Can You See Every App's Access Scope in One Place?
App permission scope review on Shopify is a BUILD, because the admin discloses each app's access at install and then one app at a time from that app's about page. Shopify's install guide describes no consolidated fleet-wide view. A register you maintain, listing app, scopes, owner and approval date, turns a 40-app stack into a single page. Store Auditor, the closest listing at 0 reviews, scans performance instead.
Your profile — see how the verdict shifts
- Confidence
- Medium — What Shopify documents is precise and was re-read on 2026-09-05. The install screen names two permission groups: View personal data, covering the types of personal data the app can view such as customers, store owner and blog contributors, and View and edit store data, covering the areas of your store the app can view and edit. After installation, you can review an app's activity and permissions at any time from that app's about page. The confidence is Medium rather than High for one specific reason: the absence of a consolidated cross-app view is established by that page never describing one, not by Shopify stating that none exists. Read the page yourself before quoting the absence in a security review. On the app side the market is thin. Store Auditor is Built for Shopify and carries 0 reviews, and what it actually does is scan storefront pages and estimate each installed app's revenue impact, a per-app inventory of performance rather than of permissions. Nothing on its listing reads or displays granted access scopes. The audit-log apps in the same category record what changed in the admin rather than what each app is entitled to read. So the fleet view is a governance artifact you assemble, and the raw material is the about page Shopify already gives you.
- Reference scenario
- $20M–$100M GMV · Shopify Plus · 30–60 installed apps across a multi-store organization · several staff with install rights
- As of
- September 2026
Decision at a Glance
| Your profile | Verdict | Why |
|---|---|---|
| Under 10 installed apps · one person installs everything | WAIT | Ten about pages is an afternoon, once a year. The register costs more than the risk it retires at this size. |
| 10–30 apps · one approver, no formal process | CUSTOMIZE | A spreadsheet register plus an install alert from an audit-log app covers this for under $20/month (illustrative). Skip the tooling build until the fleet grows. |
| 30–60 apps · multiple installers across a Plus organization | BUILD | Nobody knows what the fleet can read, and manual review across 60 about pages never actually happens twice. A register with an approval gate is the only version that holds. |
| Security certification or recurring customer security reviews | BUILD | Reviewers ask which third parties can read customer personal data, and want a dated list. Screenshots of about pages are not an answer you want to give twice. |
What App Permission Scope Review Actually Drives
| Outcome | Impact | How it works |
|---|---|---|
| Operational efficiency | High | A security questionnaire asking which third parties read customer personal data becomes a query against the register instead of a day of opening about pages one at a time. |
| Data & insight | High | A dated map of which app holds which scope is the input to every access review, and it usually surfaces installed apps that nobody in the business still owns. |
| Revenue — indirect | Medium | Enterprise security reviews gate deals, and a named third-party access inventory shortens the review cycle rather than adding a round of follow-up questions. |
| Customer experience | Low | Shoppers see none of this until an app with broad access has an incident, at which point the register decides how fast you can scope the exposure. |
Spend ceiling: The value here is the register and the approval gate, not software. Spend on the first full fleet sweep and the process that keeps it current — a tool that stores rows nobody updates is worth nothing at any price.
What buying enables (top apps)
- + An immediate, ranked view of which installed apps drag storefront performance and estimated revenue
- + Install alerting from audit-log apps, so a new app arriving is visible the same day
- + Multi-store dashboards and API export on Store Auditor's top tier for organizations running several stores
- + 365-day scan history that shows how the app stack's performance drifted over a year
What building additionally unlocks
- + A fleet-wide answer to which apps can read customer personal data, which Shopify's admin surfaces only per app
- + An approval gate that stops a broad-scope app from arriving without anyone deciding it should
- + Dated evidence for a security review or certification, in a format your reviewer can read directly
- + Ownership rows that make uninstalling abandoned apps an easy decision rather than a risky one
Find Your Verdict in 3 Questions
Does anyone outside your team ask which third parties can read your customer data?
Yes: Go to question 2.
No: Your verdict: WAIT — review about pages once a year and spend the budget on something a customer notices.
Do more than 20 apps sit installed, or do several people hold install rights?
Yes: Your verdict: BUILD — a register with an approval gate, from $8,000 (Deploi estimate, illustrative), is the only version that stays true.
No: Go to question 3.
Is an install alert plus a spreadsheet enough for the next 12 months?
Yes: Your verdict: CUSTOMIZE — pair an audit-log app's install alerting with a manual register and revisit when the fleet passes 20 apps.
No: Your verdict: BUILD — no App Store listing we checked reads granted access scopes, so the fleet view is yours to assemble.
The TCC Scorecard — 12 Dimensions
TCC — Total Cost of Capability: what it actually costs to have this capability over three years, whichever way you get it. Each dimension is scored 0–5 for both paths. How we score →
| Dimension | Buy | Build | Why |
|---|---|---|---|
| Cost | |||
| Acquisition & implementation | An app installs the same day; the register takes 3–6 weeks including the first full sweep of every installed app (Deploi estimate, illustrative). | ||
| Recurring fees | Store Auditor's Pro tier runs $29/month and Plus $99/month (verified Sep 2026); a register you own has no subscription line. | ||
| Maintenance & upgrades | The register only stays true if someone updates it at every install, which is process discipline rather than engineering work. | ||
| Switching & exit | An app's scan history leaves with the app; a register in your own systems survives every vendor decision you make later. | ||
| Risk | |||
| Vendor risk | Store Auditor carries 0 reviews, so the category's only close listing is entirely unproven; a register has no vendor to lose. | ||
| Security & compliance surface | Adding another app to see your apps is a real irony and a real extra processor; the register adds none. | ||
| Platform-deprecation exposure | Both depend on Shopify continuing to disclose scopes on the about page, which has been stable and is the documented behavior today. | ||
| Value | |||
| Fit to requirement | Store Auditor estimates each app's revenue impact rather than its data access, so the app path answers a neighboring question well and this one not at all. | ||
| Time to market | An app scans this week; the register's value arrives after the first complete sweep of the fleet. | ||
| Performance & scale | Review effort under the app path grows with every install; a register with an approval gate keeps the per-app cost flat. | ||
| Data ownership & AI-readiness | A structured register of who can read what is queryable evidence you own, and it feeds access reviews and vendor questionnaires directly. | ||
| Focus & opportunity cost | This is governance work with no revenue attached, so it earns its place only when the fleet or the obligation is real. | ||
The App Landscape
| App | Status | Pricing | Best for |
|---|---|---|---|
| Store Auditor | Live — flagged — 0 reviews; unreviewed listing, though Built for Shopify. Store Auditor scans storefront pages and estimates each installed app's revenue impact, which is the closest real building block on the Store and still not a fit: nothing on its listing reads or displays an app's granted data-access scopes. Useful for deciding which apps to remove, not for knowing what they can read. | Free (1 scan per month, homepage only, top 3 issues shown); Pro $29/month (unlimited scans on every storefront page, full per-app revenue impact breakdown, ranked fix list, 365-day scan history); Plus $99/month (multi-store dashboard, API access for export and automation, priority email support); 14-day free trial on Pro and Plus (verified Sep 2026) | Finding which installed apps cost you storefront performance and revenue |
| Store security and admin audit apps | Category — The nearest category, and a thin one for this job. Audit-log listings record what changed in the admin, including app installs, which gives you an alert when a new app arrives. None of them assembles a fleet-wide view of what each installed app is permitted to read, because Shopify surfaces that per app on the about page. | Roughly $10–$99/month across the category (illustrative) | Install alerts and change history around the app fleet, not scope review |
| App access register (custom) | Build lane — One row per installed app: granted personal-data and store-data scopes captured at approval, the business owner, the approval date, the next review date, and a link to the about page. Pair it with an approval gate so nothing installs without a row, and an install alert so nothing slips past the gate. | $8,000–$25,000 one-time plus review time (Deploi estimate, illustrative) | A security review that asks what every installed app can read |
The Build Path
- Register plus approval gate: A spreadsheet or internal tool with one row per app, populated from the install screen at approval time. The gate matters more than the tool: no row, no install.
- Scoped inventory for custom apps: Custom apps you build declare their access scopes in configuration you already keep in version control, so those rows generate themselves. The manual work is the public apps.
- Install alerting and scheduled re-review: An audit-log app or the store activity log tells you when an app arrives; a calendared quarterly sweep of about pages catches scope changes that arrived with an app update.
- Effort band
- $8,000–$25,000 one-time (Deploi estimate, illustrative); lands in the $10–25K contact-form band, with the first full fleet sweep the bulk of it
- Typical timeline
- 3–6 weeks (Deploi estimate, illustrative): sweep the installed fleet first, then wire the gate and the alerting
- Maintenance, honestly
- $3,000–$7,000/yr (Deploi estimate, illustrative): a quarterly sweep of about pages, register updates at each install, and removing rows for apps you uninstall.
- What you own — and what you take on
- You own: a dated, queryable list of which third parties can read customer personal data, and an approval trail that answers a security questionnaire directly. You take on: the discipline of updating it at install time, which is where every register of this kind dies.
3-Year Total Cost of Capability
| Buy (app path) | Build (custom path) | |
|---|---|---|
| Year 0 (setup) | $0–$350 (illustrative) | $8,000–$25,000 (Deploi estimate, illustrative) |
| Years 1–3 (recurring) | $1,044–$3,564 (illustrative) | $9,000–$21,000 (Deploi estimate, illustrative) |
| 3-year total | ≈$1,044–$3,900 (illustrative) | ≈$17,000–$46,000 (Deploi estimate, illustrative) |
- † All figures illustrative samples for the reference scenario — not quotes, not verified pricing.
- † App path: Store Auditor's Pro tier held flat for three years, which answers app performance rather than app permissions.
- † Build path: one full sweep of a 40-app fleet, a register, an approval gate, and quarterly re-review; three-year horizon.
What the Sticker Price Hides
On the buy path
- — Store Auditor scores app performance, not app permissions — the names are close enough to buy the wrong thing
- — Its listing carries 0 reviews, so the roadmap and the support are both unproven
- — Multi-store dashboards and API export sit on the $99/month Plus tier (verified Sep 2026), which is where a Plus organization would need to be
- — An app installed to watch your apps is one more processor with its own access scopes to record
On the build path
- — The first fleet sweep is the expensive part, and it is boring enough to get deferred
- — A register nobody updates at install time is worse than none, because it reads as authoritative
- — App updates can change requested scopes, so a quarterly re-review is part of the cost rather than optional
- — $3,000–$7,000/yr of upkeep and sweep time (Deploi estimate, illustrative)
What Merchants Say
The recurring theme in Plus operations: nobody can say which of the installed apps can read customer email addresses without opening every app's page one by one.
Security questionnaires are where this bites — the request is a list of third parties with access to personal data, and the honest answer takes a day of clicking to assemble.
If You Change Your Mind Later
If you bought and outgrow it
Uninstalling Store Auditor costs you its scan history and nothing else, since the permissions data was never in it. Export the ranked fix list first if it drove a performance backlog, and note that the 365-day history is a plan feature rather than a file you hold.
If you built and want out
The register is a document in your own systems, so there is nothing to strand and nothing to migrate. Every row stays readable in a spreadsheet, and the approval gate is process rather than software — it survives any tooling change you make later.
When This Answer Changes
We're watching for:
- ▸ Shopify adding a consolidated app-permissions view to the admin, which would retire most of this build
- ▸ An App Store listing that genuinely reads and displays granted access scopes across the fleet — none we checked does
- ▸ A customer security review or certification adding a named third-party access inventory to its evidence list
Verdict change log:
No changes since first publication (September 2026).
Common Questions
Where does Shopify show what an app can access?
Shopify shows an app's access on the install screen and afterward on that app's about page. The install screen names two groups: View personal data, covering customers, store owner and blog contributors, and View and edit store data. Shopify's help page says you can review an app's activity and permissions at any time from its about page. Reviewing 40 installed apps means opening 40 about pages.
Is there a single dashboard for all app permissions?
Shopify's install-and-manage-apps guide documents no consolidated permissions view, and describes review one app at a time from each app's about page. The absence is confirmed by reading that page rather than by a Shopify statement that none exists. Teams that need a fleet view build a register, one row per app, carrying granted scopes, business owner and approval date. Budget $8,000–$25,000 for the tooling around it (Deploi estimate, illustrative).
Does Store Auditor show app permissions?
Store Auditor scans storefront pages and estimates each installed app's revenue impact, not its data-access scopes. Pro costs $29/month for unlimited scans and 365-day scan history, and Plus costs $99/month for a multi-store dashboard (verified Sep 2026). The listing carries 0 reviews, so treat it as young. For a permissions register, the source is still each app's about page.
Your Next Steps
If you're going with BUILD(matches your selected profile)
- List every installed app across every store in the organization, including ones nobody claims
- Open each about page and record the granted personal-data and store-data scopes
- Assign a business owner and a next-review date to every row
- Wire an approval gate: no register row, no install, no exceptions for urgent requests
- Set a quarterly sweep to catch scope changes that arrived with an app update
If you're going with CUSTOMIZE
- Turn on install alerting from an audit-log app so new arrivals are visible the same day
- Keep a single spreadsheet register and fill it at approval time, not afterward
- Uninstall the apps nobody owns, the fastest reduction in access surface available
- Revisit the tooling build when the fleet passes 20 apps or a certification lands
Official Docs & Sources
- Install and manage apps — Shopify Help Center
- App types: public, custom and unlisted — Shopify Help Center
- Store activity log — Shopify Help Center
Official documentation linked for verification — our verdicts and estimates are our own.
Related Decisions
Can You Trust Every App Store App to Honor GDPR Deletion?
Shopify rejects any App Store app that fails to answer the mandatory compliance webhooks, with a 30-day action window. Custom apps sit outside that scope.
Does 'Built for Shopify' Mean an App Passed Security Review?
Built for Shopify certifies Core Web Vitals, admin latency and 50 net installs. No security or data-handling requirement appears anywhere in the criteria.
Do Custom Apps Inherit Any of Shopify's Compliance Vetting?
Shopify's app review covers both public app types, listed and unlisted. Custom apps are never described as reviewed, and compliance webhooks follow the App Store.
Should You Build or Buy Protected Customer Data Access on Plus?
No app grants protected customer data access; Shopify grants it per app. On Plus, build the custom app when the workflow is yours; buy a certified app when one fits.
Shopify Theme Sections: Buy Premium or Build a Section Library?
A custom theme section library wins at mid-market campaign tempo; below the floor, a premium theme is the right call.
Know what your app fleet can read?
We sweep every installed app, capture what each one is permitted to see, and leave you a register plus an approval gate that keeps it true. Security reviews stop being a week of clicking.
Contact us todayVerdict scored for the reference scenario above. Estimates are not quotes; app pricing carries its verification date and gets re-verified quarterly. Full scoring anchors: see the TCC methodology.
Read how we score these decisions (the TCC Framework). No affiliate links, no paid placement — no app vendor pays to appear here.