Role-Based Access for WordPress Chat: Who Can Message Whom
A messaging plugin on a community site, a marketplace, or a paid membership platform has to answer one question repeatedly: who is allowed to message whom? The answers vary by site. A B2B directory might let businesses message each other freely but block consumer-to-consumer DMs. A paid community might let Pro members message anyone but block Free members from initiating. A LMS might let students message instructors but not other students. Better Messages handles all of this with a role-based access matrix, four kinds of restrictions, per-role rate limiting, and user-controlled DM-blocking.
Five access controls in one panel#
All under WP Admin → Better Messages → Settings → Restrictions:
1. Role-to-role rules (blocklist or allowlist)#
The core control, under Role-to-Role Restrictions. A Default Behavior radio decides what the rules underneath it mean, and the rules themselves are a list of From role → To role pairs you build with Add Rule:
- All users can message each other — everyone can DM everyone, and each rule removes one pairing. A blocklist. Each rule carries its own Message, shown to the sender who runs into it.
- No one can message each other — nobody can DM anybody, and each rule restores one pairing. An allowlist. Here the message is a single site-wide Restriction Message instead of a per-rule one.
Restricted users are also hidden from user search, not just blocked at send time.
The allowlist is the auditable one and what most gated sites want. Example rule set for a paid membership site, with No one can message each other as the default:
| From (sender role) | To (allowed recipient) |
|---|---|
| Pro Member | Pro Member |
| Pro Member | Free Member |
| Pro Member | Administrator |
| Free Member | Administrator |
Subscribers get no rule at all, so they get no DMs. Two things that trip people up:
- Rules are one-directional. Free Member → Administrator does not by itself let the administrator write back — add the reverse pairing for anything that should work both ways.
- Administrators are exempt from role-to-role rules in both modes, so you never need a rule for them as the sender.
2. Restrict new conversations#
Lists roles that cannot start new conversations. They can still reply to threads someone else started.
Common pattern: free members cannot start DMs, but paid members can DM them, and the free member can then reply. Lowers spam, lets paying members reach the audience.
3. Restrict replies#
Lists roles that cannot reply to existing conversations. Rare, but useful for "view-only" tiers — e.g. a Lifetime member who has lost active subscription status retains read access to old conversations but cannot post new replies.
4. Restrict message visibility#
Lists roles that see placeholder text instead of message content. The placeholder is configurable. Useful for:
- Paywall preview: free members see "Subscribe to Pro to read this message" instead of paid-thread content.
- Moderation: suspended users see "Your access has been restricted" instead of any message bodies.
5. Per-role rate limits#
Two kinds:
- New Conversation Rate Limit — a minimum number of seconds between new conversations, site-wide rather than per role. It blocks the spammer pattern of thread → message → get blocked → new thread.
0turns it off. - Reply Rate Limit — a per-role cap on replies, set as a number per Hour or per Day (those are the only two windows).
0on a role means no limit. A Rate Limit Message is what the sender sees when they hit it.
User-controlled DM preferences#
Beyond admin-level access control, members can decide who is allowed to open a conversation with them. Turn on User Controls → User Conversation Restrictions, and each member gets "Who can start private conversations with you?" in their own messenger settings:
- Everyone — the default.
- Allow Friends — only appears when a friends system is active (BuddyPress, BuddyBoss, PeepSo, Ultimate Member).
- Allow Followers — only appears when a followers system is active.
- Nobody.
It governs who can start a conversation, not who can reply inside one that already exists. Sites with sensitive audiences should enable it. Sites that want maximum interaction can leave it off.
Common patterns#
| Site type | Typical setup |
|---|---|
| Paid membership | Free can reply only. Pro / Lifetime can DM freely. Admin can DM anyone |
| LMS | Students can DM instructors only. Instructors can DM students. Admin can DM anyone |
| Marketplace | Buyers and vendors can DM each other. Buyer-to-buyer DMs blocked |
| Job board | Candidates can DM employers. Employer-to-candidate DMs allowed. Candidate-to-candidate blocked |
| Public community | Everyone can DM everyone, with rate limits + user-controlled self-restriction |
| Directory site | Visitors → listing owners only. Listing owners can reply but not initiate to random visitors |
How permissions interact with guest chat#
Guest users have a synthetic "Guests" role in the restrictions matrix. Apply the same controls — typical pattern: guests can DM listing owners / vendors / support but cannot DM regular registered members.
How permissions interact with group chats#
The role matrix applies to one-on-one DMs and to creating new group conversations. Once a user is in a group chat, the chat's own admin / moderator / member hierarchy takes over — that is separate from the WordPress role.
Custom visibility placeholder#
When you hide message content for a role, the text they see instead is the Replacement Message field under Settings → Restrictions → Restrict Message Viewing. Examples:
- "Subscribe to Pro to read this message"
- "Your access is currently restricted"
- "Message hidden — contact support for details"
How to enable#
- WP Admin → Better Messages → Settings → Restrictions.
- Under Role-to-Role Restrictions, pick a Default Behavior — All users can message each other or No one can message each other.
- Add the role-to-role rules underneath it with Add Rule.
- Set restrictions for new conversations, replies, and visibility.
- Configure rate limits per role.
- Save.
Settings apply on the next request — no rebuild, no cache flush.
Frequently asked questions#
Can I run different rules in different parts of the site?#
The role matrix is global. For per-page or per-community-group differences, use the group chat's own admin / moderator settings, or hook the better_messages_can_send_message filter and return a context-aware permission.
Does the restriction apply to admins?#
Administrators bypass restrictions by default. To restrict admins too (rare), use a custom filter.
What happens when a user is blocked by the matrix?#
Usually they never get that far: restricted users are also hidden from the recipient search, so the blocked person simply does not appear as someone to write to. If they do reach the send (an existing thread, a direct link), they get the restriction message — the stock text is "You are not allowed to send messages", and every restriction has its own configurable string.
Will the user know they were blocked?#
They see the configurable message and nothing more — the system does not name the rule that stopped them.
Does this work with custom WordPress roles?#
Yes — Better Messages reads WordPress's role system. Any role registered with add_role() shows up in the restrictions matrix automatically.
Can I rate-limit by IP instead of role?#
Per-role rate limits are the built-in option. For IP-based rate limiting, a custom filter can layer in IP rules — talk to support for the template.
See also#
- Role-based access documentation — full reference for every setting
- WordPress membership site chat — typical role configurations for paid memberships
- WordPress group chat plugin — how role-based access plays with group chats
- User Block feature — user-controlled blocking on top of admin-controlled restrictions