Giving Benecaster Support Access to Your Site
Most support questions are answered without anyone touching your site. Occasionally a problem only reproduces in your own environment — a feed that renders correctly for us and not for you, a bridge that reports the wrong tier, a cron that never fires. When that happens we may ask for temporary access.
You are never obliged to grant it. If you would rather not, say so — we will keep working from logs and screenshots. It is slower, not impossible.
Try Support Mode First
Before granting anyone access, turn on Support Mode in Settings → Tools and use “Send diagnostic log to Benecaster support”. It captures your configuration, recent errors and the state of the subsystem you are having trouble with, and sends it to us with a reference number.
This resolves a good share of cases on its own, and it grants us nothing — no login, no access to your site. Start there. See Support Mode.
What We Ask For
A temporary WordPress administrator account that expires on its own.
Administrator sounds like a lot, and it is worth being straight about why it is necessary rather than asking you to take it on trust. Benecaster’s settings, feed diagnostics, subscriber screens and Tools panel all require the manage_options capability. An Editor or Shop Manager account cannot open any of them, so a lower role would let us log in and see nothing useful.
Self-expiring matters more than the role does. The risk in granting support access is not the hour we spend using it — it is the account still sitting there in six months. An account that expires on its own protects you even if we both forget.
Option 1 — Create a Temporary Admin User
Works on every WordPress site, needs no plugin, and nothing has to be installed for it.
- Go to Users → Add New
- Create a user with a role of Administrator. Use an address you control, such as
support+benecaster@yourdomain.com— not one of ours - Let WordPress generate the password. Do not email it to us — see below
- Send us the username only. We will use “Lost your password?” to set our own
- Delete the account when we tell you we are finished
Step 4 is the part people find surprising. It means the password is never in an inbox, a support ticket, or a chat log — the two places credentials most often leak from. We only ever hold a reset link that expires.
The trade-off with this route is step 5: nothing deletes the account for you. Put a reminder in your calendar for the same day.
Option 2 — A Passwordless Login Plugin
If you would rather not manage the account by hand, a temporary-login plugin does the same job and cleans up after itself. Several exist; they generate a one-off login link with an expiry date, and the access dies on its own when it lapses.
This is the more convenient route and usually the safer one, because expiry is automatic rather than remembered. We do not require a specific plugin and we do not endorse one — anything you install runs with full privileges on your site, so choose one you are comfortable with and check it is actively maintained.
Whichever you use, set the shortest expiry that is realistic. Three days is plenty for most issues, and you can always issue another link.
What We Will and Will Not Do
While we hold access:
- We will look at Benecaster settings, logs, feeds, subscriber records and anything needed to reproduce your issue
- We will tell you what we changed, if we changed anything
- We will ask first before altering content, settings or anything outside Benecaster
- We will not access your Stripe or membership plugin billing data beyond what Benecaster itself displays
- We will not install, activate or deactivate other plugins without asking
- We will tell you when we are done, so you can revoke
If you ever see activity on the account you did not expect, revoke it immediately and contact us. That is the correct response and no one will be offended by it.
Revoking Access
Temporary admin user: Users, select the account, Delete. WordPress will ask what to do with any content attributed to it — there will not be any, so “Delete all content” is safe.
Passwordless plugin: delete or expire the login link from the plugin’s screen. Deleting the plugin afterwards also works.
Either way, revoke as soon as the issue is resolved rather than leaving it until the expiry date. Access you are not using is access you are not watching.
What We Never Ask For
We will never ask for:
- Your benecaster.com account password
- Your hosting control panel or FTP credentials
- Payment details, card numbers, or your Stripe account login
- A password sent by email or chat
If you receive a message claiming to be from Benecaster asking for any of these, it is not from us. Forward it to us and do not reply to it.