Extra security: Approve changes from Claude
With Extra Security, Claude won't make any changes that send emails, transfer money, or can't be undone until you've approved them. Here's how to turn it on, and here's how to approve or reject changes.
When Claude is connected to your online store, it carries out your requests immediately. However, some changes cannot be undone. Once an email has been sent to your customers, it cannot be recalled, and a payment that was charged in error must be refunded. With Extra Security enabled, these types of changes are held until you’ve reviewed them and approved them. You approve changes from Claude on a page in your admin panel before they’re implemented.
Common changes, such as correcting a product description or a price, are still carried out immediately. This means you get more security when it comes to AI in your online store, without slowing down your daily tasks. If you haven’t gotten started with Claude yet, begin with “Manage Your Store with AI.”
How to Enable Extra Security
- Go to Integrations in the menu and click “ Manage Your Store with AI.”
- Click the “Customize Tools” button. You’ll be taken to the “AI Tools” page.
- Find the “Extra Security” card and toggle the switch to “On.” It’s turned off until you turn it on yourself.
- Click Save. The same button saves the access settings for each area: Read and Edit, Read Only, or Off. See Customize which tools Claude can use in your shop.
Extra Security applies to the entire online store, all users, and all connections to Claude or other AI assistants that use Shoporama’s AI connection. Standard integrations with an API key are not affected.
Which changes made by Claude require approval?
Shoporama evaluates each individual action. If it could have any of these side effects, it will wait for approval:
- Emails. An email to the customer, to customers on the waitlist, or to you as the store owner.
- Money. A payment withdrawal or cancellation, and a transfer to your accounting software.
- Shipping. An order placed with a shipping company.
- Deletions. An irreversible deletion.
- Scope. Many changes made at once.
- Customers. Consent to newsletters, loyalty points, and the customer’s login email.
Actions that are always pending
- Orders. Change status, cancel, mark as paid, send an invoice, order a shipping label, arrange partial delivery, or create an order.
- Customers. Import or delete customers, award or deduct loyalty points, set group prices, and add or unsubscribe newsletter subscribers.
- Deletions. Delete discount codes, blog posts, pages, menus, redirects, or images from the image library.
- Campaigns and Reviews. Create or delete campaigns, and approve or delete reviews.
When the content makes the change riskier
Some actions require approval only when the content makes them riskier. In that case, the “Why Approval? ” section on the approval page explains why. For example:
- Multiple shipping rates at once, a subscription price, or a redirect to an external address or a pattern (regex).
- A stock change or a return that sends emails to the waiting list.
- A new address on an order that has already been shipped or has a tracking number.
- Online store settings, shipping methods, and country-wide settings—such as language, inventory management, free shipping, or sales tax.
- Creating or importing customers with a welcome email or points.
The following still happens instantly
- Creating, editing, and deleting products. Deleted products go to the trash.
- Create and edit categories and menus, theme settings, and stylesheets.
- Create and edit discount codes, and edit promotions, blog posts, and pages.
- Stock levels without emails to the waiting list, and notes and tracking on an order.
- A single shipping rate and a redirect within the store.
When Claude is only retrieving information, or when you ask Claude to show you what would happen, authorization is never required, because nothing is changed.
When does it make sense to enable this feature?
Extra security is a good fit for stores where:
- multiple employees chat with Claude in the same store.
- there are new employees who are not yet familiar with the store and the customers.
- the catalog is large, and bulk changes are frequently made.
- it’s busy, for example, leading up to Black Friday.
- an agency is working in the store.
In the AI log, you can undo some changes—such as shipping rates and online store settings—but sent emails, payments, and deletions cannot be undone. That’s why it’s a good idea to review them before they take effect.
If, on the other hand, you’re working alone on the chat and mainly use Claude for text and statistics, it’s perfectly fine to leave Extra Security turned off.
Here’s how it works in practice
- You ask Claude to mark 25 orders as “Shipped.” With Extra Security, you’ll receive a single link, see for each order what the change triggers—such as an email to the customer—and approve them all at once before anything happens.
- You ask Claude to adjust the price of a product. With Extra Security, this still happens immediately.
- You ask Claude to offer free shipping to Denmark. With Extra Security, the change is held, and the approval page shows why.
How to Approve a Change from Claude
- You ask Claude to do something that requires approval. Claude doesn’t carry it out right away, but provides you with a link to the approval page. The link is valid for 24 hours.
- Open the link. If you’re not logged in—for example, on your phone—you’ll be taken directly to the approval page after logging in, even if you use two-factor authentication.
- Read what Claude wants to do and what the consequences might be.
- Tap “Approve and Proceed ” or “Reject.” You’ll see the message “The change has been approved and implemented” or “The change has been rejected. Nothing was changed.”
- Type in the chat that you’ve made your decision. Claude won’t receive a notification, but can check the status of the change and proceed from there.
If you double-click “Approve and Execute,” the change will only be executed once.
This displays the approval page
The page is titled “Approve Change from Claude” and displays Status, Received, and Expiration. Additionally:
- May result in. The possible side effects, such as emails.
- Why approval? This appears only when the content has made the change more risky.
- What will be done. The exact values that will be applied if you approve. The layout looks a bit technical, but you can still read details such as country, amount, and order numbers.
- Preview. Available for some actions, such as changing order status and shipping rates. It shows what the result looked like when Claude requested the change. Nothing has been saved yet. When changing the order status, it shows for each order what the change triggers—for example, an email to the customer or payment processing.
- Result. Appears once the change has been made.
Here’s what’s coming up
You don’t need to save Claude’s link. While Extra Security is enabled and something is pending, you can see it here:
- The menu. The item shows the number, for example, Manage the Store with AI (1).
- The "Manage the Store with AI" page. For example, it says "3 changes from Claude are awaiting your approval" with the "View Changes" button.
- Messages. You’ll receive a message from Claude: “Claude is waiting for you to approve a change. You’ll find it under Integrations > Manage the Store with AI.” No email will be sent.
- The AI Log. Pending changes are listed with the status “Pending Approval” and a link to the approval page, and you can filter by that status. When an approved change is implemented, a new row appears showing the result. Learn more about the AI Log.
The Approvals Page
The Approvals page does not have its own menu item. You can access it via “View approvals” on the Extra Security tab, “View changes” on the Manage the Store with AI page, the AI log, or Claude’s link.
The “Pending Approval” list has the following columns: Change, User, Received, and Expires. “User” is the person who connected Claude. “View Change” opens the change, and the actual approval takes place only after clicking “Approve and Execute” on the next page. Below that, “Recent Decisions” shows the status as “Approved and Executed,” “Rejected,” “Expired,” or “Failed,” and the “Decided by” column indicates who approved or rejected it. Changes on the list are deleted after 90 days.
Always Accept, or turn it off again
On the approval page, there is a checkbox labeled “Always accept changes from Claude”: “Approves this change and turns off Extra Security. Going forward, Claude will implement changes involving emails, payments, and deletions immediately. You can turn it back on under AI Tools."
Extra Security is only turned off if the change is actually carried out. Other pending changes remain and must still be approved or rejected individually.
If you turn off the toggle on the AI Tools page while changes are pending, new changes will be processed immediately again. Pending changes can still be approved or rejected; otherwise, they expire after 24 hours. The counter and the message about pending changes will disappear.
When a change cannot be applied
Expired. If you do not take action within 24 hours, the change will receive the status “Expired.” It can no longer be approved, and nothing will be executed. If you still want the change, ask Claude for it again.
Failed. When you approve a change, it is carried out using the same connection and the same rules as if Claude had done it directly. Therefore, it will not be carried out if:
- the connection to Claude has been removed.
- the connection belongs to a user with restricted access.
- the scope is now set to Off or Read-only.
- the limit on the number of changes has been reached.
In that case, the change is marked as "Failed," and the explanation appears under " Result."
Frequently Asked Questions
My son set up Claude for me. Can it send emails to my customers or withdraw money without my permission?
Yes, if the area has read and edit permissions, and Extra Security is turned off—which is the default setting. In that case, Claude will carry out the requested action immediately. Enable “Extra Security” under AI Tools, and emails and payments will be held until you click “Approve and Execute.”
What happens if I accidentally click “Reject” or don’t even get a chance to look at it?
In either case, nothing will change. If you don’t have time to review it, the change will expire after 24 hours. Just ask Claude to do it again.
Should I check the “Always Accept” box so I don’t have to approve things all the time?
Only if you’re sure. Checking this box turns off “Extra Security” for the entire store, so it applies to all users and all connections to Claude. If there are multiple people in the store, talk to your colleagues first. If you change your mind, you can turn it back on under AI Tools.
What if I don’t approve it until much later, or the order has changed in the meantime?
After 24 hours, the change cannot be approved. Before then, the exact values shown on the page will be processed according to the applicable rules when you click. The preview shows the situation as it was when Claude requested the change. If some time has passed, check the order before you approve it.
Can my employees approve the changes they requested from Claude themselves?
Yes. Any user with access to the store’s administration can approve it—not just the one who connected with Claude. However, supplier users, users with access only to specific categories, and order processors cannot view the approvals. You cannot designate specific approvers.
I have three stores. Do I need to enable this in all of them?
Yes. The extra security applies to one online store at a time, so you’ll need to enable it in each one.
If Claude needs to change the status of 300 orders, do I have to approve every single order?
No. Claude can change the status of up to 25 orders at a time, and such a bulk change counts as one approval. So 300 orders would result in 12 approvals.
Can I show my accountant who approved what?
Yes. The Approvals page shows, under “Recent Decisions,” what was changed, when, to what status, who authorized Claude, and—in the “Decided by” column—who approved or rejected it. The AI log shows the user behind each call. The information is stored for 90 days, so take a screenshot if you need to keep it longer.
If you have any questions about Extra Security or the AI integration in general, feel free to email support@shoporama.dk.
Related articles
Manage Your Store with AI: Get Started with Claude and MCP
Connect your Shoporama store to an AI assistant via MCP, and ask it to create orders, discount codes, and storefronts. Learn about the setup,...
Customize which tools Claude can use in your shop
AI Audit Log: See What the AI Has Been Up To in Your Store
The audit log shows every action an AI assistant has performed in your online store. See what’s logged, how to filter the log, and how to use it...
OAuth - give apps access to your webshop
Learn how OAuth works in Shoporama. Give third-party apps secure access to your online store without sharing your password.
Create more users in your shop
Guide to creating multiple user logins for your Shoporama admin.
Notifications: What the Admin Warns You About
Shoporama collects messages from all background processes on the notifications page. Find out where to locate it, what the messages regarding...