LFW

How we work · Platform

LFW Signet

Approval for website changes you can prove afterward. Design the flow, name who approves what, preview the change as it will look, send it live in one click. Every decision is signed and kept, on your site too.

Book a call Try the sample desk

A flow you design

Steps in order, drag them around. Each names people, roles or capabilities, a checklist, and how many must agree. Rules route a change to a flow by content type, category or author.

A preview you can trust

The proposed page renders on your own site, in your theme, from a signed link. Approve, decline or send it live from the preview or from the portal.

A record that stays yours

Every decision is one event in a signed chain. Your site keeps a copy as it happens. Export it and verify it with two public keys, no LFW required.

Where it stands. The engine, the portal, the flow designer and the record are built and tested. Pages built with LFW Mason go through it today for organizations that turn it on.

The module for sites on WordPress is in development and no client site runs it yet. Drupal follows. This page will show live numbers from our own record once our own pages go through a flow, and not before.

Try it: the sample desk

Three fictional changes wait for review. Tick the checks, approve as the content owner, then approve as the publisher. Nothing leaves your browser. The rules that refuse an incomplete checklist here are the same module LFW Signet runs.

Interactive example

An approval you can trace.

Review a change, complete its checklist, and move it to Ready.

Publishing desk
Review the change

Public meeting notice

Current version

Event time: 9:00 a.m.

Proposed version

Event time: 10:00 a.m.

Before approval

3 checks remaining

Sample content. Changes stay in this browser. The rules that decide here are the same module LFW Signet runs. About LFW Signet

How a change gets approved

  1. Someone proposes a change. On a site with the connector, editing a live page creates a proposal instead of changing the page. On Mason, submitting a page for review does the same.
  2. Signet routes it. The change enters the flow whose rule matches its content type, category or author, or the site's default flow. The flow version is pinned, so a later edit to the flow does not move it.
  3. Approvers see it in the portal, or on the site. They read the word diff, open the preview, tick the checklist, and approve, decline or return it with a note. Each decision is recorded and signed.
  4. Someone sends it live. One click. The portal rings the site, the site applies the change only if the live page still matches what was approved, and confirms. Or schedule it for a date.
  5. The record is kept twice. LFW holds the signed chain and publishes a daily root. Your site stores the same events beside its own rows, readable in your admin without any plugin.

What one event looks like

Payloads are canonical JSON. The hash of each event includes the hash of the one before it, so nothing can be removed or reordered without detection.

{ "type": "signet.step.approved", "item": "SG-7K3M9Q2A",
  "object": { "type": "page", "id": "1412", "revision": "2087", "title": "Public meeting notice" },
  "flow": { "key": "standard", "version": 3 }, "step": { "key": "owner", "name": "Content owner" },
  "actor": { "name": "Pat", "role": "editor", "via": "cms" }, "decision": "approve",
  "checklist": [{ "key": "links", "checked": true, "by": "pat@example.gov" }],
  "content_hash": "3f9a…", "base_hash": "b81c…", "at": "2026-09-22T15:04:05Z" }
seq 58 · prev 1c44… · hash 9e02… · signed by LFW and by the site

Anyone can check an export on the verification page. LFW's public key is published at a fixed address.

Built for the questions buyers ask

Who approved this, and when?
Open the page's record. Every step, every person, every timestamp, with the hash chain that proves the order.
Can we route legal notices differently?
Yes. A rule sends one category through a longer flow while the rest of the site uses a short one.
Can our AI help without approving?
Yes. Claude or ChatGPT connects to read the queue and submit content for review. No tool can approve, publish or schedule.
What if we leave?
The record and the flow stay on your site. The export verifies without us. We say this in one sentence on the export screen, and it is true.

Questions

How is this different from PublishPress or Drupal's Content Moderation?

Those decide by role inside the site's own database. Signet lets you name people, roles or capabilities per step, route by content type and category, and it keeps a signed record outside the site that the site mirrors. If a client already runs PublishPress or another workflow, we recommend keeping it. Signet is what we set up when there is nothing.

What exactly is recorded?

Who proposed the change and what it replaced (as hashes of the content), who ticked which checks, who approved or declined at each step and why, who sent it live and when the site confirmed. Each event carries the hash of the one before it and LFW's signature; events made on your site carry your site's signature too.

Can a site administrator make themselves an approver?

If a step names a role or a capability, anyone given that role or capability on the site qualifies, and the record shows their role at the moment they decided beside the role change itself. If a step names people, no one on the site can edit their way in. A site can also be set to accept approvals in the portal only.

What happens if LFW is unreachable?

The connector keeps running the flow it last received, records every decision on the site, and can send approved changes live if you allow it. When the connection returns, LFW countersigns what happened. Nothing waits on us to publish.

What if we stop working together?

The record is already in your site's database, readable without any plugin, exportable as JSON or CSV. The export verifies with two public keys and nothing else. The flow keeps running exactly as last received; what stops is editing it and the countersignature.

Which platforms?

Pages built with LFW Mason today. A module for sites on WordPress is in development, and a module for Drupal follows it. The protocol between a site and LFW is the same for all three.

What does it cost?

It is included in the Web Operations Retainer, like everything LFW installs on a client's site. There is no separate subscription.

See it pointed at your own site.

Twenty minutes, no sales pressure. Or start with the free audit and get a real first pass on your site today.

    Powered by LFW Search
    Prefer to write?

    Tell us what needs to work better.

    Slow, fragile, hard to edit, missing a workflow. Say it plainly, and you'll get a straight answer, not a ticket number.