Service eligibility and regional restrictions
PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.
Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.
Key Takeaways
- Shopify released bulk staff setup with CSV on August 21, 2026. The entry point is Settings > Users > Import.
- The official announcement confirms bulk creation, suspension and reactivation, covering Shopify Admin and POS staff as well as PIN assignment.
- It suits seasonal hiring, new stores and quick offboarding, but should not replace least privilege, identity checks and post-import audits.
- Download the current template and validate a small batch before importing. Do not guess fields, status values or permission formats from third-party examples.
- Use organization-approved secure procedures for POS PINs. Avoid exposing credentials in shared spreadsheets, chats or long-term archives.
One CSV can save an afternoon or spread errors across every store
When dozens of temporary staff need to start on the same day, creating accounts one at a time does slow a store opening. But an incorrect role column, batch of locations or status can leave dozens without access, or give them refund, reporting and user-management capabilities they should not have. These problems often surface during peak trading, stocktaking or after departure rather than immediately.
First distinguish the actions: create accounts only for people whose onboarding identity checks are complete and who genuinely need Admin or POS access; suspend accounts for departures, ended contracts or temporarily unnecessary access; reactivate only existing staff whose identity and role have been rechecked. Confirm the list with HR or store owners before upload, distinguish admin, POS and roles requiring no system account, and name the approver, acceptance owner and person responsible for stopping and rolling back.
Get the current template from the official entry point
In Shopify Admin, go to Settings > Users > Import and use the template and instructions provided for that import. Platform fields can evolve. Do not treat an old blog, old CSV or another store's export as the current specification.
Start with a small batch containing only necessary staff. Check emails, staff identifiers, Admin/POS scope, target status and PIN-related fields. Include only necessary data, not unrelated sensitive information such as identity documents, salaries or private notes.
Review permissions and POS PINs separately
Being able to create an account does not mean granting all permissions is appropriate. Establish a least-privilege baseline by role: approve checkout, refunds, inventory, reporting and user management separately. Review accounts with user-management or sensitive financial permissions individually.
POS PINs are access credentials. Do not use predictable sequences, reuse one PIN or leave plaintext tables on shared drives long term. After import, deliver credentials securely through organizational procedures and verify that staff can access only their assigned locations and functions.
Six steps for a safe import
First, freeze the approved staff list. Second, obtain the template from the current Import page. Third, deduplicate emails or staff identifiers and validate statuses. Fourth, import a few low-permission test accounts. Fifth, verify login, locations and key permissions in both Admin and actual POS devices. Sixth, process the remaining staff in batches and save the results.
For every batch, record the file version, operator, approver, import time, successful count, failed count and items requiring manual handling. Do not repeatedly upload the entire file just because some records succeeded; this may produce duplicate invitations, repeated status changes or PIN changes that are difficult to trace.
Separate failures by error type first
For format errors, check encoding, headers, required fields and blank rows. For identity conflicts, check whether the email or staff record already exists. For permission failures, check the operator's own permissions, store plan and target role. For POS issues, then check location assignments and PIN rules. Current official guidance explicitly says CSV cannot bulk-delete users, set two-step authentication requirements, change existing users' PINs, roles, groups, locations or store access, or change user types. Handle those operations individually in Admin or the POS app.
Do not bypass validation by deleting failed rows or granting the highest permissions. Preserve the original file and error details, create a new batch containing only failed records, and correct each before retrying. Do not guess a field's value if official documentation does not explain it.
Offboarding and the boundary of network troubleshooting
Bulk suspension can shorten offboarding, but access to other applications, devices and shared credentials must still be revoked, and duplicate accounts checked for omissions. Reconfirm the role and least privilege before reactivation instead of carrying forward the person's former elevated access.
If DNS, TLS or proxy authentication prevents the Import page from loading, save the time and error before investigating the network. Do not confuse an access failure with CSV rejection. Cross-region teams can visit the PuppyIP website to learn about fixed network egress and consult the proxy connection troubleshooting checklist.
Sources
Frequently Asked Questions
Where is Shopify's staff CSV import?
In Shopify Admin, go to Settings > Users > Import and follow the current template and instructions on that page.
Which staff operations can CSV perform in bulk?
The official update confirms bulk creation, suspension and reactivation of staff, supporting Admin and POS staff and PIN assignment.
Can I give all new staff full permissions?
This is not recommended. Apply least privilege by role and validate a small batch before expanding. Sensitive permissions such as finance, refunds and user management need separate approval.
Can POS PINs remain in a shared CSV long term?
Do not retain or widely share plaintext credentials long term. After using the current platform template, restrict access, delivery and destruction according to your organization's credential-security procedures.
Can I upload the entire file again after some records fail?
Check the platform's import results and separate failed records first. Correct them and retry in small batches. Blindly resubmitting the whole file may create duplicate invitations or repeated status changes.
Does bulk suspension complete all offboarding?
No. Revoke access to related applications, devices, shared credentials and other stores as well, and check for duplicate accounts.