# How agencies put AI on a client store without risking the catalogue | BYOM blog

URL: https://byom.co/blog/agencies-ai-on-client-stores  
Markdown: https://byom.co/blog/agencies-ai-on-client-stores.md  
Last updated: 2026-10-02

> How Shopify collaborator access works, what the client can really see afterwards, who is responsible under UK GDPR, and what a catalogue error has cost.

By Kina (Checked by the BYOM team). Published 2026-10-05. 9 minute read. Series: In control.

## Key takeaways

- Shopify collaborator access is set by the merchant, expires after 90 days without a login, and a four digit request code has been on by default since December 2023.
- Forum reports from merchants say Shopify's activity log misses field level edits such as prices and descriptions, so an agency needs its own change record.
- Under the ICO's definitions an agency is a processor only while it follows the client's instructions, and a contract should say so.

An agency working on a client's Shopify store is a guest in someone else's shop. Shopify has built a specific door for that guest, the collaborator account, and the rules around it decide who can touch the live catalogue, who can see what changed, and who answers when something goes wrong. This post goes through those rules, the data protection position in UK law, the clauses a sensible agency contract carries, and what a bad catalogue edit has cost a real retailer.

## The door Shopify built for agencies

A collaborator account lets a Shopify Partner work inside a client's store without being added as staff. Shopify's developer documentation says the access covers only the sections of a store that a merchant wants the partner to reach, and these accounts do not count toward the store's staff limit. The agency signs in through its own Partner account, so a dozen client stores sit behind one login rather than a dozen shared passwords. Shopify's partner blog, which describes the feature as introduced in 2017, lists the permissions an agency commonly asks for: navigation, themes, blog posts and pages, orders and products.

The merchant sets the scope. Shopify's Dev Dashboard documentation puts it in one sentence: the merchant sets the scope of your permissions, and you can only access the parts of the store they have granted. The merchant can change those permissions after the account exists, and either side can end the arrangement when the work is done. For a client with doubts about an agency, that is the first reassurance to point at: they can remove you in a minute, without changing any passwords.

Access also lapses by itself. Shopify's documentation says collaborator access stays active as long as a user logs into the store at least once every 90 days. After that it expires, and the partner has to send a fresh request. An agency doing a quarterly catalogue review needs to know this, because a dormant client's store quietly closes behind you. The expiry is also a reasonable thing to mention to a client who worries about a former agency still holding keys.

Not every agency is the same to Shopify. Its 2025 partner programme update describes a service track for agencies, consultancies and systems integrators with five tiers: Registered, Select, Plus, Premier and Platinum. Placement depends on partner attributed revenue to Shopify, a minimum number of deals, and Verified Skills credentials earned by staff, and Shopify added 13 new Verified Skills learning paths in Shopify Academy as part of the change. The tier appears on the agency's Partner Directory profile with its skill badges. For a merchant choosing between agencies, the tier is a signal about Shopify's view of the agency's commercial record and training. It says nothing about how carefully that agency edits a live catalogue, so the contract and the process still have to carry that.

## The request code, and what it replaced

A collaborator request starts in the Partner Dashboard. The agency enters the store's permanent myshopify.com address, picks the permissions it wants, and enters a four digit collaborator request code. The merchant finds that code in the admin under Settings, Users and permissions, then Collaborators, and shares it with the agency. Shopify's Dev Dashboard documentation notes one exception: if an app from that partner is already installed on the store, the partner can request collaborator access without a code.

The code was optional until Shopify's changelog of 4 December 2023 announced it would be enabled by default for all merchants. Shopify described the purpose in its own words: it gives merchants more control over who can access their store as collaborators, by ensuring only those with the unique code can send a request. In practice that means a request arrives only from a partner the owner has already spoken to, since the owner is the one holding the code.

Shopify's partner blog also says a request expires if the owner does not answer within seven days, and recommends that agencies explain why they need each permission before they send it. That advice is worth following for a reason beyond manners. Agencies that ask for full access by default look careless, and a client reading a long list of permissions will ask why a copywriter needs orders.

- **4 digits** collaborator request code, on by default for every merchant (Shopify changelog, 4 December 2023)
- **90 days** without a login before collaborator access expires (Shopify developer documentation)
- **7 days** before an unanswered collaborator request expires (Shopify partner blog)

## What the client can see afterwards

Here the picture is thinner than most agencies assume. Shopify has a store activity log, under Settings, that records some actions taken in the admin. A community thread titled how to view collaborator changes to my store, which includes a reply from a Shopify team member, shows how far that goes in practice. One participant reports that the log captures actions such as editing a blog post or removing an item from a marketplace, but not edits to meta tags, product descriptions or titles. Another describes the log as covering account level actions and not field level edits, so that if a collaborator changes a price or rewrites a description, nothing in the admin records the old value.

Treat this as a prompt to test rather than a settled description. That is a forum, not Shopify's reference documentation, and Shopify's help pages may have changed since the thread was written. Do not tell a client that the Shopify log will show everything you did. Check what it recorded on a test change first, then agree how the agency will keep its own record. Merchants who need field level history tend to add an audit trail app for it, which is another thing to ask about before a project starts.

A practical test takes five minutes. On a development store or a client's test product, change a description and a price using a collaborator account, then open the activity log and see what it shows. Whatever the answer, write it into the onboarding notes, so the client knows in advance what Shopify will and will not tell them. An agency's own change record also settles disputes. If a client says the price was always 49 and your record says it was 59 before you touched it, the record decides. It should name the product, the field, the old value, the new value, the date, and who on the client side approved it. Shopify's native tools will not hand you that for a price or a description, so it has to come from your process.

## Who is responsible under UK GDPR

Orders carry names, addresses, emails and phone numbers, so an agency with order permissions handles personal data. The Information Commissioner's Office defines a controller as the organisation that determines the purposes and means of processing, and a processor as one that processes personal data on behalf of a controller. In the normal case the store is the controller and the agency, acting on its instructions, is a processor.

The ICO page adds a warning that agencies should read twice. If a processor makes decisions about the purposes and means of the processing without the controller's instruction, it takes on controller status and the liability that goes with it. An agency that exports a client's customer list and uses it to market its own services, or to build audiences for a different client, is no longer following instructions. The same page says employees are not processors, since staff acting within their duties are agents of the controller.

The practical consequence is a short data clause in the agency contract that says what the agency may do with order and customer data, for what purpose, and what happens to exports when the engagement ends. Sprintlaw, a UK law firm, lists data protection among the nine areas where risk concentrates in agency contracts, noting that it matters especially for customer lists, CRM data, retargeting audiences and email marketing.

## What an agency contract should pin down

The same Sprintlaw guide, written for UK digital marketing agencies, gives a useful checklist. It advises listing deliverables in enough detail to price and manage them, and saying what falls outside the agreement. It advises using targets or estimates rather than guarantees where results depend on factors the agency does not control. It says the contract should record what the client must provide, such as access to websites, ad accounts and analytics tools, along with timely approvals on creative work and budgets.

| Clause | What it settles | Why a live catalogue needs it |
| --- | --- | --- |
| Scope and deliverables | What is in and out of the work | Stops a quick fix turning into an open ended edit of every product |
| Client responsibilities | Access, approvals and budgets from the client | Names who approved a change |
| Third party dependencies | Outages, policy changes and platform decisions | Platform behaviour is not the agency's fault |
| Liability cap | A limit, often linked to fees paid over a period | Sets the exposure before a mistake, not after |
| Termination and handover | Credentials, work in progress and licences at exit | Closes collaborator access cleanly |

Sprintlaw suggests linking the liability cap to the fees paid or payable under the contract, often over a defined period, and warns that a sensible cap can still hide risk if the carve outs are drafted too widely. A contract that exempts all data protection breaches and all indemnity claims from the cap leaves open ended exposure that goes far beyond the fee. The approvals row in the table does the most work for catalogue changes: a written approval from the client's named person is the clearest evidence that a change was requested and accepted.

Handover deserves its own line in the contract. Sprintlaw says exit terms should cover work in progress, prepaid amounts, access credentials and licence rights after the contract ends. For a Shopify engagement the credential item has a concrete form: remove the collaborator account in the store settings, check that no staff account or API token created for the project is still live, and confirm in writing which exports the agency has deleted. The 90 day expiry will eventually close an idle collaborator account, but a project that ends in a dispute should not wait for it.

## What a catalogue mistake costs

The cost of an unreviewed bulk change is easier to see in a documented case. In August 2016 the UK website of a large computer maker listed laptops at drastically reduced prices after what the company called a processing error. One device with a previous price of £2,378 appeared at £1.58. The company took the store offline on the Saturday, cancelled all orders placed during the error and offered refunds, according to Decision Marketing's report.

The same report records Citizens Advice's view that retailers can often cancel online orders where they have made an honest mistake that the customer should have noticed. That is why a £1.58 laptop could be cancelled. It gives much less cover for a mistake that looks plausible, such as a jacket at £39 instead of £59. A price that looks like a sale is one a customer can claim, and a store the size of a small brand has little room to absorb it. The case is a retailer's own error, not an agency's, but the position would be identical for an agency whose edit caused it. The client carries the customer relationship and the agency may carry a claim.

There is a cheaper lesson inside the case. The error was found over a weekend and the store went offline within days. A change record with timestamps shortens that clock, because the first question in any incident is what changed and when.

## How BYOM handles the confirm step

On the BYOM Shopify app, the assistant can read products, collections and stock, and propose edits. The store changes only when someone confirms the card. Every confirmed change is recorded: what changed, who approved it, and whether the store accepted it.

The product page: [For agencies](https://byom.co/agencies), [See trust](https://byom.co/trust).

## Sources

- [Shopify developer documentation, collaborations in the Dev Dashboard](https://shopify.dev/docs/apps/build/dev-dashboard/stores/collaborations)
- [Shopify developer documentation, collaborator accounts](https://shopify.dev/docs/storefronts/themes/tools/collaborator-accounts)
- [Shopify changelog, collaborator request code now required for partners to access your store, 4 December 2023](https://changelog.shopify.com/posts/collaborator-request-code-now-required-for-partners-to-access-your-store)
- [Shopify Partners blog, 2025 updates to the Shopify Partner Program](https://www.shopify.com/partners/blog/updates-to-the-shopify-partner-program)
- [Shopify Partners blog, the Shopify collaborator account](https://www.shopify.com/partners/blog/shopify-collaborator-account)
- [Shopify Community, how to view collaborator changes to my store](https://community.shopify.com/c/technical-q-a/how-to-view-collaborator-changes-to-my-store/m-p/2669628)
- [Information Commissioner's Office, what are controllers and processors](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/controllers-and-processors/controllers-and-processors/what-are-controllers-and-processors/)
- [Sprintlaw, how UK digital marketing agencies should handle risk in client contracts](https://sprintlaw.co.uk/articles/how-uk-digital-marketing-agencies-should-handle-risk-in-client-contracts/)
- [Decision Marketing, HP refuses to ship cut price laptops after price gaffe, 2016](https://www.decisionmarketing.co.uk/news/hp-refuses-to-ship-cut-price-laptops-after-price-gaffe)
