Use Case

Secure SEO Client Onboarding & Website Access

Collect the CMS, hosting, and DNS logins that delegation can't cover through an end-to-end encrypted intake, not a Slack DM or a shared doc. Secure client access onboarding for SEO and marketing agencies.

Onboard SEO Clients Securely

Clients paste passwords into Slack, email, and docs

A WordPress admin password in a Slack DM. FTP details in a Google Doc. Those credentials live in plaintext forever, readable by anyone with access to the thread.

Access requests take weeks of back-and-forth

Search Console and Analytics you get by having the client add your email. But the CMS, hosting, and DNS logins still arrive one at a time across email threads, delaying the start and frustrating the client.

Non-technical clients don't know what to send

Ask a small-business owner for 'SFTP credentials' and you get a blank stare. Unstructured requests produce wrong, partial, or unusable answers.

No record of who holds which credential

When a contractor rotates off or an engagement ends, you can't prove what access existed or that it was handled properly.

1

Send one structured access request

A single branded intake asks for the setup details (website URL, CMS platform, the Google account to grant analytics access to) and the credentials delegation can't cover: CMS admin, hosting, and DNS, all encrypted.

2

The client fills it in — guided, not guessing

Clear labels and examples tell a non-technical client exactly what each field is. Sensitive credentials are encrypted in their browser before they're sent.

3

You receive access, isolated per client

Each client's credentials live in their own project. You decrypt what you need, when you need it, with every access timestamped.

4

Rotate and revoke on handoff

When the engagement ends or a team member changes, you have a documented record of every credential to rotate or hand back.

  • —CMS, hosting, and DNS credentials encrypted end-to-end — never in Slack or email
  • —One structured request replaces weeks of access chasing
  • —Clear field labels make it easy for non-technical clients
  • —Each client's access isolated in its own project
  • —Full audit trail for every credential accessed
  • —No account required — the client just opens the link

Every SEO engagement starts with a pile of credentials. Most of them arrive in the least safe way possible.

You sign a client. Search Console and Analytics you get the right way, by having them add your email as a user. But the CMS admin, the hosting panel, and DNS are still passwords, and the client does the natural thing: they paste the WordPress login into a Slack DM, drop the FTP details into a shared Google Doc, email you the Cloudflare password.

Now those site logins sit in plaintext across three tools, readable by anyone in those threads, with no expiration and no record of who opened what. For an agency handling twenty clients, that's twenty sets of exposed logins you're quietly liable for. There's a structured way to collect them at once, encrypted.

What you'll collect

One request covers onboarding. The credential fields are encrypted end-to-end in the client's browser; the setup details go in plainly:

  • Company / brand name and primary website URL
  • The Google account to grant Search Console, Analytics, and Tag Manager access to (you send the invite, so no password changes hands)
  • Website platform / CMS, and which Google and Bing tools are already set up
  • CMS admin login (URL, username, password)
  • Hosting, DNS, registrar, and CDN logins
  • Top competitors and target keywords

Running a deep technical audit? The same request extends to server-level access, SFTP / FTP / SSH and log files, for redirects, robots.txt, and crawl analysis.

How the intake flow works

When a client signs: Create a project for them and send your standard SEO access request. It opens as a branded page with your agency's name, not a generic form.

They hand over access — safely: Non-sensitive details (URL, CMS, which Google tools exist) go in plainly. The credential fields (CMS admin, hosting, DNS) are encrypted in the client's browser before they're sent. We store ciphertext. Clear labels and examples mean even a non-technical client fills them in correctly instead of guessing.

You start work: Open the submission in that client's project, decrypt exactly what you need, and go. Every access is timestamped.

What your client experiences

A link, a guided form, a submit button. No account, no app, no jargon they don't understand. For a client who's nervous about handing over their website keys, watching the form say the credentials are encrypted on their own device is the reassurance that gets them to actually complete it.

Isolation, rotation, and the handoff

Client A's credentials are in Client A's project. Your strategist assigned to Client A doesn't automatically see Client B. When an engagement ends, or a freelancer rotates off, the project's audit trail is your checklist of exactly which credentials to rotate or return. That's how you scale to twenty clients without one mistake costing a relationship.

For the underlying capabilities, explore Secure Requests and Workspaces & Projects.

Handle sensitive client information securely — from onboarding to handoff. Try any workspace free for 3 days — no credit card required.

Onboard SEO Clients Securely