Tenant isolation
Tenant data queries and mutations are scoped by trusted shop identity, never a client ownership claim.
Security and privacy boundaries
Wand separates merchant, affiliate, internal administration, and public API authentication; scopes tenant data by trusted shop identity; and preserves audit and retry controls around sensitive workflows.
Tenant data queries and mutations are scoped by trusted shop identity, never a client ownership claim.
Merchant admin, affiliate portal, super-admin, and public API boundaries remain separate.
Webhooks, jobs, commission writes, migrations, and payout operations preserve idempotency constraints.
Sensitive status, payout, profile, tax, and administrative changes use established audit paths.
Public content and synthetic tours contain no production customer data, credentials, tax data, or payout configuration.
A control is not described as certified, production-proven, or approved without exact retained evidence.
Walk through the current product, evidence status, and launch boundaries with the team.