What a Delegate Account Is For

KB-3.7 · 1 min · Updated September 2026

Managing a domain portfolio often means more than one person needs some level of access to it: a developer who needs to edit DNS records, a client who should see only their own domains, or staff who handle renewals but shouldn't be able to transfer domains out. Handing over your primary account's full login to each of these people isn't a good solution; it gives away more access than necessary and makes it impossible to tell whose actions were whose.

A delegate account solves this by creating a separate, permissioned login tied to your account, scoped to only the access you choose to grant, rather than sharing your own credentials or granting blanket access.

Granting delegate access involves two separate choices: an access level that controls which domains it can touch (All Domains & Categories, Specific Domains, or Specific Categories), and a permission level that controls what it can do within that scope (Manage DNS, or Full Access, which excludes billing or ownership rights). The person you're delegating to has to accept the invitation from their own account before access takes effect.

NameBright's own delegate accounts keep the highest-risk actions locked to the primary account no matter what access level or permission level is granted: a delegate account can never transfer a domain out, push it to another account (moving a domain between two NameBright accounts, a separate action from an external transfer), or delete it. A delegate account also doesn't get its own shopping cart; any purchase still runs through the primary account.

Related