Harpy Glossary

R&R (Roles and Responsibilities)

Amazon & D2C glossary · Harpy Media

R&R (Roles and Responsibilities) is the who-does-what structure behind an account: which person or agency owns which task, and what access they have in order to do it. On the marketplace it becomes concrete in user permissions, where access is granted by function rather than by convenience.

What is R&R?

R&R (Roles and Responsibilities) is the who-does-what structure behind an account: which person or agency owns which task, and what access they have in order to do it. On the marketplace it becomes concrete in user permissions, where access is granted by function rather than by convenience.

It is unglamorous administration with a genuine risk dimension. Most account incidents that get described as “hacks” or “mistakes” are permission failures: someone who should have been able to edit advertising had access to pricing, or an agency login left open years after the engagement ended.

Why access discipline is a profitability issue

Two exposures. Human error: an over-scoped login can change a price, delete inventory, or alter a listing by accident, and the consequences land immediately and publicly. And security: every additional person with wide access is another credential that can be lost, shared, or misused — and marketplace accounts control funds, inventory, and customer data.

The defence is least-privilege access, defined by role. Advertising partners get campaign and reporting access. A bookkeeper gets the reports needed for reconciliation, not disbursement or pricing. Warehouse or VA support gets order and inventory functions. Nobody except the owner keeps the keys to everything.

Making the structure real

Define the roles before granting anything: list the functions the business performs, then decide who owns each and what access that ownership requires. Invite users through the platform’s permission system rather than sharing a master login, so that revoking a person removes their access completely.

Then maintain it. Review the user list quarterly, remove access that belongs to former contractors, and adjust scope as responsibilities change. It is a small annual chore with a disproportionate payoff: fewer accidental changes, a cleaner audit trail of who did what, and no quiet credentials sitting in an old inbox.

In practice

A brand hiring an advertising agency issues a secondary user invitation scoped to campaign management and reporting. The agency optimises spend effectively and lifts sales velocity — and because the access is siloed, they cannot see supplier invoices, margins, or inventory planning. The work gets done and the commercial core of the business stays closed.

⚠️ Watch out. Sharing the primary account login. A seller hands the main credentials to a contractor for convenience, the engagement ends without the password changing, and months later a pricing rule is altered from that login. Nobody can say who did it, and the account had no record of who had access. Convenience purchased at the price of control.
💡 Harpy tip. Work from the function backwards: name the task, decide who owns it, and grant exactly the access that task requires. Invite users individually, review the list every quarter, and remove anything you cannot immediately justify — including logins for people who no longer work with you.

How Harpy Media helps

Account governance is part of how we run brands: access scoped by function, third-party roles defined in writing, and quarterly reviews that keep permissions current rather than historical.

R&R FAQ

What does roles and responsibilities mean for an Amazon account?

The structure of who owns which task and what account access they need to perform it — implemented through user permissions so that people and agencies see only what their role requires.

Why does access matter so much?

Because wide access invites both accidental changes to pricing or inventory and security exposure. Least-privilege access reduces the blast radius of any single mistake or compromised credential.

How should I give an agency access?

Issue a separate user invitation scoped to the functions they need — typically advertising and reporting — rather than sharing the primary login. That way, ending the engagement also ends the access.

Want these numbers watched for you, every week?

Book Free Consultation

New guides, straight to your inbox.

Practical D2C playbooks as we publish them. No fluff, no spam — unsubscribe anytime.