Permissions
Permissions apply to one workspace at a time. Users with the “Owner” or “Admin” role can configure sellerfox. Users with the “Viewer” role can read supported areas. Users with the “External” role can receive selected emails and have no dashboard access to that workspace.
Role summary
| Documentation role | Dashboard label | Main boundary |
|---|---|---|
| Owner | “Workspace owner” | One per workspace; controls billing and starts an ownership transfer |
| Admin | “Admin” | Full operational configuration, but no billing change and no transfer start |
| Viewer | “Readonly access” | Reads the dashboard areas that support read-only access |
| External | “External” | Email only, no dashboard access to that workspace; offered in some workspaces |
A role applies to one workspace only. The same sellerfox account can be an Owner in one workspace and a Viewer in another. Invitations are managed separately for each workspace.
Permissions matrix
| Area or action | Owner | Admin | Viewer | External |
|---|---|---|---|---|
| Dashboard analytics views | Use and configure | Use and configure | Read only | No access |
| Orders | Read and use available actions | Read and use available actions | Read only | No access |
| Profit Tracking | Read; edit COGS, income and expenses, and cost settings | Read; edit COGS, income and expenses, and cost settings | Read only | No access |
| Keywords | Manage | Manage | No access | No access |
| Events | Create, manage, and read | Create, manage, and read | Read only | No access |
| KPI alerts | Configure and read | Configure and read | Read the alert list | Email summary if enabled |
| Webhooks | Configure and monitor | Configure and monitor | No access | No access |
| PDF reports | Generate and configure | Generate and configure | Generate manually and read the report list | Scheduled email if enabled |
| Product lists, KPI sets, saved filters | Manage | Manage | Select existing entries where offered | No access |
| Amazon connections | Authorize and renew | Authorize and renew | No access | No access |
| Workspace settings | Change | Change | Read; may leave the workspace | No access |
| User Management | Invite, edit, and remove | Invite, edit, and remove | No access | No access |
| MCP access for the workspace | Enable or disable | Enable or disable | No access | No access |
| Subscription and invoices | Read and change | Read only | No access | No access |
| Ownership transfer | Start or cancel | Accept or decline when selected | No access | No access |
The same permission rules apply to the analytics views in the dashboard (Overview, Marketplaces, Products, BSR Explorer, and Search Term Analyzer).
Exceptions to the matrix
- Only the Workspace Owner completes onboarding. During onboarding, authorization fixes the connected Seller Central account and Amazon selling region. Afterward, Owners and Admins can authorize and renew the Amazon connections.
- Only the Workspace Owner changes billing and starts an ownership transfer. An Admin can accept the transfer after the Workspace Owner selects that Admin.
- The “Subscription” tab is hidden from everyone, the Workspace Owner included, in a workspace where sellerfox invoices outside the dashboard. See Subscription, billing & credits.
- Viewers do not see the “Keywords” navigation entry.
- An External member must have at least one email delivery enabled: KPI alerts or scheduled PDF reports.
- MCP authorization belongs to the person, not the workspace. Removing a member from a workspace removes that workspace from the person's MCP access.
- Plan limits apply independently of the role. A higher role does not raise a quota and does not make a missing export appear.
Change a member's access
Open Settings → User Management as an Owner or Admin.
- 1
Change the role
Open the three-dot menu of the row, choose “Edit user”, and change the member's role between “Admin” and “Readonly access”. The change applies to that workspace only.
- 2
Adjust the email notifications
The member list includes the “KPI alerts email” and “Performance PDF report email” columns. Both are off by default for a new dashboard member.
The three-dot menu also includes “Remove from workspace”. Removal takes effect immediately, and sellerfox emails the person that their access was withdrawn. You cannot remove yourself, the Workspace Owner, or the last remaining member.
Owner and External follow different processes. In an existing workspace, the Owner role can only be reassigned through an ownership transfer. External cannot be converted to or from a dashboard role; remove the member and invite the person again with the role you want. See Workspaces, teams & roles for invitations, transfer, and leaving.
Related
- Workspaces, teams & roles — invitations, transfer, leaving, and deletion.
- Your account — personal identity and connected apps.
- How sellerfox works — which views support exports and in which formats.
- Data security — workspace data access and external flows.