Allow Shop Managers to edit selected user roles

Use this guide to let Shop Managers edit selected WordPress user roles in WooCommerce. It explains the role allowlist introduced by WooCommerce and how to check that the change grants only the access your store needs.

Note:

This is a Developer level doc. If you are unfamiliar working with code and resolving potential conflicts, we recommend you work with a Woo Agency Partner for larger projects, or find a WooCommerce developer on Codeable for smaller customizations. We are unable to provide support for customizations under our Support Policy.

Before you start

↑ Back to top
  • Use WooCommerce 11.2.0 or a release whose source confirms the same filter behavior.
  • Have a staging site, PHP familiarity, and a reviewed method for managing site-specific snippets.
  • Know the target role slug and review the capabilities assigned to that role before allowing Shop Managers to edit its users.

Before you change the allowlist

↑ Back to top

Test permission changes on a staging site first. A role determines which actions an account can perform across WordPress and its plugins. Add only roles whose users Shop Managers need to manage, and review every capability those roles already have.

How the role check works

↑ Back to top

WooCommerce 11.2.0 allows Shop Managers to edit users whose only role is Customer by default. The woocommerce_shop_manager_editable_roles filter changes that role allowlist. For another user, every role assigned to the account must appear in the allowlist; a mixed-role account is blocked if even one assigned role is missing.

The filter controls which roles are eligible for this check. It does not grant the underlying WordPress user-management capabilities. WooCommerce still checks the current user’s permission to perform the requested action. The separate WooCommerce REST API permission check uses the same all-roles rule for edit and delete requests; read requests use the user-list permission instead.

WooCommerce adds list_users to the Shop Manager role, which allows user details to be listed. It also assigns WooCommerce capabilities such as manage_woocommerce and create_customers. These are separate permissions: for example, manage_woocommerce does not by itself make a user role editable.

Allow Shop Managers to edit an additional role

↑ Back to top

This example adds the role with the slug subscriber to the default Customer allowlist. Use this only if that role is registered on your site, and confirm that its capabilities are appropriate. Keep the existing Customer entry unless you intend to remove it.

add_filter(
	'woocommerce_shop_manager_editable_roles',
	function ( $roles ) {
		$roles[] = 'subscriber';
		return array_unique( $roles );
	}
);

Install the snippet with a site-specific code-management method that runs in production only after it has passed review on staging. Do not add a role merely to make a particular account editable: first confirm that every capability granted by that role is appropriate for Shop Managers to manage.

Verify the permission change

↑ Back to top
  1. On staging, confirm the snippet loads without a PHP error and that the role exists with the expected slug.
  2. Sign in as a Shop Manager and check that a Customer-only account and a Subscriber-only account can be edited.
  3. Check a mixed Customer and Subscriber account. It should be editable because both assigned roles are in the allowlist.
  4. Check an account with a role outside the allowlist, such as Administrator. The role filter must not make that account editable.
  5. Confirm the Shop Manager can still view user details, and test any REST API integration separately. In WooCommerce 11.2.0, REST read permission and edit/delete permission follow different checks.
  6. Repeat the tests as an Administrator to confirm the intended recovery path, then remove the test users and role assignments.

Remove or change the customization

↑ Back to top

Remove the snippet or remove the added role from its returned list to restore the default Customer-only allowlist. After changing it, repeat the mixed-role and restricted-role checks. The code does not change role capabilities themselves.

Questions and support

↑ Back to top

Do you still have questions and need assistance? 

This documentation is about the free, core WooCommerce plugin, for which support is provided in our community forums on WordPress.org. By searching this forum, you’ll often find that your question has been asked and answered before.

If you haven’t created a WordPress.org account to use the forums, here’s how.

  • If you’re looking to extend the core functionality shown here, we recommend reviewing available extensions in the WooCommerce Marketplace.
  • Need ongoing advanced support or a customization built for WooCommerce? Hire a Woo Agency Partner.
  • Are you a developer building your own WooCommerce integration or extension? Check our Developer Resources.

If you weren’t able to find the information you need, please use the feedback thumbs below to let us know.

Use of your personal data
We and our partners process your personal data (such as browsing data, IP Addresses, cookie information, and other unique identifiers) based on your consent and/or our legitimate interest to optimize our website, marketing activities, and your user experience.