Amazon Seller Account User Roles and Permissions: Who Can Do What

Seller Central has exactly one role with unconditional full access: the primary user, meaning the login that registered the account. Everyone else you add is an “employee” — a secondary user holding per-feature permissions someone granted them. An “administrator” is not a higher tier of access; it is an employee additionally given View and edit on the User Permissions page, which lets them manage other people’s permissions. And “owner” is not a Seller Central sign-in role at all: the account cannot be transferred, so business ownership and account access are two separate facts. Below: each role’s official definition, a permission matrix across inventory, orders, finance, advertising and customer service, and the checklist for the day an employee leaves.

Every role definition, navigation path and warning quoted here comes from Amazon’s public help article “Set and edit user permissions” (sellercentral.amazon.com help hub, article G901), readable without signing in. Read and quoted 2026-09-04.

Scope note: this guide is about the user accounts inside Seller Central, not the separate authorisation a third-party app receives through the Selling Partner API — a different system, covered in Amazon seller tool permissions on AMZFinder.

The four names, and which of them are real roles

Primary user. Amazon’s definition: “A primary user, also known as the account administrator, is the one who registers a new Seller Central account. The primary user will have access to every page and feature that their account type offers.” The role is defined by an event — registration — not by a setting you can toggle, and the access is unconditional: there is no permission you can withhold from it.

Secondary user. Amazon’s definition: “A secondary user is the one invited by the primary user, that is, an employee through the User permissions page.” In the current interface these people live in the Manage Employees section, and Amazon’s help text uses “secondary user” and “employee” interchangeably.

Administrator. The name most often misread. Amazon’s definition: “An employee will become an administrator when a primary user or another administrator grants them View and edit permission through the user permissions page. The new administrator can then manage permissions for other employees or service providers.” Administrator is therefore one specific permission — reaching the User Permissions page — not a bundle of access to inventory, orders or money. Amazon states the rule directly: “Only an employee who has been explicitly granted permission to access the user permissions page by the primary user can access the page.”

Owner. There is no Seller Central role called owner. The closest official statement is about transferring: “Although you can add users to your Professional seller account as secondary users, you can’t transfer the account. If the business ownership changes, the new owner should establish a new seller account in their name.” A business owner therefore has no access unless they personally hold the primary login or were invited as an employee. Buy a business and inherit “the account”, and what you inherited is somebody else’s registration.

A fifth party sits alongside these: “A service provider is a third-party partner that you authorize to access certain tools in your Seller Central account to perform account-related activities.” They live in a separate Manage Services section.

All of it requires a Professional plan: “The ability to set and manage permissions is available only to sellers with a Professional selling plan.” If you are still weighing the two, see Individual vs Professional.

What you are actually setting when you set a permission

Permissions are granted per feature, not per role — there is no “warehouse manager” preset to pick. The route is Settings → User Permissions → Manage Employees → Invite Employee, and to change someone later, Manage Employees → Edit next to their account.

On level names, be precise about what is public. Amazon’s help page names one level explicitly, View and edit, in the sentence that defines an administrator. The interface also offers a view-only setting and a no-access setting for each feature. But Amazon does not publish a consolidated page listing every permission and the levels it supports, so the complete label set is visible only after signing in — not documented publicly.

The permission matrix: five functional areas

Read this as what each role can do without anyone changing a setting first. Cells marked not documented publicly are ones we could not confirm on any Amazon page readable without an account, checked 2026-09-04. Every other cell follows from Amazon’s own definitions on the user permissions page and the Seller account information page, both checked the same day.

Functional areaOwner (legal account holder)Primary userAdministrator (employee with User Permissions edit)Secondary user (employee)Where the switch lives
Inventory and listingsNo access from ownership aloneFull — “every page and feature that their account type offers”Only the level granted to them personally, plus the power to change this permission for other employeesNone, view-only or View and edit, per featureUser Permissions → Manage Employees
Orders, shipping and returnsNo inherent accessFullSame; administrator status alone grants no order accessAs granted; whether a view-only level still exposes buyer names and addresses is not documented publiclyUser Permissions → Manage Employees
Finance, payments and reportsLegally exposed, but a name grants no sign-inFull — that includes Account info, where deposit methods liveSame; can hand finance access to another employee without holding itAs granted; whether a view-only level still exposes settlement figures and payout reports is not documented publiclyUser Permissions → Manage Employees
AdvertisingNo inherent accessFull inside Seller CentralSame; the Ads console runs its own user list, managed there and not here (see the section below)As granted here — but ad access is also governed separately (next section)Seller Central and the Amazon Ads console’s own user management
Customer service and messagingNo inherent access, but carries the account health consequencesFullSameAs granted; messaging and feedback are where a stale account does reputational damageUser Permissions → Manage Employees

Two structural points. The administrator column is not a stronger secondary-user column — it is the same access plus one extra power, redistributing permissions; whether an administrator can raise their own level is not documented publicly. And only one of the five rows has its switch somewhere other than the User Permissions page, which is the row most often handed to an outside agency.

What Amazon does not document publicly

Three gaps are worth naming, because guides that fill them are guessing:

  • The full permission inventory. No public page lists every permission name and the levels it supports. Any complete-looking list you find was transcribed from someone’s logged-in screen on an unstated date.
  • Administrator self-escalation. Amazon says a new administrator “can then manage permissions for other employees or service providers”. Whether that includes their own row is not stated.
  • A per-user activity log. We could not find an Amazon help page documenting a history of which user made which change. Treat per-user attribution as not documented publicly and, after a departure, reconcile against the data you can see — for example your Business Reports and account health history.

Amazon’s own warning makes the last gap consequential: “Remember, you are responsible for the actions of any users that you add to your account, including any misuse or illegal activities they may conduct through your account. Only grant access to individuals you know and trust.”

Three systems the matrix does not cover

Amazon Ads. The advertising console runs its own user management, with standardised roles named admin, editor and viewer that can be assigned at manager-account or advertiser level, alongside custom application-level permissions (advertising.amazon.com advertiser account guide, checked 2026-09-04). Removing someone from Seller Central does not touch that list.

Brand Registry. A separate role system with three roles, defined by Amazon staff on the public Seller Forums: “Rights Owner: the trademark owner or their employee who is authorized to report violations. Users with this role have access to the Report a Violation tool and listing benefits.”“Registered Agent: a third party who is authorized by the Rights Owner to report violations using Brand Registry tools.”“Administrator: the user who has permission to assign roles to user accounts.” (Seller Forums, Amazon staff post, read 2026-09-04). Roles are managed from Brand Registry → Settings → User permissions → Manage. See Brand Registry.

Service-provider authorisations. These are the one kind of access that expires on its own: “The access granted to service providers will be valid only for the service duration you select. After the expiry date, the provider’s access is automatically revoked.” Employee permissions carry no such duration. If you are engaging an agency through the Service Provider Network, that expiry is a feature worth using deliberately.

Offboarding checklist: the day someone leaves

Work through this on the last day, not at the end of the month. Steps 1 and 2 use Amazon’s own wording; the rest are the systems the first two do not reach.

  1. Remove the employee. From the Settings drop-down menu, select User Permissions. “In the Manage Employees section, select the dropdown next to the user that you want to remove and click Remove user.”
  2. Disable any service-provider authorisation they arranged. Same page: “In the Manage Service section, select the dropdown next to the service provider that you want to remove and click Disable Authorization.” Do this even for providers with time left to run — expiry is a backstop, not an offboarding step.
  3. Remove them in the Amazon Ads console separately. Step 1 does not do it. If they were an agency contact, check the manager-account level too.
  4. Strip their Brand Registry roles. Brand Registry → Settings → User permissions → Manage, then uncheck the roles in that brand’s row. A departing employee holding Rights Owner keeps the ability to file violation reports in your brand’s name.
  5. Change the primary user’s password and re-check two-step verification if that login was ever shared. Amazon is blunt that sharing sits outside the permission system: “account credentials are unique, and confidential information should not be shared with anyone.” Nothing revoked on the User Permissions page touches a password someone already knows.
  6. Check where notifications go. Under Settings, review the notification destinations for any address or phone number that routed to the person leaving — a forwarding address survives every step above.
  7. Revoke third-party app authorisations they set up. Connected tools are authorised separately from user permissions; work through them as a distinct list.
  8. Reconcile, because you cannot audit. With no public per-user activity log, the substitute is a before-and-after read of listings, pricing and payout settings. If something changed on the way out, treat it as an account-health matter early — the suspension appeal process costs far more than a same-day check.

Common mistakes

  • Sharing the primary login instead of inviting an employee. It is the one failure mode that no permission setting can contain, and it is why step 5 above exists.
  • Assuming Remove user is the whole job. It clears Manage Employees. Ads console access, Brand Registry roles and app authorisations all survive it.
  • Reading “administrator” as full access. It is one permission — the User Permissions page — and Amazon defines it that way explicitly.
  • Waiting for access to lapse. Only service-provider authorisations have a duration. Employee permissions last until someone removes them.
  • Making a temporary contractor an administrator to save time. Someone hired for one workflow can then reshape everyone else’s access; see hiring an Amazon VA for how to scope the role first.

Frequently Asked Questions

Can I transfer my Amazon seller account to a new owner?

No. Amazon’s help page states: “Although you can add users to your Professional seller account as secondary users, you can’t transfer the account. If the business ownership changes, the new owner should establish a new seller account in their name.” (checked 2026-09-04).

Is an administrator the same thing as the primary user?

No. The primary user registered the account and has access to every page their account type offers. An administrator is an employee granted View and edit on the User Permissions page — that lets them manage other users, and grants nothing else by itself.

Do I need a Professional plan to add users?

Yes: “The ability to set and manage permissions is available only to sellers with a Professional selling plan.” Individual sellers have no User Permissions page to open.

Does removing a user in Seller Central also remove their advertising access?

Not necessarily. The Amazon Ads console keeps its own user list with its own roles, so removing someone from Manage Employees leaves that list untouched. Check both.

What happens if I forget to revoke a service provider?

That one case has a safety net. Amazon states the authorisation is “valid only for the service duration you select” and that “After the expiry date, the provider’s access is automatically revoked.” Employee permissions have no equivalent expiry.

An employee says a page is missing. Is that a permissions problem?

Often, yes: “If you can’t access a Seller Central feature or help topic because you don’t have the necessary permissions, ask your primary account administrator to grant you permission.” For what the interface looks like with full access, see what Seller Central is.

Conclusion

The model that survives contact with the interface is short: one unconditional login, a pile of per-feature grants, one grant that redistributes the others, and three neighbouring systems no Seller Central removal will touch. Build the offboarding checklist once, keep it beside the User Permissions page, and the day someone leaves stops being an improvisation.