The short versionBản rút gọn
- Admin is not the top level of access; it is a separate grant that hands out access, changes deposit methods and changes account settings. Count your Admins before you count anything else.
- Permissions belong to jobs, not to seniority. A finance director who never opens the catalogue does not need Edit on it, and the listings editor who opens it all day does.
- Brand Registry roles and Seller Central permissions are two separate systems. Removing someone from one leaves them exactly where they were in the other.
- Revoking takes about two minutes, so it belongs on the day a role changes, not at the next review.
- Admin không phải mức quyền cao nhất; nó là một quyền riêng, dùng để phát quyền cho người khác, đổi tài khoản nhận tiền và đổi thiết lập account. Đếm số Admin trước khi đếm bất cứ thứ gì khác.
- Quyền gắn với đầu việc, không gắn với chức vụ. Giám đốc tài chính không mở catalogue thì không cần Edit ở đó, còn người sửa listing cả ngày thì cần.
- Vai trò trong Brand Registry và quyền trong Seller Central là hai hệ tách rời. Gỡ người khỏi một bên thì bên kia vẫn nguyên.
- Thu hồi quyền mất khoảng hai phút, nên làm ngay hôm vai trò thay đổi, không đợi tới kỳ soát sau.
Admin is the setting people reach for when something is blocked and nobody has time to find out which page was blocking it. It ends the argument in ten seconds. It also hands over the ability to add users, change deposit methods and change everyone else's access — three things the person fixing a bullet point never needed.
Admin là cái người ta bấm khi có việc bị chặn mà không ai rảnh ngồi dò xem trang nào đang chặn. Mười giây là xong chuyện. Nhưng nó trao luôn quyền mời user, đổi tài khoản nhận tiền và đổi quyền của mọi người còn lại — ba thứ người đang sửa một dòng bullet không cần.
Permissions are worth designing once, because the design outlives the people. Staff change, agencies change, the catalogue changes. A matrix written by job survives that; a pile of exceptions granted one panic at a time does not, and two years later nobody can say why the third name on the list is there.
Bộ quyền nên thiết kế một lần cho tử tế, vì thiết kế sống lâu hơn con người. Nhân sự đổi, agency đổi, catalogue đổi. Ma trận dựng theo đầu việc thì trụ được; một đống ngoại lệ cấp theo từng lần cuống thì không, và hai năm sau không ai nói nổi vì sao cái tên thứ ba trong danh sách lại ở đó.
What Seller Central user permissions are, and two things they are notPhân quyền user trong Seller Central là gì, và hai thứ nó không phải
Amazon's own instruction for finding the page is one line:
Hướng dẫn của chính Amazon về chỗ tìm trang này chỉ dài một câu:
"You can manage access to your Seller Central account using the user permissions. Select the gear icon in the top menu of Seller Central, then select User permissions.""You can manage access to your Seller Central account using the user permissions. Select the gear icon in the top menu of Seller Central, then select User permissions."
Amazon, Seller Central overview pageAmazon, trang giới thiệu Seller Central
You invite a person by email address. They accept with their own Amazon credentials, so from then on every action belongs to a named human rather than to a shared login nobody owns. Access is then set page by page: for each page you pick a level, and in the accounts we work in the choice is between no access, view only, and view plus edit.
Bạn mời một người bằng email. Người đó nhận lời bằng tài khoản Amazon của chính họ, nên từ lúc ấy mọi thao tác đều gắn với một con người có tên, không phải một login dùng chung không ai đứng tên. Quyền được set theo từng trang: mỗi trang chọn một mức, và trong các account chúng tôi vận hành thì ba lựa chọn là không có quyền, chỉ xem, và xem kèm sửa.
Admin sits outside that list. It is not the top rung of the same ladder; it is a separate grant covering other users' permissions and the account's own settings. Anyone holding it can give themselves everything else on the page in a minute, which makes the number of Admins the only figure here that decides anything.
Admin nằm ngoài danh sách đó. Nó không phải nấc cao nhất của cùng cái thang; nó là quyền riêng, bao gồm quản quyền của user khác và thiết lập của chính account. Ai cầm nó thì một phút là tự cấp được cho mình mọi thứ còn lại trên trang, nên số lượng Admin mới là con số duy nhất ở đây thực sự quyết định điều gì.
This page is not the Solution Provider Portal. A registered service provider has its own account there, with its own user list for its own employees. Amazon's provider documentation uses the same phrase, "user permissions", to mean that. Check which of the two a guide is describing before you follow it.
Trang này không phải Solution Provider Portal. Service provider đã đăng ký có account riêng ở đó, kèm danh sách user riêng cho nhân sự của họ. Tài liệu Amazon dành cho provider dùng đúng cụm "user permissions" để nói về cái đó. Đọc hướng dẫn nào cũng phải xác định nó đang nói về account nào trước khi làm theo.
This page is not Brand Registry either. Brand Registry runs its own role model, assigned in the Brand Registry portal. Amazon describes protection roles — Rights Owner, Administrator and Registered Agent — as roles that "define the relationship of a Brand Registry account with a brand", and selling roles, Brand Representative and Reseller, as roles that "define the relationship of a seller with a brand". Edit on your listings gives someone nothing in Brand Registry, and a brand Administrator can touch none of your inventory. That gap is why "they already have access" is an unreliable sentence in a handover.
Trang này cũng không phải Brand Registry. Brand Registry chạy hệ vai trò riêng, gán trong portal của nó. Amazon mô tả nhóm protection role — Rights Owner, Administrator và Registered Agent — là các vai trò "define the relationship of a Brand Registry account with a brand"; nhóm selling role, gồm Brand Representative và Reseller, "define the relationship of a seller with a brand". Cấp Edit trên listing không cho ai thứ gì trong Brand Registry, còn Administrator của brand thì không đụng được vào tồn kho. Khoảng trống đó khiến câu "người ta có quyền rồi" rất không đáng tin lúc bàn giao.
One structural point before the table: on a unified account across a region, permissions are managed at global-account level and follow the user into every linked marketplace. Someone granted Edit to fix one listing in one country holds Edit in all of them.
Một điểm về cấu trúc trước khi sang bảng: với unified account của cả khu vực, quyền quản ở cấp global account và đi theo user sang mọi marketplace liên kết. Cấp Edit để sửa một listing ở một nước là người đó có Edit ở tất cả các nước.
| What the person doesNgười đó làm gì | Where in Seller CentralỞ đâu trong Seller Central | LevelMức quyền | Why that level and not moreVì sao mức đó, không hơn |
|---|---|---|---|
| Watches enforcement and policy noticesTheo dõi cảnh báo và thông báo chính sách | Account Health, Performance NotificationsAccount Health, Performance Notifications | View | Reading is the whole job.Việc của lane này chỉ là đọc. |
| Fixes titles, bullets, attributes, imagesSửa title, bullet, attribute, ảnh | Manage All Inventory, Add a ProductManage All Inventory, Add a Product | View & Edit | A correction is a write. View-only sees the error and cannot clear it.Sửa là ghi. Chỉ View thì thấy lỗi mà không xoá được lỗi. |
| Builds and revises FBA shipmentsLập và chỉnh shipment FBA | Manage FBA Inventory, Manage FBA ShipmentsManage FBA Inventory, Manage FBA Shipments | View & Edit | Shipment plans change inside the workflow, after the box list has moved.Kế hoạch shipment sửa ngay trong luồng, sau khi danh sách thùng đã đổi. |
| Answers cases and files appealsTrả lời case và nộp kháng nghị | Manage Your CasesManage Your Cases | View & Edit | A reply is a write. Read-only means missing the date shown on the case.Trả lời là ghi. Chỉ đọc nghĩa là trễ cái hạn ghi trong case. |
| Reconciles settlements and fee invoicesĐối soát settlement và hoá đơn phí | Payments, Business ReportsPayments, Business Reports | View | Reconciliation is reading and arithmetic. Nothing in it writes.Đối soát là đọc và tính. Không thao tác nào ghi vào account. |
| Changes deposit method or tax detailsĐổi tài khoản nhận tiền hoặc thông tin thuế | Account Info and the settings under itAccount Info và các trang settings bên dưới | Admin | Most of the reason almost nobody should hold Admin.Phần lớn lý do gần như không ai nên cầm Admin. |
| Adds or removes a userThêm hoặc gỡ user | User PermissionsUser Permissions | Admin | The grant that hands out every other grant. A company boundary, not a team one.Quyền dùng để phát mọi quyền khác. Ranh giới của công ty, không phải của team. |
Why permission sets driftVì sao bộ quyền trôi dần
Almost nobody sets out to over-grant. Sets drift, and they drift in the same five ways, ranked by how often we find each one on a first read of a client's user list.
Gần như không ai cố tình cấp thừa quyền. Bộ quyền trôi dần, theo đúng năm kiểu dưới đây, xếp theo mức hay gặp khi đọc danh sách user của một account lần đầu.
- Admin granted to end an argument. Someone hit a wall on a Friday, Admin was faster than finding the right page, and nobody went back on Monday.Cấp Admin cho xong chuyện. Ai đó vướng tường quyền chiều thứ Sáu, cấp Admin nhanh hơn ngồi dò đúng trang, rồi thứ Hai không ai quay lại.
- Permissions assigned by seniority. A finance director ends up with more access than the person editing listings all day, because giving a director less feels wrong. Seniority is not a job description.Cấp quyền theo chức vụ. Giám đốc tài chính lại có nhiều quyền hơn người ngồi sửa listing cả ngày, vì cấp cho sếp ít hơn thì thấy kỳ. Chức vụ không phải mô tả công việc.
- One login shared by several people. Usually the owner's. Nothing can then be attributed to anyone, and offboarding means changing a password everybody knows.Nhiều người dùng chung một login. Thường là của chủ account. Khi đó không thao tác nào truy được về ai, và cho nghỉ việc đồng nghĩa với đổi mật khẩu mà cả nhà đều biết.
- Access granted for a project that ended. The freelancer who rebuilt A+ Content in March. The logistics contact during a warehouse move. The work finished, the invitation did not.Cấp quyền cho dự án đã xong. Freelancer làm lại A+ Content hồi tháng Ba. Đầu mối logistics đợt chuyển kho. Việc xong rồi, lời mời thì chưa.
- Account Health withheld by accident. The opposite failure, and more expensive than it looks: the person watching policy notifications was never given View on Account Health, so the first anyone hears of a violation is when a listing is down with a deadline attached. Our note on what Amazon actually measures and what to fix first sets out the triage order.Quên cấp Account Health. Lỗi ngược lại, và đắt hơn vẻ ngoài: người được giao theo dõi policy notification chưa từng được cấp View trên Account Health, nên tin đầu tiên cả nhà nhận được là lúc listing đã tắt kèm hạn chót. Bài Amazon thực sự đo cái gì và nên sửa cái nào trước có sẵn thứ tự triage.
Write the matrix before you open the Users pageDựng ma trận trước khi mở trang Users
Do this on paper, away from the account. Half an hour, and it is the only step that requires thinking. Open the account first and you will design the set around whatever the current screen already says.
Làm trên giấy, tách khỏi account. Nửa tiếng, và là bước duy nhất phải nghĩ. Mở account ra làm trước thì bạn sẽ thiết kế bộ quyền quanh đúng cái màn hình đang hiện.
- List jobs, not people. "Edits listings", "sends FBA shipments", "reconciles settlements", "answers cases". One person may hold two jobs; one job never holds two people's access.Liệt kê đầu việc, không liệt kê con người. "Sửa listing", "gửi shipment FBA", "đối soát settlement", "trả lời case". Một người ôm hai đầu việc thì được; một đầu việc không bao giờ ôm quyền của hai người.
- For each job, write the smallest set of pages it could be done from, using the page names in your own account rather than the ones here.Với mỗi đầu việc, ghi tập trang nhỏ nhất đủ để làm, lấy tên trang theo account của bạn chứ không theo bài này.
- For each page, write the level and one sentence saying why. If the sentence is hard to write, the job does not need the page.Với mỗi trang, ghi mức quyền kèm một câu vì sao. Câu đó viết không nổi thì đầu việc kia không cần trang đó.
- Default to View. Move up to View & Edit only when the job includes a write you can name. "Might need it later" is not a write you can name.Mặc định là View. Chỉ nâng lên View & Edit khi đầu việc có thao tác ghi mà bạn gọi được tên. "Lỡ sau này cần" không phải thao tác ghi có tên.
- Mark every page no job touches. Banking and deposit methods, tax settings, account information and User Permissions itself belong in that group for everyone except the owner and one named deputy.Đánh dấu mọi trang không đầu việc nào đụng tới. Tài khoản ngân hàng, cài đặt thuế, thông tin account và chính trang User Permissions đều thuộc nhóm này với tất cả mọi người, trừ chủ account và một người phó có tên.
- Name the Admins. Two works for most accounts: the owner, and one person who can act when the owner is unreachable. Both inside your own company.Chốt danh sách Admin. Hai người là đủ với đa số account: chủ account, và một người xử lý được khi không gọi được chủ account. Cả hai đều trong công ty bạn.
- Only now open User Permissions, and work in the direction of removal first. Grant nothing new until the Admin list matches your sheet, because anyone still holding it can undo the rest.Đến lúc này mới mở User Permissions, và làm theo hướng gỡ trước. Chưa cấp gì mới cho tới khi danh sách Admin khớp tờ giấy, vì người còn cầm Admin lật lại được mọi thứ khác.
Menu labels, page names and the wording of each level belong to Amazon and get revised. Open the gear menu in your own Seller Central, go to User Permissions, and read the options actually shown against one user before you write the matrix. If a page named here has been renamed, search for it by name in Seller Central rather than assuming it is gone.
Nhãn menu, tên trang và cách gọi từng mức quyền là của Amazon và có được sửa lại. Mở menu bánh răng trong Seller Central của bạn, vào User Permissions, đọc đúng các lựa chọn đang hiện với một user cụ thể trước khi viết ma trận. Nếu một trang nhắc ở đây đã đổi tên, tìm theo tên trong Seller Central thay vì kết luận nó không còn.
Four worked permission setsBốn bộ quyền mẫu
The four we build most often. A starting position to argue with, not a standard — the right set depends on where your catalogue work and your fulfilment work actually sit.
Bốn bộ chúng tôi dựng nhiều nhất. Điểm xuất phát để cãi lại, không phải chuẩn — bộ đúng phụ thuộc việc catalogue và việc fulfilment thực tế nằm ở đâu.
The listings editorNgười phụ trách listing
Manage All Inventory and Add a Product at View & Edit; A+ Content Manager at View & Edit if they build content; Manage Your Cases at View, so they can see whether a listing problem is already open before opening a second case. Over-granted: Manage FBA Shipments, Payments, Account Info. The part people forget is that Edit on inventory also covers price and quantity — if changing price is not this job, that argues for a tighter set, not closer supervision.
Manage All Inventory và Add a Product ở View & Edit; A+ Content Manager ở View & Edit nếu họ dựng content; Manage Your Cases ở View để biết vấn đề listing đã có case chưa trước khi mở case thứ hai. Hay cấp thừa: Manage FBA Shipments, Payments, Account Info. Chỗ hay quên là Edit trên inventory bao gồm cả giá và số lượng — nếu đổi giá không thuộc việc này thì nên siết bộ quyền, chứ không phải giám sát kỹ hơn.
The inventory and FBA operatorNgười vận hành tồn kho và FBA
Manage FBA Inventory and Manage FBA Shipments at View & Edit; inventory and fulfilment reports at View; Manage Your Cases at View & Edit, because a receiving discrepancy is worked through a case and someone who cannot reply cannot finish the job. They also need View on Account Health, to see when a shipment problem has become a policy problem. That last one is the permission nobody thinks of. Over-granted here: Add a Product at Edit — creating ASINs is catalogue work.
Manage FBA Inventory và Manage FBA Shipments ở View & Edit; báo cáo tồn kho và fulfilment ở View; Manage Your Cases ở View & Edit, vì lệch số khi nhận hàng xử qua case, mà người không trả lời được case thì không kết thúc được việc. Họ cũng cần View trên Account Health để thấy lúc sự cố shipment đã thành vấn đề chính sách. Đúng cái quyền cuối đó là thứ không ai nghĩ tới. Hay cấp thừa: Add a Product ở Edit — tạo ASIN là việc của catalogue.
The finance viewerNgười xem số tài chính
Payments, Seller Fee Invoices and Business Reports at View. That is the whole set. It is the one role where "view everything, edit nothing" is genuinely correct, and the role most often mistaken for one needing Admin, because deposit settings live under account information. Reading a settlement and changing where the money lands are not the same page and not the same job.
Payments, Seller Fee Invoices và Business Reports ở mức View. Hết. Đây là vai trò duy nhất mà "xem hết, sửa không gì" thực sự đúng, và cũng hay bị nhầm là cần Admin, chỉ vì cài đặt nhận tiền nằm trong phần thông tin account. Đọc settlement và đổi chỗ tiền chảy về là hai trang khác nhau, hai đầu việc khác nhau.
An external agency or contractorAgency hoặc cộng tác viên bên ngoài
The same rule, applied harder: the pages the contracted work names, at the level that work requires, nothing adjacent. If the contract is listing maintenance, the set is the listings editor set above. Two conditions worth making non-negotiable. Every person from that company gets their own invitation under their own email address — one shared mailbox on your user list means you cannot tell who changed what, and cannot remove one person without removing all of them. And the end date goes into the same document that grants the access, on the same day.
Cùng nguyên tắc, siết chặt hơn: đúng các trang hợp đồng gọi tên, đúng mức công việc đó cần, không thêm gì kề bên. Hợp đồng là bảo trì listing thì bộ quyền chính là bộ ở trên. Hai điều kiện nên đặt thành bất di bất dịch. Mỗi người của bên đó nhận lời mời riêng bằng email riêng — một hộp thư dùng chung trong danh sách user nghĩa là bạn không biết ai sửa gì, và không gỡ được một người mà không gỡ cả nhóm. Và ngày kết thúc phải nằm ngay trong tài liệu cấp quyền, viết cùng ngày.
Adding an outside provider, and taking them off againThêm một đơn vị bên ngoài, và gỡ họ ra
A provider is added the way an employee is added: invited by email, accepting with their own credentials, holding a named permission set. Never by being handed the owner's password, never by being read a verification code over chat. Both destroy the two properties that make outside access safe — that it is attributable to a person, and that you can end it without their cooperation.
Thêm một đơn vị bên ngoài giống như thêm một nhân sự: mời qua email, họ nhận lời bằng tài khoản của chính họ, giữ một bộ quyền có tên. Tuyệt đối không đưa mật khẩu của chủ account, không đọc mã xác thực qua chat. Hai cách đó phá đúng hai tính chất khiến việc mở quyền ra ngoài còn an toàn — truy được về một con người, và kết thúc được mà không cần họ đồng ý.
Where a provider is registered with Amazon as a service provider, Amazon may present its own authorisation path for that relationship rather than a plain user invitation, and the roles open to an external party are not necessarily the ones open to your own staff. Follow whichever flow Amazon puts in front of you, and read what it says it is granting. The principle underneath does not move: access comes from Amazon's mechanism, never from your credentials.
Nếu bên đó đã đăng ký với Amazon với tư cách service provider, Amazon có thể đưa ra luồng uỷ quyền riêng thay vì lời mời user thông thường, và vai trò mở cho bên ngoài không nhất thiết trùng vai trò mở cho nhân sự của bạn. Cứ đi theo luồng Amazon hiện ra, và đọc kỹ nó nói đang cấp cái gì. Nguyên tắc bên dưới không đổi: quyền đến từ cơ chế của Amazon, không bao giờ từ thông tin đăng nhập của bạn.
We do not ask for, store or use a seller's password, and we do not accept a one-time verification code. Our people are invited as named users through Amazon's own flow, at the permission level the work needs, and the seller can withdraw any of it at any time without telling us first. We do not hold Admin in a client account and do not add or remove other users in one. If a provider tells you scoped permissions are not workable and only the owner login will do, that is information about the provider.
Chúng tôi không hỏi, không lưu, không dùng mật khẩu của seller, và không nhận mã xác thực một lần. Nhân sự của chúng tôi được mời vào với tư cách user có tên qua đúng luồng của Amazon, ở mức quyền công việc cần, và seller thu hồi được bất cứ lúc nào mà không cần báo trước. Chúng tôi không giữ Admin trong account của khách, không thêm hay gỡ user nào trong đó. Nếu một đơn vị nói cấp quyền theo phạm vi không làm được, phải có login của chủ account mới xong, thì đó là thông tin về chính đơn vị đó.
Offboarding is a step of the job, not an afterthought. Five actions, in order:
Thu hồi quyền là một bước của công việc, không phải phần đuôi nhớ ra sau. Năm thao tác, theo thứ tự:
- Decide the end date when you grant the access, not when the relationship ends. Same line, same document.Chốt ngày kết thúc ngay lúc cấp quyền, không phải lúc hợp tác kết thúc. Cùng một dòng, cùng một tài liệu.
- On the day, open User Permissions and remove the user. Two minutes, and it needs no conversation first.Đến ngày đó, mở User Permissions và gỡ user. Hai phút, không cần trao đổi trước với ai.
- Remove rather than downgrade. A departed contractor left at View is a live account nobody is watching.Gỡ hẳn, đừng hạ mức. Cộng tác viên đã nghỉ mà còn ở mức View là một account đang sống không ai để mắt.
- If they held Admin, read the whole user list afterwards and account for anyone they added.Nếu họ từng cầm Admin, đọc lại toàn bộ danh sách user và truy cho ra ai đã được họ thêm vào.
- If they held Brand Registry roles, remove those separately in the Brand Registry portal. The Seller Central removal does not reach them.Nếu họ có vai trò trong Brand Registry, vào portal đó gỡ riêng. Gỡ user trong Seller Central không chạm tới phần này.
What over-granting costs, and when you find outCấp thừa quyền tốn gì, và khi nào mới lộ ra
Nothing happens for a long time, and that is the problem. There is no alert for an over-permissioned account, no metric that turns yellow. The cost arrives only when something has gone wrong and you are trying to establish what happened.
Rất lâu chẳng có gì xảy ra, và vấn đề nằm đúng ở đó. Không có cảnh báo nào cho một account bị cấp thừa quyền, không chỉ số nào chuyển vàng. Cái giá chỉ tới khi đã có chuyện và bạn đang cố dựng lại xem chuyện gì đã xảy ra.
Attribution goes first. A price changes overnight, or a listing is closed with units still in a fulfilment centre. If four people share one login there is no answer to who did it, and the fix becomes a guess about intent instead of a correction.
Mất đầu tiên là khả năng truy vết. Giá đổi qua đêm, hoặc một listing bị đóng trong khi hàng vẫn nằm trong kho. Bốn người dùng chung một login thì không có câu trả lời cho câu hỏi ai làm, và việc sửa biến thành đoán ý người ta.
Then reversibility. Access granted as a permission is withdrawn in two minutes from one page. Access granted as a password is withdrawn by changing it, resetting everything else that used it, and hoping nobody kept a copy.
Sau đó là khả năng thu hồi. Quyền cấp dạng permission thì gỡ trong hai phút, ngay trên một trang. Quyền cấp dạng mật khẩu thì gỡ bằng cách đổi mật khẩu, reset mọi chỗ khác từng dùng nó, rồi hy vọng không ai giữ bản chép.
Then blast radius. The pages people over-grant are the ones with no undo: deposit method, tax settings, and the user list itself. A wrong bullet point is a five-minute fix. A wrong deposit method is a case with Seller Support and a gap in your cash whose length you do not choose. The leading indicator is not on any dashboard — it is the number of names on your User Permissions page you cannot explain in one sentence.
Rồi tới mức độ lan. Những trang hay bị cấp thừa đúng là những trang không có nút hoàn tác: phương thức nhận tiền, cài đặt thuế, và chính danh sách user. Một dòng bullet sai thì năm phút là xong. Một tài khoản nhận tiền sai thì thành case với Seller Support và một khoảng hụt dòng tiền mà độ dài không do bạn chọn. Chỉ báo sớm không nằm trên dashboard nào — nó là số cái tên trong trang User Permissions mà bạn không giải thích nổi trong một câu.
The access review, and where it sits on a cadenceViệc soát quyền, và chỗ của nó trong nhịp vận hành
Reading the whole user list is a monthly job. The part that has to be same-day is the trigger: someone joins, changes role, or leaves. That is the part that gets skipped, because a departure feels like an HR event rather than an account event, and whoever processes it is usually not whoever holds Admin.
Đọc hết danh sách user là việc hằng tháng. Phần bắt buộc làm trong ngày là phần kích hoạt: có người vào, đổi vai trò, hoặc nghỉ. Đó mới là phần hay bị bỏ, vì một người nghỉ việc trông giống chuyện nhân sự chứ không giống chuyện account, và người xử lý thủ tục nghỉ thường không phải người cầm Admin.
On a weekly cadence it belongs as a named line under the account lane, not as a meeting of its own: the review asks whether anyone joined, changed role or left this week, and only opens the page when the answer is yes. The rule that makes it work is the one that makes a weekly account review close its items instead of repeating them — one named owner, and every line ends closed, assigned with a date, or explicitly dropped.
Trong nhịp tuần, nó là một dòng có tên trong lane account, không phải một cuộc họp riêng: buổi review chỉ hỏi tuần này có ai vào, đổi vai trò hay nghỉ không, và chỉ mở trang khi câu trả lời là có. Nguyên tắc khiến nó chạy cũng chính là nguyên tắc khiến buổi review account hằng tuần chốt được việc thay vì lặp lại chúng — một người phụ trách có tên, và mỗi dòng kết thúc ở trạng thái đã chốt, đã giao kèm hạn, hoặc bỏ hẳn.
One pass worth doing once, in the other direction: take each lane on your agenda, name its owner, then check the owner actually holds the permission that lane needs. It is common to find the person accountable for account health has never been given View on Account Health, and has been working from screenshots someone else sends over. That person is not managing the lane. They are describing it.
Một lượt đáng làm một lần, theo chiều ngược lại: lấy từng lane trong agenda, gọi tên người phụ trách, rồi kiểm xem người đó có thật sự cầm quyền mà lane cần không. Rất hay gặp cảnh người chịu trách nhiệm account health chưa từng được cấp View trên Account Health, và vẫn làm việc bằng ảnh chụp màn hình người khác gửi sang. Người đó không quản lane. Người đó đang thuật lại lane.
- Open User Permissions and count the Admins, naming the reason each one holds it.Mở User Permissions và đếm số Admin, nói rõ lý do từng người đang cầm.
- Read every email address on the list and say which company it belongs to.Đọc từng email trong danh sách và nói nó thuộc công ty nào.
- Remove anyone whose project has ended, rather than downgrading them to View.Gỡ hẳn những người mà dự án đã xong, đừng hạ xuống View rồi bỏ đó.
- Check that whoever owns account health holds View on Account Health and Performance Notifications, in their own name.Kiểm xem người phụ trách account health có View trên Account Health và Performance Notifications không, đứng tên chính họ.
- Check that whoever answers cases holds View & Edit on Manage Your Cases.Kiểm xem người trả lời case có View & Edit trên Manage Your Cases không.
- Open the Brand Registry portal separately and read its own role list.Mở riêng portal Brand Registry và đọc danh sách vai trò ở đó.
- Confirm nobody is working from a shared login, and no password or verification code has gone outside your company.Xác nhận không ai dùng login chung, và không mật khẩu hay mã xác thực nào lọt ra ngoài công ty bạn.
After this you can say who is able to do what inside your account, and prove it from the page rather than from memory. What it will not tell you is whether those people are any good at the work: permissions bound the damage, they do not raise the standard. It also does not settle how much of your operation should sit with any one outside party — that is a commercial question about concentration risk, not an access one, and it deserves its own conversation rather than being decided by whichever checkbox was convenient.
Sau bước này, bạn nói được ai làm được gì trong account của mình, và chứng minh từ chính trang đó chứ không phải từ trí nhớ. Cái nó không nói cho bạn biết là những người đó làm việc có giỏi không: phân quyền chặn được thiệt hại, không nâng được chất lượng. Nó cũng không giải quyết chuyện bao nhiêu phần vận hành nên đặt vào tay một bên ngoài duy nhất — đó là câu hỏi kinh doanh về rủi ro tập trung, không phải câu hỏi về quyền truy cập, và nó xứng đáng có một cuộc bàn riêng thay vì bị định đoạt bởi ô tick nào tiện tay hơn.
The work in this article happens on the User Permissions page under Settings, and it is the seller’s own work: Mavenic does not hold Admin in a client account and does not add or remove users in one. What our people hold is the set described above — View on Account Health and Performance Notifications to see enforcement while it is still an alert, View & Edit on Manage All Inventory to correct listings, View & Edit on Manage FBA Shipments to run inbound, and View & Edit on Manage Your Cases to file and follow appeals — granted per named person by the seller.
Phần việc trong bài này diễn ra trên trang User Permissions ở mục Settings, và đó là việc của chính seller: Mavenic không giữ Admin trong account của khách, cũng không thêm hay gỡ user. Nhân sự của chúng tôi chỉ giữ đúng bộ quyền mô tả ở trên — View trên Account Health và Performance Notifications để thấy cảnh báo khi nó còn là cảnh báo, View & Edit trên Manage All Inventory để sửa listing, View & Edit trên Manage FBA Shipments để chạy hàng vào kho, và View & Edit trên Manage Your Cases để nộp và theo kháng nghị — cấp cho từng người có tên, do seller cấp.
The Mavenic App connects read-only through SP-API. Managed account management is done by Wicom staff working inside your Seller Central account under the user permissions you grant and can withdraw at any time.
Mavenic App kết nối chỉ đọc qua SP-API. Dịch vụ quản lý tài khoản do nhân sự Wicom trực tiếp thao tác trong Seller Central của bạn, theo đúng quyền bạn cấp và có thể thu hồi bất cứ lúc nào.
SourcesNguồn
- Amazon Seller Central — Amazon, on managing access through user permissions — Amazon, về việc quản lý quyền truy cập qua user permissions
- What are Brand Registry roles? — Amazon, on protection roles and selling roles — Amazon, về protection role và selling role
- Amazon Brand Registry — Amazon, on enrolment and what it covers — Amazon, về điều kiện đăng ký và phạm vi
- Amazon seller policies to know — Amazon, on the seller code of conduct — Amazon, về seller code of conduct