Skip to main content

How to use this page

This matrix is designed for brand owners and organization admins who need to build or troubleshoot roles.
  • Use the capability column to find the behavior you want.
  • Use the permission column to configure the role.
  • Also verify the related module is enabled for the brand.

Core rules

  • *.view usually controls whether a user can open a section or list.
  • *.create controls creation flows.
  • *.update controls edits, state changes, and many operational actions.
  • *.delete controls destructive actions.
  • *.export controls exports where supported.
  • Metrics are separate from feature permissions.

Common capability matrix

Metrics access matrix

Metrics are assigned separately from page permissions. Examples of metric keys include:
  • revenue
  • sales
  • net_revenue
  • conversion_rate
  • refund_total

Conversions-only viewer

  • conversions.view
  • selected metrics if you want dashboard visibility

Customers-only viewer

  • customers.view
  • customers.export only if export is required
  • selected metrics only if you want dashboard analytics

Reports reader

  • reports.view
  • report-specific permissions such as conversions.view, customers.view, tracking.view, or reporting.utm_performance.view
  • selected metrics if the dashboard should also be visible

Operations user

  • conversions.view
  • conversions.update
  • optionally integrations.view if they should inspect integration setup
  • optionally merchants.view if they need merchant settings or merchant-based selectors

Important differences to remember

  • Feature permissions decide what pages and actions a user can access.
  • Metrics decide whether analytics widgets and dashboard numbers appear.
  • A user may be able to view Fulfillment without being able to view Integrations.
  • A user may see Reports but only be allowed into a subset of report pages.

Next step

If a role still behaves unexpectedly, use Restricted Role Troubleshooting.