Skip to main content
Permissions are the building blocks of roles. Each permission grants one action on one feature. They fall into two categories: organization-level (always org-wide) and app-level (honouring a role’s app scope). Every action in the dashboard, the Meridian MCP server and the assistant is checked against this catalog. Nothing is gated on a role’s name alone.

Organization permissions

What each action covers

  • Organization: Edit changes the organization’s name, description, logo and its two-factor enforcement setting.
  • Team members: Edit invites, assigns roles and removes members. A non-owner can only remove or re-role a member whose permissions they hold themselves.
  • Roles: Edit creates and edits roles, their permissions and their app scope. A non-owner cannot grant a permission they do not hold.
  • Applications: Delete deletes an app, and covers cancelling an app.
  • Billing: View reads invoices: the invoice history and each invoice’s PDF and payment page, the organization’s billing details (billing country, and an Israeli business’s company name and VAT number) and, on the Billing page, the card on file (brand, last 4 digits and expiry). Invoices and the card cover every app of the organization, so they also need a role that reaches every app. The plan catalog and the current subscription are readable by every member, because the dashboard needs them on every page, but each member only sees the apps their role reaches. A role limited to some apps sees those apps’ plans, hosting and add-ons with their prices, and the organization’s status (a free trial, an unpaid renewal, a suspension) without the amounts owed. It sees no total for the organization: the Next invoice card says how many of the organization’s apps the role covers instead. A negotiated Enterprise plan is priced for one app, so it only shows to members whose role reaches that app.
  • Billing: Manage subscribes (including resuming or confirming a first payment after checkout), changes plan, buys add-ons and top-ups, edits the billing details, updates the card on file, resizes hosting, cancels or renews add-ons, manages always-on servers, and sends an Enterprise request for the organization. A change aimed at one app needs a role that reaches that app: its plan (and a plan change scheduled for its renewal), its hosting, and its add-ons and top-ups, bought, removed or kept. On the organization’s billing pages, a member whose role is limited to some apps only gets these controls for those apps. Accepting a published Enterprise offer moves every app at once, so it needs a role that reaches every app. Resuming a first payment, updating the card on file, moving from bank transfer to card payments and editing the billing details cover every app too, so they also need a role that reaches every app: a member whose role is limited to some apps is asked to get an owner or admin to do them, and sees the billing details read-only. When the organization has no billing country yet, that member can still give it when paying for one of their apps, but cannot change it afterwards. It never deletes an app: ending an app’s plan is cancelling the app, which needs Applications: Delete and the emailed confirmation code.
  • Data export: Manage starts, lists and downloads the organization’s data export. The export holds the apps the member’s role reaches: every app for the owner and for roles covering all apps, only its apps for a role limited to some. See Exporting your data.

App permissions

What each action covers

  • Integrations: Edit connects and disconnects Shopify, GitHub (the repository and the installation) and Slack.
  • Credentials: Manage provisions, rotates and revokes SDK API keys, rotates the hosting OAuth client and the webhook signing secret, reveals managed database and Redis passwords, and creates, edits, rotates and revokes external database access credentials. Each password reveal is recorded in the organization audit log. It also reveals the webhook signing secret and its rotation metadata. Opening the Webhooks page additionally needs Hosting: View. Hosting: Edit alone lets you change webhook routes, but does not reveal or rotate the signing secret.
  • Shopify API alerts: Edit updates alert preferences, acknowledges alerts, requests a fix and runs a scan.
  • Plan builder: Edit also publishes plans and recomputes usage views. Usage events, views and the usage feed sit under Plan builder for now.
  • Hosting: View reads environments, deployments, logs, metrics, secret metadata, add-ons, domains, previews, webhooks, security scans, external database credentials and the list of dev databases. Anyone with it can also create and manage their own dev database on that app.
  • Hosting: Edit creates environments, deploys, rolls back development and staging, creates and updates secrets, add-ons, domains, scheduler jobs, storage uploads and webhook routes, runs security scans and provisions a database.
  • Hosting: Promote brings a build to production and rolls production back. See Deployment.
  • Hosting: Delete deletes environments, add-ons, custom domains and secrets, restores a backup, and runs write or DDL statements in the SQL console.
  • Dev databases: Manage resets, deletes and inspects other developers’ dev databases. Your own only needs Hosting: View.
  • Database backups: Download downloads a whole database dump.
  • Emails: Edit creates and edits emails, activates and pauses them, test-sends, and manages sending domains within the role’s app scope. A domain another app also sends from, the organization default and adding a domain need a role that covers those apps. See Sending domain.
  • Automations: Edit edits automations, enables and pauses them, and runs test runs.
  • CRM: Contacts: Edit adds, edits and removes store contacts.
  • CRM: Custom fields: Edit also sets values on stores.
  • CRM: Reports running and exporting a report also needs each dataset’s own permission.
  • Affiliates: Payouts generates, pays and cancels payouts, and edits the payout settings.
Demo mode: Manage is the one organization permission that does not follow the view/edit split: every default role (owner, admin and member) holds it, so anyone on the team can put the organization into demo mode and take it back out again. Data export: Manage and Database backups: Download hand over a whole dataset at once, so they are not View permissions: owners and admins have them, and members only when a role gives them. The default Admin role holds every permission in both tables. The default Member role holds every View permission plus Demo mode: Manage, and nothing that mutates. Admins can grant edit, create, delete, promote and manage permissions to the member role or to a custom role as needed. App permissions only reach the apps a role is scoped to. The three things no permission grants (ownership transfer, deleting the organization, and the owner leaving) stay with the owner. See Roles and permissions.
Last modified on October 9, 2026