When several people and apps manage a Shopify store, the most reliable way to track changes is to combine individual user accounts, limited permissions, Shopify's activity log, app activity details, and a repeatable incident process. No single screen provides a perfect record of every change, but these layers can dramatically reduce the time spent asking who changed a product, order, inventory level, or setting.
The problem is not limited to large teams. A store managed by one merchant, one agency, an ERP, a marketplace feed, Shopify Flow, and a handful of apps already has several possible actors. When something unexpected happens, memory and Slack messages are not enough.
Why “who changed what?” becomes difficult on Shopify
A Shopify change can come from:
- the store owner or a staff user;
- a Shopify Partner using a collaborator account;
- an agency or freelancer working through an assigned role;
- a third-party app;
- a sales channel or marketplace;
- an ERP, PIM, feed, or custom API integration;
- a Shopify automation or background process.
These actors do not always appear in the same place or with the same level of attribution. Shopify's store activity log can identify a person, app, channel, or Shopify, but some automated changes appear under a generic system actor. App details can show recent API activity by permission area, but not a field-by-field history of every request. Effective control therefore depends on process as much as software.
1. Give every person an individual Shopify account
Avoid shared admin credentials. If several people use the same account, their actions become difficult or impossible to distinguish, and removing one person's access means changing credentials for everyone.
Shopify lets you create users and assign roles that control what each person can view and do. Use individual accounts for employees and collaborator accounts for Shopify Partners. This creates a clearer identity boundary and makes access easier to review or revoke.
Shopify's official user management guide recommends assigning roles with the permissions each user needs for their work.
2. Use roles and the minimum permissions required
Do not grant administrator access simply because it is faster during setup. Build roles around actual responsibilities, for example:
- Catalog team: products, collections, inventory, and files needed for merchandising;
- Customer support: orders and customers without access to themes or app management;
- Marketing agency: content, discounts, analytics, and the specific apps it manages;
- Developer: themes, apps, and settings required for the approved technical task;
- Operations: orders, fulfillment, inventory, and locations.
Shopify provides granular role permissions by business area. Review sensitive permissions separately and limit administrator roles to the smallest practical number of people. Permissions reduce the number of possible causes when something changes and limit the impact of mistakes or compromised accounts.
3. Manage collaborator access as temporary access
Collaborator accounts are designed for Shopify Partners such as agencies and freelancers. Before accepting a request, review the requested role and remove permissions that are not necessary for the task.
Use Shopify's collaborator request code, verify the request with the person or agency you expect, and review collaborator accounts when a project ends. Shopify requires two-step authentication for Partners using collaborator accounts and automatically expires collaborator access after 90 days without a login, but you should not rely on expiration as your only offboarding process.
Keep a simple record of the project owner, expected end date, and approved areas of access. When the work is complete, review and remove access that is no longer required.
4. Review which apps can change each area of the store
People are only part of the picture. Feed tools, ERPs, translation apps, bulk editors, bundle systems, marketplaces, and inventory integrations can all modify store data automatically.
Go to Settings → Apps, open an app, and review Activity and permissions. Shopify shows:
- which areas the app can view or edit;
- the date of its most recent activity in each area;
- the number of view and edit requests made during the last 30 days when you open recent activity;
- permissions the app has not used during the last 30 days.
According to Shopify's app management documentation, this activity view currently covers third-party apps. Shopify-built apps are not tracked in the same section.
This information does not prove which exact field an app changed, but it can narrow the list of possible causes. If inventory changed at 14:00 and only one third-party app made edit requests to inventory around that period, that is a useful lead for the investigation.
5. Start with Shopify's store activity log
Open Settings → General → Resources → Store activity log. Review actions around the time of the unexpected change and note the attributed actor, message, resource, and timestamp.
The activity log is useful, but its limitations matter:
- it displays a maximum of 250 results;
- it cannot be exported or downloaded;
- individual events cannot be expanded or clicked;
- some actions can be attributed to Shopify instead of a specific person or app.
On a busy store, 250 results might cover a short period. If you find a relevant entry, preserve the timestamp, actor, and wording immediately. For a detailed walkthrough, read How to View Shopify Activity Logs.
6. Use a repeatable incident checklist
When a product disappears or an order changes unexpectedly, use the same sequence every time:
- Describe the symptom. Record what is missing or different without assuming the cause.
- Identify the resource. Save the product ID, SKU, order number, customer, inventory item, or URL.
- Define the time window. Note the last known correct state and when the issue was discovered.
- Check the store activity log. Look for staff, app, channel, or Shopify activity around that time.
- Check resource timelines. Review the timeline for orders, customers, or inventory transfers where available.
- Review app activity. Identify apps with relevant edit permissions and recent requests.
- Check automations and external systems. Review Flow runs, feeds, ERP jobs, imports, and scheduled syncs.
- Preserve evidence. Save IDs, timestamps, screenshots, exports, and the result of each check.
- Fix the cause, then the symptom. Prevent another sync or automation from undoing the correction.
If the incident involves the catalog, follow the specific guide Shopify Product Deleted or Missing: How to Find Out What Happened.
7. Create a lightweight change process for high-impact work
Not every product edit needs a ticket. High-impact changes should have a minimal record, especially when several organizations share responsibility. Before a bulk import, theme release, market change, or major app configuration update, record:
- who is responsible;
- what will change;
- the expected start and end time;
- which app, script, or import will run;
- where the backup or rollback plan is stored;
- how success will be checked.
This is not surveillance. It is operational context. The goal is to separate planned work from unexplained activity and give the team a shared starting point when something goes wrong.
How Otheriver Audit Logs helps multi-user stores
Otheriver Audit Logs brings available Shopify Events, sanitized operational webhooks collected after installation, and summaries of the app's own API calls into one searchable workspace.
You can filter available records by resource, action, app, date, and text when supported, then export the selected results as CSV or JSON. This is useful when a merchant, internal team, agency, and several applications all need to work from the same evidence instead of comparing memories and screenshots.
Important limits: the app cannot always identify an exact staff member, does not record every API call made by other apps, does not provide a complete before-and-after diff, and is not a backup or rollback system. Covered webhook history begins after installation.
Give your team a shared place to investigate Shopify changes
Otheriver Audit Logs costs $5.99 per month. One plan, no free trial, billed by Shopify every 30 days.
Frequently asked questions
Can Shopify show which staff member changed a product?
The store activity log can attribute an action to a staff member, app, channel, or Shopify, but a specific person is not guaranteed for every event. Shared accounts also make reliable attribution impossible.
Can I see what a Shopify app changed?
Shopify shows the store areas a third-party app can access and recent view or edit request activity by area. This helps narrow an investigation, but it is not a complete field-level change history.
Should agencies use the store owner's account?
No. Shopify Partners should use collaborator accounts with only the roles and permissions required for their work.
Does Otheriver Audit Logs monitor every Shopify change?
No. Coverage depends on the Events and webhook topics available. It is designed to improve operational visibility, not to promise a complete forensic record of the store.