How-to / B2B buyer access and procurement governance · Updated 2026-09-15
Shopify B2B Buyer Offboarding: Revoke Purchasing Access Without Breaking Company History
Build a safer Shopify B2B buyer-offboarding workflow: revoke company-location access, preserve order history, replace approvers, review open orders and keep procurement controls intact.
All ShopRadar apps featured in this guide are available in English.
B2B access is rarely static. A purchasing coordinator leaves, a manager changes departments, a branch closes, or a customer asks you to move ordering authority to a new employee. The dangerous response is to treat that as ordinary customer cleanup. In Shopify B2B, the buyer profile, company-location permissions, company order history, open orders and the customer's internal approval chain are separate pieces of the operating model. Offboarding should remove purchasing authority without accidentally erasing the commercial record you still need.
Shopify provides the native identity and company-location controls for this job. B2B Procurement OS is available in English and is relevant after that access boundary is correct: its current Shopify App Store listing documents multi-level amount-based approvals, per-company credit limits and net terms, saved-list or CSV reordering, volume quote requests, and self-service editing of unfulfilled orders. The clean design is therefore native Shopify for who can enter the B2B buying environment, then procurement controls for what an authorized buyer can do inside it.
Start by identifying what is actually changing
Do not begin with a Delete button. First classify the event. If an employee left one branch but still purchases for another, you may need to revoke only one company-location assignment. If the person left the customer organization entirely, removing them from the company may be appropriate. If the person is staying but should no longer administer addresses or view the location's wider order history, a permission downgrade can be enough. Each case changes a different layer of access.
Shopify currently documents two company-contact permissions. Ordering only allows a contact to place orders for assigned company locations and view their own order history. Location admin also lets the contact review orders placed by all customers for that location and edit billing and shipping addresses. That difference is operationally important during a role change: a buyer who should keep ordering may still need Location admin removed if administrative responsibility moved to someone else.
Write the requested end state before making changes: which company locations the person should still access, whether they should be able to order, whether they should remain a location administrator, who becomes the replacement contact, and whether any pending purchase needs reassignment or cancellation. This one-minute checklist prevents a vague 'remove access' request from becoming a destructive account edit.
Revoke company-location access before you think about deleting customer data
Shopify's current B2B contact documentation lets a merchant revoke a customer's permissions for specific company locations by managing the customer's Permissions section and deselecting the relevant locations. Deselecting all locations for a company leaves the contact with no company access. That is usually the precise control needed when the objective is to stop B2B purchasing authority.
Shopify also allows a customer to be removed from a company. The documentation is explicit that this does not delete the customer profile; the profile remains in the customer list as a D2C customer. That distinction matters because 'remove from company' and 'delete customer' are not interchangeable cleanup actions. For a departing procurement employee, the access relationship is usually the thing you need to change, not the existence of the customer record itself.
Shopify further documents an order-history choice when removing a customer from a company. Migrated orders can in some cases be removed from the company and returned to D2C history, but orders created after the customer was added to the company cannot be removed from the company through that option. Treat that as a reason to preserve and review history rather than attempting to make the former buyer disappear from the commercial record.
Preserve company history because offboarding is an authorization event, not a sales-history rewrite
A wholesale account needs continuity after the individual buyer changes. Finance may still need to match invoices to purchase orders, customer service may need to explain an earlier shipment, and the replacement buyer may need visibility into prior orders at the location. Removing the departing employee's authority should not make those transactions ambiguous.
Shopify's company model supports that separation. A company is the parent organization and can contain one or more company locations; each location can carry its own tax ID, addresses, pricing, payment terms and contacts. Shopify also blocks deletion of a company when orders exist for it, and blocks deletion of a company location when orders or draft orders exist. That is a useful architectural signal: company history is not merely disposable contact metadata.
For a clean audit trail, record the offboarding date, the locations removed, the replacement contact, and the internal request that authorized the change. ShopRadar is not suggesting a particular legal retention rule here. The operating point is simpler: if someone later asks why a buyer lost access or who took over purchasing, the answer should not depend on staff memory.
Replace the buyer before a routine reorder turns into an emergency support ticket
The best offboarding workflow includes onboarding the successor. Shopify lets merchants add an existing or new customer to a company, select company locations and choose permissions for each location. If the new contact needs only purchasing authority, Ordering only is the narrower role. If the person must see all orders for the location and edit billing or shipping addresses, Location admin is the broader role.
This is especially important for replenishment accounts. A restaurant group, clinic chain or facilities buyer may place nearly identical orders every month. If the old user disappears on Friday and the new buyer discovers on Monday that no one can access the assigned location, the problem is no longer identity administration; it is a delayed procurement cycle. Replace critical buyers before revocation when the customer's process allows it, then confirm the new contact can access only the locations and permissions intended.
For repeat-order operations, ShopRadar's related guide at /blog/shopify-b2b-repeat-order-workflow explains when a previous order, quick order entry, a saved list or a CSV-driven reorder is the cleaner starting point. Offboarding should preserve that operating rhythm while changing the person authorized to initiate it.
Review open orders and approval responsibility separately from storefront access
Removing a buyer from a company does not answer what should happen to an order they already created. Before revocation, search for unfulfilled orders, drafts, outstanding quote work and any internal approval that still names the departing employee. Decide whether the transaction should continue, be reassigned, be edited or be cancelled under the merchant and customer's agreed process.
This is where access management and procurement governance meet. A buyer might no longer be allowed to place a new order, while an already approved purchase still needs to ship. Conversely, an unapproved request prepared by a departing employee might need fresh authorization from the customer's replacement purchasing contact. Treat the order's commercial state and the user's identity state as two separate decisions.
If your buying organizations use internal thresholds, B2B Procurement OS has a relevant documented role. Its current Shopify App Store listing advertises multi-level approval workflows with conditional rules based on order amount, using Purchasing, Manager and CFO as the published example. The listing does not claim that the app replaces Shopify's native company-contact access revocation. Use Shopify to remove unauthorized access, then review the procurement workflow so future orders still travel through the correct approval path.
Re-check credit and payment controls when the purchasing owner changes
A personnel change is also a useful trigger for an account-health review. The customer's company may still have net terms, open invoices, an account-specific credit policy, or overdue balances. Those commercial rules normally belong to the company relationship rather than to one employee, so do not reset them simply because a contact changed.
B2B Procurement OS currently advertises per-company credit limits and net terms that automatically block orders that are over limit or overdue. That makes it useful where a replacement buyer should inherit a controlled purchasing environment rather than a blank slate. A new employee should not gain the ability to exceed an existing account exposure policy merely because the previous buyer was removed.
The same principle applies to exceptions. If finance previously granted a one-off accommodation, document whether it survives the personnel change. ShopRadar's /blog/shopify-b2b-net-terms-vs-credit-limits guide separates payment timing from exposure control, while /blog/shopify-b2b-payment-reminders-overdue-orders explains why an overdue status and a collection workflow are different from a credit limit.
Use a seven-step offboarding checklist for every B2B buyer change
A repeatable checklist is safer than improvising from an email request. First verify the customer organization and exact company location. Second record the requested access change and the person authorizing it. Third identify open orders, drafts and quote activity. Fourth add or confirm the replacement contact where needed. Fifth assign the replacement only the locations and permissions required. Sixth revoke the former buyer's location permissions or remove the contact from the company as appropriate. Seventh review downstream approval, credit and reorder workflows so the new identity does not break the operating process.
After the change, perform a static admin review rather than assuming the task is complete: confirm the former contact shows no unintended company-location access, confirm the replacement contact has the intended permission level, and inspect the company record to make sure orders and commercial settings remain attached where expected. Do not share login codes or impersonate the customer to 'test' access; validate using the merchant-side permission state and your normal controlled account process.
For merchants whose procurement problem extends beyond identity administration, B2B Procurement OS is currently listed at $79 per month for Starter, $199 for Growth and $499 for Enterprise, with a 14-day free trial on each listed tier. The public listing presents the major procurement capabilities at product level, so verify exact plan entitlement for the workflow you need before purchase. B2B Procurement OS is available in English, and ShopRadar's App Store CTA uses the authentic b2b-procurement-os slug with locale=en; that parameter selects the English listing view and does not change the installed app's language settings.
- Classify whether the change is location removal, permission downgrade or full company removal.
- Preserve company and order history unless there is a separate justified reason to change it.
- Install the replacement contact before a time-critical replenishment cycle where practical.
- Review open orders independently from the buyer's future access.
- Re-check approval ownership without pretending the procurement app replaces Shopify identity controls.
- Keep company credit and net-term rules tied to the commercial relationship, not to one departing employee.
- Document who authorized the access change and what was changed.
Apps mentioned in this guide
B2B Procurement OS
Available in English
Self-service B2B orders: approvals, credit terms and quotes
Starter $79/mo · Growth $199/mo · Enterprise $499/mo · 14-day trial
Frequently asked
How do I stop a Shopify B2B customer from ordering for one company location?
Shopify currently lets you manage the customer's company permissions and deselect a specific company location. This is more precise than deleting the customer profile when the goal is to remove access for one location only.
Does removing a customer from a Shopify company delete the customer profile?
No. Shopify's current B2B documentation says the customer profile remains in the customer list as a D2C customer after removal from the company.
Should I delete a B2B company when one employee leaves?
Usually the employee-access relationship is the thing that changed, not the company itself. Shopify also prevents company deletion when orders exist. Review company contacts and location permissions instead of treating employee offboarding as company deletion.
What is the difference between Ordering only and Location admin in Shopify B2B?
Ordering only lets the contact place orders for assigned locations and view their own order history. Location admin also lets the contact view all orders for the location and edit billing and shipping addresses.
Does B2B Procurement OS revoke Shopify company-contact access?
That is not a capability verified by the current public listing. Shopify's native company-contact permissions are the documented access-control layer. B2B Procurement OS is positioned here for downstream procurement controls such as multi-level approvals, per-company credit limits, net terms, repeat ordering and order editing.
Is B2B Procurement OS available in English?
Yes. B2B Procurement OS is available in English. ShopRadar links to the authentic Shopify App Store slug with locale=en, which selects the English listing view rather than changing installed-app language settings.