Runbook: Vendor Suspension & Enforcement Procedure
1. Classification of Infractions & Trigger Thresholds
| Severity Tier | Trigger Conditions | Immediate Action | Authority Required |
|---|---|---|---|
| Tier 1: Regulatory / Fraud Emergency | Confirmed wire fraud, counterfeit electronics, stolen card ring, narcotics/weapons listing. | Instant Zero-Notice Account Freeze & Escrow Quarantine. | Trust & Safety Officer / Automated Guard |
| Tier 2: Strike Accumulation | Vendor accumulates 3 strikes within a rolling 90-day window. | Standard Account Suspension & Product Delisting. | Moderation Case Arbiter |
| Tier 3: Operational Failure | Order cancellation rate $> 25%$ or dispute loss rate $> 15%$ over 30 days. | 14-Day Probationary Listing Pause. | Merchant Operations Lead |
2. Emergency Account Freezing Protocol
When an emergency suspension is authorized, the on-call Trust & Safety engineer or automated guard executes a 5-step containment procedure:
mermaid
sequenceDiagram
autonumber
actor Officer as Trust & Safety Officer
participant API as VendorService
participant DB as Postgres Security Definer
participant Redis as Redis Edge Cache
participant Auth as Supabase Auth Engine
Officer->>API: 1. suspendVendor(vendorId, reason, severity)
API->>DB: 2. UPDATE vendor_profiles SET status='suspended'
API->>DB: 3. UPDATE products SET status='inactive' WHERE vendor_id=X
API->>Redis: 4. Invalidate vendor search indexes & campus feeds
API->>DB: 5. Quarantine pending payout batches in ReviewedPayoutBatch
API->>Auth: 6. Invalidate active JWTs & refresh tokens
API-->>Officer: 7. Confirmation receipt & audit loggedStep 1: Delist Active Products & Invalidate Cache
Deactivate all active listings and immediately flush edge cache so products vanish from storefront search:
sql
BEGIN;
-- Deactivate vendor profile
UPDATE public.vendor_profiles
SET status = 'suspended',
suspension_reason = '<SUSPENSION_REASON>',
suspended_at = now()
WHERE id = '<VENDOR_ID>';
-- Delist active catalog items
UPDATE public.products
SET status = 'inactive', updated_at = now()
WHERE vendor_id = '<VENDOR_ID>' AND status = 'active';
COMMIT;Flush edge search cache via backend CLI:
bash
fly ssh console -C "npm run cache:invalidate -- --vendor <VENDOR_ID>"Step 2: Quarantine Pending Escrow Balances
To protect buyers and ensure funds are available for potential chargebacks, freeze all outbound withdrawals:
sql
UPDATE public.payout_requests
SET status = 'quarantined',
transfer_failure = 'Account suspended for policy violation; funds held for 90-day chargeback buffer'
WHERE vendor_id = '<VENDOR_ID>' AND status IN ('pending', 'processing');Step 3: Revoke Authentication & Terminate Active Sessions
Terminate active sessions across web and mobile surfaces by revoking Supabase Auth tokens:
sql
-- Force token refresh invalidation in Supabase Auth
UPDATE auth.users
SET raw_app_meta_data = raw_app_meta_data || '{"suspended": true}'::jsonb
WHERE id = '<VENDOR_USER_ID>';3. In-Flight Order Management & Buyer Protection
When a vendor is suspended, existing orders must be handled according to their fulfillment state:
State A: Orders Placed but Not Yet Shipped (status = 'Processing')
- The vendor cannot be trusted to fulfill new orders.
- Automated Cancellation: Orders are automatically cancelled.
- Full Restitution: 100% of escrow funds are immediately refunded to buyer in-app wallets via
ReviewedWalletRefundService.
State B: Orders In Transit (status = 'Shipped')
- Goods have already left the vendor's physical custody and may be at a campus hub or with a student courier.
- Allow Delivery to Proceed: The buyer retains the right to inspect the goods and provide their Delivery PIN.
- Quarantined Credit: If the PIN is verified, the net funds unlock into the vendor's quarantined balance (ineligible for withdrawal until the suspension is resolved or 90 days have elapsed).
4. Vendor Appeal Protocol (ModerationAppealService.ts)
Under Debelu's merchant governance charter, suspended vendors maintain a statutory right to appeal:
mermaid
stateDiagram-v2
[*] --> Suspended : Account Frozen
Suspended --> AppealLodged : Vendor submits appeal within 14 days
Suspended --> Deplatformed : 14 days elapse without appeal
AppealLodged --> UnderReview : Independent Review Board assigned
UnderReview --> Reinstated : Appeal Upheld (Mistake / Evidence Verified)
UnderReview --> Deplatformed : Appeal Rejected (Violation Confirmed)
Reinstated --> [*] : Listings Restored & 30-Day Probation
Deplatformed --> [*] : Permanent Blacklist & Fund SettlementAppeal Review Rules
- 14-Day Filing Window: Vendor must lodge formal appeal within 14 calendar days via the support portal.
- Acceptable Evidence: Legitimate tax invoices from authorized distributors, verifiable waybill receipts, or physical proof of delivery.
- Independent Review Board: The appeal must be evaluated by two staff members who had zero involvement in the original suspension decision.
5. Permanent Deplatforming & Legal Protocol
If an appeal is rejected or severe criminal wire fraud is confirmed:
- Permanent Blacklisting:
- Add the vendor's NUBAN bank account number, phone number, and hashed BVN to
public.blacklisted_identities. - Any future attempt to register on Debelu using these credentials is blocked automatically.
- Add the vendor's NUBAN bank account number, phone number, and hashed BVN to
- Escrow Liquidation & Chargeback Reserve:
- Quarantined funds are retained for 90 calendar days from the last order date to absorb lagging commercial bank chargebacks and return claims.
- After 90 days, any residual funds minus verified customer losses and administrative penalty fees are disbursed to the vendor's original bank account.
- Law Enforcement Escalation:
- For confirmed criminal operations ($> ₦200,000$ in defrauded student funds), the Legal Compliance Officer compiles a digital evidence dossier and submits a formal referral to the Nigerian Police Special Fraud Unit (PSFU) and NFIU.