Problem + ignored cost
Copy-paste handoffs hide provenance and uncontrolled automation creates brand, security and uptime risk.
Use case · governed publishing
Every proposed content or code change stops at a review surface. Agents cannot approve, merge, deploy, publish, retrieve credentials or bypass branch protection.
Production locked
Preview ready · checks passed · human decision missing
Copy-paste handoffs hide provenance and uncontrolled automation creates brand, security and uptime risk.
Any validated content or technical output triggers the Site Experience Engineer to prepare—not publish—the exact production proposal.
Sources, diff, preview, tests, expected impact, risk, ownership and rollback guidance become one approval record.
Hard boundary
Prepare a tenant-scoped production proposal
Evidence, owner and next state remain visible.
Run configured build and content checks
Evidence, owner and next state remain visible.
Render exact diff and preview
Evidence, owner and next state remain visible.
Authenticated human approves or rejects
Evidence, owner and next state remain visible.
Protected GitHub/WordPress control applies change
Evidence, owner and next state remain visible.
Smoke checks run; revert can be proposed
Evidence, owner and next state remain visible.
GitHub honors repository protections; WordPress uses a customer-authorized REST path after approval. Credentials stay in the integration layer.
Audit events record proposal, reviewer, timestamp, production result and post-change observations.
All paid plans include human production approval. Choose by sites and capacity, not by willingness to accept weaker safety.
Paid deployment · human authority
Choose any paid plan; the protected approval boundary is included in all of them.