Amazon Secondary User Access: Security & Delegation Guide

Delegating work is the only way to scale an Amazon brand, but it introduces a major operational vulnerability: security. Far too many brand owners still share their primary Seller Central login credentials with virtual assistants (VAs), agencies, or employees.
Sharing primary credentials is a direct violation of Amazon’s Terms of Service. More importantly, it gives external users the power to alter bank deposit details, delete inventory, access sensitive tax documents, and trigger accidental suspensions.
The correct solution is the structured application of Secondary User Access. This guide details how to configure permissions, map them to specific roles, bridge the gap between Seller Central and Brand Registry, and execute a secure offboarding protocol.
Key Takeaways
Primary vs. Secondary Accounts: The Mechanics of Isolation
The primary account is the email address used to register the Amazon Seller account. It retains absolute control, cannot be deleted, and holds the ultimate liability for any policy violations.
Secondary accounts are individual sub-identities invited by the primary user. They do not share login credentials. Instead, they access the account using their own email address, password, and two-factor authentication (2FA).
The "Related Accounts" Suspension Risk
A common fear among sellers is that adding an agency or service provider as a secondary user will link their store to other, potentially suspended, seller accounts.
Official Amazon secondary user access does not trigger a "Multiple Account Association" suspension. Amazon’s security systems recognize that agencies, aggregators, and consultants manage multiple clients.
However, if you share primary login credentials, or if an external contractor logs into your primary account from an IP address associated with a suspended brand, Amazon’s automated detection systems may flag the accounts as related, leading to a swift suspension. Utilizing official secondary user invitations is your primary defense against this specific risk.
Mapping Permissions to Operational Roles
When you invite a secondary user, Amazon defaults their permissions to "None" across all categories. You must manually assign rights.
Use the principle of Least Privilege: grant only the minimum level of access required for a user to complete their job.
| Role | Required Permissions (View/Edit) | Explicitly Block (None) |
|---|---|---|
| PPC Agency / Media Buyer | Advertising (Campaign Manager), Store Design, Business Reports | Settings (User Permissions, Tax Info, Bank Accounts), Inventory (Shipments) |
| Inventory & FBA Specialist | Manage Inventory/FBA Inventory, Manage FBA Shipments, Inventory Planning | Advertising, Campaign Manager, Settings, Performance Metrics |
| Customer Service VA | Manage Orders, Feedback, Buyer-Seller Messaging | All Inventory settings, Reports, Financials, Campaign Manager |
| Financial Analyst / Accountant | Payments, Transactions, Settlement Reports | Inventory, Campaign Manager, Seller Forums, Catalog Creation |
How to Invite a Secondary User
Log into Seller Central as the Primary User.
Navigate to Settings (gear icon in the top right) > User Permissions.
Scroll to the "Add a New User" section.
Enter the user's name and corporate email address, then click Invite.
The invitee must click the link in their email, create or log into their Amazon customer account, and complete 2FA.
Once accepted, their status changes from "Pending" to "Active" on your User Permissions page. Click Manage Permissions next to their name to assign specific rights.
The Brand Registry Permission Gap
A frequent pain point for brand owners is assigning a secondary user to manage listings, only to find they cannot upload A+ Content, build a Brand Store, or access Brand Analytics.
This happens because Seller Central permissions do not automatically transfer to Amazon Brand Registry. They are completely separate databases.
To grant brand-specific capabilities, you must invite the user through the Brand Registry portal:
Navigate to brandservices.amazon.com and sign in.
Go to Settings > User Permissions.
Select your brand and click Invite a user to your brand.
Enter their email address and select the appropriate role:
- Administrator: Can manage other users (rarely grant this to external partners).
- Rights Owner: Can report intellectual property violations and manage brand elements.
- Registered Agent: Authorized to report violations on behalf of the brand (ideal for legal partners or specialized brand protection agencies).
Without this step, your creative or catalog team will constantly run into authorization errors in Seller Central when trying to optimize listings.
Managing Third-Party Software Access (SP-API)
Human users are only half of the delegation puzzle. You likely use third-party software for repricing, advertising optimization, inventory planning, or accounting. These tools do not get added as secondary users via the standard email invitation.
Instead, they authorize via the Selling Partner API (SP-API).
To audit or revoke these permissions:
Go to Settings > Partner Network > Manage Your Apps (or Appstore > Manage Your Apps).
Review the list of active applications.
Identify any software you no longer use, pay for, or trust.
Click Disable to instantly revoke their access token.
Leaving old, inactive software connections open is a quiet but severe security risk. If that software provider suffers a data breach, your store data could be exposed.
The Offboarding Protocol: Revoking Access
When an employee leaves or an agency contract ends, you must systematically strip their access. Leaving "ghost" users on your account invites malicious behavior or accidental mistakes long after the relationship has terminated.
Execute this four-step checklist immediately upon termination:
[Signal: Contract Ends / Employee Departs]
│
▼
1. Revoke Seller Central Access (Settings > User Permissions > Delete User)
│
▼
2. Revoke Brand Registry Access (Brand Services > User Permissions > Remove User)
│
▼
3. Audit Partner Apps (Disable any dedicated API tokens for that specific partner)
│
▼
4. Confirm Removal (Verify the user is absent from active logs)
- 1. Revoke Seller Central Access (Settings > User Permissions > Delete User)
- 2. Revoke Brand Registry Access (Brand Services > User Permissions > Remove User)
- 3. Audit Partner Apps (Disable any dedicated API tokens for that specific partner)
- 4. Confirm Removal (Verify the user is absent from active logs)
For employees who used individual logins but had access to shared credential vaults, ensure you cycle passwords on any complementary tools (like Helium 10, Jungle Scout, or Slack) that might contain exported Seller Central data.
Maintain Control of Your Brand
Scaling your Amazon business requires delegating tasks, but delegation without control leads to operational failure. By treating your primary credentials as a highly guarded secret and using secondary user permissions with surgical precision, you protect your inventory, your cash flow, and your seller account health. Keep your permissions lean, audit them quarterly, and maintain a strict barrier between your Seller Central and Brand Registry access levels.
Frequently Asked Questions
Does granting secondary user access risk linking my account to an agency's other clients?
Can a secondary user change my bank account details?
Why can't my secondary user see the A+ Content manager?
Ready to Scale Your Amazon Brand?
Let us build a custom growth blueprint for your account. We uncover hidden profit and scale what works.
Book Your Free AuditRead Next
Realistic Amazon PPC Budgets for New Sellers by Category
Calculate realistic Amazon PPC launch budgets using category CPCs, conversion expectations, and required click volume rather than arbitrary daily spend limits.
Read ArticleAmazon Brand Registry Walkthrough: Setup & Execution
A tactical guide for Amazon sellers enrolling in Brand Registry, avoiding application rejections, and securing catalog authority.
Read ArticleHow to Calculate and Optimize Amazon PPC Contribution Margin
Stop chasing vanity ACoS targets. Learn how to calculate and optimize your SKU-level PPC contribution margin to maximize absolute cash profit.
Read Article