Staff management, previously split between the POS channel and the admin, is now consolidated in one place (Settings > Users). It's now easier to pause and reactivate seasonal staff, identify high-trust roles, and assign roles across multiple stores. Existing users, permissions, and roles have been migrated automatically.
POS users in the POS channel, Admin users in the admin. Even the same person tended to have separate profiles and separate workflows.
Both POS and Admin in the same screen. A single user profile can handle multiple stores and multiple roles, and seasonal staff can be paused instead of deleted.
Create POS users, assign roles, and manage PINs in "Settings > Users" instead of the POS channel.
With Shopify Plus, one user profile can be granted POS access to multiple stores across your organization. No duplicate profiles needed.
Pause/deactivate accounts without deleting them. When staff return, reactivate them and carry over their full history.
Create custom roles that fit the job and assign as many as one person needs (e.g., "Store Manager" + "Marketer").
New POS roles make it easier to identify users with powerful permissions. All users keep their existing permissions, withone exception(→ Section 5). The role names are POS Administrator (formerly Full permissions)/POS Device Setup(for setting up new devices) /POS User Administrator(for user management) /Organization POS Administrator(create, edit, and delete roles across all stores).
| New role name | Role | Notes |
|---|---|---|
| POS Administrator | Full POS permissions. | Renamed Formerly "Full permissions". |
| POS Device Setup | For setting up new devices (POS terminals). | New |
| POS User Administrator | For managing users (i.e., assigning existing roles to users). | Automatically granted to anyone who previously held this permission. |
| Organization POS Administrator | Create, edit, and delete roles across all stores. | Not auto-granted Grant manually if needed (→ Section 5). |
| Item | Before | After unification (now) |
|---|---|---|
| Where it's managed | Fragmented POS channel + admin | Centralized Consolidated under Settings > Users |
| POS users' PIN / role | Configured on the POS channel | Configured under Settings > Users in the admin |
| Access to multiple stores | Duplicate profile per store | 1 profile Grant access to multiple stores in the organization (Plus) |
| Seasonal staff | Delete → recreate when they return (history lost) | Suspend/resume Reactivate while keeping history |
| Roles per person | Tends to assume a single-role setup | Multiple roles Assign as many as needed |
| Creating/editing/deleting roles | Shop-level permission | To organization-wide permission Not granted automatically (manual required) |
Shopify advises that "as a result of this change, you may need to review and clean up your list of users and roles." The following flow is the safe approach.
Under "Settings > Users," review your post-migration POS + Admin users together.
Identify who holds powerful permissions like POS Administrator. Remove any unnecessary broad permissions.
Grant Organization POS Administrator only to the people who should continue managing roles across all stores.
Existing users, permissions, and roles are migrated automatically, and everyone keeps their current access. No migration work itself is required, but auditing the result is recommended.
Permissions are inherited as-is by default. The only exception is "creating/editing/deleting roles." This is promoted to an organization-level permission and, for security reasons, is deliberately not granted automatically.
On Plus, a single profile can represent access spanning multiple stores. You can consolidate duplicate users across stores, but in turn a single account's blast radius grows.
POS PIN settings have moved to "Settings > Users." Register operation manuals and onboarding materials need to have their navigation paths rewritten away from the POS channel.
The official announcement is primarily about operational changes in the admin, and there isno mentionof the programmatic handling of the Admin API, webhooks, or staff permissions. If you want to manage organization-level role structures with IaC or scripts, validate the behavior separately in a sandbox. How multi-role assignment and suspended state surface in the API is also unconfirmed.