Text/Call →

Table of Contents

Who Can Still Touch Your Amazon Account? The Access Audit Most Brands Have Never Run

When we take over an Amazon account, the user permissions page is the first thing we open — before the ad console, before the catalogue, before the P&L. Not because we’re looking for a security problem. Because it’s the fastest read available on how the business has actually been run.

Two minutes on that page tells you whether decisions have been owned or delegated by accident, how many hands have been in the account, whether anybody has ever left cleanly, and — more often than brands expect — whether the person with the highest level of access still works there.

The answers are consistently worse than the founder believes. Not because anybody was careless. Because nobody owns the removal side of the process. Adding a user is a task somebody asks for. Removing one is a task nobody asks for.

Amazon already fixed the part that got the press

Worth being clear about what has and hasn’t changed, because a lot of brands think this problem was solved for them.

Starting in April 2025, third-party service providers had to be registered and vetted through Amazon’s Solution Provider Portal to keep accessing Seller Central, with secondary-user access for external providers phased out through August 2025. The old model — where you created a Seller Central login for your agency and handed it over, frequently with something close to blanket admin — was replaced with a token-based authorization model built around least privilege.

That was a genuine improvement and it closed a real hole. It also closed exactly one hole.

SPP governs how outside service providers connect. It does not govern:

  • The secondary user you created for an operations hire who left in 2024
  • The VA you onboarded through a contractor platform and stopped working with
  • The freelance designer who needed catalogue access for one project
  • The authorized partner designation for the agency you fired, which does not revoke itself when the retainer ends
  • Third-party app and API authorizations you granted at some point and have never reviewed
  • Advertising console access, which is a separate permission surface from Seller Central
  • Brand Registry roles, which are a third separate surface
  • Who controls the two-factor phone number and the primary account email

Seven of those eight are entirely on you, and the eighth — the ex-agency’s authorization — is on you as well, because Amazon is not going to guess that the relationship ended.

The mistake underneath all of it

Access accumulates the way inventory accumulates in a garage. Every individual decision was correct at the time and nothing ever comes back out.

There’s a second, quieter version that costs more. On a lot of $200K-a-month brands, the highest level of account access is held by a person rather than by the business. The account’s primary email is a founder’s personal address, or worse, an operations manager’s work address. The 2FA is on somebody’s phone. Brand Registry lists a rights owner who was the marketing lead three roles ago.

That’s fine right up until the day it isn’t, and the day it isn’t is never a convenient day. We have watched a brand lose two weeks getting back into a Brand Registry account because the only listed rights owner had left on bad terms and was not inclined to be helpful. That’s two weeks with no A+ edits, no Sponsored Brands changes, and no ability to file an infringement report, during a period when a competitor was actively copying their listing.

What each surface actually controls

Brands conflate these three constantly, including on calls with agencies present. They are not the same thing and they do not overlap cleanly.

Seller Central user permissions. Catalogue, inventory, orders, pricing, reports, cases, settings. This is where write access to your listings lives. A user with full inventory permissions can change a price, edit a title, or push a flat file across your catalogue.

Advertising console access. Separate. Someone can have zero Seller Central access and full authority to spend your ad budget, or the reverse. During Q4, when spend runs at multiples of baseline, this is the surface where a stale login is most expensive.

Brand Registry roles. Separate again, and the one brands understand least. We’ve covered that surface on its own — who actually controls your Brand Registry — so we won’t re-litigate it here beyond the one line that matters for this audit: it is a third list, it does not appear on either of the other two, and most brands have never opened it.

If your answer to “who has access” is one list, you have one third of an answer.

The seven-point audit

This takes one person about ninety minutes across all three surfaces. It is not technical work. It requires no tooling.

1. Pull the Seller Central user list and read every name out loud. Names, not roles. Say them. The ones that produce a pause — “who is that” or “does he still work here” — are the finding. Remove anyone who is not currently doing work that requires access.

2. Check permission level against actual job. Least privilege is not a security slogan, it’s a blast-radius decision. A reporting analyst does not need pricing permissions. A customer service contractor does not need catalogue edit rights. The question isn’t whether you trust them, it’s how large a mistake they’re able to make on a Friday afternoon.

3. Review your Solution Provider Portal authorizations. Every current provider should be there. Every former provider should not. If you’ve changed agencies, tools or freelancers in the last eighteen months, assume there’s at least one stale authorization and go look rather than assume.

4. Audit third-party app and API authorizations separately. Repricers, inventory tools, review software, analytics dashboards, listing tools. Every one is an integration with some level of read or write access, and most brands have authorized more of them than they currently pay for. Anything you no longer use gets revoked today.

5. Confirm the business owns the account, not an individual. Primary email should be a monitored business address that survives any single person leaving. Two-factor should sit on a device or method the business controls. This is a thirty-minute fix that prevents a two-week outage.

6. Open Brand Registry as its own list. Confirm the rights owner is current, confirm you have more than one administrator, and confirm the trademark record matches the entity operating the account. Thirty seconds of checking, and it is the surface with the longest recovery time when it’s wrong.

7. Check the advertising console and DSP seat separately. Names, spend authority, and whether the billing owner is your entity rather than an agency’s. Consolidation and platform migrations are the cheapest possible moment to find a stale login. October is the worst.

Do this in August, not October

Three reasons the timing is specific.

Access problems only surface under pressure. Nobody discovers they can’t file a Brand Registry case in a quiet week in August. They discover it during a takedown on Cyber Monday.

Q4 is when write access is most dangerous. More people touching the account, more urgency, more improvised decisions, higher spend, higher stakes on every catalogue change. A stale login that was harmless in July is a different exposure in November.

Removing access is disruptive if you get it wrong. Cutting off a tool you actually need in mid-peak is a self-inflicted incident. Doing this in August means any mistake surfaces in a week where fixing it costs an afternoon.

There’s also a fourth reason, which is that this is one of the very few items on a Q4 prep list that is entirely within your control, costs nothing, and has no dependency on Amazon, a supplier, or a lead time. Almost everything else on that list has a queue in front of it.

What good looks like afterward

You should end with a single document, owned by a named person, listing every human and every piece of software with access to any of the three surfaces, what level they hold, and why. Reviewed quarterly.

We also recommend one behavioural change that costs nothing: secure access before somebody’s last day, not after. The standard sequence is that a person leaves, and access removal joins a list of offboarding tasks that gets half-completed. Flip it. Whoever owns the access document runs removal as part of the same conversation as the laptop and the email account.

And if you work with an agency, this is a fair thing to ask them: can they produce, on request, a list of every one of their people who holds access to your account, and at what level? A shop that runs this properly answers in a few minutes. A shop that answers with a paragraph about their security commitment has told you something as well.

FAQ

Does SPP mean I can stop worrying about agency access?
It means outside providers now connect through a vetted, token-based, least-privilege model instead of a shared secondary login, which is a real improvement. It does not revoke authorizations when relationships end, and it doesn’t touch employees, contractors, apps or Brand Registry. Confirm what’s currently authorized in your own account rather than assuming.

How often should we run this?
Quarterly for the full pass, and immediately whenever anybody leaves or a vendor relationship ends. The quarterly rhythm matters less than having a named owner — an unowned quarterly task becomes an annual task and then an anecdote.

What’s the single most common finding?
A former employee or former contractor still holding active permissions, usually at a higher level than their job required. Second most common is an ad console login belonging to an agency the brand stopped working with.

Is removing a user’s access disruptive?
Removing someone who genuinely needs it, yes. That’s why you do the audit before peak rather than during it — and why you check what a tool is actually doing before you revoke its authorization.

We’re a small team. Is this overkill?
It’s the opposite. On a small team, business-critical access frequently depends on one individual, which is the exposure this audit exists to find. Larger organisations usually have a policy that catches some of it by accident. A five-person brand has whatever the founder set up in 2022.

If you’re looking for a team that manages every lever — creative, advertising, and operations — Velocity Sellers works with brands doing $100K+/month on Amazon. Contact us for a free account audit.

Scroll to Top