A clear path from install to recovery

Use this guide to open the app securely, understand catalog work, control access, and recover from a failed run without guessing.

Evidence before action.

Core catalog auditing is read-only. Supported normalization writes begin with an exact preview and retain an eligible narrow rollback. A product description is written only from the merchant's visible draft, after Shopify is checked for a newer description, and verified before its finding is closed.

Install and open from Shopify

The secure entry point is always Shopify-owned.

  1. Install the app from its Shopify App Store listing or the app's install control in Shopify's Dev Dashboard.
  2. In Shopify Admin, open Apps, then choose Catalog Command.
  3. Shopify completes the secure authorization flow and returns you to the embedded app.
No manual store entry

This site never asks you to type a store domain to start installation or sign in.

What the first catalog sync does

A private derived view is built without changing Shopify.

  1. Opening Overview for a new installation queues the first catalog synchronization.
  2. Bounded background jobs read products, variants, options, identifiers, pricing, inventory, media metadata, and tags.
  3. Deterministic rules create readiness results and findings with the exact observed evidence.
  4. Progress remains visible in Runs. You can leave the page and return while work continues.

Shopify remains the catalog source of truth. A sync or reconciliation does not write product fields.

Plans follow the work you want done

There is no free tier. Every store subscribes before the first audit, and every plan begins with a 14-day free trial.

PlanPublic priceWhat it adds
Essential14 days free, then $9/monthRecurring merchant-approved safe-fix capacity.
Growth14 days free, then $29/monthOpt-in Publish Guard automatic protection.
Pro14 days free, then $79/monthRead-only catalog Q&A, bounded storefront checks, and higher catalog capacity and history.
Scale14 days free, then $199/monthHigher catalog and automation capacity, Portfolio Control, and two-year history.
Allowances fail closed

Access begins only after Shopify confirms the active plan; returning from the plan selector is not enough. Every plan trial lasts 14 days, then Shopify starts billing unless the merchant cancels. There is no free tier, and annual billing is not available.

Access scopes stay separate

Read-only core access is independent from optional writes.

Requiredread_products

Synchronizes the product catalog and powers audits, reports, findings, and exports.

Optionalwrite_products

Applies or rolls back an explicitly approved title, vendor, product-type, or tag normalization. Growth can use it only for the Publish Guard safe classes you separately approve. Grant or revoke it from Settings > Access.

How a supported safe change works

Nothing is applied from a suggestion alone.

  1. 1

    Preview

    Review the exact before and after values for a supported title, vendor, product-type, or tag normalization.

  2. 2

    Check for drift

    The app re-reads Shopify. If the source changed, the change stops with a conflict and does not overwrite the newer state.

  3. 3

    Apply and verify

    Only the approved field delta is written, then Shopify is read again to verify the result. A successful external field change consumes one allowance unit.

  4. 4

    Roll back narrowly

    A verified change retains its inverse. Rollback proceeds only while the current product state still matches.

Publish Guard protects only what you approve

Observation and suggestions stay separate from automatic writes.

  1. Open Publish Guard and choose whether the app stays off, observes, suggests, or can approve eligible work.
  2. Growth is required for automatic handling. Select the exact deterministic safe classes you accept: trimming safe outer tag whitespace and removing tags that normalize to empty.
  3. Set a daily maximum and explicitly enable automatic protection. Ambiguous tag work and every unapproved class remain in review.
  4. Each candidate still needs current-state checks, remaining allowance, optional write access, and post-write verification. The operational kill switch can stop the automatic path.

Publish Guard never turns a broad recommendation into a write and never silently widens the classes you approved.

Use Optimize as a bounded readiness workspace

The tools report evidence; they do not promise rankings, approval, or sales.

CSV preflight

Essential and above can check a complete bounded file within the plan allowance. Preflight validates structure only and never imports products.

Catalog Q&A

Pro answers supported questions deterministically from current synchronized counts. It is read-only and links back to evidence.

Channel and storefront checks

Review channel-readiness factors and, on Pro, run a bounded reachability check against the authenticated myshopify.com host. This is not a search, speed, or conversion score.

Portfolio Control is implemented but gated

No store receives portfolio access from a label or an invite code alone.

A Portfolio Control hub requires an active Scale subscription. Scale can be compared on the Plans page and selected or managed on Shopify's hosted pricing page like every other plan. No sales call or manual activation is required.

  • 1

    Separate installation

    Every linked store installs and authorizes the app itself.

  • 2

    Separate billing

    The hub must be Scale; each satellite keeps its own active paid plan, quotas, and data boundary.

  • 3

    Short-lived proof

    Linking uses a one-time 15-minute code while the merchant can open both Shopify admin sessions. It never moves billing or merges allowances.

Read run states and recover

Open Runs, then select a run for progress, events, and terminal errors.

StateMeaningWhat to do
QueuedWaiting for bounded background processing.Leave it queued; refresh Runs later.
RunningProcessing with visible stage and progress.You can leave the page while it continues.
Retrying or recoveringA transient failure or expired worker claim is being retried.Wait for the automatic retry before starting more work.
SucceededThe run reached its complete stage.Review Overview, Findings, or the run events.
FailedThe run ended with a terminal error, exhausted its retry budget, or could not be dispatched.Open the run. Catalog sync and reconcile runs offer Run again.

Export or delete app-held data

Use Settings > Data from the embedded app.

Export the catalog audit

Download the current catalog CSV from Settings > Data. Exports describe the app's derived catalog view.

Delete all app data

Type DELETE in Settings > Data to queue removal of sessions, projections, evidence, snapshots, exports, and audit records. Shopify products are never deleted.

Prepare a support diagnostic

Download a privacy-safe JSON bundle from Settings > Data when reporting a problem. It includes plan, scope, record counts, and recent run states—not tokens or product content.

Find the boundary that needs attention.