Shopify staff permissions are the access controls built into your store's admin that determine exactly which sections — orders, products, customers, finances, settings — each team member can view or edit. For growing South African ecommerce businesses on Shopify in South Africa, getting permissions right at the point of hire is far easier than cleaning up an over-permissioned account later.
It also keeps you on the right side of POPIA: giving staff broader access to customer personal data than their job requires is an unnecessary compliance risk — and Shopify's permission system is the operational tool for managing it.
The Shopify permission system works through roles: reusable bundles of permissions you configure once and assign to multiple team members. Every new user gets only what their role needs — nothing more. The challenge for most SA store owners is not the concept; it is translating Shopify's 20-category permission list into a specific tick-box configuration for each actual job function. That is what this guide does.
Quick Answer
Shopify staff permissions control which parts of your admin each team member can access. Staff accounts are only available on the Grow plan (5 users), Advanced plan (15 users), and Plus (unlimited) — stores on the Basic plan have zero staff account slots. You set up permissions in Settings > Users > Roles, assign granular permissions by category, and invite the team member by email. For each role, grant the minimum permissions the job genuinely requires.
Jump to a section
Which plans include staff accounts?
What each permission category controls
Permission mapping for common SA roles
How to set up staff accounts step by step
Staff accounts vs collaborator accounts
Not sure how to structure your Shopify store for a growing team?
Share your current setup and we will identify the permission gaps before they become a problem.
Get a free Shopify reviewWhich Shopify Plans Include Staff Accounts?
Shopify staff accounts are reserved for the Grow plan and above — a detail that catches many SA operators on the Basic plan off guard. The table below shows the limits per plan as published in Shopify's official plan requirements.
| Plan | Monthly price | Staff accounts | Best for |
|---|---|---|---|
| Basic | $39/mo (~R640) | 0 | Owner-operated stores only |
| Grow | $105 (~R1,724/mo) | 5 | Small SA teams with defined roles |
| Advanced | $399 (~R6,552/mo) | 15 | Multi-department SA operations |
| Plus | from $2,300/mo | Unlimited | High-volume enterprise stores |
Rand approximations at R16.42/USD (SADCI index assumption, Aug 2026 — not a live rate). Annual billing reduces the per-month cost across all plans; see Shopify's pricing page for current annual rates.
Important for Basic plan stores: If your store is on the Basic plan, you cannot add staff accounts — the slot count is zero. Your options are to upgrade to the Grow plan, or to use collaborator accounts (for external Shopify Partners/agencies only — not for your own staff). Collaborator accounts and POS-only staff do not count toward the plan limit.
What Each Shopify Permission Category Controls
Shopify organises store-level permissions into approximately 20 categories, each with granular sub-permissions. Understanding how Shopify store permissions are grouped makes it straightforward to map permissions to a job role without working through every sub-option individually.
| Category | What it covers | Sensitive? |
|---|---|---|
| Orders | View, edit, fulfil, refund, cancel, export orders; manage disputes | Yes — customer personal data |
| Draft Orders | Create and process draft orders; apply discounts; mark as paid | Moderate |
| Products | View, create, edit, price, export, delete products and variants | No |
| Inventory | Edit quantities, SKUs, barcodes; manage transfers and shipments | No |
| Customers | View and edit customer profiles; export data; erase personal data | Yes — personal data under POPIA |
| Analytics | View and create reports; access Overview and Live view dashboards | Yes — sales data |
| Marketing | View, create, delete campaigns and automations | No |
| Discounts | View, create, delete discount codes and automatic discounts | Moderate |
| Content | Menus, metaobject definitions and entries | No |
| Files | Upload, edit and delete media files | No |
| Online Store | Themes, code editing, blog posts and pages | Moderate — code access |
| Finance | View payouts from connected payment gateways, tax documents, payment activity (Shopify Balance sub-permission not applicable to SA stores) | Yes — financial data |
| Store Settings | Domains, shipping, taxes, locations, billing, store policies | Yes — operational control |
| Apps & Channels | Install, manage and approve charges for apps and sales channels | Yes — can incur costs |
| Gift Cards | View, create, edit, export and deactivate gift cards | Moderate |
| App Development | Create and enable custom app development | Yes — technical access |
The table covers the categories most relevant to common SA non-Plus operations. User and role management (adding or removing staff) is not available as a permission — only the store owner controls who has access. Shopify user permissions vary significantly by category; some grant read-only access while others unlock destructive actions like deleting products or erasing customer data.
Shopify Staff Permissions by Role — SA Business Guide
The table below maps each common SA ecommerce job function to the specific Shopify staff permissions to enable. Grant only what is listed; leave all other categories disabled. This directly applies the principle of least privilege — each team member accesses only the data their job genuinely requires.
| Role | Enable these permissions | Leave disabled |
|---|---|---|
| Fulfilment / Warehouse (pick, pack, ship) | Orders: View, Fulfill & ship, Buy shipping labels, Return Inventory: Manage inventory, View transfers, Manage transfers Products: View | Finance, Store Settings, Customers, Analytics, Marketing, Discounts, Apps |
| Customer Service Agent | Orders: View, Manage order info, Return, Refund to original method Customers: View, Create & edit Discounts: View | Finance, Store Settings, Products (create/edit/delete), Marketing, Apps, Analytics |
| Social Media / Marketing Manager | Marketing: All Content: All Files: All Products: View Discounts: View, Create & delete Online Store: Blog posts & pages | Finance, Store Settings, Customers, Orders (financial), Apps & Channels, App Development |
| Bookkeeper / Accountant | Analytics: Reports, Dashboards Finance: View payouts, View tax documents Orders: View, Export Store Settings: View billing | Products, Inventory, Customers, Marketing, Discounts, Apps, Online Store (code/themes) |
| Product Manager / Merchandiser | Products: All Inventory: All Content: All Files: All Gift Cards: View, Create & edit Discounts: View Online Store: Blog posts & pages | Finance, Store Settings, Customers, Orders (financial), Apps & Channels, App Development |
Key rule: If a staff member's job does not require them to see customer personal information — names, addresses, purchase history — disable the Customers and Orders > Export permissions entirely. This is not just good security practice; it aligns with POPIA's minimality principle for processing personal information.
How to Set Up Shopify Staff Accounts Step by Step
Setting up staff accounts in Shopify takes under five minutes once you know which permissions to assign — use the role mapping above before you start. Shopify roles and permissions are managed entirely through the admin without needing developer access.
- Create the role first. In your Shopify admin, go to Settings > Users > Roles. Click Add role, give it a name matching the job function (e.g. "Fulfilment Staff"), and tick the permissions from the mapping table above. Save the role.
- Invite the team member. Go to Settings > Users and click Add staff. Enter the person's first name, last name and work email address.
- Assign the role. Select the role you created in step 1. A single user can hold multiple roles — their permissions stack. Avoid combining roles in ways that re-introduce access you deliberately excluded.
- Send the invite. Click Send invite. The team member receives an email to activate their account and set a password.
- Verify access. Log in with a test account or ask the team member to confirm they can reach what they need — and cannot reach what they should not.
Security best practice: Never set up a shared login for multiple staff members — individual accounts create the audit trail you need if something goes wrong. Review all staff accounts quarterly: remove accounts for people who have left, and reduce permissions for anyone whose role has changed. Enable two-factor authentication (2FA) on all staff accounts.
Roles save time as you grow. Create one well-configured role per job function and you assign it to every new hire in that role with one click — no need to tick permissions manually each time. Update the role once and the change applies to everyone assigned to it.
Staff Accounts vs Collaborator Accounts
Staff accounts and collaborator accounts serve different purposes and are managed separately — confusing the two leads to over-permissioned external parties or under-supported internal team members.
| Feature | Staff account | Collaborator account |
|---|---|---|
| Who it is for | Your own employees | External Shopify Partners (agencies, freelancers) |
| Plan requirement | Grow and above | All plans |
| Counts toward staff limit? | Yes | No |
| Who controls the account? | Store owner | Partner organisation |
| Suitable for permanent hires? | Yes | No |
If you are working with a Shopify agency or a freelance developer, they access your store through their Partner account — not a staff slot. For a full breakdown of how that access works, see Shopify collaborator access for SA businesses.
Building your Shopify store team and not sure which plan fits your headcount?
Tell us your team structure and current plan — we will give you a straight answer on whether you need to upgrade and what it will cost.
Get a plan assessmentPOPIA and Shopify Staff Access to Customer Data
POPIA (the Protection of Personal Information Act) applies to every piece of personal information your store holds — customer names, delivery addresses, order histories and payment records. When a staff member can access Shopify's Customers section or export order data, they are processing personal information, which creates obligations for you as the responsible party.
POPIA's minimality principle requires that personal information be processed only to the extent adequate and relevant for the purpose. In practice, a fulfilment packer does not need access to a customer's full profile — they need the delivery address on the label, not the purchase history.
Giving all staff broad access to the Customers section raises your exposure in a data incident. POPIA's Schedule 1 provides for administrative fines of up to R10 million for specified contraventions. Use the shopify staff permissions mapping above to limit Customers access to roles that genuinely require it — customer service agents and management — and disable it for everyone else.
POPIA takeaway: Under South African data protection law, giving staff broader access to customer data than their job requires is not just an internal security risk — it is a potential compliance failure. The Shopify permissions system is the operational tool for satisfying this obligation.
Why South African Businesses Choose Growth Pulse Media for Shopify
Growth Pulse Media is a registered Shopify Partner agency built by an operator who scaled a large South African ecommerce business before founding the agency. That background means we configure Shopify the way a working SA store needs it — not the way a generic agency manual says to. We carry a limited client load deliberately, so every store gets senior attention, not a junior running off a checklist.
When we work with SA Shopify stores, we handle the integrations SA operators actually use: PayFast, Peach Payments, Yoco, Ozow for payments; The Courier Guy, Aramex and Dawn Wing for fulfilment; Klaviyo and Omnisend for email marketing. We are also Omnisend Certified Partners. Staff permission setup, role architecture and POPIA-aligned access controls are part of the build conversation — not an afterthought.
Who Shopify Staff Permissions Are NOT For
Stores on the Basic plan expecting staff account access. The Basic plan includes zero staff account slots. If you need to give a team member their own login before upgrading, there is no configuration workaround — the feature is plan-gated.
Solo operators running everything themselves. If you are the only person in the store, the permission system is irrelevant until you hire. Do not spend time configuring roles for hypothetical future hires — set it up when the hire is real.
Businesses looking to grant agency or freelancer access. External partners — developers, designers, agencies — access your store through Shopify's collaborator account system, not staff accounts. Staff accounts are for your internal employees only.
Ready to build your Shopify team the right way from the start?
Share your current setup and team structure — we will audit your permissions configuration and flag anything that needs tightening before it becomes a liability.
Request a Shopify permissions auditFrequently Asked Questions
Do Shopify Basic plan stores get any staff accounts?
No. The Basic plan includes zero staff account slots — staff accounts are only available on the Grow plan (5 users), Advanced plan (15 users) and Plus (unlimited). If you are on Basic and need a team member to have their own login, you need to upgrade to the Grow plan. Collaborator accounts for Shopify Partners are available on all plans but are intended for external agencies and freelancers, not your own employees.
What is the difference between a staff account and a collaborator account in Shopify?
Staff accounts are for your internal employees and count toward your plan's user limit. Collaborator accounts are for external Shopify Partners — agencies, freelancers, developers — and do not count toward the limit. A staff account gives the person a direct login to your store; a collaborator connects through their Partner dashboard. Use staff accounts for your team and collaborator accounts for your agency or developer.
Can I prevent a staff member from seeing customer personal information?
Yes. Shopify's permission system lets you disable access to the Customers category entirely for roles that do not require it. A fulfilment or warehouse role, for example, can be configured to see only what is needed to pick, pack and ship — without access to full customer profiles or the ability to export customer data. This is the appropriate setup for most operational staff who do not handle customer queries directly.
How do I remove a staff member's access when they leave the business?
Go to Settings > Users in your Shopify admin, find the staff member's account, and delete it. Their access is removed immediately. Do this as part of your offboarding checklist — a former employee with an active Shopify login is an unnecessary security risk. Also change any shared credentials or API keys they had access to.
Does POPIA require me to limit staff access to customer data on Shopify?
POPIA's minimality principle requires that personal information be processed only to the extent adequate and relevant for the purpose — which means staff should not have access to customer data unless their job genuinely requires it. The principle is not Shopify-specific, but Shopify's permission system is the practical tool for satisfying it. Giving all staff broad access to the Customers section when most of them do not need it creates unnecessary exposure and is inconsistent with a POPIA-compliant data governance approach.
Get Your Shopify Store Built and Configured Correctly
Growth Pulse Media is a registered Shopify Partner based in Johannesburg. We set up Shopify stores for SA operators with the integrations you actually need — PayFast, Peach Payments, The Courier Guy, Klaviyo, Omnisend — and the permission structure and POPIA-aligned access controls your growing team requires. Senior attention, limited client load, no obligation.
Talk to us — we'll get back to you within 24 hours

