diff --git a/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json b/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json new file mode 100644 index 0000000..917e485 --- /dev/null +++ b/crates/cross-extension-smoke/tests/fixtures/activate-subscription.intent.json @@ -0,0 +1,158 @@ +{ + "manifest_version": "intent-codec-applet.v1", + "job_name": "Activate paid subscription", + "primary_job_key": "activate-subscription", + "status": "code-backed", + "source_schema": "../templates/intent-codec-applet.manifest.schema.json", + "human_readable": "activate-subscription.md", + "trigger": "subscription_activation_requested", + "current_workaround": "A billing or RevOps operator manually checks payment, plan, entitlements, and opening balance before enabling customer access.", + "source_evidence": { + "truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers activate-subscription.", + "feature": "bedrock-platform/helms/truths/jobs/activate_subscription.feature", + "executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_activate_subscription", + "tests": "execute_activate_subscription_projects_revenue_state and execute_activate_subscription_blocks_without_payment_confirmation", + "event": "crm-contracts maps SubscriptionActivationRequested to activate-subscription" + }, + "functional_need": { + "outcome": "Turn an agreed commercial plan into active subscription, entitlement, and auditable opening financial state.", + "inputs": [ + "organization_id", + "subscription_id", + "catalog_item_id", + "payment_confirmed" + ], + "output": "Completed truth session with subscription projection and entitlement IDs, or blocked truth session with approval/workflow references.", + "constraints": [ + "Subscription must belong to the organization.", + "Active subscription must resolve to a valid catalog plan.", + "Payment confirmation is required before activation.", + "Activation exceptions move through a workflow case and approval.", + "Entitlements and opening financial state must remain auditable." + ], + "success_signal": "The truth session completes, subscription_id is projected, entitlements are derived, and no approval is required." + }, + "emotional_need": { + "operator_anxiety": "The customer may have paid but still be locked out, or may receive access before payment and plan terms are trustworthy.", + "desired_confidence": "Payment, plan, subscription state, entitlement grant, and operator receipt agree before support or the customer sees a mismatch.", + "tolerance": "Prefer a blocked session and manual review over silent activation when payment or terms are uncertain." + }, + "relational_need": { + "dependent_parties": [ + "customer admin", + "billing operator", + "RevOps", + "support", + "finance", + "partner owner when marketplace or revenue-share terms apply" + ], + "trust_obligation": "Explain why access was granted or paused without treating provider IDs as commercial truth.", + "handoff_created": "If activation is blocked, Helm owns the operator-visible approval/workflow handoff." + }, + "failure_modes": [ + "Activating access before payment is confirmed.", + "Granting entitlements for the wrong organization or subscription.", + "Treating Stripe or provider object IDs as canonical entitlement truth.", + "Mutating commercial state without an auditable operator receipt.", + "Hiding activation exceptions inside app-local state." + ], + "authority": { + "requester": "subscription_activation_requested commerce/runtime envelope", + "approvers": [ + "Commerce Rails policy", + "billing operator for blocked activation" + ], + "allowed_actions": [ + "activate subscription", + "derive entitlements from catalog plan", + "open approval workflow", + "project subscription and entitlement state" + ], + "forbidden_actions": [ + "grant entitlement without payment confirmation", + "let the applet own provider reconciliation", + "store provider object ID as canonical entitlement", + "bypass Helm approval on blocked activation" + ], + "approval_points": [ + "payment_confirmed is absent or false", + "non-standard plan terms or manual review signal" + ], + "reversibility": "partially_reversible", + "expiry": "payment or activation event replay window", + "audit_visibility": [ + "operator", + "finance", + "support", + "partner owner" + ] + }, + "evidence_contract": { + "required_sources": [ + { + "source": "Commerce Rails verified subscription contract", + "freshness": "current at activation time", + "authority": "primary" + }, + { + "source": "Runtime or commerce payment confirmation envelope", + "freshness": "within replay window", + "authority": "primary" + }, + { + "source": "catalog plan definition", + "freshness": "current at activation time", + "authority": "primary" + }, + { + "source": "Helm approval record when activation blocks", + "freshness": "current workflow case", + "authority": "primary" + } + ], + "disallowed_sources": [ + "raw provider ID as entitlement truth", + "app-local boolean that bypasses commercial verification" + ], + "confidence_floor": "payment_confirmed must be true for automatic activation", + "conflict_policy": "stop", + "sensitive_fields": [ + "organization_id", + "subscription_id", + "catalog_item_id", + "payment reference or provider correlation IDs" + ] + }, + "runtime_needs": [ + "normalized commerce/runtime event ingress", + "secret handling for payment-provider verification outside the applet", + "telemetry for activation, blocked session, approval, and retry", + "durable workflow/approval references" + ], + "commercial_needs": [ + "subscription lifecycle state", + "catalog plan resolution", + "entitlement grant", + "opening ledger or balance context", + "provider reconciliation outside the applet" + ], + "projection": { + "operator_view": "subscription ID, plan/catalog item, activation state, entitlement IDs, approval IDs, workflow case IDs, stop reason", + "customer_or_partner_view": "access active or activation paused with support-safe reason" + }, + "non_goals": [ + "Build a billing dashboard inside the applet.", + "Let the applet own Stripe/provider verification.", + "Let the applet own entitlement or subscription canonical truth.", + "Add unrelated billing jobs such as top-up, upgrade, suspension, or reconciliation to this applet." + ], + "layer_mapping": { + "applet": "Minimal activation request/projection surface.", + "helm": "Operator approval, workflow case, blocked-session receipt, and trust-transfer view.", + "axiom": "activate-subscription Truth shape and candidate IntentPacket.", + "organism": "Future formation selection for non-standard activation review.", + "converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.", + "runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.", + "commerce_rails": "Subscription, catalog plan, entitlement, ledger/opening balance, and provider reconciliation authority." + } +} diff --git a/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json b/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json new file mode 100644 index 0000000..a90802f --- /dev/null +++ b/crates/cross-extension-smoke/tests/fixtures/refill-prepaid-ai-credits.intent.json @@ -0,0 +1,161 @@ +{ + "manifest_version": "intent-codec-applet.v1", + "job_name": "Refill prepaid AI credits", + "primary_job_key": "refill-prepaid-ai-credits", + "status": "code-backed", + "source_schema": "../templates/intent-codec-applet.manifest.schema.json", + "human_readable": "refill-prepaid-ai-credits.md", + "trigger": "prepaid_top_up_settled", + "current_workaround": "A billing operator manually confirms payment and updates prepaid usage balance.", + "source_evidence": { + "truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers refill-prepaid-ai-credits.", + "feature": "bedrock-platform/helms/truths/jobs/refill_prepaid_ai_credits.feature", + "executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_refill_prepaid_ai_credits", + "tests": "execute_refill_prepaid_ai_credits_updates_entitlement_balance and execute_refill_prepaid_ai_credits_blocks_pending_payment", + "event": "crm-contracts maps PrepaidTopUpSettled to refill-prepaid-ai-credits" + }, + "functional_need": { + "outcome": "Apply a settled top-up to prepaid AI credit balances with financial traceability.", + "inputs": [ + "organization_id", + "subscription_id", + "amount_minor", + "currency_code", + "payment_reference", + "payment_status" + ], + "output": "Ledger-backed credit grant and updated entitlement balance, or blocked review with approval/workflow references.", + "constraints": [ + "Top-up payment must be settled before credit grant.", + "Subscription must be active and belong to the organization.", + "Currency and amount must match the commercial event.", + "Ledger receipt must be durable before the operator projection declares success.", + "Risky top-ups move through Helm review instead of app-local mutation." + ], + "success_signal": "Confirmed top-up appears as a ledger-backed credit grant and entitlement balance increases for the correct account." + }, + "emotional_need": { + "operator_anxiety": "The customer may run out of AI credits after paying, or the system may grant spendable balance for a risky or unsettled payment.", + "desired_confidence": "Payment settlement, subscription, amount, currency, ledger entry, and entitlement balance agree before usage resumes.", + "tolerance": "Prefer a blocked review over balance mutation when payment state, amount, currency, or risk signals are unclear." + }, + "relational_need": { + "dependent_parties": [ + "customer admin", + "finance", + "support", + "runtime metering", + "billing operator", + "partner owner when marketplace settlement applies" + ], + "trust_obligation": "Explain why credits were granted or paused without turning provider reconciliation into applet-owned truth.", + "handoff_created": "If refill is blocked, Helm owns the operator-visible risk or payment review handoff." + }, + "failure_modes": [ + "Granting credits before payment is settled.", + "Increasing the wrong subscription balance.", + "Losing payment-to-ledger traceability.", + "Treating provider payment IDs as canonical credit state.", + "Hiding risk review inside app-local state." + ], + "authority": { + "requester": "prepaid_top_up_settled commerce/runtime envelope", + "approvers": [ + "Commerce Rails policy", + "billing operator for risky top-up" + ], + "allowed_actions": [ + "grant prepaid credit", + "append ledger entry", + "open approval workflow", + "project credit receipt" + ], + "forbidden_actions": [ + "grant credit for pending payment", + "let the applet own provider reconciliation", + "bypass risk review", + "mutate balance without ledger traceability" + ], + "approval_points": [ + "pending payment", + "unusual top-up size or risk signal" + ], + "reversibility": "partially_reversible", + "expiry": "payment event replay window", + "audit_visibility": [ + "operator", + "finance", + "support", + "partner owner" + ] + }, + "evidence_contract": { + "required_sources": [ + { + "source": "Commerce Rails verified top-up event", + "freshness": "within replay window", + "authority": "primary" + }, + { + "source": "active subscription commercial commitment", + "freshness": "current at top-up time", + "authority": "primary" + }, + { + "source": "ledger credit grant receipt", + "freshness": "created during truth execution", + "authority": "primary" + }, + { + "source": "Helm approval record when risk review blocks", + "freshness": "current workflow case", + "authority": "primary" + } + ], + "disallowed_sources": [ + "raw provider ID as balance truth", + "app-local credit counter without ledger receipt" + ], + "confidence_floor": "payment_status must be settled for automatic refill", + "conflict_policy": "stop", + "sensitive_fields": [ + "organization_id", + "subscription_id", + "amount_minor", + "currency_code", + "payment_reference" + ] + }, + "runtime_needs": [ + "normalized top-up event ingress", + "provider secret handling outside the applet", + "balance-change telemetry", + "durable ledger reference" + ], + "commercial_needs": [ + "payment settlement state", + "subscription commitment", + "credit entitlement balance", + "ledger credit grant", + "provider reconciliation outside the applet" + ], + "projection": { + "operator_view": "payment status, grant amount, subscription, credit entitlement, ledger entry, approval IDs, workflow case IDs, and stop reason", + "customer_or_partner_view": "credit balance updated or refill paused with support-safe reason" + }, + "non_goals": [ + "Build the usage metering engine.", + "Let the applet own provider verification.", + "Let the applet own canonical credit storage.", + "Mix subscription activation into this applet." + ], + "layer_mapping": { + "applet": "Minimal prepaid refill request/projection surface.", + "helm": "Payment/risk review, workflow case, blocked-session receipt, and trust-transfer view.", + "axiom": "refill-prepaid-ai-credits Truth shape and candidate IntentPacket.", + "organism": "Future formation selection for unusual top-up or fraud review.", + "converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.", + "runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.", + "commerce_rails": "Payment settlement, subscription commitment, credit entitlement, ledger grant, and provider reconciliation authority." + } +} diff --git a/crates/cross-extension-smoke/tests/intent_codec_applets.rs b/crates/cross-extension-smoke/tests/intent_codec_applets.rs index 8c858b5..51e3899 100644 --- a/crates/cross-extension-smoke/tests/intent_codec_applets.rs +++ b/crates/cross-extension-smoke/tests/intent_codec_applets.rs @@ -8,9 +8,12 @@ use arena_intent_cases::{AppletIntentCase, applet_cases}; use serde::Deserialize; +// Vendored from the root repo's KB/02-product/applets/ (that repo is private, +// so CI cannot reach it via a relative include). If the canonical manifests +// change, re-copy them here — divergence fails these codec checks loudly. const APPLET_MANIFESTS: &[&str] = &[ - include_str!("../../../../KB/02-product/applets/activate-subscription.intent.json"), - include_str!("../../../../KB/02-product/applets/refill-prepaid-ai-credits.intent.json"), + include_str!("fixtures/activate-subscription.intent.json"), + include_str!("fixtures/refill-prepaid-ai-credits.intent.json"), ]; #[derive(Debug, Deserialize)]