Shopify's user and permissions system has changed significantly since 2021. The old Settings → Plan & Permissions path no longer exists. The current path is Settings → Users — and the types of access available, the authentication requirements, and the way agency and developer access works are all meaningfully different from what most guides describe.
This guide covers every access type available on Shopify in 2026: staff accounts, collaborator accounts, the collaborator request code, two-step authentication, and the Shopify Plus organisation admin. Whether you are adding a team member, granting access to an agency, or managing permissions across multiple expansion stores, the process is covered here.
The difference between staff accounts and collaborator accounts
Shopify has two distinct types of user access. Understanding which one you need before you start saves time and avoids confusion.
Staff accounts are for permanent or ongoing team members — employees, in-house marketers, customer service staff, or anyone who works on your store regularly. Staff accounts count against your plan's user limit. Basic Shopify allows 2 staff accounts, Shopify allows 5, Advanced Shopify allows 15, and Shopify Plus allows unlimited staff accounts.
Collaborator accounts are for external partners — agencies, developers, designers, or freelancers who need temporary or project-based access. Collaborator accounts do not count against your staff limit. Access is requested by the partner through their Shopify Partners dashboard and requires your approval via a collaborator request code. You can revoke access at any time without the collaborator losing their Partners account.
| Feature | Staff account | Collaborator account |
|---|---|---|
| Counts against staff limit | ✅ Yes | ❌ No |
| Requires invitation from store owner | ✅ Yes | ❌ Uses request code |
| Permanent access by default | ✅ Yes | ❌ Project-based |
| Can be revoked instantly | ✅ Yes | ✅ Yes |
| Shopify Plus required | ❌ All plans | ❌ All plans |
| Access to Shopify Partners dashboard | ❌ No | ✅ Yes |
How to add a staff account on Shopify
The path has changed since 2021. The current location is Settings → Users, not Settings → Plan & Permissions.
Step 1 — Go to Settings → Users
From your Shopify admin, click Settings in the bottom-left corner. Select Users from the menu. This takes you to the Users and permissions screen.
Step 2 — Click Add users
Click the Add users button. Enter the email address of the person you are inviting. This is the address where they will receive their invitation and any store notification emails.
Step 3 — Assign a role
In the Roles section, click Assign. Shopify offers preset roles (Full permissions, Limited permissions) or you can create a custom role with specific permissions selected. For full admin access, select Full permissions. For restricted access — for example, a marketing manager who should not see financial data — create a custom role and select only the permissions they need.
Step 4 — Set two-step authentication requirements
In the Two-step authentication section, choose whether two-step authentication is required for this user when logging in via a browser. For any user with full admin access or access to financial data, making two-step authentication mandatory is strongly recommended. This is enforced at login — the user cannot access the admin without completing two-step authentication.
Step 5 — Send the invite
Click Add Users. The invited person receives an email with a link to set up their account. If the invitation is not accepted within seven days, it expires — remove the user and re-add them to send a new invitation. Users with a pending status are visible in the Users section until they complete their account setup.
How to grant collaborator access using the request code
Collaborator access works differently from staff accounts. Rather than you sending an invitation, the external partner — your agency, developer, or freelancer — requests access through their own Shopify Partners dashboard. You provide them with a collaborator request code to authorise the request.
Step 1 — Find your collaborator request code
Go to Settings → Users → Collaborators. You will see a four-digit collaborator request code. Share this code with the partner who is requesting access. The code does not expire and does not change unless you manually regenerate it.
Step 2 — The partner submits a request
Your agency or developer logs into their Shopify Partners dashboard and requests collaborator access to your store, entering your four-digit code to authorise the request. They specify which permissions they need as part of the request.
Step 3 — Approve the request
You receive a notification (by email and in your Shopify admin) that a collaborator access request is pending. Go to Settings → Users → Collaborators to review and approve or deny it. You can adjust the permissions before approving if the partner has requested more access than you want to grant.
Step 4 — Manage and revoke access
Collaborator access appears in the Collaborators tab of the Users section. You can edit permissions at any time or remove access entirely by clicking Remove collaborator. The partner loses access immediately. Removing a collaborator does not affect their Shopify Partners account or any other stores they manage.
If you are working with a Shopify Plus agency like Tribe, your account manager will request collaborator access via this process. You should never need to share your store owner login credentials with an agency — if they ask for those instead of using the collaborator access system, that is a red flag.
Two-step authentication on Shopify — what you need to know
Shopify supports several two-step authentication methods for admin users: authenticator apps (Google Authenticator, Authy), SMS verification, and security keys. Authenticator apps are the most secure option and are what Shopify recommends for any user with significant admin access.
When you set two-step authentication as mandatory for a user, they are prompted to set it up the first time they log in. If they have not completed two-step setup, they cannot access the admin. This is enforced per user — you can require it for some users and not others, depending on their access level.
For Shopify Plus merchants, you can enforce two-step authentication organisation-wide via the organisation admin, which means all staff and collaborators across all stores in your organisation must use two-step authentication. This is the recommended approach for any brand processing significant revenue.
Shopify Plus: the organisation admin and expansion store access
Shopify Plus merchants have access to the organisation admin — a separate layer of user management that sits above individual store admins. The organisation admin allows you to manage users and permissions across all stores in your Shopify Plus organisation from a single interface, rather than adding users to each store individually.
This is particularly important for brands running expansion stores for international markets or separate B2B and DTC channels. Without the organisation admin, adding a team member to three expansion stores means three separate invitations and three separate permission configurations. With the organisation admin, you manage it once and assign access to whichever stores are relevant.
To access the organisation admin, go to admin.shopify.com and select your organisation (rather than an individual store). From here you can manage users across all stores, set organisation-level two-step authentication requirements, and view which users have access to which stores.
Adding a user to a specific expansion store
If you need to add a user to one specific expansion store but not others, navigate directly to that store's admin (via the store switcher at admin.shopify.com) and follow the standard Settings → Users process. The user will only have access to that store. For agency collaborators working on a specific expansion store build, this is the correct approach — grant access at the store level, not the organisation level, to limit their exposure to other stores in your account.
Permission categories in Shopify — what each one covers
When creating a custom role or limiting a staff account's access, Shopify's permissions are grouped into these categories:
Products — view, create, edit, and delete products, variants, collections, and inventory.
Orders — view, fulfil, edit, cancel, and refund orders. Also covers draft orders and abandoned checkouts.
Customers — view and edit customer profiles, customer tags, and customer data exports.
Reports and analytics — access to sales reports, dashboard data, and analytics. Keep this restricted for staff who do not need financial visibility.
Apps — install, configure, and manage Shopify apps. This is a high-trust permission — anyone with app management access can install apps that interact with your store data.
Settings — access to store configuration including payment providers, shipping, tax settings, and checkout. Limit this to senior team members and your agency.
Themes — edit and publish theme code. Any agency working on your Shopify build needs this. Be aware that theme access includes the ability to edit Liquid code.
Subscription apps — manage Recharge, Skio, or other subscription platform configurations. If you are working with a subscription ecommerce agency, they will need access to the subscription app as well as the Shopify admin.
Common mistakes when managing Shopify user access
Sharing store owner credentials. The store owner account has irreversible actions available — including cancelling the store. Never share the store owner login with an agency or freelancer. Always use collaborator accounts or staff accounts with appropriate permissions.
Not revoking access after a project ends. When an agency or freelancer completes their project, remove their collaborator access immediately. It is easy to forget, and active access credentials are a security risk even if the relationship has ended.
Granting full permissions by default. Most team members do not need full admin access. Granting full permissions to everyone is a common shortcut that creates unnecessary security exposure. Invest the five minutes to set up a custom role with the minimum permissions needed.
Not enabling two-step authentication. Any account with access to financial data, settings, or app management should have two-step authentication enabled. A compromised staff account with full permissions is one of the most common sources of Shopify store security incidents.
If you are onboarding an agency onto your Shopify store and want to ensure access is set up correctly — with the right permissions, the right authentication requirements, and the right separation between your expansion stores — the Tribe team can help. We work with Shopify and Shopify Plus brands on builds, subscriptions, and growth, and take store security and access management seriously from day one.