Four new staff permissions have been released: payment settings, chargebacks, payouts, and tax documents. You can now grant each role only what the job requires, without sharing full access.
To share financial information, you had no choice but to grant near-full access, including areas irrelevant to the job.
"Manage payment settings", "Manage chargebacks", "View payouts", and "View tax documents" can each be assigned to roles individually.
Permission to manage payment settings.
Permission to manage chargebacks (disputes).
Permission to view payouts.
Permission to view tax documents.
| Item | Before | After this release |
|---|---|---|
| Access to payments features | All-or-nothing Shared as one broad permission | Granular Grant only the 4 permissions you need |
| Unit of assignment | Share full account capabilities | Assigned per permission to staff roles |
| Separation of view and manage | — | Separated View and Manage are separate permissions |
| Availability | — | Rolling out gradually(rolling out now) |
Go to Settings in the Shopify admin.
Select Users.
Open a staff role under Roles.
Check the new permissions under Permissions.
Permissions are assigned to roles, not to individual staff, via Settings → Users → Roles → Permissions. Sorting out your role design (accounting, customer support, etc.) beforehand makes day-to-day operations run smoothly.
Payment settings and chargebacks are "manage"; payouts and tax documents are "view". Being able to grant read-only access is the real new value in this release.
It is "rolling out now", so not all stores get it at once. Before distributing manuals or internal runbooks, verify on the target store that the permissions actually appear.
There is no mention of granting or querying these permissions via the Admin API. If you want to automate permission management, you will need to verify this separately.
Access to payments, payouts, and tax — previously an all-or-nothing grant — can now be scoped to each job function. For stores already in operation, the practical first step is auditing existing staff permissions(who currently holds the equivalent of full access) and then migrating to the new permissions.