# Connecting your own AI to Shopify, without handing it the keys | BYOM blog

URL: https://byom.co/blog/connect-chatgpt-to-shopify-the-safe-way  
Markdown: https://byom.co/blog/connect-chatgpt-to-shopify-the-safe-way.md  
Last updated: 2026-10-02

> The risks of giving an assistant store access, in plain words: what it can read, how injected instructions work, what least privilege means, and the Shopify settings that reduce each risk.

By Kina (Checked by the BYOM team). Published 2026-09-25. 9 minute read. Series: In control.

## Key takeaways

- OWASP names excessive functionality, excessive permissions and excessive autonomy as the three causes of excessive agency in an AI system.
- Customer names, emails and addresses are personal data under UK GDPR, so an assistant that can read them is a data protection decision.
- Shopify's store activity log shows at most 250 results, is read only and cannot be exported, so it cannot be your only record.

Giving an assistant access to a store is a decision about risk, and the risk comes from three places: what the assistant can read, what it can be tricked into doing, and what happens to the credential that connects it. This post sets out each in plain words, using the published guidance from OWASP, the UK government and Shopify, and ends with the settings that reduce them.

A companion post covers what a connection technically involves. This one is the risk model.

## What read access reveals

Start with the data. The ICO says personal data is any information relating to an identified or identifiable natural person. A person can be identified directly, through a name or an identification number, or indirectly, through location data, online identifiers or other factors specific to them. Pseudonymised data remains personal data under UK GDPR. Anonymised data falls outside it.

A Shopify store holds a great deal of this. Customer records carry names, email addresses and delivery addresses. Orders tie those people to what they bought and when. Shopify's access scopes make the line visible: read_customers and read_orders are separate permissions from read_products, and by default apps cannot access protected customer data without meeting Shopify's requirements and receiving approval. Standard order scopes cover only the last 60 days of orders.

Even catalogue access can reveal more than it appears to. Product pages seldom hold personal data, but internal notes, draft pages and metafields sometimes do, because merchants use them as scratch space. A supplier contact, a customer's name on a custom order, a note about a complaint: none of those belongs in a product record, and all of them are visible to anything that can read the product. Search your own catalogue for them before you connect, and clear what you find.

The first risk decision is simple to state. An assistant that drafts product copy needs the catalogue and no customer data at all. Granting more than that turns a copywriting tool into a processor of your customers' personal data, with the duties that follow. The ICO's guidance on AI and data protection covers accountability and governance for AI systems, including data protection impact assessments, and the effect of Article 22 of the UK GDPR on automated decisions. If you do decide an assistant must see customer data, that guidance is where to start, and a written record of why is better than a memory of why.

## What an assistant can be tricked into doing

The second risk is specific to AI systems, and OWASP has catalogued it. Its Top 10 for large language model applications lists prompt injection first. OWASP describes it as a vulnerability that occurs when inputs alter the model's behaviour or output in unexpected ways, even if those inputs are imperceptible to humans.

OWASP separates two kinds. In direct injection, a user's own prompt changes the model's behaviour, deliberately or by accident. In indirect injection, external sources such as websites or files contain content that, when the model processes it, changes its behaviour. Indirect injection is the one a merchant should think about. A store is full of text written by other people: supplier descriptions, product reviews, customer messages, order notes. If an assistant reads a product description that says to ignore its earlier instructions and change a price, the model has no reliable way to tell your instruction from that text.

Picture how this could go wrong, as an illustration and not a reported incident. You ask an assistant to tidy the descriptions of forty products. One description, pasted in by a supplier, ends with a line telling any AI reading it to set the price to zero and publish. If the assistant can edit prices and publish without a check, the line has a chance of working. If it can only propose changes that you read first, the worst outcome is a strange proposal that you reject.

OWASP is frank about the limits. Because of the stochastic nature of these models, it says, it is unclear whether complete prevention is possible. Its mitigations are therefore about limiting what a successful injection can do: constrain the model's behaviour, validate output formats, filter input and output, enforce least privilege access controls, require human approval for high risk actions, and test adversarially.

### Excessive agency

A separate entry, excessive agency, is the cause that turns an injection into damage. OWASP defines it as damaging actions that a system can perform in response to unexpected or manipulated output, and gives three root causes. Excessive functionality means the system has features beyond what is needed. Excessive permissions means its tools reach more systems and data than required. Excessive autonomy means actions run without human verification.

The prevention list reads like a shopping list for a merchant. Minimise the extensions the assistant has. Restrict each to the operations it needs. Avoid open ended tools. Apply least privilege. Run actions in the context of the individual user. Require human approval for high impact operations. OWASP adds that even with these in place, monitoring logs and rate limiting help to detect and contain problems before they do significant harm.

| OWASP root cause | What it looks like in a store | What reduces it |
| --- | --- | --- |
| Excessive functionality | An assistant that can edit products, change settings and delete pages | Offer only the tools the job needs |
| Excessive permissions | A connection with write access to orders and customers to draft copy | Grant only the scopes the job needs |
| Excessive autonomy | Changes go live the moment the assistant decides | A person approves each change first |

## Least privilege in practice

The UK government's 10 steps to cyber security, the NCSC guidance published on GOV.UK, states the principle plainly: all users of ICT systems should only be provided with the privileges that they need to do their job, often referred to as least privilege. The same guidance says unused or dormant accounts, perhaps provided for temporary staff or for testing, should be removed or suspended, and that the need to hold a privileged account should be reviewed more often than for a standard account.

Each of those lines maps onto Shopify. Shopify's guidance says each team member should have their own staff account with tailored permissions instead of sharing the owner's credentials, and its staff permissions allow access to be set at a granular level by role. Collaborator access given to an agency expires after 90 days of inactivity. App scopes are granted at install and can be reviewed afterwards.

Reviews need a rhythm. Put a quarterly date in the diary to go through the staff list, the collaborators and the installed apps, and to ask of each one whether it is still needed and whether its access still matches its job. Privileges tend to be added during a project and never removed afterwards. Least privilege is a habit you keep up, and the review is how you keep it.

The same GOV.UK page also says to avoid using a privileged account for day to day activities such as reading external email or browsing the internet. In a shop, that means the owner login, which can see everything and change anything, should not be the account a connected tool runs under. Create a staff account or a dedicated app with only what the job needs, and keep the owner login for the few tasks that require it.

## Protecting the account itself

A tidy set of permissions is little use if someone else can log in as you. Shopify says two step authentication means that even if someone else learns your password, they cannot log in without the second step. It supports authenticator apps, security keys and built in authenticators, with SMS text messages offered only to existing accounts and Shopify mobile prompts as a backup. Passkeys are a further option.

On some stores it is not optional. Using Shopify Payments requires two step authentication, and Shopify says it may require it on individual accounts for security reasons even if you did not turn it on. Plus stores can require it for every user. Partners must activate it to use a collaborator account. If any person with access to your store has not set it up, that person is the weakest point, whatever else you do.

Shopify's account security guidance also tells merchants to be cautious about suspicious links and attachments in email, SMS and websites, and to contact Shopify Support immediately if an account may be compromised. Attackers who want a store often start with a message to a member of staff, so staff awareness is part of the access model.

### The credential that connects the assistant

The connection itself is held together by an access token, which Shopify's documentation describes as a credential an app sends with each API request. Shopify says that because a token is scoped to a specific set of permissions and can expire or be revoked, a leaked token exposes only what it was granted. That is a reason to grant narrow scopes in the first place, and to prefer expiring tokens. It is also a reason never to paste one into a chat window, an email or a shared document, where it can be copied by people and systems you did not intend.

## What you can see afterwards

The last control is a record. The GOV.UK guidance says to monitor user activity, particularly all access to sensitive information and privileged actions such as creating accounts, changing passwords or deleting accounts, and to keep audit logs in a system separate from the one being monitored.

Shopify's store activity log is the native tool. It is read only and shows the date and time of recent actions by the owner or a user, with the name of the person, app or channel that took each one. Logged actions include deleting products, changing store settings and granting app access. It shows a maximum of 250 results, events cannot be expanded, and the information cannot be exported. Some entries show Shopify as the actor, which can mean automation, app syncing, sales channel operations or payment provider updates.

Those limits settle the question of whether it is enough. A log that holds the last 250 events and cannot be exported will not cover a busy store for long, and it records that something changed, not what the earlier value was. If an assistant changes your catalogue, you want a record of every change that you control, kept somewhere that does not depend on the assistant telling you.

Treat the log as a second witness and not as the record. It is useful for one question in particular: did anything happen that you did not expect? If a product vanished or a setting changed and nobody on your team did it, the entry will tell you which app or user the change came from, which is the starting point for cutting access off.

## An afternoon of checks

None of these checks needs a developer, and together they take a few hours. They are worth doing before you connect anything and again whenever someone new gets access, because the risks above grow with the number of people and tools that can reach the store.

- List everyone and everything with access to the store: staff, collaborators and installed apps. Remove what you no longer use.
- Confirm two step authentication is on for every person, starting with the owner.
- For each connected app, read the scopes it holds. Remove customer and order access from anything that does not need it.
- Decide whether an assistant will ever see customer data. If yes, write down the reason and read the ICO's guidance on data protection impact assessments.
- Check that nothing in the connection lets a change reach the store without a person approving it first.
- Find where the record of changes is kept, and check you can read it without the assistant.

## A record, and a way back

Every write waits for you to confirm. Product changes can be undone.

Product and catalogue text comes from you and your suppliers. BYOM tells your assistant to treat any instruction found inside that text as something to report to you, and never to act on it.

Related: [See the Shopify app](https://byom.co/shopify-app), [What BYOM is](https://byom.co/blog/what-byom-is).

## Sources

- [OWASP GenAI Security Project, LLM01 prompt injection, 2025](https://genai.owasp.org/llmrisk/llm01-prompt-injection/)
- [OWASP GenAI Security Project, LLM06 excessive agency, 2025](https://genai.owasp.org/llmrisk/llm062025-excessive-agency/)
- [GOV.UK, 10 steps to cyber security, managing user privileges](https://www.gov.uk/government/publications/10-steps-to-cyber-security-advice-sheets/10-steps-managing-user-privileges--11)
- [ICO, what is personal data, UK GDPR guidance](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/personal-information-what-is-it/what-is-personal-data/what-is-personal-data/)
- [ICO, guidance on AI and data protection](https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/)
- [Shopify developer documentation, API access scopes, 2026](https://shopify.dev/docs/api/usage/access-scopes)
- [Shopify Help Centre, two step authentication, 2026](https://help.shopify.com/en/manual/your-account/account-security/two-step-authentication)
- [Shopify Help Centre, account security, 2026](https://help.shopify.com/en/manual/your-account/account-security)
- [Shopify Help Centre, store activity log, 2026](https://help.shopify.com/en/manual/shopify-admin/activity-logs)
- [Shopify Help Centre, collaborator accounts, 2026](https://help.shopify.com/en/manual/your-account/staff-accounts/collaborator-accounts)
- [Shopify developer documentation, access tokens, 2026](https://shopify.dev/docs/apps/build/authentication-authorization/access-tokens)
