Pre-launch. Not deployable to production. This page states what the tests prove and what is missing — nothing else.

JTBD-CO-06 · Commercial Operations / CPQ

Verify signing via verified provider events

partially supported. Part of the job works and is proved; the rest is named rather than implied. Read what is excluded before planning around it.

What the catalogue records

provider events are verified as the raw signed bytes before any state changes (constant-time HMAC + replay window in the fixture), replay is idempotent by DB-unique provider event id, out-of-order and post-terminal events are recorded and ignored, unknown envelopes are quarantined, and completion produces signed-artifact evidence (hashes, provider reference, signer evidence). Replay scope is provider + event id + payload fingerprint, a reused id with different bytes is refused, and a delivery whose processing failed is resumed rather than stranded. The fixture verification key is test-only: production webhook security, secret management and legally qualified signature assurance are NOT supported, artifactHash is provider-reported, and no artifact byte is downloaded, hashed or cryptographically verified

Evidence

This row carries no test path of its own in the structured index. The matrix records the evidence for it in a block shared with neighbouring rows, which jobs.json does not split per row — so read docs/benchmarks/CRM_JTBD_MATRIX.md for it. The status above was set from that evidence, not from its absence.

What this status does not mean

A status here describes this repository at this commit, nothing more. It is not a statement about what a CRM should do, and it is not a roadmap commitment. The whole framework is local-development-only: there is no authentication, tenancy or RBAC, so no status on this page implies you can deploy it. The boundaries are listed in full on the claims ledger.

Other jobs in Commercial Operations / CPQ

All 7 jobs in Commercial Operations / CPQ · the whole catalogue