Making sense of Shopify Roles

Making sense of Shopify Roles

As your Shopify store grows, chances are you won’t be the only person who needs access to it. You might have employees managing products, someone dealing with customer enquiries, an accountant who needs access to financial information, or an agency such as Blue Horizons helping with your website and marketing.

But not everyone needs access to everything. That’s where Shopify Roles come in. Shopify’s roles and permissions system gives you much more control over who can access your store and, importantly, what they can actually do once they’re there. It’s a useful system, but at first glance there are quite a few roles, permissions and options to get your head around. So, here’s our simpler explanation.

First things first: what is a Shopify Role?

Think of a role as a collection of permissions designed around someone’s job.
Rather than individually deciding whether someone can access products, orders, customers, content, reports and so on every time you add a user, you can create or assign a role containing the permissions that person needs. For example, someone responsible for keeping your products up to date could be given a role that lets them manage products and content – without also giving them access to your financial information or other sensitive areas of your store.

Shopify also allows multiple roles to be assigned to the same person where necessary. Their overall access is then made up of the combined permissions from those roles.
It’s a much more structured way of managing access – particularly as your team grows.

Roles vs permissions – what’s the difference?

This is probably the easiest way to think about it: 

A role describes what somebody does. 
A permission determines what they can access.

So, you might create a role called Warehouse Team, for example, and give that role permission to view and fulfil orders and manage inventory – but not access customer data, finances or store settings. Shopify offers different categories of permissions depending on your Shopify plan and setup, including:

  • Store roles – access to areas within an individual Shopify store.
  • Organisation roles – access to organisation-level features, which becomes more relevant for businesses managing multiple stores and Shopify Plus merchants.
  • Point of Sale (POS) roles – for businesses using Shopify POS.
  • Partner roles – used by Shopify Partners such as agencies and developers when working with merchant stores.

For most Shopify merchants managing their day-to-day team, Store roles are likely to be the ones you'll encounter most often.

Shopify's predefined roles

To make things easier, Shopify provides a number of ready-made roles for common jobs within an ecommerce business. These include:

Online store editor

Designed for someone responsible for the content and appearance of your online store.
They can access areas such as the Online Store, Content and Files, making this a useful starting point for somebody responsible for keeping website content up to date.

Customer support

For somebody dealing with customer queries and order-related issues.
The standard role includes access to Orders and Draft Orders, without automatically giving them access to unrelated areas of the business.

Merchandiser

A useful role for somebody responsible for your product catalogue. It includes access to Products, Catalogs, Content and Files, allowing them to keep products and collections up to date without needing wider administrative access.

Marketer

For somebody responsible for marketing activity within Shopify. The predefined role provides access to Marketing and Customers.

Shopify also provides predefined Store Manager, Cashier and Sales Associate roles for merchants using Shopify POS Pro.

One important point: Shopify's predefined roles are a starting point rather than something you're necessarily stuck with. They can be edited or deleted if they don't quite match the way your business operates. You can also create your own roles and 
this is where Shopify Roles can become particularly useful.

Every business operates slightly differently, so the responsibilities of a "Marketing Manager" or "Warehouse Assistant" in one business might be very different in another.
Where your Shopify plan and setup supports it, you can create custom roles containing the specific permissions somebody needs.

For example:

Warehouse & Fulfilment -You might allow access to orders, fulfilment and inventory, plus view-only access to products – without giving access to financial information, customer information or store settings.

Finance / Accountant - Your accountant might need to see payouts, billing, reports and order information, but they probably don't need the ability to change your products, theme or store settings.

The principle we recommend is simple: Give people the access they need to do their job – rather than giving everybody access to everything. It keeps things cleaner, safer and easier to manage.

What about Administrators?

Shopify also has a number of roles that it manages itself. These can't be customised or deleted. One of the most important is the Administrator role.

This is a high-trust role because it provides access to almost all areas of the store, including user management. For Shopify Plus and multi-store organisations, there's also an Organisation Administrator role providing similarly broad access across the organisation and its stores. In other words, don't make somebody an Administrator simply because it's the easiest option.

If someone only needs to update products, manage orders or edit website content, give them a more appropriate role instead.

And what about the Store Owner?

The Store Owner sits above normal user roles. Every Shopify store has one Store Owner and this person has complete access to the store. There are also certain actions that only the Store Owner can perform, including changing ownership and pausing or deactivating the store.

Shopify also sends important store communications to the Store Owner's email address.
For that reason, we'd always recommend making sure your store ownership details are kept up to date and belong to an appropriate person within your business.

Store ownership shouldn't simply sit with whoever happened to set the website up several years ago.

What access should you give your Shopify agency?

This works slightly differently. If you're working with an official Shopify Partner such as Blue Horizons, we don't need to be added as a normal member of your staff. Instead, Shopify Partners can request collaborator access.

This allows you to approve access to the areas of your store that are relevant to the work we're carrying out. Shopify specifically recommends granting collaborators only the permissions needed for the project. It's a much better way of working with an external agency or developer because their access remains separate from your internal team.
And, importantly, you remain in control.

A few simple Shopify Role housekeeping tips

Roles aren't something you should set up once and then forget about.
It's worth periodically checking Settings > Users in your Shopify admin and asking:

  • Does everyone listed still work with us?
  • Does each person still need the access they have?
  • Have people's responsibilities changed?
  • Have we given Administrator access where a more limited role would be sufficient?
  • Are there old external users or collaborators who no longer require access?

A quick review every few months is good practice – particularly when somebody joins or leaves your business.

Don't confuse convenience with access

We understand why businesses end up giving everyone broad access. It's quick.
Someone asks for access to Shopify, you tick lots of boxes, and they can get on with their job. But taking a few minutes to set roles up properly is worthwhile.

Someone working on fulfilment doesn't need access to your finances. Your accountant doesn't need to edit your theme. And someone uploading products probably doesn't need permission to manage other users. Shopify's Roles system allows you to match access much more closely to people's actual responsibilities.

Our advice: keep it simple

You don't need dozens of highly complicated roles. Start by thinking about the different responsibilities within your business and group people accordingly. Use Shopify's predefined roles where they work and create your own where they don't.

Most importantly, apply the principle of least necessary access: give each person enough access to comfortably do their job, but no more than they actually need. As your business evolves, your roles can evolve with it. And if you're not sure what permissions someone needs – particularly when adding an agency, developer or other external supplier – it's always better to check before simply giving them access to everything.

At Blue Horizons, we work with our clients to make Shopify as straightforward as possible. So, if you're unsure about your current user setup, roles or permissions, we're always happy to help you make sense of it.

Shopify regularly updates its admin, roles and permissions. The options available to you can also depend on your Shopify plan, whether you operate multiple stores and whether you use Shopify POS.

Reading next

Back to School, Back to Business: Give Your Shopify Store a New-Term Reset
Is Your Shopify Store Ready for Peak Trading?