App Store Connect access is not all or nothing. Every person you add holds one or more of eight roles, and the role decides what they can see and change — from signing the Paid Applications Agreement down to answering reviews. Assign the wrong role and you either block the work or hand someone your financial reports. Here is the role model and the exact click path, taken from Apple's own help pages.

What you are solving today: pick the right role for each person (Account Holder, Admin, Finance, App Manager, Developer, Marketing, Sales, Customer Support), invite them in Users and Access, restrict which apps they can touch, then change or revoke access cleanly — and transfer the Account Holder role if the person who owns the membership changes.


The eight roles, and what each one unlocks

Apple's role permissions reference lists eight roles. Most can be held by many people at once, and one person can hold several roles.


Individual vs organization: the rules are not the same

How many people you can add, and what they get, depends on how the membership was enrolled.

Either way, two-factor authentication (or two-step verification) must be enabled on the Apple Account before it can sign in to App Store Connect at all.

If you are enrolled in the Apple Developer Enterprise Program, users are not managed in App Store Connect: you manage them in your developer account under Program resources → Users and Access, where the roles on offer are Admin and Developer.


Step 1 — Invite a user

Required role: Account Holder, Admin, or App Manager.

  1. In Users and Access, under People, click the plus (+) button at the top left.
  2. Enter the user's first name, last name, and a valid email address. Any email can activate the account — it does not have to be associated with an Apple Account.
  3. Assign one or more roles, which determine the sections and the tasks available to that user.
  4. If applicable, decide whether the user needs additional resources such as access to reports or to Certificates, Identifiers & Profiles.
  5. Click Next.
  6. If the user is App Manager, Developer, Marketing, Sales, or Customer Support and was not given reports access, select the apps they can access.
  7. Click Invite.

Two details worth remembering: invitations expire three days after they are sent (they can be resent afterwards), and the person manages their own name and password on the Apple Account page — you are not setting credentials for them.


Step 2 — Learn which roles you cannot scope

This is where account owners usually get surprised. Per Apple's app access documentation:

Least privilege, in practice: Finance for tax forms and financial reports, Sales for analytics, Customer Support for the review queue, Marketing for artwork and featuring contact. Reserve Admin for the people who genuinely run the account.


Step 3 — Restrict access to specific apps

Required role: Account Holder, Admin, or App Manager.

One user: in Users and Access → People, click the account, then click Manage apps in the Apps section. Select the checkbox next to an app's name to grant access, or deselect it to remove access; select the first checkbox to allow all apps. Optionally remove an app row entirely with the Delete button next to its name, then click Save.

Several users at once: click Edit in the top right, tick the users, click Edit App Access, select the apps in the dialog, and click Save.


Step 4 — Change roles and remove access

Required role: Account Holder or Admin.

  1. In Users and Access → People, click the account for the user you want to edit.
  2. Under Roles, select or deselect roles, or edit app access.
  3. Click Save in the top right.

To delete one user: open the account, scroll down, click Delete at the bottom left, then confirm in the dialog. To delete several: click Edit in the top right, select the users, click Delete, confirm, then Done.

The detail that matters: Apple notes caching may take up to 10 minutes to complete, fully revoking access. If someone is leaving the team, do not treat the removal as instant.


Step 5 — Transfer the Account Holder role

One person, and only one, is the Account Holder. For an organization, the current holder can transfer the role to another team member who has the legal authority to bind the organization to legal agreements. Required role: Account Holder.

  1. Sign in to your developer account and click Membership details in the top navigation.
  2. At the bottom of the section, click Update your information.
  3. Click Transfer Account Holder role, then Choose a candidate.
  4. Select an eligible team member from the drop-down and click Transfer.
  5. Read the Account Holder Transferor Agreement and click Agree.

The person you selected receives an email with instructions. Where ID verification is available in their country or region, they verify their identity with the Apple Developer app, then sign in to the Apple Developer website with two-factor authentication enabled, click Review Agreement, accept the Account Holder Transferee Agreement, and the transfer completes. Admins are then emailed that the team's Account Holder has changed.

Two more details from the same page. If the membership was enrolled through the Apple Developer app as an auto-renewable subscription, the outgoing holder must switch off automatic renewal so the new holder can subscribe — otherwise the card keeps being charged while the membership does not renew. And for individual memberships the transfer is not self-service: it is granted when a minor reaches the age of majority and receives the role from their guardian, or when the Account Holder is deceased, with assistance from Apple Developer Support.


Access checklist before you invite anyone


The one-line version

Add people in App Store Connect → Users and Access with an explicit role; remember that Admin, Finance, reports access and Certificates/Identifiers/Profiles access cannot be limited to specific apps; that invitations expire in three days; that removals take up to ten minutes to take effect; and that a single Account Holder is the only person who can sign agreements, renew membership, request App Store Connect API access, and transfer the role.


Sources