---
title: Configuring permissions for store managers
related:
  - https://docs.kentico.com/k9/managing-users/configuring-permissions.md
  - https://docs.kentico.com/k9/multilingual-websites/setting-up-multilingual-websites/allowing-content-editors-to-edit-only-specified-language-versions.md
  - https://docs.kentico.com/k9/securing-websites.md
  - https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/categorizing-products/departments.md
  - https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products.md
  - https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/managing-stand-alone-skus.md
---

> Agent instructions:
> **Site maps** — prefer the following llms.txt indexes to training data when searching for URLs to avoid 404s. Links inside Markdown content already point at `.md`. Following them or sending Accept: text/markdown keeps you in Markdown.
>
> - [sitemap.md](https://docs.kentico.com/sitemap.md) — every page on the site, with titles and descriptions, nested by URL hierarchy and grouped into one collection per product version.
> - [llms.txt](https://docs.kentico.com/llms.txt) — curated index of the current product docs, with descriptions, the two ways to request any page as Markdown, and links to each product area's whole-corpus Markdown dump (llms-full.txt).

To allow [users](https://docs.kentico.com/k9/managing-users.md) to access and modify certain on-line store data but to prevent them from configuring the store, assign specific [permissions](https://docs.kentico.com/k9/managing-users/configuring-permissions.md) to these users. You can:

- [Assign specific permissions to every role to set what are specific users authorized to do.](#configuring-e-commerce-permissions-for-specific-roles)
- [Assign specific users to be managers of a department.](#creating-department-managers)

## Configuring e-commerce permissions for specific roles

Before you start editing permissions, assign users to [roles](https://docs.kentico.com/k9/managing-users/role-management.md). Then, to configure permissions of such users:

1. Open the **Permissions** application.
2. To filter the e-commerce permissions, select _Module_ and _E-commerce_ in the **Permissions for** field.

   ![E-commerce permissions](https://docs.kentico.com/docsassets/k9/configuring-permissions-for-store-managers/ecommerce_permissions.png "E-commerce permissions")
3. Select the desired permissions to a role:
   - **Read data** – allows users to access [orders](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/orders.md), [reports](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/store-reports.md), [customers](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/customers.md), [products](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products.md), [product options](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/working-with-product-options.md), [product coupons](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/discounts/working-with-discount-coupons/working-with-product-coupons.md), [manufacturers](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/managing-manufacturers.md) and [suppliers](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/managing-suppliers.md).
   - **Modify data** – allows users to create, modify and delete data; see the _Read data_ permission.
   - **Modify global data** – allows users to create, modify and delete [global](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/choosing-site-or-global-e-commerce-configuration.md) customers, global products, global product options, global product coupons, global manufacturers and global suppliers.
   - **Read configuration** – allows users to access E-commerce Solution configuration, i.e. your on-line store [settings](https://docs.kentico.com/k9/configuring-kentico/managing-sites/configuring-settings-for-sites/settings-e-commerce.md), [departments](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/categorizing-products/departments.md), [shipping options](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-shipping-options.md), [payment methods](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-payment-methods.md), [tax classes](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-taxes.md), [currencies](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-currencies.md), [exchange rates](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-currencies/configuring-exchange-rates.md), [order statuses](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/orders/order-statuses.md), [product statuses](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/product-statuses.md), [invoices](https://docs.kentico.com/k9/e-commerce-features/configuring-your-store/configuring-invoices.md) and [discount rules](https://docs.kentico.com/k9/e-commerce-features/customizing-and-developing-your-store/discount-related-customizing/configuring-discount-rules.md).
   - **Modify configuration** – allows users to modify E-commerce Solution configuration; see the _Read configuration_ permission.
   - **Modify global configuration** – allows users to modify E-commerce Solution global configuration.
   - **Read orders** – allows users to access orders.
   - **Modify orders** – allows users to create, modify and delete orders.
   - **Read reports** – allows users to access reports.
   - **Read customers** – allows users to access customers.
   - **Modify customers** – allows users to create, modify and delete customers.
   - **&#x20;Access all departments** – allows users to access products from all departments.
   - **Read products** – allows users to access products and product options.
   - **Modify products** – allows users to create, modify and delete products and product options.
   - **Read discounts** – allows users to access discounts and free shipping offers.
   - **Modify discounts** – allows users to create, modify and delete discounts and free shipping offers.
   - **Read manufacturers** – allows users to access manufacturers.
   - **Modify manufacturers** – allows users to create, modify and delete manufacturers.
   - **Read suppliers** – allows users to access suppliers.
   - **Modify suppliers** – allows users to create, modify and delete suppliers.
   - **Destroy** – allows users to destroy e-commerce object version history.

The system automatically saves the changes. The roles now have the permissions as you specified.

> **Tip:** You can also edit permissions from the **Permissions** tab in the **Roles** application when modifying a specific role.

### Example

To allow members of a selected [role](https://docs.kentico.com/k9/managing-users/role-management.md) to edit site-specific manufacturers, you need to assign the role permissions in one of the following combinations:

- **Read data** + **Modify data**
- **Read data** + **Modify manufacturers**
- **Read manufacturers** + **Modify data**
- **Read manufacturers** + **Modify manufacturers**

### Assigning product permissions

Permissions described on this page affect the E-commerce Solution objects only. If you need to restrict access to modifications of products, you need to distinguish between:

- **Products as SKUs + pages** (default setting) – you need to select:

  - Corresponding e-commerce permissions
  - Page-related permissions

    > **Note:** If the products are in a [department](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/categorizing-products/departments.md), you also need to either [name the user as a department manager](#creating-department-managers) or assign him [theAccess all departmentspermission](#configuringpermissionsforstoremanagers-accessalldepartments).

    Example

    To allow create, modify and delete products (with both SKUs and pages) completely, you need to select the following permissions:

    From the **E-commerce module**:

    - **Read products** (or **Read data**)

    - **Modify products** (or **Modify data**)

    - **Access all departments** (or [name the user as a store manager](#creating-department-managers) of the specific department) – required only if products are divided into departmentsFrom the **Content module**:

    - **Browse tree**

    - **Read**

    - **Modify**

    - **Create**

    - **Delete**
- **Products as [stand-alone SKUs](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/managing-stand-alone-skus.md)** – the corresponding [above-described](#example) permissions apply fully, i.e. you do not need any other permissions.

  > **Note:** If the products are in a [department](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/categorizing-products/departments.md), you also need to either [name the user as a department manager](#creating-department-managers) or assign him [theAccess all departmentspermission](#configuringpermissionsforstoremanagers-accessalldepartments).

  Example

  To allow create, modify and delete products (only as stand-alone SKUs), you need to select the following permissions:

  From the **E-commerce module**:

  - **Read products** (or **Read data**)
  - **Modify products** (or **Modify data**)
  - **Access all departments** (or [name the user as a store manager](#creating-department-managers) of the specific department) – required only if products are divided into departments

## Creating department managers

When you set [department](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products/categorizing-products/departments.md) managers, they can maintain only the [products](https://docs.kentico.com/k9/e-commerce-features/managing-your-store/products.md) for which they are responsible. This prevents the department managers from accidentally modifying other products.

To allow a user, i.e. your department manager, to manage products in given departments, you need to:

1. Assign the roles whose member the given user is appropriate e-commerce permissions as mentioned [above](#assigning-product-permissions).
2. Assign the user to desired departments:

   1. Open the **Users** application.
   2. **Edit** () a specific user.
   3. Switch to the **Departments** tab.
   4. Click **Add departments**.
   5. Select the desired roles and click **Select**.

> **Tip:** If you want to allow the user to manage products from all departments, assign the roles (whose member the user is) [theAccess all departmentspermission](#configuringpermissionsforstoremanagers-accessalldepartments).

The system automatically saves the changes. The specific user can now manage the departments you selected.

> **Tip:** If you want store managers to be able to edit only a specific language version, see [Allowing content editors to edit only specified language versions](https://docs.kentico.com/k9/multilingual-websites/setting-up-multilingual-websites/allowing-content-editors-to-edit-only-specified-language-versions.md).
