- Configuration
App access for OrderCloud with Sitecore Cloud Portal
This guide explains OrderCloud access management through Sitecore Cloud Portal organization and app access controls.
Organization access levels
Organization-level access determines overall system permissions:
Owner/Admin privileges:
- Full access to all Sitecore apps
- FullAccess data permissions
- Complete impersonation rights
- User management capabilities:
- Team member invitations
- Access level configuration
- User access modification
- Account deletion
App access roles
Each OrderCloud marketplace (app) supports these access roles:
| App Role | Description |
|---|---|
| Full Access | Highest access level with complete feature availability (subject to data access configuration) |
| Admin | Configurable administrator role with customizable data access |
| Custom Group 1 | First custom role with defined data permissions |
| Custom Group 2 | Second custom role with defined data permissions |
| Custom Group 3 | Third custom role with defined data permissions |
| Custom Group 4 | Fourth custom role with defined data permissions |
Custom group configuration
Access control capabilities
OrderCloud enables granular access control through custom role groups:
- Flexible permission configuration
- Precise data access control
- Role-based authorization
Configuration requirements:
- Owner/Admin organization access required
- Up to 4 custom role groups available
- Customizable admin role settings
Permission components
Each custom role group includes:
- Data access levels
- Impersonation permissions
- API role assignments
Access inheritance
Role permissions affect:
- Personal API console access
- Impersonation capabilities
- Data visibility restrictions
Note: Available roles during impersonation represent the intersection of:
- Impersonated user's roles
- Impersonating user's permissions

Access assignment process
User invitation workflow
Organization administrators can assign roles during team member invitations:

Implementation recommendations
Before user invitations:
- Define app access configurations
- Configure role permissions
- Establish access hierarchies
- Document permission structures
This preparation ensures proper access assignment during onboarding.
Related reading
If you have suggestions for improving this article, let us know!