Applies to: Pro and Enterprise · Last reviewed: 2026-09-03
What this is
Before you hand a login to a brand you ship for, you want to know exactly what they will see. This lists it screen by screen, verified from a live Customer account rather than from the role description.
A client login uses the Customer role, created at Settings > Users like any other invite. See Inviting users and setting roles for the mechanics.
What a client is scoped to
A Customer account is assigned one or more of your clients, and sees only those. The client filter at the top of the screen offers exactly the clients you assigned, plus "All clients", which means all of theirs and not all of yours. A client you have not assigned does not appear anywhere in their filter.
If a brand has one company with you, assign the one client and they will only ever see that. If a brand trades under several of your client records, assign each and they can switch between them.
What they can reach
| Dashboard | Their fulfillment pipeline, orders to fulfill, orders being picked, shipped today |
| Orders | Their orders, with status and ship-to |
| Shipments | What has gone out, with carrier and tracking |
| Inventory | On hand, allocated and available by bin, with lot and expiry |
| Receipts | Inbound, with date received and status |
| Products | Their catalogue, with SKU, barcode and origin |
| Reports | Shipments and Throughput, scoped to them |
Orders, Shipments, Inventory and Products each offer Export CSV, so a client can pull their own data without asking you for it.
What they cannot reach
The Customer role has no Fulfillment, Settings, Integrations, Carriers, Users or Clients. Those are not merely hidden from the menu. A client who types the address of one of those pages is either shown a "Page not found" or returned to their Orders list.
So a client cannot see your warehouse operation, your carrier accounts, your other clients, your users, or your billing.
Your clients never see what you paid
Your client sees the carrier and the tracking number on every shipment, and never the cost. This is not a hidden column: the server removes the figure before it sends the data, so it is absent from the page and from anything a technical person could inspect behind it.
The same applies across the portal, not just that one screen. The Shipments report withholds it too, and the Rate Browser, where live carrier pricing lives, is not a screen a client login can reach at all.
What they can change, and when it stops
A client cannot touch your warehouse. There is no adjust, no move, no receive, and no way to alter stock from a client login.
What they can do is amend their own order while it is still open, including the ship-to address and the items on it. The moment you begin work the order locks: once it leaves Open status or a label exists, CanShip refuses the change and tells them to contact you.
That boundary is deliberate. A brand spotting a wrong apartment number an hour after ordering can fix it themselves rather than emailing you, and the same edit is refused the instant it would send a picker to the wrong shelf or invalidate a label you have paid for.
Orders still reach you exactly as they do today, whether that is a connected store, a feed or an email to your team.
Before you hand over a login
Check the client's inventory reads the way you would want it read. On hand, allocated and available are the numbers a brand will draw conclusions from, and "available" is the one they will treat as what they can sell. See What "on hand", "allocated" and "available" mean if you want the definitions to hand.
Decide who at the brand gets it. A Customer login is per person, not per company, so invite the people who will actually use it rather than sharing one account. Multi-factor authentication is available to a Customer user and is not forced on them.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article