Leftover Admin access

Leftover Admin access: leavers with 2FA, collaborators vs the bill, preview vs publish

People post about a former staffer holding the only 2FA, a collaborator who can edit the store while you still pay the bill, and who can publish a theme versus only preview. Score those questions here. Nothing is scraped from Admin.

No install is required for the score. Install is the path if you want the same review to re-run when people or scopes move.

Parent guide: permission drift is not a one-time user list. Adjacent jobs: PO box blocker · CRA duty records.

What you score here

Nine questions. Each gap answer adds one point. The total is leftover-access hygiene, not a security grade.

Pains this page asks about
Pain people post Question this page asks
Former staffer holds the only 2FA Is the authenticator still on a device you no longer control?
Collaborator access vs org billing Can someone edit the store while the bill stays on your org?
Preview theme vs publish Who can publish live, not only preview, since the last leave?

Users and permissions is a snapshot. This checklist asks whether that snapshot still matches who can sign in, who can publish, and who you still pay for.

Answer these leftover-access questions

Pick one answer per question. Scoring stays in this browser. Nothing is posted and no Admin API is called.

1. Does a former staffer still hold the only 2FA / authenticator for Admin?
2. Can a collaborator edit the store while org billing stays on your account?
3. Who can publish a live theme versus only preview — checked since the last leave?
4. Is anyone who left still on Users and permissions?
5. Do you have a written inventory of installed apps that can read customer or order data?
6. When did you last open Users and permissions?
7. Is any collaborator past a 90-day review?
8. Have AI or assistant apps with customer-data scopes been reviewed since install?
9. Do you have a dated export of the last access review?

After the score: keep a review you can re-run

The checklist is a one-pass self-score. It goes stale the next time someone leaves, a collaborator is invited, or publish rights move.

  1. Open the Access Audit Guard listing (apps.shopify.com/momiji-access-audit) and install it on the store you just scored.
  2. Wait for the first audit on install, or run another now.
  3. Review staff and collaborator reminders, and apps that can touch customer or order data.
  4. Export evidence on the plans that include those exports. Re-run when owners, scopes, or costs change.

The app scores and flags access you already granted. It does not revoke staff, uninstall apps, or attest that the store is secure. Confirm plan details on the live listing. This page does not add prices.

Install Access Audit Guard

Live listing: apps.shopify.com/momiji-access-audit.

What this page is not

Do I need to install an app to run this leftover Admin access checklist?

No. This page scores answers you type yourself. Nothing is sent to a store, and nothing is scraped from Admin. Install is only if you want a re-runnable review with reminders and an export you can keep.

What does this leftover Admin access checklist score?

Review hygiene for staff, collaborators, and installed-app scopes — including whether customer-data access is inventoried and whether a dated export exists. It is not a security grade, not a SOC report, and not an attestation that the store is secure.

Does a high score mean the store is secure?

No. A low gap count only means you said the last review, collaborator cadence, and app-scope inventory are current. The checklist cannot see Admin. It does not revoke staff or uninstall apps.

Is this a security audit or employee monitoring?

Neither. The questions are leftover Admin access: a former staffer holding the only 2FA, collaborator access versus org billing, and who can publish a theme versus only preview. It is not a generic security audit and not employee monitoring.

Where do I keep an ongoing leftover-access review?

Use an access audit that re-checks staff, collaborators, and installed-app scopes after the last review and can export evidence. Access Audit Guard is the App Store listing this site already uses for that job. Open the listing, install, wait for the first audit, then export if you need a file. Confirm live listing text, not this page.

Install Access Audit Guard

Related pages

Not legal advice. Not a security attestation. Not employee monitoring. The score is from answers you give; you choose what to change. The app scores and flags access you already granted.