Set the boundary before the request arrives.
Choose what stays a draft, what can reply, and what must pause. Shopkeeper carries the exact Shopify work to the merchant, then keeps the decision and result reviewable.
Control model · synthetic order #3102
Swap Medium / Sand → Small / Sand
Proposal
Paid · unfulfilled
Same price · Small in stock · Ask first
Merchant control
Approved in iMessage
The exact proposed change stays attached.
Recorded result
Completed
Human approved · Shopify updated
This diagram explains the control model with fictional data; it is not presented as customer evidence.
Start cautious. Change the mode deliberately.
Nothing sends or changes
Draft only
Shopkeeper prepares work for review but does not send customer replies or mutate Shopify.
The default
Ask first
Routine replies can keep moving, while changes, money, and exceptions pause for merchant approval.
Explicit opt-in
Trusted
Simple replies can send without review. Refunds, cancellations, configured limits, and other approval rules still apply.
A mode is the start, not the whole control system.
Action limits, merchant judgment, and reviewable outcomes stack on top of the selected autonomy mode.
Action limits
Set the refund cap, block cancellations or custom line items, and disable tool categories the workspace should not use.
Merchant judgment
Use iMessage for phone-native direction and approval, or review the same request in the dashboard.
Reviewable outcomes
The action history ties the proposal, mode, approver, execution status, result, and source thread together.
Three outcomes, stated before execution.
- 01
Follow the selected mode
Routine and structurally safe information work follows the configured autonomy.
- 02
Pause for judgment
Consequential, exceptional, or uncertain work waits with the relevant context attached.
- 03
Block or escalate
Ineligible or disabled work stops instead of crossing a limit or inventing policy.
Configure the rules and one place to reach you.
Connect Shopify, choose Draft only, Ask first, or Trusted, review the action permissions and refund cap, and add store policies. Connect iMessage for phone-native control; the dashboard remains the configuration, review, and audit surface.
- Shopify connected for order and customer context
- An autonomy mode selected deliberately
- Action permissions, refund cap, and store policies reviewed
- iMessage or dashboard available for merchant judgment
Follow the product story.
Where does the boundary hold?
- Does Ask first mean every reply waits for me?
- No. In Ask first, routine and structurally safe information replies may send automatically. Changes, money, exceptions, and work that needs judgment pause. Choose Draft only if every reply must stay a draft.
- Can I approve from my phone?
- Yes. Connect iMessage as the merchant-control channel to review and direct Shopkeeper from the phone. The dashboard remains available for configuration, review, and audit.
- Does a refund cap guarantee a refund will run?
- No. The cap is one boundary, not an eligibility promise. The order, requested amount, supported refund path, workspace rules, and current Shopify state must still allow the action.
- What happens outside policy?
- Shopkeeper can ask for missing judgment, block an ineligible action, or escalate the request. It should not improvise a store policy or force a Shopify mutation through a failed guardrail.
- Can Shopify mutations run automatically?
- Mutative work defaults to approval. Automatic execution requires explicit rollout configuration and remains subject to action permissions, limits, eligibility checks, and the execution ledger; broad autonomous mutation is not the launch promise.
- What can I inspect afterward?
- The action history shows the source channel, summary, customer-facing output when present, tool outcomes, execution mode, status, timing, and merchant approver when one was required.