The store now returns replaced_entry / replaced_entries, but the write-approval
replay (the exact path #117952 was lost on) went through
hermes_cli.write_approval_commands._apply_one, which kept only (success, error)
and printed "Approved N memory write(s)." -- the overwritten text never reached
the approver. Return the full applier result and list every overwritten entry
under the approve output (CLI and gateway share this handler).
Also re-word the staged preview: "- replace: old -> new" reads as a span patch,
which is exactly the misreading that made the approver wave the batch through.
It now says "replace entry matching '<old>' -> whole entry becomes: <new>".
One invariant test, red on the PR head (approve output lacked the entry text).