
Shopify Admin Security Audit: Logs, Staff Access, and Privacy
The admin-side audit most Shopify owners skip: an admin-side checklist for activity logs, staff access and permissions, two-step authentication, app data access, and privacy settings, with exact admin paths.
Most Shopify audits stop at the storefront: , product pages, checkout. They skip the back office, which is where a compromised login or an over-permissioned app does the most lasting damage. A Shopify admin security audit fixes that blind spot by reviewing the admin side of your store: who can get in, what they changed, which apps can read your data, and whether your security and compliance settings are correct. Verizon's 2024 Data Breach Investigations Report found that a non-malicious human element was involved in around 68% of breaches.
This checklist walks each admin-side area with the exact path, what to look for, and where Shopify's built-in tools fall short.
What Is a Shopify Admin Security Audit?
A Shopify admin security audit is a periodic review of your store's admin settings, user access, and data permissions, separate from the customer-facing storefront. A storefront audit asks whether shoppers can find products and check out. An admin security audit asks whether the store itself is secure, accountable, and compliant behind the login.
The two are complements. For the storefront side, work through the Shopify audit checklist or the step-by-step Shopify store audit walkthrough. This guide covers the back office those checks leave out: activity logs, staff access, two-step authentication, app data access, and store policy settings.
The Shopify Admin Security Audit Checklist
Each check below takes a few minutes inside your Shopify admin. Run the full set quarterly, and again after any staff change, app install, or ownership handover.
| # | Check | Where in admin | Priority |
|---|---|---|---|
| 1 | Review the store activity log | Settings > General > Store activity log | Medium |
| 2 | Remove stale staff and tighten permissions | Settings > Users | Critical |
| 3 | Check login history for each user | Settings > Users > user | Critical |
| 4 | Require a secure sign-in method for each user | Settings > Users > user | Critical |
| 5 | Review third-party app access | Settings > Apps and sales channels | Critical |
| 6 | Audit collaborator access | Settings > Users (Requests) | Medium |
| 7 | Check store policies are complete | Settings > Policies | Medium |
| 8 | Review customer privacy and cookie settings | Settings > Customer privacy | Medium |
| 9 | Handle customer data export and erasure requests | Customers > profile > More actions | Medium |
| 10 | Check tracking consent and Network Intelligence | Settings > Customer privacy; Settings > Customer events | Medium |
| 11 | Verify tax registrations and settings | Settings > Taxes and duties | Medium |
The checks marked Critical sit around account access and data, where one gap can expose customer information or hand control to the wrong person. Start there.
Check the storefront side of your store automatically
How Do You Review the Store Activity Log?
The store activity log records recent admin actions: deleted products, changed settings, new app installs, and similar events. Find it at Settings > General > Store activity log, where it also appears as a link in the Resources section of General settings (Shopify activity logs documentation).
Read it for anything you do not recognize: a setting changed outside your team's hours, an app nobody remembers installing, a product removed without a reason. The log shows who made each change and when.

Know its limits before you lean on it. The store activity log shows only the 250 most recent actions, has no built-in filtering, and cannot be exported. For a store with several staff or many daily changes, 250 actions might cover only a day or two. When you need longer history, before-and-after detail, or alerts, that gap is what a dedicated activity-log app or a regular export of the separate user activity log (below) fills.
How Do You Audit Staff Accounts, Permissions, and Logins?
Staff access is the part of this audit with the most at stake, because every active account is a door into your admin. Manage users at Settings > Users, and work through three things.
First, remove people who no longer need access. Former employees, agencies whose project ended, and one-off contractors should not keep standing access to your store.
Second, tighten permissions to least privilege. Shopify lets you build roles and assign only the permissions each person needs (Shopify staff and permissions documentation). A marketing hire rarely needs to edit payment settings or export the full customer list. Give every user the lowest level of access their role actually requires, and remove accounts the moment they are no longer needed.
Third, check login history. Open a user and find the Recent access to store section, which lists the five most recent sessions with their date, IP address, ISP, and location. Because it shows only those five, make this a regular check rather than a one-off, since a sign-in from an unfamiliar location or ISP can signal that an account has been compromised (Shopify user activity and login history documentation).
Customer account access is another part of your security workflow worth reviewing, especially for support teams. When agents need to troubleshoot an issue directly, asking customers to share their account details creates an unnecessary security risk. Instead, a tool like Magefan Shopify Login as Customer app allows authorized staff to access customer accounts without requesting or handling login details. This makes it easier to reproduce account-related issues while keeping customer credentials private.
Staff seats are plan-gated, which shapes how you structure access. On current plans, Basic includes 0 staff accounts, Grow adds 5, Advanced 15, and Plus is unlimited (Shopify plan and user requirements). Collaborator accounts, used by agencies and freelancers who request access through the Shopify Partner program, do not count toward that limit, so audit them separately under the Requests view and remove any whose work has finished.
For a record that outlasts the 250-action store log, the user management activity log at Settings > Users > Security tracks staff changes and security events, and it exports as a CSV covering up to the last six months. That export makes it the better evidence trail for accountability or compliance.
How Do You Enforce Account Security and Two-Step Authentication?
A secure sign-in method, such as two-step authentication or a passkey, is one of the most effective controls on this list, because it blocks the stolen-password attacks behind so many breaches. Each user sets up their own method, since the store owner cannot configure it for someone else.
Enforcement works at two levels. On any plan, an admin can require a secure sign-in method for an individual user from that user's page at Settings > Users > user (Shopify secure sign-in documentation). The user still picks the method, a passkey or two-step authentication, but cannot skip it. What Shopify Plus adds is requiring it for every user across the organization at once, from Settings > Users > Security, instead of user by user. One default already helps on every plan: Shopify Payments requires two-step authentication, so anyone who manages payouts is covered.

If you work with a Shopify Partner or agency, their collaborator access carries the same protection. Partners must have two-step authentication enabled to use a collaborator account at all.
See the storefront issues an admin audit can't catch
How Do You Review Third-Party App Access?
Every app you install asks for permission to read or change parts of your store, and that access keeps running until you remove it. Open Settings > Apps and sales channels to see everything installed.
For each app, open its page and find the Activity and permissions section. It shows which areas of your store the app can view or edit, when it last did anything over the past 30 days, and an Unused access list that flags permissions the app holds but has not used (Shopify working-with-apps documentation). Ask three questions:
- Do you still use it? If not, uninstall it.
- Does it need the data it can reach? An app that reads customer or order data deserves more scrutiny than one that only touches theme files.
- Is the access actually used? Unused access is a quiet liability worth trimming.
Uninstalling an app revokes its access to your store, and Shopify then sends the developer a request to erase the customer data the app collected (Shopify uninstalling-apps documentation). It is a request, not a guarantee, so if you need confirmation the data was deleted, contact the developer directly. That makes removing dead apps a data-hygiene step, not only a speed one. The performance side of app cleanup sits in the main audit checklist.
What Settings and Compliance Items Belong in an Admin Security Audit?
The last group is quieter, but it shapes trust and legal exposure.
Store policies come first. Confirm your refund, privacy, terms of service, and shipping policies exist and read correctly at Settings > Policies. Shopify can generate templates here, but a generated policy still needs your real terms before it goes live.
Customer privacy and data come next. At Settings > Customer privacy, Shopify provides a privacy policy template, a customizable cookie and consent banner, and a data-sharing opt-out page. New stores selling to the UK or EEA get the banner enabled by default. You can also handle per-customer data requests from a customer's profile under More actions, where one action exports their data and another redacts it. Redaction keeps the customer profile and order history but removes personal details such as name and address, and Shopify gives you a 10-day window to cancel a pending erasure (Shopify customer data requests documentation).
Two caveats Shopify states plainly: its automated privacy settings are not a substitute for legal advice, and the built-in cookie banner only governs Shopify's own tools, so you add still need their own consent handling. If you sell to EU consumers, your audit should also cover newer rules like the EU withdrawal button requirement, which sits outside Shopify's default settings.
Close the privacy review with two checks. List the third-party scripts and pixels you have added, such as analytics, ads, and chat widgets, and confirm each has its own consent path, since the Shopify banner does not govern them. Then open your live storefront and confirm your privacy and refund policies actually appear in the footer and at checkout, not only saved in Settings.
One newer setting deserves a look of its own. If Shopify Network Intelligence is enabled at Settings > Customer privacy, confirm your privacy policy includes the required disclosures, your consent banner is set up for the markets where consent is required, and any third-party consent tool is integrated with Shopify's Customer Privacy . The feature lets Shopify combine your customer data with data from other merchants, which is what triggers those extra requirements (Shopify Network Intelligence documentation).
Taxes round it out. Confirm that the regions listed at Settings > Taxes and duties match where your business is registered to collect, and look into anything that does not fit: an unexpected registration, a manual rate override, or a region you sell into that is missing.
How Often Should You Run an Admin Security Audit?
Quarterly is a sensible cadence for an active store, and pairing it with your storefront audit means you do both in one sitting. Run it again after any staff change, app install, ownership handover, or security scare, since those are the moments new risk gets introduced. A small store can often complete the first review in around 30 minutes once you know where each setting lives, though a store with many staff and apps will take longer. Either way, it is some of the cheapest insurance a store has against a problem it might not otherwise see coming.
Run it with someone who holds full admin access, since the user-management and security checks need it. Keeping a short note of what you reviewed and changed each quarter turns the audit into its own record, useful if you ever need to show that access and data are handled with care.
For the customer-facing half of store health, pair this with the storefront audit walkthrough. Together they cover both sides of the login.
FAQ
How do I see the activity log in Shopify?
Go to Settings > General > Store activity log in your admin. It lists recent admin actions with who made each change and when. The log holds up to 250 recent actions and cannot be exported, so for longer history you need the separate user activity log or a third-party app.
How do I track staff activity on Shopify?
Open Settings > Users > Security and view the user management activity log for staff and security events. To check one person's logins, open their profile under Settings > Users and review the Recent access to store section, which shows recent sessions with date, IP address, ISP, and location.
Can I export my Shopify activity log?
The store activity log itself cannot be exported. The separate user activity log can: go to Settings > Users > Security, open the user activity logs, and export a CSV that covers up to the last six months of events.
Does Shopify have an audit log?
Yes, in two places. The store activity log (Settings > General) tracks admin and setting changes, and the user management activity log (Settings > Users > Security) tracks staff access and security events. Both are built in, though native retention and filtering are limited.
How often should I run a Shopify admin security audit?
Quarterly suits most active stores, with an extra pass after any staff change, app install, or ownership handover. These reviews are short, and they catch access and data issues that a storefront audit does not.
Jakub is the founder of Ecomhint, an AI-powered ecommerce audit tool focused on UX and conversion optimization. He helps online stores identify friction points across product pages, cart, and checkout using CRO best practices and original research data.

