# Set up WMS users, roles and client access
URL: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access
Canonical: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access
Markdown: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access.md
Updated: 2026-07-20

> For the complete documentation index, see [llms.txt](https://support.starshipit.com/llms.txt).

> Choose WMS roles, add user permissions, limit 3PL client access, and resolve missing pages or actions.

Use WMS roles and permissions to give each warehouse user the access they need, while limiting selected users to specific clients in a shared 3PL workspace.

## Understand the two access layers

Starshipit account membership and WMS authorization are separate:

- **Starshipit account membership** controls the user's login and which Starshipit account they belong to.
- **WMS authorization** controls which WMS pages, records, job types, and actions that user can access.

Adding a WMS role does not create a Starshipit login. Removing a WMS role does not remove the user from your Starshipit account.

When you select **Sync Users**, WMS adds new users from the Starshipit account without changing existing WMS role assignments. The primary account is assigned **Admin** by default, while new Starshipit user accounts are assigned **Operator** by default. Review these defaults before users begin work.

## Before you begin

To manage WMS access, you need:

- The **Admin** role, or the custom `staff.manage` permission.
- Access to all clients. A client-scoped user cannot manage roles, even if they have `staff.manage`.
- Existing Starshipit account membership for each person who needs to sign in.
- Active WMS client records if you want to limit access by client.

## Choose a standard role

Each user has one of seven standard roles. The role supplies a set of default permissions.

| Role | Default access | Best suited to |
| --- | --- | --- |
| **Admin** | All WMS permissions, including settings, roles, products, locations, reporting, and every job type. | WMS owners and system administrators. |
| **Supervisor** | All operational job types; view all jobs; create, assign, release, and complete work; manage inventory, locations, purchase orders, fulfilment, and stock movements; view settings, staff, and process logs. It does not manage roles, settings, or products by default. | Warehouse managers and shift supervisors. |
| **Operator** | All operational job types; claim and complete work; adjust and move inventory; view products, locations, purchase orders, and stock movements. | Cross-trained warehouse operators. |
| **Picker** | Claim and complete picking work, with read access to products, inventory, and locations. | Team members who only pick orders. |
| **Packer** | Claim and complete packing work, with read access to products, inventory, and locations. | Team members who pack and ship orders. |
| **Receiver** | Receive stock, complete putaway and replenishment work, adjust inventory, and view purchase orders, products, and locations. | Goods-in and replenishment teams. |
| **Viewer** | Read-only access to jobs, products, inventory, locations, purchase orders, fulfilment, stock movements, analytics, and process logs. | Auditors, client service teams, and managers who should not change data. |

:::important
An **Operator** can complete every operational job type. Use **Picker**, **Packer**, or **Receiver** when a user only needs one part of the warehouse workflow.
:::

## Understand permission groups

Permissions control both page visibility and individual actions. The custom permission editor groups them into these areas:

| Permission group | What it controls |
| --- | --- |
| **Job Management** | Viewing your own or all users' jobs, and creating, assigning, claiming, releasing, completing, or deleting jobs. |
| **Job Types** | Picking, packing, receiving, putaway, replenishment, kitting, and cycle count workflows. |
| **Inventory & Locations** | Viewing, adjusting, and moving inventory, plus viewing or managing locations. |
| **Products & Orders** | Viewing or managing products, purchase orders, fulfilment records, and related actions. |
| **Reporting & Admin** | Analytics, exports, staff access, settings, process logs, and stock movement access. |

A page-level **View** permission does not include its **Manage**, **Adjust**, **Assign**, or **Export** actions. This is why a user may see a page but not see every button on it.

The editor shows permission codes such as `jobs.view.all`, `jobs.assign`, and `staff.manage`. Use the group and code together to identify the access you want to add.

## Add permissions for one user

Custom permissions add to the selected standard role. They cannot remove any of that role's defaults.

For example, you can start with **Packer** and add `jobs.view.all` and `jobs.assign` for a packing-bench lead. You cannot start with **Operator** and remove receiving or picking. To reduce access, choose a narrower role and add only the missing permissions.

Changing a user's standard role clears the custom permission selections so you can review the new base access before saving.

An **Interface Policy** is separate from authorization. It controls workflow options such as scanning and manual controls, but it does not grant access to pages or actions.

## Limit access by client

In a shared 3PL WMS instance, client records map child Starshipit accounts to the WMS account. A user's **Client Access** can be:

- **All clients**: No client restriction is added to the role.
- **Selected clients**: Client-aware products, inventory, orders, filter options, and supported reports are limited to the selected active clients.

Client scoping works alongside the role. A user needs both the page permission and access to the relevant client.

:::important
Client scoping is not the same as using a separate WMS instance. Shared products that are not assigned to a client and shared warehouse configuration, such as locations, may remain visible when the user's role grants access. Use separate WMS instances when clients require complete workspace isolation.
:::

Client-scoped users cannot manage WMS roles or modify and sync the shared product catalogue. This prevents a user limited to one client from changing account-wide access or shared product data.

## Assign or update a user's access

1. In WMS, go to **System > Roles & Permissions**.
2. Select **Sync Users** to add any new users from your Starshipit account. Existing assignments are preserved.
3. Find the user, open the actions menu, and select **Edit Role**.
4. Select the narrowest standard **Role** that covers the user's normal work.
5. Under **Client Access**, select **All clients** or **Selected clients**. If you choose selected clients, select at least one active client.
6. If needed, select **Add custom permission overrides** and add only the extra permissions the user requires.
7. Confirm the **Interface Policy** separately if the user's scanning or manual-control experience should differ from the account default.
8. Select **Save Role**.

Use **Add User Role** only when the user already has a Starshipit login and you know their Starshipit user ID. This action creates a WMS role assignment, not a new Starshipit user.

## Verify the user's access

After saving, ask the user to refresh WMS and check that:

- The sidebar shows only the pages allowed by their effective permissions.
- They can open the required workflow and complete an expected action.
- Client filters show only the clients they are allowed to use.
- Read-only users do not see create, edit, assign, adjust, or export actions that were not granted.

The WMS mobile app uses the same effective role, custom permissions, and client assignments as the web app. Mobile role preferences can further filter the job types shown in the app, but they cannot grant a job type that the WMS role does not allow.

Unified search is also permission-aware. It only includes result types whose destination pages the user can access. A missing search result can therefore indicate an access restriction rather than a missing WMS record.

## Apply least-privilege access

Use these examples as starting points:

| User | Suggested access |
| --- | --- |
| Picker working for one 3PL client | **Picker**, that client under **Selected clients**, no custom permissions. |
| Goods-in operator for several clients | **Receiver**, only those clients under **Selected clients**, no custom permissions. |
| Packing-bench lead | **Packer**, appropriate client scope, plus `jobs.view.all` and `jobs.assign` if they allocate work to others. |
| Client service or audit user | **Viewer**, only the clients they support. |
| Warehouse shift manager | **Supervisor**, appropriate client scope. Reserve **Admin** for people who manage WMS configuration and access. |

Review **Operator** assignments created by user sync. Downgrade them when the person does not need every operational job type.

## Troubleshooting missing pages or actions

| Problem | What to check |
| --- | --- |
| The user can sign in to Starshipit but has no WMS access | Select **Sync Users**, then confirm the user has an active WMS role assignment. Starshipit membership alone does not grant WMS permissions. |
| A page is missing from the sidebar | Check whether the user's role or custom additions include that page's **View** permission. Restricted pages are also excluded from unified search. Opening a page URL directly does not add permission to its protected data or actions. |
| The page opens, but a button or action is missing | Check the action-level permission, such as **Manage**, **Adjust**, **Move**, **Assign**, or **Export**. View access alone is not enough. |
| **Roles & Permissions** is missing | The user needs `staff.manage` and must have access to all clients. |
| A client or its data is missing | Confirm the client is active, mapped to the correct child Starshipit account, and selected in the user's **Client Access**. Also confirm the role can view that type of data. |
| The mobile app is missing a job type | Confirm the WMS role includes that job type, then check the user's mobile role preferences. Reopen the app or sign in again after an access change. |
| Search does not show a result type | Confirm the user can open the destination page. Search hides result groups for pages outside the user's permissions. |
| The user still has too much access | Choose a narrower standard role. Custom permissions only add access and cannot remove role defaults. |

## Related articles

- [WMS for 3PLs: suggested setup guide](/articles/14700000000032-wms-for-3pls-suggested-setup-guide)
- [How to set up Starshipit WMS](/articles/14700000000002-how-to-set-up-starshipit-wms)
- [Set up Starshipit WMS Mobile](/articles/14700000000023-setting-up-the-mobile-app)
- [Unified search](/articles/14700000000022-unified-search)
- [WMS settings reference](/articles/14700000000031-wms-settings-reference)
