Approval Workflows for Changes to Live Shopify Stores
Refunds, stock edits and discounts change a live store instantly. How to set roles, approvals and an audit trail so your team moves fast without costly mistakes.
In a Shopify store, most changes go live the moment someone presses save. That speed is great for a solo merchant. For a team, it means one mistyped discount, one refund to the wrong order or one stock count set to zero reaches customers straight away, and nobody else saw it coming.
An approval workflow puts a second pair of eyes on the changes that cost money, without slowing down everything else.
Which changes deserve a second look
Not every edit needs approval. Sort changes by what a mistake would cost:
| Change | Cost of a mistake | Suggested control |
|---|---|---|
| Refunds, cancellations, payment captures | Money leaves or is lost, often irreversibly | Owner only |
| Inventory levels | Overselling, or products hidden as sold out | Approval required |
| Discounts | Margin lost on every order until noticed | Approval required |
| Product tags | Collections or filters shift | Automatic |
| Customer notes, blog posts | Low and easy to fix | Automatic |
The rule of thumb: the harder a change is to undo, and the more money it moves, the more control it needs.
The building blocks
1. Roles
Start with a small set of roles and give each person the lowest one that lets them do their job:
- Admin: manages people, settings and the audit log.
- Manager: approves changes and sees every screen.
- Staff: does the daily work on the screens and stores they have been given.
Limit staff by screen (someone handling support may not need inventory) and by store (a contractor working on one brand should not see the others).
2. Approval levels per type of change
For each risky change, decide whether it applies automatically, waits for approval, or can only be done by an owner. Allow the level to differ per store: a test store can be relaxed while the main store stays strict.
3. A before-and-after view
An approver should see exactly what will change, how many objects it touches, and whether it can be undone. “Approve change #482” with no detail turns approvals into rubber-stamping.
4. An audit log
Record sign-ins, failed sign-ins, role changes and other sensitive actions, newest first. When something goes wrong, the first question is always “who changed this, and when?”
5. Two-factor sign-in for everyone
Roles and approvals mean little if a password is phished. Require two-factor sign-in for the whole team, not as a personal choice.
Rolling it out without slowing the team
- Start strict on money, relaxed on the rest. Put refunds and payment captures behind the owner, stock and discounts behind approval, and leave everything else automatic.
- Name approvers for each store so requests do not sit waiting.
- Review after two weeks. If an approval type is always granted without changes, consider relaxing it. If mistakes still slip through, tighten it.
- Check the audit log monthly, especially after someone leaves the team.
How Storefleet handles approvals
In the Storefleet web dashboard, refunds, cancellations, payment captures, inventory levels, discounts and product tags go through approval, and each has a level: automatic, approval required, or owner only. Refunds, cancellations and payment captures are always owner-only, and that level cannot be relaxed. A pending change shows a before-and-after and how many objects it touches, and it is flagged when it cannot be undone. Levels can be set for each store.
Every member is an admin, a manager or staff, staff can be limited by screen and store, an admin can require two-factor sign-in for the whole workspace, and an audit log records sensitive actions. The full list is on our security page.
In the app inside Shopify admin, a change applies when you press the button, as it would in Shopify admin itself; approvals are a feature of the web dashboard. If your team works across several stores, read how to manage multiple Shopify stores next.