Admin Role Access Control vs Amasty Advanced Permission: what a restriction actually stops
Amasty Advanced Permission restricts more kinds of things; Admin Role Access Control enforces fewer kinds on the server and restricts new roles by default. A side-by-side read of both, with AITOC for reference.
GuideMagento Open Source roles decide what an admin may do, never where: a role that may edit orders may edit every store's orders. Both Amasty Advanced Permission and Admin Role Access Control, which is ours, add that missing dimension. They differ in how much of the admin they reach and in what a restriction does when someone goes around the form.
Everything about Amasty and AITOC below was read on 2026-10-08 from the vendors' own pages, user guides and changelogs, and from their rendered Adobe Commerce Marketplace listings. Prices change; check the vendor's page before you buy.
The short answer
Choose Amasty Advanced Permission if you need restrictions beyond store scope:
- product ownership (an admin sees only the products they created);
- CMS pages, blocks and widgets per store;
- delegated creation of admin users;
- import and export by role.
Amasty is also the choice if you want an established vendor with a long changelog.
Choose Admin Role Access Control if the requirement is that a restricted admin cannot reach what is out of scope, even with a crafted request. Also choose it if new roles should start restricted.
Side by side
| Admin Role Access Control | Amasty Advanced Permission | |
|---|---|---|
| Price and licence | EUR 149.99; includes 12 months of updates and support, renewable; the licence to use it has no time limit | USD 249 for the first year, then USD 155 a year (Open Source); 549 / 335 on Adobe Commerce, 849 / 515 on Cloud. The extension keeps working after the subscription ends |
| Store scope | Websites and store views, per role | Websites and store views, per role |
| Orders, invoices, shipments, credit memos | Scoped by store | Scoped by store, switchable per document type |
| Customers, products | Scoped by store | Scoped by store; products also by owner ("own created" or same-role) |
| Categories | Granted category trees only; writes outside them are refused | Selected categories |
| Attributes | Product and category attributes and attribute groups, deny or allow mode | Selected product attributes |
| CMS pages, blocks, widgets | Not covered | Yes |
| Import / export by role | Not covered | Yes, with an active subscription |
| Delegated admin-user creation | Not covered | Yes |
| Reports and dashboard | Scoped to granted store views | Scoped |
| New role default | Restricted until granted | Not stated by the vendor |
| How restrictions are enforced | On the request: hidden attributes are removed from the save, out-of-scope records return 404 on a direct URL and never enter grids, mass actions or reports | Not documented in general. For product-page tabs Amasty's guide says the restriction "only hides tabs visually and does not prevent editing (via mass actions or the API)" |
| Latest version | 1.3.0 | 1.7.0, 2025-11-24 |
| Reviews | New, none yet | 4.4 from 5 on amasty.com; 3.0 from 2 on the Marketplace |
Where Amasty is the better choice
It restricts more kinds of things. Product ownership, CMS content, delegated user creation and role-based import and export are all absent here. If any of them is the requirement, Amasty covers it and we do not. It also has years of releases behind it and a support organisation, and it sells an explicit Cloud edition.
Where Admin Role Access Control differs
The restriction is enforced where the data is. A field a role cannot see is stripped from the save request, so a crafted POST cannot change it. A record outside the role's stores returns 404 when its URL is opened directly, and it never appears in a grid, a mass action, a report or the dashboard's bestsellers tab. Amasty documents this distinction for one feature and draws it the other way: its product-tab restriction "only hides tabs visually and does not prevent editing". For Amasty's other restrictions, the vendor does not say how they are enforced, so we make no claim about them.
New roles start closed. A role created here is restricted until someone grants it scope; the Administrator role stays unrestricted. Neither Amasty nor AITOC states what a new role defaults to.
What the price covers. Amasty sells a yearly subscription for updates and support, USD 249 the first year and USD 155 after, and the extension keeps working when it ends. Ours includes 12 months of updates and support, renewable, and the licence to use it has no time limit.
AITOC, for reference
AITOC Advanced Permissions costs USD 185 one-time, the same price for Open Source and Adobe Commerce, with free lifetime code updates and 90 days of support. It scopes by website, store view and category. It can restrict orders, invoices, shipments and credit memos by status, which neither of the other two does, and it can restrict product creation by product type. AITOC does not document how its restrictions are enforced or what a new role defaults to.
Sources, read 2026-10-08
- Amasty: https://amasty.com/advanced-permissions-for-magento-2.html, https://amasty.com/docs/doku.php?id=magento_2:advanced_permissions, https://commercemarketplace.adobe.com/amasty-module-advanced-permission.html
- AITOC: https://www.aitoc.com/magento-2-advanced-permissions.html, https://www.aitoc.com/docs/advanced-permissions/, https://commercemarketplace.adobe.com/aitoc-advanced-permissions.html
How Admin Role Access Control works is in its documentation; the extension is on its product page.