Skip to main content

Shopify: Critical Access Advisory

  • App install: Arbitrary app installation and improper configuration may lead to UX inconsistency, security vulnerabilities, data breaches and performance degradation.
    • New app installation requests follows the following process:
      • The app user team creates a request on #tech-requests channel. We ask for the following details in the request so that the approver have enough context
        • Purpose / use cases (also add a shared document link demonstrating the use cases, if applicable)
        • Which team will be using it?
        • For paid apps: How much will it cost per month? (also cost justification, and are the costs already approved in your team budget / will it require approval?)
      • Then, once the request is approved, tech evaluates the app, assesses impact on the production site, any side effects on site performance and such.
      • Tech executes the installation (if applicable), and monitor the app for potential impact on site performance and operational / maintenance overhead if any.
      • Tech team then provides access to the installed app to the app user team
  • Online store (theme: edit code): Changes may affect/break website appearance, functionality, performance, and SEO. All theme codes are version controlled and are managed by tech team for feature development, bug fixes, UX improvements, and to satisfy operational needs. Any change made directly to the theme code without going through proper development and testing process may lead to unexpected issues.
  • Online store (theme edit): Direct theme edits may lead to UX inconsistency, performance degradation, and SEO issues. Once a theme and/or feature is established, tech provides necessary metaobjects and metafields that operations and marketing teams can use to manage content. Direct edits may lead to inconsistency and unexpected issues.
  • Products: Deletion may affect SEO and customer (including legacy customers) experience.
  • App development: Credentials disclosure may lead to unauthorized access and data breaches.
  • Content (meta objects and metafields): Definition modification/deletion may lead to data loss and affect reporting.
  • Checkout and customer accounts: Changes may affect data collection flow, break ordering and fulfillment process.
  • Orders (any kind), and Customers: Deletion may lead to data loss and affect reporting.
  • Store settings (manage settings): May affect store operations, configuration, and availability.
  • Finance: May impact operations and may lead to financial data disclosure

This is not an exhaustive list of potential risks. When you are granted any of the above mentioned access, please proceed with caution and reach out to tech team if you have any questions or need assistance.