# Keep the AI on Shopify, but don't let it save until you say yes | BYOM blog

URL: https://byom.co/blog/ai-on-shopify-without-losing-control  
Markdown: https://byom.co/blog/ai-on-shopify-without-losing-control.md  
Last updated: 2026-10-02

> The controls already inside your Shopify admin: staff permissions, app activity, draft and unpublished states, Flow, theme copies, and what a real human check looks like.

By Kina (Checked by the BYOM team). Published 2026-09-29. 9 minute read. Series: In control.

## Key takeaways

- Shopify's Settings, Apps page shows which areas of your store a third party app can view or edit, and how many requests it made in the last 30 days.
- Draft and archived products, and unpublished themes, give you a holding area before anything is visible to customers.
- A Shopify Flow action runs on its trigger without asking, so the human check has to happen when you turn the workflow on.

Most merchants who connect an AI assistant to Shopify worry about the same morning: you open the admin and the catalogue is different. The fear is reasonable, and it is also answerable, because Shopify already has several control points. They are spread across different pages and most stores use few of them.

This post walks through those control points in the order you would meet them: who in your team can change what, what an installed app can reach and how to see what it did, where you can park work before it goes live, what an automatic workflow does without asking, and what a regulator means when it says a person must be involved.

## Staff permissions are finer than most stores use

Shopify's help centre describes four permission categories: store, organisation, Shopify POS and Partner. The store category is the one most merchants touch, and it is granular. Under products, a user can be allowed to view, to create and edit, to manage costs, to edit pricing, to export, and to delete products and collections. Orders have their own set: view, edit, apply discounts, process payments, fulfil, refund and manage returns.

Themes are split in two. The Themes permission lets a user view, change and publish themes and use command line tools, and Edit code is a separate permission for changing theme code directly. Manage settings is a third, and it grants access to the administration options, the Preferences page and the ability to create webhooks.

Two details in that page matter for anyone adding an assistant to the team. First, many permissions pull others in. Selecting any inventory permission automatically selects View products, and you cannot untick it. A role that looks narrow can be wider than its label. Second, Shopify says access to some tasks, such as user and role management, is not available directly as permissions. Those stay with the owner.

App access has its own pair of permissions. Manage and install apps and channels lets a user add, access or delete apps and channels. Approve app charges is separate: it lets a user install paid apps or themes that carry a one off charge or a subscription, and a user still needs it to install an app that starts with a free trial and turns into a paid plan. In practice you can let a colleague edit products and still stop them from connecting a new tool or spending on one.

The sensible habit is to give the person who connects an assistant the permissions the assistant needs and no more, and to keep Manage and install apps and channels with the owner. Give each person their own staff account too, so that an action in the log points at one person.

## Apps: what they can reach, and what they have done

When you install an app, the permission list you approve states which areas of your store it can view or edit. Shopify gives you a way to check that list again later, which almost nobody does. Go to Settings, then Apps, then choose the app and look at the Activity and permissions section.

That section shows which areas of your store the app can view or edit, along with the date of the app's most recent activity in each area. Hover over an area such as Products and Shopify gives a more specific description of what the app can access there. Click a recent activity date and you see the number of view requests and edit requests the app made in the past 30 days, with the date of the last one. The page adds a limit: app activity and permissions are tracked only for third party apps, not Shopify's own.

Read that as a quiet audit tool. An assistant that you only ever ask about stock levels should show view requests and no edit requests. If the edit count is not zero, you can ask why.

The Privacy section sits beside it. It lets you expand categories such as Customers and Staff and contributors to see the personal data the app can access.

The store activity log covers everything else. It displays the date and time of recent actions taken by the owner or a user, with the name of the person, app or channel that took each action. It shows a maximum of 250 results, it is view only, and it cannot be exported. To open it, a user needs the Home and Manage settings permissions. Weekly attention is the realistic cadence, since on a busy store 250 events can cover a short span.

### Taking an app away

You revoke an app's access by uninstalling it from the Apps page, which also lets you reinstall it and view its install history. The history timeline lists install and uninstall events, with optional details such as the reason and the staff member who took the action. Two cautions from Shopify's page. Some apps add code to your theme that is not removed automatically when you uninstall, so check the listing or ask the developer about extra steps. And some apps store data you cannot recover after uninstalling, so export what you need first.

- **30 days** window for view and edit request counts shown per app (Shopify Help Center, working with apps, 2026)
- **250** most results the store activity log displays (Shopify Help Center, activity logs, 2026)
- **4** product statuses: active, draft, archived and unlisted (Shopify Help Center, product details, 2026)

## Holding areas: draft products, archived products and theme copies

The cheapest control Shopify offers is to keep work out of sight until you are ready. Shopify defines four product statuses. Active means the product details are complete and the product is ready to be sold. Draft means the details need to be completed before the product can be sold. Archived means the details are complete but the product is no longer for sale. Unlisted means the product can be sold but cannot be discovered by customers.

For AI work, draft is the status that matters. An assistant that creates new products as drafts cannot put an unfinished listing in front of customers. A person has to change the status, and that change is a visible act. The same goes for rewrites of existing products: ask for the new copy to be delivered for you to paste in, and you keep a point where a person reads it.

Themes have the equivalent. Shopify's theme management page says you can make a backup copy of a theme you want to customise, change which theme is live, download a theme for future use, and remove an unused theme. A duplicate is where edits can happen with no effect on the live store until you choose to publish it. For custom theme work, Shopify suggests considering GitHub version control to track and manage changes, which tells you something: the admin itself does not give you a history of code changes, so one has to come from somewhere else.

| Control point | Where in Shopify | What it gives you |
| --- | --- | --- |
| Staff role | Staff accounts in Settings | Limits who and what can edit products, themes and apps |
| App activity | Settings, Apps, Activity and permissions | View and edit request counts for 30 days |
| Draft status | Product page | Keeps a product invisible until a person changes it |
| Theme copy | Online Store, Themes | Lets edits happen away from the live theme |
| Activity log | Store activity log | Names the person, app or channel behind recent actions |

## Shopify Flow: an action runs when its trigger fires

Flow is Shopify's workflow tool, and it is the one place where Shopify itself acts without asking. Every workflow starts with a trigger, from Flow or from an app, such as order created or order risk analysed. Conditions then decide whether the actions run. Shopify says workflows run promptly, though there can be a delay between a trigger starting a workflow and its actions completing.

The action list is wider than most merchants assume. In the product area it includes Add product tags, Add product to collections, Publish product, Unpublish product, Update product status, Update product metafield, Delete product and Delete product variant. There is also a Send HTTP request action, which passes data to an outside service, and several email actions including Send order invoice and Send payment reminder.

The consequence is simple. In a Flow workflow nobody confirms each run. The decision point is the moment you turn the workflow on. Shopify advises testing a workflow with a test trigger event before activation, and says workflows generated by its Sidekick assistant are inactive by default: you must turn them on yourself. Treat that activation as the approval, and read the actions list before you press it, especially if it contains Delete product or Publish product.

Flow also has no step that waits for a person to read a result. The documentation lists triggers, conditions and actions, and a workflow can have only one trigger, though it may have any number of conditions and actions after it. A condition is the nearest thing to a safeguard: it can check properties of the order, product or customer involved before an action runs. Write conditions narrowly, so a workflow touches the products you meant it to.

If an AI assistant offers to build a Flow workflow for you, the same rule holds. The workflow is a standing instruction, and it keeps acting after the chat has closed.

## What a regulator means by a person being involved

Merchants often hear that a human must stay in the loop, without a definition. The closest official definition comes from the UK Information Commissioner's Office, in its guidance on AI and data protection. The UK GDPR's rules on automated decisions, which the Data (Use and Access) Act 2025 has since rewritten, protect people from solely automated decision making that has legal or similarly significant effects, such as a mortgage or job decision. Product descriptions are not that. The guidance is still the clearest published statement of what counts as a person being involved, and it applies the same test to any kind of review.

Under the guidance, organisations can run such processing only when the decision is necessary for a contract, authorised by law, or based on explicit consent. The ICO says mere human involvement in the AI process does not make a decision AI assisted in the meaningful sense. Timing is the test it stresses: human involvement should come after the automated decision has been made, and it should relate to the actual outcome. The ICO's example of a failure is the person who only supplies the data the system uses. In that case, the guidance says, the human's involvement in the decision is not meaningful.

Translate that to a store. A person who types a prompt and then receives the finished change has supplied data, nothing more. A person who is shown the exact change, with the old value beside the new, before it takes effect, is reviewing the outcome, and that is the one that counts.

## A review you can run this week

None of this needs a project. It needs about an hour, and each step uses a page Shopify already provides.

- Open Settings, then Apps, and for each third party app read Activity and permissions. Note any app with edit requests in the last 30 days that you did not expect.
- List which roles hold Manage and install apps and channels, and which hold Approve app charges. Both should sit with as few people as you can manage.
- Check that new product work is created as Draft, and say so in the instructions you give any assistant.
- Read every Flow workflow that is switched on and look for Delete product, Publish product and Unpublish product among its actions.
- Duplicate your live theme before any assistant or agency edits theme code, and keep the duplicate until you have checked the result.

The ICO test is a useful last filter. For each of these automatic paths, ask whether a person sees the actual outcome before it takes effect, or only supplies the data that triggers it. Where the answer is the second, that is the place to add a check.

## Where BYOM fits

Your assistant proposes the change on a confirm card. You see what will change, and you confirm or reject it. Unconfirmed proposals expire quickly, so a forgotten draft does not land later by mistake. A confirmed change is written to Shopify and recorded.

The product page: [See the Shopify app](https://byom.co/shopify-app), [See approvals](https://byom.co/approvals).

## Sources

- [Shopify Help Center, store permissions, 2026](https://help.shopify.com/en/manual/your-account/users/roles/permissions/store-permissions)
- [Shopify Help Center, setting staff account permissions, 2026](https://help.shopify.com/en/manual/your-account/staff-accounts/staff-permissions)
- [Shopify Help Center, working with apps, 2026](https://help.shopify.com/en/manual/apps/working-with-apps)
- [Shopify Help Center, uninstalling apps, 2026](https://help.shopify.com/en/manual/apps/uninstalling-apps)
- [Shopify Help Center, activity logs in the Shopify admin, 2026](https://help.shopify.com/en/manual/shopify-admin/activity-logs)
- [Shopify Help Center, product details page, 2026](https://help.shopify.com/en/manual/products/details/product-details-page)
- [Shopify Help Center, managing themes, 2026](https://help.shopify.com/en/manual/online-store/themes/managing-themes)
- [Shopify Help Center, creating workflows in Shopify Flow, 2026](https://help.shopify.com/en/manual/shopify-flow/create)
- [Shopify Help Center, creating workflows manually or from a template, 2026](https://help.shopify.com/en/manual/shopify-flow/create/create-workflow)
- [Shopify Help Center, Shopify Flow actions reference, 2026](https://help.shopify.com/en/manual/shopify-flow/reference/actions)
- [ICO, what is the impact of Article 22 of the UK GDPR on fairness, 2026](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/how-do-we-ensure-fairness-in-ai/what-is-the-impact-of-article-22-of-the-uk-gdpr-on-fairness)
