Permissions & super admin · who may do what in the PIM
Access to the PIM is controlled on two levels: the Shopware roles with the privilege group "StawPim (products)" and the PIM's own super admin list with its feature switches. This page shows what each level actually protects.
Two levels: Shopware roles and PIM super admin
Two independent levels decide who may do what in the PIM:
- Shopware roles: In Shopware's role management (Settings → System → Users & permissions) you find the privilege group "StawPim (products)" in the catalogues area. It decides whether someone can open the PIM at all and adds the matching Shopware product privileges.
- PIM super admin: In the config matrix, tab "PIM Super Admin", you define who is a super admin and which areas and features all other users see in the PIM.
The four roles of the privilege group
| Role | Key | Contains |
|---|---|---|
| View | staw_pim.viewer | product.viewer plus read access to custom fields, sales channels, languages, dynamic product groups, tags, delivery times, units and tax rates |
| Edit | staw_pim.editor | product.editor, requires "View" |
| Create | staw_pim.creator | product.creator, requires "View" and "Edit" |
| Delete | staw_pim.deleter | product.deleter, requires "View" |
What the roles protect in the code
- View is required for the three menu items in the Stone & Water menu (PIM Dashboard, PIM, PIM Configuration Matrix) and for all pages of the module. Users with this role are also redirected from Shopware's product list to the PIM automatically, as long as the redirect is enabled in the config matrix.
- Create protects the page for creating new products.
- Edit and Delete are not checked by the PIM itself. They take effect through the included Shopware privileges
product.editorandproduct.deleter.
The super admin concept
You enter super admins in the config matrix, tab "PIM Super Admin", under "Super admin users": Shopware usernames, separated by commas or one per line. Upper and lower case do not matter. Below the field the PIM shows your own detected username.
- Super admins always see all areas and features, regardless of any switch.
- Only super admins see the "PIM Super Admin" tab.
- Super admins may always approve and reject in the approval workflow.
Visibility for regular users
In the "Visibility" section you define which areas users without super admin status see. All three switches are on by default.
- PIM Configuration (
seeConfig): When off, the config matrix shows a notice instead of the settings and the button in the header disappears. - PIM dashboard (
seeDashboard): When off, the dashboard button in the header disappears and opening the dashboard directly leads to the product list. - Translation dashboard (
seeTranslations): The switch exists but has no visible effect in version 1.11.72 because this dashboard is not included.
Features for regular users: the 14 switches
In the "Features" section you turn off individual features for users without super admin status. A switch that is still missing in an older saved configuration counts as allowed.
| Switch | Effect when off |
|---|---|
| Create products | The create button in the product list disappears, creating is blocked |
| Duplicate products | The "Duplicate" entry in the context menu disappears |
| Generate variants (bulk edit) | Generating and deleting variants in bulk edit disappears |
| Copy to variants | Buttons for copying images and properties to variants disappear |
| Delete products | Deleting individually, via the selection and in bulk edit is blocked |
| Set active/inactive | Manual activating and deactivating is blocked |
| Bulk edits | The bulk edit button disappears |
| Snapshots | The jump from the product list to the snapshots disappears |
| Change history | The "Changes" tab in the detail view disappears |
| CSV export | Export in the CSV window is blocked |
| CSV import | Import in the CSV window is blocked |
| Feed generator | The feed generator button disappears |
| Manage categories | The category management button disappears |
| Approval workflow | Off by default. Who may approve is defined by the list "Approval authorized users" |
Except for "Approval workflow", all switches are on by default. There is no separate Shopware privilege for CSV import or CSV export, both are controlled by these two switches. If export and import are both off, the CSV button disappears from the product list completely.
Edit lock with timeout
Also in the "PIM Super Admin" tab you enable the edit lock (default: off). When it is on, the detail view registers an opened product with the server and confirms this every five seconds. If a second person opens the same product, a notice with name and time appears. That person can take over editing or return to the product list.
- Timeout: selectable from 3 seconds to 5 minutes, default 30 seconds. If the confirmation stops for that long, for example because the browser crashed, the lock is released.
- When you leave the product, the PIM releases the lock.
- A shorter timeout releases locks faster but creates more server requests.
Reset PIM to defaults
At the end of the tab, "Reset to defaults" resets field selection, order, general settings and the variant, CSV and log settings. In addition, filter presets, import and export profiles, snapshots, change history and approval entries are deleted. You confirm with your admin password, the action cannot be undone.
Approval authorized users
The right to approve is not a Shopware role. You enter the usernames in the config matrix, tab "Approval", under "Approval authorized users", separated by commas or one per line. Super admins may always approve. If the list is empty, every user may approve and reject.
Security notes
- Fill the super admin list as soon as more than one person works with the PIM.
- Before saving, check that your own username is in the list, otherwise you lock yourself out of the "PIM Super Admin" tab.
- Set approval authorized users if you use the approval workflow.
- The super admin list and the feature switches control the PIM interface. The plugin's endpoints require a sign-in to the Shopware admin but check neither PIM roles nor switches. Therefore also assign suitable Shopware roles.
- The lists compare Shopware usernames. If you rename a user, update the lists.
What's next
All other tabs are described in the config matrix. How approvals work is shown in the approval workflow. The initial setup is covered in getting started, protection against external systems in external system protection.
Frequently asked questions
What happens if no super admins are entered?
Then every signed-in user counts as super admin. All feature and visibility switches have no effect in this state.
Is there a separate privilege for CSV import?
No. CSV import is controlled by the feature switch "CSV import" in the "PIM Super Admin" tab. It is on by default, super admins may always import.
Where do I assign the PIM roles?
In Shopware's role management in the catalogues area under "StawPim (products)". There you find the roles View, Edit, Create and Delete.
Can I lock myself out as super admin?
Not via the switches, they never apply to super admins. You can only lock yourself out by saving a super admin list without your own username. That is why the field shows your detected username.