Permission approach
| Service area | Typical authorized activity | Access principle | Customer PII |
|---|---|---|---|
| Account and catalog operations | Business settings support, listings, variations, catalog cases and account-health workflows | View or Edit only as required by the written scope | Not required |
| Brand and A+ Content | Prepare, submit and maintain eligible brand content | Edit only when the seller authorizes content management | Not required |
| Inventory and fulfillment | Inventory review, replenishment planning and shipment workflow support | View for analysis; Edit only for approved operational execution | Not required for FBA planning |
| Merchant-fulfilled orders and returns | Shipping, delivery support, returns and legally required records | Restricted access only when the contracted service genuinely requires it | Only where permitted for fulfillment, returns, tax or legal obligations |
| Payments and reports | Settlement, fee, reimbursement and profitability reconciliation | View by default; no customer PII requested | Not required |
| Advertising | Campaign analysis and seller-approved changes | View for audit; Edit only for managed campaigns | Not required |
| Buyer communications | Approved communication workflows relating to an order | Only the applicable permission and approved templates | Limited to the authorized order-related purpose |
How access is granted
- The seller and NexZeta approve a written statement of work.
- NexZeta documents the specific tasks, information and minimum role level required.
- The seller grants access through Amazon-approved authorization or secondary-user permissions. Passwords and access keys are never shared.
- Access is attributable to an individual, protected with MFA, reviewed at least quarterly and removed when no longer required.
- The seller may revoke authorization at any time. Applicable Amazon information is then securely deleted within the required period.
Why we do not request every role by default
Amazon requires access to be limited to the minimum necessary for authorized functions. A comprehensive service provider may support many service areas, but requesting every role at Admin level for every client would not meet that principle. Higher access is requested only when a specific approved task cannot be completed with a lower level.