When StoreClaw is ready to perform an action that may affect store data, customer experience, account settings, or financial outcomes, it determines whether approval is required based on the connected account's approval policy, the action's risk level, and its business impact. When an approval card appears, you can review the planned action and decide whether to authorize it and for how long. Choosing an appropriate policy for each account helps balance operational efficiency with business safety.

How Sensitive Action Approvals Work

StoreClaw can connect to and operate business systems such as Shopify, Amazon, ERP platforms, email, customer support, and marketing tools through Plugins. Approval policies and individual approval decisions help you control changes to real business data:

  • When approval is required, StoreClaw identifies the Plugin or account it is about to use.
  • You can review the action and its potential impact in the approval card.
  • You can approve only the current action, the current request, or the current task.
  • You can deny the action and continue the chat with revised instructions.
  • You can configure a separate approval policy for each connected account.

Configure Approval Policies for Connected Accounts

After connecting an account through a Plugin, you can configure how StoreClaw requests approval for each store or platform account. On the Plugin detail page, locate the account in Connected Accounts and click Permissions.

This setting controls only when StoreClaw requests approval. It does not expand or reduce the connected account's permissions on the third-party platform. The data and actions StoreClaw can access still depend on the OAuth scopes, API Key permissions, and platform-account permissions granted during connection.

Option Meaning When to use it
Always ask StoreClaw can read account data but requests approval before performing any action New or unfamiliar accounts, or when you want to review every change
Allow low-risk actions (default) StoreClaw can complete routine low-risk actions automatically and asks before higher-risk actions Recommended for balancing efficiency with control of important actions
Allow all actions (high risk) StoreClaw reads data and performs actions within the connected account's authorized scope without asking each time Only highly trusted, repeatable internal workflows with controlled risk

Warning: After you select Allow all actions, StoreClaw may no longer ask separately before actions involving prices, inventory, publishing, customer outreach, or financial impact. Enable it only after verifying the workflow, target account, and action scope.

Note: These permissions apply only to connected Plugin accounts. They do not control local files, system commands, or local browser automation in the desktop app, which continue to use their respective safety confirmation mechanisms.

What Is a Low-Risk Action?

Low-risk actions normally do not immediately affect live store status, transaction outcomes, spending, customer outreach, account status, platform compliance, or important user-visible assets. Examples include:

  • Creating an unpublished product, page, post, video, or ad creative draft.
  • Editing an object that has not been published, launched, or activated.
  • Creating an inactive marketing campaign or coupon draft.
  • Saving a theme or admin configuration without publishing it immediately.

Reading account data normally does not require additional approval. StoreClaw can read data within the account's existing authorization scope for analysis, diagnostics, recommendations, or preparing proposed actions.

Which Actions Are Normally High Risk?

The following actions are not classified as low risk. Under Always ask or Allow low-risk actions, they normally trigger approval:

  • Deleting any business object or data.
  • Publishing a product, page, theme, post, video, advertisement, or marketing campaign.
  • Changing a product price, inventory level, discount, coupon, or campaign with immediate effect.
  • Affecting orders, refunds, payments, fulfillment, invoices, subscriptions, or advertising charges.
  • Sending messages, comments, direct messages, customer notifications, or marketing outreach.
  • Following, unfollowing, blocking, or banning users, or deleting comments.
  • Changing account details, permissions, payment methods, compliance settings, or platform status.
  • Adjusting the budget, bid, audience, schedule, conversion target, or live creative of an active advertisement.

An action can also be high risk even when it is not a deletion or publication. Examples include creating a free product, changing a product price to zero, applying a 100% or near-free discount, setting an unusually high advertising budget, removing a budget cap, or enabling unverified automatic expansion or bidding.

How StoreClaw Determines Risk

StoreClaw evaluates the action, available interface capabilities, and business impact. It considers:

  1. Whether it takes effect immediately: Actions that take effect immediately, after publication, or without another confirmation are usually higher risk.
  2. Whether it is user-visible: Actions that change content visible to customers, followers, or advertising audiences are usually higher risk.
  3. Whether it affects transactions or money: This includes prices, inventory, discounts, orders, refunds, payments, advertising budgets, bids, and charges.
  4. Whether it affects outreach or interaction: This includes publishing, messaging, commenting, following, unfollowing, blocking, banning, or expanding an advertising audience.
  5. Whether it affects an account or compliance: This includes account details, permissions, payment methods, compliance settings, and platform status.
  6. Whether it creates unusual business-loss risk: This includes free purchases, abnormal discounts, rapid advertising spend, or uncontrolled delivery.

Only changes that remain drafts, are unpublished and inactive, and do not create an external or real business impact may be classified as low risk.

Which Actions Are Sensitive or High Risk?

Actions that may have a real business impact include the following categories. Whether an approval card appears depends on the connected account's approval policy, the action risk, and the specific business impact:

  • Products: Creating, editing, or deleting products, descriptions, images, prices, categories, or tags.
  • Orders and fulfillment: Creating, editing, or canceling orders, and processing refunds, shipments, or fulfillment.
  • Inventory: Changing inventory quantities, locations, replenishment information, or synchronization rules.
  • Customer data: Adding, editing, or deleting customer, member, or shipping-address information.
  • Store settings: Changing payment, shipping, tax, discount, or marketing settings.
  • Customer communications: Sending email, direct messages, marketing messages, or customer notifications.
  • Billing and permissions: Actions that create charges or affect subscriptions, invoices, financial outcomes, or account permissions.
  • Local files and devices: Using the desktop app to create, overwrite, move, or delete files, run dangerous or unknown commands, or open a local browser for automation. Connected-account Permissions do not control these actions.

What Does the Approval Card Show?

The approval card normally shows:

  • The Plugin or account StoreClaw is about to use, such as a specific Shopify store.
  • The data to be created, edited, or deleted and the key details of the action.
  • The available approval scopes and the option to deny the action.

If the action contains many details, select Learn more and review the complete description before continuing.

Tip: Before approving, confirm that the account, target, changes, and scope match your request. If anything is unclear, deny the action and ask StoreClaw to explain it or reduce its scope.

Choose the Right Approval Scope

The approval card displays three buttons by default:

Allow for this request ↓ | Allow once | Deny

Select the arrow next to Allow for this request to access Always for this Task.

Option Scope When to use it
Allow once Performs only the current action; StoreClaw asks again before the next action You want to approve one step or review the process step by step
Allow for this request Completes the current request; approval is required again for your next request One request needs several related actions
Always for this Task Performs the actions needed for the current task; approval is required again for a new task A longer task requires a series of related actions
Deny Does not perform the current action or change the account The action, target, or scope does not match your intent

Allow Once

For example, StoreClaw is about to create a Shopify product named “001.” After you select Allow once, StoreClaw performs only that product-creation action. If it needs to update the images, inventory, or category next, it asks for approval again.

Allow for this request

For example, you ask StoreClaw to “create this product and complete its basic information.” If the request requires creating the product, writing its description, and adding tags, Allow for this request lets StoreClaw complete those related actions. StoreClaw asks again when you send a new request.

Always for This Task

This option is designed for longer workflows. A complete Shopify product-listing task may include creating a product, adding a description, uploading images, assigning a category, and setting inventory. After you select Always for this Task, StoreClaw can perform the related actions needed within that task. Approval is required again for a new task.

Deny

After you select Deny, StoreClaw stops the current action and does not change your account as a result of that action. You can continue the chat, revise the action, reduce its scope, or use another approach.

What Should I Check Before Approving?

Before authorizing an action, quickly confirm the following:

  1. Correct account: Make sure the Plugin, store, or business account is the one you intend to use.
  2. Correct action: Review exactly what StoreClaw will create, edit, delete, or send.
  3. Acceptable impact: Pay close attention to prices, inventory, refunds, customer messages, charges, and permission changes.
  4. Appropriate scope: If you are unsure about the next steps, choose Allow once. Use a broader scope only after you understand the full request or task.

FAQ

Q: Will StoreClaw automatically change my account after I connect a Plugin?

A: Connecting a Plugin does not start actions automatically. When you later ask StoreClaw to perform an action, whether it requests approval depends on the connected account's policy and the action risk. The default Allow low-risk actions policy performs routine low-risk actions automatically and asks before higher-risk or sensitive actions.

Q: Does changing Permissions alter the third-party platform's authorization scope?

A: No. Permissions control only when StoreClaw requests approval. They do not change OAuth scopes, API Key permissions, or the permissions of the third-party platform account itself.

Q: Does “Allow all actions” also apply to local files and system commands?

A: No. Permissions for connected Plugin accounts do not control local files, system commands, or local browser automation in the desktop app. Those actions continue to use their respective safety confirmation mechanisms.

Q: Can I continue the chat after denying an approval?

A: Yes. Denying the approval blocks only the current action. You can provide revised instructions and let StoreClaw submit an updated action for approval.

Q: What is the difference between a request and a task?

A: A request is the instruction you have just sent. A task may span multiple messages and several consecutive steps. Always for this Task has a broader scope, but StoreClaw still asks for approval again when you start a new task.

Q: What should I do if I do not understand the approval details?

A: Do not approve yet. Deny the action and ask StoreClaw to explain which data it will change, why the change is needed, and what impact it may have.