December 11, 2024

Role-based access controls

Shopify's new role-based access control (RBAC) model is now available for your store or organization. This update is designed to enhance how permissions are assigned and managed, making user management more efficient and secure as your business grows.

New enhancements include:
* Simplified Role Assignments: Set up roles with specific permissions and assign them to multiple users at once. This change is aimed at reducing the time and effort involved in user onboarding and ongoing management.
* Enhanced Flexibility: Easily assign multiple roles to a single user, allowing for greater adaptability to meet diverse business needs and simplify the auditing process.
* Efficient Onboarding with Groups (Shopify Plus only): Utilize Groups to simultaneously assign roles and store access across your staff, improving onboarding and management of large teams.

Your existing users will keep their access and be marked with a 'Legacy access" badge. If your organization had used roles in the past, those roles have now been converted into user groups under the same names and marked with a 'Legacy Access' badge. Create and assign roles to users or groups to remove the badge and ensure smooth transition to the new model.

As the organization administrator or owner, we recommend you update permissions for all users by May 1, 2025. After this date, users and groups with legacy access will be automatically migrated to have one role per store, potentially creating many auto-generated roles. For detailed instructions on how to migrate users with legacy access, please visit the Shopify Help Center.