Skip to content
This repository was archived by the owner on Aug 7, 2026. It is now read-only.
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,158 @@
{
"manifest_version": "intent-codec-applet.v1",
"job_name": "Activate paid subscription",
"primary_job_key": "activate-subscription",
"status": "code-backed",
"source_schema": "../templates/intent-codec-applet.manifest.schema.json",
"human_readable": "activate-subscription.md",
"trigger": "subscription_activation_requested",
"current_workaround": "A billing or RevOps operator manually checks payment, plan, entitlements, and opening balance before enabling customer access.",
"source_evidence": {
"truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers activate-subscription.",
"feature": "bedrock-platform/helms/truths/jobs/activate_subscription.feature",
"executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_activate_subscription",
"tests": "execute_activate_subscription_projects_revenue_state and execute_activate_subscription_blocks_without_payment_confirmation",
"event": "crm-contracts maps SubscriptionActivationRequested to activate-subscription"
},
"functional_need": {
"outcome": "Turn an agreed commercial plan into active subscription, entitlement, and auditable opening financial state.",
"inputs": [
"organization_id",
"subscription_id",
"catalog_item_id",
"payment_confirmed"
],
"output": "Completed truth session with subscription projection and entitlement IDs, or blocked truth session with approval/workflow references.",
"constraints": [
"Subscription must belong to the organization.",
"Active subscription must resolve to a valid catalog plan.",
"Payment confirmation is required before activation.",
"Activation exceptions move through a workflow case and approval.",
"Entitlements and opening financial state must remain auditable."
],
"success_signal": "The truth session completes, subscription_id is projected, entitlements are derived, and no approval is required."
},
"emotional_need": {
"operator_anxiety": "The customer may have paid but still be locked out, or may receive access before payment and plan terms are trustworthy.",
"desired_confidence": "Payment, plan, subscription state, entitlement grant, and operator receipt agree before support or the customer sees a mismatch.",
"tolerance": "Prefer a blocked session and manual review over silent activation when payment or terms are uncertain."
},
"relational_need": {
"dependent_parties": [
"customer admin",
"billing operator",
"RevOps",
"support",
"finance",
"partner owner when marketplace or revenue-share terms apply"
],
"trust_obligation": "Explain why access was granted or paused without treating provider IDs as commercial truth.",
"handoff_created": "If activation is blocked, Helm owns the operator-visible approval/workflow handoff."
},
"failure_modes": [
"Activating access before payment is confirmed.",
"Granting entitlements for the wrong organization or subscription.",
"Treating Stripe or provider object IDs as canonical entitlement truth.",
"Mutating commercial state without an auditable operator receipt.",
"Hiding activation exceptions inside app-local state."
],
"authority": {
"requester": "subscription_activation_requested commerce/runtime envelope",
"approvers": [
"Commerce Rails policy",
"billing operator for blocked activation"
],
"allowed_actions": [
"activate subscription",
"derive entitlements from catalog plan",
"open approval workflow",
"project subscription and entitlement state"
],
"forbidden_actions": [
"grant entitlement without payment confirmation",
"let the applet own provider reconciliation",
"store provider object ID as canonical entitlement",
"bypass Helm approval on blocked activation"
],
"approval_points": [
"payment_confirmed is absent or false",
"non-standard plan terms or manual review signal"
],
"reversibility": "partially_reversible",
"expiry": "payment or activation event replay window",
"audit_visibility": [
"operator",
"finance",
"support",
"partner owner"
]
},
"evidence_contract": {
"required_sources": [
{
"source": "Commerce Rails verified subscription contract",
"freshness": "current at activation time",
"authority": "primary"
},
{
"source": "Runtime or commerce payment confirmation envelope",
"freshness": "within replay window",
"authority": "primary"
},
{
"source": "catalog plan definition",
"freshness": "current at activation time",
"authority": "primary"
},
{
"source": "Helm approval record when activation blocks",
"freshness": "current workflow case",
"authority": "primary"
}
],
"disallowed_sources": [
"raw provider ID as entitlement truth",
"app-local boolean that bypasses commercial verification"
],
"confidence_floor": "payment_confirmed must be true for automatic activation",
"conflict_policy": "stop",
"sensitive_fields": [
"organization_id",
"subscription_id",
"catalog_item_id",
"payment reference or provider correlation IDs"
]
},
"runtime_needs": [
"normalized commerce/runtime event ingress",
"secret handling for payment-provider verification outside the applet",
"telemetry for activation, blocked session, approval, and retry",
"durable workflow/approval references"
],
"commercial_needs": [
"subscription lifecycle state",
"catalog plan resolution",
"entitlement grant",
"opening ledger or balance context",
"provider reconciliation outside the applet"
],
"projection": {
"operator_view": "subscription ID, plan/catalog item, activation state, entitlement IDs, approval IDs, workflow case IDs, stop reason",
"customer_or_partner_view": "access active or activation paused with support-safe reason"
},
"non_goals": [
"Build a billing dashboard inside the applet.",
"Let the applet own Stripe/provider verification.",
"Let the applet own entitlement or subscription canonical truth.",
"Add unrelated billing jobs such as top-up, upgrade, suspension, or reconciliation to this applet."
],
"layer_mapping": {
"applet": "Minimal activation request/projection surface.",
"helm": "Operator approval, workflow case, blocked-session receipt, and trust-transfer view.",
"axiom": "activate-subscription Truth shape and candidate IntentPacket.",
"organism": "Future formation selection for non-standard activation review.",
"converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.",
"runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.",
"commerce_rails": "Subscription, catalog plan, entitlement, ledger/opening balance, and provider reconciliation authority."
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,161 @@
{
"manifest_version": "intent-codec-applet.v1",
"job_name": "Refill prepaid AI credits",
"primary_job_key": "refill-prepaid-ai-credits",
"status": "code-backed",
"source_schema": "../templates/intent-codec-applet.manifest.schema.json",
"human_readable": "refill-prepaid-ai-credits.md",
"trigger": "prepaid_top_up_settled",
"current_workaround": "A billing operator manually confirms payment and updates prepaid usage balance.",
"source_evidence": {
"truth_catalog": "bedrock-platform/helms/crates/truth-catalog/src/lib.rs registers refill-prepaid-ai-credits.",
"feature": "bedrock-platform/helms/truths/jobs/refill_prepaid_ai_credits.feature",
"executable": "bedrock-platform/helms/crates/workbench-backend/src/lib.rs execute_refill_prepaid_ai_credits",
"tests": "execute_refill_prepaid_ai_credits_updates_entitlement_balance and execute_refill_prepaid_ai_credits_blocks_pending_payment",
"event": "crm-contracts maps PrepaidTopUpSettled to refill-prepaid-ai-credits"
},
"functional_need": {
"outcome": "Apply a settled top-up to prepaid AI credit balances with financial traceability.",
"inputs": [
"organization_id",
"subscription_id",
"amount_minor",
"currency_code",
"payment_reference",
"payment_status"
],
"output": "Ledger-backed credit grant and updated entitlement balance, or blocked review with approval/workflow references.",
"constraints": [
"Top-up payment must be settled before credit grant.",
"Subscription must be active and belong to the organization.",
"Currency and amount must match the commercial event.",
"Ledger receipt must be durable before the operator projection declares success.",
"Risky top-ups move through Helm review instead of app-local mutation."
],
"success_signal": "Confirmed top-up appears as a ledger-backed credit grant and entitlement balance increases for the correct account."
},
"emotional_need": {
"operator_anxiety": "The customer may run out of AI credits after paying, or the system may grant spendable balance for a risky or unsettled payment.",
"desired_confidence": "Payment settlement, subscription, amount, currency, ledger entry, and entitlement balance agree before usage resumes.",
"tolerance": "Prefer a blocked review over balance mutation when payment state, amount, currency, or risk signals are unclear."
},
"relational_need": {
"dependent_parties": [
"customer admin",
"finance",
"support",
"runtime metering",
"billing operator",
"partner owner when marketplace settlement applies"
],
"trust_obligation": "Explain why credits were granted or paused without turning provider reconciliation into applet-owned truth.",
"handoff_created": "If refill is blocked, Helm owns the operator-visible risk or payment review handoff."
},
"failure_modes": [
"Granting credits before payment is settled.",
"Increasing the wrong subscription balance.",
"Losing payment-to-ledger traceability.",
"Treating provider payment IDs as canonical credit state.",
"Hiding risk review inside app-local state."
],
"authority": {
"requester": "prepaid_top_up_settled commerce/runtime envelope",
"approvers": [
"Commerce Rails policy",
"billing operator for risky top-up"
],
"allowed_actions": [
"grant prepaid credit",
"append ledger entry",
"open approval workflow",
"project credit receipt"
],
"forbidden_actions": [
"grant credit for pending payment",
"let the applet own provider reconciliation",
"bypass risk review",
"mutate balance without ledger traceability"
],
"approval_points": [
"pending payment",
"unusual top-up size or risk signal"
],
"reversibility": "partially_reversible",
"expiry": "payment event replay window",
"audit_visibility": [
"operator",
"finance",
"support",
"partner owner"
]
},
"evidence_contract": {
"required_sources": [
{
"source": "Commerce Rails verified top-up event",
"freshness": "within replay window",
"authority": "primary"
},
{
"source": "active subscription commercial commitment",
"freshness": "current at top-up time",
"authority": "primary"
},
{
"source": "ledger credit grant receipt",
"freshness": "created during truth execution",
"authority": "primary"
},
{
"source": "Helm approval record when risk review blocks",
"freshness": "current workflow case",
"authority": "primary"
}
],
"disallowed_sources": [
"raw provider ID as balance truth",
"app-local credit counter without ledger receipt"
],
"confidence_floor": "payment_status must be settled for automatic refill",
"conflict_policy": "stop",
"sensitive_fields": [
"organization_id",
"subscription_id",
"amount_minor",
"currency_code",
"payment_reference"
]
},
"runtime_needs": [
"normalized top-up event ingress",
"provider secret handling outside the applet",
"balance-change telemetry",
"durable ledger reference"
],
"commercial_needs": [
"payment settlement state",
"subscription commitment",
"credit entitlement balance",
"ledger credit grant",
"provider reconciliation outside the applet"
],
"projection": {
"operator_view": "payment status, grant amount, subscription, credit entitlement, ledger entry, approval IDs, workflow case IDs, and stop reason",
"customer_or_partner_view": "credit balance updated or refill paused with support-safe reason"
},
"non_goals": [
"Build the usage metering engine.",
"Let the applet own provider verification.",
"Let the applet own canonical credit storage.",
"Mix subscription activation into this applet."
],
"layer_mapping": {
"applet": "Minimal prepaid refill request/projection surface.",
"helm": "Payment/risk review, workflow case, blocked-session receipt, and trust-transfer view.",
"axiom": "refill-prepaid-ai-credits Truth shape and candidate IntentPacket.",
"organism": "Future formation selection for unusual top-up or fraud review.",
"converge": "Admission, criteria outcomes, completed or blocked truth session, and stop reason.",
"runtime_runway": "Event ingress, auth, secrets, telemetry, and durable runtime envelope.",
"commerce_rails": "Payment settlement, subscription commitment, credit entitlement, ledger grant, and provider reconciliation authority."
}
}
7 changes: 5 additions & 2 deletions crates/cross-extension-smoke/tests/intent_codec_applets.rs
Original file line number Diff line number Diff line change
Expand Up @@ -8,9 +8,12 @@
use arena_intent_cases::{AppletIntentCase, applet_cases};
use serde::Deserialize;

// Vendored from the root repo's KB/02-product/applets/ (that repo is private,
// so CI cannot reach it via a relative include). If the canonical manifests
// change, re-copy them here — divergence fails these codec checks loudly.
const APPLET_MANIFESTS: &[&str] = &[
include_str!("../../../../KB/02-product/applets/activate-subscription.intent.json"),
include_str!("../../../../KB/02-product/applets/refill-prepaid-ai-credits.intent.json"),
include_str!("fixtures/activate-subscription.intent.json"),
include_str!("fixtures/refill-prepaid-ai-credits.intent.json"),
];

#[derive(Debug, Deserialize)]
Expand Down
Loading