Approval applies to a version, not an idea
A customer should approve the exact page or code change that will execute. Store the evidence, rationale, affected resource, before state, after state, risk class, and hash of the change-set version.
Remote edits make a proposal stale
Before mutation, re-read the Shopify resource or repository state. If it differs from the reviewed before-state, stop and rebuild the proposal instead of overwriting the customer’s newer work.
Pre-authorization must stay typed and narrow
Low-risk, reversible classes may eventually be pre-authorized. New pages, redirects, factual claims, theme work, code, and regulated content remain explicitly approved in the early product.
Execution ends with verification
An API success response or merged pull request is not the final state. Verify the live response, rendering, canonical, schema, content, and links, then retain the receipt and rollback status.