Shopify collaborator access is the permission system that lets an external agency, developer, or freelancer into your store's admin — without using a staff seat, without sharing your password, and without handing over control of your account.
If you are setting up Shopify in South Africa and working with any external partner, this is the correct way to give them access. Done right, the agency sees exactly what it needs. Done wrong, you have either locked them out of half the tools or given a freelancer more visibility than your store's billing section should ever warrant.
This guide covers both sides of the relationship: what you do as the store owner to enable and approve access, what a registered Shopify Partner does to request it, and — the part most guides skip — precisely which permissions to enable depending on what role the collaborator is filling. It also covers the 90-day inactivity trap that quietly revokes access mid-project if nobody notices in time.
Quick Answer
Shopify collaborator access allows a registered Shopify Partner (agency or freelancer) to work in your store through their own Partner Dashboard, using only the permissions you choose. It does not count toward your plan's staff limit, requires the partner to have two-step authentication active, and expires automatically after 90 days of inactivity. To enable it: generate a 4-digit request code in Settings > Users > Security, share it with your partner, then approve their access request with the specific permissions they need for their role.
Jump to a section
What Is Shopify Collaborator Access?
Staff Accounts vs Partner Accounts
Enabling the Request Code on Your Store
What Happens on the Agency Side
Which Permissions to Grant by Role
Not sure what access level your Shopify agency actually needs?
Send us your current setup and we will identify the exact permissions required for your campaign without exposing anything sensitive.
Get a Free AssessmentWhat Is Shopify Collaborator Access?
Shopify collaborator access is a dedicated account type that lets a registered Shopify Partner work inside your store admin using their own login credentials — completely separate from your owner account and your internal staff. The key operational difference: collaborator accounts do not count toward your plan's staff limit, so an agency can work inside your store without forcing you to upgrade your plan to accommodate an extra seat.
Collaborators do not log in via your store's standard login page. They access your store through the Stores section of their own Shopify Partner Dashboard. This means the partner's credentials are entirely their own — you never share a password, and the partner's access is controlled by the specific role and permissions you approve.
You can adjust, restrict, or revoke that access at any time from your admin. The full technical specification is covered in Shopify's official collaborator accounts documentation.
A collaborator account is not a shortcut to full admin access. It is a scoped, auditable access grant that shows exactly which store sections an external party can reach — and exactly which they cannot.
Staff Accounts vs Partner Accounts: The Core Difference
A staff account is an internal seat that consumes your plan's allowance; a collaborator account is a scoped access grant exclusively for registered Shopify Partners, and never counts as a staff seat. Choosing the wrong type creates friction — adding your agency as a staff member eats into your plan limit, while the collaborator route is reserved for agencies and freelancers with an active Partner account only.
| Feature | Staff Account | Collaborator Account |
|---|---|---|
| Counts toward staff limit | Yes | No |
| Who holds the account | Employee / internal team | Registered Shopify Partner only |
| Who initiates access | Store owner invites by email | Partner requests via their dashboard |
| Login method | Direct store login | Via Partner Dashboard |
| Administrator role | Can be assigned | Cannot be assigned |
| Shopify POS access | Yes (if permitted) | No |
| Ownership transfer | Possible | Not possible |
| Auto-expiry | No | Yes — 90 days of inactivity |
| Two-step auth required | Optional per plan | Mandatory |
On the Shopify Basic plan in South Africa, no additional staff accounts are included — only the store owner has direct access. The Grow plan includes up to five staff accounts, Advanced up to fifteen, and Plus offers unlimited. All plans, regardless of tier, can invite third-party collaborators. If you are on Basic and need to give your agency working access, collaborator accounts are the only route that does not require a plan upgrade.
Enabling the Request Code on Your Store
Setting up Shopify collaborator access on your end takes five steps, all done inside your admin — no external tools required. The central mechanism is a 4-digit code that controls who can even submit a request to access your store.
- Go to Settings > Users in your Shopify admin.
- Open the Security section and locate the Collaborator request code.
- Click the code to copy it, then share it securely with your agency — messaging apps, email, or your onboarding documentation all work.
- Wait for the access request. When your agency submits theirs, you receive an email and an admin notification. Shopify shows you the partner's account creation date, collaboration history, and signup location so you can verify their identity before approving.
- Review and adjust permissions, then approve. Shopify auto-generates a role based on the permissions the partner requested — you can accept it as-is or narrow it down before clicking confirm.
Code hygiene: The moment you generate a new code, every previous code is immediately invalidated. Do this any time you suspect an old code was shared more widely than intended. There is no list of who has your code — rotating it is the only way to close that door.
Enable the setting that requires a request code before anyone can even submit a collaborator request. Without it, any Shopify Partner who knows your store URL can send an access request — you will still approve it manually, but restricting requests to code-holders filters out cold outreach from agencies you have never spoken to.
What Happens on the Agency Side
On the partner's side, the process is equally straightforward, but your agency must have an active Shopify Partner account before they can submit any request. If a freelancer contacts you and says they need to be added as a staff member rather than going through the Partner Dashboard, they are either not a registered Shopify Partner or unfamiliar with the correct process — both worth noting before you grant store access.
The standard process for a registered partner:
- Log into their Partner Dashboard.
- Navigate to Stores > Add Store > Request Access to Store.
- Enter your store URL and the 4-digit collaborator request code you provided.
- Select the permissions they require — specific sections, or all available.
- Add a message explaining the scope of work.
- Submit the request and wait for your approval.
One common technical issue to know about: if the partner's email address already exists as a staff account in your store, their request will fail with a conflict error. In that case, remove the old staff account first, then have the partner resubmit. If a request has been declined, the partner must contact Shopify Partner Support before a new request can be submitted.
Which Permissions to Grant by Role
The most consequential decision in granting Shopify collaborator access is not whether to approve the request — it is which permissions you tick. Over-permissioning an agency freelancer is the most common mistake: giving a theme designer access to Orders means they can see every customer transaction, address, and contact detail on your store. Under-permissioning wastes the engagement because your agency cannot do the work they were hired to do.
The table below reflects practical guidance based on Shopify's documented permission structure. Treat it as a starting framework — your agency's specific scope may require adjustments.
| Collaborator type | What they need to do | Grant | Do NOT grant |
|---|---|---|---|
| Theme developer | Build, edit, and publish themes | Themes; View products (read-only for context); Apps (if they need to install theme-adjacent apps) | Orders; Customers; Reports; Settings (billing, payments) |
| Performance marketer (Meta Ads, email, Google) | Set up pixels, flows, product feeds, discount codes | Products; Marketing; Apps; Reports/Analytics; Discounts | Settings; Themes (unless also doing landing-page work); Customers (in bulk) |
| SEO consultant | Audit pages, optimise metadata, fix redirects | Products; Online store (blog/pages); Reports/Analytics | Orders; Customers; Themes (edit access — view is enough for auditing); Settings |
| Full-service agency | Marketing, theme, and store operations | Themes; Products; Orders (read); Reports; Apps; Marketing; Discounts | Administrator role (never); Settings > Billing; Settings > Plan; Store ownership |
| Logistics or ops partner | Process and fulfil orders; update stock | Orders; Products (inventory view); Customers (shipping context) | Themes; Marketing; Reports; Settings |
SA-specific note on billing: Shopify Payments is not available in South Africa. Your store uses a third-party payment gateway (PayFast, Peach Payments, Ozow, or similar). Even so, the Settings > Billing section contains your subscription, payment method, and plan details. There is no reason a collaborator needs this — keep it locked for all external partners regardless of role.
Customer data and POPIA: Granting Orders or Customers permissions gives your collaborator access to personal information — names, addresses, contact details, purchase history. POPIA (Act 4 of 2013) requires a written agreement between you (the responsible party) and any operator processing customer personal information on your behalf. Before granting this access, ensure a signed data processing agreement is in place and confirm with your legal advisor that it covers your agency's specific processing activities.
Unsure how to scope your Shopify agency brief?
Tell us your current growth objective and we will map the exact team access, tool setup, and timeline that fits your store.
Request a Timeline AssessmentKeeping Your Store Secure
Granting collaborator access is not a one-time task — it requires ongoing management to stay secure and functional over the lifetime of an agency relationship. Four practices protect your store without creating administrative burden.
Rotate your request code when a relationship ends. Your collaborator code does not expire on its own. If you change agencies or end a freelance engagement, generate a new code immediately. Old codes are invalidated the moment a new one is created, so there is no list to manage — one action closes the gate.
Track the 90-day rule proactively. If a collaborator does not log into your store for 90 consecutive days, their access expires automatically. This is useful during quiet periods, but it also means access can lapse mid-project without warning if the partner shifts focus to other clients.
Set a reminder at the 75-day mark if a project is running long. Reactivation is straightforward — Settings > Users > select the account > Actions > Reactivate user — but it requires you to notice the lapse first.
Use the admin activity log. Shopify records admin actions. If you see changes you did not make, the activity log lets you trace which account made them. This is more useful than it sounds on stores where multiple collaborators have overlapping permissions.
Remove, do not just ignore. Permanently removing a collaborator (Settings > Users > select name > Remove collaborator account) is irreversible — the partner must resubmit a new request if they need access again. This is the right call when an agency engagement is definitively over. Do not leave inactive collaborators sitting in your Users list on the assumption that 90-day expiry is sufficient; removal is cleaner and creates no re-entry path without your explicit approval.
Two-step authentication is mandatory for every collaborator before they can use the account. This is not a setting you control — Shopify enforces it on the partner's side. It is one of the structural security advantages collaborator accounts have over shared staff passwords.
Why South African Businesses Choose Growth Pulse Media
Growth Pulse Media is a registered Shopify Partner operating from Johannesburg, Gauteng. Dirk van Greuning founded the agency after building and scaling a South African ecommerce business — which means the agency-side experience of managing Shopify stores, requesting collaborator access, configuring payment gateways (PayFast, Peach Payments, Ozow), and integrating SA-relevant apps is operational history, not theoretical knowledge.
For SA businesses who want a Shopify agency that does not require hand-holding through the access process: GPM works with a limited client load, all work is executed in-house by senior team members, and setup starts with a proper scope conversation rather than a generic onboarding form. If you are evaluating whether a Shopify partner relationship makes sense for your store, our Shopify marketing agency for South Africa page covers how that engagement works in practice.
Related reading if you are still in the build phase: the ecommerce build, week by week guide walks through exactly how a Shopify store goes from brief to live — including which external parties typically need access at each stage and what permissions they actually require.
Who This Is NOT For
Internal employees and in-house team members. Collaborator accounts are for Shopify Partners — registered agencies, developers, and freelancers with a Partner Dashboard. Your in-house marketer, customer service staff member, or warehouse assistant belongs on a staff account with the relevant scoped permissions, not as a "collaborator." Using the collaborator route for employees bypasses the standard staff management tools and creates unnecessary confusion in your Users list.
Shopify Plus businesses using organisation management. If you run a Plus organisation, collaborators face additional restrictions: they cannot be assigned to organisation-level roles and cannot be added to collaborator groups within the organisation. Plus merchants with complex multi-store setups need to review the organisation-specific access documentation before routing external partners through the standard collaborator flow.
Store owners who want shared team logins. Collaborator access is individual — each partner at an agency logs in via their own Partner Dashboard account. If your agency team of four all share a single login, none of them are using this correctly, and you lose all audit trail visibility. Each active collaborator should have their own Partner account and their own access grant.
Merchants who want permanent billing or plan access for their agency. No collaborator should ever have access to your Shopify plan settings, billing details, or payment method. The administrator role cannot be assigned to collaborators by design — but within granular permissions, Settings access can still be granted carelessly. If an agency asks for Settings access as part of a standard onboarding, ask specifically which settings and why before approving.
Ready to have a Shopify partner who already knows the right way in?
Book a no-obligation call and we will walk through your store's current setup — access structure, permissions, and all — within 24 hours.
Book Your Free Store AuditFrequently Asked Questions
Does a Shopify collaborator account count against my staff limit?
No. Shopify collaborator accounts do not count toward your plan's staff limit. This is one of their key advantages over staff accounts for external partners. Whether you are on the Basic plan (no additional staff included), Grow (up to five staff), Advanced (up to fifteen), or Plus (unlimited), adding a collaborator does not consume a staff seat.
What is a Shopify collaborator request code?
A collaborator request code is a 4-digit number generated in your Shopify admin under Settings > Users > Security. You share this code with the agency or freelancer who needs access. They must enter it when submitting their request through their Partner Dashboard — without it, the request cannot go through. You can generate a new code at any time, which immediately invalidates all previous codes.
What happens if my collaborator has not logged in for 90 days?
Their collaborator access expires automatically. Shopify requires at least one login every 90 days to keep collaborator access active. If it lapses, you can reactivate it from Settings > Users by selecting the account, clicking Actions, and choosing Reactivate user. The reactivation restores existing permissions without a new request — but you need to notice the lapse, so build a 75-day reminder into any long engagement.
Can I give my agency access without them seeing my customer data?
Yes. Orders and Customers are separate permission categories — a theme developer or marketer working on setup, theme work, or analytics does not need either, so leave both unticked when assigning their role. You can adjust permissions at any time after the account is active without revoking and resubmitting a new request.
How do I remove a collaborator from my Shopify store?
Go to Settings > Users, select the collaborator's name, and click Remove collaborator account. This action is permanent and cannot be undone. If you want to re-engage the same partner in the future, they will need to submit a new access request from scratch. If you only want to pause the relationship without full removal, the 90-day inactivity expiry will handle it naturally — though removal is cleaner for ended engagements.
Does my agency need to be a Shopify Partner to request collaborator access?
Yes. The collaborator access system is built on Shopify's Partner Programme. The agency or freelancer must have an active Shopify Partner account and access the store through their Partner Dashboard. If someone asks to be added as a staff member because they "don't have a Partner account," they are not set up to use the collaborator system and should register as a Shopify Partner before requesting access.
Work With a Registered Shopify Partner Who Knows SA Stores
Growth Pulse Media is a registered Shopify Partner based in Johannesburg. We work with SA merchants across PayFast, Peach Payments, Ozow, and the local logistics integrations — no global-template onboarding, no juniors on your account. Tell us about your store and we will respond within 24 hours with a concrete next step. No obligation.
Start the Conversation

