E-commerce

How to manage billing and access permissions on Shopify?

How to manage billing and access permissions on Shopify?

September 1, 2026

Are you wondering how to assign precise financial rights on Shopify without granting full access to your administration? This is essential for securing your banking data while allowing your accountant or operational teams to manage invoices and failed payments. The confusion between invoice access, payment method management, and financial reporting is a major risk to your store's security.

So how do you manage billing permissions and access on Shopify? On the agenda:

  • What is the critical difference between platform invoices and customer revenue?

  • How do you create a restricted administrative role for your accountants?

  • What are the sensitive permissions related to paying your Shopify invoices?

  • How does billing access differ from managing Shopify Payments payouts?

  • How can you secure your store against security risks associated with compromised accounts?

Let's get started.

Summary

What are the different types of invoices and financial flows on Shopify?", "Section Title 1 Visible": true, "Section 1": "<h3 dir="auto">Understanding the money landscape</h3> <p>In the Shopify admin, the term billing covers several distinct areas that you should not confuse. The first area concerns what you pay to Shopify itself: your monthly subscription, the costs of installed third-party apps, premium themes, and shipping labels. These items are managed via the Settings > Billing page and fall strictly under billing permissions.</p> <p>The second area corresponds to payments received from your customers, known as Shopify Payments payouts. The money that lands in your bank account is not managed in the same places as the bills to be paid. Managing these financial flows often requires specific permissions located in the Finance section, separate from the administrative management of the site.</p> <p>A third category involves invoices issued to your customers, particularly for B2B wholesale orders or draft orders. These rights fall under order management and not organizational billing. If your financial controller asks you for billing access, it is imperative to clarify exactly which of these three components they wish to handle.</p>

Understanding the Money Surface

In the Shopify admin, the term billing covers several distinct realities that you should not confuse. The first surface concerns what you pay to Shopify itself: your monthly subscription, the costs of installed third-party apps, premium themes, and shipping labels. These items are managed via the Settings > Billing page and fall strictly under billing permissions.

The second surface corresponds to payments received from your customers, known as Shopify Payments payouts. The money that lands in your bank account is not managed under the same sections as the bills to be paid. Managing these financial flows often requires specific permissions located in the Finance section, distinct from the administrative management of the site.

A third category involves invoices issued to your customers, particularly for B2B wholesale orders or draft orders. These rights fall under order management and not organizational billing. If your financial controller asks you for billing access, it is imperative to clarify exactly which of these three components they wish to handle.

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

Who holds sensitive financial permissions by default?", "Section Title 2 Visible": true, "Section 2": "<h3 dir="auto">The Owner Hierarchy</h3> <p>By platform design, the Store Owner and the Organization Owner in a broader Shopify organization setup automatically hold all sensitive financial rights. They are the only ones capable by default of updating saved credit cards and resolving failed payments on the platform.</p> <p>Staff or collaborator accounts, on the other hand, start with no specific financial rights. They cannot view invoices or access payment settings unless a custom role is explicitly assigned to them. This initial configuration is deliberately restrictive to prevent a regular employee from unintentionally accessing critical banking details.</p> <p>This is where the user management system becomes invaluable: you must create named accounts and assign precise roles, thereby avoiding the sharing of a generic login like finance@yoursite.com. This strict separation allows you to know exactly who did what in your store.</p>

The Owner Hierarchy

By platform design, the Store Owner and the Organization Owner, within a broader Shopify organization framework, automatically hold all sensitive financial rights. By default, they are the only ones capable of modifying registered credit cards and validating failed payments on the platform.

Staff or collaborator accounts, on the other hand, start with no specific financial rights. They can neither view invoices nor access payment settings unless a custom role is explicitly assigned to them. This initial configuration is deliberately restrictive to prevent a regular employee from unintentionally accessing critical banking data.

This is the main benefit of the user management system: you must create named accounts and assign precise roles, thereby avoiding the sharing of a generic login like finance@yoursite.com. This strict separation allows you to know exactly who did what in your store.

How do billing permissions differ from general staff permissions?", "Section Title 3 Visible": true, "Section 3": "<h3 dir="auto">The specific role of financial permissions</h3> <p>There is a fundamental distinction between granting full administrative access and providing targeted financial delegation. Granting a staff account general administrator rights allows the accountant to download a PDF invoice, but it also gives them access to installed apps, the customer list, and sensitive payment settings.</p> <p>Billing permissions are designed to be specifically delegated. They isolate financial tasks within a restricted scope that does not include the rest of the administration. If you mistakenly grant full access, you expose your store to unnecessary risks and increase the attack surface in the event of an account compromise.</p> <p>The delegability of these permissions, introduced particularly during the deployment of advanced billing features, means that the owner is no longer the only person capable of paying a failed invoice when they are away. This separates operational treasury tasks from global administration.</p>

The specific role of financial permissions

There is a fundamental distinction between giving full administrative access and providing targeted financial delegation. Granting a staff account general administrator rights allows the accountant to download a PDF invoice, but it also gives them access to installed applications, the customer list, and sensitive payment settings.

Billing permissions are designed to be specifically delegated. They isolate financial tasks into a restricted scope that does not include the rest of the administration. If you give full access by mistake, you expose your store to unnecessary risks and increase the attack surface in the event of a compromised account.

The delegability of these permissions, introduced in particular during the deployment of advanced billing features, ensures that the owner is no longer the only person capable of paying a failed invoice when they are away. This separates operational treasury tasks from general administration.

What are the sensitive permissions related to payment methods?", "Section Title 4 Visible": true, "Section 4": "<h3 dir="auto">Payment Method Security</h3> <p>One specific permission deserves special attention: the permission to modify billing payment methods and pay invoices. This capability is classified as sensitive because it allows for the adding or changing of the credit card associated with your Shopify account.</p> <p>Changing a payment method or manually retrying a failed invoice is an action that directly impacts your cash flow. It is closer to a banking transaction than simply viewing data on the website. Consequently, this permission should only be granted to individuals of absolute trust, such as a designated financial manager.</p> <p>Never grant this permission to an intern or a marketing team member who is temporarily "helping" with invoices. The risk of an accidental error or unauthorized access is too high to compromise the security of your banking details.</p>

The security of payment methods

A specific permission deserves very special attention: that of modifying billing payment methods and paying invoices. This capability is classified as sensitive because it allows for adding or changing the credit card associated with your Shopify account.

Changing a payment method or manually retrying a failed invoice is an action that directly affects your cash flow. It is closer to a banking intervention than simply reading data on the website. Therefore, this permission should only be granted to individuals of absolute trust, such as a designated financial officer.

Never grant this permission to an intern or a marketing department member who occasionally "helps" with invoices. The risk of a manipulation error or malicious access is too high to inadvertently compromise the security of your banking details.

What is the difference between read-only access and payment rights?", "Section Title 5 Visible": true, "Section 5": "<h3 dir="auto">Distinguishing viewing from action</h3> <p>If your accountant only needs to retrieve documents for their reports or expense claims, they do not need to be able to pay for anything. The 'View billing and receive billing emails' permission is more than enough in this case.</p> <p>This permission allows the user to view, download, and export Shopify invoices, as well as access information on saved payment methods. They can also receive billing-related emails, which is useful for administrative tracking. However, this permission excludes any ability to make changes or financial transactions.</p> <p>It is crucial to note that collaborators with only this permission will not receive automatic billing emails sent by Shopify, unless the system is specifically configured to do so. This helps reduce digital clutter and avoid unnecessary notifications for those who only have a viewing role.</p>

Distinguishing visualization from action

If your accountant only needs to retrieve documents for their reports or expense claims, they do not need to be able to pay for anything. The 'View billing and receive billing emails' permission is more than sufficient in this case.

This permission allows the user to view, download, and export Shopify invoices, as well as access information on registered payment methods. They can also receive billing-related emails, which is useful for administrative traceability. However, this permission excludes any ability for modification or financial transactions.

It is crucial to note that staff members with only this permission will not receive automatic billing emails sent by Shopify, unless the system is specifically configured. This helps reduce digital noise and avoid unnecessary notifications for those who only have a viewing role.

How to configure a secure financial role in settings?", "Section Title 6 Visible": true, "Section 6": "<h3 dir="auto">Operational implementation</h3> <p>To secure your store and respect the principle of least privilege, it is recommended to create a custom role dedicated to finance rather than using the existing Administrator role. In the Settings > Users interface, you need to access role management to duplicate or create a new profile.</p> <p>Once this role is created, assign it the specific checkboxes related to billing and finance without enabling other administrative permissions such as modifying products, adding apps, or managing orders. This allows you to build a tight security perimeter around billing.</p> <p>Roles managed by Shopify cannot be edited directly, but you can use them as a starting point to create your own configurations. By duplicating a standard role and systematically removing unnecessary access, you achieve tailored security adapted to the size of your team and your actual needs.</p>

Operational Implementation

To secure your store and respect the principle of least privilege, it is recommended to create a custom role dedicated to finance rather than using the existing Administrator role. In the Settings > Users interface, you need to access role management to duplicate or create a new profile.

Once this role is created, assign it the specific checkboxes related to billing and finance without enabling other administrative permissions such as modifying products, adding apps, or managing orders. This allows you to build a tight security perimeter around billing.

Roles managed by Shopify cannot be modified directly, but you can use them as a basis to create your own configurations. By duplicating a standard role and systematically removing unnecessary access, you obtain tailored security adapted to the size of your team and your actual needs.

Why is separation of duties vital for security?", "Section Title 7 Visible": true, "Section 7": "<h3 dir="auto">Reducing the blast radius of a compromise</h3> <p>The logic behind these sensitive permissions is based on a well-established IT security principle: separation of duties. According to best practices like the OWASP cheat sheet, the person managing your ads or marketing campaigns should never have the ability to replace your primary billing card.</p> <p>If a staff account is compromised by a malicious third party, limiting access to invoices only significantly reduces the \"blast radius\"—meaning the potential damage. The attacker will be able to see your financial data but will not be able to drain your account or change your payment terms.</p> <p>This strategy is all the more important when you use two-factor authentication for all administrator accounts. The combination of RBAC (Role-Based Access Control) and 2FA forms the foundation of your store's security against financial intrusions.</p>

Reducing the blast radius of a compromise

The logic behind these sensitive permissions rests on a well-established IT security principle: separation of duties. According to best practices like the OWASP cheat sheet, the person managing your advertisements or marketing campaigns should never have the ability to replace your primary billing card.

If a staff account is compromised by a malicious third party, restricting access to invoices only significantly reduces the "blast radius"—that is, the potential damage. The attacker will be able to see your financial data but will not be able to drain your account or change your payment terms.

This strategy is all the more important when you use two-factor authentication for all administrator accounts. The combination of RBAC (Role-Based Access Control) and 2FA forms the foundation of your store's security against financial intrusions.

What are the risks associated with account sharing and weak passwords?", "Section Title 8 Visible": true, "Section 8": "<h3 dir="auto">The Importance of Unique Identities</h3> <p>A common bad practice is to share a single user account, such as "finance@yoursite.com", among several team members. This method must be absolutely avoided because it makes any traceability impossible in the event of an error or a malicious action.</p> <p>Each member of your team must have their own named account and their own secure login. This not only allows you to know who accessed what, but also to quickly revoke the access of a single individual without impacting other collaborators.</p> <p>This granularity of rights is the most effective way to keep control of your store. By avoiding shared generic accounts, you also limit the risks associated with weak or reused passwords on other less secure platforms.</p>

The Importance of Unique Identities

A common bad practice is to share a single user account, such as "finance@yoursite.com", among multiple team members. This method must absolutely be avoided as it makes any traceability impossible in the event of an error or malicious action.

Each member of your team must have their own named account and secure login. This not only allows you to know who accessed what, but also to quickly revoke the access of a single individual without impacting other collaborators.

This granularity of rights is the most effective way to maintain control over your store. By avoiding shared generic accounts, you also limit the risks associated with weak or reused passwords on other less secure platforms.

How does Qstomy help secure and optimize these processes?", "Section Title 9 Visible": true, "Section 9": "<h3 dir="auto">AI assistance for access management</h3> <p>Qstomy acts as an expert AI agent for your Shopify store to support you in securing your administrative and customer processes. Our solution integrates proactive monitoring of access configurations and helps identify inappropriate or overly broad permissions that could expose your business.</p> <p>In the event of a customer request regarding an incorrect email address, Qstomy makes it easy to retrieve tracking information and invoices without compromising account security. It also guides your teams on managing partial returns or invoice requests for gifts, ensuring that only the correct permissions are used.</p> <p>Our approach aims to reduce the team's cognitive load by automating rights verification and providing recommendations based on over 100 supported merchants. Qstomy thus ensures that your configuration is not only functional but also compliant with security best practices.</p>

AI Assistance for Access Management

Qstomy acts as an expert AI agent for your Shopify store to assist you in securing your administrative and customer processes. Our solution integrates proactive monitoring of access configurations and helps identify inappropriate or overly broad permissions that could expose your business.

In the event of a customer request regarding an incorrect email address, Qstomy facilitates the retrieval of tracking information and invoices without compromising account security. It also guides your teams on managing partial returns or billing requests for gifts, ensuring that only the correct permissions are used.

Our approach aims to reduce the team's cognitive load by automating rights verification and providing recommendations based on support provided to over 100 merchants. Qstomy thus ensures that your configuration is not only functional but also compliant with security best practices.

How to handle specific requests related to gift cards and taxes?", "Section Title 10 Visible": true, "Section 10": "<h3 dir="auto">Handling complex payment questions</h3> <p>Questions regarding gift cards can be a source of confusion, particularly concerning the application of VAT. It is important to distinguish the management of the gift card itself from the overall billing of the store. Billing-related permissions do not automatically cover the tax rules applied to cards.</p> <p>If your customers ask questions about the taxes applicable to gift cards or about the combined payment using a card and a standard method, Qstomy provides accurate answers through its chatbot. This helps relieve pressure on your customer support without requiring manual intervention for each tax request.</p> <p>Clear management of these aspects prevents billing errors and ensures that your customers receive accurate information regarding debited or credited amounts, thereby strengthening their trust in your store.</p>

Handling Complex Payment Questions

Gift card questions can be confusing, especially regarding the application of VAT. It is important to distinguish the management of the gift card itself from the global billing of the store. Billing-related permissions do not automatically cover the tax rules applied to cards.

If your customers ask questions about the taxes applicable to gift cards or about combined payment using a card and a standard method, Qstomy provides precise answers via its chatbot. This helps relieve congestion in your customer support without the need to manually intervene on each tax request.

Clear management of these aspects prevents billing errors and ensures that your customers receive accurate information about debited or credited amounts, thereby strengthening their trust in your store.

What checklist should be adopted before modifying financial permissions?", "Section Title 11 Visible": true, "Section 11": "<h3 dir="auto">Prerequisite Checks</h3> <p>Before validating any modification of roles or financial access, verify that the principle of least privilege is respected for each user concerned. Ensure that the individual's identification is clear and that they are not using a shared account.</p> <p>Also, verify that two-factor authentication (2FA) is enabled on all administrator accounts before granting sensitive permissions. This step is non-negotiable to guarantee the security of your banking data.</p> <p>Finally, document any changes made to financial roles and test the new profile with a temporary account to validate that the user cannot access areas outside their scope, such as payment settings or products.</p>

Prerequisite Verifications

Before validating any role or financial access modification, verify that the principle of least privilege is respected for each user concerned. Ensure that the individual's identification is clear and that they are not using a shared account.

Also, verify that two-factor authentication (2FA) is enabled on all administrator accounts before granting sensitive permissions. This step is non-negotiable to guarantee the security of your banking data.

Finally, document any modifications made to financial roles and test the new profile with a temporary account to validate that the user cannot access areas outside of their scope, such as payment settings or products.

What are the quick answers to frequently asked questions about billing?", "Section Title 12 Visible": true, "Section 12": "<h3 dir="auto">Concise FAQ</h3> <p>Why not just give Administrator access to my accountant? Because that gives them full control over the store, including customers and apps, which is excessive for their billing needs.</p> <p>Do billing permissions handle product returns? No, managing returns, especially for bundles or complex orders, is handled by specific modules and not the basic organizational billing system.</p> <p>How do I handle an email address error blocking the invoice? Contact support with Qstomy to regain access to the documents without touching the store's security settings. Every action is tracked to guarantee the integrity of your data.</p>

Concise FAQ

Why not simply give Administrator access to my accountant? Because it gives them full control over the store, including customers and apps, which is excessive for their billing needs.

Do billing permissions handle product returns? No, managing returns, especially for bundles or complex orders, is handled by specific modules and not by the core organizational billing system.

How to handle an email address error blocking the invoice? Contact support with Qstomy to regain access to documents without touching the store's security settings. Every action is tracked to ensure the integrity of your data.

To go further: Email address error in an order: helping the customer retrieve tracking, invoice, and account - Qstomy, How to handle customer questions about gift cards combined with a card payment - Qstomy, How to handle customer questions about taxes applied to gift cards - Qstomy, Customer support for partial returns: packs, bundles, and multi-product orders - Qstomy, Social commerce: answering customers between TikTok Shop, Instagram, and Shopify without losing track - Qstomy, Name error on an order: correcting what can be corrected before the package gets blocked - Qstomy, How to handle invoice requests for gifts and professional orders? - Qstomy.

Enzo

September 1, 2026

Convert over 2,000 customers on average per month with Qstomy.

The world’s 1st Shopify AI dedicated to customer conversion

Empowering 200+ e-commerce merchants

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.

Subscribe to the newsletter and get a personalized e-book!

No-code solution, no technical knowledge required. AI trained on your e-shop and non-intrusive.

*Unsubscribe at any time. We do not send spam.