Manage Roles and Permissions for Your Storefront in Business Manager (Beta)

With storefront-scoped permissions in Business Manager, specify the access for each role on one storefront, separate from other storefronts. For example, a developer for one brand manages environments for that brand’s storefront only. Each role is a named set of permissions that you assign to one or more users.

Developer Workspace is a pilot or beta service that is subject to the Beta Services Terms at Agreements - Salesforce.com or a written Unified Pilot Agreement if executed by Customer, and applicable terms in the Product Terms Directory. Use of this pilot or beta service is at the Customer’s sole discretion.

Important

Prerequisites 

  • The Business Manager Administrator role.

Set Business Manager Permissions 

Set storefront permissions for an existing or a new role in Administration > Organization > Roles > Role Name, and then click Storefronts. Select one or more storefronts, and then assign the permissions. A permission grid shows the capabilities for that role and those storefronts, and the Read, Write, and Delete state for each capability. Apply Read, Write, and Delete for one storefront, or apply the same permissions to all storefronts.

See Roles and Permissions in B2C Commerce in Salesforce Help.

The Administrator role has full access to all storefronts. Its permissions are fixed and can’t be changed from this page.

Global 

CapabilityDescriptionPermissions
StorefrontAccess this storefront in Business Manager.Read: View the storefront. Write: Create and update the storefront. Delete: Delete the storefront.

Runtime and Configuration 

CapabilityDescriptionPermissions
Storefront EnvironmentsCreate and manage the Managed Runtime environments for this storefront.Read: View environments. Write: Create, configure, set as primary, and clone environments. Delete: Delete environments.
Storefront Environment VariablesCreate and manage environment variables for the deployed storefronts.Read: View environment variables. Write: Edit and delete environment variables. Delete: Delete environment variables.

Deployment and Delivery 

CapabilityDescriptionPermissions
Storefront DeploymentsUpload, manage, and deploy Managed Runtime bundles for this storefront’s environments.Read: View deployments and download the deployed bundle. Write: Deploy bundles. Delete: Delete bundles.
Storefront URL RedirectsManage URL redirects served from Managed Runtime.Read: View redirects. Write: Create and edit redirects. Delete: Delete redirects.

Admin and API Interface 

CapabilityDescriptionPermissions
UI and API AccessSelect the user interface and the API for the storefront. This permission sets the admin interface that users in the role use (Business Manager or Runtime Admin) and the Storefront APIs (SCAPI, SCAPI and MRT, or MRT).Read: View admin user interface and API configurations. Write: Assign and change admin user interface and API configurations.

How Business Manager Permissions Differ from Runtime Admin 

In Managed Runtime, users log in to Runtime Admin through Account Manager, and Account Manager grants one of the predefined roles. See Users, Abilities, and Roles in the Composable Storefront guide. In the Developer Workspace beta, users log in to Business Manager. You assign storefront permissions through a role for that Business Manager instance.

Managed RuntimeDeveloper Workspace
Admin interfaceRuntime AdminBusiness Manager, on the B2C Commerce instance
Account Manager roleManaged Runtime User or Managed Runtime AdministratorBusiness Manager User or Business Manager Administrator
Permission modelPredefined project roles: Admin, Developer, Marketer, and ViewerCustom Business Manager roles built from storefront permissions
ScopePer projectPer one or more storefronts on a single B2C Commerce instance. Because roles are instance-specific, assign the role in every B2C Commerce instance where the user works, and then recreate or import the role into each instance.

Permission Considerations for the Developer Workspace Migration 

These considerations apply when you migrate from Runtime Admin to the Developer Workspace beta in Business Manager.

  • Each Managed Runtime project corresponds to one storefront in Business Manager. The permissions that a user has for a project become the permissions that you grant on the corresponding storefront.
  • Recreate each Managed Runtime role in Business Manager, and grant Business Manager access. The roles don’t transfer automatically.
  • During the Developer Workspace beta, grant each user a Managed Runtime project role in addition to the Business Manager permissions.

Before You Begin 

Before you can grant Business Manager and Managed Runtime permissions to users, you must have these permissions.

  • Account Manager: The User Administrator or Account Administrator role, to add Business Manager access for your users.
  • Business Manager: The Administrator role, or a role with access to the Roles & Permissions and Users modules on the B2C Commerce instance where you set up storefront roles.

After you turn on Developer Workspace for the B2C Commerce instance, the Storefronts tab appears on the Administration > Organization > Roles & Permissions page in Business Manager. If the Storefronts tab doesn’t appear, confirm that Developer Workspace is turned on for the instance.

Step 1: Give Users Business Manager Access 

Grant each Managed Runtime user access to Business Manager for the B2C Commerce instance. Use Account Manager.

  1. Log in to Account Manager at https://account.demandware.com.
  2. Select User and open the user’s account, or add a new user.
  3. In the Roles section, add the Business Manager User role. To give a user full Business Manager control of the storefront, assign Business Manager Administrator instead of Business Manager User.
  4. Click the filter icon next to the role, and then select Add Instance Filters. Select the organization and the instances (for example, development, staging, and production) where the user works.
  5. Click Add, and then save the user.

The Business Manager User role lets a user log in to the instance. It doesn’t grant storefront permissions in Business Manager. You assign the storefront role separately in Step 2: Create Storefront Roles in Business Manager.

Note

Keep the user’s Managed Runtime User or Managed Runtime Administrator role during the transition. During the beta, storefront operations require this role. Runtime Admin stays available until end of life.

Note

Step 2: Add Storefront Permissions in Business Manager 

Create a role for each set of storefront permissions, and then assign it to users. Repeat for each role. For example, use a role for each user group: admin, developer, marketer, and viewer.

  1. In Business Manager, select Administration > Organization > Roles & Permissions.
  2. Click New, enter a name for the role (for example, Storefront Developer), and then click Apply.
  3. Set Business Manager module permissions. Click Business Manager Module, and then set the Storefronts module to Read or Write so that a user in that role opens the Storefronts section. Use Write for roles that edit the storefront, and select Read for view-only roles.
  4. Set storefront permissions. Click Storefronts, and then click Select Storefront.
    • Select the storefronts that this role applies to: one storefront, a subset of storefronts, or all storefronts.
    • For each permission, select the level for the role: Read for view-only, Write to manage, or Delete for full control, including deletion.
  5. Click Update.
  6. On the Users tab, select the users to assign to this role, and then click Assign.

The Storefronts module permission shows Sites > Storefronts in the Business Manager navigation. Grant this permission to every Developer Workspace user. The Sites menu group appears after the user has the Storefronts permission.

Note

Recommended Business Manager Storefront Roles 

Check out these role recommendations to create roles in Business Manager that map the Managed Runtime roles.

PermissionStorefront AdminStorefront DeveloperStorefront MarketerStorefront Viewer
StorefrontDeleteReadReadRead
Storefront EnvironmentsDeleteWriteReadRead
Storefront Environment VariablesDeleteWriteNo accessNo access
Storefront DeploymentsDeleteWriteReadRead
Storefront URL RedirectsDeleteWriteWriteRead
UI and API AccessWriteNo accessNo accessNo access

See Also