Sales approves the ADR-0039 caller inventory and production workload policy
Sales approves the caller inventory, production workload identity, and exact
Sales policy proposed by Platform. This memo clears
event:sales-service-auth-caller-inventory-approved.
Sales verification
Sales traced the current production client surface from the shared
lib/platform/service-token-client.ts mint client through every Revenue client
that imports it. The active operations are exactly the proposed route map:
- credit-account coverage read;
- invoice-link and credit-purchase reads;
- invoice-link creation and cancellation;
- single and atomic multi-create reservation creation;
- reservation release; and
- Sales ordering close.
Sales found no active client for
GET /api/v1/sales-ordering/orders/{id} and does not request authority for it.
Sales also found no second mint implementation or direct root-secret caller.
The shared client is the one migration point for these Revenue operations.
Sales confirms the production Vercel project is sales under the inventoried
owner and approves the exact workload proof subject
owner:jack-allreds-projects:project:sales:environment:production. Sales
approves policy sales-production-to-revenue-v1, capability selector
revenue.sales-operations, issued sub: sales, aud: revenue, tenant
tnt_sguild, canonical Sguild Organization reach, a maximum lifetime of 300
seconds, and the seven exact scopes in Platform's proposal. No broad, wildcard,
Delivery-only, settlement, refund, grant, payment-capture, correction, or
lesson-consumption authority is approved.
Sequencing and remaining gates
This approval does not claim migration readiness. Sales will begin its caller migration after Platform and Revenue complete the gated policy implementation and production migration handoff. Sales will then exchange Vercel OIDC through the shared client, cache only short-lived tokens in process, fail closed when exchange fails, and verify all approved operations in production.
Sales will clear event:sales-workload-auth-migration-ready only after the
production and preview root-mint variables are removed, local consumer copies
are removed, the legacy mint path is absent from Sales, and production evidence
covers the approved route set. No root secret is rotated and no legacy route is
retired by this memo.
References
2026-08-02-platform-adr-0039-root-inventory-and-sales-policy-proposaladrs/ADR-0039-platform-issued-workload-identity.mdcontracts/service-auth/README.md