This page is written for the person setting things up, so it talks about you rather than to you. Someone asked you to help is the one written for you, and it takes about five minutes.
These guides are for your own devices and accounts, or for devices you are legally allowed to administer, such as a child’s device, a managed family device, or your own home network. Do not use these steps to control another adult’s device, accounts, passwords, or communications without consent. Keep a documented emergency path for medical, work, banking, travel, and safety needs.
Pick the right person
- Pick one person who is reliable, calm, and not easily pressured.
- Explain that their job is not to monitor everything. Their job is to hold recovery.
- Do not pick someone who will give the password back immediately when you ask impulsively.
- Agree on normal maintenance windows, emergency exceptions, and what counts as an emergency.
- Use a second backup person only for disaster recovery, not casual overrides.
Inventory what they should hold
Use this table as the handoff list. Anything that can undo the block belongs here.
| Item | Why it matters | Who should hold it |
|---|---|---|
| Screen Time passcode | Can change iPhone, iPad, or Mac web and app restrictions. | Trusted person. |
| Screen Time Passcode Recovery account | The Apple Account entered when the Screen Time passcode was set can reset that passcode at any time. | Trusted person's Apple Account, chosen at the prompt when the passcode is set. Do not relocate your own account's recovery phone or email instead. See the caution under Handoff steps. |
| Google Family Link parent account | Can approve apps, change Chrome filters, and alter Android or Chromebook settings. | Trusted person. |
| Microsoft family organizer account | Can change Family Safety, web filters, and app limits. | Trusted person. |
| Windows administrator password | Can install browsers, change DNS, edit hosts, and remove policies. | Trusted person. |
| Mac administrator password | Can install apps, remove profiles, change Screen Time, and edit hosts. | Trusted person. |
| Linux root or sudo credentials | Can undo DNS, hosts, firewall, and browser policy. | Trusted person. |
| Router admin login | Can change DNS, firewall, guest network, and Wi-Fi settings. | Trusted person. |
| DNS provider dashboard | Can disable filtering, change blocklists, or remove devices. | Trusted person. |
| BitLocker or FileVault recovery key | Can recover encrypted devices after hardware or account problems. | Trusted person, plus a second copy you cannot reach. See the redundancy rule. |
| MDM, Intune, Chrome Enterprise, or Apple Business/School admin | Can remove or change enforceable device policy. | Trusted person or organization admin. |
| Third-party blocker password | Can pause, uninstall, or weaken blocker apps. | Trusted person. |
What this arrangement is, and is not
A common hope, worth answering directly before you plan around it: there is no way for one adult to be placed under another adult's control on an iPhone. Apple's family features run in one direction only. An adult can be set as a parent or guardian and manage a child's account; an adult account cannot be made the managed one, and the age boundaries are enforced by the account's date of birth rather than by preference.
So nobody can remotely approve your settings, lock your phone from their own device, or be notified by Apple when you change something. Every arrangement described on this site is a shared-secret arrangement rather than a permissions one: the trusted person knows a passcode or password that you do not, and that is the entire mechanism.
Handoff steps
- Make a list of every device, account, router, DNS service, and blocker involved.
- Decide who holds the record as well as the credentials. See Accountability for what a trusted person can actually see.
- Change each passcode or password while the trusted person is present.
- Have the trusted person enter the final password or passcode when possible.
- Store passwords in the trusted person's password manager, not yours.
- For recovery keys, use the trusted person's password manager, a sealed paper copy, or another storage method they control.
- Remove your copies from Notes, screenshots, iCloud Drive, Google Drive, email, browser password managers, and password-manager shared vaults you can still access.
- For accounts the trusted person owns outright, such as a Family Link parent account, a Microsoft organizer account, a router login, or a DNS dashboard, put the recovery email and phone on their contact details rather than yours.
- Test one harmless change that requires their approval so both of you understand the process.
- Document how to reverse the setup in a real emergency without giving you routine access.
It is tempting to hand your Apple, Google, or Microsoft recovery contacts to the trusted person, but it buys almost nothing and risks a lot. You still need to know your own password for daily life, and a password is enough to reset most of these settings, so recovery contacts were never the control point. Meanwhile, on Apple accounts a trusted phone number is part of the two-factor and account-recovery system: if you ever lose your trusted devices, getting back in runs through whoever holds that number, and you can lose the account outright if they become unreachable or the relationship ends badly.
Use the mechanisms built for this instead. On Apple, add the trusted person as an Account Recovery Contact, which lets them help you regain access without controlling your sign-in. For Screen Time specifically, the control point is the account entered at the Passcode Recovery prompt, not the recovery route on your own account.
That recovery account is only a control if its password is one you have never seen and cannot autofill: not in a shared iCloud Keychain or family password vault, not a household pattern, and not on an unlocked phone lying next to you. Spouses very often know each other's Apple Account password, and that alone reopens the Screen Time passcode. If you cannot guarantee it, skip the recovery prompt instead. Apple documents that with no recovery account, the only way past a forgotten Screen Time passcode is to erase the device and set it up as new, so nobody's account can reset it. The cost is that a genuinely forgotten passcode means a wipe, so the trusted person must store it well.
The redundancy rule
"Do not keep a copy" means do not keep a copy you can reach. It does not mean the trusted person should hold the only copy in existence.
For most items on this page the difference does not matter much: if a router password is lost, you reset the router. For disk-encryption recovery keys it matters enormously. If the trusted person loses your FileVault or BitLocker key, or is unreachable when the machine demands it after a firmware or hardware change, and you have also forgotten the login password, the data is unrecoverable. No support call fixes that.
- Keep encryption recovery keys in at least two places, neither of which you can access on impulse.
- A good pairing is the trusted person's password manager plus a sealed envelope held by the backup person named in your handoff worksheet.
- Never store the second copy in your own password manager, cloud drive, email, or phone. That defeats the point.
- Confirm with the trusted person that they can actually find the key on request. An unfindable copy is not a copy.
- Write down what happens to these copies if the trusted person becomes unavailable, and revisit it yearly.
Device-specific handoff map
iPhone / iPad
Trusted person holds the Screen Time passcode, the Apple Account used at the Screen Time Passcode Recovery prompt, the DNS profile account, and any MDM credentials.
Android
Trusted person holds the Family Link parent account and its recovery route, Play approval, the Private DNS account, and any app-blocker password. Family Link supervision only applies to accounts under 18; see Android lockout.
Chromebook
Trusted person holds owner account, Family Link parent account, managed ChromeOS admin account if used, and recovery options.
Windows
Trusted person holds administrator password, Microsoft family organizer account, BitLocker recovery key, router login, and policy-changing credentials.
Mac
Trusted person holds administrator password, Screen Time passcode, FileVault recovery key, profile/MDM credentials, and DNS provider account.
Linux
Trusted person holds root or sudo credentials, disk encryption recovery, firewall/router access, and DNS dashboard access.
Router / network
Trusted person holds router admin login, Wi-Fi admin app, ISP account if it can reset router settings, and DNS or filtering dashboard credentials.
Third-party blockers
Trusted person holds uninstall password, override password, account recovery email, and any billing or admin account that can cancel filtering.
Rules for maintenance
- Use scheduled maintenance windows instead of instant overrides.
- Make changes together on a call or in person so the trusted person can keep the password private.
- Do not let the trusted person type passwords while screen recording, remote control, or password reveal is active.
- After maintenance, sign out of admin accounts and clear any temporary passwords.
- Review the setup after major OS updates, new devices, new browsers, router changes, or phone upgrades.
- If the trusted person can no longer help, transfer the recovery path before removing them.
Privacy and logging
Filtering tools can create sensitive logs. DNS dashboards, router logs, accountability apps, parental-control reports, and browser-management tools may reveal searches, domains, app usage, or attempted bypasses.
- Use the least invasive tool that still works.
- Prefer trusted-person control of recovery over constant monitoring when that is enough.
- Decide in advance what the trusted person can see, what they should ignore, and what should trigger a conversation.
- Protect the trusted person’s dashboard with strong authentication.
- Review logging after major setup changes, new DNS providers, new routers, or new accountability tools.
Message template
Use or adapt this when asking someone to help.
I am setting up device guardrails because I do not want to be able to undo them impulsively.
I am asking you to hold the recovery path, not to monitor everything I do.
You would hold: [Screen Time passcode / admin password / router login / DNS account / recovery key].
Please do not give it back just because I ask quickly. I want changes to happen only during a planned maintenance window or a real emergency.
Common failure modes
| Failure | Fix |
|---|---|
| You keep a screenshot or note with the passcode. | Delete it from every device and cloud location. Have the trusted person rotate the passcode. |
| You can reset the account through your own email or phone. | Do not move recovery on your own primary accounts (see the warning above). Make the passcode-recovery account one the trusted person owns, or skip the recovery prompt so no account can reset it. |
| The trusted person gives the password back too easily. | Set clearer rules or choose someone else. |
| You can install another browser or VPN. | Remove admin rights and add app-install restrictions or application control. |
| The router filter works, but mobile data bypasses it. | Add device-level controls, carrier controls, Private DNS, or app restrictions. |
| The setup breaks legitimate work. | Use a planned maintenance window and add a narrow allowlist entry instead of disabling everything. |
What not to do
- Do not leave passwords in your own password manager if you are the person being blocked.
- Do not keep recovery keys only on the blocked device.
- Do not share a single admin account for daily browsing.
- Do not rely on one browser extension as the only layer.
- Do not lock yourself out of essential medical, work, banking, or safety access without a documented emergency process.