Skip to content

How access rules combine

Step 2 of the lock editor, Access & Message, decides who can get past a lock. It is built from rules, and each rule is built from conditions.

Animation: create a Collections lock, add Rule 1 with Tagged customers and Rule 2 with a passcode, then continue to Exclude Pages
Creating a lock: pick the target, add two access rules (tagged customers OR passcode), then exclude pages.

A condition describes a visitor who is allowed in. For example, Signed-in customers - Must be logged in means “signed-in customers can see the locked content, everyone else sees the lock message”.

To turn a condition into a block instead, tick Reverse access rule on that condition.

Where Logic Example
Conditions inside one rule All must match (AND). The rule summary shows “2 conditions - all must match”. Tagged customers wholesale and Location United States
Separate rules in the same lock Any rule is enough (OR). Rules are shown with an OR divider. Rule 1: tag wholesale. Rule 2: Passcode. Either one unlocks.

So “wholesale customers in the US, or anyone with the passcode” is two rules: rule 1 with two conditions, rule 2 with one.

Two access rules joined by an OR pill: Rule 1 collapsed, Rule 2 with a Tagged customers condition

Rule 1 (tagged customers) and Rule 2 (passcode) are joined by an OR badge. The Summary on the right lists both rules.

Limit Value
Rules per lock 10
Conditions per rule 10
Rule that must have a condition Only the first rule. Empty extra rules are removed when you save.

Reverse access rule is not available for: Passcode, Email subscribers, Secret link, Age verified, After/Before date and time, URL parameter and Request access.

When the lock target is Price and add to cart or Variants, these conditions are not offered: Secret link, Email subscribers and Age verified.

For these targets, the passcode option Enter passcode each time to access each … is saved as Enter passcode once to access all ….

Click User type (or another group) under Select a condition to add, then open Select access rule to pick the exact condition.

The User type condition list: Everyone, Signed-in customers, Tagged customers, Specific customers, Request access, company name, company location, B2B customer

Button Conditions
User type Everyone, Signed-in customers, Tagged customers, Specific customers, Request access, Customer must be in this company name, Customer must be in this company location, B2B customer (Shopify B2B only)
Passcode Passcode - Must enter the correct passcode
Date & time After date/time (Visible from), Before date/time (Visible until). After can show a clock countdown.
More > Email Email domain, Email subscribers
More > Location Specific market, IP address (IPv4 only), regions, countries
More > Other condition URL parameter, Secret link, Age verified, Custom code (Liquid)

Related: Control Access (Access & Message) · Rule Builder Deep Dive