Skip to content

Command center implementation status ​

Updated 9 October 2026. The original full enterprise blueprint is not complete. The substantial implemented release and migration records below describe delivered slices, not completion of every original requirement. The cleanup and Orders debounce fix are merged; their frontend production releases passed. The remaining implementation and acceptance work is tracked in the full-suite completion plan. Earlier claims that the core release completed Phases0–7 were too broad. External configuration and real operational evidence remain distinct from software completion.

Implemented foundations ​

Live staff permissions and campus scope; independent approvals for control restoration, wallet adjustments, sensitive configuration and category commissions; versioned staff access and invitations; financial observations with explicit unknowns; privacy triage and holds; immutable audit export snapshots; campus order investigations; staff support sessions; ticket triage, attachment ownership and atomic conversations; versioned taxonomy and campus operations.

Current additions ​

  • Support replies commit durable notification intent with the message, unread state and audit. Leased workers recover interruptions, fence stale claims and publish one inbox record. Notification status shows the latest 100 replies. Existing notification webhooks remain active; inbox persistence does not prove provider delivery.
  • Moderation claims, releases, decisions, restrictions and audit commit together. Listing/review restrictions invalidate public caches. Unsupported account removal is refused. The admin now uses this workflow instead of legacy partial writes.
  • Audit downloads verify private pages and the complete file against SHA-256. Complete frozen snapshots support 100,000 rows / 128 MiB, with bounded storage, request rates and expiry. Interrupted or corrupt downloads are refused.
  • New orders capture approved category/global fee rates and pricing evidence. Escrow settlement and pending earnings consume these snapshots. Historical orders retain explicit legacy policy. Pre-settlement refunds are proportional because refund records do not identify returned items; post-release platform-fee reversals remain outside this change.
  • Privacy cases can prepare protected exports of six declared owned collections. Downloads verify the case, revision, receipt, expiry and SHA-256 before saving. Preparation does not complete a case or claim delivery; maintenance expires payloads while retaining bounded receipts.
  • Live queue observations filter counts by current permissions and distinguish unavailable sources from zero. Owner-only dashboard aggregates and financial/order-specific observations use fresh access checks; revoked sessions clear cached data and discard older responses.
  • Checkout reserves a stable payment intent before provider initialization. Uncertain dispatch cannot create another reference or repeat initialization. Payment investigation exposes bounded private observations to finance staff without access codes, hosted payment links or payment mutations.
  • Payout batches fix exact requests, amounts and bank destinations before independent review. Approved work enters a durable dispatch queue; single and batch transfer paths share one immutable reference and fenced dispatch. Unknown outcomes cannot release the payout for another transfer. Provider callbacks retain canonical settlement authority. Payout investigation exposes private ledger conflicts, stale processing and uncertain outcomes with explicit missing evidence.
  • Payout reconciliation verifies an existing reference with Paystack, fixes the provider observation in a proposal, requires independent review and re-verifies before canonical settlement. Failed/reversed transfers use the established idempotent restoration ledger. Verification does not resend transfers or certify bank delivery beyond the provider observation.
  • Moderation appeals require a reviewer distinct from the original decision maker and submitter. New decisions record prior restriction provenance; overturn restores only that recorded state after checking target and case revisions. Legacy decisions without prior provenance cannot invent restoration values.
  • Additive privilege hardening closes inherited direct write/truncate access to control and privacy command tables while preserving needed reads and authorized functions.
  • Privacy inventory plans freeze counts and content fingerprints for seven owned collections and owned storage metadata. Independent review rechecks identity, case revision, holds, authority and inventory contents. Approval remains plan only; no deletion or request completion is certified. Privacy operators can reach the dedicated workspace without settings permissions.
  • Independent-session PostgreSQL concurrency checks cover checkout reservation/dispatch, payouts and privacy authority/hold races. Checkpoint 61a7f7b7 passed CI quality verification and the complete migration replay, launch flows and native concurrency job (run 37229129193). Later migrations require a new passing run; local serial fixtures do not prove concurrent behavior.
  • Campaign proposals freeze the complete consenting audience and content for independent review. Leased publication records actual inbox receipts while external delivery stays unverified. The direct bulk-send actions are retired. Checkpoint 878d056a passed the full quality and native database CI jobs (run 37268623667).
  • Reviewed refunds freeze funding and order evidence before an independent decision. The supported execution credits the Debelu wallet for proven full unsettled payments and verifies the actual ledger result. Historical ambiguities remain explicit investigation cases. Provider refunds and settled-order recovery are outside this operation.
  • Scoped privacy execution requires its own destructive approval after inventory review. It verifies deletion counts for seven declared owned collections and uses exact avatar versions for storage deletion. Financial/account/shared data, unclassified storage, backups and external systems remain retained; the overall privacy request remains incomplete. The matching checkpoint passed full quality and native database CI. Later authority and export changes require their own verification.
  • Expanded protected exports include thirteen minimized owned collections and preserve the original export contract. Case refreshes clear private context while checking current access; identity evidence/history and support diagnostic receipts bind exact cases, actors and subjects.
  • Legacy return claims no longer certify refunds or runner dispatch. Administrator bulk order statuses cannot refund orders, mark delivery or release escrow; canonical buyer cancellation and handover remain intact. Finance investigation replaces the misleading direct refund UI.
  • Recovery guidance is visible in the dependency cockpit. An isolated representative drill passed eight suites / 85 assertions with fixed source hashes. This is serial fixture evidence, not a hosted restore or provider delivery certificate. Maintenance calendar entries describe plans and do not certify activation or live health.

Database rollout ​

On 7 October, ten additional migrations (022, 023, and 025–032) were applied through Supabase MCP with hosted history and permission readback. See the migration receipt. The full native PostgreSQL replay and independent-session command tests passed. The invitation Edge worker is deployed with JWT verification and rejects unauthenticated requests; sending configuration was not changed.

The latest application batch adds actual sidebar dropdowns, bounded order-list and detail requests, independent vendor identity review with protected evidence, encrypted invitation delivery intent, governed WhatsApp support replies with one-attempt fencing and signed delivery status, and explicit vendor sanction commands with expiry, revocation and audited receipts. Legacy direct identity review and strike mutations are retired. Provider acceptance remains separate from actual delivery. PR312 additionally enforces active vendor sanctions in marketplace discovery, checkout and commercial writes, provides independent owner appeals, and makes the configured campus registry authoritative across the applications. Migrations033–036 were applied through MCP; hosted versions and Edge worker19 are recorded in the operations checkpoint.

Historical 5 October checkpoint: the user renewed migration authorization and reconnected Supabase. Nineteen migrations were applied through MCP; 134 function bodies and 19 command-table privilege boundaries were verified in production. See that migration receipt. Earlier manually installed history requires reconciliation before CLI push. Later application releases require their own deployment evidence.

Latest delivered controls ​

Migrations037–044 are applied through Supabase MCP. They provide reviewed refund-exception dispositions, retained-system privacy handling, recovery objectives and evidence, deterministic authority locking, owner continuity, independently reviewed temporary staff access, scoped personal command work, and financial period evidence snapshots. Sidebar sections are actual dropdowns; configured campuses are administered centrally and used dynamically by the applications.

PR317 delivered reviewed merchandising and Explore banners, platform coupons and flash sales, actual scheduled maintenance activation, and financial-case authority preflight correction (045–047 and049). PR318 delivered reviewed category attribute definitions and protected prospective product validation (048), fresh leased authority after protected resource waits (050), and exact atomic observed listing-change review with publication guards and retained history (051). Passing exact-candidate CI, MCP application/readback and matching backend/admin/storefront deployment are recorded in the receipt. Owner-specific branding mutations052 are installed and verified too.

Operational configuration and evidence ​

The implemented slices passed their recorded release gates. The full original program still has product and acceptance gaps tracked in the completion plan above. Selected external channels, invitation sending, hosted recovery and retained-system privacy outcomes also require operator configuration and independently inspected evidence. Paystack health remains unverified. No live provider delivery, bank settlement, full customer erasure or hosted recovery is certified by a passing software test. Conditional integrations retain the original blueprint's business-need condition. See the operational closeout for real-world enablement requirements.

Released under Proprietary Enterprise License.