Auto-Expiry
Smart Detector
Time-limited access is one of the most requested and least provided features in WordPress access control. The need arises constantly — you need to give a developer temporary admin access, an author needs to publish posts just for this week, a freelancer needs to configure a plugin setting but shouldn’t have permanent elevated permissions. The standard WordPress approach is to manually grant the access, then manually remember to remove it — a process that fails regularly, leaving elevated permissions in place indefinitely.
DominoRole provides two distinct time-limited access systems: Temporary Roles (assign a complete role for a period, then auto-restore original roles) and Temporary Permissions (grant a single specific capability to a user for a defined time, without touching their role). Both systems feature automatic expiry with real-time status tracking — making DominoRole the only comprehensive wordpress user role manager that solves time-limited access natively. This article also covers the Smart Capability Detector — which ensures you always know what new permissions are available to assign, temporarily or permanently.
Temporary Roles: Complete Role with Auto-Expiry
A Temporary Role assigns a complete WordPress role to a user for a defined time period — after which the user’s original role configuration is automatically restored. Key characteristics:
- Complete role inheritance: The user inherits all capabilities of the assigned temporary role during the active period
- Original role preservation: The user’s original roles are stored in user meta before the temporary role is assigned
- Automatic restoration: At expiry time, DominoRole removes the temporary role and restores the stored original roles without any manual action
- Datetime precision: Expiry is set to the exact minute using a datetime picker — useful for giving someone access from 9 AM to 5 PM on a specific date, or exactly 48 hours from now
💻 Freelance Developer
Temporary Administrator role for 48 hours to fix a site issue. Expires automatically — no risk of forgotten elevated access.
🎓 Intern Review Period
Temporary Editor role for a month while an intern is being evaluated. After the trial period expires, they revert to Author automatically.
🎉 Event Coverage
Temporary Shop Manager role for a guest blogger covering a product launch event for 24 hours, with full WooCommerce access during that window.
Temporary Permissions: Single-Capability Granular Control
While Temporary Roles assign an entire role, Temporary Permissions are more surgical: they grant a single specific WordPress capability to a specific user for a defined time period, without modifying their role at all.
This is handled by the Temporary Permissions module (DominoRole → Temporary Permissions). The creation workflow:
- Select the user from the user dropdown
- Select the specific capability to grant (from the full list of capabilities on your site)
- Set the expiry date and time with the datetime picker
- Save — the temporary permission is stored in the database with the user ID, capability, and expiry timestamp
At runtime, DominoRole uses WordPress’ user_has_cap filter to dynamically inject the granted capability into the user’s capability set if the current time is before the expiry timestamp. When the expiry passes, the filter stops injecting the capability — the user loses it automatically without any database cleanup required. This is a non-destructive, runtime-only capability injection that never modifies the user’s permanent role or individual capability records.
Status Tracking: Active, Expired, Revoked
The Temporary Permissions management table shows all current and past temporary permission records with real-time status indicators:
Active
The temporary permission is currently active. The user has this capability right now.
Expired
The expiry time has passed. The user no longer has this capability. Record kept for audit trail.
Revoked
Manually revoked before the expiry time. The permission was removed early by an admin.
The status tracking history provides a permanent audit trail of what temporary access was granted, to whom, for how long, and whether it was manually revoked or allowed to expire naturally. This is invaluable for security compliance on sites that handle sensitive data or have regulated access requirements.
Smart Capability Detector: Never Miss a New Permission
The Smart Capability Detector is a background monitoring module that solves one of WordPress’ most invisible access control problems: when a new plugin is installed, it often adds new capabilities — but there is no native mechanism to notify administrators that these new capabilities exist or to assign them to custom roles.
DominoRole’s Smart Detector works by:
- Maintaining a baseline snapshot of all capabilities present on the site in WordPress options
- Scanning the current global capability list on admin load and comparing to the stored baseline
- Identifying any capabilities that are present now but were not in the last saved baseline — these are “newly detected” capabilities
- Displaying an admin notice alerting you that new capabilities have been detected and linking to the Smart Detector page
- The Smart Detector page shows each new capability, which plugin registered it, and allows you to acknowledge it (removing the admin notice) and assign it to your custom roles
The practical value is significant: a newly installed WooCommerce extension might add manage_bookings, view_booking_reports, and edit_bookings capabilities. Without the Smart Detector, these go unnoticed and your custom Shop Manager role never gets them — the Shop Manager can’t access the booking management section, and you spend time debugging why. With the Smart Detector, you get an immediate notification after activating the extension, see the new capabilities in the detector interface, and can assign them to the appropriate roles in minutes.
Plugin Attribution: Which Plugin Added What
The Smart Detector doesn’t just show new capabilities — it shows which plugin is responsible for registering each capability. This attribution is determined by cross-referencing the capability name patterns and registration timing with the active plugin list. For example:
manage_woocommerce— WooCommerce pluginmanage_galleries— [Gallery Plugin Name]dominorole_manage— DominoRole itself
Plugin attribution helps you make informed decisions about whether to assign a new capability — if you recognize the plugin as security-sensitive (e.g., a backup plugin), you’ll want to be careful about which roles get its capabilities.
FAQ
What is the difference between a Temporary Role and a Temporary Permission?
A Temporary Role assigns an entire WordPress role (with all its capabilities) to a user for a time period. A Temporary Permission grants a single, specific capability to a user without changing their role. Use Temporary Roles for comprehensive access needs (“act as an editor for a week”) and Temporary Permissions for targeted one-capability needs (“publish your own posts just for today”).
Can I manually revoke a temporary permission before it expires?
Yes. The Temporary Permissions management table includes a Revoke button for each active permission record. Clicking it immediately removes the temporary capability and marks the record status as Revoked in the audit history.
Does the Smart Detector work with any WordPress plugin?
Yes — the Smart Detector scans the full WordPress global roles and capabilities data regardless of which plugin added them. Any plugin that registers capabilities via add_role(), $role->add_cap(), or similar WordPress core functions will have those capabilities detected automatically.
Are expired temporary permissions cleaned up from the database?
Expired records remain in the database with an “Expired” status for audit trail purposes. They have no functional effect — the runtime filter only grants the capability if the current time is before the expiry. There is a bulk delete option in the Temporary Permissions table for cleaning up old records.
Stop Forgetting to Revoke Access. Automate It.
Temporary roles and permissions with automatic expiry, real-time status tracking, and a smart detector for new plugin capabilities.