- Proposal and mutation envelope
- Deterministic policy
- Decision and approval lineage
- Exact authority binding
- Stale-authority invalidation
- Execution admission
- Verification model
- Evidence
- Tenant boundaries
CommerceGov · Production-authority control plane
Agentic Authority Protocol
for AI-driven commerce
Give AI systems the capability to propose and operate without giving the model independent production authority. Deterministic policy, human authorization of the exact change, controlled execution, read-back verification, and evidence decide whether a change becomes real.
Today, a human authorizes every change. Shopify is the first and most mature production adapter.
Multiple agent capabilities. One production authority boundary.
FOUR STATES, FOUR RECORDS
Capability ≠ Authority ≠ Applied ≠ Verified
An agent can request a change. That grants no production authority.
An authorized human approves one exact, versioned change.
A controlled worker executes only what was authorized.
Production is read back and compared with the authorized state, where the mutation class supports it.
No state is inferred from another.
AUTHORITY KERNEL · UNDER THE HOOD
One kernel decides. Adapters connect it to production.
The kernel is generic by design. Adapters bind it to a production system. Shopify is the first adapter and the only production-proven one. ERP and other business systems are planned, not implemented.
- Production-system objects
- Mutation classes
- Controlled execution route
- Authoritative read-back
- Reconciliation
The kernel decides whether a change may become real. The adapter makes it real and reads production back.
THE PRODUCTION AUTHORITY BOUNDARY
Multiple agent capabilities. One production authority boundary.
Different agents, models, and tool surfaces bring different capabilities. Their proposals terminate at one independent production-authority boundary. Integration maturity differs by agent stack, and none is claimed as production-proven.
Real product evidence
See one proposal move from queue through controlled Shopify writeback
Review the proposed change, approve it, apply it through the controlled worker path, and inspect the resulting audit evidence.
Queue → review → approval → controlled Apply → audit evidence
FIRST ADAPTER · AGENCY OPERATIONS
Governed multi-store workflows for agency operations
Agency controls authority. Client controls policy. Store defines exceptions.
- OperatorsPrepare and submit changes
- ReviewersVerify content and policy
- ApproversAuthorize production changes
- Shared policies
- Approval queues
- Operator permissions
- Store-specific exceptions
- Cross-store evidence
- Client Store AOwn permissions and exceptions
- Client Store BOwn permissions and exceptions
- Client Store COwn permissions and exceptions
WHAT YOU CAN VERIFY
Proof, not promises
Human approval before Apply. Worker-mediated Shopify writeback. Auditable change and recovery.
PUBLIC EVIDENCE
- Shopify App Store listingVerify that CommerceGov is a publicly listed Shopify app.Open listing ↗
- Sandbox DemoInspect the governed workflow without connecting a live store.Open sandbox ↗
- Product walkthroughWatch proposal → review → approval → controlled Apply → evidence.Watch walkthrough ↗
- Architecture WhitepaperInspect the tenant model, production boundary, workflows, and evidence architecture.Open whitepaper ↗
GOVERNED CHANGE EVIDENCE
What one governed production change records as it moves from proposal to authoritative readback.
- ProposalProposal receivedSource: AI or operator · Target: Client Store B · Proposed value: example content revision
- ApprovalApproved for this governed changeApproved value and scope · Authorized actor and decision time attached
- ApplyControlled writeback recordedWorker outcome · Applied value: example content revision
- VerificationSubsequent Shopify readbackConfirmed value via sync: example content revision · Mutation-scoped confirmation
- RecoveryRecovery context recordedAvailable recovery path or recorded action, where supported for this change
Applied ≠ Verified. Apply records the controlled production action; a later sync or drift check separately confirms Shopify's live state. Divergence there opens a separate reconciliation event.
DIRECTION · AUTHORITY DATA LAYER
Governed lifecycle evidence can become a secondary data layer.
Every governed change leaves a reconstructable record: source, policy result, authority decision, execution, read-back, and exceptions.
Over time, that lifecycle evidence could enrich infrastructure and MSP, security and observability, audit and risk, AI platforms, enterprise integrators, and payments and procurement workflows.
Direction, not a shipped partner offering or public API.
RESOURCES
From business case to reference architecture
Start with the Executive Brief for the decision case, then the Architecture Whitepaper for the kernel, adapters, and verification model.
Executive Brief
A decision-oriented introduction for executives, operators, partners, and buyers: the production-authority problem, the governed lifecycle, and what is implemented, demonstrated, and planned.
Open Executive Brief ↗Architecture Whitepaper
The technical architecture for evaluators: the authority kernel and adapters, authority lifecycle, controlled execution, and verification model.
Open Architecture Whitepaper ↗CHOOSE YOUR EVALUATION PATH
Start in the sandbox. Move to production deliberately.
Use the Sandbox Demo for instant, non-production access. Apply for a paid Production Pilot when you are ready to test the operating model on an agreed Shopify workload.
Explore the governed workflow instantly in a controlled environment.
- Instant access
- No live Shopify writeback
- No client store connected
- Review the proposal-to-evidence workflow
Run a milestone-based 6-week operating test on an agreed Shopify workload.
- Application required
- Paid engagement
- Defined scope and success metrics
- Controlled production writeback
Measure time, rework, capacity, authority, verification, policy exceptions, and recovery evidence.
Pilot target: 3–5× operator capacity — a hypothesis measured against your workflow, not an achieved result.
Review savings estimator
Estimate review time, rework savings, and annual savings using conservative defaults.
Choose the next step for your team.
Explore the governed lifecycle in the sandbox, review the authority boundaries in a demo with the CommerceGov team, or run a paid six-week Production Pilot on an agreed Shopify workload.
Review Savings Calculator
Adjust inputs to calculate review time, rework savings, and annual savings from governed workflows.
Current operations
Projected with CommerceGov
Estimated savings
Estimate based on conservative defaults
Inputs changed — update estimate
Review cost comparison
Savings
Estimates vary by workflow maturity, QA baseline, and approval process.