Your wholesale catalog shouldn't be open to every shopper who lands on your store. WooCommerce product restrictions let you control who can see products, view prices, or place orders, with the right extension.

We recommend starting with one clear access rule, then testing it as a customer before going live. That keeps setup manageable and protects the buying experience.

First, decide what each customer group should be allowed to do.

Key Takeaways

  • Choose separate controls for product visibility, price display, and purchasing. One setting doesn't automatically cover all three.
  • Use a role-based visibility extension for customer groups, or WooCommerce Memberships when access depends on a membership plan.
  • Test guests and approved customers separately, including direct product links, cart behavior, and checkout.

Decide What WooCommerce Product Restrictions Should Control

"Restrict this product" can mean several things. Getting clear now saves you from choosing a plugin that solves only half the problem.

WooCommerce's standard catalog visibility settings aren't a complete customer-role restriction system. The approaches below use extensions.

Hide products from the wrong audience

Product visibility controls determine whether shoppers can discover an item in your catalog. That matters for wholesale ranges, approved-buyer products, and private catalogs.

You may want restricted products removed from shop pages, category listings, and search results. But a shopper could still have a saved product link.

We recommend checking direct-link access separately. A product disappearing from the shop page doesn't prove its individual page is protected.

Also check related-product sections and any custom product listings your theme creates.

Control prices and purchases separately

Some stores want everyone to browse, while only approved customers can buy. Others want prices hidden until login.

Those are different requirements. Hiding a price doesn't automatically establish a complete purchase restriction across every route.

Role-based pricing is another separate feature. Charging wholesale customers a different amount requires pricing functionality, not just visibility controls.

We keep these decisions separate: who can view, who can see prices, and who can purchase. Your plugin choice should match those answers.

Prepare Customer Roles Before Changing Products

Restrictions work only when the store can identify the right customer group. We recommend reviewing your accounts before touching catalog rules.

Separate customers from store staff

WooCommerce includes Customer and Shop Manager roles. Customer is intended for shoppers; Shop Manager is a staff role with store-management permissions.

Don't give buyers a staff role simply to grant access to restricted products. Keep their permissions appropriate for shopping.

For wholesale access, use a customer-facing role supported by your chosen role-management extension. Don't assume WooCommerce creates a dedicated wholesale role automatically.

WooCommerce's role-management extension documentation describes tools for adding, assigning, and switching roles. Review permissions before assigning any role to real buyers.

Plan for guests and account approval

A guest is someone who isn't logged in, not a WordPress user role. Your extension may provide a separate guest setting.

Decide whether registration alone should grant access. For an approved-buyer catalog, creating an account shouldn't automatically qualify someone.

Before installing extensions, take a restorable backup and work on staging. Our WooCommerce hosting launch checklist covers the hosting basics worth checking first.

Set Up Product Visibility by Customer Role

Products Visibility by User Roles is a direct option for controlling which products and categories different roles can see.

Its documented controls include global visibility settings and per-role show/hide rules. We recommend starting with a small product selection before applying restrictions across your catalog.

Configure the visibility rules

Follow the extension's product visibility setup instructions alongside these steps:

  1. Install and activate the extension on your staging site using its supplied plugin package.
  2. Review the global visibility controls and establish the catalog's starting behavior.
  3. Open the "visibility by user roles" tab and select the customer role you want to configure.
  4. Choose the products or categories that should be shown or hidden for that role.
  5. Repeat for other customer groups, review guest behavior, and save your settings.

Category rules are useful when an entire range shares the same audience. Product-level rules suit individual exceptions.

After saving, confirm that your intended customers can still discover and open the allowed products.

Set a helpful response for blocked visitors

The extension's documentation describes removing hidden products from shop, category, search, and other listing pages. Direct-link visits can display a custom error message.

Make that message useful. Tell visitors whether they need to sign in or contact your team for approval.

Avoid promising instant access if you manually review accounts. The message should match your actual process.

Then open a restricted product's saved address while logged out. Check the result rather than assuming the catalog rule covers it.

If blocking purchases is also required, verify the extension's supported controls and test that behavior independently.

Choose the Right Tool for Purchase Access

A visibility extension suits catalog segmentation. Your requirements may go further, especially when access depends on membership or when products should remain visible.

Use Catalog Visibility Options for separate controls

Catalog Visibility Options provides role-based controls at product and category level. It separates viewing, purchasing, and price visibility, and products can inherit category settings.

That makes it worth considering when customers should see a product but shouldn't be allowed to buy it.

One detail matters: disabling prices also disables Add to Cart in this extension.

It changes visibility rather than the underlying product price. If you need wholesale discounts or quantity-based prices, evaluate a pricing extension separately.

We recommend choosing by the required behavior, rather than installing several overlapping plugins.

Use Memberships when access follows a plan

WooCommerce Memberships supports separate product-viewing and purchasing restrictions. Membership plans can grant access through purchase, registration, or manual assignment.

Choose it when eligibility depends on a membership plan rather than a customer role alone. A membership plan and a WordPress role are different systems.

The WooCommerce Memberships documentation explains its access model and restriction tools.

Check the extension's content restriction settings when deciding how restricted content should appear. We recommend keeping the storefront message consistent with the way customers obtain membership.

Keep Caching from Mixing Customer Experiences

Role-based catalogs need careful caching. A page generated for an approved customer shouldn't become the shared version shown to everyone.

Review your WordPress cache plugin, hosting cache, CDN, and reverse proxy. Ask whether role-dependent catalog pages bypass shared caching or use a configuration compatible with your restriction extension.

Excluding checkout from caching doesn't protect a role-specific product page. Catalog pages need their own cache review when their content changes by customer role.

Cart, Checkout, and My Account should also bypass page caching. These pages depend on the current shopper's session.

After changing exclusions, purge each active cache layer. Clearing a plugin cache alone may leave an older page at your host or CDN.

We recommend testing in both directions: visit as an approved customer, then as a guest, and reverse the order. That helps expose a shared cached response.

If a restricted product appears only sometimes, check cached HTML before repeatedly changing role rules. Make one change at a time, then repeat the same test.

Test the Full Customer Journey Before Launch

An administrator's view isn't a reliable customer test. Staff permissions and saved sessions can hide problems that buyers encounter immediately.

We test both sides of the rule: approved customers should succeed, and unapproved visitors should receive the configured restriction.

Start with fresh browser sessions

Open a private browser window for guest testing. Use a separate clean session for each customer role you need to check.

Review the shop, category pages, search results, related products, and direct product links. Then confirm the expected price and Add to Cart behavior.

For an approved customer, add a product, refresh, browse elsewhere, return to the cart, and continue through a controlled test checkout.

Repeat on a phone using mobile data. If purchasing fails, our guide to troubleshooting WooCommerce checkout errors helps you investigate the buying path.

Check HTTPS and access changes

Keep the product page, cart, and checkout on a consistent HTTPS hostname. Watch for redirects between HTTP and HTTPS or different versions of your domain.

Those changes can interfere with cookies and sessions. A lost session may make an approved customer appear logged out.

Also test what happens after an account loses its approved role. Check saved product links and any restricted items already in the cart.

Confirm whether your chosen solution blocks purchase at that point. WooCommerce product restrictions should behave correctly after access changes, not only when a customer first logs in.

Choose Hosting That Supports Safe Store Changes

Your restriction plugin controls access. Your hosting gives you the space and tools to test it safely.

We recommend looking for staging, restorable backups, SSL, and support before adding customer-specific catalog behavior. Check the plan's resources against your catalog size and existing extensions too.

Our WordPress hosting for WooCommerce stores offers plans with daily backups, staging, SSL, and malware scanning. Compare the listed features to choose the package that fits your store.

Staging lets you check a new visibility rule without disrupting live shoppers. Backups give you a recovery option if an update causes trouble.

Choose your hosting and restriction extension as separate parts of the same setup. Hosting doesn't replace access controls, but the right plan makes testing, maintenance, and recovery easier.

Frequently Asked Questions

Can products be restricted without a plugin?

Custom development can enforce role-based restrictions, but it requires ongoing maintenance and testing. WooCommerce's standard visibility settings don't provide the complete role-based workflow described here. We recommend an extension when you want manageable controls without maintaining custom code.

Does hiding a product stop customers buying it?

Don't assume it does. Hiding listings, blocking direct access, and preventing purchase are separate behaviors. Check what the extension documents, then test direct links and existing cart items. Choose purchase controls when preventing orders is part of your requirement.

Will wholesale pricing hide wholesale products?

Pricing rules and visibility rules solve different problems. WooCommerce Wholesale Prices documentation includes role-based and quantity-based pricing functionality. That doesn't establish complete catalog protection. Confirm whether your chosen setup also controls product visibility and purchase access.

Give the Right Customers the Right Access

Effective WooCommerce product restrictions start with a clear decision about who can view, see prices, and buy. We recommend matching the extension to that decision, then testing every relevant customer group.

Keep safe testing part of the setup, with staging, backups, and customer-aware caching.

Choose a ZADiC WordPress hosting plan that supports that workflow, and give your restricted catalog a dependable place to run.

We use cookies so you can have a great experience on our website. View more
Cookies settings
Accept
Decline
Privacy & Cookie policy
Privacy & Cookies policy
Cookie name Active

Who we are

Our website address is: https://zadic.net.

Comments

When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection. An anonymized string created from your email address (also called a hash) may be provided to the Gravatar service to see if you are using it. The Gravatar service privacy policy is available here: https://automattic.com/privacy/. After approval of your comment, your profile picture is visible to the public in the context of your comment.

Media

If you upload images to the website, you should avoid uploading images with embedded location data (EXIF GPS) included. Visitors to the website can download and extract any location data from images on the website.

Cookies

If you leave a comment on our site you may opt-in to saving your name, email address and website in cookies. These are for your convenience so that you do not have to fill in your details again when you leave another comment. These cookies will last for one year. If you visit our login page, we will set a temporary cookie to determine if your browser accepts cookies. This cookie contains no personal data and is discarded when you close your browser. When you log in, we will also set up several cookies to save your login information and your screen display choices. Login cookies last for two days, and screen options cookies last for a year. If you select "Remember Me", your login will persist for two weeks. If you log out of your account, the login cookies will be removed. If you edit or publish an article, an additional cookie will be saved in your browser. This cookie includes no personal data and simply indicates the post ID of the article you just edited. It expires after 1 day.

Embedded content from other websites

Articles on this site may include embedded content (e.g. videos, images, articles, etc.). Embedded content from other websites behaves in the exact same way as if the visitor has visited the other website. These websites may collect data about you, use cookies, embed additional third-party tracking, and monitor your interaction with that embedded content, including tracking your interaction with the embedded content if you have an account and are logged in to that website.

Who we share your data with

If you request a password reset, your IP address will be included in the reset email.

How long we retain your data

If you leave a comment, the comment and its metadata are retained indefinitely. This is so we can recognize and approve any follow-up comments automatically instead of holding them in a moderation queue. For users that register on our website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.

What rights you have over your data

If you have an account on this site, or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we erase any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.

Where your data is sent

Visitor comments may be checked through an automated spam detection service.
Save settings
Cookies settings