Staff access audit
Staff access audit: permission drift is not a one-time user list
A staff access audit re-checks staff, collaborators, and installed-app scopes after the last review — including AI apps that can read customer or order data. Users and permissions is only a snapshot.
Live listing: apps.shopify.com/momiji-access-audit. The first audit runs on install. The app scores and flags. It does not revoke staff or attest that the store is secure.
Adjacent jobs: PO box blocker · B2B purchase order · CRA duty records.
Opening Users and permissions today is a snapshot. It is not a drift log. Scopes, owners, and recorded costs can move after you last checked.
Leftover Admin access checklist (no install)
Score questions people actually post: a former staffer holding the only 2FA, collaborator access versus org billing, and who can publish a theme versus only preview. The checklist does not open Admin and does not scrape the store.
Open the leftover Admin access checklist — nine questions, scored in the browser, then an Install path if you want the same review to re-run.
Install, run the first audit, then keep the evidence
Opening Users and permissions today is a snapshot. The paid path is a scored audit you can re-run when staff, collaborators, or installed-app scopes move.
- Install Access Audit Guard from the App Store.
- Wait for the first audit on install (or run another now).
- Review staff/collaborator reminders and apps that can touch customer or order data - including AI apps with broad scopes.
- Export CSV or PDF evidence on plans that include those exports.
- Re-run when owners, scopes, or costs change.
The app scores and flags access. It does not revoke staff, uninstall apps, or attest that the store is secure.
Demo
Short walkthrough of the app flow. Then follow the start path below.
People on the staff list are not the same inventory as app scopes
The staff and collaborator list answers “who can open Admin?” Installed-app scopes answer a different question: “which apps can read or write customer, order, or broad store data?”
A one-time screenshot of Users and permissions misses both problems after the next change:
| Inventory | What moves after a review | Caught by a one-time user list? |
|---|---|---|
| Staff / collaborators | New invites, role edits, overdue 30/90-day reviews | No history, no overdue flag |
| Installed apps (including AI) | New installs, scope grants, owner or cost drift | No scored scope risk |
| Access audit with re-run | Scopes + owners + costs + review cadence | Yes, if you re-run and keep the export |
Treat AI assistants like any other installed app with protected customer-data or broad-write scopes. They will not appear as “staff.” Put them on the scope inventory, not on the people list.
Suggested path (unchanged job, sharper test):
- Install Access Audit Guard from the App Store.
- Wait for the first audit on install (or run another now).
- Review staff/collaborator reminders and apps that can touch customer data.
- Export CSV or PDF evidence on plans that include those exports.
- Re-run when owners, scopes, or costs change.
Free: Audit score + staff reminders. Pro ($19/month): Free + CSV export + drift alerts. Business ($49/month): Pro + PDF evidence packs.
Start path: audit, then re-check drift
- Open the Access Audit Guard listing (
apps.shopify.com/momiji-access-audit) and install it on the store that needs a staff access audit. - Wait for the first audit — the listing states it runs automatically on install. You can run another at any time.
- Review staff and collaborator access (30/90-day reminders), and check which apps — including AI apps — can read or write customer data.
- Export CSV or PDF evidence on the plans that include those exports. Re-run when owners, scopes, or costs change.
The app scores and flags access. It does not revoke staff, uninstall apps, or attest that the store is secure.
Snapshot vs a recurring access audit
| Control | What it sees | Permission drift? |
|---|---|---|
| Users and permissions screen | Who currently has staff or collaborator access | No history, no overdue review flags |
| Installed-app list | Which apps are installed | No scored scope risk, no customer-data flag |
| One screenshotted user list | That day’s snapshot | Stale the next time a role or scope changes |
| Access audit with drift alerts | Scopes, owners, costs, staff review cadence | Yes, if you re-run and keep the evidence |
Example fields you keep against a review (paraphrase, not a form):
staff / collaborator
last review date
overdue? (30 / 90 day)
installed app
granted scopes
customer-data or broad-write flag
risk score
owner / cost drift since last audit
How a recurring staff permissions audit differs from a snapshot
A Users and permissions screen is today’s list. A recurring staff permissions audit re-checks staff, collaborators, and granted scopes after that snapshot, so permission drift is a later record you can export — not a screenshot that goes stale after the next role or app-scope change.
What this page is not
- Not a security attestation, SOC report, or automatic remediation.
- Not employee monitoring or a customer-data export.
- Not a B2B purchase-order rule. That job is require a PO number on B2B checkout.
- Not catalog readiness for AI shopping agents. That path is llms.txt, crawler rules, and product JSON-LD.
- Not CRA product duty / Article 14 incident records. That path is Cyber Resilience Act duty files.
Does a one-time admin user list catch staff permission drift?
No. Users and permissions show who currently has access. They do not keep a review cadence, overdue flags, or a log of what changed since the last check. Collaborators, staff roles, and installed-app scopes can all move after you last opened that screen. A later audit is a different record from a screenshot of today’s list.
Do installed apps, including AI assistants, show up on the staff list?
Not as a scored access review. Installed apps request scopes, including apps that can read customer or order data. The staff list is people. Scope risk is a separate inventory: which app was granted protected customer-data or broad-write access, and whether that set drifted after the last audit.
What counts as permission drift?
A change after the last scheduled audit: granted scopes, app owners, or recorded costs. Staff and collaborator reviews that go past a 30- or 90-day reminder are overdue, not merely “still installed.” Duplicate paid categories are a cost-drift signal, not a permission grant by themselves.
Does an access audit remediate risky staff or apps?
No. An audit scores and flags. It does not revoke staff, uninstall apps, or attest that the store is secure. You still review findings before you change access. It is not attorney advice, a SOC report, or employee monitoring.
Does the audit read customer or order bodies?
The listing’s job is store-level audit metadata, app scope findings, a manual access register, and report history. It does not store customer data bodies, order contents, screen recordings, or employee-monitoring events. Confirm the live privacy text, not this page.
How do I keep evidence of an access audit?
Run the audit, review staff and collaborator reminders, and export CSV or PDF evidence on the plans that include those exports. A first audit can run on install; you can run another at any time. Keep the export with the date you reviewed it.
Where do I run a staff and app-scope access audit?
Use an access audit that scores installed-app scopes (including AI apps), flags customer-data access, tracks staff and collaborator reviews, and alerts on scope, owner, or cost drift. Access Audit Guard is the App Store listing this site already uses for that job. Open the listing, install, wait for the first audit, then export evidence if you need a file.
Related pages
- Access Audit Guard — live App Store listing
- Leftover Admin access checklist — leavers with 2FA, collaborators vs the bill, preview vs publish
- Staff access audit install page
- Cyber Resilience Act duty records — product cybersecurity duties, not staff scopes
- Catalog readiness for AI shopping agents — crawler rules, not staff scopes
- Require a PO number on B2B checkout
- Shopify apps hub
- Tools
Not a security attestation. Not attorney advice. Not employee monitoring. The app scores and flags access you already granted; you choose what to change.