Skip to content
Inkstand
← Insights

An approval is about a text, not a document

3 min read

Approved is usually a column on a row, and the row stays editable afterwards. Which makes the only question anybody actually asks — was this approved? — unanswerable the moment somebody fixes a headline.

Bound to the words

A sign-off stores a fingerprint of the exact words that were reviewed. The words on screen are fingerprinted again on every render. When the two fingerprints differ, the approval is shown as needing to be given again rather than continuing to describe content that no longer exists.what was signed off“…will help with fatigue.”approved · 12 Marsha-2569f2c…41abcarried by the approvalwhat is on screen now“…will cure your fatigue.”edited · 14 Marsha-2564d81…c07erecomputed on every renderThe sign-off voids itselfneeds re-approval

An approval stores a fingerprint of the content exactly as it was reviewed. The content on screen is fingerprinted again on every read, and when the two differ the post reads edited since approval — needs re-approval. Nobody has to remember to withdraw anything.

What goes into the fingerprint is the whole of the design. The frames and the post copy both, because the caption is where the claims, the disclaimers and the links live: a fingerprint over the frames alone means a disclaimer can be deleted from the caption after sign-off and the approval stands, silently, over words nobody approved.

What stays out matters as much. Editor-local geometry is excluded, and so is the brand palette. An approval that dies because somebody nudged a text box two pixels teaches people that the state is noise, and a signal nobody trusts protects nothing either.

A field belongs in the fingerprint if a reader can see it, or a rule can fire on it. Everything else stays out.

The same thing happens when the rules move

A client republishes their guidelines on 12 June and a house rule changes with them. A post approved on 11 June goes on reading as approved, because its content has not moved. It was cleared against a rule set that no longer exists, and nothing on the screen says so.

So an approval carries a second fingerprint, of the rule set that was in force when it was given. Only what decides an outcome goes into it: the pattern, the severity, whether the rule is switched on at all, the dates a closed period is armed for. A rule’s provenance and the history of its wording matter enormously to a person and not at all to whether a post passes — folding those in would void approvals across an account because somebody corrected a page number.

Tighten a rule an hour after sign-off and the post reads the rules changed since approval — needs re-approval. It names which of the two moved, so nobody spends the afternoon hunting for an edit to a post nobody edited.

What happens when the two cannot be compared

The rules fingerprint carries the version of the algorithm that produced it, and it is compared only when the version on the approval matches the version running now. Across versions it says nothing and the post goes on reading as approved. That is a choice in the quiet direction and it is the right one: an equality test across versions reports a change to a post nobody touched, and — far worse — can report a match between two different texts.

Not comparable is not a synonym for changed, and it is not a synonym for clear either. There is no third thing on screen saying which of the two you have. That is a gap rather than a design, and it is the part of this mechanism least finished.

What it does not do

It does not decide who may approve beyond who may edit the brand, and it does not stop you approving your own work. A segregation rule that leaves a single-editor brand unable to release anything gets worked around by sharing a login — which destroys the attribution the record rests on. So the separation is recorded rather than enforced, and an account that needs it can read from its own register whether it has it.

The name on an approval is always the person who gave it, because the database overwrites the field with the caller’s identity instead of checking what was sent.

A check that can be satisfied by sending the right value is a check that teaches people which value to send.

How a change to a rule reaches an approval given before it is set out on rule inheritance.