Migrating to the role-based access control model
Partner organizations are automatically migrated to role-based access control. You don't need to take any action. Shopify automatically assigns roles that preserve your team's current access with no setup, reconfiguration, or disruption to day-to-day work.
After migration, you can review the Shopify-added roles that preserve your team's current access. These are custom roles based on your previous permission sets for your users. Users with the same permissions are assigned the same roles.
After migration, your organization uses 7 system roles managed by Shopify instead of assigning permissions for each user. You can also create custom roles for anything the system roles don't cover.
What changes after migration
The role-based access control migration brings all user access into a single view. As a result, the user list includes anyone with access to any part of your organization, even if they weren't previously visible in one place.
This includes the following users with:
- Access to Partner Dashboard
- Access to Dev Dashboard
- Access to stores in your organization, including Client Transfer, Development, and Collaborator stores
- Store ownership, including users who originally created Client Transfer or Development stores
If someone in the list has left your organization or no longer needs access, then remove them promptly. You can use filters to find those users and bulk remove them.
In addition, review the following changes with the role-based access control model:
- Permissions model: Role-based permissions replace assigning user permissions for each user. System roles are automatically assigned to preserve access.
- Organization structure: The previous model allowed multiple organization owners. After migration, each organization has one organization owner. All other previous owners become organization administrators with the same level of access, except for the ability to transfer organization ownership.
Known access change
Users who previously had the manage members permission are migrated to the Organization user administrator role. This role allows users to assign existing roles to other users, but not to create or edit roles. To grant full role management access, the organization owner can assign the Organization administrator role to these users.
After migration
After migration, you can do the following tasks:
- Review the role assignments and permissions in each role and edit roles or reconfigure access as needed.
- Create custom roles with specific permissions for your team.
- Assign multiple roles to a single user.
- Manage store access centrally for all stores in your organization.
Learn more about roles managed by Shopify.