Settings holds four things: your own sign-in, who else is in the workspace and what they may see, the browser extension that records LIVE video receipts, and the shipping account labels are bought through. Most of it is quiet housekeeping. A few of the buttons take effect instantly for other people, and a few cannot be taken back — this guide is mostly about which ones those are.
The rail down the left side of the screen jumps to each one, and the dot beside it mirrors that section's status — orange means something there wants attention.
Two things, both about you and nobody else. The card header shows the email address you are signed in as.
Change password opens a small dialog that asks for your current password first, then the new one twice. The dialog states the minimum length underneath the field and will not let you submit something shorter, or one of the passwords that turn up most often in breaches. If the current one is wrong the dialog says so and nothing changes.
Changing your own password does not sign you out anywhere — the confirmation says "use it next time you sign in", and it means it. That is deliberately different from an owner resetting someone else's password, which does sign that person out (step 09).
Every phone or tablet signed in to the mobile app as you, with the label it gave at sign-in, whether it is an Android or an iPhone/iPad, the last four characters of its access token so you can tell two of the same model apart, and when it was last used. Sign out asks you to confirm, then kills that device's access immediately.
You only ever see your own devices here, and you can only revoke your own. There is no way from this card to see or revoke somebody else's phone — for that, an owner resets that person's password, which revokes their devices as part of the same operation.
There are two ways to add someone: send them an invitation, or create the account yourself. Inviting is the normal path and it leads the card. Only people who can manage the team see any of this.
Type the email address, pick a role, press Send invite. The invitation goes out by email and appears in the pending list underneath with the date it expires — invitations are good for seven days, then the link stops working.
The link takes the recipient to a page showing the workspace name and the role they were offered. It deliberately does not show the email address it was sent to, so a link that ends up in the wrong hands does not disclose who it was for.
The invitation still exists. A warning bar appears with the full accept link and a Copy link button — send it however you like. This is why a failed send is never a dead end: the row is real, the link is valid, only the delivery failed.
Resend issues a fresh link and re-sends the email. It also invalidates whatever link was already out — there is only ever one live invitation per email address, so the old one dies the moment the new one is issued. If someone says "I clicked the link and it did not work", check whether a resend happened after they got theirs.
Revoke asks you to confirm and then kills the invitation and its link for good. There is no undo — to invite that person again you send a new invitation, which is fine and creates a fresh seven-day link.
The list below the invitations is everyone with access right now. This is the part of Settings that changes what other people see, immediately.
Add member directly creates the account there and then: name, email, a temporary password, and a role. The password field states the minimum length it will accept, and refuses the passwords that turn up most often in breaches — including the person's own name. No email is sent and nothing has to be accepted — they can sign in as soon as you press the button. Use it when you are sitting next to the person; use an invitation when you are not.
Owner has everything, always. Manager has everything except managing the team. Packer has three things: view fulfillment and packing, buy and print shipping labels, and view orders — with every money figure hidden, because a packer does not hold the financial-figures permission. The full breakdown is in the roles table at the end.
Clicking a member's row expands a permission matrix underneath, grouped the same way the permissions are grouped: Data access, Financial, Actions, Account. Every box starts where the role puts it; ticking or unticking one records a difference from the role, and the row gets a customized pill in the list. Set a box back to what the role already gives and the override disappears again rather than being stored as a no-op.
Some boxes are greyed out with a Requires: note. Those permissions depend on others — you cannot let someone edit line costs without also letting them see the costing workbench and see financial figures. Turning off something upstream drops everything that needed it, all the way down the chain.
Set password on a member's row opens a dialog that asks only for the new password. There is no current-password check — that is the whole point, and it is why the button needs seniority over the person you are pointing it at.
Setting a member's password does three things at once, all or nothing:
That combination is the answer to a lost or stolen device belonging to someone else. It is also, in practice, what actually happens when a device goes missing — far more often than the person finding the self-service revoke list themselves.
Remove asks you to confirm on the row, then deletes their membership and signs them out of everything. Your own row shows you instead of a Remove button — you cannot remove yourself here.
Managing the team is not the same as outranking everyone in it. Four rules are enforced on the server, and each has its own message:
The same rules apply to invitations, which is why an invitation can never mint a role its sender could not have created directly. They are also re-checked when the invitation is accepted, against the sender's standing at that moment — a week-old invitation from someone who has since been demoted will not still create an owner.
The Chrome extension that records what was said on a LIVE and attaches it to the orders that came out of it. Setting it up is four steps and one button.
The pill reports what this browser actually says right now, not what happened during this visit:
Download the .zip and keep the folder somewhere permanent — Chrome loads the extension from
that folder, so moving or deleting it breaks the extension. Load it at
chrome://extensions with Developer mode on, via Load unpacked. Then reload
this page: Chrome only exposes a freshly installed extension after a page load, which is
why this cannot happen on its own. Finally press
Pair to this workspace.
Pairing creates the access token for you and hands it straight to the extension — there is nothing to copy. If it does not confirm, the card says so and asks you to reload and try again; retrying reuses the same token rather than minting another. A paired card offers Re-pair instead, which is the thing to press if capture stops working.
A first-timer should use the Full walkthrough with screenshots link at the bottom of the card. The four cells are a reminder, not a tutorial.
Access tokens is folded away because pairing handles it. Open it to see every live token: its label, the last four characters, and when it was last used — which is how you tell a token that is still capturing from one nobody has touched in months.
Create token mints one by hand for a machine you cannot pair from. The token itself is shown once, in a green box, with a Copy button; it is stored as a hash and can never be shown again. Losing it means creating another.
Where labels are quoted and bought from. Everything on the ship dock depends on this card being complete and correct.
Paste a Shippo token into the field and save. It is stored encrypted and only its last four characters are ever shown again, in the card header. Leaving the field blank on a later save keeps whatever token is already stored — you never have to re-enter it to change an address or a preset.
The pill beside the card title is derived from the token itself: a token beginning
shippo_live_ shows LIVE; anything else shows
TEST MODE. Anything that is not explicitly a live token is treated as test,
which is the safe way round.
Where parcels are shipped from, and the return address printed on the label. Five fields are required before a label can be bought at all: name, street, city, state and ZIP. Phone, email and second street line are optional. The country is fixed at US and shown under the grid rather than being editable.
Label format is one of PDF_4x6 (the thermal-printer size),
PDF or PNG, and it is what every purchased label comes back as.
Parcel presets are the boxes and mailers you actually use: a name, length, width and height in inches, and a weight in ounces. They become the choices offered when quoting a shipment, so a preset with the wrong dimensions quietly produces wrong quotes on every order it is picked for. + Add preset adds a row; Remove deletes one. Neither takes effect until you save.
The bar at the foot of the card sticks to the bottom of the screen because the form is long. ● Unsaved changes appears the moment anything differs from what was loaded, including a token typed into the field. Discard re-reads the saved settings and throws your edits away. Save shipping settings is disabled until there is genuinely something to save.
If a box at the top says Couldn't load your account, both cards are hidden because they depend on the same request — press Retry. Everything below is unaffected and still trustworthy. If there is no error box, you simply do not hold the permission each card needs.
The member list and permission definitions did not arrive. Try again in place is the fix. A separate failure to refresh only the invitations list is reported on its own and leaves the rest of the card working — reload the page to see the latest pending invitations.
Two refusals land on this screen as a toast, both enforcing one shop to one workspace from opposite directions. "That TikTok shop is already connected to another workspace" means somebody else has it. "This workspace is already connected to a different TikTok shop" means this workspace is taken — connecting another shop needs a new workspace. Neither leaves your existing connection damaged: the refusal happens before anything is saved.
Three things here sign a person out, all of them immediately and without warning them first: changing their role, changing their permissions, and setting their password. Setting their password also kills their phones and tablets. If it was not one of those, it was not this screen.
Four causes, in order of likelihood: a later Resend replaced it; the seven days ran out; it was revoked; or it has already been accepted. A revoked or unknown link is deliberately indistinguishable from one that never existed — that is a privacy choice, not a bug. Send a fresh invitation.
Everything below is what the app actually enforces, not a summary of intent. Where a table says a role does not hold something, the server refuses it — not just the screen.
| Role | Can | Cannot |
|---|---|---|
| Owner | Everything. Every permission in the list below, always — including managing the team, and acting on other owners. Custom permission overrides are not applied to an owner at all. | Change their own role. Remove or demote the last remaining owner. |
| Manager | Everything an owner can, except manage the team: every read, edit and action, including seeing financial figures, running syncs, spending AI credits, buying labels, approving returns, managing the TikTok connection, the Shippo account and capture tokens, and changing their own password. | Manage team members or permissions — so no Team & access card, no inviting, no removing, no password resets for other people. |
| Packer | Exactly three things: view fulfillment and packing, buy and print shipping labels, and view orders. | Everything else — including seeing any financial figure (order screens render for a packer with every money field blank), opening Settings at all, and changing their own password. Packer credentials are set by an owner. |
These are the rows of the matrix, in the groups the screen shows them in. The third column is what must also be on — switch a prerequisite off and everything that needed it goes with it.
| Group | Permission | Requires |
|---|---|---|
| Data access | View orders | — |
| Data access | View returns | — |
| Data access | View fulfillment & packing | — |
| Data access | View show detail | — |
| Data access | View costing workbench | — |
| Data access | View purchases | — |
| Data access | View reports & P&L | — |
| Data access | View customers & buyer history | View orders |
| Data access | View operating expenses | Show financial figures |
| Data access | View settlements, payouts & reserve | — |
| Financial | Show financial figures (revenue, profit, margins, costs) | — |
| Actions | Edit line costs & cost catalog | View costing workbench, Show financial figures |
| Actions | Create & edit purchases | View purchases, Show financial figures |
| Actions | Create & edit expenses | View operating expenses, Show financial figures |
| Actions | Approve & reject returns | View returns |
| Actions | Buy & print shipping labels | View fulfillment & packing |
| Actions | Rename & resolve shows | View show detail |
| Actions | Correct AI transcripts | View orders |
| Actions | Run AI transcription (spends credits) | — |
| Actions | Trigger TikTok sync & refresh | — |
| Account | Change own password | — |
| Account | Manage capture tokens & TikTok connection | — |
| Account | Manage team members & permissions | — |
| What you change | What it affects | Reversible? |
|---|---|---|
| Your own password | Only your next sign-in. Nothing is signed out. | Change it again. |
| Sign out a device | That phone or tablet loses access immediately. | No — sign in again on the device. |
| A member's role or permissions | What they see and can do, everywhere, at once. Every browser session they have is deleted in the same operation. | Yes — change it back. They stay signed out either way. |
| Show financial figures, off | Revenue, profit, margins and costs disappear for that person across the whole app, and everything that requires it (cost, purchase and expense editing, the expenses screen) turns off with it. | Yes. |
| Set a member's password | Their password changes, every device of theirs is revoked, and every browser session is deleted. | No — set another password. |
| Remove a member | Access ends immediately; their role and custom permissions are gone. | No. Re-adding creates a fresh membership at whatever role you pick. |
| Revoke an invitation | Its link stops working. | No — send a new invitation. |
| Resend an invitation | A new link goes out and the previous one dies. | No — the old link cannot be restored. |
| Revoke a capture token | That browser stops recording LIVE video receipts. | No — pair again or create a new token. |
| Shippo token | Which Shippo account is quoted and charged, and whether the ship dock is spending real postage or test postage. | Yes — paste a different token. |
| Sender address | The return address printed on every label bought from now on, and whether labels can be bought at all. | Yes — but labels already bought keep the old address. |
| Parcel presets | The box choices offered when quoting a shipment, and therefore the rates quoted. | Yes. |
None of these are on this screen. They are platform settings, edited in a separate super-admin console with its own sign-in, and they apply to every workspace on the server. They are listed here because when a screen behaves in a way no seller setting explains, one of these is usually why.
| Setting | Default | What it changes, and where |
|---|---|---|
| Stalled-parcel threshold | 4 days | A parcel already handed to the carrier with no new scan for this long is flagged stalled — the badge on Fulfillment and the tracking timeline. Set above the carrier's normal quiet stretch, or ordinary ground parcels read as stalled. |
| Tracking poller interval | 15 minutes | How often carrier scans are refreshed. Set to 0 and the Movement and Last update columns on Fulfillment go empty. Applies after a restart. |
| Margin-outlier floor | 10% product margin | A costed line whose product margin falls below this is flagged in Costing. Below-cost selling is normal in clearance-heavy live selling, so a low or negative floor turns that from a queue into information. |
| Margin-outlier ceiling | 65% product margin | A costed line above this is flagged in Costing. The high side catches data errors — a margin near 100% is usually a missing digit or a cost of zero. |
| Use known item weights | off | Buys labels at your own approved item weights rather than only TikTok's declared one. Changes what every label costs, so it is switched on deliberately once approved weights look right. |
| Look up unknown item weights with AI | on | Enables the Suggest weight buttons on Merchandise. On-demand only — nothing is looked up automatically, and no suggestion reaches a label until approved. |
| Monthly transcription cap | 5,000 per workspace per month | How many AI transcriptions one workspace may run in a calendar month, and the figure behind the used/remaining credit display. 0 stops new transcriptions. |
| Correct misheard names as they arrive | on | Asks the name-cleanup model whether an unrecognised brand or product name is a mishearing of one you already sell. Corrections are reviewable name fixes. |
| Background auto-sync interval | 15 minutes (0 disables) | A floor under the webhook triggers. Applies after a restart — see the note below about how syncs actually start here. |
| Break-detect sensitivity / base idle threshold | 500% of pace / 5 minutes | When the packing timer asks "still packing?" — the gap that triggers the prompt, and the floor used before there are enough packs to know your pace. |
| Trend volume floor | 20 packages | A packing day below this still appears in history but is greyed out and left out of the trend line and the average. |
| Error-log retention | 30 days resolved / 90 days quiet | How long the Error log keeps a resolved error, and how long an unresolved one that has stopped recurring survives. An error that keeps happening resets its own clock and is never aged out while active. |
| Thing | Where it lives |
|---|---|
| Connecting or re-authorizing your TikTok shop | The Connect TikTok / Reconnect TikTok button in the Dashboard header, which sends you to TikTok's own authorize page. Only the outcome lands back on Settings. The pill beside it also warns when TikTok says the authorization is expiring, or that the app was deauthorized. |
| Which events TikTok pushes to us | Registered against the push URL in TikTok Partner Center — not in this app. |
| The push URL's secret, and every platform tunable in table D | The super-admin console, a separate sign-in. Nothing in this workspace's Settings reaches it. |
| A listing's price, and its declared package weight and dimensions | Set on TikTok. SellerFolio imports them after each order sync and never writes anything back to a listing. |
| Fees, payouts, reserve and bank details | TikTok's. The app only ever reads statements and settlements; there is no path from here that changes them. |
| Running a sync | The freshness indicator in the sidebar. |
Removing is permanent and takes their custom permissions with it. Turning access down is reversible and does the same job for someone who is away, on notice, or between shifts.
Role and permission saves sign that person out mid-task with no warning at their end. Ten seconds of notice turns "the app broke" into "I know why".
A resend kills the link already out. If someone is halfway through accepting, an impatient second click is what breaks their link.
Sender address and parcel presets are cheap to get wrong and expensive to discover live. A test token produces a label that looks exactly right and costs nothing.
It is per-browser. The only status that matters is the one on the laptop that will actually be broadcasting, checked before the show rather than after it.
Last used is the tell. A token nobody has touched in months is a live key to your workspace's capture endpoint with no owner — revoke it, and re-pair the machine if it turns out to matter.