Access & permissions

Broad expertise does not mean unrestricted access.

NexZeta can support the full Seller Central operating lifecycle. For each client, access is limited to the roles and level necessary for the services actually selected.

Permission approach

Service areaTypical authorized activityAccess principleCustomer PII
Account and catalog operationsBusiness settings support, listings, variations, catalog cases and account-health workflowsView or Edit only as required by the written scopeNot required
Brand and A+ ContentPrepare, submit and maintain eligible brand contentEdit only when the seller authorizes content managementNot required
Inventory and fulfillmentInventory review, replenishment planning and shipment workflow supportView for analysis; Edit only for approved operational executionNot required for FBA planning
Merchant-fulfilled orders and returnsShipping, delivery support, returns and legally required recordsRestricted access only when the contracted service genuinely requires itOnly where permitted for fulfillment, returns, tax or legal obligations
Payments and reportsSettlement, fee, reimbursement and profitability reconciliationView by default; no customer PII requestedNot required
AdvertisingCampaign analysis and seller-approved changesView for audit; Edit only for managed campaignsNot required
Buyer communicationsApproved communication workflows relating to an orderOnly the applicable permission and approved templatesLimited to the authorized order-related purpose

How access is granted

  1. The seller and NexZeta approve a written statement of work.
  2. NexZeta documents the specific tasks, information and minimum role level required.
  3. The seller grants access through Amazon-approved authorization or secondary-user permissions. Passwords and access keys are never shared.
  4. Access is attributable to an individual, protected with MFA, reviewed at least quarterly and removed when no longer required.
  5. The seller may revoke authorization at any time. Applicable Amazon information is then securely deleted within the required period.

Why we do not request every role by default

Amazon requires access to be limited to the minimum necessary for authorized functions. A comprehensive service provider may support many service areas, but requesting every role at Admin level for every client would not meet that principle. Higher access is requested only when a specific approved task cannot be completed with a lower level.