| Role | Typical Access | Should Not Have Access To |
|---|---|---|
| Store Owner / Administrator | Full administrative access, including user management, finance, and Store settings. | Access should be limited to a small number of authorized individuals. Multi-Factor Authentication (MFA) must be enabled. |
| Operations / Fulfillment | Manage orders, fulfillment, and basic customer information required for order processing. | Finance, Store settings, user management, and application installation permissions. |
| Merchandising / Catalog | Manage products, collections, inventory, and Store content. | Customer personal data, finance, and Store settings. |
| Marketing | Access to marketing tools, discounts, analytics, and approved marketing applications. | Finance, Store settings, and the ability to export complete customer lists. |
| Finance / Accountant | Access to financial reports and accounting functions only (using Shopify's scoped accountant access where applicable). | Products, content management, and Store settings. |
| External Agency (Collaborator) | Time-limited, role-specific access to designated Store areas necessary for the engagement. | Any resources outside the agreed scope of work, including finance, user management, and administrative settings. |
6. Provisioning, Review and De-provisioning
a) Joiners
Access is requested by the appropriate role owner, approved by the designated approver, and assigned using the appropriate Shopify role. Permission changes take effect immediately once granted.
b) Movers
When an employee's responsibilities change, their access permissions are reviewed and updated to align with their new role.
c) Leavers / End of Engagement
Access is suspended or revoked immediately when an employee or collaborator leaves the organization or their engagement ends. Shopify terminates active sessions when a user is removed or suspended, and collaborator access codes are revoked.
d) Periodic Review
User accounts, roles, and permissions are reviewed on a regular basis to identify inactive accounts, excessive permissions, and external collaborators who no longer require access. Multi-Factor Authentication (MFA) is also verified during these reviews, and any identified issues are documented and promptly remediated.
7. Security Baseline
a) Multi-Factor Authentication (MFA) is mandatory for all accounts with access to the Shopify Store.
b) Store ownership and billing access are assigned only to authorized personnel and are reviewed regularly.
c) Access logs and user activity are periodically reviewed to detect and investigate unauthorized access or suspicious activity.
8. Ownership and Review
This Policy is jointly owned by the IT/Security and Operations teams and is reviewed at least annually, or whenever there are significant changes to the Shopify platform, our organizational structure, or applicable laws and regulations.
No products were added to the Wishlist