# Set up WMS users, roles and client access
URL: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access
Canonical: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access
Markdown: https://support.starshipit.com/articles/14700000000036-set-up-wms-users-roles-and-client-access.md
Updated: 2026-09-04

> For the complete documentation index, see [llms.txt](https://support.starshipit.com/llms.txt).

> Choose WMS roles, customise user permissions, limit 3PL client access, and resolve missing pages or actions.

Use WMS roles and permissions to give each warehouse user the access they need, while limiting selected users to specific clients in a shared 3PL workspace. WMS supports both Starshipit-backed users and WMS-local workers who do not need an email address or Starshipit login.

## Understand the two access layers

Starshipit account membership and WMS authorization are separate:

- **Starshipit account membership** controls the user's login and which Starshipit account they belong to.
- **WMS authorization** controls which WMS pages, records, job types, and actions that user can access.

Adding a WMS role does not create a Starshipit login. Removing a WMS role does not remove the user from your Starshipit account.

When you select **Sync Users**, WMS adds new users from the Starshipit account without changing existing WMS role assignments. The primary account is assigned **Admin** by default, while new Starshipit user accounts are assigned **Operator** by default. Review these defaults before users begin work.

The **Roles & Permissions** page shows each person's role, client access and effective permission count before you open their detailed assignment.

![The WMS Roles and Permissions page showing users, roles and client access](/uploads/articles/starshipit-wms/web/warehouse-configuration/roles-and-permissions.png)

## Before you begin

To manage WMS access, you need:

- The **Admin** role, or the custom `staff.manage` permission.
- Access to all clients. A client-scoped user cannot manage roles, even if they have `staff.manage`.
- Existing Starshipit account membership for each Starshipit-backed user. WMS-local workers are created separately in **Roles & Permissions**.
- Active WMS client records if you want to limit access by client.

## Choose a standard role

Each user has one of seven standard roles. The role supplies a set of default permissions.

| Role | Default access | Best suited to |
| --- | --- | --- |
| **Admin** | All WMS permissions, including settings, roles, products, locations, reporting, and every job type. | WMS owners and system administrators. |
| **Supervisor** | All operational job types; view all jobs; create, assign, release, and complete work; manage inventory, locations, purchase orders, fulfilment, and stock movements; view settings, staff, and process logs. It does not manage roles, settings, or products by default. | Warehouse managers and shift supervisors. |
| **Operator** | All operational job types; claim and complete work; adjust and move inventory; view products, locations, purchase orders, and stock movements. | Cross-trained warehouse operators. |
| **Picker** | Claim and complete picking work, with read access to products, inventory, and locations. | Team members who only pick orders. |
| **Packer** | Claim and complete packing work, with read access to products, inventory, and locations. | Team members who pack and ship orders. |
| **Receiver** | Receive stock, complete putaway and replenishment work, adjust inventory, and view purchase orders, products, and locations. | Goods-in and replenishment teams. |
| **Viewer** | Read-only access to jobs, products, inventory, locations, purchase orders, fulfilment, stock movements, analytics, and process logs. | Auditors, client service teams, and managers who should not change data. |

:::important
An **Operator** can complete every operational job type. Use **Picker**, **Packer**, or **Receiver** when a user only needs one part of the warehouse workflow.
:::

## Understand permission groups

Permissions control both page visibility and individual actions. The custom permission editor groups them into these areas:

| Permission group | What it controls |
| --- | --- |
| **Job Management** | Viewing your own or all users' jobs, and creating, assigning, claiming, releasing, completing, or deleting jobs. |
| **Job Types** | Picking, packing, receiving, putaway, replenishment, kitting, and cycle count workflows. |
| **Inventory & Locations** | Viewing, adjusting, and moving inventory; counting or approving stocktakes; and viewing or managing locations. |
| **Products & Orders** | Viewing or managing products, purchase orders, fulfilment records, and related actions. |
| **Reporting & Admin** | Analytics, exports, staff access, settings, process logs, and stock movement access. |

A page-level **View** permission does not include its **Manage**, **Adjust**, **Assign**, or **Export** actions. This is why a user may see a page but not see every button on it.

The **Create Cycle Count** control is governed by the cycle-count workflow permission (`cycle-count.*`) in **Job Types**. Generic create or manage permissions in **Job Management** do not reveal this control.

The editor shows permission codes such as `jobs.view.all`, `stocktake.count`, `stocktake.approve`, and `staff.manage`. Use the group and code together to identify the access you want to keep or add.

## Customise permissions for one user

Select **Customize role permissions** to replace the selected standard role's permission set for one user. Permissions included by the role template are marked **(template)**. Clear a template permission to remove it, or select another permission to add it.

For example, you can start with **Packer** and add `jobs.view.all` and `jobs.assign` for a packing-bench lead. You can also separate stocktake duties by giving counters `stocktake.count` without `stocktake.approve`, then keeping approval with supervisors.

Changing a user's standard role turns off the custom permission set and restores the new role template. Review and customise the permissions again before saving when the user needs an exception.

An **Interface Policy** is separate from authorization. It controls workflow options such as scanning and manual controls, but it does not grant access to pages or actions.

## Limit access by client

In a shared 3PL WMS instance, client records map child Starshipit accounts to the WMS account. A user's **Client Access** can be:

- **All clients**: No client restriction is added to the role.
- **Selected clients**: Client-aware products, inventory, orders, filter options, and supported reports are limited to the selected active clients.

Client scoping works alongside the role. A user needs both the page permission and access to the relevant client.

:::important
Client scoping is not the same as using a separate WMS instance. Shared products that are not assigned to a client and shared warehouse configuration, such as locations, may remain visible when the user's role grants access. Use separate WMS instances when clients require complete workspace isolation.
:::

Client-scoped users cannot manage WMS roles or modify and sync the shared product catalogue. This prevents a user limited to one client from changing account-wide access or shared product data.

## Assign or update a user's access

1. In WMS, go to **System > Roles & Permissions**.
2. Select **Sync Users** to add any new users from your Starshipit account. Existing assignments are preserved.
3. Find the user, open the actions menu, and select **Edit Role**.
4. Select the narrowest standard **Role** that covers the user's normal work.
5. Under **Client Access**, select **All clients** or **Selected clients**. If you choose selected clients, select at least one active client.
6. If needed, select **Customize role permissions**, then select every permission the user should keep or add and clear any template permissions they should not have.
7. Confirm the **Interface Policy** separately if the user's scanning or manual-control experience should differ from the account default.
8. Select **Save Role**.

Use **Add User Role** only when the user already has a Starshipit login and you know their Starshipit user ID. This action creates a WMS role assignment, not a new Starshipit user.

## Verify the user's access

After saving, ask the user to refresh WMS and check that:

- The sidebar shows only the pages allowed by their effective permissions.
- They can open the required workflow and complete an expected action.
- Client filters show only the clients they are allowed to use.
- Read-only users do not see create, edit, assign, adjust, or export actions that were not granted.

The WMS mobile app uses the same effective role, custom permissions, and client assignments as the web app. Mobile role preferences can further filter the job types shown in the app, but they cannot grant a job type that the WMS role does not allow.

Unified search is also permission-aware. It only includes result types whose destination pages the user can access. A missing search result can therefore indicate an access restriction rather than a missing WMS record.

## Apply least-privilege access

Use these examples as starting points:

| User | Suggested access |
| --- | --- |
| Picker working for one 3PL client | **Picker**, that client under **Selected clients**, no custom permissions. |
| Goods-in operator for several clients | **Receiver**, only those clients under **Selected clients**, no custom permissions. |
| Packing-bench lead | **Packer**, appropriate client scope, plus `jobs.view.all` and `jobs.assign` if they allocate work to others. |
| Client service or audit user | **Viewer**, only the clients they support. |
| Warehouse shift manager | **Supervisor**, appropriate client scope. Reserve **Admin** for people who manage WMS configuration and access. |

Review **Operator** assignments created by user sync. Downgrade them when the person does not need every operational job type.

## Troubleshooting missing pages or actions

| Problem | What to check |
| --- | --- |
| The user can sign in to Starshipit but has no WMS access | Select **Sync Users**, then confirm the user has an active WMS role assignment. Starshipit membership alone does not grant WMS permissions. |
| A page is missing from the sidebar | Check whether the user's effective permissions include that page's **View** permission. When **Customize role permissions** is enabled, check the complete custom set because cleared template permissions are excluded. Restricted pages are also excluded from unified search. Opening a page URL directly does not add permission to its protected data or actions. |
| The page opens, but a button or action is missing | Check the user's effective permissions for the required action, such as **Manage**, **Adjust**, **Move**, **Assign**, or **Export**. View access alone is not enough. |
| **Create Cycle Count** is missing | Add the cycle-count workflow permission (`cycle-count.*`) under **Job Types**. Generic create or manage permissions under **Job Management** do not reveal this control. |
| **Roles & Permissions** is missing | The user needs `staff.manage` and must have access to all clients. |
| A client or its data is missing | Confirm the client is active, mapped to the correct child Starshipit account, and selected in the user's **Client Access**. Also confirm the user's effective permissions allow them to view that type of data. |
| The mobile app is missing a job type | Confirm the user's effective WMS permissions include that job type, then check their mobile role preferences. Reopen the app or sign in again after an access change. |
| Search does not show a result type | Confirm the user can open the destination page. Search hides result groups for pages outside the user's permissions. |
| A submitted stocktake is waiting for approval | Confirm another user has `stocktake.approve`. Users with only `stocktake.count` can submit counts but cannot apply the variance. |
| The user still has too much access | Select **Customize role permissions** and clear the unwanted template permissions, or choose a narrower standard role. |

## Related articles

- [WMS for 3PLs: suggested setup guide](/articles/14700000000032-wms-for-3pls-suggested-setup-guide)
- [How to set up Starshipit WMS](/articles/14700000000002-how-to-set-up-starshipit-wms)
- [Set up Starshipit WMS Mobile](/articles/14700000000023-setting-up-the-mobile-app)
- [Unified search](/articles/14700000000022-unified-search)
- [WMS settings reference](/articles/14700000000031-wms-settings-reference)
