Website representations

A buyer's former employee still has access to its company account

Confirm the requester's authority before touching the account. Verify that the person asking is authorized by the buyer organization to manage its users, then map exactly what the departed employee can reach: order history, company and location association, saved payment methods and any open requests. Shopify's B2B documentation shows that company association and location permissions can change without deleting the customer profile, so removing access and deleting records are different actions. Follow the installed system's actual capabilities, preserve the order records the business must retain, and do not transfer the former employee's permissions to whoever happens to ask.

For: An authorized staff member of a research-only merchant asked by an organizational buyer to remove a departed employee from the buyer's company account.

Updated 2026-10-01

Verify who is allowed to ask

An organizational contact is not automatically authorized to manage everyone in that organization's account. Before acting, establish who at the buyer company holds that authority: a named account administrator in your records, or a written confirmation through a channel you can trace back to the organization. A request from a work email address is a lead, not proof, and the higher the privilege being moved around, the more the verification matters.

Record the authority decision with its evidence and date. If the requester cannot be confirmed, the access stays as it is while you route the request to the buyer's known authorized contact. Acting on an unverified request can hand an outsider control of an organizational account, which is precisely the failure this process exists to prevent.

Map what the departed employee can still reach

Identify the exact customer profile involved; do not guess from an email match, because two people at one company can share a name pattern. Then inventory the access paths attached to that profile: membership in the company account and its locations, visibility of order history, reach to any saved company payment method, and open items such as draft orders, quotes, returns or support threads.

Each path gets its own line because each has a different owner and consequence. Order visibility is a privacy and confidentiality question. Saved payment methods belong to the buyer organization's payment arrangements, and the decision about them belongs to its authorized administrator, not to the departing person's manager by default. Open requests need a new owner before the old one loses access, or they silently stall.

Separate access removal from record deletion

Removing someone's ability to act for a company and erasing their history are different operations, and conflating them causes two opposite failures: cutting access while leaving obligations dangling, or deleting records the merchant is required to keep. Shopify's B2B company documentation shows the distinction concretely: a customer's association with a company and their location permissions can be changed without deleting the underlying customer profile and its order history.

That documentation applies to Shopify B2B; a different account system needs its own confirmed capabilities before you assume the same separation exists. Past orders remain business records for both parties regardless of who can see them, and any retention or erasure question beyond routine access management goes to qualified review rather than being settled by a delete button.

Make the change through supported controls

Execute only the actions the installed system documents: removing the user from the company, revoking their location permissions, or deleting the profile where deletion is genuinely intended and permitted. Record what was changed, by whom and when. Never hand the former employee's role to the requester as a side effect; a replacement user gets their own grant through the buyer's authorized administrator, scoped to what that person actually needs.

Check for access paths outside the account system before closing the task: a saved login on a shared device is the buyer's problem to manage, but a shared password your support team ever issued is yours to retire, and any saved-payment consent tied to the individual rather than the company needs review rather than silent reuse.

Confirm the result and close the outstanding items

After the change, reopen the account and verify what the former profile can no longer reach, then confirm to the buyer's authorized contact what was done, in writing, without disclosing other customers' data. Reassign the open drafts, returns and threads you mapped earlier, and record who accepted each one.

Leave anything unresolved explicit: an unconfirmed requester, an unclear payment-method owner, or a system whose capabilities you could not verify. If the access question is tangled into how the storefront presents organizational accounts, a scoped Prism website-review consultation can consider those public pages with the URLs and a non-sensitive summary; confirm scope, responsibilities, fees and terms before work, and keep customer records and credentials out of the inquiry.

Buyer-access removal worksheet

Complete one worksheet per departed user, in your internal system only. No change is made until authority and the access map are recorded. Completing the worksheet does not erase records the business must retain or settle eligibility questions.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Buyer-access removal worksheet. The last column is for temporary notes.
Access checkWhat must be verified before the changeYour finding
Requester's authorityTraceable evidence that the buyer organization authorizes this person to manage its account users.
Named user identifiedThe exact customer profile and login of the departed employee, not a guess from an email match.
Company and location membershipWhich company and locations the user is attached to, and what each permission grants.
Order visibilityWhich past orders the user can see, and which records the business retains regardless of access.
Saved payment accessWhether company payment methods are reachable by the user, and the authorized administrator who owns that decision.
Outstanding requestsOpen drafts, quotes, returns or support items involving the user, each with a newly assigned owner.
Removal actionThe supported control used, such as a permission change or profile removal, and who performed it.
Post-change confirmationThe date the account was rechecked and the buyer's authorized contact notified of the completed change.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Authority to manage a buyer's account comes from that organization; an email domain, job title or urgency alone does not establish it.
  • Removing access must not erase order records the merchant is required to keep; retention and erasure questions go to qualified review.
  • Shopify's documented company features apply to Shopify B2B; other account systems need their own capabilities confirmed before acting.

Sources

  • Shopify: Company customers — checked 2026-10-01. Company association and location permissions can be changed without deleting the customer profile; actual plan, permissions, retained history and saved payment access still need verification.

Request a website review

Want a second look at your own storefront pages?