How to Use Roles, Permissions & 2FA (Advanced)
What is it?
This is your store's security system. Roles & Permissions (in `Settings` > `Users and permissions`) let you give staff or Virtual Assistants (VAs) access to *only* the parts of your store they need. 2FA (Two-Factor Authentication) is a mandatory security layer that requires a code from a phone (in addition to a password) to log in.Why is it important?
Giving a VA 'full admin' access is like giving a new intern the master key to your bank vault. It's an unnecessary risk. Using the 'Principle of Least Privilege' (giving the *minimum* access required) protects your customer data, your financial information, and prevents accidental (or malicious) changes, like someone deleting all your products.How to Set Up Staff Permissions:
- Go to Settings > Users and permissions.
- Click Add staff.
- Enter their name and email, then uncheck all permissions.
- Carefully check *only* the boxes they need. For a customer service VA, this is typically just Orders, Customers, and maybe the Inbox. They almost *never* need access to Settings, Billing, or Apps.
- Ensure Two-Factor Authentication is required for all staff logins (this is now standard on Shopify).
✅ Do's and ❌ Don'ts
- Do: Use 'Collaborator Access' for developers or agencies. This gives them their own access and doesn't use up one of your staff seats.
- Don't: Ever share your own 'Store Owner' login. Ever. You will lose all ability to recover your store if that password is stolen.
- Do: Review staff permissions every 90 days. If someone no longer needs access, remove it immediately.
- Don't: Give a 'general VA' access to `Discounts`, `Products`, or `Theme` unless you 100% trust them and have a backup. A simple mistake can cost you thousands.
DijiPilot Academy Access Required
This comprehensive masterclass (6.7 - Creating Standard Operating Procedures (SOPs) & Team Workflows (Difficulty: Advanced | Path: Scale)) is locked. Upgrade your plan to unlock the full technical roadmap.
Loading lesson roadmap for Phase 6.7...
Questions & Answers
Reviewing this step? Browse questions from other DijiPilot users below. If you are stuck, check the existing answers to bridge the gap between setup and success.