Step-by-step guide
Last updated: August 2026
Have these ready — it's what onboarding stalls on:
Grant the minimum the work needs. On Shopify, the levels are:
| Access level / role | What it can do |
|---|---|
| Collaborator | Agency-specific access, separate from staff, with granular per-area permissions and its own login. The right method for agencies. |
| Staff account | An employee-style account with permissions you set. Use for ongoing team members, not external agencies. |
| Store owner | Full control including billing and closing the store. Never share. |
A few minutes. The agency sends a collaborator request; you approve the requested permissions. No password exchanged.
Open Settings → Users and permissions → Collaborators and grant the access — a few minutes.
Accept and confirm from their side, then start work.
Access is granted when:
The most common problems and how to fix them:
Under Users and permissions, set collaborator requests to “anyone” or share your collaborator request code with the agency.
Don't share a staff login — it sends 2FA to the wrong person. Use a collaborator account, which is Shopify's official agency method.
Review the requested permission list and approve only what the work needs.
Collaborator accounts are Shopify's official agency access — separate from your logins, with their own permissions and audit trail, and no shared 2FA. Remove the collaborator anytime from Users and permissions.
Everything above is why agencies switch to a single link. HandItSafe requests exactly this Shopify access for you — the client approves through Shopify's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.
FAQ
Collaborator accounts are Shopify's official agency method — separate access, its own permissions, its own audit trail, and no shared 2FA.
No. The agency requests collaborator access; you approve the specific permissions.
Settings → Users and permissions → remove the collaborator. HandItSafe adds a one-tap client remove.
Collaborator is designed for agencies and developers: separate access, its own login, granular permissions, and it doesn't use a staff seat. Staff accounts suit ongoing internal team members.
No — collaborator accounts don't consume your paid staff seats, so agency access doesn't cost you a seat.
Keep reading
HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.