Staff & roles
Invite team members and control exactly what each one can do.
Add people to your store without giving anyone more than they need. Roles are permission templates; staff members are people you assign a role to. Both live under Settings (Roles and Managers).
Roles are permission templates
A role is a named bundle of permissions. Assign it to a person and they get exactly that access. Cartisto ships three to start from:
| Role | Access |
|---|---|
| Owner | Everything. It’s a system role — it can’t be edited or deleted. |
| Manager | Day-to-day operations: products, categories, orders, customers, inventory, reviews, refunds, coupons, invoices, shipping, themes, pages, notifications, POS, marketing, metafields. |
| Viewer | Read-only: analytics and invoices. |
Duplicate one of these or build your own — a role can be as narrow as a single area.
Permission areas
Permissions map to the parts of the dashboard, including: products, categories, orders, customers, inventory, coupons, marketing, reviews, refunds, invoices, shipping, payments, themes, pages, blog, metafields, redirects, pixels, webhooks, domain, analytics, notifications, language & currency, store info, POS (and a separate POS price override), COD settlement, affiliate payouts, the AI assistant, managers, roles, subscription, and the audit log.
Grant only what a job needs — a warehouse packer might get orders and inventory and nothing else.
Adding a team member
- Go to Settings → Managers and invite the person by email.
- Assign a role.
- They sign in with their own account — actions are recorded against them in the audit log, so you always know who did what.
Only trusted staff should hold managers or roles
Those two permissions let someone create staff and edit roles — effectively
granting access. Keep them on the Owner and a small number of trusted admins.
Staff vs. developers vs. integrations A person on your team → a staff account with a role (this page). An outside theme developer → a scoped Developer access key. Another software system → an API key.