Payment controls and records

A procurement agent places orders for several buying organizations

Keep each purchasing context separate until the agent’s authority is mapped to the specific buyer organization, order and invoice recipient. A person placing the order is not automatically the billed party, and software access is not legal purchasing authority. Shopify’s B2B model distinguishes a company, its locations with distinct billing details and terms, and an individual customer who purchases for a business; use that separation rather than putting unrelated organizations under one customer record. Combine records only after the authority, billed party and order linkage are documented for each context.

For: Authorized staff at a research-only merchant receiving orders from one procurement agent that says it buys for several organizations.

Updated 2026-10-01

Treat the agent as a role until the buyer is named

Start every order by identifying the buying organization that will receive the goods or be billed, the procurement agent acting for it, and the document that connects them. The agent’s email domain, storefront login or familiar contact history cannot substitute for the buyer organization on the commercial record. Preserve the order reference, buyer organization name as supplied, agent name or role, requested bill-to, ship-to and any purchase order or authorization reference.

This is the buyer-side mirror of a merchant collecting payments for another business, and it is not merely an overwritten-contact problem. The risk is combining obligations across organizations because one person touched all the orders. The decision is whether this order belongs to that buyer under documented authority, not whether the agent is generally helpful or known.

Use the platform model without overstating it

Shopify’s B2B documentation says a company can have locations with distinct billing addresses, payment terms, contacts and tax identifiers, while a customer represents an individual who purchases for a business. That supports separating the organization, its locations and the individual placing the order. It does not establish that the individual has legal authority for every organization whose orders they touch.

Shopify also states that a customer can belong to one company and multiple locations of that company, with ordering-only and location-admin permissions providing different access. Do not claim that one Shopify customer natively represents multiple unrelated companies. If several buying organizations are genuinely unrelated, model and document them separately unless the business has a supported, deliberate arrangement and qualified review for any legal or tax questions.

Map authority, invoice recipient and order for each context

For each organization, record the source of authority you rely on operationally: a buyer purchase order naming the agent, an authorization letter held in a controlled file, a portal role assigned by the buyer, or a standing agreement. Keep sensitive identity and banking material out of the worksheet and note only its custodian and confirmation status. If the evidence is a forwarded email or verbal statement, mark authority as unconfirmed rather than converting it into a standing permission.

Then connect three records for the specific transaction: the order names the buying organization or an acceptable documented agent relationship; the invoice recipient matches the organization or location authorized for billing; and fulfillment details belong to that same context. A mismatch among those three is not a formatting issue. It changes who owes, who receives and whose history the transaction belongs in.

Combine only after the map survives exceptions

Do not merge order history, credit terms, tax handling or account access across organizations merely because one agent requests convenience. Where a single login is requested, confirm which company and locations the platform permits it to represent, and keep permissions limited to the documented purchasing role. Ordering-only access and administration access should not be treated as interchangeable.

Classify each relationship as documented for this buyer, documented for several locations of one buyer, or unresolved across unrelated organizations. The merchant’s sales and finance owners decide whether to accept the commercial setup; the buyer organization decides who may purchase for it; qualified review handles legal, privacy, tax and retention conclusions. If the storefront or B2B checkout makes the buyer, agent, location and bill-to hard to distinguish, describe that website concern for a scoped Prism consultation and confirm scope, responsibilities, fees and terms before work.

Agent-to-buyer authority map

Use one map per procurement agent and one line-set per buying organization. Keep identity, tax and banking evidence in controlled records. Do not combine accounts or order history until each context has documented authority, billed party and order linkage.

Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.

Agent-to-buyer authority map. The last column is for temporary notes.
Record or checkDecision purpose and findingYour finding
Buying organization identityNames the organization for this order using commercial records rather than the agent’s contact details.
Agent role and evidenceRecords the document or portal role relied on operationally and whether authority is confirmed, limited or unverified.
Order linkageConnects the specific order to that buyer and agent so one person’s activity across organizations stays separable.
Company, location and customer modelShows the organization, billing location and individual purchaser as distinct records where the platform supports them.
Invoice recipient and termsConfirms bill-to, payment terms and any tax identifier custody for this context instead of copying another organization’s terms.
Account permission scopeDistinguishes ordering-only from administration access and prevents one login from silently spanning unrelated buyers.
Combination decisionStates whether records may be combined for one company’s locations, must remain separate, or remain unresolved.
Owner and exceptionNames who decides unresolved authority or billing conflicts and the exact exception blocking a clean mapping.

These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.

Limits

  • Software contact access does not prove agency authority, and Shopify’s B2B model does not make one customer the native representative of unrelated companies.
  • Platform company, location and customer records do not establish legal entity substitution, agency law conclusions or invoice tax treatment.
  • Do not combine order history, terms or permissions across organizations without documented buyer authority and merchant approval.
  • Privacy, retention, tax and legal conclusions are jurisdiction-limited and belong with qualified review.
  • Keep payment credentials, identity documents, tax numbers, bank details and confidential buyer files out of the worksheet and public forms.

Sources

  • Shopify: Companies and customers in B2B — checked 2026-10-01. A company can have locations with distinct billing addresses, payment terms, contacts, and tax identifiers. A customer represents an individual who purchases for a business.
  • Shopify: Adding and managing B2B company contacts — checked 2026-10-01. A customer can belong to one company and multiple locations of that company. Ordering-only and location-admin permissions provide different access.

Get help with checkout

Is this happening on your own store?