E-commerce
June 28, 2026
Support can answer a general question without authentication, but must verify identity before modifying an address, revealing an order, changing an email, processing a payment, or accessing personal data.
The chatbot must explain why verification is necessary, ask only for useful information, and transfer sensitive actions to a secure channel.
This guide shows how to authenticate a customer with clarity, without creating a cumbersome or risky experience.
Summary
Why is authentication indispensable?
A customer may find verification annoying, especially if they want a quick answer. However, without authentication, support could details an address, order, refund, or account information to the wrong person.
The chatbot must explain the reason for verification simply: to protect the customer's account and data.
The right authentication is the one that protects without asking for more than necessary.

Convert over 2,000 customers on average per month with Qstomy.
The world’s 1st Shopify AI dedicated to customer conversion



Empowering 200+ e-commerce merchants
Which requests require verification?
Sensitive actions include changes of address, cancellation, refund, email modification, access to history, account deletion, payment, merging accounts, and subscription management.
General questions about a return policy, size, or standard delivery can often be handled without authentication.
What information should be requested?
The bot may request the account email, the order number, a code sent via a secure channel, or a confirmation required by the procedure. It must never request a password, bank code, or full card details.
The level of verification must depend on the risk of the requested action.
How do you explain a temporary refusal?
If the customer cannot be authenticated, the chatbot must continue to provide general information whenever possible. It must explain that it cannot perform actions on the account until the identity is confirmed.
This distinction avoids leaving the customer without help while protecting data.
How to manage suspected cases?
If the request concerns an inaccessible account, a changed email, an unknown order, or a suspicious payment, the bot must transfer to a secure channel. It must not attempt to bypass verification to go faster.
Support must receive the context and the detected level of risk.
Which flow to follow?
The flow must adapt the verification to the risk.
Identify the request: general, account, order, payment, personal data, or security.
Determine if authentication is required before responding or taking action.
Only request information that is specified by the secure procedure.
Provide a general response if the identity is not confirmed but the subject allows for it.
Transfer inaccessible accounts, fraud, payments, modified emails, and enhanced verification.
Which messages should be used?
To explain: "Before taking action on your account, I must verify that the request is indeed coming from you."
For security: "I will never ask you for your password or your full card details here."
For limit: "Without verification, I can answer general rules but cannot modify your order."
When to transfer?
Transfer is necessary if the action requires enhanced verification, if the customer no longer has access to their email, if fraud is possible, if a payment is involved, or if personal data must be consulted.
The bot must transmit the request, account, order, verification level, risk, and encounter blockage.
Which KPIs should be monitored?
Track authenticated requests, verification failures, security transfers, data-related rejections, resolution times, and avoided incidents.
These metrics show whether the journey protects the customer without creating too much friction.
Which mistakes should be avoided?
Avoid revealing account information too early, asking for secrets, blocking general responses, or treating suspected fraud as a simple forgotten password.
The chatbot must help quickly, but never at the expense of security.
How can Qstomy help?
Qstomy can connect the chatbot to support conversations, attachments, authentication rules, internal alerts, the CRM, the catalog, product filters, and privacy procedures to respond clearly, and then hand over sensitive cases with an actionable summary.
The chatbot helps the customer move forward without inventing a file validation, a confirmed identity, a business alert, a persona, or a product filter that still needs to be verified by a secure and reliable source.
Explore AI support, the AI sales agent, or request a demo.
Key takeaways
Key takeaways
Authentication must depend on the risk involved: general question, account, order, payment, personal data, or security.
What the customer must understand
The customer must understand why verification is necessary and what information should never be shared.
The appropriate limit of the chatbot
The chatbot can handle simple topics, but it must hand over sensitive actions, fraud, payments, and enhanced verifications.

Enzo
June 28, 2026


