Nothing is written during the first two stages, so a refusal costs you nothing. The two stages that can change your site are the two you switch on yourself.
The uploaded file and the ZIP structure are checked. Nothing has been extracted at this point and nothing has been written.
The plugin header is parsed and the declared platform requirements are tested against this install. A refusal here costs nothing to undo.
The validated archive is handed to WordPress's native upgrader. Replacement of an existing folder happens only if you ticked it.
A structured report is saved, and successful installs are activated only if you asked for that too. Both switches default to off.
Every new client site gets the same fifteen plugins. One batch, one report, and the report doubles as the record of what the site started with.
Staging has drifted and you are rebuilding it to match live. Replacement is a deliberate tick rather than a default, so the rebuild cannot quietly overwrite something you wanted to keep.
The new owner wants to know exactly what is installed and where it came from. Download the CSV and the question is answered in one attachment.
You have a folder of ZIPs from a previous developer and no idea which are valid. Run them through: the twelve refusals tell you which archives are broken before any of them touch the site.