Docs navigation
Home / Docs / Roles & permissions

Roles & permissions

What each user role can see and do in Foundry, and which role to give warehouse, purchasing, sales and finance staff.

Every person you invite to your organization gets one role. A role is a fixed set of permissions; you cannot edit the sets, but you can change a person’s role at any time from Settings → Users.

If you need something narrower than a role — for example an integration that may only read products — use an API key with custom scopes instead of a user.

Which role should I give someone?

Their jobRole
Runs the business, handles billing, can close the accountOwner
Manages everything day to day, including inviting usersAdmin
Counts, receives, moves and adjusts stock on the floorWarehouse
Buys from suppliers, raises purchase orders, handles vendor invoicesPurchasing
Looks after storefronts and marketplaces, listings and pricesChannel Manager
Maintains product data, images, categories, supplier feedsCatalog Manager
Picks, packs and ships ordersFulfillment
Answers customer questions, edits ordersCustomer Service
Approves invoices, reviews costs and reportsFinance
Needs to look but never change anythingViewer

Everyone can

Regardless of role, every member can view organization settings, the activity feed and notifications, file and read support tickets, and see the org’s affiliate codes.

What each role can do

Read = see it. Write = create, edit and delete it.

OwnerAdminWarehousePurchasingChannel MgrCatalog MgrFulfillmentCustomer SvcFinanceViewer
Products & variantswritewritewritewrite¹readwritereadreadreadread
Warehouses & binsmanagemanagemanagereadreadreadreadreadreadread
Adjust stock
Stock counts
Sources (suppliers)writewritewritewritewriteread
Purchase orderswritewriteread + receivewrite + receivereadreadreadread
Invoicesapproveapprovewriteapproveread
Landed costswritewritewritewriteread
Sales channels & listingswritewritewritewritereadreadread
Orderswritewritereadwritereadwritewritereadread
Shipmentsmanagemanagereadmanagereadread
Reports
Audit log & data exports
Users, API keys, apps, webhooks, org settings
Close the org, restore from a snapshot

¹ Purchasing can edit products (for supplier links and costs) but not variants.

Member is a legacy role identical to Admin; new invitations should use Admin.

Warehouse staff

For people on the floor the Warehouse role is the right fit: it covers receiving purchase orders, cycle counts, bin moves and stock adjustments, and product edits (so a wrong barcode or weight can be fixed on the spot), while keeping orders, channels, invoices and settings out of reach. If someone also picks and ships, give them Fulfillment instead and have a Warehouse user handle adjustments — a single account cannot hold two roles.

Changing a role

Settings → Users, pick the new role from the dropdown on the person’s row. It applies on their next request; no sign-out needed. Only Owners and Admins can change roles, and there must always be at least one Owner.