Leftover Admin access
Leftover Admin access: leavers with 2FA, collaborators vs the bill, preview vs publish
People post about a former staffer holding the only 2FA, a collaborator who can edit the store while you still pay the bill, and who can publish a theme versus only preview. Score those questions here. Nothing is scraped from Admin.
No install is required for the score. Install is the path if you want the same review to re-run when people or scopes move.
Parent guide: permission drift is not a one-time user list. Adjacent jobs: PO box blocker · CRA duty records.
What you score here
Nine questions. Each gap answer adds one point. The total is leftover-access hygiene, not a security grade.
| Pain people post | Question this page asks |
|---|---|
| Former staffer holds the only 2FA | Is the authenticator still on a device you no longer control? |
| Collaborator access vs org billing | Can someone edit the store while the bill stays on your org? |
| Preview theme vs publish | Who can publish live, not only preview, since the last leave? |
Users and permissions is a snapshot. This checklist asks whether that snapshot still matches who can sign in, who can publish, and who you still pay for.
Answer these leftover-access questions
Pick one answer per question. Scoring stays in this browser. Nothing is posted and no Admin API is called.
After the score: keep a review you can re-run
The checklist is a one-pass self-score. It goes stale the next time someone leaves, a collaborator is invited, or publish rights move.
- Open the Access Audit Guard listing (
apps.shopify.com/momiji-access-audit) and install it on the store you just scored. - Wait for the first audit on install, or run another now.
- Review staff and collaborator reminders, and apps that can touch customer or order data.
- Export evidence on the plans that include those exports. Re-run when owners, scopes, or costs change.
The app scores and flags access you already granted. It does not revoke staff, uninstall apps, or attest that the store is secure. Confirm plan details on the live listing. This page does not add prices.
Live listing: apps.shopify.com/momiji-access-audit.
What this page is not
- Not a generic security audit, SOC report, or attestation that the store is secure.
- Not employee monitoring, and not a customer-data or order-body export.
- Not attorney advice. This score is not legal advice.
- Not a store scrape. Answers stay in this browser.
- Not a B2B purchase-order rule. That job is require a PO number on B2B checkout.
Do I need to install an app to run this leftover Admin access checklist?
No. This page scores answers you type yourself. Nothing is sent to a store, and nothing is scraped from Admin. Install is only if you want a re-runnable review with reminders and an export you can keep.
What does this leftover Admin access checklist score?
Review hygiene for staff, collaborators, and installed-app scopes — including whether customer-data access is inventoried and whether a dated export exists. It is not a security grade, not a SOC report, and not an attestation that the store is secure.
Does a high score mean the store is secure?
No. A low gap count only means you said the last review, collaborator cadence, and app-scope inventory are current. The checklist cannot see Admin. It does not revoke staff or uninstall apps.
Is this a security audit or employee monitoring?
Neither. The questions are leftover Admin access: a former staffer holding the only 2FA, collaborator access versus org billing, and who can publish a theme versus only preview. It is not a generic security audit and not employee monitoring.
Where do I keep an ongoing leftover-access review?
Use an access audit that re-checks staff, collaborators, and installed-app scopes after the last review and can export evidence. Access Audit Guard is the App Store listing this site already uses for that job. Open the listing, install, wait for the first audit, then export if you need a file. Confirm live listing text, not this page.
Related pages
- Staff permission drift access audit — snapshot vs a recurring review
- Staff access audit install page
- Access Audit Guard — live App Store listing
- Cyber Resilience Act duty records — product cybersecurity duties, not staff scopes
- Shopify apps hub
- Tools
Not legal advice. Not a security attestation. Not employee monitoring. The score is from answers you give; you choose what to change. The app scores and flags access you already granted.