cyber security, smartphone, cell phone, protection, cyber, security, data, online, digital, network, mobile, lock, encryption, computer, phone, technology, cybersecurity, safety, privacy, access, secure, internet, hacker, attack, cyberspace, safe, blue computer, blue technology, blue laptop, blue phone, blue data, blue mobile, blue online, blue network, blue internet, blue digital, blue security, blue safety, blue smartphone, blue telephone, cyber security, cyber security, cyber security, cyber security, cyber, security, cybersecurity, cybersecurity, cybersecurity, cybersecurity, cybersecurity, privacy, hacker, safe
Photo by BiljaST on Pixabay

Platform Governance

Ecommerce platform security and access

Plan staff permissions, app access, backups and account recovery for an Australian ecommerce store, with clear owners and checks.

Secure an ecommerce store by controlling who can change it, which connected services can use its data, and how the business would recover access or trading records. Give each decision an owner. A secure login alone will not restore lost orders or remove an app’s access.

Map access around the work

List who publishes products, handles orders and refunds, changes payment settings, installs apps and manages users. Give each person an individual account with the access their work requires. Review access when duties change; suspend it promptly when someone leaves.

Separate routine administration from ownership. Shopify has one store owner. Actions including ownership changes and Shopify Payments management are reserved for that owner.

Shopify’s staff and custom-role options depend on the plan and organisation structure. Basic and Starter stores cannot add admin users or create custom store roles.

WooCommerce’s Shop Manager can handle products and orders, but the role also has broad access to settings and customer details. Check the permissions behind a role before assigning it.

Keep a short access record: account holder, required actions, access granted and review owner. Include agency, hosting, payment and domain accounts where they affect the store.

In Shopify, a user with multiple assigned roles receives the cumulative permissions of those roles. Check the combined access when assigning more than one role, rather than considering each role in isolation.

Shopify-managed roles, including owner and administrator roles, cannot be customised or deleted.

For stores within a Shopify organisation, distinguish the organisation owner from each store’s owner. An organisation can have one organisation owner, and each store has its own store owner.

Shopify sends store-related email messages to the store owner’s email address. Keep that contact current and ensure the business knows which store ownership it refers to.

Review apps and API credentials separately

As a general access-control risk, an app connection may be managed separately from the staff account of the person who installed it. Do not assume the connection is removed when that person’s access changes; check its status and owner.

Record each connection’s purpose, data access, supplier and business owner. Customer and order records may contain contact details, addresses and purchase information.

Shopify displays requested access before app installation. It provides permission and activity information for installed third-party apps.

WooCommerce REST API keys are linked to a WordPress user and can be set to read, write or read/write.

BigCommerce API accounts use OAuth scopes. Check the account type, access token and scopes for each connection rather than assuming its installer’s staff role defines its continuing access.

Before removing a connection, check whether orders, stock feeds or service tasks depend on it.

Plan credential ownership and lifecycle

Treat API credentials as separate access routes, not as extensions of a staff member’s login. Assign each connection a named business owner, record its purpose and required access, and make sure the business can identify where the credential is stored and how it can be revoked or replaced.

For WooCommerce, create a key for a specific WordPress user and give it a description that identifies its use. Choose Read, Write or Read/Write according to the connected application’s needs; the Consumer Secret is shown only once, so store it securely before leaving the key screen.

BigCommerce recommends limiting each API account’s OAuth scope to the privileges needed for its tasks. It recommends creating separate accounts for each app, store API user or function.

Its client ID and client secret do not change. Access tokens do not expire based on time and cannot be manually invalidated; include those properties in credential-lifecycle planning.

Decide what recovery must restore

List what the store needs to resume trading: current products and prices, customers and orders, site files or theme, settings, connected services and the ability to take a new order. Record who can restore each part and from which recovery point.

Protect ownership and recovery access

Keep ownership, billing and support contacts current. Protect staff sign-ins with individual accounts, strong unique passwords and multi-factor authentication where available.

Keep account recovery contact details current and store recovery codes securely. Make sure authorised people know the platform’s account-recovery route. Do not make a shared login or another person’s credentials the succession plan.

Document who can act when an administrator leaves and which independent accounts they will use. Only the current Shopify store owner can change ownership to a new user.

Shopify’s role-management controls allow eligible users to suspend or reactivate users and revoke device permissions. Include these controls in the store’s access plan, and identify who is authorised to use them.

Key security metrics for Australian ecommerce platforms

Multi-factor authentication enabled
Required for all admin and owner accounts
API keys with read/write access
Must be reviewed quarterly; limit to essential services only
Recovery codes stored securely
At least one copy held offline and accessible to authorised personnel
Ownership changes documented
Only the current store owner can transfer ownership; process must be recorded

Review the arrangement

At each review, check active users, app and API access, recoverable data, ownership contacts and unresolved gaps. Record who will resolve each gap.

In this guide

  1. Assigning store permissions by staff responsibilityMap ecommerce staff duties to store permissions, check role limits and manage access changes without giving everyone administrator rights.
  2. Reviewing app access to customer and order dataCheck what ecommerce apps and API credentials can read or change, why they need it and how to remove access safely.
  3. Checking platform backup and recovery optionsCheck what an ecommerce backup includes, how it can be restored and how to account for orders placed after its recovery point.
  4. Planning emergency access after an administrator leavesPrepare an ecommerce administrator handover, secure departing staff access and identify supported account recovery routes.

More from Platform Governance