{"id":75184,"date":"2026-10-06T00:20:49","date_gmt":"2026-10-06T06:20:49","guid":{"rendered":"https:\/\/www.scalahosting.com\/blog\/?p=75184"},"modified":"2026-10-06T03:25:40","modified_gmt":"2026-10-06T09:25:40","slug":"five-spanel-team-access-settings","status":"publish","type":"post","link":"https:\/\/www.scalahosting.com\/blog\/five-spanel-team-access-settings\/","title":{"rendered":"Five SPanel Settings to Lock Down Team Access Today"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Tighten SPanel team access in five moves: stop sharing passwords and give each team member their own account, trim each one&#8217;s permissions page by page, turn on two-factor authentication, put an expiration date on every API token, and restrict admin logins to known IPs under Control Panel Access. Then skim the activity log monthly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Shared logins represent an enormous risk for small businesses. The more you grow, the more people you&#8217;ll have working on the website. Developers, designers, and marketing specialists will all need access to your hosting account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The easiest option is to simply share your password with all of them. However, the problems are bound to start almost immediately. When something breaks, for example, you can&#8217;t tell who did what. And when someone leaves, you have to change the password and give the new login to all team members. If you don&#8217;t do it, you&#8217;re putting your business at risk. If you forget to share the new password with someone from your team, you&#8217;re disrupting the workflow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SPanel gives you the pieces to fix this in a few simple steps. Today, we&#8217;re looking at the five settings worth changing first: why each one matters, where it lives, and how it should all look in the end.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Why Bother Locking Down Team Access at All?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most account compromises don&#8217;t start with a clever exploit. Software vulnerabilities are not to be underestimated, but in most cases, we&#8217;re talking about a simple password. It could be reused, guessed, phished, or left with a former employee. Whatever the case, a compromised shared password equals a compromised hosting account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fix: give each person their own login, scoped to what their job needs and protected by a second factor. It&#8217;s called the principle of least privilege: the access a job requires and nothing more. Every control below is available on ScalaHosting&#8217;s managed VPS plans.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On many panels, per-seat access and audit logging sit behind a paid tier or an add-on. On SPanel, all of it is standard on every managed VPS plan: separate admin accounts, page-level permissions, server-wide 2FA, and the activity log. The log itself lives on ScalaHosting&#8217;s control server, not on your hosting account, so a compromised site can&#8217;t rewrite the record of who did what.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SPanel has two interfaces. The <strong>Admin Interface<\/strong> is the server-wide layer for hosting accounts, packages, and server settings. The <strong>User Interface<\/strong> is the per-account layer where one account&#8217;s email, databases, domains, and files live. The team access features we&#8217;ll look into today are designed to protect both. Let&#8217;s go through the steps.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>1. Replace the Shared Login With Per-Person Accounts<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The single most valuable change: stop sharing one login. In the Admin Interface, go to <strong>Server Management \u2192 Manage Admin Users<\/strong> and use the <strong>Create Admin User<\/strong> form to give each administrator their personal login. They&#8217;ll still have access to the tools they need to manage the server, but instead of using your username and password, they&#8217;ll have their own credentials.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A similar mechanism can be found within every account you create on your VPS. From the User Interface homepage, open <strong>Manage Users<\/strong> and click <strong>Add a New User<\/strong>. You can create a new sub-user for everyone who needs to manage the files, databases, email inboxes, etc. associated with the website hosted on the current account.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><img decoding=\"async\" width=\"1140\" height=\"713\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image1-1140x713.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 1. Replace the Shared Login With Per-Person Accounts\" class=\"wp-image-75186\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image1-1140x713.webp 1140w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image1-300x188.webp 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image1-768x480.webp 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image1.webp 1440w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">In the end, everyone who has access to SPanel has their own login. If you&#8217;ve shared your password with the team up until now, you must change it and keep it to yourself. When someone leaves, you delete their account and ensure they can no longer work on your project.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>2. Trim Each Person&#8217;s Permissions to the Pages They Actually Use<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Creating the account is only half the job. The other half is deciding what the user can reach. The <strong>principle of least privilege<\/strong> is the rule to follow here: give each account only the access its role requires, and nothing more.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">SPanel has a permissions system that grants access page by page. There&#8217;s no job title to pick&nbsp; off a menu. On the <strong>Create Admin User<\/strong> screen, permissions appear as a grid of page checkboxes grouped under <strong>Accounts Management, Server Management, Software,<\/strong> and <strong>Cluster Management<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sub-users work identically in the User Interface, with categories for <strong>Email<\/strong>, <strong>MariaDB Databases<\/strong>, <strong>Settings<\/strong>, <strong>Domains<\/strong>, <strong>Files<\/strong>, <strong>Tools<\/strong>, and <strong>Software<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><img decoding=\"async\" width=\"1140\" height=\"713\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image3-1140x713.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 2. Trim Each Person&#8217;s Permissions to the Pages They Actually Use\" class=\"wp-image-75187\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image3-1140x713.webp 1140w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image3-300x188.webp 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image3-768x480.webp 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image3.webp 1440w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Bear in mind that these are per-user, page-level grants, not named roles. SPanel doesn&#8217;t ship preset role bundles you assign by title. Instead, you compose each person&#8217;s page set by hand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.spanel.io\/docs\">SPanel API documentation<\/a> describes the same structure if you&#8217;d rather automate it.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>3. Turn On Two-Factor Authentication<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every password is just one phishing email away from being stolen. Two-factor authentication (2FA) adds a second proof, a rotating code from an authenticator app. When 2FA is enabled, the code must be provided during login, meaning a stolen password is no longer enough to compromise an account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In SPanel the control lives in <strong>both<\/strong> interfaces under <strong>Profile Settings \u2192 Login Security \u2192 Two-Factor Authentication (2FA)<\/strong>. It uses TOTP (Time-based One-Time Password) generated by a 2FA app like Google Authenticator, the kind of second factor recommended by <a href=\"https:\/\/pages.nist.gov\/800-63-3\/sp800-63b.html\">NIST&#8217;s digital identity guidelines<\/a>. Our full walkthrough covers <a href=\"https:\/\/www.scalahosting.com\/blog\/two-factor-authentication-in-spanel\/\">enabling two-factor authentication in SPanel<\/a> step by step.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><img decoding=\"async\" width=\"1140\" height=\"713\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image2-1140x713.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 3. Turn On Two-Factor Authentication\" class=\"wp-image-75188\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image2-1140x713.webp 1140w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image2-300x188.webp 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image2-768x480.webp 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image2.webp 1440w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">As a server owner, you can force people with SPanel access to use 2FA. In SPanel&#8217;s Admin Interface, go to <strong>Server Settings<\/strong> and scroll down to the <strong>Security Settings<\/strong> section. You&#8217;ll see three toggle switches: the first one enables two-factor authentication server-wide, and the other two enforce it for admins and users, respectively.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If you switch them on, team members will have to set up 2FA on their phones the next time they try to log in to SPanel. When enabling two-factor authentication for users, you&#8217;re also affecting sub-users on SPanel&#8217;s User Interface, as well as email account owners.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full mpg-gallery\"><img decoding=\"async\" width=\"478\" height=\"148\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image5.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 3. Turn On Two-Factor Authentication 2\" class=\"wp-image-75189\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image5.webp 478w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image5-300x93.webp 300w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">Ultimately, your company policy must determine whether 2FA is enforced across all SPanel accounts. Given how useful it is as a security mechanism, however, considering enabling it for people with access to the most vital tools is a good idea.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>4. Put an Expiration Date on Your API Tokens<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you automate anything (provisioning, syncing, scripts, etc.), you&#8217;re using API tokens, and a token with no expiry is a key that works forever. You generate them at <strong>Server Management \u2192 Manage API Tokens<\/strong> via the <strong>Create API Token<\/strong> button.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">At the top of the form, you have a couple of radio buttons that let you decide whether the token will access SPanel&#8217;s Admin or User interface. Once you click the correct one, you&#8217;ll see a <strong>Token Privileges<\/strong> section listing the SPanel utilities the token will have access to.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There&#8217;s also an <strong>Expiration date<\/strong> toggle, allowing you to choose when the token will become invalid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By default, the Expiration date toggle is turned off, and the token privileges are set to <strong>Unrestricted<\/strong>, meaning if you don&#8217;t configure it manually, the API token will have access to all the tools in the chosen interface and will be valid forever.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Think about what you&#8217;ll use the token for and how long you&#8217;ll need it. Make sure you set the privileges and expiration date accordingly. The principle of least privilege applies to API tokens in the same way it does for users, and having valid tokens that are obsolete is a risk that simply isn&#8217;t worth taking.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><img decoding=\"async\" width=\"1140\" height=\"713\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image4-1140x713.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 4. Put an Expiration Date on Your API Tokens\" class=\"wp-image-75190\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image4-1140x713.webp 1140w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image4-300x188.webp 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image4-768x480.webp 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image4.webp 1440w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>5. Restrict Admin Logins to Known IP Addresses<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If your team accesses SPanel from an office and a couple of home addresses, there&#8217;s no need for the login page to be available on every computer in the world. SPanel can limit logins by source IP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Open <strong>Server Management \u2192 Server Settings<\/strong> and find the <strong>Control Panel Access<\/strong> section. Tick <strong>Enable Access Control<\/strong> and add your trusted addresses to the <strong>IP Whitelist<\/strong> (IPv4 entries). It&#8217;s off by default, and if you remove your own current IP from the list, SPanel warns you that you might lock yourself out.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large mpg-gallery\"><img decoding=\"async\" width=\"1140\" height=\"713\" src=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image6-1140x713.webp\" alt=\"Five SPanel Settings to Lock Down Team Access Today, 5. Restrict Admin Logins to Known IP Addresses\" class=\"wp-image-75191\" srcset=\"https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image6-1140x713.webp 1140w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image6-300x188.webp 300w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image6-768x480.webp 768w, https:\/\/www.scalahosting.com\/blog\/wp-content\/uploads\/2026\/10\/image6.webp 1440w\" sizes=\"(max-width: 361px) 660px, (max-width: 767px) 89vw, (max-width: 1000px) 54vw, (max-width: 1071px) 910px, 1140px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">You can add multiple IPs and ensure SPanel is accessed only from trusted sources. Don&#8217;t forget to click the <strong>Apply<\/strong> button when you&#8217;re ready.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Five Settings at a Glance<\/strong><\/h2>\n\n\n\n<figure class=\"wp-block-table is-style-regular green-rows\"><table class=\"has-fixed-layout\"><thead><tr><th>Setting<\/th><th>Location<\/th><th>Correct configuration<\/th><\/tr><\/thead><tbody><tr><td>Per-person accounts<\/td><td>Admin Interface \u2192 Manage Admin Users \/ User Interface \u2192 Manage Users<\/td><td>One login per person, no shared passwords<\/td><\/tr><tr><td>Trimmed permissions<\/td><td>Create Admin User \/ Add a New User grid<\/td><td>Each login reaches only the pages it needs<\/td><\/tr><tr><td>Two-factor authentication<\/td><td>Profile Settings \u2192 Login Security \u2192 2FA<\/td><td>Login needs a password plus an app code<\/td><\/tr><tr><td>API token expiration<\/td><td>Manage API Tokens \u2192 Create API Token<\/td><td>Tokens have the correct privileges and a set expiration date<\/td><\/tr><tr><td>IP access restriction<\/td><td>Server Settings \u2192 Control Panel Access<\/td><td>Admin logins limited to known IPs<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Make It a Habit: Skim the Activity Log Monthly<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Locking things down once is good; noticing when something&#8217;s off is better. SPanel records the actions performed in the interface, stored centrally on the control server, off your own hosting account. In the Admin Interface, the <strong>Admin Activity Logs<\/strong> page shows a timestamp, source IP, admin username, and action for each event. You can view this record; you can&#8217;t delete it, which is exactly what you want from a record of who did what.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It isn&#8217;t a tamper-proof audit system, and there&#8217;s no log export or SIEM feed; it&#8217;s a log you read. Put a monthly reminder on your calendar. Five minutes catches the &#8220;wait, who logged in from there?&#8221; moments while they still matter.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Lock It Down Before You Need To<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">If you change only one thing from this list, retire the shared login. Every other control here, from trimmed permissions to a second factor to expiring tokens, only starts working once you can tell one person&#8217;s actions from another&#8217;s. Setting all five up is a single sitting&#8217;s work. Untangling who did what after a shared password leaves with a former contractor is not.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Every one of these controls ships on <a href=\"https:\/\/www.scalahosting.com\/managed-cloud-hosting.html\">every ScalaHosting managed VPS plan<\/a>, with no per-seat fees and no security add-on to buy. Put the whole checklist in place on a real account today.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>FAQ<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Can I have more than one admin in SPanel?<\/strong>\u00a0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> Yes. SPanel supports multiple admin accounts in the Admin Interface, each restricted to exactly which pages and actions it can use. Create them under Server Management \u2192 Manage Admin Users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Does SPanel have named roles like &#8220;Editor&#8221; or &#8220;Billing Admin&#8221;?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> Not as named roles. SPanel gives you per-user, page-level permission grants; you choose the exact tools each admin or sub-user can use. It&#8217;s the control you get from preset roles, but much more granular.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>How do I give a client access to only their email?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> In that account&#8217;s User Interface, open Manage Users, add a new user, and check only the email permissions. They manage their mailboxes and forwarders, and never see the databases, files, or DNS utilities. It&#8217;s the same scoped access that makes SPanel practical for <a href=\"https:\/\/www.scalahosting.com\/hosting-for-agencies.html\">agencies running multiple client sites<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Does SPanel support two-factor authentication, and can I force my team to use it?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> 2FA is supported in both interfaces under Profile Settings \u2192 Login Security, using an authenticator app (TOTP). From the Server Settings page in the Admin Interface, you can enforce 2FA for both admins and users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Do SPanel API tokens expire?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> Expiration is optional; the Create API Token form has a toggle that is disabled by default. Turn it on and pick an Expiration date. You can also scope a token to specific API endpoints on the same form.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Can I restrict admin logins to specific IP addresses?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong> Yes. In Server Settings \u2192 Control Panel Access, enable Access Control and add your trusted addresses to the IP Whitelist. It&#8217;s off by default, and the form warns before you remove your own current IP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Q:<\/strong> <strong>Where are the activity logs kept, and can I export or delete them?<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A:<\/strong>\u00a0They&#8217;re stored centrally on SPanel&#8217;s control server, away from your own hosting server. You can view them under Admin Activity Logs but can&#8217;t delete them, and there&#8217;s no log export or SIEM feed today. If that&#8217;s on your wishlist, raise it on ScalaHosting&#8217;s public <a href=\"https:\/\/features.spanel.io\">feature board<\/a>.<\/p>\n\n\n\n<script type=\"application\/ld+json\">\n    {\n      \"@context\": \"https:\/\/schema.org\",\n      \"@type\": \"FAQPage\",\n      \"mainEntity\": [{\n        \"@type\": \"Question\",\n        \"name\": \"Can I have more than one admin in SPanel?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. SPanel supports multiple admin accounts in the Admin Interface, each restricted to exactly which pages and actions it can use. Create them under Server Management \u2192 Manage Admin Users.\"\n        }\n      }, {\n        \"@type\": \"Question\",\n        \"name\": \"Does SPanel have named roles like 'Editor' or 'Billing Admin'?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Not as named roles. SPanel gives you per-user, page-level permission grants; you choose the exact tools each admin or sub-user can use. It's the control you get from preset roles, but much more granular.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"How do I give a client access to only their email?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"In that account's User Interface, open Manage Users, add a new user, and check only the email permissions. They manage their mailboxes and forwarders, and never see the databases, files, or DNS utilities. It's the same scoped access that makes SPanel practical for agencies running multiple client sites.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"Does SPanel support two-factor authentication, and can I force my team to use it?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"2FA is supported in both interfaces under Profile Settings \u2192 Login Security, using an authenticator app (TOTP). From the Server Settings page in the Admin Interface, you can enforce 2FA for both admins and users.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"Do SPanel API tokens expire?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Expiration is optional; the Create API Token form has a toggle that is disabled by default. Turn it on and pick an Expiration date. You can also scope a token to specific API endpoints on the same form.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"Can I restrict admin logins to specific IP addresses?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"Yes. In Server Settings \u2192 Control Panel Access, enable Access Control and add your trusted addresses to the IP Whitelist. It's off by default, and the form warns before you remove your own current IP.\"\n        }\n      },{\n        \"@type\": \"Question\",\n        \"name\": \"Where are the activity logs kept, and can I export or delete them?\",\n        \"acceptedAnswer\": {\n          \"@type\": \"Answer\",\n          \"text\": \"They're stored centrally on SPanel's control server, away from your own hosting server. You can view them under Admin Activity Logs but can't delete them, and there's no log export or SIEM feed today. If that's on your wishlist, raise it on ScalaHosting's public feature board.\"\n        }\n      }]\n    }\n<\/script>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Tighten SPanel team access in five moves: stop sharing passwords and give each team member their own account, trim each &#8230;<\/p>\n","protected":false},"author":113,"featured_media":75185,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_titles_title":"SPanel Team Access: 5 Settings to Lock Down %%sep%% %%sitetitle%%","_seopress_titles_desc":"Tighten SPanel team access in five steps: per-person logins, scoped permissions, 2FA, expiring API tokens, and IP whitelisting. See how it's done.","_seopress_robots_index":"","_seopress_robots_follow":"","_seopress_robots_imageindex":"","_seopress_robots_snippet":"","_seopress_robots_primary_cat":"","_seopress_robots_breadcrumbs":"","_seopress_robots_freeze_modified_date":"","_seopress_robots_custom_modified_date":"","_seopress_robots_canonical":"","_seopress_social_fb_title":"","_seopress_social_fb_desc":"","_seopress_social_fb_img":"","_seopress_social_fb_img_attachment_id":0,"_seopress_social_fb_img_width":0,"_seopress_social_fb_img_height":0,"_seopress_social_twitter_title":"","_seopress_social_twitter_desc":"","_seopress_social_twitter_img":"","_seopress_social_twitter_img_attachment_id":0,"_seopress_social_twitter_img_width":0,"_seopress_social_twitter_img_height":0,"_seopress_redirections_value":"","_seopress_redirections_enabled":"","_seopress_redirections_enabled_regex":"","_seopress_redirections_logged_status":"","_seopress_redirections_param":"","_seopress_redirections_type":0,"_seopress_analysis_target_kw":"","_seopress_news_disabled":"","_seopress_video_disabled":"","_seopress_video":[],"_seopress_pro_schemas_manual":[],"_seopress_pro_rich_snippets_disable_all":"","_seopress_pro_rich_snippets_disable":[],"_seopress_pro_schemas":[],"footnotes":""},"categories":[125],"tags":[],"class_list":["post-75184","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-spanel"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/75184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/users\/113"}],"replies":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/comments?post=75184"}],"version-history":[{"count":3,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/75184\/revisions"}],"predecessor-version":[{"id":75195,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/posts\/75184\/revisions\/75195"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/media\/75185"}],"wp:attachment":[{"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/media?parent=75184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/categories?post=75184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.scalahosting.com\/blog\/wp-json\/wp\/v2\/tags?post=75184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}