Home shopify-plus-role-migration-google-ads-multi-store-audit
September 22, 2026

Shopify Plus organizations using paid acquisition should treat the unified staff model as a change requiring acceptance, not as proof that operations are ready. Shopify announced on June 11, 2026 that POS and admin staff management is now handled in Settings > Users. The company says existing users, permissions and roles were automatically migrated, but it also identifies an exception with operational consequences: authority to create, edit or delete roles is now organization-wide and was not automatically granted.
Shopify also says merchants can manage POS users and PINs from the unified area, assign multiple or custom roles, suspend seasonal staff without deleting their accounts, and give Shopify Plus staff access across multiple shops through one profile. Four high-trust POS roles are identified: POS Administrator, POS Device Setup, POS User Administrator and Organization POS Administrator. These are confirmed product facts. The audit design below is CreatikLab methodology for deciding whether the resulting access model is safe and usable for multi-store Google Ads work; Shopify does not claim that the update validates advertising operations.
A migrated account can still fail at the moment a commerce team needs to inspect a product page, correct promotional content, verify a shop-specific destination or obtain approval for a change. The useful question is therefore not whether a user appears in the new interface. It is whether an identified person can complete an approved task in the intended shop, while someone else retains responsibility for reviewing sensitive changes.
CreatikLab separates identity continuity from task readiness. Identity continuity asks whether the expected user, history and role record remain present. Task readiness asks whether access is sufficient, excessive or blocked for a defined workflow. For Google Ads operations, the test should start with real dependencies: which shop serves each campaign, who owns the destination experience, who can authorize commerce changes, and who investigates a mismatch. This framing avoids turning a permissions review into a list of usernames with no connection to campaign risk.
Build the audit around tasks that affect the route from ad click to commercial outcome. The following CreatikLab matrix is deliberately evidence-based. It does not prescribe Shopify permissions; each merchant must map the task to its own approved role design.
Use a simple decision rule: retain access only when a named business task, accountable owner and review path can all be demonstrated. If one element is missing, pause the assignment and document the gap rather than expanding authority to make the immediate problem disappear.
The central design decision is who may perform commerce work and who may redesign the access system itself. Shopify's update makes role creation, editing and deletion an organization-wide authority. CreatikLab therefore recommends treating that authority as a governance function rather than bundling it automatically with campaign management, merchandising or local shop administration.
Start with four responsibility layers: requester, executor, reviewer and access administrator. One person may hold more than one layer when the organization is small, but the overlap should be recorded and approved. A Google Ads specialist might identify a broken destination or inconsistent offer; that does not automatically mean the specialist should edit organization-wide roles. Conversely, an access administrator should not be assumed to understand campaign intent. The handoff must include the affected shop, requested task, urgency, evidence, rollback path and final verifier. This creates inspectable accountability without claiming that any particular role structure is universally correct.
The checklist is complete only when each result has evidence. A statement such as access looks fine is not an acceptance test. A stronger record identifies the task, expected boundary, observed result, owner and corrective decision.
Do not claim that a permission change caused revenue, ROAS or lead quality to improve. Access is an operational control, and its direct measures should remain operational: percentage of critical task tests passed, unresolved access exceptions, privileged assignments without documented justification, time to route an incident, and changes completed with the required review. These indicators reveal whether the operating model is dependable; they do not establish media incrementality.
Keep campaign and business measurement in a separate layer. For ecommerce, compare order, revenue, cancellation, return or margin information only when the business has reliable definitions and data. For wholesale or lead-generating journeys, report raw enquiries separately from qualified leads. CreatikLab defines qualification with the client before analysis, using inspectable CRM evidence such as valid commercial fit, sales acceptance or progression to an agreed stage. Reconcile those outcomes with Google Ads conversion records, but label discrepancies rather than forcing the systems to match. The official Shopify announcement does not specify advertising measurement behavior.
A narrow audit is preferable to broad access granted for convenience. When a task fails, diagnose whether the cause is identity, role assignment, shop scope, approval design or missing ownership before changing permissions.
For this use case, a provider should deliver more than an account screenshot. Ask for a campaign-to-shop dependency map, a user and privileged-role inventory, representative task scripts, an exception register, a responsibility matrix, remediation priorities and a retest record. The Google Ads portion should inspect destination ownership, conversion governance and the process for resolving commerce-side incidents. Exact platform permissions should remain a merchant-approved decision.
Compare providers by the quality of their evidence and decision boundaries. A credible proposal explains what will be tested, which production actions are excluded, who must participate, how qualified outcomes are defined and how unresolved risks will be reported. It should separate confirmed Shopify capability from its own operating recommendations. It should also avoid guaranteeing ROAS, rankings or lead volume. Seniority is demonstrated when the provider can trace a campaign issue to an owner and an acceptance test, not when it requests the broadest possible access.
Begin with a Google Ads account audit scoped to produce a campaign-to-shop dependency map, critical access-path tests, a conversion and destination change-control review, and a prioritized findings register. This is the primary diagnostic deliverable; it is not a promise of traffic, ROAS or lead volume.
If the audit exposes decisions about ownership, multi-shop operating design or remediation sequencing, use senior Google Ads consulting as the next decision step. The Google Ads Expert route explains the authority bridge between diagnosis and accountable implementation. To continue with context before choosing a scope, tell Lia how many shops are involved, what changed after migration, which campaign task is blocked and how your business currently recognizes a qualified sale or lead.
Shopify announced that POS and admin staff management is unified under Settings > Users. The update also introduced organization-level role options for Shopify Plus, support for multiple roles, seasonal staff suspension and named high-trust POS roles.
Shopify says existing users, roles and permissions were migrated automatically. The important exception concerns authority to create, edit or delete roles: that authority is now organization-wide and was not granted automatically.
Automatic migration confirms that records were moved; it does not prove that every person can complete the correct business task in the correct shop. CreatikLab recommends task-level tests, evidence capture and explicit ownership before relying on the new model during paid campaigns.
Not by default. CreatikLab recommends granting only the access required for an approved task. The owner of organization-wide role administration should be selected through an internal governance decision, not inferred from a media role.
For lead-generating or wholesale journeys, define a qualified lead using agreed CRM evidence such as sales acceptance, valid commercial fit or progression to a meaningful stage. Report that separately from raw forms, calls or platform conversion totals.
The scope should identify shop-to-campaign dependencies, test critical access paths, inspect conversion and landing-page change control, document owners and produce a prioritized remediation register. It should not promise a particular ROAS, ranking or lead volume.
Get practical insights about Google Ads, SEO, GEO, AEO, ecommerce, tracking and AI-powered digital growth.
©2024 CreatikLab. All Rights Reserved