When you hire a person, you trust them with a lot but not with everything. The new hire in the warehouse does not get to cancel orders. The freelancer writing product copy does not get to change prices. Nobody gets to email your whole customer list on a hunch.
StoreWorkers works the same way. Every worker has things it reads on its own, things it asks you about first, and a short list of things it can never do without you, whatever else you have allowed.
The list
- Cancel an order. A cancellation is a customer conversation and a refund. A worker can tell you an order looks like it should be cancelled. You cancel it.
- Change a price. The pricing watch worker will show you the products you are selling at a loss. It will not touch a price. Neither will the promo manager, even to end a promotion early.
- Delete a product or customer. Deletion is the one thing you cannot undo, so no worker can start it.
- Refund without your yes. Small refunds can be a one-tap approval in your queue. They are still an approval.
- Email your whole customer list. The winback worker writes to customers who have gone quiet, one message at a time, each one shown to you first. There is no "send to everyone".
- Publish anything to your storefront. Drafted descriptions, rewritten titles and new meta stay drafts until you publish them.
Why it is fixed
It would have been easy to make this a setting. Plenty of tools do, with a checkbox labelled something like "allow autonomous actions". We did not, for two reasons.
The first is that a setting can be changed by the wrong person. An agency managing your store, a new member of your team, or a support agent on our side could tick a box. We would rather there was no box.
The second is that the list is what lets shadow mode and graduation mean something. When you let a worker act on its own for one kind of task, you are choosing from the tasks that were always yours to delegate. The six above were never on the table, so you never have to remember to withhold them.
How it is enforced
The list is written into the shape of every worker before it runs, not checked after the fact. A worker's tools are classified as safe, sensitive or destructive, and a destructive tool cannot be set to run on its own by any configuration: not the merchant's, not an agency's, not an administrator's. If a worker were somehow to ask for one of these actions, the request lands in your approval queue like any other and waits there.
Every action a worker takes, proposes or is refused is recorded in its work log with who asked and who approved. That log stays even if you let the worker go.
What that leaves
Quite a lot, as it turns out. Reading orders, products, inventory and customers. Drafting emails, descriptions and replies. Flagging stuck orders and risky ones. Proposing reorders and promotions. Everything that takes time and attention, with the decisions that take judgement left where they belong.



