The Amazon Seller Central authorization change that started on August 10 is being written up as a workflow update. It is not. It is a permission reset, it has a September 3 deadline attached to it on the provider side, the reauthorization wave lands on brands in September, and the stated consequence of doing nothing is that existing access to your account expires.
That is roughly three weeks before your highest-revenue ten weeks of the year, and after managing hundreds of brands through takeovers we can tell you exactly how it will be handled at most companies: in a hurry, by whoever is free, with every box ticked so nothing breaks during peak. That is the expensive answer, and it is the default one.
Before anything else: confirm the specifics against your own Seller Central notifications and your providers’ Solution Provider Portal messages rather than any blog, including this one. Amazon stages these things, dates move by account, and the role lists differ by service category.
What changed and when
As of August 10, 2026, the old invite-based delegation process for Solution Providers was replaced. Two paths now exist. For services listed on the Solution Provider Network, a seller uses an “Authorize Now” action on the provider’s SPN listing, with the provider confirming on the Solution Provider Portal. For services not listed on SPN, the provider shares a unique authorization link generated from the SPP homepage, and the seller uses it to grant access.
The date that carries a consequence is September 3, 2026. That is the deadline for providers to verify and update their role coverage — the specific set of Seller Central roles their service is approved to hold. Roles a provider uses today that are not part of their approved set will not be included when you reauthorize.
Amazon’s own framing also notes that some Seller Central roles are designated for direct employees of the seller and are not available to service providers at all.
And the line brands should read twice: sellers who do not act to reauthorize by Amazon’s communicated deadline will see existing access to their Seller Central account expire.
Why this is not the 2025 migration again
Brands who lived through the April–August 2025 Solution Provider Portal migration will pattern-match this to that, and it is not the same event.
The 2025 change killed shared agency logins. It moved outside providers from “here is a secondary user account with near-blanket admin” to a token-based, least-privilege authorization model. That was a genuine improvement and it closed exactly one hole.
This change does something different. It moves the definition of what a provider is allowed to hold from the seller to Amazon. You are no longer assembling a permission set from the full menu of Seller Central roles based on what you feel comfortable granting. You are picking from a pre-approved set attached to that provider’s service category. The platform decides the ceiling; you decide where you sit under it.
That is a structural trend, not a one-off. It is the same project as vendor verification, INFORM Act enforcement, and Brand Registry reconciliation: Amazon narrowing the gap between who is contractually responsible for an account and who is actually operating inside it.
The three access surfaces, and which one this touches
We open the user permissions page first in every takeover audit, before the ad console and before the catalog, because two minutes there tells you how a business has been run. What that page never tells you is the whole story, because there are three separate surfaces and brands conflate them constantly.
Seller Central roles. Catalog, inventory, orders, pricing, reports, cases, settings. This is where write access to your listings lives, and this is the surface the authorization change governs.
The advertising console. Separate. Someone can hold zero Seller Central permissions and full authority to spend your Q4 ad budget, or the reverse. This reset does not touch it.
Brand Registry roles. Separate again, with the longest recovery time of the three when it is wrong.
If your answer to “who has access to our account” is one list, you have one third of an answer. The reset is going to force you to rebuild the first list. It will not prompt you about the other two, and that is a gap worth closing in the same sitting.
The trap: a reset is where over-grants become permanent
Here is the part nobody is writing about, and it is the reason we are treating this as a strategy piece rather than an admin one.
A forced reauthorization is the only moment in the life of an Amazon account when the permission structure gets rebuilt from zero. That is an enormous opportunity. It is also, handled badly, how an account ends up with a permission set that nobody revisits for three years.
Under time pressure, with peak approaching and a queue of providers waiting on access, the path of least resistance is to grant everything on offer to everyone who asks so that nothing stops working in November. It takes four minutes and it feels responsible.
What you have actually done is convert a one-time audit — the single best opportunity you will get to right-size access — into a permanent over-grant, and the next natural review point is the next forced migration, which may be years away. Least privilege is not a security slogan, it is a blast-radius decision. The question is never whether you trust a provider. It is how large a mistake they are able to make on a Friday afternoon in December.
Decide the standard before the requests arrive, not while they are queuing.
Role coverage runs on your provider’s clock, not yours
This is the second trap and it is the one that produces a mid-peak surprise.
The September 3 deadline is a provider obligation. Your agency, your listing tool, your repricer, your creative shop each has to verify and update its own role coverage. If a provider does not, they lose roles they currently use — and you will not be notified about a role you never knew they held.
The way that surfaces is unpleasant. Something a provider does routinely stops working. Nobody connects it to a coverage deadline that passed weeks earlier. A case gets opened, a round trip gets burned, and it happens during the window where a day matters more than it does in March.
The fix is one email, sent this week, to every provider with access:
> Have you verified and updated your role coverage ahead of the September 3 deadline? Which Seller Central roles will you be requesting from us at reauthorization, and are any roles you currently use falling outside your approved set?
A provider who has been paying attention answers with a list of roles and a date. A provider who replies with a paragraph about their commitment to security and compliance has not looked, and that reply is itself the answer.
There is a third possibility worth preparing for. Some brands are going to discover that their agency has been operating under a role that is designated for direct employees and will not survive the reset. If that is you, the work that role enabled needs a named internal owner before September, not a workaround in October.
What to do in the next ten days
Pull the current Seller Central user and provider list and read every name out loud. Names, not roles. The ones that produce a pause are the finding. On most accounts we audit, at least one is a former contractor, a departed employee, or an agency that stopped working there.
Write down the role standard per provider category before you touch anything. What does an advertising provider need? A creative provider? A logistics tool? Deciding this on a quiet Tuesday in August is how you avoid deciding it on day thirteen of the reauthorization window while three people are waiting on you.
Email every provider about role coverage. Above. Ten minutes, and it converts a September surprise into an August fact.
Name one owner for the reauthorization. Not a team, a person, with a backup, because one of them will be traveling in September. This is exactly the kind of task that becomes nobody’s job because it arrives as a notification rather than a request.
Audit the other two surfaces while you are in here. Advertising console access — including whether the billing owner is your legal entity rather than an agency’s. Brand Registry roles and the listed rights owner. Neither is covered by this reset, both are worth thirty minutes, and the Registry one has the longest recovery time if it is wrong.
Confirm the business owns the account, not an individual. Primary email on a monitored business address, two-factor on something the company controls. On a lot of $200K-a-month brands the highest level of access is held by a person rather than by the business, which is fine right up until the day it is not, and that day is never convenient.
Do it in August, not October. Access problems only ever surface under pressure. Nobody discovers they cannot file a Registry case in a quiet week. They discover it during a takedown on Cyber Monday. This is also one of very few Q4 preparation items entirely inside your control, with no queue, no lead time, and no dependency on a supplier or on Amazon.
FAQ
Will my providers lose access automatically on September 3?
September 3 is the provider-side deadline to verify and update role coverage. The seller-side reauthorization is a separate step with its own communicated deadline. What is clear is that roles outside a provider’s approved set will not carry over, and access that is never reauthorized expires. Read your own notifications for your dates rather than planning off a general timeline.
Does this affect API integrations and SP-API apps too?
Third-party application authorizations are their own list and deserve a separate pass. Most brands we audit have authorized more tools than they currently pay for. Whether a given integration is touched by this specific change depends on how it connects, so check each one rather than assuming the reset cleans up after you.
Can I just grant everything so nothing breaks during peak?
You can, and it is the most common mistake we expect to see this September. You would be spending your only forced audit in years to buy four minutes of convenience. Grant what each provider needs to do the job you are paying them for, and treat anything beyond that as a decision requiring a reason.
Our agency says they are handling it. Is that enough?
Your agency can update their own role coverage. They cannot reauthorize on your behalf, and they cannot audit the users, tools, and former employees who have nothing to do with them. The provider half is theirs. The account half is yours.
We have never done an access audit. Where do we start?
Start with the list you can produce in ten minutes: Seller Central users, provider authorizations, advertising console logins, Brand Registry roles. The reset is going to make you rebuild one of those four anyway. Doing all four in the same sitting costs an afternoon and it is the cheapest Q4 risk reduction available to you right now.
—
If you are looking for a team that manages every lever — creative, advertising, and operations — Velocity Sellers works with brands doing $100K+/month on Amazon. Contact us for a free account audit.