How to Hire a Shopify Virtual Assistant Without a Disaster

You found someone. The trial task came back clean, the rate works, and there is a chat window open where they have just asked, reasonably, how they get into the store. Your thumb is hovering over the email and password you use for everything. That one message is behind most of the horror stories on r/ecommerce, and it has nothing to do with the person you just hired.

So here is the answer before the detail. Almost every Shopify VA disaster is an access design failure, not a hiring failure. A Shopify virtual assistant with the wrong permissions can refund to a card, create a discount code with no cap and no expiry, publish a half-finished theme over your live storefront, install an app that pulls your customer list into a third party, and export that list to a CSV on a laptop you will never see. None of it requires bad intent. It requires a helpful person, a checkbox you left ticked, and no written rule about what to do next.

So the work happens before the person arrives. Decide what they touch, decide what they are allowed to decide, write both down, then hire.

What a Shopify virtual assistant is genuinely good at

The jobs that transfer well share a shape: high frequency, clear inputs, a right answer that lives somewhere other than your head.

  • Order and fulfilment exceptions. Address corrections before dispatch, stuck tracking, split shipments, chasing the 3PL about the parcel that never scanned. Daily, interrupt-driven, and usually the highest-value handover.
  • Product data and listings. Drafting products, variants, SKUs, alt text, collections, and fixing the descriptions written at 1am during launch week.
  • Inventory reconciliation. Supplier confirmations against Shopify quantities, variances flagged, incoming dates kept honest.
  • Customer email. The order-status, sizing and policy tier, worked against templates.
  • Returns processing. Create the return, issue the label, inspect against a checklist, close the loop. Processing a return and refunding money are different jobs, and Shopify treats them as different permissions.
  • Review requests and content scheduling. Post-purchase sequences with anything under four stars escalated; blog posts and pages loaded as drafts.
  • Reporting. A weekly one-pager: sales by channel, refund rate, return reasons, stockouts.

Four things stay with the owner, permanently rather than until trust is established. Pricing and margin. Discount strategy. Anything that moves money out of the business. App and integration decisions. Not trust-graded tasks: four levers where one wrong action is unrecoverable or expensive.

The permission model, and the permissions that cost real money

Shopify’s admin no longer uses “staff accounts” the way most blog posts still do. Access is built from users, who hold roles, and a role is a bundle of granular permissions. Categories exist for store level, organization level and the POS app, a user can hold more than one role, and permissions accumulate when they do. Predefined roles exist too: Merchandiser grants admin home plus the store-level permissions in Products, Catalogs and Content.

The granularity is finer than people expect. Inside Orders alone, Shopify separates View, Manage order information, Edit orders, Apply discounts, Fulfill and ship, Buy shipping labels, Return, Refund to original payment method, Refund to store credit, Cancel, Export and Delete, among others. So you can let someone fulfil orders and create returns while withholding any ability to send money. Most owners never look, grant Orders wholesale, and learn its shape during an incident.

Treat these as owner-only from day one:

  • Discounts, exposed as a single combined “View, create, and delete” permission. You cannot grant creation without deletion, which is reason enough to keep it back.
  • Refund to original payment method and Refund to store credit. Two permissions, and the difference between them is the whole control.
  • Customers > Export and Request data, the CSV export of a customer’s data, flagged sensitive by Shopify. Also Erase personal data and Delete.
  • Manage and install apps and channels, plus Approve app charges, also flagged sensitive.
  • Online store > Themes and Edit code. Themes covers viewing, changing and publishing. Publishing is the dangerous verb there.
  • Store settings > Manage settings, which opens the Settings pages and allows webhook creation, plus the billing, payments, domains and custom pixel permissions beside it. Several are flagged sensitive; pausing or deactivating the plan is owner-only regardless.

A least-privilege starting set for a general VA, from those same names: Orders (View, Manage order information, Fulfill and ship, Buy shipping labels, Return), Draft orders (View, Create and edit), Products (View, Create and edit), Inventory (Manage inventory excluding transfers), Customers (View, Create and edit), Analytics (Reports, Dashboards), and Online store (Blog posts and pages) if content is in the role. Nothing from Discounts. No refund permissions. No Export anywhere. Nothing from Apps and sales channels, Themes, Store settings or Finance.

That covers the whole job list above with two deliberate gaps, refunds and exports, so those actions reach you as a request instead of a side effect. Shopify auto-selects some permissions when you pick others, so read the checkboxes after you save. And check the live list in your own admin, because the naming changes.

Nobody gets the owner account. Not for ten minutes.

Sharing the owner login destroys three things at once. Attribution, because every action in the log is now yours. Revocation, because pulling access means a password reset that locks out every device you own. And two-step authentication, because a second factor forwarded over chat is not a second factor. The alternative takes four minutes. Create a user account in their name with an email address they control, assign a role containing only the permissions above, and require two-step authentication for that user. Shopify lets the owner set two-step authentication as required rather than optional, and documents that the owner cannot view or change the phone number, authenticator app or recovery codes a user has set against their own Shopify ID. That separation is the point: their credentials are theirs, the audit trail is theirs, your revocation is one click.

Hiring a Shopify Partner, agency or freelance developer instead? Use a collaborator account. Shopify documents that collaborators do not count toward your store’s user limit, that they can only request access with the four-digit collaborator request code you give them, which you can regenerate at any time to kill the old one, and that Partners must have two-step authentication active to use one. They can request every available permission, so grant only what you are comfortable granting.

Three mistakes, three controls

A discount code with no limits. A VA is asked for a 20% newsletter code, names it something guessable, leaves the defaults, and it is on a coupon aggregator by Thursday. Shopify’s field names map onto the failure modes exactly: “Limit number of times this discount can be used in total” caps the blast radius, “Limit to one per customer” stops recycling, “Minimum purchase amount” and “Minimum quantity of items” protect margin, start and end dates stop it living forever, and eligibility narrows to customer segments or markets. The control is not training on those fields. It is that Discounts stays owner-only, and the VA’s job is to request a code with the limits specified in the request.

A refund issued without approval. The customer is angry, the VA wants to help, the button is right there. Shopify separates the return from the money, which makes this easy. Grant Return so they can create returns, generate labels and move the case along. Withhold Refund to original payment method. If you want small cases resolved without you, grant Refund to store credit only, which keeps the value inside the business and caps a bad call. Then write the threshold: under this value, store credit, act; above it, or if this customer has already had one, escalate. A refund limit that lives in your head is not a limit.

A theme edit on the live theme. The one that takes a store down, and it is almost always a content task that drifted into a code task. Shopify’s guidance is to duplicate before customising, so you can discard the changes and start again. For a VA the rule is stricter: they work on a duplicate, always, and they do not publish. You publish, after looking. The Themes permission includes publishing, which is exactly why a content-only VA gets “Blog posts and pages” and not Themes. Shopify caps the theme library at twenty, so whoever duplicates has to clean up after themselves.

The two quiet leaks: apps and exports

Installing an app is a data-sharing decision

Owners underrate this because installing an app feels like installing a plugin, and it is not. Authorising an app grants a third party ongoing programmatic access to store data through Shopify’s APIs. Shopify documents a tiered model for protected customer data: Level 0 is no customer data, Level 1 is general customer data excluding name, address, phone and email, and Level 2 covers those protected fields. Public apps must request access and pass review, and Level 2 carries an expectation of participating in data protection reviews. The scope spans customer profiles, orders, fulfilment data and gift cards.

None of which protects you from a VA installing a review widget at 11pm because a Facebook group recommended it. The control is structural, then written. Structurally, “Manage and install apps and channels” and “Approve app charges” are owner-only, permanently. Written, it is one line: any app, integration, pixel, Zapier connection or browser extension that touches store data is requested in writing with a link, and installed by the owner.

Where the customer CSV ends up

An export is a file. Files get downloaded to a personal laptop, dropped into a personal Drive to open in Sheets, and left there. Your store’s security posture is now that of a device you have never seen.

The compliance point, kept short. The ICO’s security guidance requires appropriate technical and organisational measures so that personal data can be accessed, altered, disclosed or deleted only by those you have authorised, acting within the scope you set. The ICO is explicit that staff should not process personal data unless you have instructed them to, that home working needs measures so it does not compromise security, and that many incidents come from theft or loss of equipment. What applies to you depends on where you and your customers are, which is a question for an adviser.

Practically: export permissions stay off, the owner runs an export when one is genuinely needed and shares it inside a business account the company controls rather than sending the file, and it gets deleted when the task is done. Where a task can run on order IDs and the two fields it needs instead of full customer records, strip it back. A VA handling personal data routinely needs written data-handling terms, not a verbal understanding.

Write the rule before they need it at 2am

Permissions stop catastrophes. Process stops the slow bleed, and the slow bleed is what ends most VA arrangements. An unwritten rule becomes the VA’s judgement call, made at the worst possible moment with the least possible context. So write decisions, not tasks. One line of trigger, one line of action, one line of escalation:

  • Refunds. Under what value, within what window, in what form, on what evidence. Always escalate: high-value orders, repeat claimants, injury claims, anything mentioning a chargeback or a lawyer.
  • Replace versus refund. Damaged in transit, wrong item sent, not as described, genuinely faulty, changed their mind. Five cases, five answers, and everyone assumes theirs is obvious.
  • Goodwill. The gesture they can offer unprompted: free return postage, a fixed store credit, a no-return replacement under a stated value. Name the number.
  • Discounts. What they may offer without asking, which for a new VA is nothing, and how they request one.
  • Address changes, cancellations, oversells. The cutoff in hours relative to fulfilment, and whether a stockout means contact-and-offer or hold-and-escalate.
  • The silence rule. When nothing covers the situation, what happens? “Use your judgement” produces the incident. “Holding reply, tag it ESCALATE, post it in the channel” produces a decision you make.

Write them as they come up, not in a documentation sprint before anyone starts. Your first thirty days of questions is the SOP library, and anything answered in chat and never written down gets asked again by the next hire.

Week one, week four, and the day they leave

Week one: their own user account with two-step authentication required, the least-privilege role above, a store email address they own or delegated access to a shared inbox from their own account rather than your login, non-Shopify credentials shared through a password vault you control, the task system, the decision records. Nothing from Discounts, refunds, exports, apps, themes, settings or finance.

Week four, only if the work has been clean and the rules are written: Refund to store credit inside the documented threshold, Themes on a duplicate with publishing still owner-only, one specific report export if reporting is theirs. Add one permission at a time and name the rule that governs it. Permissions granted without a matching rule are the ones that generate incidents.

The day they leave, same day, friendly parting or not:

  • Remove their Shopify user account, or revoke the collaborator account and regenerate the request code so the old one is dead.
  • Remove them from the shared inbox and revoke mail delegation.
  • Revoke vault access and rotate every credential that was shared rather than delegated. Shared means compromised on exit.
  • Check the apps list against what you remember authorising. Remove anything you cannot account for.
  • Remove them from the task system, shared drives, chat groups, and every 3PL, supplier and carrier portal they had a seat in. The portals are what everyone forgets.
  • Ask in writing for confirmation that local copies of exports or customer files are deleted, and keep the reply. Not enforceable alone, but it is the only record you will have, and the asking changes behaviour.
  • Read the admin activity log for their final week. Not out of suspicion. Pending work you did not know about lives there.

Twenty minutes on the day is the difference between a role ending and a liability continuing.

If that permissions and process layer is the part you would rather not build alone, it is exactly what AB7 Solutions does. We place remote store-operations professionals and back-office teams who arrive working to a least-privilege access model and written decision rules instead of asking for your login; we design the role, permission set and the onboarding and offboarding checklists before anyone touches the store; and our security practice audits existing admin users, app authorisations and data exports when you suspect the access design has already drifted. We will also tell you when you do not need us. Plenty of stores need one rewritten returns rule and a permission audit, not a hire. Send your user list and the tasks you want moved, and we will tell you which it is. Call +1 321 341 7733, or email ab@ab7solutions.com or director@ab7solutions.com.

Questions that come up next

My plan only allows a few users. Do I share an account? No. Collaborator accounts do not count toward the limit, so a Partner or agency route sidesteps it entirely. If both people are genuinely staff and you are out of seats, the plan upgrade costs less than an unattributable audit log, which is what a shared account gives you the first time something goes wrong.

Do I really need to withhold refunds from someone I trust? It is not about trust. It is about whether a judgement call sits with the person who carries the consequence. The version that goes wrong is rarely a dishonest VA. It is a kind one refunding a fraudulent claim in full because nobody described the pattern.

What if my VA knows Shopify better than I do? Common, and it changes the grants but not the structure. Themes on a duplicate, Edit code if they can genuinely read Liquid, publishing and app installation still yours, rollback rule in writing. Competence is a reason to widen permissions deliberately, not a reason to skip the audit trail.

Sources: Shopify Help Center, Store permissions, Roles, Two-step authentication for users, Collaborator accounts, Percentage and fixed amount discounts and Duplicating themes; Shopify Dev, Protected customer data; Information Commissioner’s Office, A guide to data security.

Leave a Comment

Your email address will not be published. Required fields are marked *