Skip to content

Advanced Admin Permissions User Guides

These guides cover the day-to-day work of running admin permissions with Advanced Admin Permissions: handing out roles, restricting people to the websites they look after, time-boxing access, and checking afterwards who can reach what.

Where to Start

  • Multiple Roles per Admin User - assign several roles to one admin user, understand how their permissions combine, use negative (deny) roles to carve out exceptions, and assign or remove a role across many users at once.
  • Website and Store View Restriction - limit a role, an admin user or an integration to certain websites or store views, and what a restricted admin sees across the panel.
  • Time-Boxed Role Grants - grant a role until a chosen date and time, for contractors, cover during leave, or a one-off migration.
  • Roles for Integrations - grant group roles to an integration instead of ticking its resource tree box by box, and restrict an integration's API calls to certain scopes.
  • Role Assignment Audit Log - read the record of every role grant and revocation, including the attempts that were refused.
  • Effective Permissions Viewer - see everything an admin user or integration can reach, and which role grants each resource.
  • Permission Guardrails - the four rules that stop an admin widening their own access, and what to do when a save is refused.

New to Magento admin roles?

Advanced Admin Permissions builds on Magento's own role system rather than replacing it. Roles, the resource tree and the users grid all work the way they always have. These guides only cover what Advanced Admin Permissions adds on top.