Shopify access sits close to products, orders, customers, refunds, payouts, themes, domains, apps, analytics, and store settings. A user who can complete a routine retail task may also inherit a sensitive permission through a broad or additional role. A partner who needed temporary theme or app access can remain visible long after the project. Access security therefore begins with business duties and ends only when the identity, sessions, integrations, and custody attached to that identity have been resolved.
Shopify's current role model groups granular permissions into roles, and multiple assigned roles grant cumulative access. Secure sign-in is tied to the individual's Shopify ID. Store administrators can require two-step authentication for eligible users but cannot view or replace a staff member's authenticator phone, app, or recovery codes. Collaborators are distinct Shopify Partner identities: the merchant controls the request, approved permissions, and removal without sharing an owner password.
This guide addresses Shopify admin and account security. It does not design physical checkout devices or POS hardware. A retailer should coordinate the software access plan with human resources, finance, legal, privacy, managed IT, and any Shopify Partner so that onboarding, role changes, incident response, and offboarding follow the same evidence-backed lifecycle.
Key decisions at a glance
- Translate merchandiser, customer service, fulfillment, marketing, finance, developer, and administrator duties into Shopify roles instead of granting broad access to familiar people.
- Account for cumulative permissions when users receive multiple roles, and examine sensitive exports, refunds, finance, customer data, themes, apps, and user-management privileges explicitly.
- Require each person to use an individual Shopify ID with a secure sign-in method, backup authentication, protected recovery codes, and a tested recovery path that does not rely on shared credentials.
- Use collaborator accounts and a controlled request code for Shopify Partners, approve only the needed role and store, review inactivity and access history, and remove the relationship when work ends.
- Offboarding is complete only after access is suspended or removed, active devices and sessions are revoked, dependent apps and ownership are transferred, shared secrets are rotated, and evidence is reviewed.
Build Shopify Roles from Retail Tasks and Permission Dependencies
Inventory the actual decisions each job performs. A merchandiser may manage products, collections, content, and files without needing refunds, finance, app installation, or user administration. Customer service may need to view and update orders and customer records but not export all customers, erase personal data, alter checkout, or approve app charges. Fulfillment staff may require order and inventory actions but not theme code. Finance may need reports and payouts while product editing remains outside the role. Write these boundaries before selecting permissions.
Review Shopify permission dependencies and cumulative access. Granting one permission can select required permissions, while a related but ungranted permission may still block the real task. Assigning multiple roles combines their privileges, so testing each role separately is insufficient for a user with several roles. Use representative accounts in a controlled store or safe test window to prove allowed tasks, denied tasks, exports, app access, and approval boundaries. Do not use the store owner account for daily work merely because it avoids permission troubleshooting.
Treat sensitive capabilities as named risk decisions. These include customer export and deletion, gift cards and store credit, refunds and payment actions, finance and billing, domains, checkout, theme publishing and code, app installation, paid app approval, custom app development, store settings, and user or role management. Record the approver, business justification, separation-of-duties concern, compensating review, and expiry where access is temporary. Re-certify roles when Shopify changes permission granularity or the business changes a job.
- Create a Shopify access matrix that maps each job duty to specific permissions, expected denied actions, store scope, and business owner.
- Calculate effective access across every assigned role instead of reviewing role names in isolation.
- Test common and sensitive tasks with representative user accounts, then preserve proof of both successful work and intended denial.
- Review owner, administrator, finance, customer export, refund, app, theme code, domain, checkout, and user-management access at least quarterly and after job changes.
Require Individual Secure Sign-In and Recoverable Shopify IDs
Every administrator should have an individual Shopify account. Shared accounts destroy attribution, encourage shared authentication methods, complicate recovery, and make offboarding ambiguous. Require a secure sign-in method for eligible users. Favor phishing-resistant passkeys or security keys where the operating model supports them, and use authenticator apps or other Shopify-supported methods with an approved backup. Two-step authentication is also required for Shopify Payments users and for Partners using collaborator accounts according to Shopify's current guidance.
The individual, not the store administrator, controls the authentication methods and recovery codes on a Shopify ID. Onboarding must therefore include observed completion without collecting the secret: the user enrolls the primary method, adds a backup, stores the provided recovery codes in an approved confidential location, and demonstrates how to reach recovery. Shopify provides ten one-time recovery codes when they are generated. Do not paste them into a ticket, shared document, chat, or manager's spreadsheet.
Monitor security posture through Shopify's available user filters, secure-sign-in requirement, activity, login history, and device or application access. Investigate unfamiliar locations, impossible travel, unexpected app sessions, repeated recovery, or access outside the person's role and schedule. If a device is lost or an account may be compromised, suspend access when appropriate, revoke device or application permission, rotate affected credentials and app secrets, preserve event details, and validate critical store changes before restoring access.
- Issue a unique Shopify user to each person and prohibit password, authenticator, recovery-code, or browser-session sharing.
- Require a primary secure sign-in method, a separate backup method, protected recovery codes, and a documented account-recovery route.
- Record compliance without recording the authentication secret, recovery code, passkey, QR seed, SMS code, or security-key material.
- Define an account-security incident playbook for suspension, session revocation, credential rotation, store-change review, recovery, and owner escalation.
Govern Shopify Collaborators as Scoped, Time-Bound Identities
A Shopify Partner should request a collaborator account rather than ask for a merchant password or an ordinary shared staff identity. Keep the collaborator request code confidential to the approved partner, rotate it after unexpected disclosure or at project milestones, and validate the requesting Partner organization and named people through an independent channel. The merchant should approve a role derived from the written scope, not every permission requested for convenience.
Define the store, role, data, theme, app, configuration objects, business hours, testing method, change authority, and end date for the engagement. Shopify collaborators cannot receive every administrator role and do not gain ownership. Current Shopify guidance also states that collaborator access expires automatically after ninety days without a login, but automatic expiry is not a substitute for closing completed work. Review collaborator filters, last access, approved roles, app activity, and open requests on a routine schedule.
Require evidence for partner changes: request or ticket, pre-change state, test result, deployment time, affected objects, and rollback. For app or integration work, identify who controls the Dev Dashboard, custom app, API configuration, webhook endpoint, billing subscription, external hosting, domain, repository, and support account. The merchant needs durable custody even if the collaborator relationship ends. Remove or suspend access promptly at completion, incident, dispute, or personnel change at the Partner.
- Use a collaborator account with an approved request code; never give a Partner the store owner's credentials or authentication method.
- Approve a purpose-built role for the exact store and work, with a business sponsor, change window, evidence standard, and expected end date.
- Review pending requests, active collaborators, last access, effective permissions, recent changes, and inactive relationships on a scheduled cadence.
- Before removal, transfer merchant custody of configurations, app and hosting accounts, repositories, domains, billing, support history, secrets, and rollback evidence.
Execute Offboarding as a Verified Access and Ownership Procedure
Trigger Shopify offboarding from an authoritative employment, contract, or role-change event. For an urgent separation or suspected compromise, suspend access first so investigation and handoff can proceed without continued entry. Revoke known device and application permissions, review login and activity history, capture the person's effective roles and collaborator relationships, and inspect material changes during the relevant period. Permanent removal is consequential and cannot simply be undone, so distinguish immediate containment from final deletion.
Close dependencies that do not disappear with the Shopify user. Reassign reports, Flow workflows, private or custom apps, app owner contacts, developer and Partner accounts, external integrations, repositories, support portals, billing approvals, notification addresses, domains, marketing channels, fulfillment services, and data exports. Rotate shared secrets, API credentials, request codes, distribution lists, and external service passwords that the person knew. Confirm that automation still runs under a supported identity and that removing an app user did not break a business process.
Complete a post-offboarding check from the Shopify user list, collaborator filter, security history, apps, sales channels, billing, Flow, themes, and connected systems. Preserve who requested and approved the action, when access was suspended and removed, which sessions were revoked, what was transferred, which credentials changed, and what operational tests passed. A manager's statement that the person left is not evidence that Shopify access and ownership are clean.
- Use a single offboarding case with identity, stores, roles, collaborators, devices, apps, integrations, secrets, ownership, billing, evidence, and accountable owners.
- Suspend immediately when risk requires containment, preserve activity evidence, then remove permanently only after required custody and approval checks.
- Revoke device and application access and rotate every shared or external credential the departing person could use outside the Shopify user session.
- Run operational acceptance after access removal so product, order, fulfillment, reporting, app, and automation workflows do not fail silently.
Vendor documentation and ALLMSP resources
- Shopify Help Center: Managing users
- Shopify Help Center: Roles
- Shopify Help Center: Store permissions
- Shopify Help Center: Security settings for users
- Shopify Help Center: Two-step authentication for users
- Shopify Help Center: Secure sign-in
- Shopify Help Center: Recovery codes
- Shopify Help Center: Collaborator accounts
- Shopify Help Center: Managing users from Shopify admin
- ALLMSP Shopify Software Support category
- ALLMSP Software Support services
- ALLMSP Cybersecurity services
- ALLMSP Cybersecurity articles
- ALLMSP Retail and Restaurants IT
- Contact ALLMSP
Frequently Asked Questions
Should employees share one Shopify administrator account?
No. Each person needs an individual Shopify ID so permissions, secure sign-in, recovery, activity, and offboarding are attributable. Shared credentials also make it impossible to remove one person's access without disrupting everyone else.
Do multiple Shopify roles replace one another?
No. Assigned roles generally provide cumulative permissions. Review the user's effective access across every role, store, app, and channel because an apparently restricted role can be broadened by another assignment.
Which Shopify permissions deserve extra approval?
Pay special attention to owner and administrator roles, user management, customer export or deletion, refunds and payment actions, finance, billing, domains, checkout, theme publishing or code, app installation, app charges, custom app development, and store settings.
Can a Shopify store owner set up two-step authentication for staff?
The owner or eligible administrator can require a secure sign-in method, but each staff member manages the authentication methods and recovery codes on their own Shopify ID. The administrator should verify completion without collecting those secrets.
Where should Shopify recovery codes be stored?
Store them in a confidential location the individual can reach when the primary method fails, such as an approved password manager or protected secure storage. Do not place them in tickets, shared drives, chat, email, or a manager's access spreadsheet.
What is a Shopify collaborator account?
It is a Shopify Partner identity that a merchant approves for specified access to a store or organization. It does not consume a normal user seat, requires Partner two-step authentication, and can be managed or removed by eligible merchant administrators.
Should a merchant approve every permission a Shopify collaborator requests?
No. Compare the request with the written scope and assign only the role required for the work. Sensitive settings, customer data, apps, finance, themes, and exports need explicit business justification and evidence.
Does Shopify's collaborator inactivity expiry replace offboarding?
No. Shopify currently expires collaborator access after ninety days without login, but completed, terminated, or risky engagements should be closed immediately. Transfer custody and remove access rather than waiting for inactivity.
When should a Shopify user be suspended instead of removed?
Suspend when access must stop immediately but investigation, evidence preservation, or ownership transfer is still underway. Remove permanently after the business confirms that custody, legal, audit, and operational dependencies are complete.
What should be tested after Shopify offboarding?
Verify the person cannot access the store, revoked devices require sign-in, roles and collaborators are clean, apps and automations still run under supported ownership, reports reach approved recipients, billing and support contacts are current, and critical order workflows still pass.


