Introduction

CRM Sync Knowledge Base

Every article in the CRM Sync knowledge base, as one book: 96 articles in 7 chapters, in reading order. Use the sidebar or the table below, ← → to turn pages, and S to search.

Built from the Markdown in crm-sync-setup, so it never drifts from the source

1. Setup

  1. 1.1 CRM Sync — Migration Guide: CSV & Legacy Tools → Connected Streams

    For: Marketing ops, analytics teams, and CRM administrators planning the transition Date: 2026-05-18

  2. 1.2 Agency → Client Deploy Handoff

    Checklist + Interactive Key Rotation ceremony. This document is the normative handoff procedure for transferring a deployed CRM Sync / headless commerce stack from the implement…

  3. 1.3 CRM Sync — PWA & Native App Commerce Setup Reference

    Ship your CRM as an installable PWA and native app (iOS · Android · desktop) on Shopify + Webflow + Xano — with auth, real-time consent, GA4, and agent permissions. Everything you need to get it running, in order.

  4. 1.4 CRM Sync Setup Reference

    The full technical reference for the CRM Sync stack. New users: start with the short numbered guide at crm-sync.dev/start — this page is for depth.

  5. 1.5 Consent, Cookies & Preferences — User Guide

    The consent banner, cookie preferences, reset, Do Not Sell vs consent, and the audit trail.

  6. 1.6 File System Agnostic Publishing

    Ship the Webflow design as a WordPress theme (Udesly or Pinegrow) or on EmDash/Astro — the Shopify Web Components block and CRM Sync embeds carry across verbatim.

  7. 1.7 How to capture a HAR file — a plain-language guide

    A HAR file is a recording of every conversation your browser had with a website. This explains what one is, how to capture a useful one in Chrome, Edge, Firefox or Safari, the single setting most people miss, how to check what is inside before you share it, and how to redact it safely. Written for someone who has never opened a browser's developer tools.

  8. 1.8 Logging and trace fees: what monitoring costs by volume

    Log entries and trace spans are the two monitoring lines that grow with traffic rather than with tenants. What Google Cloud Logging, Cloud Trace and Cloud Monitoring charge, what Cloudflare Workers Logs and Traces charge from 1 October 2026, what a fixed-fee Xano plan leaves out, and the four settings that decide the bill before the first invoice does.

2. Security

  1. 2.1 CRM Sync — Security Audit & Paired Data Requirements

    Date: 2026-05-18 Version: 1.1 Worker Version: dac8f178-f6ed-4a11-96be-f640a67c64ae

  2. 2.2 Shopify Expiring Token Management

    As of April 2026, Shopify mandates that all OAuth apps use expiring offline access tokens with rotation. Non-expiring tokens return 403: Non-expiring access tokens are no longer…

  3. 2.3 CRM Sync — Auth Pipelines

    For: Engineering, security auditors, and compliance teams reviewing authentication architecture Date: 2026-05-19

  4. 2.4 Key Ceremony — Loop Review Checklist (Automation)

    Version: 1.0 Date: 2026-06-22 Companion to: KEY-MANAGEMENT-LIFECYCLE.md (§8 rotation, §9 ceremony, §10 glossary, §12 ownership) Run mode: recurring automated review (e.g. Claude…

  5. 2.5 CRM Sync — Key Management Lifecycle

    Version: 1.5 Date: 2026-07-03 (v1.4: 2026-06-22; v1.2: 2026-06-15; v1.1: 2026-06-11; v1.0: 2026-05-26) Scope: Dev → Stage → Prod key management, consulting team workflow, stakeh…

  6. 2.6 Security & Privacy — Questions from CISOs and DPOs

    The questions a security or privacy office would ask if we weren't in the room — including the ones we'd rather they didn't. Open findings, with dates, at the bottom.

  7. 2.7 BIM Fortress vs Event-Socket

    Two diagrams: the fortress wound map and the event-socket heal — envelope encryption, healing encryption, evidence ledger, AI robots on mandates. A+-respectful for Trimble estates: you need more, not different.

  8. 2.8 Dark Factory Entitlement Security

    Where the vulnerability lives — IoT firmware, game bundles, 3D/BIM assets — with the Unity, Trimble and ImageMagick receipts, why no platform yet handles 3D securely, and the entitlement architecture that survives AI-speed extraction.

  9. 2.9 Entitlement Strategy — RBAC, ABAC, RuBAC & Permissions for AI Agents

    How RBAC, ABAC, and RuBAC actually relate; why WordPress roles, AWS IAM, and Azure RBAC stop at the door; and how an entitlement plane with purchase-granted capability caps, envelope encryption, and AP2 mandates gates AI agents.

  10. 2.10 CRM Sync — Firmware, SBOM & the Cyber Resilience Act

    What an SBOM is, what firmware vaulting does, and how the EU Cyber Resilience Act maps onto both — plus a glossary of the security terms (envelope encryption, hash-chained ledger, grant-gated download, CORS, nosniff).

  11. 2.11 Cybersecurity for AI — CISO · CTO · DPO

    What the EU Cyber Resilience Act requires, what firmware and SBOMs are, why CISOs, CTOs, and DPOs are personally exposed when a system only looks like it works, the billion-dollar GDPR precedent behind the server-side migration, and two pathways to compliance: bundled-AI SaaS vs. AI-as-middleware.

  12. 2.12 SOC / SOX Application Review — AI Middleware, Reinforced Security, Data Scaling

    The application-review checklist across the four IT General Control domains plus AI requirements and dependency/failover — and why the foundation holds: AI as free-to-use middleware, security reinforcement that fails closed, and data scaling on one session-keyed ledger, with SOC-aligned controls built in rather than bolted on.

  13. 2.13 The Wrong-Size Tool — Why Consent Never Lands on a Server

    Enterprise IT was built to guard the perimeter; regulators now ask what the servers did. Into that gap walk consulting firms selling platform programs — Salesforce, MuleSoft, ESB rebuilds, WMS replacements — that still never put consent on a server. The ladder runs from scoping failure to material weakness to securities litigation, and the fix that would have protected the organization was nearly free. Why the right-size tool gets dismissed, what a station is versus a destination, and why every high-order function — consent, entitlement, evidence, even the design system — must arch both.

  14. 2.14 Agent Authority — Technical Brief

    For teams already building agent workflows: the mandate model (scope, cap, expiry, revocation), how authority resolves per call rather than at the boundary, MCP integration with scoped tokens, and public verification against a published Ed25519 key.

  15. 2.15 Two Ways to Give an Agent a Key

    Participant-held (Nostr) vs edge-held Ed25519 key custody for AI agents: identity vs authority, rotation after compromise, decentralized egress under enterprise controls, three-leg resilience, and a 20-term glossary.

  16. 2.16 Your Firmware Is a URL — the CRA Assumes an Evidence Chain

    The two CRA dates as a records problem, what an SBOM is and isn't, what firmware vaulting replaces — and the SaaS answer: ledger sessions, not artifacts. Includes the relay-vs-entitlement model contrast.

  17. 2.17 Rotate a Key in Three Steps — the AI-Safe Ceremony for Webflow Teams

    Neither Webflow nor Shopify has native key rotation — a token is one static secret, and replacing it is a flag day. The fix: demote platform tokens to plumbing, and put people, agents, and permissions on Google/Shopify-paired entitlement tokens that rotate with named generations.

  18. 2.18 What Is an SBOM? Who Uses This? Everyone.

    The LinkedIn edition — question-first: what an SBOM is, who uses it (everyone), and how a regulatory threat became a composable, enterprise-grade publishing system for SBOMs and firmware security on Shopify WASM.

  19. 2.19 The Trust Vocabulary — Every Term on One Page

    The working grammar of the platform: permission, privacy, license vs grant, receipt, record of consumption, fingerprint, vault, token vs session bookmark, key pair, mandate — each defined in one breath, with who acts on it and the confusions to avoid.

  20. 2.20 Verify It Yourself — the IT Sheet

    One page for both sides of a security review: the four-click demo script for the business stakeholder, and the independent-verification claims, endpoints, and tests for the IT/SME reviewer.

  21. 2.21 Server-Side or It Didn't Happen — Developer Due Diligence for Commerce

    A theme that looks right is not a system that is right. Why the jeopardy lives in cart, checkout, returns, fraud, and remittance; why functions stay server-rendered and shape-gated; why the record is part of the deliverable — and who carries what you didn't write down.

  22. 2.22 Trust With Login — The Bind Is the Product

    Why this login is different: it binds the Shopify and Google accounts you already own, reset never dead-ends, permissions are read from the entitlement register rather than an installed app, and the same grant gates WordPress, AEM, Salesforce, Webflow, Next, Nuxt, Svelte, and Astro. Every sign-in is a ledger event.

  23. 2.23 Permissions for AI, in plain terms — capability, not perimeter

    Permissions for AI agents in plain 1-2-3: what RBAC, ABAC, RuBAC, OIDC and OAuth mean, why a filesystem perimeter + Next.js RBAC breaks for AI, and five use cases — household streaming, HIPAA remote 3D printing, a private mortgage, a dark warehouse where robots read GS1 QR (Sunrise 2027), and a geo-verified BIM building inspection. Money- and privacy-gated. Own your auth (Google/Shopify), run everywhere.

  24. 2.24 CRM Sync — Security & Compliance Posture

    Encrypted per-tenant credentials, scoped revocable tokens, fail-closed consent, offline-verifiable agent mandates, and a public, dated list of open findings.

  25. 2.25 CRM Sync — Keys to the Castle with Design Ops Tools

    You want security with the tools you use. Same utility, same security, same scaling as an infrastructure secrets stack — plus minting, which turns a file into an asset a customer can be granted. Mapped feature by feature, with the honest column intact.

  26. 2.26 HAR permissions audit — a portable prompt for testing an e-commerce storefront

    Hand this file and a HAR capture to any AI assistant and get a permissions audit of your own storefront: what the server actually returned versus what the page displayed, whether the consent gate resolved before the tags fired, credentials reaching the client, and what a caller with no browser would see. Evidence-cited, severity-ranked, no findings without a HAR entry.

  27. 2.27 Trust Roots Across Clouds

    What TLS actually buys and where it stops — and why a permission is intent, mandate and policy together, never a token anybody carries.

  28. 2.28 Paired permissions and grant impact on machine endpoints

    On a machine endpoint a permission and its grant impact are two different statements. Read on a SaaS API is revocable; read on a content-addressed CID is a copy you can never call back. Paired across four endpoint classes — SaaS, content-addressed (IPFS, the DAT endpoint), device attestation in the dark factory, and edge cache — with the shipped envelope gate, and the finding that latency and revocation lag are the same dial unless you enforce at unwrap.

  29. 2.29 The BYO data plane fallback ladder: whose warehouse, and what erasure does to it

    When a tenant brings its own Xano and BigQuery, every write has to land in the tenant's warehouse, and every erasure has to respect the tenant's choice. The five-rung ladder that resolves a tenant's BigQuery project, the operator-approved exceptions and the page that manages them, the tombstone-then-purge erasure and the per-tenant policy for the tenant's own planes, and what Shopify, Google and Klaviyo each do with a deletion.

  30. 2.30 Security Reinforcement: Firmware Asset Publishing

    Configuration tooling, a UAT plan, and the severity of shipping secrets in code — for teams publishing firmware where a signed byte stream is the only thing standing between a download URL and a device.

  31. 2.31 QA and Release Gating for Agents, Mandates and Robots

    What changes in a test suite when the caller is an AI agent or a machine with an actuator — adversarial refusal tests, mandate enforcement, a release gate that fails closed, and what Subresource Integrity actually protects.

  32. 2.32 AI cross-border requirements: a scannable checklist

    What an AI service that moves personal data across borders must guarantee — data governance, transport, horizontal scaling, AI-specific controls — mapped to the SOC 2 Trust Services Criteria, with the evidence a reviewer asks for; plus US middleware fees and the retention, consent and retargeting gaps that turn into penalties.

  33. 2.33 Secure frontend, AI-safe backend: Webflow collections, fallback publishing and grants

    How a Webflow site published as static files pairs each publishing step with a permission: collections as MVC, fallbacks that fail toward less exposure, review switches as publish grants, and where TLS, memory safety and authorization each fit.

3. Specs

  1. 3.1 CRM Sync — Why This Architecture Is Safer

    For: Business leaders, compliance officers, and operations teams evaluating CRM Sync Date: 2026-05-18

  2. 3.2 Analytics Export via Xano Polling + Worker Cron

    Version: 1.0 Date: 2026-05-27 Status: Specification

  3. 3.3 CRM Sync — Clean Room Utility & Security Rules

    Version: 1.1 — Cloudflare-Native Architecture Date: 2026-05-27 Classification: Internal — Confidential Compliance: GDPR Art. 6/9, CCPA §1798.140, CPRA, UK DPA 2018 Infrastructur…

  4. 3.4 Forward-Deploy Guideline — Server-Side GraphQL + Agentic Workflows + Tool Runner

    Audience: merchants, app developers, and platform teams planning their Shopify roadmap. Thesis: Shopify's 2025–2026 deprecation cliff retires the client-side / REST / Script-Edi…

  5. 3.5 CRM Sync — Feature Specification Addendum

    Document ID: CRM-FEAT-002 Version: 1.0 Date: 2026-05-17 Status: Draft — Architecture Review Parent: CRM-FUNC-SPEC-001 v1.2

  6. 3.6 CRM Sync — Feature Specification

    Document ID: CRM-FEAT-003 Version: 1.0 Date: 2026-07-06 Status: Published Classification: Public Parent: CRM-FUNC-SPEC-001

  7. 3.7 CRM Sync — UI Component & ID Registry

    Canonical naming + delivery model for the storefront UI system (nav, footer, cart, login, search) across design-sync.myshopify.com → crm-sync.dev. One addressable crm- namespace…

  8. 3.8 JS Execution Order — Challenge & Solution

    Consent fires first: the client-JS execution-order contract and the tests that enforce it.

  9. 3.9 CRM Sync — Functional Specification

    Document ID: CRM-SYNC-FUNC-SPEC-001 Version: 1.0 Date: 2026-07-12 Status: Active Classification: Public

  10. 3.10 CRM Sync — What Traditional CRMs Miss

    For: Business leaders, investors, and operations teams evaluating CRM Sync against Salesforce, HubSpot, and Klaviyo Date: 2026-05-19

  11. 3.11 CRM Sync — Event-Driven Integration Spec

    Version: 1.0 Date: 2026-05-27 Status: Specification Replaces: Cron-only polling for external integrations

  12. 3.12 AI Trust Framework Requirements — and What to Add to Your REST Layer

    Ten requirements an AI trust framework has to satisfy under the 2024–2027 EU wave, why REST-shaped integration cannot meet them as-is, and nine additive changes that close the gap without replacing your existing endpoints.

  13. 3.13 Process Management Guide — Webflow · Xano · Cloudflare · Shopify

    Running a four-platform commerce stack: layer split, event-driven automation, outage runbook, and RACI - now extended with verification evidence, SBOM/CRA obligations, and AEO surfaces, plus a ten-point evidence checklist.

  14. 3.14 Server-Side Function Tools with AI Runners

    The additive way into an enterprise stack: bounded server-side functions that resolve authority per call, write their own record, and can be invoked by an agent through a scoped token - no replacement, no migration, and nothing that has to clear a re-platforming review.

  15. 3.15 Product Taxonomy, GraphQL and the GID Rename — CPG Planning for Sunrise 2027

    Shopify moved product identity into a typed graph with GID-form identifiers and server-side events. For CPG planning toward Sunrise 2027, that changes the item master, the parent/child model, and every downstream join - here is what actually breaks and what to hold yourself.

  16. 3.16 Shopify / Google Integration on an AEM Scaffold — via Webflow Export

    How the Shopify + Google integration ships onto an Adobe Experience Manager estate: the Webflow export as the page scaffold, worker embeds as the behavior layer, and an either/or substrate election (Cloudflare or Adobe/Azure) — beside AEM, never inside it.

  17. 3.17 Fragments on Any Frontend — One Webflow Source, Every Platform

    The platform-agnostic fragment architecture: sections authored once in Webflow mount verbatim on AEM, WordPress, Astro, Next, 11ty, or a Shopify theme — markup travels through two worker rails, behavior and identity never leave the worker.

  18. 3.18 PIM Anywhere — One Catalog Record, Any Frontend

    The PIM plane treats the catalog as a plane, not a page: the store's own record is the single live source, and every surface — AEM, Webflow, WordPress, Next, plain HTML — renders a projection via a two-tag embed. The same record ships to Google through the Merchant API.

  19. 3.19 Git to Every Surface — the Article Pipeline

    One markdown commit becomes a Webflow article, a Shopify metaobject, and an AEM Content Fragment — with hashtags as the filter dimension and ALT text carried from the source.

  20. 3.20 Claim Provenance — the metadata schema

    How every document in this archive states what was checked, how it was checked, when, and when it should be checked again.

  21. 3.21 Consent Resolution on Higher-Order Load

    The five-phase load contract that resolves consent from durable state before any tag loads — portable to any client-side template, device- and browser-agnostic.

  22. 3.22 Why Xano + AI + e-commerce is the right runtime as a service

    A runtime as a service is judged by what it holds when nothing is being rendered. The identity path across Shopify OIDC, a Cloudflare Worker and Xano; why a consent gate must be metered rather than loaded; what a render surface structurally cannot hold; and the Liquid-to-Deno lineage that ends in a capability you cannot forget to check.

  23. 3.23 Compile to update — the estate by seven lifecycle stages

    Every application in a Shopify, Webflow, Cloudflare and Xano estate described by the same seven stages: compile, permissions, render, bundle, deploy, version, update. No recommendation — each cell states what happens, who owns it, and what the smallest possible change is. The empty cells are the informative ones.

  24. 3.24 The spec is the source — a writing layer for designers and analysts

    Configuration files are the specification, and the only part of a build a non-developer could plausibly own. Write the intent in plain language, generate the config from it, check it against closed vocabularies — and get the developer and compliance documentation from the same file. Includes a vocabulary for permission, entitlement, mandate, key custody and chain of thought, and why CSR, SSR and ISR say nothing about where authority lives.

  25. 3.25 AI enabled forms with LLM weighting — one form, many outcomes

    A form collects intent, policy and permission in the same moment. This is the business case for owning the infrastructure behind it — against CRM latency, per-contact fees and vendor lock-in — with sprint directives, the compile and binding models, and why a claim's shape decides what an AI can later be asked.

  26. 3.26 BYO Shape Pipeline

    How to bring your own Xano to the data-shape pipeline: the merge contract, the write path, the permissions model, and how to swap the runtime for Kubernetes or the model for Google AI — without buying anything that isn't self-serve.

  27. 3.27 Consent-first tracking and the demotion of page and client data

    A business analysis of four dated platform moves that demoted the page view and client-side data from record to hint — Google Signals out of reporting identity, Universal Analytics switched off, Signals stripped of ad authority by Consent Mode ad_storage, and the container's shift to the destinations model. Current state, gap, requirement and risk for an ecommerce theme, what an agent-driven conversion strategy needs instead of a page view, and where the page view is still the right instrument — the AEO and SEO split.

  28. 3.28 BYO Xano and BigQuery against Google's agent platform: what AI automation costs per call

    Google's agent platform is the faster way to build an AI automation, and its managed layers bill every request. What Conversational Agents, Agent Search, grounding and Agent Runtime charge per call, what the same jobs cost on a bring-your-own Xano and BigQuery stack with Cloudflare Workers AI, where Google is cheaper, and the price changes dated between now and January 2027.

  29. 3.29 From Plugins to Mandates

    Why per-seat SaaS pricing taxes the automation you bought it for, what each external DAM, PIM and CRM adds to your supply chain risk, why Shopify and GA4 JSON is the wrong shape for an agent, and why the deprecation timeline is doing the demolition anyway.

  30. 3.30 Render and Runtime: A Working Dictionary

    Precise definitions for business analysts and designers — ISR, islands, Astro, Eleventy, Petite Vue, HTMX, Liquid, PHP passthrough, Deno against Node, keys against cookies, UAT, boundary pipelines, TDD, adversarial testing and SRI — each with the distinction that changes a decision.

  31. 3.31 Asset Management, Security and AI

    A media manager's pipeline: what a re-encode destroys and what it protects, metadata and provenance, raster and mesh compression including Draco and KTX2, programmatic resize from UIkit to the edge, Webflow and Shopify's media models, Cloudinary and OpenText and filesystem handling compared against an R2-backed DAM, and the ImageMagick precautions for WordPress, Drupal, Magento and AEM.

  32. 3.32 The AI ladder: retrieval, adapters, humans, and who holds the keys

    Challenge and solution for putting AI into commerce without letting it decide what it may not. Definitions of RAG, CRAG, LoRA and human-in-the-loop escalation; when data justifies each rung; and why ADK, Kubernetes/Helm and a Cloudflare higher-order 'helmet' are three different layers — with the mandate as the only way an agent is allowed to act; and what a SOC 2 review — a procedural assessment of how an organisation operates, not a certification — asks of AI transport.

  33. 3.33 October 1: script tags, Functions, the cart, the catalog agents read — Globalized Language ISO requirements

    What server-side consent buys globally: the three-year conversion from browser tags to Consent Mode v2 (September 2023 to March 2027), what Google, Meta and the law require, and why no session-level consent log means no YouTube or Meta retargeting; a real-time consent log, California's Honda and Todd Snyder fines, and the browser opt-out signal from 1 January 2027; business-as-usual data vs an API-reinforced global namespace, from market-prefixed domains to Cloudflare Rules; a retire and adopt checklist; then Shopify's 1 October 2026 script tag deadline, Functions, what is reserved in cart and checkout, the ISO standards of the UCP catalog, and Korea's NICEPAY and consent path.

  34. 3.34 RMA decision ladder — functional and data design spec (hypothetical)

    A hypothetical functional and data design for a support chatbot that climbs from knowledge-base answers to opening an RMA, escalates to a person on named conditions, links only attested firmware, runs only verified browser code, and deploys only through a locked, human-reviewed workflow. With a test matrix and testing diagrams.

4. Compliance

  1. 4.1 Consent gate attestation — crm-sync.dev, 2026-09-08

    What the storefront sent before the visitor decided, measured before and after a fix, with the release ids and signed ledger records needed to check the claim independently. A self-attestation with verifiable evidence, not a third-party certification.

  2. 4.2 Ownership before the wire: a per-country rules ladder for AI, functions and forms

    Most forms, ERPs and CRMs were designed before Rust made ownership checkable and before GDPR, PIPA and the AI Act made it law. They shape the record first and filter it later. This article sets out the alternative: rules owned per country, published as tested artifacts, and AI agents and functions that receive a data binding only when a mandate resolves.

5. Global

  1. 5.1 Globalization — Goal Checklist (Pending / Review State)

    Status board for the globalization parameters of the chat-commerce platform (chatbot, Knowledge Base, market storefronts). Each entry is a goal with its current state. States:

  2. 5.2 Global Payouts — Dependency Map

    Status: Living reference · Globalized Commerce settlement layer Scope: How an agentic purchase gets from authorized to money-in-a-bank, per market, and what each market depends on.

  3. 5.3 From Wayfair to AI Agents — The Road to Machine-Readable Commerce

    How South Dakota v. Wayfair (2018), a decade of EU enforcement against Google, and Shopify's Markets architecture (Horizon, GraphQL, Catalogs) converge on one rule: commerce compliance follows the buyer's context — and AI agents now read that context literally. Why i18n, accessibility, and machine-readability are the same plumbing; why semantic components beat compiled utility CSS as LLM context; and how design and content privacy work when the machine plane is an egress channel.

  4. 5.4 The Trust Framework

    Eight practices that make automated and AI-assisted work defensible — adoptable with tools you already own, no purchase required. Written for the operator who is being asked to adopt AI and has rational reasons to hesitate.

  5. 5.5 The AI Dialog — Terms for Designers and BAs

    Plain definitions of the words the AI-first architecture keeps using — silent failure, event bus, hydration, judgment, mandate, system of record, privacy streaming — with the parameters each framework actually evaluates. Written for the people who ship the work but didn't pick the vocabulary.

  6. 5.6 The Compliance Calendar — 2018 to 2027

    Every dated obligation shaping commerce data, from GDPR and Wayfair to the Content API sunset, the CRA, and GS1 Sunrise 2027 — all public record, including the two Shopify pixel changes that took effect without asking anything of the merchant. Plus what the calendar obliges of builders: signed non-destructive releases, self-improving test loops that keep their own verdicts, and an adoption path for security that does not wait six months for procurement.

  7. 5.7 Served, stored, subpoenaed — sovereign edge serving for Korea

    Data sovereignty is three questions, not one: where a page is served, where the record lives, and whose law can compel it. A working definition of sovereign edge serving, Korea's PIPA as the worked example — entrustment vs third-party provision vs cross-border transfer — what Webflow, Cloudflare and Naver each actually offer, and the crossing inventory that makes a regulator's suspension order survivable.

  8. 5.8 Global compliance harness checklist: test-driven, AI-assisted

    A checklist for a test harness that blocks a release when a consent, privacy, payment, residency or catalog rule fails. Each item is a test to write before the code: the rule, the kind of test, and the tool — static check, unit, integration, or end to end with Playwright or Selenium.

6. Shopify

  1. 6.1 CRM Sync — Shopify App Platform Changes

    For: Product managers, operations teams, and business stakeholders tracking Shopify app compliance Date: 2026-05-18

  2. 6.2 Shopify App Requirements Checklist (2026)

    A comprehensive, downloadable checklist for building, submitting, and maintaining a Shopify App Store app. Based on Shopify's official App Store requirements and the latest plat…

  3. 6.3 Risk & Liability Brief — The 2026 Client-Side Cliff

    Audience: owners, finance, legal, and engineering leads who carry the downside. As of: 2026-06-21 · Companion to: FORWARD-DEPLOY-AGENTIC-GRAPHQL.md (the fix).

  4. 6.4 Dawn → Horizon: Agentic Cart Functions

    Migration guideline: move Dawn's client-side business logic to Horizon's thin presentation with cart, pricing, and checkout re-homed to server-side Shopify Functions and the Tool Runner — driveable by an agent under an AP2 mandate. Includes why REST→GraphQL and GA4 Consent Mode v2 are one seismic move, and the dated migration checklist.

  5. 6.5 Google turned off the list upload. We were never uploading lists.

    For: Marketing ops, analytics engineering, and the business analyst who owns segments Status: Plan of record · GA4 pipe built · Live Google push routes via the Data Manager API

  6. 6.6 Marketing was built on the page view. The funnel now pays for the consented login.

    For: Marketing ops, performance media, and analytics engineering Status: Built (GA4 push + audiences) · Direct Google Ads push pending Ads API credentials Date: 2026-07-07 Depen…

  7. 6.7 REST Is Not GraphQL

    What actually breaks when a Shopify integration moves from REST to GraphQL: the inverted error model, cost-based rate limiting, GID identifiers, cursor pagination, and the surfaces that exist in only one API — with the failure mode each produces and an audit checklist.

  8. 6.8 Shopify and Google sunsets: what is due before 11 November 2026

    Every Shopify, Google Analytics and Google Ads deprecation dated between 16 September and 11 November 2026, the five topics merchants ask about — native mobile, short-lived tokens, the REST sunset, GraphQL data layers, and GA4 consent and conversions — and whether CRM Sync is exposed to each, with every source linked.

7. Webflow

  1. 7.1 Webflow App Requirements Checklist (2026)

    A comprehensive, downloadable checklist for building, submitting, and maintaining a Webflow Marketplace app. Based on Webflow's official Marketplace guidelines and the latest pl…

  2. 7.2 The Webflow App Stack — Vite + TypeScript Monorepo, with 11ty/Vue/Svelte Islands

    The modern scaffold for a hybrid Webflow app: pnpm monorepo, Vite + TypeScript designer extension (Svelte or Vue), Cloudflare Worker backend, shared types end-to-end — plus the 11ty islands setup for the site side, where pages stay static and components hydrate one at a time.

  3. 7.3 Safe SVG for Webflow and UIkit

    Inline SVG without inheriting the upload's privileges — an allow-list sanitiser, async hydration, monochrome paint, and where GSAP and Lottie actually sit.