Team access is delegated, tenant-scoped and separated from merchant ownership so people can collaborate without receiving unnecessary authority.
Invite a person using their intended work email and role.
The recipient accepts through the invitation link and receives access to the owner's effective workspace. Remove duplicate or obsolete pending invitations rather than sending repeated links.
The tenant owner controls billing, team membership and store relationships.
The owner remains responsible for Shopify authorization and commercial decisions. Team membership does not transfer ownership of the merchant account or Shopify store.
Members can collaborate without receiving every administrative permission.
A member works on the owner's authorized stores but does not need a separate empty billing or team-management surface. Sensitive changes remain protected by backend authorization, not merely hidden navigation.
Administrators may coordinate approval and deployment when authorized.
Changeset approval, live deployment, rollback and overrides are consequential actions. Assign administrative access only to people who understand the store and are expected to make those decisions.
Agency access should remain delegated and revocable.
An Agency Managed relationship does not make the agency the owner of the merchant account. The merchant should retain visibility and the ability to remove agency access without losing its own history.
Treat AI integration and MCP tokens as credentials.
Generate tokens only for an approved integration, store them securely, avoid sharing them in chat and revoke them when the integration or teammate no longer requires access.
Related TaskerArmy pages
Connect the store. Start with evidence.
Connect your store, review the audit and choose the first change you want TaskerArmy to prepare in staging.