CommerceGov · Production-authority control plane

Agentic Authority Protocol
for AI-driven commerce

Give AI systems the capability to propose and operate without giving the model independent production authority. Deterministic policy, human authorization of the exact change, controlled execution, read-back verification, and evidence decide whether a change becomes real.

Today, a human authorizes every change. Shopify is the first and most mature production adapter.

Multiple agent capabilities. One production authority boundary.

Try Sandbox DemoInstant access · No live-store writeback
Book a Demo
Apply for Production PilotApplication required · Paid 6-week engagement

FOUR STATES, FOUR RECORDS

Capability ≠ Authority ≠ Applied ≠ Verified

CAPABILITY

An agent can request a change. That grants no production authority.

AUTHORITY

An authorized human approves one exact, versioned change.

APPLIED

A controlled worker executes only what was authorized.

VERIFIED

Production is read back and compared with the authorized state, where the mutation class supports it.

No state is inferred from another.

AUTHORITY KERNEL · UNDER THE HOOD

One kernel decides. Adapters connect it to production.

The kernel is generic by design. Adapters bind it to a production system. Shopify is the first adapter and the only production-proven one. ERP and other business systems are planned, not implemented.

AUTHORITY KERNEL OWNS
  • Proposal and mutation envelope
  • Deterministic policy
  • Decision and approval lineage
  • Exact authority binding
  • Stale-authority invalidation
  • Execution admission
  • Verification model
  • Evidence
  • Tenant boundaries
ADAPTERS OWN
  • Production-system objects
  • Mutation classes
  • Controlled execution route
  • Authoritative read-back
  • Reconciliation

The kernel decides whether a change may become real. The adapter makes it real and reads production back.

THE PRODUCTION AUTHORITY BOUNDARY

Multiple agent capabilities. One production authority boundary.

Different agents, models, and tool surfaces bring different capabilities. Their proposals terminate at one independent production-authority boundary. Integration maturity differs by agent stack, and none is claimed as production-proven.

AGENT SURFACES · ILLUSTRATIVE
  • ChatGPT / WebMCPDemonstrated · not production-proven
  • GeminiDemonstrated via ADK · not production-proven
  • Claude and other agentsSame proposal boundary · no native integration claimed
  • Applications and peopleSubmit proposals to the same boundary
  • ImportsNormalized proposals with provenance

Named agents are illustrative. No vendor endorsement or partnership is implied.

Example change packetProduct changeStore: Client Store B
COMMERCEGOV · PRODUCTION AUTHORITY CONTROL PLANE
  1. 01Proposal
  2. 02Deterministic policy
  3. 03Review
  4. 04AuthorityHuman authority boundary
  5. 05Controlled executionWorker-mediated writeback
  6. 06Read-back verificationAuthoritative, mutation-scoped
  7. 07Evidence

Capability ≠ Authority ≠ Applied ≠ Verified. Apply records the governed write; verification separately confirms the governed production change.

PRODUCTION / EVIDENCE Shopify production · first adapter

Human-approved changes enter Shopify only through the controlled worker-mediated path.

Writeback resultApplied

Separate Shopify readback

Verification resultAuthoritative read-back matched the authorized state.
Evidence recordGoverned lifecycle attached
  • Proposal
  • Approval
  • Apply
  • Verification

CommerceGov governs the path it controls. It does not prevent writes made through separate access.

CommerceGov does not replace Shopify RBAC; it governs production authority inside access Shopify already grants.

Apply-time verification is separate from ongoing monitoring; later divergence opens reconciliation without changing the original Apply result.

Real product evidence

See one proposal move from queue through controlled Shopify writeback

Review the proposed change, approve it, apply it through the controlled worker path, and inspect the resulting audit evidence.

CommerceGov product walkthrough

Queue → review → approval → controlled Apply → audit evidence

FIRST ADAPTER · AGENCY OPERATIONS

Governed multi-store workflows for agency operations

Agency controls authority. Client controls policy. Store defines exceptions.

AGENCY TEAM
  • OperatorsPrepare and submit changes
  • ReviewersVerify content and policy
  • ApproversAuthorize production changes
Agency Tenant
  • Shared policies
  • Approval queues
  • Operator permissions
  • Store-specific exceptions
  • Cross-store evidence
CLIENT STORES
  • Client Store AOwn permissions and exceptions
  • Client Store BOwn permissions and exceptions
  • Client Store COwn permissions and exceptions
CROSS-STORE AUDIT TRAILSee who approved each change, what was applied, and the verification evidence for the governed production state.

WHAT YOU CAN VERIFY

Proof, not promises

Human approval before Apply. Worker-mediated Shopify writeback. Auditable change and recovery.

PUBLIC EVIDENCE

GOVERNED CHANGE EVIDENCE

What one governed production change records as it moves from proposal to authoritative readback.

  1. ProposalProposal receivedSource: AI or operator · Target: Client Store B · Proposed value: example content revision
  2. ApprovalApproved for this governed changeApproved value and scope · Authorized actor and decision time attached
  3. ApplyControlled writeback recordedWorker outcome · Applied value: example content revision
  4. VerificationSubsequent Shopify readbackConfirmed value via sync: example content revision · Mutation-scoped confirmation
  5. RecoveryRecovery context recordedAvailable recovery path or recorded action, where supported for this change

Applied ≠ Verified. Apply records the controlled production action; a later sync or drift check separately confirms Shopify's live state. Divergence there opens a separate reconciliation event.

DIRECTION · AUTHORITY DATA LAYER

Governed lifecycle evidence can become a secondary data layer.

Every governed change leaves a reconstructable record: source, policy result, authority decision, execution, read-back, and exceptions.

Over time, that lifecycle evidence could enrich infrastructure and MSP, security and observability, audit and risk, AI platforms, enterprise integrators, and payments and procurement workflows.

Direction, not a shipped partner offering or public API.

RESOURCES

From business case to reference architecture

Start with the Executive Brief for the decision case, then the Architecture Whitepaper for the kernel, adapters, and verification model.

Executive Brief

A decision-oriented introduction for executives, operators, partners, and buyers: the production-authority problem, the governed lifecycle, and what is implemented, demonstrated, and planned.

Open Executive Brief ↗

Architecture Whitepaper

The technical architecture for evaluators: the authority kernel and adapters, authority lifecycle, controlled execution, and verification model.

Open Architecture Whitepaper ↗

CHOOSE YOUR EVALUATION PATH

Start in the sandbox. Move to production deliberately.

Use the Sandbox Demo for instant, non-production access. Apply for a paid Production Pilot when you are ready to test the operating model on an agreed Shopify workload.

SANDBOX DEMO

Explore the governed workflow instantly in a controlled environment.

  • Instant access
  • No live Shopify writeback
  • No client store connected
  • Review the proposal-to-evidence workflow
PRODUCTION PILOT

Run a milestone-based 6-week operating test on an agreed Shopify workload.

  • Application required
  • Paid engagement
  • Defined scope and success metrics
  • Controlled production writeback

Measure time, rework, capacity, authority, verification, policy exceptions, and recovery evidence.

Pilot target: 3–5× operator capacity — a hypothesis measured against your workflow, not an achieved result.

Review savings estimator

Estimate review time, rework savings, and annual savings using conservative defaults.

Estimate your potential capacity lift.

Choose the next step for your team.

Explore the governed lifecycle in the sandbox, review the authority boundaries in a demo with the CommerceGov team, or run a paid six-week Production Pilot on an agreed Shopify workload.

Try Sandbox DemoInstant access · No live-store writeback
Book a DemoDiscuss your workflow and operating model
Apply for Production PilotApplication required · Paid 6-week engagement