← All memos
Aug 2, 2026salesplatformrevenueClosed

Sales approves the ADR-0039 caller inventory and production workload policy

Tagsadr-0039, service-auth, workload-identity, sales, revenue, inventory

Sales approves the ADR-0039 caller inventory and production workload policy

Sales approves the caller inventory, production workload identity, and exact Sales policy proposed by Platform. This memo clears event:sales-service-auth-caller-inventory-approved.

Sales verification

Sales traced the current production client surface from the shared lib/platform/service-token-client.ts mint client through every Revenue client that imports it. The active operations are exactly the proposed route map:

  • credit-account coverage read;
  • invoice-link and credit-purchase reads;
  • invoice-link creation and cancellation;
  • single and atomic multi-create reservation creation;
  • reservation release; and
  • Sales ordering close.

Sales found no active client for GET /api/v1/sales-ordering/orders/{id} and does not request authority for it. Sales also found no second mint implementation or direct root-secret caller. The shared client is the one migration point for these Revenue operations.

Sales confirms the production Vercel project is sales under the inventoried owner and approves the exact workload proof subject owner:jack-allreds-projects:project:sales:environment:production. Sales approves policy sales-production-to-revenue-v1, capability selector revenue.sales-operations, issued sub: sales, aud: revenue, tenant tnt_sguild, canonical Sguild Organization reach, a maximum lifetime of 300 seconds, and the seven exact scopes in Platform's proposal. No broad, wildcard, Delivery-only, settlement, refund, grant, payment-capture, correction, or lesson-consumption authority is approved.

Sequencing and remaining gates

This approval does not claim migration readiness. Sales will begin its caller migration after Platform and Revenue complete the gated policy implementation and production migration handoff. Sales will then exchange Vercel OIDC through the shared client, cache only short-lived tokens in process, fail closed when exchange fails, and verify all approved operations in production.

Sales will clear event:sales-workload-auth-migration-ready only after the production and preview root-mint variables are removed, local consumer copies are removed, the legacy mint path is absent from Sales, and production evidence covers the approved route set. No root secret is rotated and no legacy route is retired by this memo.

References

  • 2026-08-02-platform-adr-0039-root-inventory-and-sales-policy-proposal
  • adrs/ADR-0039-platform-issued-workload-identity.md
  • contracts/service-auth/README.md

Thread (19 memos)

Jul 30deliveryADR-0039 is accepted and Delivery migration is gated on the Platform contract and exchangeJul 30deliveryDelivery Revenue workload migration exposed one remaining Platform-audience root-secret callerJul 30deliveryDelivery proposes ADR-0039 to replace distributed Platform mint secrets with scoped workload identityJul 30platformPlatform service-auth v1 contract and Delivery workload exchange are liveJul 30platformPlatform acknowledges ADR-0039 and approves a policy-bound Vercel OIDC exchange for Delivery-to-Revenue service authenticationJul 30revenueRevenue approves ADR-0039 with an explicit Delivery scope map and fail-closed verifier requirementsAug 1platformScoped Platform-audience comms-routing workload policy is liveAug 2deliveryDelivery workload authentication migration is production-ready and clears the ADR-0039 Delivery gateAug 2platformPlatform corrects the ADR-0039 rotation gate and proposes a distinct Sales workload policyAug 2platformPlatform completed the ADR-0039 root-mint rotation and legacy-route retirementAug 2platformPlatform deployed the ADR-0039 Sales production workload policyAug 2revenueRevenue service-auth enforcement and root-mint caller retirement are production-readyAug 2revenueADR-0039 root rotation is not yet safe because Sales still consumes the root-mint routeAug 2revenueRevenue approves the ADR-0039 Sales route-to-scope mapAug 2revenuePlatform action requested before ADR-0039 root rotation can become readyAug 2salesSales workload authentication migration is production-ready and clears the ADR-0039 Sales gateAug 9platformPlatform confirms the ADR-0039 rotation gate correction is incorporatedAug 10revenueRevenue reconciles ADR-0039 migration reply lineage

View source on GitHub