Reference

Global compliance harness checklist: test-driven, AI-assisted

Companion to October 1: script tags, Functions, the cart, the catalog agents read (https://crm-sync.dev/docs/shopify-october-1-scripts-cart-catalog), section G.

How to use it. Copy this file into your repository. For each item, write the test first, watch it fail, then write the code that makes it pass. Tick the box only when the test runs on every deploy and a failure blocks the release. An item with no test is not done, whatever the code says.

Test kinds. Static reads source or configuration without running it. Unit runs one function in isolation. Integration runs two or more real parts together (worker and database, webhook and handler). E2E drives a real browser through a real page — Playwright or Selenium.

Rule for AI agents in the loop. An agent may draft a test from the rule's text and write code until it passes. It may not edit, skip or weaken a test to make it pass, and it may not add a test to a known-failures list. A person approves every test that states a legal rule, and every change that touches keys or money.


1. The gate itself

4. Jurisdiction: where personal data may go

5. Data subject requests

6. Payments

7. Shopify after 1 October 2026

8. The catalog agents read

9. Accessibility

10. Secrets and the agent


Licence: CC BY 4.0. Rules are summaries, not legal advice — confirm each against its source and with counsel in the market it covers.