Title: Nubocoder Agency Manager
Author: César Siancas
Published: <strong>October 10, 2026</strong>
Last modified: October 10, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/nubocoder-agency-manager.svg)

# Nubocoder Agency Manager

 By [César Siancas](https://profiles.wordpress.org/melkor1985/)

[Download](https://downloads.wordpress.org/plugin/nubocoder-agency-manager.0.1.1.zip)

 * [Details](https://wordpress.org/plugins/nubocoder-agency-manager/#description)
 * [Reviews](https://wordpress.org/plugins/nubocoder-agency-manager/#reviews)
 *  [Installation](https://wordpress.org/plugins/nubocoder-agency-manager/#installation)
 * [Development](https://wordpress.org/plugins/nubocoder-agency-manager/#developers)

 [Support](https://wordpress.org/support/plugin/nubocoder-agency-manager/)

## Description

When a developer or marketer joins an agency, they need an account on every client
site. When they leave, every one of those accounts must go. Doing it site by site
is slow and one forgotten account is a security risk.

Agency Manager keeps your team in one place and applies it to your client sites:

 * Define team members and teams (for example Developers or Marketing), each with
   the role it gets on client sites.
 * Give access to one or many people on one, several or all sites, with a review
   of every change before anything is sent.
 * Change roles, suspend, restore or remove accounts in bulk.
 * Retire a member: every account is removed or suspended, and sites that do not
   answer are retried until it is done. Their content goes to an agency service 
   account.
 * See who has access to what in the access matrix, including accounts whose role
   was changed on the site and administrators not managed by the agency.
 * Follow every change site by site, retry failures and read the tamper-evident 
   activity log.

Each client site needs the companion plugin Nubocoder Agency Manager Client.

#### Security

 * Every request to a client site is signed with a key pair dedicated to that site,
   is valid for five minutes and cannot be replayed. Responses are signed too.
 * Site keys are encrypted in the database with the NBAM_ENCRYPTION_KEY constant.
 * Client sites only let the agency change accounts it created; the site owner decides
   what the agency may do and can disconnect at any time.
 * Removing access and granting administrator roles ask for your password again.
   The owner is emailed about critical actions.
 * Dedicated capabilities, optional mandatory two-factor authentication and an emergency
   button that revokes every key.

Install the hub on a dedicated WordPress site with few plugins, not on the public
website of the agency.

### External services

This plugin does not use any third-party service. It only talks to the client sites
that you add in Agency Manager  Sites, which run the companion plugin Nubocoder 
Agency Manager Client. Nothing is sent until you add a site and its owner pastes
the connection key on that site.

 * When a client site connects, it sends its address, its REST endpoint, its public
   key and the client plugin version.
 * To show and apply access, the hub sends signed requests to each connected site:
   the login, email, first and last name and role of the team members you give access
   to, and the role changes, suspensions and removals you confirm.
 * Client sites answer with their WordPress and PHP versions, their name and address,
   their roles and number of users, and the login, email, role and post count of
   the accounts the agency manages there, plus the login, email and role of their
   administrators, so they appear in the access matrix.
 * When you disconnect a site or use Revoke all, the hub tells that site to forget
   the connection.

The data stays between your hub and your client sites. The hub also sends emails
about critical actions through wp_mail() of your own site.

### Third-party libraries

The plugin includes Action Scheduler (https://actionscheduler.org/, GPLv3 or later)
to run jobs in the background. The full source, including composer.json, is part
of the plugin.

## Installation

 1. Install and activate the plugin on the agency WordPress site.
 2. Add define( ‘NBAM_ENCRYPTION_KEY’, ‘…’ ); to wp-config.php. Agency Manager  Settings
    shows a ready to copy line.
 3. In Agency Manager  Sites, add a client site and copy its connection key.
 4. On the client site, install Nubocoder Agency Manager Client and paste the key in
    Settings  Agency Connection.
 5. Create your teams and members, then give access.

For reliable background jobs, run WP-Cron from a server cron job and set DISABLE_WP_CRON.

## FAQ

### Does the hub store passwords of client sites?

No. New accounts get a random password and, if you choose, an email to set their
own. The hub never receives passwords.

### What happens to posts of removed accounts?

They are reassigned to the agency service account configured in Settings, created
on each site with the Subscriber role.

### Can the agency delete accounts of the site owner?

No. The client plugin only changes accounts the agency created or linked, and never
removes the last administrator.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Nubocoder Agency Manager” is open source software. The following people have contributed
to this plugin.

Contributors

 *   [ César Siancas ](https://profiles.wordpress.org/melkor1985/)

[Translate “Nubocoder Agency Manager” into your language.](https://translate.wordpress.org/projects/wp-plugins/nubocoder-agency-manager)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/nubocoder-agency-manager/),
check out the [SVN repository](https://plugins.svn.wordpress.org/nubocoder-agency-manager/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/nubocoder-agency-manager/)
by [RSS](https://plugins.trac.wordpress.org/log/nubocoder-agency-manager/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.1

 * The Agency Manager menu now sits at the end of the admin menu instead of near
   the top.
 * Deactivation removes the Action Scheduler WP-Cron event, so WP-Cron no longer
   logs an error for it afterwards.

#### 0.1.0

 * First release: sites, teams, members, access grants, role changes, suspension,
   removal, retirement, access matrix, jobs and activity log.

## Meta

 *  Version **0.1.1**
 *  Last updated **1 day ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.9 or higher **
 *  Tested up to **7.1.3**
 *  PHP version ** 8.1 or higher **
 * Tags
 * [access management](https://wordpress.org/plugins/tags/access-management/)[agency](https://wordpress.org/plugins/tags/agency/)
   [multiple sites](https://wordpress.org/plugins/tags/multiple-sites/)[team](https://wordpress.org/plugins/tags/team/)
   [users](https://wordpress.org/plugins/tags/users/)
 *  [Advanced View](https://wordpress.org/plugins/nubocoder-agency-manager/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/nubocoder-agency-manager/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/nubocoder-agency-manager/reviews/)

## Contributors

 *   [ César Siancas ](https://profiles.wordpress.org/melkor1985/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/nubocoder-agency-manager/)