Agency Access to Client Shopify Stores: Staff, Collaborators, AI

Agencies juggle collaborator accounts, staff limits and now AI tools across client stores. The Shopify rules to know and how to keep each person to their stores.

An agency with many client stores does not have one access problem, it has one per store. Each store grants access separately and has its own staff limit. Add a freelancer, a virtual assistant and an AI tool or two, and “who can change what, on which store?” becomes hard to answer.

This guide covers the Shopify rules behind client access, how to keep each person to the stores they work on, and how to bring AI tools in without losing track.

How collaborator accounts work

Most agencies reach client stores through Shopify collaborator accounts. The rules are worth knowing in detail (Shopify Help Center):

  • Access starts with a 4-digit collaborator request code that the store gives you.
  • Only the store owner or a user with the Administrator role can grant collaborator access.
  • Collaborators can’t be given the Administrator role.
  • Collaborators don’t count toward the store’s user limit.
  • If a collaborator hasn’t logged in to the store within 90 days, their access expires automatically.

With many clients, keep your own list of which store granted what, and keep your own record of the changes your team makes, so you can answer a client without searching chat history.

Staff limits per Shopify plan

When a client adds your team as staff instead, their plan sets the ceiling. Shopify lists the maximum users per plan as 0 on Basic, 5 on Grow, 15 on Advanced and unlimited on Shopify Plus. The store owner, collaborators and POS-only staff don’t count toward that limit (Shopify Help Center).

Shopify also advises giving sensitive permissions only to your most trusted users (Shopify Help Center). For an agency, that means planning access store by store, and keeping refunds and captures behind an owner’s approval rather than handing them to everyone who works on the store.

Where sign-off goes wrong

Agencies running many client stores often approve changes in Slack threads and spreadsheets, away from the store they change. That works until a client asks “who refunded this order?” and the answer is buried in a chat. A sound setup has four parts:

  1. One account per person, with a role and the client stores they are assigned to, and nothing else.
  2. Approval in one place, next to the change itself, for the changes that cost money.
  3. A record per change: who asked, who approved, and what it looked like before and after.
  4. Two-factor sign-in for everyone, because roles mean little if a password is phished.

Bringing AI tools onto client stores

Treat an AI connection like a new team member: decide which stores it reaches, what it may change, and how you will see what it did. Not every tool asks before it acts.

How Storefleet works for agencies

In Storefleet for agencies, you link each client store to one workspace with its connection key and group stores by client. Admin > Users & Roles gives each person one account, a role and the stores they are assigned to, so a contractor with the staff role on one client sees that client. Admin > Security can require two-factor sign-in for the whole workspace, and Admin > Audit shows who did what, and when.

In the web dashboard, each store has its own approval levels, and refunds, cancellations and captures are always owner-only. Every pending change across client stores sits in one Approvals list, and each change is approved for its own store. After an approved change is written, Storefleet reads the store back from Shopify before marking it applied, and the Ledger records who asked, who approved and the before and after: the record to show a client.

For AI, there are two routes, with different controls:

  • Your own AI tool through MCP (Pro plan). A connection covers the whole workspace or one store. MCP connections have no approval step: a connection created by an admin or manager can act right away, refunds included, while a store connection created by staff can only apply the changes that store allows without approval. Every MCP write is recorded as made by AI, writes can be rolled back where Shopify allows it, and an admin can revoke a connection or turn MCP off for the workspace. To let a freelancer’s AI tool work on one client store, give the freelancer a staff account on that store, set the store’s approval levels first, and have them create a store connection.
  • StoreFleet Agent (Mac preview / early access). The agents run on your Mac with the model you bring, whether Claude Code, an API key or a model on your own Mac; StoreFleet does not resell model usage. Here refunds, cancellations and captures always wait for a person.

Read connect AI tools like Claude to your Shopify store with MCP for the basics, and see pricing for which plan includes MCP.

Summary

Know the collaborator and staff rules, give each person only the client stores they work on, keep approvals and the record next to the change, and set each AI connection’s reach before it touches a client store.

Install Storefleet Store Ops on Shopify and bring your client stores into one workspace.

Sign in to your workspace

Each workspace has its own address: <workspace>.getstorefleet.com. Enter your workspace name, or paste its address, and we take you to its sign-in page.

You will go to

New to StoreFleet? Create a workspace