Understand the built-in role behavior
- Administrator: can manage vehicles and site-wide configuration, including plugins, themes, Setup, updates, Inventory settings, Shopper Tools, and Sync.
- Editor: receives LotPress vehicle capabilities and can create, edit, publish, delete, and organize vehicles, manage vehicle terms, review Inventory Overview, and arrange Vehicle Display.
- Author, Contributor, and Subscriber: do not receive vehicle-management access from their ordinary post permissions.
LotPress grants its dedicated vehicle capabilities to the Administrator and Editor roles during activation or capability migration. Existing custom roles are not modified automatically.
Keep sensitive configuration administrator-only
The following areas require the WordPress manage_options capability or additional administrator capabilities:
- LotPress Setup and component installation or repair.
- LotPress Website Settings and Inventory permalink settings.
- LotPress Sync connections, credentials, mapping, reconciliation, schedules, and missing-vehicle policy.
- Shopper Tools settings, recipient email, calculator defaults, and Turnstile credentials.
- LotPress Manager license connection and private updates.
- Plugin installation, theme switching, user administration, and broader WordPress settings.
Do not promote an inventory employee to Administrator only so they can edit vehicles. Use Editor or a tested custom role instead.
Use the dedicated vehicle capabilities
Custom dealership roles can be granted the LotPress capability set through a trusted role-management plugin or site-specific code:
edit_lotpress_vehicle
read_lotpress_vehicle
delete_lotpress_vehicle
edit_lotpress_vehicles
edit_others_lotpress_vehicles
publish_lotpress_vehicles
read_private_lotpress_vehicles
delete_lotpress_vehicles
delete_private_lotpress_vehicles
delete_published_lotpress_vehicles
delete_others_lotpress_vehicles
edit_private_lotpress_vehicles
edit_published_lotpress_vehicles
create_lotpress_vehicles
manage_lotpress_vehicle_termsGrant only the capabilities the role genuinely requires. For example, a role that may edit its own drafts does not necessarily need to publish, delete published vehicles, edit other users’ vehicles, or manage makes and models.
Choose a dealership access model
- Owner or accountable manager: one named Administrator who approves vendors, billing, recovery, and major configuration.
- Website administrator: a named Administrator responsible for WordPress, LotPress settings, updates, backups, email delivery, and Sync configuration.
- Inventory manager: Editor or a custom role allowed to manage all vehicles, vehicle terms, photos, publishing, and Vehicle Display.
- Inventory assistant or salesperson: a custom role limited to creating or editing appropriate vehicle records; publishing and deletion can remain with the inventory manager.
- Outside developer or agency: a named, time-bounded account with only the access required for the contracted task; remove or downgrade it when the engagement ends.
Small dealerships may combine responsibilities, but each person should still use an individual account so actions can be attributed and access can be removed without disrupting someone else.
Protect accounts and service credentials
- Never share one Administrator login among employees or vendors.
- Use unique passwords and enable multi-factor authentication with a maintained WordPress security or identity solution.
- Keep license keys, feed URLs and passwords, SFTP host fingerprints, SMTP credentials, Turnstile secrets, hosting access, DNS access, and backup encryption keys restricted to responsible administrators.
- Do not paste secrets into public support posts, screenshots, issue trackers, analytics tools, or source control.
- Avoid sending reusable credentials through ordinary email or chat; use the organization’s approved credential-sharing method.
- Review Administrator accounts and active sessions regularly.
Test a role before assigning staff
- Create a temporary test account with the proposed role. Do not reuse a real employee account.
- Sign in with a separate private browser session.
- Confirm the user can see only the intended WordPress menus.
- Create a draft vehicle, add photos, decode a test VIN if appropriate, edit fields, and preview the listing.
- Test publishing, editing other users’ vehicles, deleting, restoring, managing terms, viewing insights, and arranging Vehicle Display according to the role design.
- Confirm the account cannot reach Setup, Sync, Shopper Tools settings, LotPress Updates, plugin installation, theme controls, user administration, or unrelated site settings unless those permissions were deliberately granted.
- Delete the test content and remove the temporary account after approval.
Re-test custom roles after changing role plugins, authentication systems, or capability-related code.
Handle staff and vendor turnover
- Disable or remove access promptly when a person changes duties or leaves.
- Before deleting a WordPress user, attribute their content to an appropriate continuing account.
- End active sessions and remove application passwords, recovery access, hosting accounts, and vendor access that belonged to that person.
- Rotate shared service credentials the person could view, including feed, SMTP, DNS, hosting, backup, and security-provider credentials.
- Review recent vehicle, user, plugin, theme, update, and configuration changes when the departure was unexpected.
- Keep a current list of who owns the domain, hosting, backups, transactional email, feed relationship, and LotPress administration.