B2B Marshal Policy

App Permissions and Scopes

Merchant-facing explanation of the Shopify scopes configured for B2B Marshal.

As of August 19, 2026. B2B Marshal's production configuration requests the 21 Shopify scopes below. Shopify access remains subject to platform eligibility, protected customer-data approval, restricted-scope approval, and the scopes actually granted to each installation.

Company and customer resources

  • read_customers, write_customers, read_companies, and write_companies: access Shopify business-customer Company and CompanyLocation resources; synchronize company/location identifiers, names, external IDs, counts, lifetime facts, B2B settings, and related summaries; and write B2B Marshal's app-owned company/location credit-projection metafields. B2B Marshal does not store or edit customer contact profiles, customer email, phone, or address fields.

Shopify's API can authorize Company and CompanyLocation resources through customer/company scope families. B2B Marshal requests the configured families for its B2B resource and app-owned metafield workflows; it does not use these permissions to market to customers or create a customer database.

Orders, refunds, transactions, and payment terms

  • read_orders: read B2B order identity, company/location association, timestamps, financial/fulfillment/return state, amounts, refunds, transaction timing/status, and payment schedules needed for exposure, aging, payment reliability, synchronization, and audit.
  • read_all_orders: extend approved order access beyond Shopify's default recent-order window so full-history reconciliation can establish accurate account coverage. Without an approved and granted scope, B2B Marshal labels coverage as bounded and avoids destructive unseen-history cleanup.
  • write_orders: authorizes Shopify order-resource writes. B2B Marshal's reconciliation of ordinary completed orders is read-only; it does not edit order totals, payment transactions, fulfillment, or customer data. Use of this scope is limited to documented B2B Marshal order-management purposes and remains subject to least-privilege review.
  • read_payment_terms: read order and location payment-term templates, schedules, issued/due/completed timestamps, and balances needed to determine due and overdue state.
  • read_draft_orders and write_draft_orders: identify app-routed B2B review drafts and add or maintain the B2B Marshal review tag, concise merchant note, and app-owned review metadata. Ordinary drafts created directly in Shopify admin are not annotated by B2B Marshal.

Checkout resources

  • read_payment_customizations and write_payment_customizations: read, create, update, enable, and repair the app-owned payment customization used for configured payment-method and eligible payment-term actions.
  • read_delivery_customizations and write_delivery_customizations: read, create, update, enable, and repair the app-owned delivery customization used for account shipping-option restrictions.
  • read_validations and write_validations: read, create, update, enable, and repair the app-owned cart/checkout validation used for credit holds, credit-policy blocks, order limits, and quantity rules.
  • read_discounts and write_discounts: read, create, update, enable, and repair the app-owned automatic free-shipping discount and the combined ORDER + PRODUCT automatic discount used for company/location order-subtotal and product/variant-quantity tiers.

B2B Marshal keeps at most one app-owned Shopify resource per checkout capability rather than creating one resource per company.

Tiered discounts do not require customer contact fields. Shopify supplies the purchasing company/location and applicable cart-line inputs directly to the discount Function at checkout.

Products and shipping

  • read_products and write_products: authorize product/variant identity reads and versioned app-owned product metafields for the validation architecture. Current static company/location quantity controls resolve from company/location projections. B2B Marshal does not edit product titles, descriptions, prices, inventory, images, or publication status.
  • read_shipping: load active shipping/delivery option titles used in merchant policy editors and refresh them after delivery-profile changes. B2B Marshal does not request write_shipping and does not edit Shopify delivery profiles or carrier-service configuration.

Protected customer data and minimization

Shopify treats order, draft-order, refund, transaction, and related data as protected customer data even when direct contact fields are omitted. B2B Marshal must receive applicable approval and uses selected financial/account fields for the stated exposure, reconciliation, policy, and audit purposes.

B2B Marshal does not request or store customer names, contact email, phone, billing/shipping addresses, product line-item descriptions, or payment card data for these workflows. See the Privacy Policy for the exact stored-data description.