How to Clean Up Your Wagtail User Accounts

This video is from Wagtail CMS 2025 .

How to Clean Up Your Wagtail User Accounts
0:04:59
Published March 11, 2025
268 views

Have too many users on your website? This video shows you how to use Wagtail's built-in tools to identify inactive user accounts and remove them. We'll walk through the tools on a demo website and show you a real-world example from wagtail.org.

💻 Wagtail is the easiest open-source Python CMS to use:
Install the demo and start building your first site in 10 minutes: https://wagtail.org/get-started/

What will I learn from this video?

You'll learn how to use Wagtail's native features for identifying inactive users and how to remove them from your website. Regular user clean ups are great for reducing security risks and for keeping your Wagtail website tidy.

📹 Related Videos To Watch Next:

â–¶ How to use the Wagtail Starter Kit https://www.youtube.com/watch?v=5MAwXoDE_ws
â–¶ The Latest on Wagtail AI https://www.youtube.com/watch?v=4zfs1u4Vy5Y
▶ What’s New in Wagtail CMS 6.0 https://www.youtube.com/watch?v=2AxLFyOFjQo

Wagtail future proofs your CMS system, as it’s open source, continuously updated and built on Python, one of the most popular global programming languages, used widely in machine learning and big data. So you’re always ahead of the curve when it comes to CMS platforms.

Wagtail is the #1 choice for accessibility, is scalable and most importantly, secure.

👉 Get started with a FREE Wagtail CMS TRIAL: https://wagtail.org/get-started/
and see how easy it is to build a website that works for you.

📊 Read why Google, NASA, and the British NHS, are powering their digital estates with Wagtail: https://wagtail.org/about-wagtail/

🎥 More Wagtail Videos: https://www.youtube.com/watch?v=cne2kxemMAQ&list=PLfwZ-fob20cPvSQ_v1hkjto8BAPN21tLJ

📣 Follow us on social:

#WagtailCMS #Django

Summary

Megan demonstrates how to review and clean up Wagtail user accounts using the Users page in Settings. Sorting by access level helps identify people with unnecessary administrator privileges, while status and last-login information help find accounts that may no longer be needed; status is only an indicator because administrators can change it manually. Accounts can be edited individually or removed in bulk, and the Wagtail.org example shows inactive accounts—including inactive administrators—that have not logged in for many years and may pose avoidable security risks.

Key takeaways

  • Sort users by access level to review whether each person needs their current permissions, especially administrator access.
  • Use status and last-login dates to identify accounts that may no longer be in use, while remembering that status can be changed manually.
  • Review individual accounts to change permissions or remove them, and use bulk deletion for groups of obsolete users.
  • Inactive administrator accounts and accounts that have not logged in for years are strong candidates for cleanup because they create unnecessary security risk.

Summarised automatically from the transcript.

Transcript

873 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:00

Hey y'all, Megan here. I don't know about you, but I'm not the biggest fan of cleaning up, and we're starting to do a real big data cleanup on Wagtail. org this week. Fortunately, Wagtail has a lot of great tools that makes it easier to identify things you don't need anymore. And so I'm gonna go ahead and show you one of the things that I'm using this week to clean up our user accounts So this is a demo site I have right here. Nothing on it is real. I'm gonna go ahead and head to the settings section and then I'm gonna go to users here And right here is a list of all the users that are on the site. It is much longer on a real website, trust me Uh but I'm

0:45

gonna right here on our users we have the name of our users, we have the username for each user. And then these three columns over here are the columns that'll definitely help you out when you're deciding which users you want to keep or which ones maybe should not have accounts anymore. And those are access level, status, and last login. So if I go ahead and click on access level here That sorts all my users according to the access role that they have. And you can see we have a fair amount of admins on this website. I can go ahead and take that list and double check like, does this person really need this level of access? Or maybe I should bump them down to a lower level of access. It gives you a chance to decide like what level of access do

1:32

does each person really need. And you especially want to make sure that you limit the number of admin users you have on your site because admins have access to everything. And frankly, it can be a real big security risk if one of your admin accounts gets confident. So limiting a number of those accounts is a super super good idea. Another useful tool is the status column here, which we only have one inactive user in this demo. Uh but pretty much like this label gives you an idea uh which users might not be using their accounts. Uh now take it with a grain of salt because down here, like you know, if I wanted to click here um You know, I can go ahead and set this user as active if I wanted to because I have admin privileges right now and I can change things that users can do.

2:23

So definitely keep in mind that that is a possibility when you're going through this list. But another piece of information that can help you make decisions is when the last login was. And so it looks like you know the last login for some of these users was pretty long ago. Some of them are still labeled as active, uh, which means that they might still be using their accounts. Uh but you know I would definitely flag something like this as maybe we'll double check whether Jordan over here really, really, really needs their account on this site. Uh whereas like, you know, active users who logged in a year ago or a couple hours ago or a few months ago, I might just go ahead and leave those in place. All right. So kind of when you identify which users you want to get rid of, you can open up the user individually and make edits there, especially if you want to change their level of access.

3:20

But also, if you just identified a whole swath of users that you don't need anymore, you can use our bolt delete functions over here to go ahead and sort things. So through the magic of some video editing, I have decided to show you guys a more real-world example of how these tools This is Wagtail. org. This is our users page. Only I have a guard Wagtail uh standing in front of the usernames and the email addresses because I don't want to expose that data to the internet. And you can see here in the columns though, which are still visible, that I've sorted our users according to status here. And this whole first page of users

4:08

is inactive. And some of them have not logged in in years, years. Like, looks. Five years, six years, seven years, eight years, oh goodness, even nine years ago. I think we are really due for a cleanup on Wagtail. org. And we also have a couple admins that have been inactive as well. And that's a really good sign that we should probably go ahead and get rid of those accounts. because we don't want to leave those as a potential security risk. And so this is a great chance for us to clean up. I hope that I've inspired you to consider going to your site and also considering a cleanup of your own. I think that this is a great uh set of tools that are built into Wagtail here and are really, really helpful for keeping sites more secure and tidy.

Questions this talk answers

How can I identify which Wagtail user accounts should be cleaned up?

Review each user’s access level, status, and last-login date. Inactive accounts and accounts whose users have not logged in for years are good candidates for removal, while recent activity may justify keeping an account.

Discussed at 0:45

Why should I limit the number of admin users in Wagtail?

Administrators have access to everything, so a compromised admin account creates a significant security risk. Review whether each admin really needs that level of access and downgrade accounts when appropriate.

Discussed at 1:32

How do I edit or bulk-delete user accounts in Wagtail?

Open an individual user to change their access level or other details, or use Wagtail’s bulk-delete functions when removing a group of unnecessary accounts.

Discussed at 3:20

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos from Wagtail CMS