Needed shortly after launch Procedure 14 of 15

14. User access and controls

Owner
You (solo operation)
Trigger
Whenever access to Shopify, banking, or accounting systems is granted, changed, or should be removed.
Approval
You approve every access grant.

Procedure

  1. Today, you hold all Shopify, banking, and accounting access directly — there is no separate access list to maintain yet beyond your own accounts.
  2. Enable two-factor authentication on Shopify, banking, and accounting/bookkeeping accounts now, before anyone else needs access — the effort is the same either way, and it closes a gap before it matters.
  3. When granting access to anyone else (staff, bookkeeper, photographer), grant the minimum permission level the task actually requires — e.g. a photographer needs product image upload, not financial data.
  4. Remove access immediately when someone's role ends. Do not leave dormant accounts active.
  5. Where practical, once more than one person is involved, separate who creates a transaction, who approves it, and who executes payment, so no single person controls all three.

Required evidence

A simple access log — who has access to what, granted when, removed when. Start it now, even with only your own accounts listed, so the habit exists before it matters.