Skip to content

Refund exception investigations ​

Migration 037 adds a finance investigation register. It never issues an external refund, credits a wallet or repairs a settled-order balance. Existing reviewed wallet refund execution remains the separate financial command.

Current global canApproveRefunds staff with verified AAL2 can open a case for an order, claim/release ownership and propose a documented disposition. Finance observation staff can read cases with current global canViewFinanceReports authority and AAL2. Buyer/vendor beneficiaries cannot own or decide their own investigation. Immutable opening evidence and command receipts retain reasons, actors and revisions; every accepted command records an audit event.

A current global finance investigator may take over only when the existing owner has lost refund authority. The command requires the exact owner, current case revision and reason, and records an immutable audited handover. Active owners cannot be displaced. A pending proposal must first be independently rejected; handover preserves evidence and disposition receipts and changes no money.

Disposition approval requires a different authorized reviewer, unexpired proposal and unchanged order/ledger fingerprint. Rejection remains available if financial evidence changed or the proposer lost access, so stale work can be reconsidered. blocked and investigating retain unresolved work and do not certify a refund. resolved_wallet_receipt requires an executed reviewed wallet refund command, matching canonical REFUND-<order> completed ledger, full order refund projection and no other refund credit for that order. Resolution records that receipt and does not move money. Provider refund delivery remains unverified.

The finance refund workspace exposes the investigation register, exact case evidence, independent review and recent immutable command receipts. Network uncertainty retains the command ID and frozen input for exact replay. A definitive conflict clears the decision and requires reinspection. Never issue another command to work around an unknown outcome or change financial rows directly.

Endpoints mounted under /api/admin/refund-exceptions: GET /, GET /:id, POST /commands. Commands are open, claim, release, takeover, propose, review. Case states are investigating, pending_review, blocked, resolved_wallet_receipt. The API forwards authenticated actor and AAL2 into guarded SQL; no browser RPC execution or direct table mutation is granted.

Verification: scripts/db-refund-exception-checks.mjs exercises exact replay, authority/MFA, ownership, stale evidence, independent review, canonical receipt resolution and regranted mutation/truncate boundaries. The full-schema local runner scripts/db-native-refund-exception-checks.mjs executes supabase/tests/support/native_refund_exception_fixtures.sql with commerce and identity triggers enabled. These are disposable checks; no production refund or provider request is made. Run the native fixture in the release database gate before applying the migration through MCP.

Released under Proprietary Enterprise License.