You are asked what is live
Not what was approved. What is on the site right now, and whether anyone has read it since it shipped.
ExposureFor Legal & Compliance
You are asked what was decided, by whom, and whether it landed. Governance answers with a record that reads the same in a year as it did on the day.
Risk quoted “absolute safety” from the live page and cited the approved fact it contradicts, at version 4.
Policy assigned severity and sent it to Legal. The agent did not choose either.
Priya Raman, reviewer, approved the replacement wording. The approval is the artefact, not a message about it.
The CMS write was previewed, approved, and executed against /products/atlas-x200.
The live URL was read again. The sentence is gone. Only then did the issue close.
What you are up against
Not what was approved. What is on the site right now, and whether anyone has read it since it shipped.
ExposureThe decision was made in Slack eight months ago by someone who has left. There is no artefact you can hand anyone.
EvidenceThe ticket says done. Nobody read the published page again to check.
ClosureControl
None of these are settings somebody can leave off. They are properties the application is built to hold.
A reviewer can change workflow state. A viewer cannot. Enforced server-side.
No external send or CMS write executes without a preview and an explicit approval.
The organisation is derived from the verified session. No request can select another one.
Agent output cites its evidence and never sets its own severity.
More review capacity is useless without closure.