14. User access and controls
- Owner
- You (solo operation)
- Trigger
- Whenever access to Shopify, banking, or accounting systems is granted, changed, or should be removed.
- Approval
- You approve every access grant.
Procedure
- Today, you hold all Shopify, banking, and accounting access directly — there is no separate access list to maintain yet beyond your own accounts.
- Enable two-factor authentication on Shopify, banking, and accounting/bookkeeping accounts now, before anyone else needs access — the effort is the same either way, and it closes a gap before it matters.
- When granting access to anyone else (staff, bookkeeper, photographer), grant the minimum permission level the task actually requires — e.g. a photographer needs product image upload, not financial data.
- Remove access immediately when someone's role ends. Do not leave dormant accounts active.
- Where practical, once more than one person is involved, separate who creates a transaction, who approves it, and who executes payment, so no single person controls all three.
Required evidence
A simple access log — who has access to what, granted when, removed when. Start it now, even with only your own accounts listed, so the habit exists before it matters.