The Complete Shopify Staff Permissions Guide: Delegate Safely & Scale Faster

As your Shopify store grows, you can't be the one to do everything. But how do you delegate tasks without handing over the keys to your entire business? This is where mastering Shopify's new, more granular staff permissions becomes your competitive advantage. This operational guide will show you...

Share

As your Shopify store grows, you can't be the one to do everything. But how do you delegate tasks without handing over the keys to your entire business? This is where mastering Shopify's new, more granular staff permissions becomes your competitive advantage. This operational guide will show you exactly how to grant specific access for tasks like managing payments, editing themes, and handling orders, empowering your team while securing your store.

Key takeaways

  • Stop giving full 'Admin' access to team members. Create limited, custom roles for every new hire, even trusted ones, following the principle of least privilege.
  • Immediately use the new granular permissions to separate financial tasks (like managing disputes and payouts) from technical tasks (like theme edits).
  • Regularly audit all staff permissions on a quarterly basis, and always review a team member's access when their role changes or they leave the company.
  • Build a library of 'role templates' for common positions like Customer Service Agent or Marketing Coordinator to dramatically speed up secure onboarding.
  • Always use 'Collaborator' accounts for outside agencies, developers, and marketing partners. Never give them a full staff account.
  • Train your team on why permissions are structured the way they are. A shared understanding of security protocol is more effective than rules alone.
Table of contents

What Exactly Are Shopify Staff Permissions?

Shopify staff permissions are settings that control which actions a user can perform and what information they can see within your Shopify admin. These permissions operate on a hierarchy, with the Store Owner having ultimate control, followed by staff with full administrative access, and then staff with limited, role-specific permissions. Shopify provides default roles like 'Admin' and 'Sales,' but the true power for scaling businesses lies in creating custom roles tailored to specific job functions. The number of staff accounts available is also determined by your Shopify plan (e.g., Basic, Shopify, Advanced).

Why Granular Permissions Are a Game-Changer for Scaling Stores

Granular permissions allow you to delegate specific, high-stakes tasks without granting broad, risky access. Previously, to grant someone the ability to manage payment disputes, you might have had to give them extensive financial access. Now, you can assign only the 'Manage disputes' permission. This capability is crucial for operational efficiency, reducing bottlenecks where you're the sole point of contact for certain tasks, leading to faster completion and clearer role responsibilities. From a security standpoint, it drastically minimizes the risk of accidental data deletion, costly configuration errors, and potential internal fraud.

a tablet and a laptop

A Guided Tour of the Shopify Permissions Dashboard

You can find your user and permission settings by navigating to Settings > Users and permissions. Here, you'll see the main components: the Store Owner, your Staff, any Collaborators, and defined Roles. When adding or editing a role, you'll access a comprehensive list of permissions, helpfully grouped by category such as 'Orders,' 'Products,' and 'Marketing.' Shopify also manages permission dependencies; for instance, to edit products, a user must also have permission to view them, and Shopify will automatically select related boxes to ensure functionality.

a person typing on a laptop on a table

How to Build a Custom Staff Role From the Ground Up

Creating a custom staff role is straightforward. Navigate to Settings > Users and permissions, then click Roles, and then Add role. Give your role a descriptive name, and then carefully select the specific permissions required for that role.

For example, let's create a 'Theme Content Manager' role. This individual needs to update blog posts and customize theme elements but should not access sales data or financial information. You would grant permissions under categories like 'Themes' and 'Blog posts and pages,' while strictly avoiding any permissions under 'Orders' or 'Analytics.'

The decision process for creating a custom role can be visualized as follows:

  1. Identify the Specific Task(s): What exactly does this role need to accomplish? (e.g., "Update product descriptions," "Process returns").
  2. Locate Relevant Permission Group(s): In the Shopify admin, find the section that corresponds to these tasks (e.g., "Products," "Orders").
  3. Select Specific Permission(s): Within the group, choose the exact action(s) allowed (e.g., "Edit products," "Create and edit returns").
  4. Check for Dependencies: Review any permissions that Shopify indicates are automatically selected or required for the chosen permissions. Ensure these are appropriate.
  5. Set Limitations: If the role requires restricted access (e.g., view-only for certain items), ensure only read permissions are granted.
  6. Name and Save the Role: Give the role a clear, descriptive name and save it.
a close up of a computer screen with some stickers on it

Inviting and Onboarding Team Members: A Step-by-Step Guide

To invite a new staff member, go to Settings > Users and permissions, and in the 'Staff' section, click Add staff. Enter their details (name and email address) and then crucially, assign them a pre-defined role or select their permissions manually.

Once invited, the staff member will receive an email with instructions to accept the invite and set up their account, or link an existing Shopify ID. Be mindful of the permissions you assign during this invitation process; you can either give them a broad 'Admin' role or, preferably, assign one of your custom-defined roles. Shopify also offers a 'POS only' option for staff who only need to access the Point of Sale system and not the main admin.

two men sitting at a table with papers and a pen

How to Safely Delegate Financial Tasks (Without Giving Away the Keys)

Shopify's recent updates have introduced more granular permissions for sensitive financial tasks, allowing for greater control. Key permissions here include 'View Shopify Payments payouts' and 'Manage payment disputes.' You can grant these precisely to individuals responsible for these areas, while excluding them from broader financial settings. Similarly, you can grant access to manage Gift Cards without also providing access to Discounts or other sensitive financial tools.

Implementing these granular controls leads to a clear separation of duties, enhancing security and accountability.

Task Category Full Admin Access Limited Finance Role (Hypothetical) Dispute Specialist Role (Hypothetical)
View Payouts Yes (inherent to Admin) Yes No (unless explicitly granted)
Manage Disputes Yes (inherent to Admin) No Yes
Process Refunds Yes (e.g., Refund to original payment method, Refund to store credit) Yes (specific refund types, e.g., store credit only) No (unless explicit for dispute resolution)
Manage Gift Cards Yes No (unless it's a specific task for this role) No
View Discount Codes Yes No No
Access Reports Yes (e.g., Finance reports, Sales reports) No (unless specific financial reports related to their role are needed) No
Manage Shopify Payments Settings Yes (e.g., Payout details, supported payment methods) No No

Managing Technical Access: Who Can Edit Your Theme and Apps?

Granting access to your theme code or app settings carries significant risk if not managed carefully. Untrained staff can inadvertently break your site's appearance or functionality. The 'Themes' permission set includes the ability to 'Edit code,' which should be restricted to trusted developers only. Similarly, 'App' permissions allow you to grant access to specific applications. This prevents a marketing team member, for example, from accidentally altering the configuration of a critical shipping logistics app. By controlling these technical permissions, you safeguard your store's stability, prevent broken checkouts, and maintain a consistent brand experience.

Permission "Recipes" for Your Most Common Team Roles

Establishing standardized permission sets for common roles dramatically speeds up secure onboarding. Here are a few "recipes" for typical e-commerce positions:

  • Customer Service Representative:
    • Permissions: View Orders, View Customers, Shopify Inbox, specific content permissions for looking up order details.
    • Excludes: Reports, Analytics, Marketing, Discounts, Payment settings.
  • Junior Marketer:
    • Permissions: Marketing campaigns (view, create, delete), Blog posts and pages, SEO settings, Files (for uploading assets).
    • Excludes: Discounts, sensitive financial data, Order fulfillment details.
  • Fulfillment Associate:
    • Permissions: View Orders, View Products (for accurate picking), potentially inventory management (with strict view-only).
    • Excludes: Editing products or orders, financial sections, customer personal data.

This structured approach ensures that each team member has exactly the access they need, no more and no less.

This architecture visually represents how different roles map to specific permission groups, highlighting the separation of duties:

  1. Core Store Owner: Full access.
  2. Admin (High Trust): Approaching full access, but potentially with restrictions on core financial settings or user management.
  3. Customer Service: Focused on 'Customers' and 'Orders' (view/manage), with communication tools like 'Shopify Inbox.'
  4. Marketing: Primarily 'Marketing,' 'Content,' 'Files,' and potentially 'Products' (for descriptions/SEO).
  5. Fulfillment: Concentrated on 'Orders' (view/fulfill) and 'Products' (view).
  6. Technical/Development: Concentrated on 'Themes' (edit code) and 'Apps' (manage).
  7. Finance/Accounting: Highly restricted to specific 'Finance,' 'Orders,' and 'Disputes' permissions.

Staff vs. Collaborator Accounts: Choosing the Right Access for Outsiders

Collaborator accounts are a free, secure solution for granting access to non-employees such as agencies, freelancers, or developers. Collaborators log in using their own Shopify Partner credentials, rather than using an account you create for them. This method significantly enhances security as you don't manage their login details directly. To grant access, a collaborator typically sends a request, which you then approve and assign specific permissions to. It's a best practice to exclusively use Collaborator accounts for any external party and reserve Staff accounts for your direct employees.

The Staff Permission Lifecycle: Audits, Updates, and Offboarding

Managing staff permissions is not a one-time setup; it's an ongoing process. Regularly auditing your team's access is crucial for maintaining security and efficiency.

A quarterly permissions audit should include these steps:

  • Review All Active Accounts: Go through every staff member logged into your admin.
  • Verify Role Relevance: Ensure each employee's assigned role and permissions still align with their current job responsibilities.
  • Remove Unused Accounts: Deactivate or remove any accounts that are no longer needed.

When an employee departs, immediately deactivate their staff account to revoke all access. This is a critical security step that should never be overlooked.

This framework summarizes how to audit staff access security:

Aspect Status Check Action Required
Existing Staff Accounts Are all current staff members still employed and in their current roles? Deactivate/Remove accounts for departed employees. Adjust roles/permissions for role changes.
Role Assignment Accuracy Does each role accurately reflect the minimum necessary permissions for the tasks performed by its assigned staff? Create new custom roles, modify existing roles, or reassign staff to appropriate roles if permissions are too broad or too narrow.
External Access (Collaborators) Are all external collaborators still engaged, and is their access level appropriate? Remove collaborators who are no longer working on the project. Ensure their assigned permissions are still necessary.
Security Best Practices Is 'least privilege' being applied consistently across all roles? Is two-factor authentication enabled where possible? Educate staff on security protocols. Implement new roles or refine existing ones to adhere to the principle of least privilege.

Conclusion and Next Steps

Mastering Shopify's granular staff permissions is essential for any growing e-commerce business. By carefully defining roles and assigning specific permissions, you can empower your team to handle critical tasks efficiently while safeguarding your store's sensitive data and configurations. Moving away from broad 'Admin' access to tailored roles enhances security, streamlines operations, and builds a more robust foundation for scaling.

Here are the concrete next steps you can take today:

  1. Audit Your Current Staff Permissions: Log in to your Shopify admin (Settings > Users and permissions) and review every staff account and their assigned roles and permissions. Identify any accounts with overly broad access.
  2. Create a "Least Privilege" Role Template: Design a custom role for a common position (e.g., Customer Support) based on the principle of giving only necessary access. Save this as a template.
  3. Identify Financial and Technical Tasks: Make a list of sensitive financial tasks (disputes, payouts) and technical tasks (theme edits, app configurations) and ensure they are managed by separate, uniquely permissioned roles.
  4. Schedule Quarterly Reviews: Set a recurring calendar reminder to conduct permissions audits every three months.
  5. Onboard New Hires with Custom Roles: For every new team member, create or assign a specific role aligned with their responsibilities before they begin their tasks.

Frequently asked questions

How many staff accounts can I have on my Shopify plan?

The number of staff accounts varies by Shopify plan. The Basic plan typically offers zero staff accounts, the Shopify plan provides five, and the Advanced plan offers fifteen. Shopify Plus plans come with unlimited staff accounts. Importantly, 'POS only' staff and 'Collaborator' accounts do not count towards this staff account limit.

Can a staff member see my store's total revenue?

Yes, a staff member can see your store's total revenue if they are granted permissions to view the 'Home' page, 'Analytics,' or 'Reports.' To prevent this, you must create a custom role that specifically excludes these viewing permissions, ensuring revenue data remains private.

What happens when I remove or deactivate a staff account?

Deactivating a staff account immediately revokes all access to your Shopify admin and Point of Sale system. The account itself remains in your system but is dormant. Removing a user account permanently deletes it from your store, and this action cannot be undone. Deactivation is often the safer first step when an employee departs.

Can I create a 'view only' role in Shopify?

Yes, for many sections within Shopify, you can create a 'view only' role. When selecting permissions for a role, you can often choose only the 'View' permission without granting 'Edit' or 'Create' access. For instance, you could create a 'View Products' role for an analyst who needs to monitor inventory levels but shouldn't make any changes.

How do I change the permissions for an existing staff member?

To change permissions for an existing staff member, navigate to Settings > Users and permissions. Click on the staff member's name. In the 'Roles' section, you can either un-assign their current role and assign a new one, or you can edit the existing role if it's used by other staff members as well.

What is the difference between a POS-only staff member and an admin staff member?

A POS-only staff member can only log in to the Shopify POS app using a unique PIN. They have no access to the online store's administrative panel. An admin staff member, on the other hand, can access the online store admin based on the specific permissions assigned to their role.

Can I give a staff member access to only one specific product or collection?

No, Shopify permissions are not that granular. Permissions are applied to entire categories of items, such as all products or all orders. You cannot restrict a user's access to individual items within a category.

Can I see a log of what my staff members have been doing?

Yes, Shopify provides an 'Activity log' that is accessible to store owners. This log records recent changes made within the store, including which staff member made each change. This is a vital feature for accountability and security.

What are 'organization-level permissions' in Shopify Plus?

'Organization-level permissions' is a feature designed for Shopify Plus merchants who manage multiple stores within an organization. It allows administrators to manage users and their access rights across all stores in the organization from a single, central dashboard, simplifying user management for complex setups.

How do I know which permissions are required for a specific task?

A practical approach is to start with a minimal set of permissions for a new role. When the staff member encounters an error indicating they lack permission, you can add the necessary permissions one by one. Alternatively, you can consult Shopify's official help documentation, which often details the dependencies and required permissions for various tasks.

Additional Resources

Watch

References

Read more