Skip to content

Migrations 053–078 were applied successfully through Supabase MCP on 9 October 2026. Exact hosted versions and canonical checksums are in the deployment receipt. Do not reapply these migrations. Earlier checklist text is retained as historical release guidance.

Command center migration checklist ​

Main project: New Debelu Marketplace. Production checkpoint verified 8 October 2026; pending releases are listed separately below.

Compare these files with the target database migration history before applying. Apply only pending files. On 5 October 2026 this task applied 19 migrations through Supabase MCP to project havugmqmyplqgbrlthhs after renewed user authorization. See production migration receipt for exact scope and history reconciliation requirements.

Existing prerequisite migrations ​

These existing main migrations must already be applied, or applied first in the order below. Older schema and launch-hardening migrations are also prerequisites; this list does not replace the full baseline history. The legacy underscore version names require history reconciliation before an automatic Supabase CLI push.

text
20261003_001_extended_rbac.sql
20261003_002_circuit_breakers.sql
20261003_003_maker_checker.sql
20261004_001_reconciliation.sql
20261004_002_fee_engine.sql
20261004_003_ledger_adjustments.sql
20261004_004_kyc_workspace.sql
20261004_005_dispute_sla.sql
20261004_006_whatsapp_conversations.sql
20261005_001_media_moderation.sql
20261005_002_strike_system.sql
20261005_003_listing_change_tracking.sql
20261006_001_taxonomy.sql
20261006_002_merchandising.sql
20261006_003_campus_ops.sql
20261007_001_canned_responses.sql
20261007_002_support_metrics.sql
20261007_003_impersonation.sql
20261008_001_dsar.sql
20261008_002_audit_immutability.sql
20261008_003_maintenance_windows.sql
20261009_001_order_sla.sql
20261009_002_rma.sql
20261009_003_payout_controls.sql
20261010_001_api_integration_contract_fixes.sql

New command center migrations ​

The following local filenames are ordered after the prerequisite baseline. Migrations through044, plus045–047 and049, have production receipts; compare hosted history and receipts before applying anything.

text
20261010000000_authoritative_staff_access.sql
20261010000100_governed_control_commands.sql
20261010000200_reviewed_wallet_adjustments.sql
20261010000300_financial_observation_snapshots.sql
20261010000400_privacy_case_governance.sql
20261010000500_durable_audit_exports.sql
20261010000600_campus_order_operations.sql
20261010000700_staff_support_views.sql
20261010000800_staff_access_commands.sql
20261010000900_staff_invitation_acceptance.sql
20261010001000_versioned_platform_configuration.sql
20261010001100_support_ticket_triage.sql
20261010001200_support_attachment_boundary.sql
20261010001300_atomic_support_conversation.sql
20261010001400_category_governance.sql
20261010001500_campus_operations_governance.sql
20261010001600_reviewed_platform_configuration.sql
20261010001700_reviewed_category_commissions.sql
20261011000000_retire_legacy_wallet_adjustment.sql
20261011000100_support_notification_outbox.sql
20261011000200_moderation_case_governance.sql
20261011000300_chunked_audit_exports.sql
20261011000400_order_fee_snapshots.sql
20261011000500_bounded_support_notification_status.sql
20261011000600_privacy_export_artifacts.sql
20261011000700_command_center_queue_observations.sql
20261011000800_checkout_payment_intents.sql
20261011000900_payment_intent_inspection.sql
20261011001000_reviewed_payout_batches.sql
20261011001100_payout_transfer_intents.sql
20261011001200_moderation_appeals.sql
20261011001300_payout_exception_observations.sql
20261011001400_payout_transfer_reconciliation.sql
20261011001500_reviewed_privacy_erasure_inventory.sql
20261011001600_command_table_privilege_hardening.sql
20261011001700_governed_inbox_campaigns.sql
20261011001800_reviewed_wallet_refunds.sql
20261011001900_scoped_privacy_erasure_execution.sql
20261011002000_expanded_owned_privacy_exports.sql
20261011002100_governed_admin_order_status_boundary.sql
2026101102200_atomic_return_case_governance.sql
2026101102300_granular_command_capabilities.sql
2026101102400_align_manually_installed_command_functions.sql
2026101102500_subject_privacy_export_delivery.sql
2026101102600_guard_internal_wallet_refund_snapshot.sql
2026101102700_staff_invitation_delivery_outbox.sql
2026101102800_vendor_kyc_governance.sql
2026101102900_vendor_kyc_onboarding_control_guard.sql
2026101103000_governed_whatsapp_replies.sql
2026101103100_governed_vendor_sanctions.sql
2026101103200_close_vendor_strike_truncate_boundary.sql
2026101103300_vendor_sanction_enforcement.sql
2026101103400_governed_vendor_sanction_appeals.sql
2026101103500_governed_notification_provider_receipts.sql
2026101103600_campus_registry_management.sql
2026101103700_governed_refund_exception_dispositions.sql
2026101103800_governed_privacy_system_handling.sql
2026101103900_governed_recovery_objectives_and_evidence.sql
2026101104000_deterministic_review_authority_lock_order.sql
2026101104100_governed_owner_continuity.sql
2026101104200_exceptional_staff_access_reviews.sql
2026101104300_scoped_command_workspace.sql
2026101104400_governed_financial_period_snapshots.sql

The 20261011000000 migration retires application access to the old single-actor wallet adjustment function, including if the compatibility migration was previously applied. Do not reapply the old compatibility migration afterward.

The next three migrations add durable support reply notification recovery, atomic moderation decisions with actual restrictions, and complete audit snapshots up to 100,000 records / 128 MiB. Deploy the support worker and new moderation/export interfaces after these database changes.

The 20261011000400 migration captures approved category fee rates for new orders and uses those immutable snapshots at escrow settlement. Existing orders retain explicit legacy handling. The 20261011000500 migration bounds and indexes notification status and distinguishes confirmed inbox persistence from unverified external delivery.

The 20261011000600 migration prepares protected exports of six declared database collections; it does not complete a privacy request or verify member delivery. The 20261011000700 migration adds permission-filtered queue observations. The 20261011000800 migration reserves checkout payments before provider dispatch and prevents uncertain outcomes from creating another charge attempt. The 20261011000900 migration adds private, read-only payment investigation with fresh finance permissions and excludes provider access codes and hosted payment links.

The 20261011001000 migration fixes payout selection, amount and destination in an independently reviewed proposal. The 20261011001100 migration queues approved payouts and persists one transfer reference and dispatch claim before provider calls. Unknown outcomes do not create replacement transfers; initiation never certifies payment. The 20261011001300 migration exposes private payout exception evidence and distinguishes missing evidence from zero. The 20261011001600 migration removes inherited direct write/truncate privileges from existing control and privacy command tables, preserving required reads and authorized command functions.

The 20261011001200 migration adds independent moderation appeals and records restriction provenance for new decisions. Legacy decisions without proven prior state cannot be automatically restored. The 20261011001400 migration adds independently reviewed reconciliation of existing transfer references: authenticated provider verification is required at preparation and approval, and canonical settlement receipts must confirm the outcome. It does not initialize another transfer.

The 20261011001500 migration freezes a declared inventory of seven owned collections and owned storage metadata for independent review. Approval is explicitly plan only: it does not delete data, verify retained or external systems, or complete the privacy case. Unknown storage sizes remain unknown. Missing sources and changed content invalidate the inventory.

The 20261011001700 migration freezes explicitly consenting campaign audiences for independent review and durable inbox publication. Existing direct broadcast actions are retired. Inbox records do not establish push or email delivery. The 20261011001800 migration permits independently reviewed full refunds to the Debelu wallet only for proven, unsettled payments; ambiguous historical claims remain investigation cases. It retires the old single-actor manual wallet refund function.

The 20261011001900 migration requires a separate destructive approval after inventory review. It deletes only the declared owned low-retention records, checks actual deletion counts, and processes frozen avatar versions through a version-bound storage API. Account identity, financial and shared history, other storage, backups and external systems remain retained. Completing this limited scope does not complete the overall privacy request. Their application is recorded in the production receipts below; listing a local filename is not itself a release receipt.

The 20261011002000 migration adds an expanded, minimized export of thirteen declared owned collections while preserving the original six-collection export contract. Security credentials, third-party content and storage bytes remain excluded. The 20261011002100 migration closes the legacy administrator order-status path that could cancel/refund orders or release escrow outside the governed workflows. Canonical buyer cancellation and handover paths remain separate. Their released application state is recorded in the production receipts below.

The command-center migrations through052 are installed in production, with manually installed baseline definitions and MCP application records distinguished in the receipts below. Migrations 015, 017 and 018 were already installed manually; their function definitions were verified and two older definitions aligned through 024. Migration 000's retired privilege was already absent. MCP-generated remote versions differ from local filenames, and manually installed baseline migrations are missing from recorded history: reconcile history before any automatic CLI push. Do not replay this list blindly. New future migrations need their own application receipt.

Recorded production application ​

  • 5 October receipt: original command controls through021 and the024 alignment, including manually installed definitions verified separately.
  • 7 October migration receipt and operations checkpoint:022–023 and025–036 application and deployment evidence.
  • Case release receipt:037–040 refund exceptions, privacy handling, recovery evidence and deterministic review authority locks.
  • 8 October release receipt:041–044 applied through Supabase MCP to havugmqmyplqgbrlthhs after exact-head quality/native CI. Hosted versions are041→20261008050338,042→20261008050349,043→20261008050356 and044→20261008050403.

The041–044 receipt binds the released application revision ef801bbc788d1f76ceb631f99fabed949d222d20. Owner continuity is explicitly enrolled; temporary grants are independently reviewed; command work is scoped; financial period closure seals declared evidence and does not certify bank settlement.

The same 8 October receipt records 045–047 and 049 applied through Supabase MCP and hosted history read back: 045→20261008060122, 046→20261008060123, 047→20261008060126 and 049→20261008060127. PR317 merged as 3cdb9c4af98c7a097aa393422118dfd0e135f437 after exact-head CI 37734237238 passed quality and native PostgreSQL checks on 98231d12f298adfcef8577f2bace2ec0cc7b820c. Application deployment evidence remains separate from database application.

Final catalog release — applied through MCP ​

Local migrationPurposeCurrent status
20261011004800_governed_category_attribute_schemas.sqlReviewed category fields and prospective product validationApplied; hosted version20261008141253
20261011005000_final_effect_staff_lease_authority.sqlFresh leased permissions after protected resource waitsApplied; hosted version20261008141255
20261011005100_governed_listing_change_reviews.sqlExact atomic listing-change decisions and publication receiptsApplied; hosted version20261008141258
20261011005200_vendor_branding_owner_mutations.sqlOwner-specific branding mutationsAlready applied; hosted version20261008130910

CI37788584773 passed both quality and native PostgreSQL gates on23cbac034cc0a6e08e2c488cefe7f3b101ec22f5. Migrations048,050 and051 were applied in that order through MCP and verified before PR318 merged. Migration052 was already installed and was not replayed. See the final release receipt. No migration from this batch remains for manual application. Local tests, a PR or a file on disk alone do not establish hosted application.

Deploy database changes before backend and admin. Validate against a restored copy first, and verify owner login, scoped access, independent approvals, support replies, and audit records after migration. Local representative database checks do not prove compatibility with the hosted baseline.

Enterprise suite expansion — pending verification and MCP application ​

These new files are not applied and the application changes are not released. Finish implementation, write the complete acceptance package, and pass the consolidated gates before applying through Supabase MCP in this dependency order. Do not use CLI push against the unreconciled hosted migration history.

text
20261011005300_staff_session_controls.sql
20261011005400_campus_operational_policies.sql
20261011005500_governed_data_imports.sql
20261011005600_command_workspace_extensions.sql
20261011005700_line_refund_operations.sql
20261011005800_financial_execution_policies.sql
20261011005900_inventory_exception_commands.sql
20261011006000_search_quality_observations.sql
20261011006100_fraud_evidence_rules.sql
20261011006200_growth_budget_policy.sql
20261011006300_incident_and_job_replay.sql
20261011006400_integration_and_automation_governance.sql
20261011006500_immutable_bulk_work.sql
20261011006600_retention_and_recovery_adapters.sql
20261011006700_financial_policy_and_close.sql
20261011006800_granular_action_policies.sql
20261011006900_assignment_handover_and_work_context.sql
20261011007000_support_and_moderation_evidence.sql
20261011007100_governed_intelligence.sql
20261011007200_vendor_identity_reverification.sql
20261011007300_staff_assignment_scopes.sql
20261011007400_user_contact_reveal.sql
20261011007500_command_work_coverage.sql
20261011007600_integration_observations_cost_rotation.sql
20261011007700_work_routing_and_blockers.sql
20261011007800_connected_investigation_graph.sql

Migrations68–72 extend capability/session registries for earlier domains. Apply the entire verified dependency chain before exposing the new backend. Record hosted migration versions and read back the installed definitions; replace this pending status only with actual MCP receipts.

Released under Proprietary Enterprise License.