September 28, 2026
Give every person their own login, and give each login only the permissions its job requires. Shared logins are how stores end up with mystery changes nobody owns and ex-contractors who can still get in months later. Shopify's permission system is granular enough for this: create a role per job function, assign the minimum permissions that let the job get done, and review the list every few months.
Shared logins feel efficient and cause every access problem stores actually have. When three people share one login, you cannot tell who changed the shipping rates, you cannot revoke one person's access without disrupting the other two, and the password ends up in a chat thread that outlives everyone's employment. Individual logins are free. Use them.
This applies to contractors and agencies too, especially to them. A freelancer who needed theme access for a week in March should not still have it in September. Individual logins make offboarding a one-click job; shared logins make it a password rotation that everyone resents.
Turn on two-factor authentication for every account with meaningful permissions. It takes a minute per person and it is the single highest-leverage security step a small store can take. Owners and anyone with settings access should have it on from day one.
Start with three roles that cover most stores. The fulfillment role gets orders, inventory, and shipping permissions: everything needed to pick, pack, and ship, and nothing that touches money or settings. The support role gets customers and orders with refunds disabled or limited: enough to help shoppers, not enough to move money freely.
The marketing role gets products, discounts, and content permissions: they can build promotions and edit pages but cannot change payment settings or install apps. Keep app installation restricted to owners. Apps can read customer data and modify the storefront, so installing them is an owner-level decision.
Resist the urge to hand out full permissions "just for now." Temporary full access has a way of becoming permanent, and every permission you grant is a permission you have to remember to revoke. Minimum permissions feel slower for a day and safer forever.
The most common mistake is giving financial permissions to roles that do not need them. Payouts, billing, and tax settings belong to owners. A support agent who can issue refunds is reasonable; a support agent who can change the bank account for payouts is a fraud waiting for an opportunity.
The second is ignoring the POS permissions. If the store has retail locations, POS access is a separate permission set, and the staff PIN is not a substitute for a proper login. Set POS roles to match the job: cashiers get sales and refunds within limits, managers get the rest.
The third is forgetting about collaborator accounts. Agencies and freelancers should come in as collaborators with scoped permissions and an expiry mindset, not as full staff. Review collaborator access after every project ends.
Put a quarterly reminder on the calendar to review the staff list. It takes five minutes: open the users list, remove anyone who no longer works with the store, and check that each remaining person still needs their permissions. This one habit prevents the slow accumulation of stale access that causes real incidents.
When someone leaves, revoke first and ask questions later. Remove their login the day their work ends, not the week after. The awkwardness of revoking promptly is nothing compared to the awkwardness of discovering they still had access.
Write down who has what. A simple list of names, roles, and permissions, kept somewhere the owner can find it, turns access management from a mystery into a checklist. Future you will be grateful.