When a new vendor is approved on a marketplace, they need the right security group memberships so they can do their job — list products, manage orders, communicate with buyers — without accidentally gaining admin access.
Why Defaults Matter
- Approval should be a single click — admins shouldn't have to remember to assign 3 groups every time.
- Consistency: every vendor gets the same baseline permissions; deviations are deliberate.
- Onboarding: their first sign-in lands them in the right experience without further setup.
- Compliance: documented default reduces risk of one vendor being over-privileged.
Recommended Default Set
- Vendor: The baseline “you are a vendor” group — controls visibility of vendor menus.
- Marketplace Seller: Permission to create/edit/delete own listings.
- Order Manager: View and update orders for their own listings.
- Vendor Messaging: Send/receive messages with buyers.
Setting Defaults
- Open Site Settings → eCommerce → Vendor Defaults.
- Pick the groups to apply on approval (multi-select).
- Optionally configure per-vendor overrides for specialised vendors (e.g. an Enterprise Vendor gets an extra reporting group).
- Save.
Worked Examples
- Basic marketplace: Default = Vendor + Marketplace Seller. Everything else is admin-only.
- Two-tier marketplace: Standard vendors get the default set; Premium vendors additionally get the Premium Vendor group with analytics access.
- Healthcare marketplace: Default groups plus a mandatory Compliance Acknowledged sub-group that requires the vendor to accept additional terms before activating.
- B2B wholesale: Defaults include access to bulk-order tools and net-30 invoicing permissions.
Tip: Review default groups annually. As your product evolves, what's appropriate for a new vendor may change — and inertia means stale defaults persist if no-one checks.