E-commerce
August 13, 2026
The Shopify billing management permissions decide who can view your Shopify bills, who can change the card on file, and who can retry a failed platform bill. This is not the same as "letting finance view reports", and it is not the same as Shopify Payments payouts. If you give a staff account full admin access just so the accountant can download a PDF, you have also given them apps, customers, and often payment settings. Role-based access exists so you don't have to do that.
This guide is narrower than a complete tour of roles: the billing and finance checkboxes in the Shopify admin, how they intersect between a single Shopify store and an Organization, and what Shopify changed when they released delegable billing permissions (November 11, 2025). For Plus, the Help Center is explicit: billing access is managed via organization roles, not the store-level finance set. For others, the store permissions View billing and receive billing emails and Edit billing payment methods and pay bills (a sensitive permission) are the core pair.
Shopify's reason for delegating is operational: the store owner should not be the only person capable of paying a failed bill while they are offline. The sensitive permissions help also states that spreading these tasks reduces the blast radius of a compromised account. Pair this with two-factor authentication. See Sensitive permissions and account security best practices.
What you will clarify: platform billing vs. payouts vs. customer invoices vs. B2B wholesale terms.
What you will be able to do: build a finance role in Settings, Users, assign read-only or pay-bill rights, and keep collaborators away from the card.
To connect: RBAC in the Shopify admin, the Shopify integration and customer support.
Do not treat this as legal advice. Your accountant remains the owner of the chart of accounts. The Shopify Help is the source of truth when the admin UI moves a checkbox.
Summary
What do the Shopify billing management permissions control?
In the Shopify admin, "billing" generally means what you pay to Shopify: subscription, apps, themes, shipping labels, and related invoices. Shopify billing management permissions lock down the Billing page, the payment methods on this page, billing emails, and (separately) the visibility of app charges.
Three financial areas that people mix up
Platform billing: Settings > Billing. Staff permissions: view invoices, modify payment methods, pay invoices, manage app billing.
Shopify Payments and payouts: customer money landing in your bank account. Permissions like View Shopify Payments payouts live under Finance and often require extra Settings checkboxes. This is not "paying Shopify."
Customer invoices / B2B: draft orders, company locations, Net terms. These are order and B2B permissions, not organization Billing.
If your controller asked for "billing access," ask which of the three they need. Most of the time, they want invoices and the card on file. Sometimes payout CSVs. Almost never Manage install apps plus Home plus Products.
Who has billing by default
The store owner (and in an organization, the organization owner) already holds sensitive finance rights. Staff and collaborator accounts start with nothing unless a role includes these permission category controls. That is the whole point of user management: named accounts, named roles, no shared "finance@" logins.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
How is this different from general staff permissions?
Qstomy has already published a complete RBAC walkthrough on the sister URL role-based access control in Shopify. Use it for categories, POS roles, CSV user export, and how many custom roles your plan allows. Use this article when the question is specifically Shopify billing management permissions.
Why billing is a special case
Shopify marks Edit billing payment methods and pay bills as a sensitive permission. Changing a card or retrying a failed bill is closer to treasury than "viewing the homepage". The OWASP Authorization cheat sheet (least privilege, separation of duties) maps cleanly: the person booking ads should not also be able to replace the billing card.
Administrator role vs finance role
The store user administrator role (or a generic "Administrator" package) is the lazy path. It works. It also grants view, create, edit on most of the admin. A custom role with only the Finance billing checkboxes ticked is the adult path. Duplicate a Shopify-managed role if you must, then strip it down. Shopify-managed roles themselves are not editable.
Which billing and finance boxes exist at the store level?
On a store that does not use Plus organization billing, Shopify documents these store-level controls in Store permissions.
View billing and receive billing emails
Users can view, download, or export Shopify invoices, view billing information and payment methods, and receive billing-related emails. Staff members who have this permission do not receive billing emails. Give this to an accountant who only needs PDFs and expense reports.
Edit billing payment methods and pay invoices
Users can add a payment method on the Billing page and pay invoices if a payment fails. Sensitive. Give this to a designated finance lead, not to the intern who "helps out on Shopify". Combine with two-factor authentication on this Shopify ID.
Manage app billing
Users can view app billing charges for one-time purchases, app usage, and app subscriptions. This is how an ops lead audits third-party apps without touching the corporate card. This does not, on its own, install apps. Manage install apps is a different permission and a different risk.
Related finance permissions that are not platform billing
View payouts / View tax documents: payout summaries and tax files. View tax documents auto-selects View payouts and is sensitive.
View Shopify Payments payouts: settings, payouts, transactions. Requires Manage settings, Checkout and customer accounts, and Store settings.
Manage other payment settings: PayPal and third-party checkout providers, not the Shopify invoice card. Sensitive. Requires Manage settings.
View Balance / Shopify Credit activity: spending and cardholder data if you use these products.
A clean finance role for "pay the Shopify invoice" is view billing + edit billing. Add Manage app billing if they own the app stack. Do not add Manage other payment settings unless they also own the checkout gateways.
How do the Plus billing and organization roles work?
If the store is within an Organization, or you are on Shopify Plus, the Help Center repeats the same warning regarding store permissions: for Plus stores, billing access is managed via organization roles. Checking Show billing at the store level will not do what your accountant expects.
Organization billing permissions
Organization permissions list two billing rights on an Organization role category:
View bills and preferences, including payment methods: past and upcoming bills, export, Billing page, billing emails.
Pay bills and modify preferences, including payment method: the former, plus authorizing and retrying failed bill payments, and changing information on the Billing page.
Plus centralized invoices
Manage billing for Plus: all stores in the organization share a single billing account and a single invoice. You update the billing profile, review past invoices, and see the charges of the current cycle in the same place. Non-Plus organizations can still review the invoices of each store from Organization settings > Billing, but billing remains per store. Assign the Organization administrator role only to people who need to see the charges of each store.
Changelog: delegable billing
On November 11, 2025, Shopify announced delegable billing for merchants in an organization: grant viewing bills, managing payment methods, and billing information without making someone the account owner. Path: Settings > Users and permissions. If your finance recruit joined after this date and still doesn't have the Billing page, you are probably assigning a store role in a Plus org. Switch to an organization role with Billing.
Who can assign these roles
Generally the organization owner, a user with the Organization administrator role, or (for scoped store access) a Store user administrator role. If the Billing toggles are missing, you might be editing a role managed by Shopify. Duplicate into a custom organization role, enable Billing, save, assign.
Why is modifying billing considered a sensitive permission?
Shopify lists Finance > Edit billing payment methods and pay invoices in the sensitive permissions table, shop role category. Owners already have it. Staff only get it when you check the box.
Why Shopify wants you to delegate
Continuity: someone can pay a failed invoice if the owner is traveling.
Two-factor authentication: help docs argue you can activate 2FA for the owner with less fear if billing is not a one-person bottleneck.
Blast radius: separate view-billing and pay-billing between two people when the team is large enough.
Transfer of ownership: easier if billing is not tribal knowledge in a single mailbox.
2FA is per Shopify ID
Account security help: activate two-factor authentication on the owner account and require it for staff. You cannot enroll 2FA for another human. You can require it. Shopify Payments already pushes 2FA when this gateway is used. Access to the billing payment method deserves the same bar, even in countries without Shopify Payments.
Shopify Mobile App
Staff who approve invoices from a phone still hold the same role. A lost phone with a session cookie is a billing incident. Screen lock, 2FA, and same-day access revocation during offboarding.
How to create and assign a billing role?
The labels change, but the 2026 path is role-based: Settings > Users (sometimes Users and permissions) > Roles.
Create a "Finance - billing" store role
Open Roles: Add a role, Store category (not POS, not Organization unless you are in that environment).
Name it: Finance billing viewer or Finance billing payer. Description: "Shopify invoices only".
Check view billing: View billing and receive billing emails.
Check edit only if they pay: Edit billing payment methods and pay invoices.
Optional: Manage app billing. Home (to land in the admin). Analytics reports if they reconcile charges.
Do not check: Products, Customers, Manage install apps, Manage other payment settings, unless it is literally their job.
Save: then open the user > assign the role > confirm they see Billing and nothing else critical.
Invite the user
Use a professional email. Assign the role before they accept. Pending invitations to a mistyped domain are a security bug. After acceptance, have them open Settings > Billing once while you watch (screen share). If the menu is grayed out, you are in the Plus/org scenario or you have assigned the wrong role category.
Change or revoke
Editing a role changes every user assigned to that role. If only one person needs to lose pay-invoice, remove the role from that user or split viewer vs payer into two roles. Offboarding: remove roles the day HR closes the laptop. Export users to CSV during a quarterly review if your plan allows.
Do employees and Partners need to have billing?
Collaborator accounts (Shopify Partners, agencies, freelancers) can carry many store permissions. They should almost never carry Edit billing payment methods. They also do not receive billing emails even if View billing is on.
Agency pattern
Theme and apps: collaborator with app development or theme permissions, time-bound.
App charges visibility: Manage app billing for a trusted partner ops who monitors usage fees, still without card editing.
Never: Pay bills organization permission on a Partner login that also has theme access.
Shopify Partners vs staff
Staff accounts are employees. Collaborator access is designed for Partners working on your store. When the retainer ends, revoke the collaborator before paying the final invoice. The app development permission concerns custom apps, not Shopify payments. Do not bundle them.
Third party apps and install rights
Installing an app can create a recurring charge. The person who can Manage install apps can increase your bill even without the Billing payment method permission. Separate "can install" from "can pay the Mastercard". Approve new apps in a ticket. Limit which apps a role can even see. See also the Shopify app ecosystem.
How do wholesale, POS, and support complicate billing?
Wholesale and B2B blur the vocabulary. Shopify wholesale / Plus B2B company locations have their own permission restrictions (for example, limiting a user to assigned company locations). This is customer credit and order invoices, not Settings > Billing.
B2B Customer Invoices
Sending a Net-30 invoice to a retailer requires order and draft order permissions, and perhaps company permissions. Your AP clerk who pays Shopify does not need this. Your AR clerk who invoices wholesale customers does not need the Shopify subscription card. Two roles.
Shopify POS
A POS staff member refunding a sale is not platform billing. POS Pro roles cover till, discounts, and refunds. The help center lists some POS channel permissions as exposing private payment settings. Keep store cashiers entirely out of Finance billing.
Customer Support
Support needs orders and customers. Support does not need View Billing. If they ask "why is the store paused?", that is an owner or finance ticket, not a macros issue. Giving billing access to support "just in case" is how invoices leak into a shared inbox.
What happens when billing permissions are incorrectly configured?
Once billing is delegated, failure modes are predictable.
Greyed-out Billing Menu
Plus / org: you have assigned a store role. Use an Organization role with Billing.
Wrong category: a POS role will not display Settings > Billing.
Collaborator: they can see invoices in the admin but will not get the email trail.
Failed invoice, no one can pay
Only the owner + users with Edit billing / Pay invoices can add a method and retry. If this person has left the company, the owner must take over the Billing page first, then assign a new finance role. Do not share the owner password just to "update the card."
App bill shock
Usage-based apps bill through Shopify. Managing app billing lets someone see these line items. Without this, finance only sees a bulk Shopify charge. Give the app billing view to whoever owns the app stack.
Payout vs invoice
An accountant who wanted Shopify Payments payout CSVs was given Edit billing. They can now change the card that pays Shopify. Reverse this: View payouts / View Shopify Payments payouts, not platform edit billing.
What does a least-privilege billing matrix look like?
Write a one-page matrix and keep it next to the role names in the admin.
Starting Matrix
Store owner: all sensitive permissions, 2FA, hardware key if you can.
Finance payer (1 person): view billing + modify billing payment methods. Optional: Manage app billing.
Finance viewer (accountant): view billing only. No card. No app installs.
Ops / support: orders, customers. Zero billing.
Partner collaborator: theme or scoped apps. No billing editing. Revocation on date.
Org admin (Plus): Org billing view or pay, only if they own the group finance.
Review Cadence
Quarterly: CSV of users, who still has Edit billing, who still has Organization administrator. After each offboarding: confirm that the Billing page still has a living human. After each Plus migration: re-test that the store-level finance boxes did what you think. The Shopify Help, not a 2024 screenshot, is the contract. Cross-reference with inventory management if the same staff have too many boxes checked "out of habit".
Logs
Use the store activity log when a payment method changes. Account security help tells you to review unrecognized changes. A billing permission without log review is just theater.
Should customer support have the Billing page?
Support teams often ask for Shopify admin access because they can't see the subscription status or app charges when a merchant asks, "Is my store down because of billing?". This is a process smell. The public storefront still needs answers about orders and shipping. It does not need six customer support agents with Settings access.
Keep Support Out of Billing
Macros: "Billing questions go to finance@" with a named owner.
Storefront chat: Order tracking, returns, product questions. Not "update the Visa".
Fewer staff accounts: Every extra admin is one more phishing target for billing.
Example
A 12-person D2C brand had the founder as the sole billing contact. A failed Shopify invoice paused apps over a long weekend. They created a paid Finance role for the ops lead, read-only billing for the accountant, and left support on orders only. Qstomy remained on the storefront so that support never needed the admin for the FAQ. This is the intended split: AI customer support for buyers, AI sales assistant on the catalog, Shopify for the money. Book a demo if admin sprawl is how you "cover" chat today.
Checklist, sources and FAQ
Checklist
Name the surface: platform invoice, payout, or customer invoice.
Check Plus vs single store: Organization billing vs Store finance.
Create viewer and payer as two roles: if you have two human beings.
Mark edit billing as sensitive: 2FA required on this Shopify ID.
Keep collaborators out of pay-bill: they won’t receive billing emails anyway.
Separate Manage install apps: from the card.
Test the Billing page: with a staff login before you need it in an outage.
Document the owner of the failed payment SMS: phone number on the billing profile.
Revoke on the last day worked: not after the laptop is wiped.
Reread the Help after a plan change: Plus upgrades billing by one level.
In brief
Shopify billing management permissions: these are the Finance / Organization checkboxes for invoices and the card on file.
View vs edit: accountants view and export. A trusted user pays and changes methods. Editing is sensitive.
Plus and organizations: use Organization Billing permissions. Store-level billing will let you down.
November 2025: delegable billing exists so you are not forced to give up store ownership.
Not payouts, not B2B invoices: these are other permission sets.
External sources
Shopify Help: Store permissions (billing, billing apps, payouts); Organization billing permissions; Sensitive permissions; Manage organization billing.
Shopify Changelog: Delegable billing permissions (Nov 11, 2025).
Security: Account security best practices; OWASP Authorization Cheat Sheet.
FAQ
What are the specific billing permissions available in Shopify?
At the store level: View billing and receive billing emails; Edit billing payment methods and pay bills; Manage app billing. At the organization level: View bills and preferences; Pay bills and edit preferences. Plus uses the organization pair. Confirm the labels in your admin.
How can billing permissions be delegated or restricted for staff accounts?
Create a custom role in Settings > Users > Roles, check only the desired billing boxes, and assign this role to a named staff account. Do not use a full administrator role. On Plus, use an Organization role with Billing.
How do billing permissions affect invoice management and payment processing?
Viewing allows downloading and exporting Shopify invoices. Editing/Paying allows adding a payment method and retrying failed invoices. They do not by themselves change Shopify Payments customer checkout or wholesale invoices.
Are there recent updates about billing permissions?
Yes. The Shopify changelog on November 11, 2025, published delegable billing for organization merchants, so finance staff can manage bills without becoming the account owner.
What are best practices in a B2B or wholesale Shopify environment?
Keep platform billing (what you pay to Shopify) on a finance role. Keep B2B company invoicing and draft orders on sales/AR roles. Do not merge them. Restrict company location access where the Help allows. Never give Partner collaborators the pay-bill permission.
Going further
Full RBAC: Role-based access control in Shopify
Staff inventory: Inventory management
Apps: Shopify App Ecosystem
Give billing to the fewest named people capable of paying a failed bill at 2 AM, then lock everyone else out. See Qstomy if the reason you are creating admin accounts is storefront questions, not the Visa card.

Enzo
August 13, 2026


