names the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems (General Data Protection Regulation, Article 32(1)(b)). Paragraph 4 of the same article additionally obliges controllers to take steps to ensure that any natural person acting under their authority who has access to personal data processes it only on instructions (General Data Protection Regulation, Article 32(4)).

  • Access on need: whoever maintains opening hours needs no access to form messages containing names, phone numbers and requests. The editing role can be thought of separately from the mailbox.
  • Documented permissions: a list with person, role, date granted and date revoked. It doubles as the practical evidence for the accountability obligation in Article 5(2) (General Data Protection Regulation).
  • Delete old accounts: a deactivated login is an intermediate step, not an end state. Once the reasons for retention fall away the account is removed, not merely parked.
  • Instructions in writing: anyone in the business working with data from the website receives a short written instruction on what may be done with it. That is not a formality but exactly what paragraph 4 addresses.
  • Treat external people separately: an agency, a photographer, an intern — external logins get the view-only role as long as they do not need to write, and are created with an end date.

If an external service provider looks after or hosts the website, a second layer arrives: processing on behalf of the controller. Which agreements are needed and what belongs in the record of processing activities is described in the article on data processing agreements with website vendors. For the internal role question that changes nothing — on the contrary: the clearer it is internally who may do what, the easier it is to demonstrate to third parties that access is under control.

What this means for choosing the tool

A role model is only as good as the system that can represent it. If the website technically knows only one account, every rule ends as a statement of intent — and then the shared account is not carelessness but a constraint. That is why the question of roles and seats belongs before the decision, not after it. Which routes to your own website exist at all and how they differ in operation and collaboration is set out in the comparison of builder, agency and AI. How much structure a site needs in day-to-day operation is covered in the maintenance routine for small firms.

Roles instead of full access

XICflow separates ownership, administration, editing and view only. Staff maintain content without gaining access to the contract, the domain or the invoices.

Seats per plan

The plans include staggered editor seats — from one seat on the entry plan up to 25 on the largest. How many people can work on the site is therefore settled before booking.

Invite and revoke

Logins are granted by invitation to a personal email address and can be revoked individually, without anything changing for the remaining people.

Anyone weighing up a new website anyway should put the team question into the same calculation: a site only one person can change causes a permanent coordination overhead that appears in no quote. When the step pays off and which signs point to it is described in the article on when a new website pays off. What working in the editor actually looks like can be seen in the demos; which roles and seats are included in which plan is set out in the plan overview. And if you would like to talk your role setup through once, a short conversation via contact is usually faster than any template.

In the end, organising collaboration is unspectacular: four roles, a handful of approval-bound content types, personal logins, standing cover, one offboarding line and a plan on a single page. The effort arrives once. What disappears afterwards is the kind of effort nobody plans for: hunting for the password, reconstructing a change, and the call from a customer standing in front of a locked door because the opening hours have been wrong for three weeks.

Sources and studies

This article is based on data from: Federal Office for Information Security (BSI) — recommendations on handling passwords and creating secure passwords (8 to 12 characters with four character types, 20 to 25 characters with two character types, at least 20 characters for WPA2 and WPA3, a separate password per login, password managers, second factor) as well as the IT-Grundschutz Compendium, module ORP.4 on identity and access management; General Data Protection Regulation (Regulation (EU) 2016/679) — Article 32(1)(b) and Article 32(4) on security of processing and on processing under instructions, and Article 5(2) on accountability; Bitkom e. V. — study report Digitalisation of the Skilled Trades 2025 (n = 504 skilled-trades companies, telephone survey in calendar weeks 23 to 29 of 2025, weighted to be representative, margin of error plus/minus 4 per cent) and study report Economic Protection 2025 (n = 1,002 companies with ten or more employees, surveyed from mid-April to mid-June 2025); Federal Statistical Office of Germany (Destatis) — survey on the use of information and communication technologies in enterprises 2025 including its quality report (net sample of 20,000 reporting units, field work from March to mid-July 2025, response rate 24.6 per cent, companies with ten or more persons employed); Bavarian State Office for Statistics — regional results of the same survey for 2025.