Granular Role-Based Access Permissions

I would like to request the implementation of more granular, role-based access permissions within StoreKit.

Currently, some users require access to reporting and analytics data but should not be granted administrative privileges or permissions to modify store configurations, users, or system settings. For example, our Chef needs access to sales and operational reports to analyse performance and support decision-making, but does not require the ability to make changes to stores, settings, or system administration functions.

Introducing separate permission levels, such as View Analytics, Manage Orders, Manage Users, and Admin Settings, would provide our organisation with greater flexibility in assigning access based on job responsibilities. This would enable users to perform their duties effectively while limiting access to sensitive functions.

In addition to improving security, this enhancement would support the principle of least privilege and segregation of duties, which are key controls within security and compliance frameworks such as SOC 2 and ISO 27001.

This feature would strengthen governance, reduce the risk of unauthorised changes, improve audit readiness, and provide customers with better control over user access across the StoreKit platform.

Please authenticate to join the conversation.

Upvoters
Status

In Progress

Board

Features

Date

About 4 hours ago

Author

Terence Borg

Subscribe to post

Get notified by email when there are changes.