Give an outside Amazon agency access through the account's current Authorized Partners workflow. Reserve secondary-user permissions for people inside the seller's own organization. Do not share the primary login, email account, recovery method or multi-factor authentication code.
Grant permissions only after the scope is approved, test access with the assigned user, review it periodically and remove it when the work ends. Menu names and partner workflows can change, so follow the current instructions shown in Seller Central for the account and region.
Discuss a controlled account handoffWhy password sharing creates more than a security problem
A shared primary login makes it difficult to attribute changes, remove one provider or prove who controlled recovery settings. It can also expose financial, tax, customer or brand information that has nothing to do with the assignment.
The brand should own the primary account, recovery email, phone and multifactor authentication. An outside agency should connect through Authorized Partners using its approved roles. Individual staff should not circulate one provider credential among a team.
Map tasks before selecting permissions
Do not begin by turning on every permission and planning to reduce it later. List the actual work: edit catalog fields, upload images, open support cases, view advertising, review inventory or reconcile payments. Then map those tasks to the current controls available in the account.
Some assignments cross sensitive boundaries. A catalog team may not need payment reports. A finance specialist may not need to edit detail pages. An advertising operator may need campaign access but not account-user administration. Keep these roles separate when the platform permits it.
Use a controlled onboarding sequence
Confirm the legal or business contact, confidentiality terms, scope and internal owner before connecting anyone. The Authorized Partners workflow applies only when the provider has the Amazon-approved roles needed for the work. Otherwise, follow the current Seller Central instructions for the account and region. Secondary users are for people inside the seller's organization. Connect only a verified provider identity, not an address supplied in an unconfirmed chat.
After access is accepted, ask the provider to demonstrate only the required screens. Record the date, role and approver. If a needed task is unavailable, review the permission mapping; do not solve it by sending a password or a one-time code.
Plan the transition before replacing an agency
A provider change should begin with an ownership inventory: Seller Central users, advertising access, brand assets, source files, dashboards, case records, catalog workbooks and external software. Note open cases, scheduled promotions, bulk files in progress and changes waiting to publish.
Create the new access separately and test it before removing the old provider. Once the handoff is accepted, revoke old users and tokens, rotate credentials the former provider legitimately knew, and monitor material changes. Do not accuse a former provider without evidence; preserve logs and escalate unusual activity through the appropriate support and security channels.
Review access as an operating control
Permissions are not a set-and-forget setup task. Review active providers, users, scopes and last-known business need at a regular interval and after staffing changes. Remove access that no longer has an owner or purpose.
Keep a short access register outside the marketplace: who approved the provider, what work it performs, how it authenticates, which tools it can reach and how to revoke them. Do not store passwords in that register. The purpose is accountability, not another secret vault.
Start with one clear requirement.
Share the current stage and the work you need reviewed. Do not send marketplace passwords or one-time codes.
Frequently asked questions
How do I give an Amazon agency Seller Central access?
Use the current Authorized Partners workflow shown in Seller Central, connect a verified outside provider and grant only the approved roles required by the scope. Secondary users are for people inside the seller's organization.
Should I share my Amazon Seller Central password with an agency?
No. Keep the primary login, recovery methods and multifactor codes under brand control. External providers should use separate supported access.
Which permissions should an Amazon account management agency receive?
There is no universal set. Map each approved task to the minimum current permission required and keep catalog, advertising, finance and user administration separated where practical.
What should I do when changing Amazon agencies?
Inventory access and assets, preserve open work, test the new provider's access, complete the handoff, revoke old identities and tokens, and monitor material account changes.
Primary references
The Esellerclub Editorial Team used the linked primary references when preparing this operational framework on 2026-08-06. Platform features and workflows can change, so confirm the current account options before acting.
Esellerclub is an independent ecommerce service provider and is not endorsed by Amazon. Marketplace names belong to their respective owners. This article is operational guidance, not legal, tax or product-compliance advice, and does not promise ranking, approval or sales results.

