Applies to Cmsmart Product Designer (NBDesigner) 2.17.0 · Updated October 2026. Covers the AI access, audience and usage-limit settings in Cmsmart Cloud → AI Tools, as shipped today — not a roadmap item.

In short

  • Outcome: you decide who can click an AI button in your design tool, so the store's token wallet is never spent on traffic you can't account for.
  • How it works: a master switch, an audience setting (Everyone, Members, or customers who have ordered), per-tool toggles and daily usage limits, all in one Cmsmart Cloud screen.
  • What it takes: about ten minutes in wp-admin — no code, no second account, no extra login system.

A shopper opens your product designer late one night, uploads a blurry photo from their phone, and asks for a cleaner cut-out before they buy. The fix takes seconds — and somebody has to pay for it. Not every visitor who clicks that button is a paying customer, and until you decide otherwise, your store pays for all of them the same way.

This guide shows you how to control who can use AI in your WooCommerce store, turn some of that interest into leads instead of pure cost, and keep the usage predictable. It covers the AI access controls built into Cmsmart Product Designer (NBDesigner) today, with real screens from the current version — not a wishlist.

What does ungoverned AI access cost your WooCommerce store?

Cmsmart Product Designer bills AI background removal, upscaling and preflight checks to one store-level token wallet — never to the shopper. Without a policy on who may trigger them, that balance can be spent entirely by anonymous visitors, with no record of who they were or what they wanted.

A few concrete ways this shows up:

  • Every click is a cost with no name attached. On the day these screens were captured, a background-removal run on a 500×500 photo drew 94 tokens from the wallet (background removal is metered by image size, so yours will vary), an upscale pass cost 60, and a resolution check cost 2. None of that is visible to the shopper — only to you, afterward.
  • A depleted wallet looks like a broken store. If every visitor can use AI and nobody is watching the balance, the tools can run out mid-month, and the next ten customers who click get nothing — or a locked button with no explanation, if you haven't set one.
  • Interest with no follow-up. An anonymous visitor who removes a background and never orders leaves you nothing to act on: no email, no way to bring them back.
  • No usage picture. Without the settings in this guide, you can't easily tell whether AI demand is coming from real buyers, bots, or one enthusiastic visitor testing every option.

This is not a web-to-print problem specifically — it is what happens anywhere a business adds an AI feature without deciding who it is for first. IBM's 2025 Cost of a Data Breach Report found that organizations with heavy unmanaged ("shadow") AI use absorbed an extra $670,000 in breach costs on average, and that 97% of organizations with an AI-related incident had no proper AI access controls in place. Store-level AI tools are smaller stakes, but the underlying fix is the same: decide who gets access before you find out the hard way.

What does AI access control look like in practice?

With Cmsmart, a store owner picks one audience setting once, and every AI click in the design tool is measured against it from then on — no custom code, no second system to maintain, and nothing a shopper has to configure themselves.

Example scenario. A print shop turns on AI background removal and upscaling, but limits them to shoppers who already have an account. A visitor browsing t-shirts clicks "Remove background," is asked to create a free account first, and keeps the design they were working on while they do. They don't order that day. Two weeks later, the shop emails everyone with an unfinished AI design a reminder — the shop has a name and an inbox to reach, not just a blank visit in an analytics report. A returning customer who already has an order on file never sees that extra step at all.

That is the trade a merchant is making every time they choose between Everyone, Members and customers who have ordered — smoother first-click experience against a record you can act on later.

Cmsmart insight: Everyone gives the smoothest first click and costs you for every anonymous run with nothing to show for it afterward if the visitor leaves. Members trades a little friction for a name and an email on every design someone starts. Once AI clicks are more than an occasional trickle, that trade is usually worth making — the usage limits in the next section are what keep Everyone safe until you do.

How does Cmsmart control who can use AI in your WooCommerce store?

Cmsmart Cloud's AI Tools screen gives a store owner one master switch, an audience setting, per-tool toggles and two usage brakes — all applied before a request ever reaches the AI service, so a turned-off tool never loads a script or spends a token.

The building blocks, all live in the plugin today:

  • Master switch. Turns every buyer-facing AI feature on or off at once. Your own admin-side tools — order preflight and its auto-fix — keep working either way.
  • Who may use it. Everyone, Members (which asks for a free account first and keeps the in-progress design), or customers who have ordered at least once.
  • Per-tool switches. Preflight Quality Checker, AI Background Remover and AI Image Upscale can each be turned off independently, with their own required print DPI and upscale engine choice.
  • Usage limits. AI runs per customer per day, and a balance threshold below which customer-facing AI pauses automatically — a reserve kept for your own admin tools, which this setting does not touch.
  • What a customer sees when they can't use it. A locked button (recommended, so you can see what people still wanted) or the tool hidden completely, plus one pause email to you — never a flood of one-per-request alerts.
Settings to control who can use AI in your WooCommerce store: master switch and Everyone, Members or past-customer audience options in Cmsmart Cloud
Cmsmart Cloud → AI Tools: the master switch and the audience setting — Everyone, Members, or customers who have ordered.
Per-tool AI switches for Preflight, Background Remover and Image Upscale in Cmsmart Product Designer settings
Per-tool switches for Preflight, Background Remover and Image Upscale, with the required print DPI and the upscale engine.

One wallet, shared across every tool, authenticates with the store's existing Cmsmart licence and domain — there is no second account for a customer or an admin to set up. This is part of Cmsmart's wider AI toolkit for WooCommerce stores, not a one-off add-on. A buyer never sees a token count or a price; they only ever see whether the tool is available to them right now.

Two things worth naming precisely: the buyer-side Preflight check scores print resolution only, with a one-click upscale offered when a photo falls short. Colour mode, fonts, bleed and transparency are checked separately — by your team, with AI Print Preflight on the order screen, on the finished print file, before you approve the artwork. And AI image generation (the separate "AI Design" tab) only appears once a store adds its own OpenAI API key; it is not part of the token wallet described here.

What's the business value of AI access control for your store?

Cmsmart turns an open-ended AI bill into a budget you set once: you choose who spends your tokens, you see what they did with them, and you get warned once — not once per failed click — when the balance runs low.

Without AI access controlWith Cmsmart AI access control
Who pays for AI runsEvery visitor, silently, until the balance is goneOnly the audience you chose — Everyone, Members, or past customers
Where the usage shows upDiscovered after the fact, if at allOne dashboard: operations, defects caught, and blocked demand by day and by tool
What happens at zero balanceTools fail with no warning, or you get an alert per failed requestButtons lock (or hide), one pause email, a waiting list you can email once you top up
What AI interest turns intoNothing — an anonymous visitA customer record, when Members is selected
Cmsmart Cloud overview showing AI operations, defects caught and blocked demand
Cmsmart Cloud → Overview: AI usage, defects caught and blocked demand in one place.

The Overview tab is also where you track the KPI that matters most for this setting: blocked demand — customers who clicked an AI tool and could not use it, and why. A high blocked-demand count on a depleted balance is a signal to raise a limit or add tokens; a high count on audience restrictions tells you how many non-members are interested, which is a case for trying Members for a month.

Estimate your own number: monthly AI spend is roughly (design sessions per month) × (share of those that use an AI tool) × (average tokens per action, read from your own Cmsmart Cloud → Billing tab) × (your plan's cost per token). Weigh that against the reprint-and-rework time you avoid when a low-resolution photo is caught and fixed before the order ships, not after.

How do I set up AI access control in my WooCommerce store?

Cmsmart's AI access controls live on one screen, so turning on the right audience and the right limits for your store takes a handful of clicks and no developer time.

  1. Open Cmsmart → Cmsmart Cloud → AI Tools in wp-admin (the same place preflight, background removal and upscale all live).
  2. Check the master switch. Leave "AI in the design tool" on only once you're ready for customers to use it; your own admin preflight keeps working regardless.
  3. Choose who may use it. Pick Everyone for the smoothest first experience, Members to collect a lead on every design someone starts, or customers who have ordered to keep AI as a perk for people who have already paid you.
  4. Set usage limits. Decide how many AI runs a single customer gets per day, and the balance level at which customer-facing AI should pause automatically to protect a reserve for your own order-screen tools.
  5. Decide what a blocked customer sees — a locked button (so you can see what they wanted) or the tool hidden entirely — and turn on the pause email so you hear about it once, not per request.
  6. Turn individual tools on or off — Preflight Quality Checker, AI Background Remover, AI Image Upscale — and set the required print DPI and upscale engine for each.
  7. Save, then watch the Overview tab for a week: tokens used, operations by tool, and blocked demand tell you whether the audience and limits you picked match real traffic.
AI usage limits and locked-button behavior settings in Cmsmart Cloud AI Tools
Usage limits and what a customer sees when AI is paused or out of balance.

Going further: what can Cmsmart build on top of AI access control?

The built-in audience setting covers Everyone, Members and past customers. For stores with more complex access rules, Cmsmart builds the custom development on top — tiered B2B permissions, usage reporting per brand, or AI gated behind your own account system.

None of what follows exists as a toggle in the plugin today — it is custom work Cmsmart scopes and delivers for stores whose access rules go beyond the three built-in audiences:

  • Role- or tier-based AI permissions. For B2B catalogs, granting AI tools only to specific customer groups or account tiers, instead of the binary member/guest/past-buyer choice shipped today.
  • Per-group token budgets. Separate usage caps for different product lines, brands, or reseller accounts sharing one storefront, with their own reporting.
  • SSO or ERP-linked identity for the Members gate, so "who may use AI" follows an existing account system instead of a fresh WooCommerce sign-up.
  • Finer-grained abuse detection beyond the daily per-customer cap — rate limits by session, device or order history for stores that have seen targeted abuse.
  • White-labelled AI usage reporting for marketplace or multi-vendor setups, where each vendor needs to see only their own tokens and blocked demand.

Cmsmart's delivery approach for this kind of work is the same for any custom project: discovery, solution design, build in sprints, QA, launch and ongoing support — the same team that ships the plugin.

Get my AI integration quote

Why work with Cmsmart on your AI strategy?

Cmsmart has built ecommerce and web-to-print solutions since 2012, with 6,300+ client projects and a Trustpilot rating of 4.2 from 404 reviews — the same team that shipped the AI access controls in this guide also scopes the custom work in the section above.

"We have had the NB Designer plugin installed for three years and have experienced absolutely no problems during that time. It is wonderful to see their commitment to continuous development, with new features being added frequently to keep the software current and highly capable." — Web Developer, Trustpilot

Cmsmart is a Netbase JSC division, with 6,300+ client projects and 1,800+ live stores since 2012, reviewed on Trustpilot at 4.2 from 404 reviews.

Frequently asked questions

Can shoppers see how many tokens an AI action costs?

No. The token wallet and its balance are an admin-only view in Cmsmart Cloud. Shoppers only ever see whether a tool is available to them right now.

What happens when the AI wallet runs out?

Customer-facing AI pauses. Depending on your setting, buttons either show locked or disappear, you get one email when the pause starts and at most one digest a day after that, and customers who were blocked join a waiting list you can email once you top up.

Does turning off buyer-facing AI affect my own admin tools?

No. The master switch only controls what shoppers see in the design tool. Preflight and its auto-fix on order files, run from wp-admin, keep working either way.

Can I limit AI to customers who have already bought from me?

Yes — choose "Customers who have ordered" as the audience. It is the tightest of the three built-in options: it costs the least and collects the fewest new leads, since it only reaches people who already paid you once.

Does the Members option need a separate login system?

No. It uses the free WooCommerce account creation a visitor is asked to complete before their first AI click; their in-progress design is kept while they do.

Can I restrict AI by B2B customer tier or role instead of just Members vs. guest?

Not out of the box today. That level of role-based permission is custom development — see the section above.

Ready to put your store in control of AI?

Decide who gets access, see what they do with it, and never get surprised by the balance again. Cmsmart can set up the built-in controls or scope the custom rules your store needs.

Get my AI integration quote See the AI integration service

Related reading: Product Designer 2.15: a security fix, a steadier dashboard and AI you control and Product Designer 2.12: AI on your own licence, a real quotes area and print files you can trust.

Cmsmart Cloud monthly AI token plans, Starter through Partner, captured October 2026
Cmsmart Cloud → Billing: the monthly AI token plans a store can subscribe to, captured October 2026; plans may change.
David Nguyen

David Nguyen

eCommerce consultant
Member since Jan 2020
319 Posts
213,553 Views
0 Helpful
David Nguyen — Founder & CEO, Cmsmart Ecommerce (a Netbase JSC division since 2012)