The Permission Layer No One in E‑Commerce Is Talking About — Yet
Every cross‑border seller I know is running some kind of AI‑powered sidekick: a repricing bot, a review‑analysis agent, an automated ad copy generator. We hand over product feeds, customer chat logs, even spreadsheet dumps of P&L data. And we’ve gotten comfortable with a dangerous trade‑off: we let these tools see everything we have in exchange for speed. The unspoken cost is that most of them operate with a binary permission model — either “give me full API access” or “go away.” The middle ground, where an AI assistant can see exactly what I choose, when I choose, and nothing more, barely exists.
That’s why the philosophy behind a fledgling tool called AI Eyes (the creator, Deen Storkey, is testing it on Product Hunt) grabbed my attention. It has nothing to do with building a DTC storefront or automating fulfillment. Yet the design decisions its maker is wrestling with — session‑based permission, separate controls for different data streams, visible sensing state — are precisely the unsexy foundations that the next generation of cross‑border tooling needs. If you’re an Amazon FBA operator running a seven‑figure brand, or a TikTok Shop manager juggling three marketplace strategies, the way you instrument your AI stack right now is almost certainly broken. AI Eyes offers a blueprint for fixing it, even if the product itself is still a prototype.
What Problem This Actually Solves (Before It’s Even Solving It)
The core friction AI Eyes addresses is not about screen sharing. It’s about ephemeral context versus persistent surveillance. When you use a tool like Helium 10 to analyze your keyword rankings, you give it ongoing access to your Seller Central data. When you let a ChatGPT plugin read your Google Sheets, that connection lives until you revoke it. The default is “always on” unless you remember to switch it off.
Storkey’s prototype flips that: the human chooses exactly what is shared, sees when sensing is active, and can pause or end the session instantly. Version 0.1 captures a selected screen or window, exposes separate controls for system audio and microphone, supports named companions and interaction modes, and clears temporary context when the session ends. The semantic understanding — the actual “thinking” — isn’t built yet. That’s honest, and that’s the point.
For an e‑commerce operator, think about the all‑too‑common scenario: you’re using an AI assistant to draft a listing optimization. You copy‑paste your product title, bullet points, and competitor ASINs. The assistant responds. Then you close the tab. But did your data stay? If you used a SaaS tool with a shared backend, the prompt history might be stored on their servers, used for model training, or leaked via a vulnerability. AI Eyes’ model — where context is explicitly temporary and cleared at session end — is a direct answer to that fear. It’s not about “privacy” as a marketing buzzword. It’s about control over your competitive data, which is the only moat a small brand has against a giant like Anker.
How It Differs From the Incumbents (and Why That Matters to Sellers)
The obvious comparison is Shadow, a polished Mac product focused on meetings, screen context, and actions. As Storkey himself acknowledges, “Shadow is already a polished Mac product focused on meetings, screen context, and actions. AI Eyes v0.1 is narrower: it explores explicit session control for named AI companions.” Shadow is great for capturing what happens in a Zoom call. But for a seller who wants to point an AI at a specific Amazon order report without exposing their entire Seller Central, Shadow’s model of persistent context is a non‑starter.
Other tools in this space include Rewind AI (always‑recording screen capture with search) and Mem (AI‑powered notes). They all trend toward “collect everything, let the AI figure it out later.” That’s fine for personal productivity. It’s dangerous for cross‑border commerce where a single spreadsheet of supplier costs or a screenshot of a competitor’s ad strategy could ruin months of work if it ends up on the wrong server.
AI Eyes’ emphasis on visible sensing state is the differentiator. The user interface makes it crystal clear when the AI is “looking” and what it’s focusing on. In e‑commerce, where we often onboard new tools on a trial basis, that transparency builds trust faster than any privacy policy ever could. A seller testing a new repricing tool should be able to see exactly what data the tool collected and when the session ended — not have to dig through API logs.
Why Amazon Sellers Should Care More Than Shopify Ones
This might sound like a tool for everyone, but the pain point is acute for Amazon sellers. Amazon Seller Central is notoriously stingy with its API access. Most third‑party tools rely on scraping or limited OAuth scopes. If you grant a tool access to your account, it can often see your entire catalog, your advertising spend, your return rates. A permission‑first model that lets you share only the product‑listing page you’re currently editing — not your full inventory — would be revolutionary.
Shopify merchants, on the other hand, have a more open ecosystem. They can create private apps with granular permissions. But they still face the same trust issue: once a third‑party app has an access token, it holds that power until revoked. AI Eyes’ approach of clearing context after each session models exactly what a Shopify store owner should demand from any AI tool that touches customer PII or sales data.
What Cross‑Border Sellers Can Borrow From This (Even Without Using It)
You don’t need to install a screen‑sharing prototype to benefit from its design philosophy. Here are three concrete practices any seller can implement this week:
Audit your AI tool permissions like you audit your PPC. Go through every tool that has access to your marketplace accounts — repricing, analytics, review management, advertising automation. For each one, ask: “Can I limit the data it sees to only what it needs for the next 30 minutes?” If the answer is no, consider whether the convenience is worth the risk. Tools like TradeGecko (now part of QuickBooks) and RestockPro often request more access than they need.
Adopt a “session‑based” mindset for data sharing. Instead of giving an AI assistant permanent access to your spreadsheet of Amazon PPC keywords, export a filtered subset and import it into a disposable Google Sheet. Let the assistant work on that sheet. Delete the sheet after. That’s what AI Eyes is formalizing with its “temporary context clearing” feature — but you can do it manually today.
Demand visible sensing from your vendors. When you evaluate a new SaaS tool for cross‑border logistics or returns management, ask: “Does your software show me exactly what data it’s reading from my account at any moment?” Most will say no. The ones that say yes — or are building toward it — are the ones worth betting on.
Where My Judgment Says It Falls Short (And Where the Math Breaks)
AI Eyes is v0.1, and Storkey is upfront about its limitations. The semantic understanding layer isn’t there yet. “Screen capture, source controls, pause/end behaviour, and context clearing work; semantic understanding and agent responses are still simulated,” he wrote in response to a comment. That means you cannot actually use this tool today to get an AI to analyze your screen and give you actionable advice. It’s a permission shell waiting for an brain.
That’s fine for a prototype. But the risk is that the team spends so long perfecting the privacy model that they miss the window to build the actual value layer. E‑commerce operators are utilitarian: they care about privacy until it costs them time. If a competitor launches a tool that gives instant, useful insights with slightly weaker controls, most sellers will choose the faster tool, then worry about data leakage later. The history of SaaS adoption in e‑commerce is littered with examples — Jungle Scout took off because it was fast, not because it had the best security posture.
The other problem is the re‑grant friction that commenter Stella Reed flagged: “whether re‑granting access every session feels annoying or feels safe.” Storkey chose the safe default — manual re‑selection each session. He’s right to do so for a prototype. But in a high‑volume e‑commerce workflow where you might run 50 small analyses a day (checking a listing, reviewing a return reason, profiling a competitor’s pricing), that friction becomes unbearable. The tool will become a “annoying but secure” relic that gets replaced by a rival that remembers your preferences — and quietly keeps the trust.
The Chrome Extension Trap
AI Eyes runs as a browser‑based tool. That’s smart for reach — every seller already has a browser. But browser extensions have notoriously weak security sandboxes. If a malicious actor compromises the extension’s update server, they could push a version that silently exfiltrates screen captures. Cross‑border sellers handle sensitive data like supplier contracts and wholesale prices. I’d be hesitant to use any browser‑based screen‑capture tool for commercial data until it’s been audited by a third party. The local‑first approach Storkey mentions is good, but “local‑first” + “browser extension” is an oxymoron unless the extension disables network calls entirely.
Where the Math Breaks: The Business Model of Trust
Let’s talk economics. A permission‑first, privacy‑hard tool has two structural disadvantages:
- Higher user friction → lower adoption → fewer data points for the AI to learn from → worse suggestions → churn.
- Higher development cost because you must build granular controls, auditing logs, and possibly on‑device inference instead of cheaper cloud processing.
Storkey’s own comment acknowledges that “some magic disappears when every sensing state is visible.” The “magic” in e‑commerce AI is the feeling that the tool just knows what you need. That feeling comes from broad, continuous data access. If you restrict access, the AI becomes dumber, slower, or both.
I’ve seen this play out with Klaviyo alternatives that promised no data storage on their servers. They never matched Klaviyo’s segmentation accuracy because Klaviyo’s models are trained on aggregated data from thousands of stores. The trade‑off between privacy and performance is real. AI Eyes hasn’t solved it — it’s simply postponed the decision by not building the semantic layer yet. Once they add real AI, they’ll have to decide: do they run a local model (slower, limited, but private) or send screen data to an API (fast, smart, but insecure)?
For cross‑border sellers, the practical takeaway is: don’t trust any tool that promises both perfect privacy and perfect intelligence simultaneously. One of those claims is usually marketing.
What I’d Watch / Test Next
The concept of session‑based, visible AI companions is not going away. Whether AI Eyes succeeds or fades, the design pattern it’s pioneering — explicit permission, independent audio/video/screen controls, temporary context — will become table stakes for any AI tool that touches commercial data within two years.
Here’s what I’d do this week:
Test the AI Eyes prototype (it’s currently functional as a permission control layer). Use it to share a specific e‑commerce dashboard screen — say, your Amazon business report — with a note‑taking AI. See how the friction of re‑selecting the source feels. If it’s too annoying, that’s valuable feedback for the maker. If it feels acceptable, you’ve validated a new workflow.
Run a “session audit” on your current tool stack. List every SaaS tool you use. For each, go to its API permissions page in your marketplace account and revoke any scopes that aren’t strictly necessary. Then set a calendar reminder to re‑audit in 30 days. This is the behavioral equivalent of AI Eyes’ “clear context at session end.”
Explore local‑first alternatives for sensitive data analysis. Tools like Ollama let you run small language models locally. Combine that with a screen‑capture utility that respects the AI Eyes permission model (e.g., only captures a selected window), and you have a seller‑grade private AI assistant today — no cloud dependency.
The winner in cross‑border e‑commerce over the next five years won’t be the tool with the most features. It will be the tool that earns the right to see your data, one session at a time. AI Eyes is asking the right question. Now someone needs to answer it with a product that actually works for a seller who has 47 open tabs and no time to re‑grant permissions 90 times a day.






