Chykalophia Docs
Give us access

How to revoke our access later

A step-by-step guide to securely removing our access when a project ends.

Time
5 minutes
Difficulty
Beginner

At Chykalophia, we believe a true strategic partnership means putting your security first. When our project engagement concludes — and if you are not moving into The Boring Stuff or a Fractional retainer — it is best practice to revoke our access to your systems.

Quick summary

Because we request delegate access (where you invite support@chykalophia.com as a user), you remove us the same way you would remove anyone else. You keep complete ownership of your accounts. Every tool words the button differently — remove, delete, revoke — so the exact steps for each one are below.

The offboarding access checklist

When our work is complete, our team securely deletes any stored project credentials from our encrypted internal password manager.

However, it is always the account owner's (your) responsibility to revoke the active invitations. Use this checklist to ensure you've closed all the doors:

1. Your Website Backend

  • WordPress: Go to Users → All Users. Hover over the Chykalophia account and click Delete. WordPress then asks what should be done with the content owned by that user: choose Attribute all content to another user, pick your own admin account, and click Confirm Deletion.
  • Webflow: In your Workspace settings, open the members list, click the options icon next to our name and choose Remove from Workspace. Webflow asks you to type REMOVE to confirm.
  • Shopify: Go to Settings → Users (labeled Users & permissions if your store isn't part of an organization), click our name, click Remove collaborator account, then confirm with Remove.
  • Squarespace: Go to Settings → Permissions & Ownership and click our name under Contributors. Click ..., then Remove Contributor, and confirm. (Any blog posts we wrote will then be credited to a basic author called "Guest User", which you can rename or reassign.)

2. Your Hosting Environment

Every host puts this in a slightly different place:

  • WP Engine: open Users → Account Users in your User Portal, click Edit next to our name, click Remove, then Confirm.
  • Flywheel: on the site's collaborator list, hover over the 3-dot menu next to our name and click Remove. Flywheel collaborators are granted per site, so check every site you invited us to.
  • Kinsta: click your username → Company settings → Users, then the trash icon next to our name, and confirm with Remove user. If you only gave us access to one site, you can remove us from that site's User management page instead.

Removing a hosting user doesn't reset everything

Two of these hosts spell this out. WP Engine says that deleting an account user "does not delete WordPress users or modify SFTP users they have access to". Kinsta says removing a user "does not automatically revoke access to any API keys they may have used", and that database and SSH/SFTP passwords are not reset either. So after removing us, check your WordPress users, your SFTP or SSH users, and any API keys.

3. Your Domain & DNS

  • GoDaddy: open your GoDaddy Delegate Access page. In the People who can access my account section, select Edit next to our name, then select Delete underneath the Save button.
  • Namecheap: open Domain List → Manage for the domain, go to the Sharing & Transfer tab and find Share Access. Open the Edit dropdown next to our name, choose Remove, then click Done.
  • Cloudflare: go to Manage Account → Members, expand our record, click Revoke, then Yes, revoke access. You need the Super Administrator role to do this.

4. Google Tools & Analytics

  • Google Analytics: Go to Admin, then under Property open Property access management, select our email, and remove access.
  • Google Search Console: Open the property, go to Settings → Users and permissions (visible only if you're a property owner), then use the menu next to our name and click Remove access. If Search Console warns that the user might regain access, remove the ownership tokens it lists.
  • Google Tag Manager: Click Admin, then select User Management in the Container column (and in the Account column too, if you gave us account-level access). Select our entry, click Remove, then Save.

5. Third-Party Integrations

  • Did you invite us to your Stripe, Mailchimp, or CRM? Check the user settings in those platforms and revoke the permissions. In Stripe that's Team and security → Team: use the menu in our row, or open our profile and click Remove member.
  • If we generated API keys for any integration, removing our user login does not disable them. Stripe's own advice is to rotate keys when someone with access to them leaves, so ask us which keys are in play and plan the swap.

What if I shared a raw password with you?

If a platform didn't support delegate access and you had to share a raw password securely with us, we will delete that password from our secure vault at the end of the project.

However, as a matter of standard digital security hygiene, you should log into that platform and change your password once the project is over.

Staying on for The Boring Stuff or a Fractional retainer?

If you are transitioning into The Boring Stuff or a Fractional CTO/CMO retainer, do not revoke our access! We will need continued access to your WordPress dashboard, hosting, and DNS to run proactive updates, monitor security, and execute ongoing strategic improvements.

Need a hand?

If you're stuck, email support@chykalophia.com and we'll help. Include your website address and a screenshot if you can.

Last updated

On this page