App Store Connect access is not all or nothing. Every person you add holds one or more of eight roles, and the role decides what they can see and change — from signing the Paid Applications Agreement down to answering reviews. Assign the wrong role and you either block the work or hand someone your financial reports. Here is the role model and the exact click path, taken from Apple's own help pages.
What you are solving today: pick the right role for each person (Account Holder, Admin, Finance, App Manager, Developer, Marketing, Sales, Customer Support), invite them in Users and Access, restrict which apps they can touch, then change or revoke access cleanly — and transfer the Account Holder role if the person who owns the membership changes.
The eight roles, and what each one unlocks
Apple's role permissions reference lists eight roles. Most can be held by many people at once, and one person can hold several roles.
- Account Holder — the person who completed program enrollment, responsible for entering into legal agreements with Apple. Only one person holds it. It is the only role that can sign legal agreements, renew membership, request access to the App Store Connect API, remove auto-renewable subscriptions from sale, submit Safari Extensions, or create Developer ID certificates.
- Admin — secondary contact for the team, with many of the same responsibilities and access to all apps. In an organization team, Admin has Certificates, Identifiers & Profiles by default.
- Finance — manages financial information: downloading reports and uploading tax forms, with visibility of all apps in Payments and Financial Reports, Sales and Trends, and App Analytics.
- App Manager — manages all aspects of an app, including pricing, App Store information, and development and delivery.
- Developer — manages development and delivery of an app.
- Marketing — manages marketing materials and promotional artwork, and is the contact Apple uses if an app is considered for featuring.
- Sales — analyses sales, downloads, and other analytics for an app.
- Customer Support — analyses and responds to customer reviews on the App Store.
Individual vs organization: the rules are not the same
How many people you can add, and what they get, depends on how the membership was enrolled.
- Individual enrollment — you can give up to 50 additional users access to your content in App Store Connect. They are not part of the Apple Developer Program team and receive no other membership resources or benefits.
- Organization enrollment — you can add an unlimited number of members. Everyone gets App Store Connect plus all other membership resources and benefits, because management of users and roles is done in App Store Connect for the whole team.
Either way, two-factor authentication (or two-step verification) must be enabled on the Apple Account before it can sign in to App Store Connect at all.
If you are enrolled in the Apple Developer Enterprise Program, users are not managed in App Store Connect: you manage them in your developer account under Program resources → Users and Access, where the roles on offer are Admin and Developer.
Step 1 — Invite a user
Required role: Account Holder, Admin, or App Manager.
- In Users and Access, under People, click the plus (+) button at the top left.
- Enter the user's first name, last name, and a valid email address. Any email can activate the account — it does not have to be associated with an Apple Account.
- Assign one or more roles, which determine the sections and the tasks available to that user.
- If applicable, decide whether the user needs additional resources such as access to reports or to Certificates, Identifiers & Profiles.
- Click Next.
- If the user is App Manager, Developer, Marketing, Sales, or Customer Support and was not given reports access, select the apps they can access.
- Click Invite.
Two details worth remembering: invitations expire three days after they are sent (they can be resent afterwards), and the person manages their own name and password on the Apple Account page — you are not setting credentials for them.
Step 2 — Learn which roles you cannot scope
This is where account owners usually get surprised. Per Apple's app access documentation:
- Admin and Finance can view all app information and cannot have their app access limited.
- Users with access to reports or to Certificates, Identifiers & Profiles can also view all app information, and their app access cannot be limited either.
- Only App Manager, Customer Support, Developer, Marketing, and Sales (without Access to Reports) can be restricted to specific apps.
- In an organization, a member with Certificates, Identifiers & Profiles access can still view all app information there, because app access cannot be limited in that section.
Least privilege, in practice: Finance for tax forms and financial reports, Sales for analytics, Customer Support for the review queue, Marketing for artwork and featuring contact. Reserve Admin for the people who genuinely run the account.
Step 3 — Restrict access to specific apps
Required role: Account Holder, Admin, or App Manager.
One user: in Users and Access → People, click the account, then click Manage apps in the Apps section. Select the checkbox next to an app's name to grant access, or deselect it to remove access; select the first checkbox to allow all apps. Optionally remove an app row entirely with the Delete button next to its name, then click Save.
Several users at once: click Edit in the top right, tick the users, click Edit App Access, select the apps in the dialog, and click Save.
Step 4 — Change roles and remove access
Required role: Account Holder or Admin.
- In Users and Access → People, click the account for the user you want to edit.
- Under Roles, select or deselect roles, or edit app access.
- Click Save in the top right.
To delete one user: open the account, scroll down, click Delete at the bottom left, then confirm in the dialog. To delete several: click Edit in the top right, select the users, click Delete, confirm, then Done.
The detail that matters: Apple notes caching may take up to 10 minutes to complete, fully revoking access. If someone is leaving the team, do not treat the removal as instant.
Step 5 — Transfer the Account Holder role
One person, and only one, is the Account Holder. For an organization, the current holder can transfer the role to another team member who has the legal authority to bind the organization to legal agreements. Required role: Account Holder.
- Sign in to your developer account and click Membership details in the top navigation.
- At the bottom of the section, click Update your information.
- Click Transfer Account Holder role, then Choose a candidate.
- Select an eligible team member from the drop-down and click Transfer.
- Read the Account Holder Transferor Agreement and click Agree.
The person you selected receives an email with instructions. Where ID verification is available in their country or region, they verify their identity with the Apple Developer app, then sign in to the Apple Developer website with two-factor authentication enabled, click Review Agreement, accept the Account Holder Transferee Agreement, and the transfer completes. Admins are then emailed that the team's Account Holder has changed.
Two more details from the same page. If the membership was enrolled through the Apple Developer app as an auto-renewable subscription, the outgoing holder must switch off automatic renewal so the new holder can subscribe — otherwise the card keeps being charged while the membership does not renew. And for individual memberships the transfer is not self-service: it is granted when a minor reaches the age of majority and receives the role from their guardian, or when the Account Holder is deceased, with assistance from Apple Developer Support.
Access checklist before you invite anyone
- Decide the role first, then the person — not the other way round.
- Keep the Admin list short: Admins see everything and cannot be scoped to specific apps.
- Grant reports access and Certificates, Identifiers & Profiles deliberately — either one silently removes app-level restrictions.
- Use Finance only where financial reporting and tax forms are actually needed.
- Two-factor authentication on every Apple Account that will sign in.
- Re-check the user list when a contract ends; deletions need up to 10 minutes to propagate.
- Resend expired invitations instead of adding the same person twice.
- Keep the Account Holder contact reachable — only that role can renew membership or sign agreements.
The one-line version
Add people in App Store Connect → Users and Access with an explicit role; remember that Admin, Finance, reports access and Certificates/Identifiers/Profiles access cannot be limited to specific apps; that invitations expire in three days; that removals take up to ten minutes to take effect; and that a single Account Holder is the only person who can sign agreements, renew membership, request App Store Connect API access, and transfer the role.
Sources
- Role permissions — App Store Connect Help (Apple)
- Overview of accounts and roles — App Store Connect Help (Apple)
- Add and edit users — App Store Connect Help (Apple)
- Edit access to apps — App Store Connect Help (Apple)
- Roles and access — Apple Developer Account Help
- Invite team members (Enterprise Program) — Apple Developer Account Help
- Transfer the Account Holder role — Apple Developer Account Help