BlockMyself
Trusted person setup

Give someone else the keys.

The trusted person is the difference between a reminder and a lockout. They hold the passwords, passcodes, recovery keys, router login, and admin routes that would let you undo the setup during a weak moment.

Passwords off-device Recovery control Clear rules
Have you been asked to hold a passcode for someone?

This page is written for the person setting things up, so it talks about you rather than to you. Someone asked you to help is the one written for you, and it takes about five minutes.

Use this only with consent and authority.

These guides are for your own devices and accounts, or for devices you are legally allowed to administer, such as a child’s device, a managed family device, or your own home network. Do not use these steps to control another adult’s device, accounts, passwords, or communications without consent. Keep a documented emergency path for medical, work, banking, travel, and safety needs.

Pick the right person

  1. Pick one person who is reliable, calm, and not easily pressured.
  2. Explain that their job is not to monitor everything. Their job is to hold recovery.
  3. Do not pick someone who will give the password back immediately when you ask impulsively.
  4. Agree on normal maintenance windows, emergency exceptions, and what counts as an emergency.
  5. Use a second backup person only for disaster recovery, not casual overrides.

Inventory what they should hold

Use this table as the handoff list. Anything that can undo the block belongs here.

Item Why it matters Who should hold it
Screen Time passcode Can change iPhone, iPad, or Mac web and app restrictions. Trusted person.
Screen Time Passcode Recovery account The Apple Account entered when the Screen Time passcode was set can reset that passcode at any time. Trusted person's Apple Account, chosen at the prompt when the passcode is set. Do not relocate your own account's recovery phone or email instead. See the caution under Handoff steps.
Google Family Link parent account Can approve apps, change Chrome filters, and alter Android or Chromebook settings. Trusted person.
Microsoft family organizer account Can change Family Safety, web filters, and app limits. Trusted person.
Windows administrator password Can install browsers, change DNS, edit hosts, and remove policies. Trusted person.
Mac administrator password Can install apps, remove profiles, change Screen Time, and edit hosts. Trusted person.
Linux root or sudo credentials Can undo DNS, hosts, firewall, and browser policy. Trusted person.
Router admin login Can change DNS, firewall, guest network, and Wi-Fi settings. Trusted person.
DNS provider dashboard Can disable filtering, change blocklists, or remove devices. Trusted person.
BitLocker or FileVault recovery key Can recover encrypted devices after hardware or account problems. Trusted person, plus a second copy you cannot reach. See the redundancy rule.
MDM, Intune, Chrome Enterprise, or Apple Business/School admin Can remove or change enforceable device policy. Trusted person or organization admin.
Third-party blocker password Can pause, uninstall, or weaken blocker apps. Trusted person.

What this arrangement is, and is not

A common hope, worth answering directly before you plan around it: there is no way for one adult to be placed under another adult's control on an iPhone. Apple's family features run in one direction only. An adult can be set as a parent or guardian and manage a child's account; an adult account cannot be made the managed one, and the age boundaries are enforced by the account's date of birth rather than by preference.

So nobody can remotely approve your settings, lock your phone from their own device, or be notified by Apple when you change something. Every arrangement described on this site is a shared-secret arrangement rather than a permissions one: the trusted person knows a passcode or password that you do not, and that is the entire mechanism.

One exception, on Windows. Microsoft's family groups do not work the way Apple's do: an adult can be a managed member, only the organiser can change that member's safety settings, and only the organiser can remove someone from the group. So on a Windows PC a trusted person genuinely can hold settings you cannot alter. Note the web filtering is Edge-only, and Microsoft has said it intends to let adult members opt out in future, so treat it as useful now rather than permanent.
This has a practical consequence people are often disappointed by. Because the control is a passcode rather than a permission, the trusted person generally has to be physically present to make a change. Plan for that when you agree maintenance windows, and factor it in if you live far apart. Where you genuinely need a second person to hold something remotely, it has to be an account they own rather than a setting on your device: the DNS dashboard, the router login, or the mobile account.

Handoff steps

  1. Make a list of every device, account, router, DNS service, and blocker involved.
  2. Decide who holds the record as well as the credentials. See Accountability for what a trusted person can actually see.
  3. Change each passcode or password while the trusted person is present.
  4. Have the trusted person enter the final password or passcode when possible.
  5. Store passwords in the trusted person's password manager, not yours.
  6. For recovery keys, use the trusted person's password manager, a sealed paper copy, or another storage method they control.
  7. Remove your copies from Notes, screenshots, iCloud Drive, Google Drive, email, browser password managers, and password-manager shared vaults you can still access.
  8. For accounts the trusted person owns outright, such as a Family Link parent account, a Microsoft organizer account, a router login, or a DNS dashboard, put the recovery email and phone on their contact details rather than yours.
  9. Test one harmless change that requires their approval so both of you understand the process.
  10. Document how to reverse the setup in a real emergency without giving you routine access.
Do not move the recovery phone or email on your own primary accounts.

It is tempting to hand your Apple, Google, or Microsoft recovery contacts to the trusted person, but it buys almost nothing and risks a lot. You still need to know your own password for daily life, and a password is enough to reset most of these settings, so recovery contacts were never the control point. Meanwhile, on Apple accounts a trusted phone number is part of the two-factor and account-recovery system: if you ever lose your trusted devices, getting back in runs through whoever holds that number, and you can lose the account outright if they become unreachable or the relationship ends badly.

Use the mechanisms built for this instead. On Apple, add the trusted person as an Account Recovery Contact, which lets them help you regain access without controlling your sign-in. For Screen Time specifically, the control point is the account entered at the Passcode Recovery prompt, not the recovery route on your own account.

That recovery account is only a control if its password is one you have never seen and cannot autofill: not in a shared iCloud Keychain or family password vault, not a household pattern, and not on an unlocked phone lying next to you. Spouses very often know each other's Apple Account password, and that alone reopens the Screen Time passcode. If you cannot guarantee it, skip the recovery prompt instead. Apple documents that with no recovery account, the only way past a forgotten Screen Time passcode is to erase the device and set it up as new, so nobody's account can reset it. The cost is that a genuinely forgotten passcode means a wipe, so the trusted person must store it well.

The redundancy rule

"Do not keep a copy" means do not keep a copy you can reach. It does not mean the trusted person should hold the only copy in existence.

For most items on this page the difference does not matter much: if a router password is lost, you reset the router. For disk-encryption recovery keys it matters enormously. If the trusted person loses your FileVault or BitLocker key, or is unreachable when the machine demands it after a firmware or hardware change, and you have also forgotten the login password, the data is unrecoverable. No support call fixes that.

  1. Keep encryption recovery keys in at least two places, neither of which you can access on impulse.
  2. A good pairing is the trusted person's password manager plus a sealed envelope held by the backup person named in your handoff worksheet.
  3. Never store the second copy in your own password manager, cloud drive, email, or phone. That defeats the point.
  4. Confirm with the trusted person that they can actually find the key on request. An unfindable copy is not a copy.
  5. Write down what happens to these copies if the trusted person becomes unavailable, and revisit it yearly.
The test for every credential on this page: during a weak moment, can you get at it within a few minutes? If yes, it is not handed off. During a genuine emergency, can it be recovered at all? If no, you have built a different problem.

Device-specific handoff map

iPhone / iPad

Trusted person holds the Screen Time passcode, the Apple Account used at the Screen Time Passcode Recovery prompt, the DNS profile account, and any MDM credentials.

Android

Trusted person holds the Family Link parent account and its recovery route, Play approval, the Private DNS account, and any app-blocker password. Family Link supervision only applies to accounts under 18; see Android lockout.

Chromebook

Trusted person holds owner account, Family Link parent account, managed ChromeOS admin account if used, and recovery options.

Windows

Trusted person holds administrator password, Microsoft family organizer account, BitLocker recovery key, router login, and policy-changing credentials.

Mac

Trusted person holds administrator password, Screen Time passcode, FileVault recovery key, profile/MDM credentials, and DNS provider account.

Linux

Trusted person holds root or sudo credentials, disk encryption recovery, firewall/router access, and DNS dashboard access.

Router / network

Trusted person holds router admin login, Wi-Fi admin app, ISP account if it can reset router settings, and DNS or filtering dashboard credentials.

Third-party blockers

Trusted person holds uninstall password, override password, account recovery email, and any billing or admin account that can cancel filtering.

Rules for maintenance

Privacy and logging

Filtering tools can create sensitive logs. DNS dashboards, router logs, accountability apps, parental-control reports, and browser-management tools may reveal searches, domains, app usage, or attempted bypasses.

Message template

Use or adapt this when asking someone to help.

I am setting up device guardrails because I do not want to be able to undo them impulsively.

I am asking you to hold the recovery path, not to monitor everything I do.

You would hold: [Screen Time passcode / admin password / router login / DNS account / recovery key].

Please do not give it back just because I ask quickly. I want changes to happen only during a planned maintenance window or a real emergency.

Common failure modes

Failure Fix
You keep a screenshot or note with the passcode. Delete it from every device and cloud location. Have the trusted person rotate the passcode.
You can reset the account through your own email or phone. Do not move recovery on your own primary accounts (see the warning above). Make the passcode-recovery account one the trusted person owns, or skip the recovery prompt so no account can reset it.
The trusted person gives the password back too easily. Set clearer rules or choose someone else.
You can install another browser or VPN. Remove admin rights and add app-install restrictions or application control.
The router filter works, but mobile data bypasses it. Add device-level controls, carrier controls, Private DNS, or app restrictions.
The setup breaks legitimate work. Use a planned maintenance window and add a narrow allowlist entry instead of disabling everything.

What not to do

Trusted-person tools