Curated Free Backlinks is live · Browse vetted free-submission opportunities with fit, submission steps, and risk notes.

1/2
Beginner50 minutesStep 3

Users, Roles, and Security: Give Each Person Only What They Need

Create individual accounts and least-privilege roles for owners, operators, support, developers, and collaborators, then complete 2FA, recovery codes, and offboarding controls.

3
Current Lesson
3/20 lessons

Published

Updated

Last reviewed

Review note: Reviewed the current Shopify Help Center for English admin paths, eligibility, risk boundaries, and acceptance steps.

Review scope Reviewed against Shopify, Google Search, ads, analytics, and ecommerce operating workflows.

Lesson Progress
Progress
3/20 lessons
Current lesson unlockedContinue in sequence
Text version of this lessonExpand

Phase 1 Account and store foundations

Create individual accounts and least-privilege roles for owners, operators, support, developers, and collaborators, then complete 2FA, recovery codes, and offboarding controls.

Admin path
Settings > Users
Estimated time
50 minutes
Course phase
Phase 1 Account and store foundations
English Shopify admin: Settings > Users list
Figure 3-1: Settings > Users list

Why this lesson comes now

A small team is not a reason to share one admin account. Shared logins remove accountability, security boundaries, and clean offboarding. Each person should sign in separately and receive a role based on work. Developers and agencies should use collaborator or restricted access rather than the owner password.

What you should have at the end

A permission matrix, 2FA status for every active user, recovery-code custody, collaborator expiry dates, and a standard revocation procedure.

Prepare before opening the admin

  • List everyone who will access the store, including contractors, agencies, developers, and report-only users.
  • Group work into products, orders, customers, marketing, analytics, finance, settings, and apps.
  • Prepare the company password manager and recovery-code custody process.

Follow the English admin step by step

After each step, refresh the admin or verify the storefront. A saved state in admin does not automatically prove the customer-facing result.

1

Keep one owner account

Confirm that the store owner is a durable responsible person. Do not use this login for every product, order, and support task. Reserve it for ownership, security, and selected high-risk settings.

2

Create roles by job

Open Settings > Users, review existing roles, and create operations, support, finance-read-only, and technical roles. Name roles by purpose instead of Admin 1 or Admin 2.

English Shopify admin: Role permission editor
Figure 3-2: Role permission editor
3

Reduce permissions field by field

Support usually does not need payment or app-install access, developers usually do not need customer exports, and finance-read-only does not need theme editing. Start with the minimum and expand only for a defined task.

4

Invite individual users or collaborators

Each person accepts with an individual email. Agencies and Shopify Partners should use collaborator access where appropriate and receive a revocation date. Never send the owner password through chat.

English Shopify admin: Two-step authentication status
Figure 3-3: Two-step authentication status
5

Require and verify two-step authentication

Require two-step authentication for high-privilege users, especially owner, payments, user management, and app access. Sign out and back in once to prove the authenticator or phone works.

6

Store recovery codes and create an offboarding checklist

Store recovery codes in a controlled vault rather than one person's screenshot. When work ends, revoke the user, review app and API access, rotate shared secrets, and check activity logs.

How North & Pine configures it

North & Pine has owner, operations, support, and external developer roles. Support handles orders and customer communication, the developer receives only theme and approved-app access, and finance has read-only reports. Every privileged account uses 2FA, with recovery codes controlled by the owner and a second administrator.

Decisions to make in this lesson

DecisionRecommended settingWhy
Store owner One person Keeps ownership and recovery responsibility clear
Operations role Products, orders, discounts Does not include payments or user management by default
Developer role Themes and required apps Customer export, billing, and payments stay off by default
Collaborators Expiry-based revocation Access does not remain after the project
English Shopify admin: Collaborator revocation action
Figure 3-4: Collaborator revocation action

Do not change these blindly

  • Do not share the owner login or send its password to an agency.
  • Do not grant Full permissions to everyone for convenience.
  • Do not leave former users or collaborators active after work ends.

Completion standard

The lesson is complete only when every item below has evidence. Saying that the page was reviewed is not acceptance.

  • Every active person has an individual account.
  • Roles map to actual job tasks.
  • All privileged users have verified 2FA.
  • Recovery codes are in a controlled vault.
  • The offboarding checklist covers users, apps, API secrets, and activity review.

Common failures and fixes

SymptomWhat to do
An invited user cannot see a feature Check the assigned role and store or organization scope before escalating to Full permissions.
A collaborator asks for the owner password Use a collaborator request or restricted user and map the request to specific permissions.
A lost phone blocks 2FA Use controlled recovery codes or a backup method, then regenerate and replace old recovery codes after access is restored.

Frequently asked questions

What is the difference between a Shopify collaborator and a staff user?

Collaborator access is generally for Shopify Partners or agencies and is requested for specific permissions. Regardless of account type, use least privilege and revoke access when work ends.

Does everyone need 2FA?

At minimum, the owner and privileged users should enable it. A store-wide requirement is safer because a lower-privilege account can still become an entry point.

Does a developer need customer and order permissions?

Most theme work does not require full customer data. Grant temporary access only for a defined debugging task, scope, and period, then remove it.

Official sources

Admin labels and rules change. These official pages are the maintenance baseline, and every screenshot must be checked against the current English admin.

Post-lesson FAQ

After the lesson, resolve these common questions

What is the difference between a Shopify collaborator and a staff user?

Collaborator access is generally for Shopify Partners or agencies and is requested for specific permissions. Regardless of account type, use least privilege and revoke access when work ends.

Does everyone need 2FA?

At minimum, the owner and privileged users should enable it. A store-wide requirement is safer because a lower-privilege account can still become an entry point.

Does a developer need customer and order permissions?

Most theme work does not require full customer data. Grant temporary access only for a defined debugging task, scope, and period, then remove it.

Lesson HowTo steps

Complete this lesson step by step

  1. 1

    Keep one owner account

    Confirm that the store owner is a durable responsible person. Do not use this login for every product, order, and support task. Reserve it for ownership, security, and selected high-risk settings.

  2. 2

    Create roles by job

    Open Settings > Users, review existing roles, and create operations, support, finance-read-only, and technical roles. Name roles by purpose instead of Admin 1 or Admin 2.

  3. 3

    Reduce permissions field by field

    Support usually does not need payment or app-install access, developers usually do not need customer exports, and finance-read-only does not need theme editing. Start with the minimum and expand only for a defined task.

  4. 4

    Invite individual users or collaborators

    Each person accepts with an individual email. Agencies and Shopify Partners should use collaborator access where appropriate and receive a revocation date. Never send the owner password through chat.

  5. 5

    Require and verify two-step authentication

    Require two-step authentication for high-privilege users, especially owner, payments, user management, and app access. Sign out and back in once to prove the authenticator or phone works.

  6. 6

    Store recovery codes and create an offboarding checklist

    Store recovery codes in a controlled vault rather than one person's screenshot. When work ends, revoke the user, review app and API access, rotate shared secrets, and check activity logs.

Back to Course Outline
20
View All Tutorials

Share this lesson with your reviewer

Share it with the copyable lesson notes so everyone reviews the same evidence, decision line, and next action.