MIZOKI Signal for Shopify
The net-contribution offering — merchant-facing
Revision: r1.1 · September 2026. r1.0 (August 2026) is archived byte-for-byte at
docs/marketing/history/MIZOKI_SHOPIFY_OFFERING_AUG2026_r1.0.md; this revision reconciles
it to the lane canon (Wave 2, WS-11).
Governing canon (authority order): docs/product/SIGNAL_OVERVIEW_v5.md (top-level product
overview) → docs/product/SIGNAL_SHOPIFY_MASTER_v4.md (MASTER v4 — the Shopify build spec).
Any conflict between this offering and MASTER v4 resolves to MASTER v4. The earlier
positioning fragment (# MIZ OKI 3.5/docs/marketing/mizoki-shopify-net-yield-positioning.md)
is one of the inputs MASTER v4 consolidated; it no longer governs anything here.
Claim discipline: capability statements carry MASTER's merchant-facing triad
[Validated] / [Illustrative] / [Roadmap] alongside the platform axis
LIVE · PARTIAL · IN BUILD · PROPOSED; every figure carries exactly one TRUTH.md label
(verified result · benchmark result · pilot result · design target · illustrative scenario).
Stories are composites until a named pilot signs off. Preview labels flip only on claim-ledger
entries whose evidence class is at least DESIGN-PARTNER; self-pilot data never flips a public
label.
Naming (MASTER standard): product MIZOKI Signal for Shopify · brand MIZOKI3 ·
division Signal. Version numbers stay in engineering, never in merchant-facing copy.
Services are named, never numbered, in this document.
1. WHY SHOPIFY IS THE RIGHT WEDGE
Every claim in the platform's net-yield thesis requires data most advertisers cannot produce. Shopify merchants already have all of it in one system:
| Required for net contribution | Where it lives in Shopify | Availability |
|---|---|---|
| Order and line-item lineage | Orders API | Direct |
| Cost of goods per variant | InventoryItem unit_cost |
Direct, when merchant maintains it |
| Refunds and returns | Refunds / Returns API | Direct, with real timestamps |
| Discount liability | Price rules, applied discounts | Direct |
| Fulfillment cost | Fulfillment records, third-party logistics | Partial — often needs merchant input |
| Payment processing | Shopify Payments / gateway fees | Direct |
| Stock position | InventoryLevel | Direct |
| Behavioral signal | Web Pixels API | Direct — already the collector |
The consequence: for a Shopify merchant, "revenue is not contribution" stops being a thesis and becomes an arithmetic the platform can actually perform. For a merchant on a custom stack, the same claim typically needs a multi-week data engagement before the first number (illustrative scenario, not a customer result).
The thesis, in MASTER's words: independent merchants lose money to two structural failures — ad platforms grade their own homework (self-attribution inflates ROAS), and every tool optimizes revenue while merchants live on margin. Signal measures what ad spend actually causes and optimizes Net Contribution Margin — what an order actually nets after everything it costs — under governance a founder can watch working.
2. THE ONE-SENTENCE OFFER
Your ad platforms report revenue. Shopify knows what that revenue actually earned you after COGS, refunds, discounts, fees, and fulfillment. MIZOKI Signal connects the two — and proves which spend caused the difference.
The wedge's headline number is the truth delta: platform-reported ROAS versus measured or estimated incremental Net Contribution Margin, read off the merchant's own ledger.
3. WHAT A SHOPIFY MERCHANT GETS, BY LOOP
PROVE — causal contribution [LIVE] · [Validated]
Holdout registration and lift-measurement machinery is serving (claims-ledger row C41, status backed; the intent family — signal ingest, scoring, graph, causal — is deployed and IAM-locked). The prediction never grades itself: the intent graph produces targeting hypotheses; only the experiment stack substantiates lift, and graph adjacency never establishes causality. Causal machinery: X-Learner / DR-Learner with DoWhy refutation on every estimate. Platform-reported conversions are treated as evidence, never as truth.
MASTER's measurement tiers, each labeled where it stands today: - Intent-cohort holdouts — registration write-once, lift reports served (Validated machinery). No merchant holdout is registered yet; the first registration precedes any activation, by rule. - Ghost bidding — PROPOSED: registration shipped, the execution path is in development, and no live ghost-bid experiment has run against real ad spend. - Geo experiments — the calibration lane was armed under governance on 2026-08-24 (observe-only, human-approved actions only, guardrail audit owed); no pilot readout exists. - Lift-calibrated mini-MMM and pooled category priors (labeled as priors) — [Roadmap].
Attestation honesty: cryptographic attestations verify that an approved computation ran — never that measured lift was causal. The two are never conflated.
PROFIT — net yield [IN BUILD] · Preview · in development
Revenue → refunds and returns → fulfillment and required costs → net contribution, as the NCM-v1 metric contract defines it (MASTER §2.5): net revenue after discounts, minus landed and bundle-decomposed COGS, pick/pack and dimensional shipping, platform and payment fees, pro-rated promotion, and E[RL] — expected reverse logistics — with ad spend under causal credit, never last-touch. NCM's definition is versioned; any change to a term ships as a new version with a migration note, and dashboards, covenants, and value feeds pin a version. Secondary metric for growth-tier merchants: miNCM, incremental NCM per marginal dollar — where the next dollar goes [Roadmap].
Three rules that make this credible rather than convenient: - E[RL] is modeled per SKU × cohort × season and trued-up at return-window close. A modeled reverse-logistics estimate is labeled as an estimate and never presented as an observed return; true-ups are batched on a fixed cadence so measurement honesty does not destabilize the bidder it feeds. - Missing required costs leave a row incomplete and excluded. Costs are never invented to complete a calculation; a missing input is a named gap. - The order-economics inputs (COGS by SKU, pick/pack, shipping, fees, returns) are declared once, in the authenticated onboarding flow — never re-asked ad hoc, never defaulted.
Returns-adjusted net yield — what is shipped today, labeled honestly:
- Mechanism — verified result: RETURNS_ADJUSTED_NCM=true serving on the net-yield service, revision 00013-bfc, NET_YIELD_WRITEBACK=false held
(re-measured 2026-08-29 and 2026-09-02, docs/reports/GATE2_SOAK_STATUS_2026-08-29.md). The
label covers the mechanism only.
- What the mechanism does: a tenant-configured return-cost multiplier, bounded to
[1.0, 4.0] and refused (never clamped) outside that range, scales the already-observed
refund processing cost toward a fully-loaded reverse-logistics estimate. The default is the
identity 1.0, so the flag alone never changes a served number
(services/net-yield/returns_adjustment.py). The full E[RL] model above is the [Roadmap]
form; the multiplier is its shipped first step.
- Outcome: any yield or margin improvement from returns adjustment is a design target — no
pilot readout exists, and the soak measured zero refund rows because no live merchant
traffic has crossed the service.
NET_YIELD_WRITEBACK remains OFF. The platform does not claim to bid on net contribution;
value feeds are the ceiling of the L1 Signal level and stay off until reconciliation passes.
ANTICIPATE — intent evidence [PARTIAL] · Preview · in development
The intent machinery is deployed and IAM-locked [Validated]; merchant-facing intent evidence stays in preview until pilot artifacts exist. The Shopify Web Pixel is already the collector. Signal capture extends the existing pixel — a second collector is a build error. Content-free behavioral sequence only, with per-module retention bounds and session-end purge. Positioning is anticipatory intent with proof of causal lift: every intent-driven activation requires a holdout registered before first exposure.
GOVERN — the gates [LIVE] · [Validated]
Consent gate fail-closed. GDPR erasure cascade across every store. O-1 privacy lock
(DISALLOWED_KEYSTROKE_DYNAMICS). Observe-only default on every adapter. Authorization is
the clipped-ReLU Decision Eligibility Layer per action class (canon:
docs/architecture/DEL_AUTHORIZATION_FUNCTION.md): flat zero below threshold is a
deterministic denial, and a barely-cleared score earns only the smallest reversible version.
The platform sets per-class floor thresholds; a merchant may raise them, never lower them —
safety is not configurable downward. Per-class parameterization is [Roadmap].
4. THE SHOPIFY-NATIVE DECISION JOBS
The High-Value Decision Jobs J-01…J-06, instantiated against data a merchant actually has:
| Job | Shopify-specific form |
|---|---|
| J-01 Incrementality | Does paid spend on this collection cause purchases, or harvest them? |
| J-02 Waste Prevention | CPA rose — is it auction pressure, or did checkout slow down? |
| J-03 Margin Control | Which SKUs are being advertised into negative contribution after returns? |
| J-04 Learning Stability | Platform feedback noisy after a catalog change — stage or withhold? |
| J-05 Executive Defensibility | Shopify says one number, Meta says another. Which is governed? |
| J-06 Team Leverage | Recurring margin-vs-spend reconciliation, assembled not authorized |
Story bank (MASTER §1.4, v1.2 integrated): ten composites, one grammar — their question → the quiet test → what the ledger showed → what changed. Story 7, The Bundle That Lost Money (net yield — preview), leads every Shopify-audience surface; J-03 Margin Control is its Decision Job. Executive briefing arc: PROVE (1) → PROFIT (7) → GOVERN (9) → ANTICIPATE (6). J-02 Waste Prevention is told through the demo's mobile-checkout-latency trace — an illustrative scenario replayed deterministically, not a customer result. Preview rule: infrastructure-live ≠ outcome-proven; preview framing holds until pilot artifacts exist, and the first verified pilot number replaces its composite the same day.
J-03 is the one that closes deals. Most merchants cannot currently answer "which SKUs am I advertising into a loss after returns?" — and it is a question they know they should be able to answer.
5. HIGH-RETURN CATEGORIES — THE SHARPEST WEDGE
Apparel, footwear, and furniture carry return rates where platform ROAS and net contribution diverge most violently. Illustrative scenario: a campaign at 4× reported ROAS with a 40% return rate and a 55% gross margin can be contribution-negative while every dashboard shows success. That is a scenario, not a customer result and not an industry statistic.
These merchants are the ideal first pilot. The gap between what they're told and what they earn is largest, so the platform's value is most visible — and most verifiable against their own Shopify data.
Which merchants, honestly (MASTER §1.3 tiers — capability floors set by statistical power, not plan price) [Illustrative]: T1 Emerging stores get value feeds, feed enrichment, cold-start seeding, and pooled priors labeled as priors — no merchant-level incrementality claims; T2 Growth adds ghost-bid and cohort holdouts and NCM reallocation; T3 Mid-market adds geo-lift, lift-calibrated mini-MMM, cross-channel, and covenant autonomy.
The measurement tax, stated honestly: always-on holdouts cost real conversions — that is the price of truth, and the product says so. The holdout share is a floor-bounded covenant parameter (MASTER owner decision 15); the share is stated as a design target, never a promise.
6. PHASE BINDING — P1–P4 ON THE PLATFORM'S B1–B5
MASTER §3.3 binds the Shopify product phases to the platform blueprint phases. There is no five-phase rollout; each product phase has an exit criterion, and no phase advances on assertion.
| Product phase | Platform phase | Scope | Exit criterion | Status |
|---|---|---|---|---|
| P1 Foundation | B1 Control foundation | App, Canonical Event Envelope, NCM, value feeds, L0–L1. Commerce truth observe-only; the existing Web Pixel extended (content-free, consent-gated); consent-off produces zero persistence; erasure round-trip across every new field; no second collector. | Clean Shopify-vs-tracked reconciliation across the design partners | IN BUILD — code-complete: every activation surface flag-OFF, zero live merchant traffic until operator secrets land; no reconciliation attestation exists for any merchant yet (docs/roadmap/P1_BUILD_PLAN.md, docs/reports/SIGNAL_SHOPIFY_LANE_STATUS_2026-08-12_R3.md) |
| P2 | B2 Measurement & world model | Holdout UX, ghost bids, cohort experiments, causal-credit reports, L2–L3. The first holdout is pre-registered with a declared estimand, population, and horizon before any activation, and is refutable. | First auditable incrementality artifact per partner | [Roadmap] |
| P3 | B3 Bounded autonomy | Geo, lift-calibrated mini-MMM, cross-channel, miNCM, covenant GA. Contribution economics reconciled against the causal estimate; return windows closed, not assumed; NET_YIELD_WRITEBACK still OFF; recommendations only. |
Sustained miNCM accuracy over two or more cycles at several T3 merchants | [Roadmap] |
| P4 | B4 Hardening & scale | Cold-start GA post-artifact, pooled priors, App Store, Audiences interop. | Per MASTER §3.3 | [Roadmap] |
| post-P4 covenant GA | B5 Certified L5 | Full class authority within a signed covenant, reversible classes first. | At least one merchant running a certified L5 class a full quarter, zero breaches | [Roadmap] |
Binding rules (MASTER §3.3): no product phase outruns its platform phase; certification artifacts are shared — covenants cite platform gates, never re-assert them.
Decisions taken (MASTER §3.6a, attributed — copy never contradicts them): - Decision 1 — distribution (DECIDED 2026-08-12): direct distribution for P1–P3; App Store at P4. One platform-owned unlisted public Signal app, installed by direct link; App Store listing and Built-for-Shopify review land at P4, after which App Store serves the self-serve tiers while direct install stays supported for enterprise merchants. - Decision 2 — credential custody (DECIDED 2026-08-12): merchant-owned ad accounts with merchant-granted credentials; managed accounts not adopted. Credentials are granted on the merchant's Connectors page into per-tenant secret custody and are merchant-revocable at will. This preserves the L0/L1 no-spend gate and tenant isolation; a managed-account offering would be a new owner decision gated behind L3+ autonomy.
Autonomy is earned per account × action class on MASTER's ladder (§3.2): - L0 Observe — read-only recommendations with reasoning paths; the install default. - L1 Signal — value feeds, audience syncs, feed enrichment; no spend changes. Gate: a clean Shopify-vs-tracked reconciliation window. - L2 Housekeep — pause low-inventory / high-return SKU ads, rotate creative, exclusions. Gate: one purchase cycle at L1 with zero violations. - L3 Reallocate — intra-platform budget, cumulative ±20% per campaign per day (design target), hard monthly cap. Gate: calibrated forecasts over two cycles and at least one completed holdout. - L4 Cross-channel — cross-platform reallocation and bid-strategy changes. Gate: two or more completed experiments and a clean authorization history. - L5 Autonomous yield — full class authority within a signed covenant (daily max, cash floor, exclusions); T3 volume, sustained miNCM accuracy, covenant signature — per class, reversible classes first.
Platform certification gates are cited from platform canon (CONSTITUTION III.6), never re-asserted here — promotion requires Brier ≤ 0.20, AUC ≥ 0.72, and stable lift across ≥ 2 purchase cycles (design target thresholds) on that class's decision stream. Signal ships at L0/L1, and the promotion decision is human. Demotion is mechanical, never discretionary. Every level carries a one-tap kill switch, an immutable journal, and a weekly plain-language digest.
7. WHAT THIS IS NOT
Stated plainly, because Shopify merchants have been sold each of these:
- Not an attribution app. It does not re-credit conversions with a better model.
- Not a bid manager. Adapters default observe-only; execution authority is separate.
- Not a profit dashboard. Dashboards report. This produces governed decisions with evidence.
- Not a personalization engine. Creative compatibility is a bounded input to incremental economics, never a psychological profile.
- Not autonomous. Every action in the pilot period requires human approval.
- Not the platform grading its own homework. Platform lift studies are the platform grading itself; Signal's experiments are publisher-agnostic by design.
Fleet integrity — as more merchants run on the platform they will meet in the same auctions and product categories, so independence is built in rather than promised. Each merchant's optimization loop runs on its own signals, its own net-contribution objective, and its own authorization thresholds: there is no cross-merchant bid coordination, and because every decision journals its inputs, an auditor can verify from the ledger that no decision for one merchant consumed another merchant's data [PARTIAL — test-pinned by tests/governance/test_fleet_integrity.py and the ledger independence audit in contracts/mizoki_contracts/independence_audit.py; the release-time run of that audit is not yet scheduled]. Where cold-start seeding draws on pooled category priors, those priors are differentially private aggregates, always labeled as priors, and never a merchant-level incrementality claim [IN BUILD — no pooled-prior pipeline exists today; consent default is an open owner decision]. The platform runs in a single region today; EU data residency per tenant is an owner decision with counsel before any EU merchant is onboarded [PROPOSED — owner decision D-14 open; no residency setting exists in any tenant configuration, and that absence is test-pinned so nothing can silently claim it].
8. PRICING AND ENTRY POSTURE
Wedge (MASTER §1.4): the free Profit Truth Audit — connect store and ad accounts, get a short observe-only report whose headline is the truth delta. The audit converts on the merchant's own ledger [Roadmap — owner decision 3, go/no-go].
Entry engagement: the governed 90-day pilot — one brand, agreed source systems, two consequential decision classes, standard onboarding rather than a bespoke engagement. The pilot starts at L0 and reports honest states only: incomplete, ready for review, approved for observe, active observe, blocked.
Pricing shape [Roadmap — owner decision 7]: T1 self-serve, T2 flat tiers under agency retainers, T3 platform pricing. The binding constraint: pricing must never punish the honest "spend less" verdict — a percentage of spend misaligns; flat or performance-on-NCM aligns. No price point is stated in merchant copy until the owner decides.
What a merchant brings: the order-economics inputs — variant-level unit_cost, pick/pack,
shipping, fees, and return cycles — declared once in the authenticated onboarding flow. Cost
data quality is the single largest determinant of time-to-first-evidence, and merchants who
have never maintained unit_cost should be told that during scoping rather than discovering
it in week three.
9. IMMEDIATE ACTIONS
- This offering is reconciled to MASTER v4 (r1.1); any future conflict resolves to MASTER v4, never the other way round
- Identify one high-return-category pilot candidate
- Confirm the merchant maintains variant-level
unit_cost, or plan the ingest - P1 acceptance is test-pinned (
docs/roadmap/P1_BUILD_PLAN.md); the P1 exit — design-partner reconciliation — is an owner item, not an engineering one
All capability claims carry status labels. Illustrative figures are not production telemetry or customer results. Preview labels flip only after verified pilot numbers enter the claim ledger at design-partner evidence class or above.