You’re in control of this

Your vendor’s support team asked for access to this site. Nothing happens unless you click Grant Support Access, and anything you grant, you can end yourself, at any time, from your own site.

Ending it early

Go to Users in your WordPress admin. The support account is listed there like any other user, with a Revoke Access link on its row. Deleting the account works too, and neither one needs TrustedLogin to be reachable.

If you did not expect this request, close the screen and ask your vendor about it before granting anything.

What granting does

Granting creates a new WordPress user account on your own site for that support team, with the role and the time limit your vendor set. Both are named on the screen before you decide. When the window ends, your site deletes the account on its own. Your own password is never asked for, never sent, and never changed.

What TrustedLogin can see

Which site requested access, which support agent was granted it, what role, for how long, and when the session started and ended. Not the login itself: your site encrypts that before it leaves your server, and the key that opens it sits on your vendor’s own site rather than on ours. The full architecture, including what we cannot see and why, is on our security page.