← Hub

Shopify
Access Setup

Two things to switch on, about fifteen minutes together. What each one grants, what it is incapable of reaching, and why the live storefront cannot change without you clicking publish.

yoreh.co · Setup walkthrough · Both steps reversible
What This Does
And Does Not Do
Worth two minutes before any clicking. The safety here does not come from us being careful. It comes from the access itself being incapable of the things that would worry you.
What it allows
Reading your product titles, descriptions and SEO text
Reading your pages, blogs and translations
Working on a copy of your theme
Sending you a preview link to review
What it cannot do
See a single order or customer record
Change a price, a product or your inventory
Edit the theme your customers currently see
Publish anything to the live store
The short version We are asking for permission to look at your store content, and permission to work on a duplicate of your theme. Publishing stays with you, as a manual click, every time.
One consequence worth naming upfront Because these are read only, we cannot write SEO titles and descriptions back to your store ourselves. They come to you as a prepared file that you import, which has the useful side effect of leaving you a clean before and after at every step. If you would rather we applied them directly, that means adding a write permission to the same app later. We are not asking for it now, and we would raise it with you properly rather than slipping it in.
Theme Access
A free Shopify app that issues a password for working on themes. It is scoped to themes and nothing else, so it is structurally unable to see products, orders or customers. Each person gets their own password, and you can revoke any of them individually.
Read Only
App Token
This lets us read your product and page content programmatically, so the audit covers all seventy products accurately instead of by hand. Every permission requested is a read permission. None of them can write, and none of them touch orders or customers.
How Theme Work
Actually Runs
A Shopify store can hold many themes, but only one is published. Every other theme sits in your library, invisible to customers, with a private preview link that renders against your real products and prices. That is what we work on. Your live theme is never edited.
Your live theme keeps running
Untouched throughout. Customers see exactly what they see today, for the entire duration of the work.
Nothing changes here
We duplicate it
A copy is made and left unpublished. It carries your current design, settings and content exactly as they are now.
Node AI
All edits happen on the copy
Headings, structured data, crawler rules. Every change lands on the duplicate and nowhere else.
Node AI
You get a preview link
A working version of your storefront with the changes applied, running on your real catalogue. Only people with the link can reach it.
Fin reviews
You publish, by hand
One click in your admin, whenever you are satisfied. If anything looks wrong afterwards, republishing the previous theme puts everything back in seconds, because Shopify keeps it in your library.
Fin only
Being precise about this Worth stating plainly, because it matters. Shopify does not enforce this part. A theme password is able to write to a published theme, and the command to do it exists. What we do is configure our tooling to refuse those commands, so it cannot happen in a hurry or by accident. That is a working practice we hold ourselves to, and you should read it as such rather than as a lock.

The protections you can verify yourself are the ones that matter: your live theme stays in your library untouched, nothing reaches customers without your click, and republishing the previous version restores everything in seconds. If you want a rollback that predates our involvement entirely, duplicate your live theme once before we start and keep it aside.
Turning It Off
Both grants are independent and revocable at any moment, without our involvement and without affecting anything else on the store.