How to use this page
This matrix is designed for brand owners and organization admins who need to build or troubleshoot roles.- Use the capability column to find the behavior you want.
- Use the permission column to configure the role.
- Also verify the related module is enabled for the brand.
Core rules
*.viewusually controls whether a user can open a section or list.*.createcontrols creation flows.*.updatecontrols edits, state changes, and many operational actions.*.deletecontrols destructive actions.*.exportcontrols exports where supported.- Metrics are separate from feature permissions.
Common capability matrix
Metrics access matrix
Metrics are assigned separately from page permissions.
Examples of metric keys include:
revenuesalesnet_revenueconversion_raterefund_total
Recommended restricted-role patterns
Conversions-only viewer
conversions.view- selected metrics if you want dashboard visibility
Customers-only viewer
customers.viewcustomers.exportonly if export is required- selected metrics only if you want dashboard analytics
Reports reader
reports.view- report-specific permissions such as
conversions.view,customers.view,tracking.view, orreporting.utm_performance.view - selected metrics if the dashboard should also be visible
Operations user
conversions.viewconversions.update- optionally
integrations.viewif they should inspect integration setup - optionally
merchants.viewif they need merchant settings or merchant-based selectors
Important differences to remember
- Feature permissions decide what pages and actions a user can access.
- Metrics decide whether analytics widgets and dashboard numbers appear.
- A user may be able to view Fulfillment without being able to view Integrations.
- A user may see Reports but only be allowed into a subset of report pages.