Platform Guide

Who Gets Into Your Shopify Admin, and With What Access

Staff seat or collaborator account, what each permission category controls, what to give an assistant, bookkeeper or agency, and what to revoke when they go.

Staff vs CollaboratorPermission ScopePlan GatesOffboarding
August 6, 2026·26 min read·
Listen to a short brief of this article
Hands-free while you multitask

Key Insights in 60 Seconds

Skim the highlights, then jump to the person you are about to let in.

An agency need not cost you a seat: collaborator accounts for Shopify Partners don't count toward your user limit.
Store permissions come in 19 categories. We counted 108 toggles inside them, plus two for apps; Shopify publishes no total.
Two role recipes are published — bookkeeper and warehouse — plus a Customer support role that includes refunds.
Basic and Starter include zero user seats. Grow gives 5, Advanced 15, Plus unlimited; the owner never counts.
Collaborator access lapses by itself. Shopify documents a 90-day inactivity expiry, and advises removing the account when work ends.
Two things a collaborator never gets: Shopify POS and the Administrator role. Both sit on the staff side.

What You'll Learn

1Staff seat or collaborator, by situation
2Which plans allow users at all
3What each permission category controls
4What to give an assistant or bookkeeper
5What staff still see without Finance
6What to revoke the day they leave

Your developer asks to be made an admin. Your bookkeeper wants to see payouts. The assistant who processes orders is asking why she cannot print shipping labels. Each of those is the same decision wearing different clothes: which door you open, and how wide.

Shopify gives you two doors into the admin — a staff seat, which spends a place on your plan, and a collaborator account, which a Shopify Partner requests and which spends nothing — plus a POS-only lane for counter staff who never enter the admin at all. Behind both admin doors sits a store-permission system of nineteen categories. This guide is about choosing the door and setting the width. Everything here is read off Shopify's own documentation, as of August 2026.

The Quick Verdict

Key takeaway

Find your own case in column one — everything after this table is the evidence underneath it. The two mechanisms named in column two, a staff seat and a collaborator account, are defined in the section that follows.

Which door, by who they are

Your situationPickWhy
Someone working your orders day to dayStaff seat, Customer support roleIt is Home plus every Orders and Draft orders permission, refunds and cancellations included — Shopify says you can edit a predefined role if that is more than you want
A bookkeeper reconciling payoutsStaff seat, bookkeeper-shaped roleShopify publishes this combination: finance and reports to read, orders to view and export but not edit, refund or cancel
An agency or freelancer on your themeCollaborator request codeIt costs no plan seat, and you approve the permission set they asked for before they get in
Help you need for a few weeks, not foreverCollaborator code if they're a Partner — otherwise a staff seat with a diarised end dateOnly Shopify Partners can hold one — and it is the account Shopify documents an expiry for, after 90 days without a login
Someone at the counter on Shopify POSStaff seat or POS-only staffCollaborators have no access to the Shopify POS app or the Point of Sale channel at all

Two Ways In, and They Are Not the Same Door

Key takeaway

The request almost always arrives in the wrong shape. "Can you make me an admin?" describes a level of power, not a mechanism — and the mechanism is the part that decides what is even possible. Before you decide how much to give, decide which of the two accounts you are creating.

Why the wording in your admin keeps changing

Most guides you will find still say staff accounts. Your admin says Users and Roles, and Shopify's own name for the mechanism is role-based access control. The help pages moved with it: the old staff permissions descriptions address now lands on a page titled Managing users.

It matters for one practical reason. When you cross-check anything in this guide against Shopify's documentation, search for users and roles rather than staff accounts, or you will land on third-party pages describing a model that has moved on.

What a staff seat actually is

A staff seat begins with an invitation to an email address. The person creates their own login, you attach a role to it, and the account occupies one of the user slots your plan includes. It is the mechanism for everyone on your side of the business: employees, a virtual assistant, a warehouse packer, a bookkeeper you pay monthly.

One detail catches people out at the very start. Invitations to create a staff login expire in seven days, and an expired invitation is not re-sent on request: Shopify's instruction is to remove the user and add them again to trigger a new one. If your new hire starts in three weeks, send the invitation nearer the date.

What a collaborator account is

A collaborator account works the other way round: the person asks you. Collaborators are Shopify Partners you have allowed into your store, and requesting that access requires a Shopify Partner account. They log in from their Partner Dashboard rather than through your store's login page — and after that first Dashboard login, from the Shopify mobile app too.

The request code is the part that gives you control. You generate a code and share it only with the agency or freelancer you are hiring, and only Partners holding that code can ask for access to your store. If the code has been passed around, you generate a new one and every old code stops working. Nothing about this involves handing over your own password.

Security is not optional on that side of the door, which is the one place Shopify is blunt about a requirement rather than a recommendation.

Without two-step authentication activated, collaborators cannot log in to your store.
Shopify — Collaborator accounts — Shopify Help Center ·

Read the boundary of that carefully, because it is widely misquoted. Two-step authentication is a condition of the collaborator mechanism itself, and Shopify attaches no plan requirement to it. Forcing a secure sign-in method across every user in an organization is a different feature, and that one is limited to Shopify Plus. For ordinary staff, Shopify's wording is that you can encourage them to turn it on — the full picture is in our answer on whether Shopify requires two-step authentication.

The differences that actually decide it

None of the nine rows below is a matter of preference: no permission setting anywhere in your admin will change any of them.

Staff seat vs collaborator account

What differsStaff seatCollaborator account
Counts against your plan's user limitYesNo — collaborators are exempt
Who it can beAnyone you invite by emailA Shopify Partner, and only a Partner
How they get inYour store's admin loginPartner Dashboard, or the Shopify app after one Dashboard login
Who starts itYou send an invitationThey send a request, using your code
Shopify POSAvailable, with POS roles or POS-only staffNo access to the POS app or the Point of Sale channel
Administrator roleCan be assignedCannot be assigned
Store ownership transferPossibleNot possible
Billing emails, with the billing permissionReceivedNot received
Expires on its ownNot documented — you deactivate or remove it yourselfAfter 90 days without a login

Both sides read on Shopify's collaborator accounts and user limits pages, August 6, 2026. Removal removes the account, not the history: Shopify states that a removed collaborator's name and actions remain in timelines such as the store activity log.

What Your Plan Actually Lets You Do

Key takeaway

Merchants tend to collapse these into one question and then optimise the wrong thing — refining a role they cannot create, or upgrading a plan when the person did not need a seat in the first place. They are different gates, and you hit them in order.

Gate 1: does your plan include user seats?

The seat count is published as a plain table, and users are available only on the Grow plan and higher. You check your own position in Settings → Users; if the plan is Basic or Starter, Shopify's own instruction is to upgrade to Grow, Advanced or Plus.

User accounts included, by plan

PlanMaximum user accountsWhat it means in practice
Pause and Build1One user while the store is parked
Starter0No staff seat to give — the exempt lanes are the only way in
Basic0Same as Starter: users start on the plan above
Grow5Five seats, enough for a small team plus a bookkeeper
Advanced15Fifteen seats, and roles you can shape per department
Shopify PlusUnlimitedSeats stop being the constraint; organization roles take over

Shopify Help Center, user limits by plan, read August 6, 2026. These counts are additional user accounts — the store owner is exempt and never occupies one.

The zero is narrower than it looks

Shopify states that the zero-user limit on Basic and Starter applies to staff accounts only, and names four user types exempt from the limit altogether:

  • the store owner
  • the organization owner
  • collaborators, with no cap
  • POS-only staff, with no cap

That is the most useful lever on this page: an agency can work on a Basic store without a seat ever existing, and so can counter staff, once the store has Shopify POS — the POS conditions are in the role table below.

Downgrading has its own logic worth knowing before you plan a move: when a plan change reduces your seats, Shopify suspends pending users first, starting with the most recently invited, and then active users by how long they have been inactive. What a seat costs, and where the upgrade sits against the rest of your invoice, belongs to our breakdown of the fees the pricing page underplays.

Gate 2: which roles you are allowed to use

Passing the first gate does not hand you the whole role system. A second set of conditions decides what you can build once you have someone to build it for — and this is the one people discover halfway through a permission plan.

Role machinery, by plan

CapabilityWho gets itIf you don't
Store roles — Shopify's own and custom onesEvery plan other than Basic or StarterNeither Shopify's own store roles nor custom ones exist on those two plans
Custom organization rolesShopify Plus, multi-store organizations not on Plus, and partner organizationsOrganization-level permissions stay out of reach on a single store
GroupsShopify PlusUsers are assigned roles one at a time
SCIM user provisioningShopify PlusJoiners and leavers are handled by hand, not by your directory
POS roles and POS-only staffStores with the Point of Sale channel and at least one location on POS ProCounter staff need a different arrangement — see the POS row in the staff-seat vs collaborator table

Shopify Help Center — role categories, migrate to roles, and user limits by plan, read August 6, 2026.

Two of those rows have owners elsewhere, and Organization-level permissions have a reference page of their own. Directory-driven provisioning — SCIM, and the single sign-on setup that usually comes with it — is Plus territory and part of the wider enterprise picture we cover in the B2B on Shopify Plus guide. The POS row has a subscription behind it rather than a plan: POS roles and POS-only staff need the Point of Sale channel and at least one location on a POS Pro subscription.

Which Door Is Yours?

Key takeaway

The verdict table sorts people by job. That is the right first cut, but it assumes every lane is open to you, and often one is not. The quiz below answers the other question — not who they are, but which mechanism your own situation still allows. Five questions, about a minute, and no wrong answers: every route it returns is a legitimate way to let someone in.

Staff Seat or Collaborator?5 questions · about a minute · every route it returns is a legitimate way in
Question 1 of 5
Who are you letting in?

How Shopify Permissions Are Actually Organized

Key takeaway

Once the door is chosen, the width is a matter of ticking boxes — but the boxes are arranged in a way that rewards five minutes of orientation. Two structural rules and one long list cover almost everything you will need.

Roles, categories, and the rule that trips people up

There are four role categories — Store, Organization, Point of sale and Partner — and each represents a different business context. The rule that surprises people is that a role can hold only one category: you cannot build a single role mixing store permissions with organization ones. You can, however, assign roles from different categories to the same person, where more than one category is available to you.

Organization roles grant access to organization features across every store in the organization, but they do not conjure accounts: Shopify notes that staff accounts must still be created for each store before anyone can get into it. Store roles work the other way, granting access to one store — or to several, when the stores belong to the same organization.

The 19 categories, and what to watch for in each

Shopify groups store permissions into 19 categories. Reading the list end to end is not the point — the third column is. It carries the boundary inside each category that determines whether the role you build does what you think it does.

Store permission categories, and the boundary inside each

CategoryWhat it coversThe boundary that surprises people
Home1 permissionIt shows the Home page, which carries sales information
Orders19 permissionsCharging, refunding, cancelling, buying shipping labels and exporting are each their own toggle
Draft orders9 permissionsPayment terms and charging a card are separate from creating the order
Products7 permissionsView hides cost — View cost is its own permission
Inventory4 permissionsAny of them auto-selects View products, and it can't be deselected
Catalogs3 permissionsThe same hard dependency as Inventory: View products comes along and cannot be removed
Gift cards4 permissionsDeactivate also allows viewing and exporting gift cards
Customers9 permissionsRequest data is flagged as a sensitive permission
Analytics2 permissionsYou can't specify which reports users can access
Marketing1 permissionCampaigns and automations travel together
Discounts1 permissionIt includes exporting discounts to CSV
Content7 permissionsMenus, metaobject definitions and their entries are governed separately
Files4 permissionsView, Create and Edit arrive with Products, Metaobject definitions or Entries, Themes or Blogs and pages — deselectable
Online store3 permissionsEdit code doesn't block or prevent access to the Assets API
Checkout and customer accounts3 permissionsIdentity providers and store-credit visibility live here
Companies7 permissionsThe location restriction filters only four admin pages
App development3 permissionsCustom app development isn't permitted by default
Store settings15 permissionsChanging the plan is delegable; pausing or deactivating the store is not
Finance6 permissionsStore-level only — on Plus, billing moves to organization roles

Shopify Help Center, store permissions, read August 6, 2026. Permission counts are ours: one row of Shopify's tables counts as one permission.

Adding those up gives 110 individual permissions — 108 across the nineteen store categories plus two app permissions — but treat that as our count, not a Shopify figure: Shopify publishes the categories and the descriptions, never a total. POS permissions sit outside it entirely, because they are managed through organization roles rather than store permissions.

Narrowing access to specific apps and channels

Apps are governed by two permissions of their own: Manage and install apps and channels, which lets someone add, access or delete apps, and Approve app charges, which is separately required to install anything that starts as a free trial and turns into a paid subscription.

The narrowing is the useful part. If you check specific apps and sales channels when granting access, the person can only reach those apps and channels, and cannot install or delete apps. That is the setting behind "give the email agency Klaviyo and nothing else", and it works for collaborators and staff alike.

Building custom apps is a third thing again. It lives under App development, custom app development is not permitted by default, and enabling it also requires the app management permission — a deliberate double lock rather than an oversight.

Why your admin does not match older guides

If the screenshots you find online show a flat list of checkboxes attached to a person, they predate the current model. Shopify moved to a new model and set a deadline for the old one.

Shopify's new role-based access control (RBAC) model is now available for your store or organization. This update is designed to enhance how permissions are assigned and managed, making user management more efficient and secure as your business grows.
Shopify — Role-based access controls — Shopify Changelog ·

Three dates explain almost every discrepancy between a guide you find and the screen in front of you.

Role-based access control arrives
Shopify made the RBAC model available for stores and organizations. Permissions stopped being a flat list attached to a person and became roles you build, name and assign.
Legacy permissions were converted automatically
Permissions for users and groups with legacy access were converted into roles, with one auto-generated role per unique set of permissions — the reason inherited stores carry oddly named roles. The conversion ran through June.Source: Migrate to roles — Shopify Help Center
Four new permissions for payments, payouts, disputes and tax documents
Manage payments settings, Manage disputes, View payouts and View tax documents joined the role editor. As of August 2026 the changelog still describes them as rolling out, so your store may not show all four yet.Source: New and updated staff permissions — Shopify Changelog

The middle event is the one that shows up in real stores: if you have inherited a shop with roles named after nobody in particular, that is the automatic conversion, which generated a role for each unique set of permissions rather than trying to guess your intent.

What to Give Each Kind of Helper

Key takeaway

The verdict table answered which door each person goes through. This section answers the other half of the decision — how wide to open it, and which single permission you would regret handing over. Shopify publishes fewer templates for that than merchants expect: two examples of a custom role you can build, plus one predefined role that already exists in your admin. A third block on the same page is not a template at all — it is there to say that for a collaborator you do not build a role in advance, because the Partner asks for the permissions and you approve the request.

Five profiles, and the permission you would regret

Who they areGiveDeliberately leave offWhere this comes from
Someone working your ordersThe Customer support role: Home, all Orders, all Draft ordersNothing, as it comes — to withhold refunds, edit this predefined role or build a custom oneShopify's predefined role
A bookkeeper or accountantHome; Finance to view payouts and billing; Analytics reports; view and export OrdersEditing, refunding or cancelling orders; products; store settingsShopify's published example
Warehouse and fulfilmentHome; Orders to view, fulfil and ship; Inventory management; Products view onlyFinance, Customers and store settingsShopify's published example
An agency or developerWhat their collaborator request asks for, narrowed to specific apps and channels where that fitsAdministrator, which they can't hold anyway; Customers > Request data unless the job needs itOur reading, on Shopify's advice to grant only what you're comfortable with
A short-term contractorA collaborator request code, if they're a Shopify PartnerA staff seat where a collaborator account would do — the documented 90-day expiry covers collaborator accountsOur conclusion from two documented facts

Columns two and three follow Shopify's published examples where the fourth column says so; the remaining rows are our reading of the permission descriptions, marked as such.

What we looked for and did not find

As of August 2026 we read Shopify's Help Center pages on collaborator accounts, custom role examples, predefined roles, store permissions, inviting users, managing users, the user management activity log and the users security index, plus its documentation on custom apps, uninstalling apps, exporting orders and managing custom reports, and its blog post on hiring a virtual assistant.

Several things merchants expect to find are simply not published on those surfaces, and each is named again in the section where it matters. The absence is itself the finding: where Shopify documents no template, the honest answer is a combination you assemble and own, not a rule you can cite.

The assistant who works your orders

There is a role for this already. Customer support is one of Shopify's predefined roles, and its contents are published exactly: Home, all permissions in Orders, and all permissions in Draft orders. For an assistant whose job is processing what comes in, that is a one-click answer.

The word doing the work there is all. Every Orders permission includes refunding, cancelling and exporting. If that is more than you want, Shopify says you can edit or delete predefined roles, so Customer support can be adjusted rather than treated as fixed — and the plan gate above still matters, since the store roles Shopify manages and the custom ones you build are both named as unavailable on Basic and Starter.

One thing you will not find is a named template for this job under the label merchants actually use. No official page we have found publishes a role template for a "virtual assistant" — the surfaces we read are listed in the box above. Customer support is the closest published thing, and the rest is your own combination.

The bookkeeper who reconciles payouts

This one Shopify does describe, and the description is worth reading before you build the role, because it defines the job in terms of what the person reads rather than what they change.

A bookkeeper or accountant role suits someone who reconciles payouts, reviews orders, and exports data for taxes. These users read financial and order data, but they don't change products or store settings.
Shopify — Custom role examples — Shopify Help Center ·

The combination Shopify publishes for that role is short:

  • Home
  • Finance permissions to view payouts and billing
  • Analytics permissions to view reports
  • View and export access to Orders, without the ability to edit, refund or cancel them

One boundary travels with it. Finance permissions are store-level: if your store is part of an organization, organization-level billing access is managed with the Billing organization permissions instead. For Plus merchants it goes further — payment settings move to organization roles as well, and the store-level finance permissions stop applying. Check which of the two worlds you are in before you promise your accountant anything.

This is access to your admin, which is a different question from how your sales end up in your books. Nothing here covers reconciling ledgers, syncing invoices or picking a bookkeeping tool — the role above simply lets a person read the numbers where they already live. That other half, from the payout-versus-order decision to what a connector actually moves, is covered in our guide to Shopify accounting.

The agency or freelancer working on your theme

For a Partner you do not build a role at all. The request arrives with an auto-generated role built from the permissions they asked for, named along the lines of Collaborator name x Store name, and you can rename it. Your job is reviewing the request, not designing it — and the Finance ticks in that request are the ones that decide whether the agency sees your payouts. Shopify's advice to merchants on how to review it is unusually direct: "Give only the permissions that you feel comfortable giving. If a freelancer or agency asks for certain permissions, then there might be a good reason. If you aren't sure, then ask the freelancer or agency why they need the permissions."

The request screen may show you some context about the Partner — how long they have been a Partner, how many active collaborations they have, where they signed up from — but Shopify is careful to say those details might be displayed rather than will be, and that they do not guarantee identity, work quality or intent. Judging the firm itself is a separate exercise, and our guide to hiring a Shopify developer covers the vetting side.

Ask one question before the work starts, because the documentation does not answer it for you. No page we have found describes what happens to an installed app, or to a custom app's API access, when the account that installed or created it is removed from the store — the surfaces we read are in the box above. If your developer is building a custom app, agree in advance who owns it and how it keeps running after the engagement ends.

The contractor you need for a few weeks

Here the documentation runs out, and it is worth being explicit about where our advice starts. No official page we have found names a "temporary contractor" arrangement or a time-limited staff account, and the surfaces we read are listed above. What exists are two separate documented facts, and the recommendation below is ours, assembled from them. Shopify does go one step in this direction: its collaborator example says to grant access for the scope of the project and remove the collaborator account from your store when the work is done.

The first is that a collaborator request code is under your control: only Partners you share it with can ask for access, and generating a new code kills the old ones. The second is that a collaborator's access expires after 90 days without a login. Put together, that is the closest thing Shopify has to access with a built-in end date — which is why, when the short-term helper is a Partner, we would route them through a collaborator account rather than a seat.

When they are not a Partner, read the mechanics carefully. The seven-day expiry applies to the invitation, not to the access it creates — accepting it produces an ordinary staff account, while the inactivity expiry Shopify documents is the collaborator one. For a fixed engagement, put the end date in your calendar and treat the removal as a scheduled task rather than something you will notice.

What a Staffer Without Finance Permissions Still Sees

Key takeaway

Shopify does not publish a page called "what your staff can still see", so the section below is assembled from the permission descriptions themselves rather than quoted from a single source. Every individual fact in it is Shopify's; the picture they add up to is ours.

The boundaries that surprise people

Home alone shows sales
The Home permission lets a user view the Home page, which Shopify describes as including sales information and other store data.
Product cost is a second toggle
View products deliberately excludes cost. If you want margins hidden, the permission to leave off is View cost, not View.
Analytics is all or nothing
Shopify states you can't specify which reports users can access — the Reports permission is granted whole, and Overview and Live view sit behind the separate Dashboards permission.
Inventory drags products in
Every inventory permission auto-selects View products, and that selection can't be deselected afterwards.
Files ride along
View, Create and Edit for Files are selected automatically when you assign any Products permission, the Metaobject definitions or Entries permissions under Content, or Themes or Blogs and pages under Online store. Unlike the inventory and catalog pull-ins, these you can still deselect by hand.
Seeing an order isn't moving money
Viewing orders is separate from charging a card, capturing payment, refunding and cancelling — those are individual permissions.

There is a plan-shaped boundary underneath all of them. Finance permissions are store-level: if your store is part of an organization, organization-level billing access is managed with the Billing organization permissions instead, and for Plus merchants billing and payment settings are managed at the organization level entirely, with the store-level finance permissions not applying.

B2B stores have one more. The Companies category includes a restriction that limits a user to their assigned company locations — but Shopify is precise about how far it reaches: it filters only Orders, Draft orders, Customers and Companies, and all other pages in the admin are not filtered by company. Even inside those four pages the filter is not total: some customer values, such as Amount spent, still show totals for all locations. Alongside it, you can assign up to 10 sales staff to each company location, and the same person can be assigned to several. Shopify says that staff who had Customers permissions before January 31, 2024 were automatically granted Companies permissions, because Companies permissions were previously part of Customers permissions.

Which permissions Shopify calls sensitive — and where its own pages disagree

Shopify marks some permissions as sensitive, which is a useful shortcut when you are reviewing a role in a hurry. It is also the one place in this topic where two live official pages tell you different things, so it is worth seeing both.

Its dedicated sensitive permissions page tabulates six across the Store, Organization and Partner categories, and lists one more — Store settings > Manage other payment settings — for the Point of Sale channel underneath the table. The store permissions page, read the same day, describes two further permissions with the same sentence — "This is a sensitive permission" — that the six-row table does not include.

Sensitive permissions, and where each is flagged

PermissionWhere Shopify flags it
Customers > Request data (Store)The sensitive-permissions table, and its own description
Store settings > Edit billing payment methods and pay invoices (Store)The sensitive-permissions table, which files it under Finance instead
Finance > Manage other payment settings (Store)The sensitive-permissions table
Business entities > View sensitive information (Organization)The sensitive-permissions table
View financials (Partner)The sensitive-permissions table
Manage credits and refunds (Partner)The sensitive-permissions table
View tax documents (Store)Only in its own description on the store permissions page
Manage payments settings (Store)Only in its own description on the store permissions page

Both pages read on August 6, 2026, and re-read to rule out a stale cache. The two highlighted rows are the disagreement: flagged in their own descriptions, absent from the dedicated table.

What to do while the two pages disagree: read the description of the permission on the page where you are actually ticking the box, because that is where Shopify writes the warning next to the setting itself. Treating the wider list as sensitive is the cheaper mistake — a permission you withhold can be granted in a minute, and one that quietly exposed tax documents cannot be un-granted retroactively.

Can you give someone one report instead of an account?

It is the natural instinct — the accountant needs a number, not the keys — and the honest answer is that nothing in the documented permission system is shaped that way. No official page we have found describes handing someone a report or an export instead of giving them an account; the surfaces we read are listed in the box above. Every export path we read assumes the person pressing Export already has a role that allows it.

The permission system pushes the same way. Analytics cannot be narrowed to a single report, and any store staff with the Analytics permissions can access the reports you create, as well as duplicate and modify them. A reporting-shaped role is therefore a whole-reporting-surface role.

What you can do instead is narrow the role to the Export permission that matches the job, and let the person pull the file. One boundary comes with that: exporting up to 50 orders downloads the CSV to the device, while exporting more than 51 orders, or exporting by date, emails the file to the person who asked and to the store owner. Customer exports behave the same way: over the threshold they are emailed, and if the person is not the store owner, a copy goes to the owner as well.

Who Can Hand Out Access at All

Key takeaway

For single stores not on the Shopify Plus plan, the list is two entries long: the store owner, and users with the Administrator store role. For organizations and Plus stores it becomes four — the organization owner, the store owner, users with the Organization administrator role and users with the Store user administrator role. POS staff are managed separately again, by the store owner, the organization owner and the POS user administrator role, and only for locations on POS Pro.

Delegating user management does not delegate everything. The Administrator role explicitly cannot perform ownership changes, and the Store user administrator role is narrower still: it cannot create or edit roles, delete users from an organization, assign organization-level roles, manage groups or suspend users. And six things belong to the owner account alone, whatever anyone's role says.

Managing Shopify Payments
The payments account itself stays with the store owner, whatever the Finance permissions say.
Creating and managing Shopify Balance
The Balance account is owner territory and can't be delegated through a role.
Accessing Shopify Capital settings
Capital settings sit outside the permission list entirely.
Pausing or deactivating the store
Changing the plan can be delegated; switching the store off cannot.
Transferring or changing ownership
No role does this — Administrators are explicitly excluded from ownership changes.
Some optional and early-access features
Some optional or early access features that require Shopify Support's assistance to activate must be requested by the store owner.

The same logic explains a collaborator limit that otherwise looks arbitrary. A collaborator cannot hold the Administrator role and cannot receive store ownership — not because you forgot a checkbox, but because the account type is built that way.

When the Person Leaves

Key takeaway

This is where the documentation is thinnest. No official page we have found gathers the steps for revoking access into a single checklist — the mechanics are documented in pieces across the pages listed in the box above, and the word offboarding does not appear on them. The list below is assembled from those pieces, which is exactly why it is worth having in one place.

Deactivate or remove: they are not the same

Deactivating a user stops them logging into your store and can be reversed later — the right move for a leave of absence, a suspended contract, or freeing a seat you may want back. Removing is permanent, cannot be undone, and asks you to enter the password of the account you are signed in with before it will proceed.

Two side effects are worth checking before you choose. If the person is a Shopify Credit secondary cardholder, deactivating them locks their active cards while removing them cancels the cards outright. And removal deletes the account, not the record: a removed collaborator's name and actions remain in relevant timelines, such as the store activity log and order timelines.

Your access-revocation checklist

Work through it on the day the engagement ends rather than the week after. If you are picking up a store somebody else ran, the same steps apply, but the wider sweep — old apps, leftover code, orphaned integrations — belongs to our store code audit walkthrough, which treats inherited access as one item on a longer list.

Access Revocation Checklist

Six steps, assembled from Shopify's own documentation. The order matters: revoke first, verify second, then look at who is left.

0 of 6 done
  1. Deactivating stops the login and can be reversed; removing is permanent and asks for the password of the account you're signed in with.

  2. Collaborators are removed from the Users and permissions page, permanently, with the same password confirmation.

  3. A new request code invalidates every old one, so a code that has been passed around can no longer be used to ask for access.

  4. The log tracks user and role changes with an event, a resource, a date and a user, and login history shows the five most recent sessions.

  5. A secondary cardholder's active cards are locked when you deactivate the user and cancelled when you remove them.

  6. Roles outlive the people who needed them, so review the remaining users against the jobs they actually do now.

The 90-day timer deserves one last word, because it is easy to lean on. Shopify's own framing is sequential: remove the account when you no longer need the collaborator, and otherwise access expires after 90 days without a login. It is what catches the account you forgot, not the process you should be running.

The Bottom Line

Key takeaway

Most of the anxiety around this topic comes from treating it as a security question, when it is really a clarity question. You are not deciding whether to trust the person — you are deciding which of two accounts fits the work, and which of nineteen store categories that work actually touches.

Ask for the permission list before you grant anything. The one habit that prevents almost every problem on this page is making the other person name what they need and why. Shopify recommends it for agencies, and it works just as well for an assistant: a request you can read is a request you can narrow, and a role you narrowed once is a role you can review later without unpicking a mystery.
Your Next Step by Stage
Just startingBasic and Starter include no staff seats — only the exempt lanes. See which plan actually fits before you promise anyone access.Choose the right Shopify plan
Commissioning custom workCustom app development is a permission of its own, and it is switched off by default. Know what the work involves before you enable it.Custom Shopify development
Bringing in outside helpWork with a developer who requests collaborator access and names the permissions the job needs, rather than asking for your login.Hire a Shopify developer

Before You Hand Over the Keys

Granting access is a five-minute job you should do yourself. Knowing which permissions a build actually needs is the part that is worth pinning down first — a scoped brief lists them, so you grant those and nothing else.

Get a scoped project quote

Frequently Asked Questions

No. Shopify states that collaborators don't count towards your store's user limit, and the same page lists collaborators and POS-only staff among the user types exempt from it. That is why an agency can work on a Basic store which has no staff seats at all, provided the person is a Shopify Partner.
Not as staff accounts. Shopify's user limits table gives Basic and Starter zero user accounts and says users are available only on the Grow plan and higher, so adding one means upgrading. The zero applies to staff accounts specifically: the store owner, collaborators and POS-only staff are all exempt from it.
A staff seat is an account you create by emailing an invitation, and it counts against your plan's user limit. A collaborator account belongs to a Shopify Partner who requests access with a code you issue, logs in from their Partner Dashboard, and never counts against that limit. Only a staff seat can hold the Administrator role.
It is the term most guides use and the label on Shopify's pricing comparison, but the manual now talks about users and roles, and Shopify's own name for the mechanism is role-based access control. The old staff permissions descriptions URL now serves the manual's Managing users index instead, so search for roles when you cross-check.
No. Shopify states plainly that you can't assign the Administrator store role to collaborators, and in organizations they also can't take organization roles or the Store user administrator role. Store ownership can't be transferred to a collaborator either. If you need a stand-in admin, that person needs a staff seat.
You give them a collaborator request code. Only the Partners you share that code with can request access to your store, and you approve the permissions they asked for. You can generate a new code whenever you like, and older codes stop working. Sharing an owner login instead hands over everything, billing included.
It expires. If a collaborator user hasn't logged into your store within 90 days, their access ends automatically, and you can reinstate it from the Users and permissions page through Actions and Reactivate user. Shopify frames that timer as what happens when you haven't removed the account yourself, not as an offboarding process.
Yes, and Shopify publishes the combination: Home, Finance permissions to view payouts and billing, Analytics for reports, and view-and-export access to Orders without the ability to edit, refund or cancel them. If your store belongs to an organization or is on Plus, billing access is managed through organization permissions instead.
No. Shopify says directly that you can't specify which reports users can access, and any store staff with Analytics permissions can access, duplicate and modify the reports you create. The narrowest honest option is a role carrying the relevant Export permission, so they pull the file they need rather than browsing everything.
On a single store that isn't on Shopify Plus, exactly two kinds of user: the store owner and anyone holding the Administrator store role. For organizations and Plus stores, the users who can view and grant access requests are a different four: the organization owner, the store owner, Organization administrators and Store user administrators. Even an Administrator can't perform ownership changes on your behalf.
Decide between deactivating, which stops the login and can be reversed, and removing, which is permanent and asks for your password. Remove any collaborator account separately, generate a fresh request code, then read the user management activity log and the recent login sessions to confirm nothing unexpected happened.
Yes. When you approve access you can assign permissions for specific apps and sales channels, and Shopify states that a user restricted this way can only access those apps and channels and can't install or delete apps. Building custom apps is a separate permission, and custom app development isn't permitted by default.
About This Article
Shopify Developer & E-Commerce Writer
9+ years with Shopify since 2017

Front-end developer specializing in Shopify since 2017. Experienced in building custom Liquid themes, optimizing storefront performance, and integrating third-party apps. Writes in-depth, data-driven e-commerce guides based on hands-on experience with real merchant stores.

This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.

Editorial Policy
Continue Learning

What to Read Next

Stay updated

Get notified about new articles

Subscribe to receive updates when we publish new Shopify guides and insights.