Help · Settings

Your team

Settings → Team is where the people who work in your store live. This chapter covers the two ways in, the four roles, and how people join and leave.

The people who work in the app are your team members. Settings → Team is where they live: who is on the team and what each of them may do, the invitations you have sent, anybody who has asked to join, and anybody whose access has ended.

There are two doors into the app, and they lead to the same screens, the same data and the same store. Inside your Shopify admin you need no password; at app.carpemessaging.com you sign in with your email address and a password.

From your Shopify admin. You open the app there and it runs inside the admin. Shopify has already signed you in, so this door asks for no password and there is nothing to remember.

From app.carpemessaging.com. There is a sign-in page at that address. You sign in with your email address and the password you chose when you accepted your invitation. This is the door for somebody who works with you and has no Shopify login of their own — an agency, a designer, a writer who never opens your admin.

The role is the same through either door. Which door somebody uses is not a setting and not a kind of team member; it is only how they reached the screen.

Somebody who already works in another store keeps their login. Invite the address they already use. When they accept, they are told to sign in with the password they already have, and your store is added to their list of stores. We never tell you which other stores an address works in — that is theirs.

Each team member holds one of four roles, and each role includes everything the one below it can do. A viewer reads, a marketer builds and sends, a manager also runs the settings and the team, and the owner also has billing and deleting data.

Beside each role, the app says:

Even four specific sentences leave a few things unsaid, and these are the places a merchant is most likely to be surprised. A marketer's own back-in-stock powers are below, and are not in that sentence because the app's own is shorter than the list of everything it covers.

A marketer may notify a back-in-stock queue, and may hold one. Both are bounded decisions about who a back-in-stock email reaches, so both sit with sending. Holding only ever stops mail, and stopping mail should never be harder than starting it.

The store-wide hold is a setting, and that one is a manager's. Hold every back-in-stock email for me is a standing rule about every variant that comes back in stock, which is the same kind of authority as the wave settings beside it — so it sits with your store's settings, alongside them. So does Follow the store setting in the row menu, which hands a variant back to that rule and can start its back-in-stock emails going out again on their own.

A marketer may send, pause, enable an automation, and record what somebody told you about their consent. They go together on purpose: the person who decides what goes out is the person who decides when it starts, who it should stop going to, and who has asked to be left alone. A resume can re-open mail to thousands of people at once, and enabling an automation leaves it running unattended, so both are worth a second look before you press them — but neither is taken away from the people doing the work.

Consent is the one record here that is somebody else's answer, not your decision about them, so it is worth saying what recording it by hand does and does not do. It is on the profile, in the menu at the end of each consent row. Marking a person unsubscribed stops their marketing mail and tells your store. Marking them subscribed asks you to confirm, in one sentence, that they gave you permission — and that sentence is kept with the change. Nothing at any role puts back somebody who has bounced or reported you as spam: that state is permanent, and no role in this table can undo it. Nothing at any role signs somebody up for text messages either — only the person can do that.

What a manager adds is the store itself — its settings, its connection to Shopify, and its team — rather than anything about one person.

And nobody at Carpe Messaging can do any of it for you. We can shape what would be sent while we are looking at your store to help — we cannot send it, enable an automation or a message, pause or resume anybody, change anybody's consent, or touch your discount settings. Those presses are yours, whatever role we are looking through.

Only an owner can remove data. Removing a metric you brought here — one your own integration posts, or one that arrived on an import of another tool's history — deletes history and changes what your segments catch, so it takes the one role that also holds billing. Deleting profiles, one at a time or a segment or a list at a time, is the owner's alone for the same reason, and nobody at Carpe Messaging can do it for you.

Only an owner can send your text-message registration. It buys a number your store is billed for and signs a declaration in your business's legal name, with your EIN on it. A manager still enables and disables text messages and sets their hours, name and forwarding number; the registration itself, and the details on it, are the owner's.

Only an owner can confirm a person by hand. On a profile that reads Not confirmed yet, Confirm this person says you know somebody is a real person at that address, and it moves them into your segments and your audiences. One person answers for it, by name, with a typed reason — so it is the owner's alone, and nobody at Carpe Messaging can do it for you. It does not change anybody's consent.

Only an owner can hand out the owner role. A manager may invite and manage everybody else. The invite card tells them so, and so does the row menu:

It is said a third time above No longer on your team, because putting a former owner back is the same grant made a different way. That section is Putting somebody back, further down this page.

A role is checked on every action, not by hiding controls — someone who may not do something cannot do it by finding another way in. Where an action is not available to you, the app usually just does not draw it, which is why a marketer sees no pause option in a segment's row menu rather than a grayed-out one.

A marketer and a viewer see who is on the team and nothing else. They see who is here and at what role. There is no invite card, no row menus, nobody asking to join, no invitations waiting and nobody who has left — those sections are not drawn for them at all, and the app does not tell them what is in a section they may not act on.

One thing worth being plain about while you read the table: sending is your store's own act, and only your store's. A marketer, a manager or your owner writes a campaign and schedules it themselves, and that is the only way an email goes out. Nobody at Carpe Messaging can make your store send. We can help you shape what would go out — that is where it stops, and it is why send is a permission the table above hands to people who work in your store. A campaign is built under Campaigns in three steps and sent or scheduled from the last one, Schedule; the roles in the table above are what governs who may do it.

Members lists everybody on the team: their name and address, their role, when they joined, and when they were last here. The person Shopify holds as your store's account owner is badged Account owner, and your own row is badged You.

If you are working alone, the table says so rather than sitting empty:

Last seen is a best estimate, and it is per store. It counts visits at both doors — signing in at the app, and opening it from your Shopify admin — so somebody who only ever works inside the admin is counted here too. Time somebody spends in another store they work in is not counted and is none of this store's business. The app has not always kept this record, and nothing from before it started counts, so somebody who has not been here since then, and somebody who has never signed in at all, both read the same:

That is deliberate. A date the app cannot stand behind would be worse than the honest sentence.

Type their full name and email address, pick the role, and Send invitation. The name is required — it is how the invitation greets them and the name their login is created under. The person gets an email inviting them to join your store, with one link in it, and the email says what the link is worth: it works once and it expires in seven days.

The link opens a page that already knows who they are. It is headed with your store's name and says who invited them and at what role — "Rosa Whitlock invited you to Fennimore & Vale as an owner," for example.

Their name and email address are shown on the page, not asked for: they are the ones you typed, and nobody can change them there. They choose a password of at least twelve characters, and they are in. The password box works with the password manager in their browser or phone, which can suggest a strong password and save it against that address, and the eye at the end of the box shows what they typed. (An invitation sent before names were asked for still asks them for their name.)

If the link has already been used, has expired or has been revoked, they get one sentence for all three:

They are not told which of the three it was, on purpose. Telling them apart would turn that page into a way of asking which links were ever real.

Somebody who already has a login gets a different email. One login works in every store that invites it, so an invitation never sets a new password for an account that already exists. Their email asks them to accept the invitation and then sign in with the password they already use.

That link opens the same kind of page — your store, who invited them, and their address — with no boxes at all, just Accept. Once they accept, they sign in with the password they already have, and your store is one of the stores they can open. Somebody new to Carpe Messaging still gets the email above and sets their password from it.

A login with no password yet — somebody who has only ever opened Carpe Messaging from their Shopify admin — gets the ordinary invitation email, since there is no password for them to sign in with. When they accept, their password is not saved from that page; instead they see:

If the email could not be sent, you are told, and there is something to do about it:

The link is never shown to you to copy, and it cannot be shown again — that is what makes an invitation impossible to intercept. So the answer to an email that did not arrive is always to revoke that invitation and invite the same address again.

Invitations waiting lists everything sent and not yet accepted — the name you typed, the address, the day you sent it and the day it expires. A name cannot be edited once it is sent; if it is wrong, revoke the invitation and invite them again with the right one. Revoking one:

Every other member's row carries a menu with Change role and Remove from team. Both say what they do before they do it. A role change:

A removal:

Their work is not theirs to take with them: the segments, templates and forms they made stay in your store.

Nobody changes their own role, and nobody removes themselves. Your own row carries no menu, so a manager who wants to leave asks somebody else:

The account owner is Shopify's to name. That row carries no menu either:

A store needs at least one owner. When there is only one, the menu still draws Change role and Remove and refuses both, with the reason beside them:

Somebody on your Shopify staff who opens the app and is not on your team is not let in. They can press Ask for access, which usually puts a row on your Team screen, and an owner or a manager decides whether to invite them.

Shopify's staff list is a list of who works in your store, not a list of who should see your customers, so nobody joins your team by opening the app. What they get instead is Ask for access, and pressing it usually puts a row on your Team screen rather than letting them in. Usually, because some asks never become a row: an address Shopify has not confirmed, a second press inside the hour, and anybody who already holds a seat here. Nobody is emailed or notified either way — an ask that does become a row waits there until an owner or a manager looks, and what the person asking is told promises them no row and no answer:

The ask arrives at the top of Settings → Team, where an owner or a manager sees it under Asking to join:

Each row carries who asked and when, a role — set to Viewer until you change it — and two buttons. Invite sends them an ordinary invitation at that role, so a granted ask comes in through the same door as one you started yourself, and the same rules apply to it. Dismiss clears the row:

An ask never reaches you from an address Shopify has not confirmed, because that is not an ask you could grant.

Everybody whose access has ended is listed under No longer on your team, at the foot of Settings → Team. Putting somebody back returns them at the role they had, with the same login.

It is where they come back from:

Putting somebody back:

A manager may put back anybody except a former owner — that one takes an owner, because it hands out the owner role — and the note above the rows says so:

This is also the list a reinstalled store comes back to. Uninstalling ends everybody's access, and reinstalling brings back the account owner alone — everybody else is waiting here, to be let back in one at a time.