Commerce OS guide

Team Access

Guide status: Administration guidance. Last reviewed 14 August 2026. Shopify and Liva 7 permission models must be verified in the current applications before roles are assigned.

Purpose

Team access should give each person enough authority to perform their role without combining unnecessary data access, policy control, approval and publication power. Separation of duties protects the store while keeping daily work practical.

Before you begin

  • List the people and service accounts that currently access Shopify and Liva 7.
  • Identify who owns the store, integration, merchandising, content, measurement, privacy, billing and support processes.
  • Confirm which controls exist in each system; do not assume a Liva 7 role overrides Shopify permissions.
  • Remove or disable access that no longer has a current business purpose.

Practical role patterns

An observer may review operating briefs, evidence and performance without changing policies or publishing. A specialist may prepare recommendations or content within a defined workspace. An approver may accept or decline specified action types. An administrator manages configuration, access and governance. The store owner retains Shopify account and billing authority.

These are operating patterns, not claims about implemented role names. Map them to the controls actually available and document any gap.

Separate sensitive duties

  • Where practical, the person preparing a high-impact change should not be its only approver.
  • Changing an Auto-execute policy should require stronger authority than viewing its history.
  • Billing approval and plan administration should remain with an authorised commercial owner.
  • Customer-level data should be available only to roles that genuinely require it.
  • Support access should be time-bound and limited to the diagnostic need.

Manage the access lifecycle

Grant access for a named purpose, use the lowest suitable level and record the owner. Review access after role changes, contractor end dates, security events and material product changes. Revoke access promptly without deleting the person's historical decisions or actions.

Use individual accounts and the security controls provided by Shopify and Liva 7. Do not share passwords, recovery codes, access tokens or owner credentials.

Safe use and fallback

If the required separation cannot be enforced technically, use an explicit operating procedure and review record until the control exists. Do not broaden access simply to bypass a workflow problem. When a critical owner is unavailable, follow the merchant's authorised recovery process rather than sharing credentials.

You are finished when

  • each person has a named purpose and appropriate access;
  • policy, approval, publication and billing powers are intentionally assigned;
  • access review and revocation have owners; and
  • historical accountability survives staff changes.