App-specific disclosure
CommerceGuard Revenue Assurance
Also known as: CommerceGuard
Tests revenue-critical Shopify workflows, correlates failures with observable changes, estimates revenue at risk, and supports controlled recovery.
Read-first monitoring with progressive optional permissions. Write access is disabled by default; any narrow remediation requires explicit enablement, preview, approval, verification, and rollback where supported.
Information by use level
Store, catalog, and configuration
Required- Examples
- shop and product IDs; Markets; inventory; discounts; theme metadata
- Source
- Shopify
- Purpose
- Discover the store and build monitoring coverage.
Synthetic journey evidence
Required- Examples
- test results; redacted screenshots; timing; selected console and network errors
- Source
- Controlled browser runs
- Purpose
- Detect and investigate workflow failures.
Order-derived and customer-event metrics
Optional- Examples
- aggregated order or revenue metrics; selected protected order fields; pixel events
- Source
- Shopify, when separately enabled
- Purpose
- Measure impact and verify configured journeys.
Narrow remediation data
Future- Examples
- resource state; preview; approval; verification; rollback record
- Source
- Shopify and authorized users
- Purpose
- Support a future, controlled remediation feature.
Customer identity and payment secrets
Not used- Examples
- customer passwords; payment credentials; unnecessary names or full addresses
- Source
- Not intentionally requested
- Purpose
- These fields are normally avoided.
Sources
- Shopify Admin GraphQL API
- Shopify webhooks
- controlled synthetic journeys
- merchant configuration
- merchant-selected integrations
Purposes
- Discover configuration
- run synthetic checks
- manage incidents
- estimate exposure as a range
- notify teams
- verify recovery
- maintain an audit trail
| Scope | Status | Why | Review |
|---|---|---|---|
read_products | ● Required | Catalog assertions. | Confirm this scope and its status against the production app configuration. |
read_inventory | ● Required | Inventory controls. | Confirm this scope and its status against the production app configuration. |
read_locations | ● Required | Location-aware controls. | Confirm this scope and its status against the production app configuration. |
read_discounts | ● Required | Promotion checks. | Confirm this scope and its status against the production app configuration. |
read_markets | ◇ Optional | Market-aware monitoring when enabled. | Confirm this scope and its status against the production app configuration. |
read_themes | ◇ Optional | Theme monitoring pack. | Confirm this scope and its status against the production app configuration. |
read_orders | ◷ Future | Optional order-derived verification; not core initial access. | Protected customer data review may be required. Confirm this scope and its status against the production app configuration. |
write scopes | ◷ Future | Narrow remediation only; never requested during initial installation. | Confirm this scope and its status against the production app configuration. |
Integrations and AI
Integrations
- [[CONFIRM_COMMERCEGUARD_INTEGRATIONS]]
AI status: Confirmation required. Generative AI: confirmation required.
Configured or proposed uses
- Evidence summarization
- plausible-cause ranking
- draft incident briefs
Limitations
- Must show confidence and evidence
- must not invent loss
- must not silently change production
- must not use customer PII for shared model training
Decisions and write access
Automated decisioning
Operational severity and risk estimates are not decisions about a person. Assumptions and confidence should be visible and overridable with an audit note.
Write access
Write access is disabled by default. Any future remediation must use narrow scopes, current-state checks, authorization, approval, idempotency, audit logging, verification, and rollback where supported.
Protected customer data posture: Confirmation required.
Minimization
- Prefer aggregate and synthetic data
- redact screenshots, URLs, headers, and cookies
- mask test credentials
- never store payment credentials
Retention and uninstall
Retention notes
- Configuration, synthetic evidence, incidents, audit events, order-derived metrics, and secrets each require a confirmed period.
On uninstall
- Normal app processing and active jobs stop; active sessions and connector access are revoked.
- Secrets are deleted or queued for deletion, and ordinary app data is deleted or anonymized under the configured retention rules.
- Backups expire through rotation; isolated records may remain where a legal, fiscal, security, dispute, or legal-hold exception applies.
- Validated Shopify privacy webhooks are processed where required.