Adobe Commerce

Adobe Commerce

Corma governs Adobe Commerce admin accounts: who can reach orders, customers and store settings, with clean offboarding for staff and agencies.

The Corma and Adobe Commerce integration puts every Adobe Commerce admin account under Corma's identity governance, so e-commerce, IT and security teams know who can reach orders, customer records and store configuration, and can remove that access as soon as it is no longer needed. Adobe Commerce, the platform formerly known as Magento, is a B2B and B2C commerce platform built on the Magento Open Source code base.

Key takeaways

  • Adobe Commerce is licensed on gross merchandise value and order tiers, not per admin user, so an extra admin account is a security risk rather than a cost.
  • Adobe Commerce admin permissions come from user roles whose resource access opens sales, catalog, customer and configuration areas.
  • Corma ties each Adobe Commerce admin account to a real person, a team and an end date, including agency and freelance accounts.

Where Adobe Commerce admin access goes wrong

An admin user in Adobe Commerce cannot log in until a role is assigned, and each role's resource access decides which parts of the back office it opens. Over time, stores accumulate accounts: the agency developer who launched a seasonal campaign, the freelancer who fixed the checkout, the merchandiser who moved to marketing but kept full catalog rights. Each of these accounts can read customer and order data.

Adobe has strengthened the login itself. Two-factor authentication has been required for the Admin since version 2.4.0, and from 2.4.5 admins can sign in with an Adobe ID. Yet roles and entitlements are still managed in the Commerce Admin: a strong login does not tell you whether an account should still exist.

How Corma governs Adobe Commerce

  • Admin inventory: see every Adobe Commerce admin user next to your other tools, and spot accounts that belong to former staff or past agencies.
  • Time-boxed external access: agencies and freelancers ask for access through self-serve access requests, approved by the right manager and removed at the end of the mission.
  • Role hygiene: define which Adobe Commerce role each team should hold, following role-based access control, so a move from merchandising to marketing replaces a role instead of stacking a new one.
  • Offboarding without leftovers: departures trigger revocation in Adobe Commerce along with the rest of the stack, through Corma's automated identity governance.

Retail teams apply the same discipline to their whole stack, as this retail startup story shows.

Frequently asked questions

How do I connect Corma to Adobe Commerce?

Generate an API credential in your Adobe Commerce admin settings and paste it into Corma: setup takes a few minutes. If your plan does not expose the required API, Corma's browser agents can manage admin accounts all the same.

Does Corma replace Adobe Commerce two-factor authentication?

No. Keep 2FA or Adobe ID sign-in in place. Corma governs which admin accounts exist and which roles they hold, which the login layer does not decide.

What happens to our customer and order data?

Corma requests only the permissions needed to manage admin access and encrypts data in transit and at rest. Data is hosted in France on AWS, and Corma is ISO/IEC 27001:2022 certified.

Ready to clean up your store's admin access? Book a Corma demo.

Related Integrations

Check out other integrations that could help you on managing your software licences and accesses!