Skip to content

How Promotler borrows git's model (snapshots, hashes, merges and signed tags) to make sponsored posts provable, without making marketers learn git.

JP 2 min read

Sponsored posts have a trust problem. The brand approves a text, the creator posts something slightly different, deletes it after two days, and suddenly both sides argue from screenshots. What's missing is a record both parties can point to and neither can quietly change.

Developers have had a tool for this for decades: version control.

Map git to a deal

Git In Promotler What users see
commit immutable snapshot of text and terms "Version v3 · a1b2c3d"
branch + pull request a change request on a base version "Suggested changes"
merge fast-forward or three-way merge "Accept changes"
merge conflict both changed the same passage "Resolve overlap"
signed tag both parties sign one hash "Approve final version"

Marketers never see the word "rebase". The UI uses their vocabulary and keeps git's guarantees underneath.

Terms belong in the snapshot

The most important design decision was to put price, publish window, days live and auto-delete into the commit, next to the post text. Changing the price is just another suggested change, reviewed and accepted like a typo fix. So one hash covers everything, and signing that hash is the agreement.

ts
type Snapshot = {
	v: 1;
	content: string; // NFC-normalized, \n line endings
	terms: { priceCents: number; minLiveDays: 7 | 14 | 30 /* … */ };
};

Hash in exactly one place

The snapshot hash is computed in one place only, by an insert trigger in Postgres:

sql
sha256('pp-snapshot-v1\n' || content || '\x00' || terms::jsonb::text)

jsonb normalizes key order, so the hash is deterministic. Clients can't supply it, and there's deliberately no TypeScript implementation that could drift from the SQL one. The UI shows the first seven hex characters, just like git.

The database is the referee

If the hash is the contract, the database must not let anyone bend the rules, including a buggy UI:

  • Row-level security on every table, and no direct writes: every mutation is an audited RPC function.
  • Versions, reviews, sign-offs and the audit log are append-only.
  • A sign-off is bound to a version fingerprint. Any later change voids it.

pgTAP tests check privileges, RLS and workflow invariants against a written catalogue of logic flaws, and assert that the database says no to every one of them.

What it buys

When a post goes out, the platform publishes exactly the signed text via the LinkedIn API, then keeps checking that it stays up and unchanged. Payouts release on verified milestones. If anyone ever asks "is this what we agreed on?", you compare two hashes.

#postgres#security#product

About the project

  1. v1 3f9c2e1
  2. v2 a71d08b
  3. v3 c04e5f2
  4. ✓ signed
B C Draft v1 · 3f9c2e1

Acmecutsreportingtimeby80%.Tryitfreetoday!

Price €400 14 days live
In development

Promotler

Sponsored LinkedIn posts with a verifiable agreement.

A platform for sponsored LinkedIn posts: brand and creator sign off on the exact text and terms, then the platform publishes it and pays out on verified milestones.

View project →

Keep reading