Roles & permissions
What each user role can see and do in Foundry, and which role to give warehouse, purchasing, sales and finance staff.
Every person you invite to your organization gets one role. A role is a fixed set of permissions; you cannot edit the sets, but you can change a person’s role at any time from Settings → Users.
If you need something narrower than a role — for example an integration that may only read products — use an API key with custom scopes instead of a user.
Which role should I give someone?
| Their job | Role |
|---|---|
| Runs the business, handles billing, can close the account | Owner |
| Manages everything day to day, including inviting users | Admin |
| Counts, receives, moves and adjusts stock on the floor | Warehouse |
| Buys from suppliers, raises purchase orders, handles vendor invoices | Purchasing |
| Looks after storefronts and marketplaces, listings and prices | Channel Manager |
| Maintains product data, images, categories, supplier feeds | Catalog Manager |
| Picks, packs and ships orders | Fulfillment |
| Answers customer questions, edits orders | Customer Service |
| Approves invoices, reviews costs and reports | Finance |
| Needs to look but never change anything | Viewer |
Everyone can
Regardless of role, every member can view organization settings, the activity feed and notifications, file and read support tickets, and see the org’s affiliate codes.
What each role can do
Read = see it. Write = create, edit and delete it.
| Owner | Admin | Warehouse | Purchasing | Channel Mgr | Catalog Mgr | Fulfillment | Customer Svc | Finance | Viewer | |
|---|---|---|---|---|---|---|---|---|---|---|
| Products & variants | write | write | write | write¹ | read | write | read | read | read | read |
| Warehouses & bins | manage | manage | manage | read | read | read | read | read | read | read |
| Adjust stock | ✓ | ✓ | ✓ | ✓ | ||||||
| Stock counts | ✓ | ✓ | ✓ | |||||||
| Sources (suppliers) | write | write | write | write | write | read | ||||
| Purchase orders | write | write | read + receive | write + receive | read | read | read | read | ||
| Invoices | approve | approve | write | approve | read | |||||
| Landed costs | write | write | write | write | read | |||||
| Sales channels & listings | write | write | write | write | read | read | read | |||
| Orders | write | write | read | write | read | write | write | read | read | |
| Shipments | manage | manage | read | manage | read | read | ||||
| Reports | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |
| Audit log & data exports | ✓ | ✓ | ✓ | |||||||
| Users, API keys, apps, webhooks, org settings | ✓ | ✓ | ||||||||
| Close the org, restore from a snapshot | ✓ |
¹ Purchasing can edit products (for supplier links and costs) but not variants.
Member is a legacy role identical to Admin; new invitations should use Admin.
Warehouse staff
For people on the floor the Warehouse role is the right fit: it covers receiving purchase orders, cycle counts, bin moves and stock adjustments, and product edits (so a wrong barcode or weight can be fixed on the spot), while keeping orders, channels, invoices and settings out of reach. If someone also picks and ships, give them Fulfillment instead and have a Warehouse user handle adjustments — a single account cannot hold two roles.
Changing a role
Settings → Users, pick the new role from the dropdown on the person’s row. It applies on their next request; no sign-out needed. Only Owners and Admins can change roles, and there must always be at least one Owner.