User roles
Give team members controlled access to your Stripe account.
Note
If you assign a user multiple roles, they’re assigned all the permissions of each individual role. Be cautious of conflicts and unintended authority.
Admin roles
Administrator
This role is for anyone who needs similar access as the account owner—they can see and manage almost everything.
They can't delete the default bank account, or change the account owner.
SSO Role ID:
admin
View details
IAM Administrator
This role is for people who need to invite team members and assign roles. They can also remove any user, including Administrators and Super Administrators.
They can't do anything beyond access management. They also can't assign a user to the Administrator or Super Administrator role.
SSO Role ID:
iam_admin
View details
Super Administrator
This role is assigned to the creator of a business account and should only be assigned to users who are allowed to perform all privileged actions. Only a Super Administrator can assign the Super Administrator role to other team members.
Change the account owner (only the owner can transfer ownership).
SSO Role ID:
super_admin
View details
Important
These roles can invite users to your account. If an attacker compromises a user with one, they can invite additional users under their control.
Account owner
An Account Owner is a special type of Administrator that can perform all actions, including closing the account. There can only be one Owner for an account. To change the Account Owner, please refer to this guide .
Connect roles
These roles are only available if you use Connect
Connect Onboarding Analyst
This role is for people who need to create connected accounts and edit their identity information.
They can't do anything on the platform account except view and edit connected accounts.
SSO Role ID:
connect_onboarding_analyst
View details
Transfer Analyst
Your account must require two-step authentication in order to allow non-Administrators with this role to transfer funds.
This role is for people who need to transfer funds to connected accounts and view the platform’s balance and historical payouts. They can also view disputes and charges.
They can't resolve disputes, refund or create payments, pay out money to external bank accounts, add or edit bank accounts, or create new connected accounts.
SSO Role ID:
transfer_analyst
View details
Connect Risk Analyst
This role is for people who need to manage risk on connected accounts and take actions such as pausing payments and payouts.
They can't do anything on the platform account except view and edit connected accounts and their capabilities.
SSO Role ID:
connect_risk_analyst
View details
Developer roles
Developer
This role is for developers who need to set up a Stripe integration. This role can create secret keys, which grant access to almost all API resources.
They can't invite team members or change the account owner.
SSO Role ID:
developer
View details
Identity roles
These roles are only available if you use Identity
Identity Analyst
This role is for Identity users who need to create, review, cancel, or redact verifications.
This role can’t edit verifications for connected accounts.
SSO Role ID:
identity_analyst
View details
Identity View Only
This role is for Identity users who need to view verification data.
This role can’t create, review, cancel, or redact verifications.
SSO Role ID:
identity_view_only
View details
Payment roles
Analyst
This role is for people who need to pay out money, refund payments, and export data.
They can't edit payout schedules or account settings.
SSO Role ID:
analyst
View details
Dispute Analyst
This role is for people who need need to view, submit evidence for, and accept disputes.
They can't do anything that's not related to disputes.
SSO Role ID:
dispute_analyst
View details
Refund Analyst
This role is for people who need to refund payments and issue credit notes on invoices.
They can’t create payments, view balance, or view connected accounts.
SSO Role ID:
refund_analyst
View details
Support roles
Data Migration Specialist
This role is for people who need to perform data migrations (copy, import, export) for their account.
They can't create connected accounts, transfer funds, payout money or edit any account and product settings.
SSO Role ID:
data_migration_specialist
View details
Support Associate
This role is for people who need to refund payments and resolve disputes, but should not have the ability to edit products. It has administration permissions for connected accounts, where it can edit the payout schedule, update the legal entity, update the bank account, and more.
They can't create connected accounts, transfer funds, payout money, or edit any account or product settings.
SSO Role ID:
support_associate
View details
Support Communications
This role is for people who need to authenticate email support cases, use Support Centre to view and respond to support cases, or share files securely with Stripe.
They can’t access financial information, transfer funds, access or edit connected accounts, or edit any account and product settings.
SSO Role ID:
support_communications
View details
Support Specialist
This role is for people who need to refund payments, resolve disputes, and may need to update products. It has administration permissions for connected accounts, where it can edit the payout schedule, update the legal entity, and more. This role can add, edit, and delete products.
They can't create connected accounts, transfer funds, payout money, or edit any account settings.
SSO Role ID:
support_specialist
View details
Terminal Specialist
This role is for people who need to manage their Terminal fleet. They can register readers, manage locations, place hardware orders and deploy software to Terminal devices.
They can't view or manage payments, products, or customers. They also can't configure payment methods or other product settings.
SSO Role ID:
terminal_specialist
View details
Tax form roles
These roles are only available if you use 1099s
Tax Analyst
This role is for people who need to configure tax form settings, file tax forms for connected accounts, and export data.
They can't create connected accounts, transfer funds, payout money, or edit account and non-Tax product settings.
SSO Role ID:
tax_analyst
View details
View only roles
View Only
This role is for people who need to view payments, balance, and connected accounts, but can’t edit any of them. This role can also export data and download reports.
They can't create connected accounts, transfer funds, payout money, or edit any account and product settings.
SSO Role ID:
view_only
View details
Other roles
Accountant
This role is for accountants who need to access Stripe Revenue Recognition and its features for monthly bookkeeping. The accountants can set up a custom chart of accounts, create accounting rules and modify revenue amortisation settings. They can also view payments, balance, invoices, customers and connected accounts, etc., but can't edit any of them.
They can't create connected accounts, transfer funds, payout money, choose pricing plans or edit any account and other product settings including signing-up or cancelling Stripe Revenue Recognition.
SSO Role ID:
accountant
View details
Top-up Specialist
This role gives access to the Top-ups feature, including creating, viewing, and updating top-ups, as well as viewing balance and payouts. Accountants or Financial employees may find this useful.
They can't access any other Stripe features.
SSO Role ID:
topup_specialist
View details
Financial Connections Specialist
This role gives access to Financial Connections operations, including viewing and editing Financial Connections settings, registration and objects, with limited customer read access.
They can't access any other Stripe features.
SSO Role ID:
financial_connections_specialist
View details
Data Engineer
This role is for Stripe Data Pipeline users who need to setup and manage data pipelines.
They will not have access to other parts of the Dashboard other than Stripe Data Pipeline.
SSO Role ID:
data_engineer
View details
