An agency needs access scoped to the work in the contract, which for most engagements means themes and products, sometimes apps, and rarely orders or finance. Proposing the narrow set themselves is one of the cheapest trust-building moves an agency has available, and it removes the offboarding conversation at the end of the engagement.
What this person actually does
Agency work varies more than any other role here. A theme build needs theme access and essentially nothing else. A migration needs far more. An ongoing retainer sits somewhere between and drifts upward over time unless somebody resets it.
The usual arrangement is bad for both sides. The client hands over far more access than the work requires because narrowing it is effort, and the agency accepts it because asking for less feels like an odd conversation to start.
It is not odd, it is professional. An agency that scopes its own access is signalling that it has thought about the client's risk, which is exactly what a client wants to believe about a supplier holding their keys.
The two layers
Shopify permissions decide what they can do in the admin. The Store Huddle role decides what they see in the workspace. Both are needed, and they are set separately.
| Layer | For this person | Why |
|---|---|---|
| Shopify staff account | Required, per person | Not one shared login for the agency |
| Shopify permissions | Scoped to the contracted work | Theme work needs themes, not orders |
| Store Huddle role | Custom, or a scoped set of rooms | Client visibility without admin |
| End date | Contract end, set at grant | The engagement has a date; so should access |
Shopify access to grant
Scope to the contract rather than to the relationship. Shopify's permission labels change from time to time, so these are described by what they control rather than quoted as exact checkbox names. Check the current names in your own admin.
- Themes, for any front-end work. This is often the entire requirement.
- Products, where the work touches catalogue structure or merchandising.
- Apps, only where installing or configuring them is contracted.
- Reports, if performance work is in scope, which is usually preferable to granting finance access.
- Individual accounts per person, never one shared agency login, because a shared login makes both audit and offboarding impossible.
Access to withhold, and why
- Finance and payouts, unless the engagement is genuinely financial.
- Customer data, unless the work requires it. This is the one with regulatory weight, and it should appear in your data processing agreement if it is granted.
- Settings and staff management. An agency should not be able to add people.
- Anything for a person who has rotated off the project, which is where agency access quietly accumulates.
Rooms they belong in
A scoped client room gives an agency the visibility a weekly status call was standing in for, without giving them the admin.
- A shared project room with the client, which is the whole engagement.
- Read access to the relevant operational room, if their work depends on knowing what is happening in it.
- Not internal management or finance rooms.
- Not rooms belonging to other agencies or contractors working on the same store.
Offboarding
Set the end date to the contract end date, at the moment access is granted. Extend it deliberately if the engagement extends.
Remove per-person, and check for people who rotated off the project earlier. Agency teams change without the client being told, and access granted to a developer who left the agency six months ago is nobody's responsibility until it is.
Handover is the moment to do this properly, because it is the last point at which both sides are paying attention. There is more in client communication after handover.
Common questions
What Shopify access should I give an agency?
Scope it to the contracted work. Theme work needs theme access and usually nothing else. Grant individual accounts per person rather than one shared agency login.
Should an agency have admin access?
Rarely. Most agency work needs themes, products and sometimes apps. Full admin is the path of least resistance rather than a requirement, and it makes offboarding harder.
How do agencies give clients visibility without admin access?
A scoped shared room where the work is discussed, which is what the weekly status call was substituting for. The client sees progress without the agency needing broader permissions.
What happens to access when the engagement ends?
It should already have an end date set from the contract. Remove per person, and check for agency staff who rotated off the project earlier and were never removed.