Pelcro Collaborator Roles & Permissions
🔍 Problem Statement
As an Account Owner, Pelcro's collaborator roles lack granular permissions — the Admin role has unrestricted access to high-risk operations (deleting collaborators and customers, managing integrations and API keys, the import tool, and core account settings such as taxes, billing, ACH, identity and sites) while other roles lack capabilities they need for daily work. This creates security risks and operational friction.
💡 User Story
As an Account Owner, I want granular, role-based permissions across all collaborator roles, with destructive and account-level actions reserved for Owners, so that each team member has exactly the access they need — no more, no less.
🎯 Definition of Done (DoD)
- ✔ Given the updated permission model, when a collaborator attempts an action outside their role's permissions, then it is blocked with a clear error — and when they attempt an action within their role, then it succeeds.
- ✔ Only Account Owners can delete collaborators, delete customers, create/edit/enable integrations, manage API keys, run the standard import tool, and change core account settings.
- ✔ This change will impact UI / API — specifically the Collaborators page (Platform UI) and permission enforcement across the Core API.
- ✔ Limitations: existing collaborators are mapped onto the new model at rollout; no custom per-collaborator permission sets in this scope.
This request was merged into another request
Comments2
Chris Gogos
Nov 27, 2025
I would also like to add to this suggestion. In our use case we require a level above ‘Support’ so that our users can update a card for a customer and enter a payment. Currently we have opened up the admin role to users that shouldn’t have it, which is not good practice for many obvious reasons.
Zamir
Nov 13, 2025
was just adding this on. Currently there are only five collaborator roles in Pelcro backend. Admin is fine but the rest and not suitable. For example the next level down is support, but a support role cannot add products to ecommerce or refund ecom products. I would suggest if there is a way to decide what a user can have access to or action they can do.