Direct answer

Shopify recommends collaborator accounts for Partners who need to work on a client’s existing store.

What to remember
  • Before approving a request, confirm the agency name, Partner organization, sender, business email, project scope, named account lead, subcontractors, and expected dates.
  • Shopify lets the merchant generate a four-digit collaborator request code.
  • Shopify says collaborator accounts are the recommended path for Partners.

01

Checklist

  • Verify the Partner identity.
  • Use and rotate the request code.
  • Use collaborator access, not shared credentials.
  • Require two-step authentication.
  • Map tasks to permissions.
  • Bound theme permissions.
  • Review file dependencies.

Direct answer.

Shopify recommends collaborator accounts for Partners who need to work on a client’s existing store.[1]

A collaborator account is requested through the Partner or Dev Dashboard, approved by the merchant, limited to selected permissions, excluded from normal staff limits, protected by required two-step authentication, and removable from the Shopify admin.[1][2]

The agency should not ask for the merchant owner’s password. Shopify explicitly prohibits Partners from using merchant credentials.[1]

Verify the Partner identity.

Before approving a request, confirm the agency name, Partner organization, sender, business email, project scope, named account lead, subcontractors, and expected dates. Confirm through a known channel rather than approving a lookalike request.

Use and rotate the request code.

Shopify lets the merchant generate a four-digit collaborator request code.[2]

  1. Share the code privately.
  2. Wait for the expected request.
  3. Verify the Partner organization.
  4. Approve the minimum role.
  5. Generate a new code after onboarding when appropriate.

Changing the code blocks old codes. It does not remove an already approved collaborator.

Use collaborator access, not shared credentials.

Shopify says collaborator accounts are the recommended path for Partners.[1] A staff account can be justified when a task cannot be completed through collaborator access, but the reason should be documented.

Do not create a generic staff login shared by several agency employees. Named Partner users improve accountability and revocation.

Require two-step authentication.

Shopify requires two-step authentication for collaborator access.[2] The merchant should still require named users, removal of former agency staff, governed devices, and clean subcontractor controls. Two-factor authentication does not make excessive permissions harmless.

Map tasks to permissions.

Common SEO work can touch:

Content.

  • blog posts and pages;
  • navigation;
  • metaobjects;
  • redirects;
  • files.

Online store.

  • themes;
  • theme code;
  • preferences;
  • domains in limited cases.

Products.

  • titles;
  • descriptions;
  • collections;
  • images;
  • search listings.

Apps.

  • analytics;
  • feeds;
  • schema;
  • redirects;
  • reviews;
  • consent tools.

Build a task-to-permission table before approval.

Bound theme permissions.

Theme access can change storefront code. Require a duplicate theme or development workflow, preview, approval, rollback, change record, and production verification. A content task should not inherit unrestricted theme-code authority by default.

Review file dependencies.

Shopify documents that several content, product, and theme permissions can bring required file permissions with them.[3] Review automatically selected dependencies before saving the role.

A top-level label is not always the complete effective permission set.

02

Completion criteria

Separate app use, installation, and charges.

Distinguish:

  • access to an existing app;
  • permission to install or delete apps;
  • permission to approve app charges;
  • custom app development;
  • webhook creation.

An SEO agency can often use an existing analytics app without permission to install every future app. Paid-app approval should remain with the merchant unless procurement is explicitly delegated.

Exclude sensitive data.

Most technical SEO work does not require access to orders, customers, gift cards, payouts, finances, billing, users, or private API credentials. Do not grant broad Administrator access because the theme editor requested one dependent permission.

Change control.

For production changes, preserve:

CHANGE_ID:
THEME_OR_RESOURCE:
OLD_STATE:
NEW_STATE:
APPROVED_BY:
DEPLOYED_BY:
ROLLBACK:
VERIFIED_AT:

Offboarding.

  1. Export collaborator and role inventory.
  2. Transfer final theme and content work.
  3. Remove collaborator access.
  4. Review custom apps and webhooks.
  5. Revoke API credentials.
  6. Remove agency-owned integrations.
  7. Preserve analytics and Search Console ownership.
  8. Confirm billing.
  9. Verify storefront and checkout.

Checklist.

  • Partner identity verified.
  • Request code shared privately.
  • Collaborator account used.
  • Two-step authentication confirmed.
  • Tasks mapped to permissions.
  • Theme access bounded.
  • File dependencies reviewed.
  • App installation separated from app use.
  • Charge approval retained.
  • Customer and financial data excluded.
  • Production change control defined.
  • Named users required.
  • Offboarding completed.

Evidence limits.

Shopify roles and plan-specific features change. Effective permissions can include dependencies. Review the current permission screen and exact requested tasks before approval.

References

Sources behind this record

  1. Working on client storesShopify Help Center (accessed August 5, 2026)
  2. Collaborator accountsShopify Help Center (accessed August 5, 2026)
  3. Store permissionsShopify Help Center (accessed August 5, 2026)

Corrections

Correction history

No corrections recorded.

To report an error, use the public corrections path.

Claim limit

Shopify roles and plan-specific features change. Effective permissions can include dependencies. Review the current permission screen and exact requested tasks before approval.