Sooner or later someone else needs to work inside your Shopify admin: a virtual assistant, a developer, an agency, a friend helping with the launch. The quickest way is to send them your login. It is also the one way you cannot cleanly take back, and Shopify gives you two better ones.
Never share the owner login
The owner account can do everything in the store, including billing, payouts, and transferring or closing the store. Anyone holding that password can do all of it, and whatever they do is recorded as you. If you later want them out, the only fix is to change the password, and everything else that relied on it has to change too.
Option one: a staff account
A staff account is a login in the other person’s own name, added from Settings > Users in your admin. You decide what it can see and do by assigning roles, and each role is a bundle of permissions: orders, products, customers, content, apps and so on. Their work is recorded under their name, and you can remove the account yourself at any time.
Staff accounts count towards your store’s user limit, which depends on your Shopify plan. Settings > Users shows where you stand.
Option two: collaborator access
If the person works through a Shopify Partner account, as most agencies and freelance developers do, they can ask for collaborator access instead. Shopify describes collaborators as “Shopify Partners who you’ve allowed to access your store”. It works in three steps:
- You find your 4-digit collaborator request code in Settings > Users > Security and send it to them. Only someone with the code can ask for access, and you can generate a new code whenever you like, which makes the old one useless.
- They send a request from their Partner account.
- You review it, choose the roles and permissions, and accept.
Three things worth knowing. Collaborators do not count towards your user limit. Their access expires on its own if they have not logged in to your store for 90 days. And a collaborator cannot be given the Administrator role.
Which one to use
- Someone who will work in the store every week, like a VA or an operations team: a staff account in their name, so their work sits under one login you can see and remove.
- A developer or agency doing a project from a Partner account: collaborator access, with permissions for the project only.
Give the least access the job needs
Whichever you choose, start from the job, not from “full access”. Someone answering customer emails needs orders and customers, not apps or themes. Someone uploading products needs products, not payments. You can always add a permission later; nobody ever remembers to take one away.
Three more habits that cost nothing:
- Turn on two-step authentication for your own login, and ask anyone with access to do the same on theirs.
- Give access to your email platform, helpdesk and apps through each tool’s own user invites, never a shared password.
- When someone stops working on the store, remove their access that day.
How we do it
When we take on a store, we work from a staff account in our own name, never the owner login, with only the permissions the work needs and two-step sign-in on every account we use. Payments, payouts, billing, store ownership and your plan stay yours alone, and you can remove our account yourself in one click. The rest of how we run a store day to day is on our store management page.

