Skip to content

Command center migration receipt — 7 October 2026 ​

Target: Debelu Supabase project havugmqmyplqgbrlthhs. The user renewed standing authorization to apply migrations through MCP.

Applied successfully with Supabase MCP, and confirmed in migration history:

FileHosted history version
20261011002200_atomic_return_case_governance.sql20261007065328
20261011002300_granular_command_capabilities.sql20261007065339
20261011002500_subject_privacy_export_delivery.sql20261007065344
20261011002600_guard_internal_wallet_refund_snapshot.sql20261007065346
20261011002700_staff_invitation_delivery_outbox.sql20261007065717
20261011002800_vendor_kyc_governance.sql20261007070519
20261011002900_vendor_kyc_onboarding_control_guard.sql20261007072902
20261011003000_governed_whatsapp_replies.sql20261007082935
20261011003100_governed_vendor_sanctions.sql20261007081924
20261011003200_close_vendor_strike_truncate_boundary.sql20261007085423

Migration 024 was already recorded and was not replayed. MCP assigns hosted timestamps and descriptive names; the table maps hosted versions to the checked-in filenames. The hosted name for 030 is governed_whatsapp_replies.

Readback through Supabase MCP on 7 October 2026 confirmed all ten records above. Migration 030 was applied after independent review of its messaging-pause, definitive-rejection, and command-table permission fixes. Its browser RPC execution grants are disabled and the necessary service-role RPC execution grants are enabled. Migration 031 was applied before 030 because it is independent. Backend, admin and storefront were deployed and verified against application commit 1a89a969. Database application alone does not verify a provider delivery.

Local checks passed: 14 atomic return checks, 12 subject-export checks, 36 staff-access/invitation checks, and 14 vendor-identity checks. Production readback confirmed the restrictive identity-document read/update/delete policies. Application deployment and actual invitation delivery are separate steps; this receipt does not certify provider delivery. No live email, WhatsApp message, or sanction was issued.

Migration 029 also passed five local SQL checks covering paused, null, and missing controls, rejection during a pause, and approval after restoration. The migration serializes seller enrollment against the settings row used by the onboarding circuit breaker. The verified application revision and release checks are recorded below.

Invitation delivery stays disabled until its Edge Function and matching encryption/worker secrets and SES sender are configured. See the release runbook in docs/operations/command-center-release-runbook.md.

The deliver-staff-invitation Edge Function was deployed through Supabase MCP as active version 1 with JWT verification enabled. An unauthenticated POST returned HTTP 401. Sending secrets and backend worker enablement were not changed, and no invitation was sent.

Railway backend deployment d37bad72-40c3-4d54-9be6-599ff4a4ce03 succeeded after a fresh source build recovered a provider snapshot-fetch failure. The service settings were identical before and after recovery. Production health reported full commit 1a89a969437fe92f6987c3b3070c7c363d053162 and /health/ready returned HTTP 200 with ready; Redis and Supabase checks passed. Overall health still classifies Paystack as unverified; this is not payment delivery evidence.

Application release verification completed successfully:

  • Monorepo CI 37620321609: database replay/concurrency, production dependency audit, typechecks, lint, full tests, every application build, React runtime consistency and accessibility/route smoke tests passed.
  • Production release 37620321690: test gate, storefront/admin builds, both Cloudflare production deployments and post-deployment checks passed.
  • admin.debelu.com and app.debelu.com returned HTTP 200. Their delivered JavaScript embeds the full application SHA 1a89a969437fe92f6987c3b3070c7c363d053162.
  • Production protected KYC, sanctions and WhatsApp API requests without authentication returned HTTP 401. This is an unauthorized-access smoke check, not a live privileged decision or provider-send test.

WhatsApp verification passed: 17 SQL behavior checks, 17 backend tests, 7 admin workflow tests, and backend/admin typechecks. Coverage includes inherited service-role mutation/truncate grants, the authoritative messaging-breaker row, paused queue preservation, fenced provider attempts, definitive rejection recovery, and uncertain receipt reconciliation. Native full-schema replay and the exact release SHA must still pass the release gates before deployment.

Migration 032 closes the vendor-strike truncate boundary. Supabase MCP applied its hosted record as 20261007085423, named close_vendor_strike_truncate_boundary. Hosted readback confirmed can_truncate=false for anon, authenticated, and service_role. All 12 SQL vendor-sanction checks passed. The native return concurrency fixture was also corrected to use canonical refund_status='requested' rather than the invalid pending value; this preserves the intended race test. Exact-release CI and application deployment passed as recorded above.

Released under Proprietary Enterprise License.