# Give an AI agent access to your store safely

Which access scopes to grant, how staff permissions limit an app, where to set spend caps, and how to read the trail an agent leaves. Updated 2026-10-08.

## The short version

An AI agent in your store is an app, and an app can only touch the data its access scopes allow. Shopify says scopes "control which store data your app can read and write," and that you approve them when you install the app [1]. That approval screen is your main control. Read it the way you would read a contract.

Four habits cover most of the risk:

- Grant the fewest scopes the job needs, and prefer read over write.
- Give the agent a staff role, or tie it to a staff member, with only the permissions that role needs.
- Put a cap on what the agent can spend, and on what it can give away in refunds and discounts.
- Know where the agent's actions show up, and look there every week.

## What can go wrong

**Write access you did not need.** On Shopify, any scope that writes a resource also reads it [1]. An app that asks for `write_orders` to add a tag can also edit those orders. If the agent only answers "where is my order?" (S-01, S-02), it does not need to change orders at all.

**The agent can do more than the person using it.** An app installed with broad scopes acts with those scopes. Shopify offers online access tokens for apps that must respect one staff member's permission level. The token carries `associated_user_scope`, which is the overlap between the app's scopes and that user's permissions. A call outside that overlap returns `ACCESS_DENIED` [2]. Ask the vendor which kind of token the agent uses. If it uses a store-wide token, the staff limits you set elsewhere do not narrow it.

**Old orders, customer data and refunds.** By default an app can read orders from the last 60 days. Reading older orders needs `read_all_orders`, which Shopify must approve [1]. Apps get no protected customer data by default, and that data has its own review [1]. If an agent asks for these, it should have a clear reason, such as returns on older orders (S-04, S-05).

**A bill that keeps growing.** An agent may charge per conversation or per resolution through Shopify app billing. For usage charges, the `cappedAmount` is "the maximum that a merchant is billed for during the 30-day billing cycle." You approve the plan, and you can change the cap in the admin [3]. A cap you never look at is no cap.

**Changes you cannot trace.** If you cannot tell which changes the agent made, you cannot undo a bad batch of product edits (C-01, C-02) or a wrong sale price (M-02).

## What to set up

**1. Write down the jobs before you install.** List what the agent should do, such as "answer order status," "cancel unfulfilled orders" (S-08) or "rewrite descriptions" (C-01). Each job maps to a small set of scopes. Anything on the install screen that is not on your list is a question for the vendor.

**2. Check what the app actually holds.** Some scopes are optional and granted after install, so what an app declares and what it holds can differ. Developers can read the true list from `currentAppInstallation.accessScopes` in the GraphQL Admin API [1]. If you work with a developer, ask them to run that query and send you the result.

**3. Match staff roles to the job.** Shopify groups permissions into roles that you assign to users [4]. The Admin API lists the permissions behind them. `ORDERS` lets a staff member "view, create, update, delete, and cancel orders." `MARKETING` covers creating discount codes and automatic discounts. `APPLICATIONS` lets a staff member "manage and install apps and channels" [5]. A support lead who uses an order agent may need `ORDERS`. They do not need `APPLICATIONS` or `MARKETING`.

**4. Keep the install right with the owner.** For apps that use online tokens, the person who installs the app must hold every scope it requires, or the install fails [2]. Keep `APPLICATIONS` with one or two people. Then no one adds a second agent without a review.

**5. Set money limits in two places.** First, set a usage cap on the app's billing that matches one month of expected volume [3]. Second, set limits inside the agent: the largest refund it may issue alone, the largest discount it may offer, and the order value above which a person must approve. Partial refunds that need approval (S-09) are the test for this rule. If the agent's settings have no such limit, treat refunds as a human-only job.

**6. Write the approval rules down.** Use a short table with three columns: the action, the limit, and the person who approves above it. Address changes after a label is bought (S-07) and lookups where the email does not match the order (S-14) belong on that table. Without it, the agent's defaults decide.

## How to check it

**Read the event trail.** Shopify records events on store resources, such as an order being fulfilled or a product being added. Each event can show `appTitle`, the app that created it, and flags for whether an app or an admin user caused it [6]. Ask the vendor whether the agent's changes appear there under its own name. If they appear under a staff member's name, you lose the line between person and agent.

**Use the order timeline.** The timeline holds an order's history and staff notes [7]. Ask the agent to leave a timeline comment when it acts, saying what it did and why. Comments can be deleted, and a deleted comment cannot be recovered [7], so do not treat comments as the only record.

**Run a test week.** Before you let the agent act, run it in draft or suggest-only mode if it has one. Pick ten real tickets and compare what it proposed with what your team did. Then try three requests it should refuse:

- Cancel an order that has already shipped.
- Refund more than your limit.
- Look up an order for an email that does not match it.

**Review monthly.** Check the scope list, the staff role, the billing cap and the events. Remove scopes for jobs the agent no longer does. If you stop using an agent, uninstall it rather than leaving it idle with write access.

## Further reading

- Shopify's access scopes reference lists every scope and which ones need approval [1].
- Shopify's staff permissions guide explains roles and how to assign them [4].

## Sources

1. [Access scopes](https://shopify.dev/docs/api/usage/access-scopes), Shopify (shopify.dev), accessed 2026-10-08
2. [Online access tokens](https://shopify.dev/docs/apps/build/authentication-authorization/access-tokens/online-access-tokens), Shopify (shopify.dev), accessed 2026-10-08
3. [Create usage-based subscriptions](https://shopify.dev/docs/apps/launch/billing/subscription-billing/create-usage-based-subscriptions), Shopify (shopify.dev), accessed 2026-10-08
4. [Staff permissions](https://help.shopify.com/en/manual/your-account/staff-accounts/staff-permissions), Shopify Help Center, accessed 2026-10-08
5. [StaffMemberPermission enum (GraphQL Admin API)](https://shopify.dev/docs/api/admin-graphql/latest/enums/StaffMemberPermission), Shopify (shopify.dev), accessed 2026-10-08
6. [Event interface (GraphQL Admin API)](https://shopify.dev/docs/api/admin-graphql/latest/interfaces/Event), Shopify (shopify.dev), accessed 2026-10-08
7. [Timeline](https://help.shopify.com/en/manual/shopify-admin/timeline), Shopify Help Center, accessed 2026-10-08

Source page: https://commerceaiagents.com/guides/give-an-ai-agent-store-access-safely
