# Validation Report: URS-031

**Title:** Record all transactions with timestamps and user IDs
**Date:** 2026-09-29T02:30:47.546Z
**Duration:** 107.3s
**Overall Status:** ✅ PASS

## User Requirement

> The system shall record all transactions (orders, edits, returns) with timestamps and user IDs.

*Source: `User_Requirement_Specifications_Vantis_DeviceFlow.xlsx` — the run below proves the system meets this requirement.*

## Environment

- **Inbox URL:** http://localhost:37077
- **Database:** localhost:37139/cc_repinbox_dev

## Setup

Status: ✅ PASS

## Test Steps

Each step below corresponds to one Playwright test that ran sequentially. Screenshots and video recordings provide visual evidence of the UI behaviour.

### 1. Step 1: Logged in as Blair Bennett — ✅ PASS

**What this step proves:**

Authenticates as Blair Bennett (Corveta sales rep), establishing the user identity that will be recorded against subsequent transactions.

**Audit events generated by this step:**

*(Evidence matched by declared name — step timing not available or no events fell in window)*

| Time | Type | Action | User | Org | Performed |
|------|------|--------|------|-----|-----------|
| 2026-09-29 02:30:53Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:30:57Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:31:34Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:06Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:14Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:21Z | user_log | user:login | mark.manufacturer@vantismedical.com | Vantis | — |

**Screenshots:**

![step 01 logged in](screenshots/step-01-logged-in.png)

**Video recording:**

[▶ Watch step recording](videos/step-01-login-bob.webm)

---

### 2. Step 2: First order — ✅ PASS

**What this step proves:**

Submits the first bill-only order as Blair Bennett. The system records the order in billing_orders with created_by_user_id and a server-side created_at timestamp.

**Audit events generated by this step:**

*(Evidence scoped to step execution window: 2026-09-29T02:31:07.969Z → 2026-09-29T02:31:30.392Z)*

| Time | Type | Action | User | Org | Performed |
|------|------|--------|------|-----|-----------|
| 2026-09-29 02:31:09Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:31:27Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:31:27Z | decision | bill_only.link_purchase_order | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:31:27Z | decision | basicErp.deriveSalesOrder | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:31:27Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | yes |
| 2026-09-29 02:31:27Z | decision | bill_only_order.direct_po_import_on_create | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:31:27Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:31:27Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:31:27Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:31:29Z | decision | bill_only.notifications.cc_incident_recipients | — | Vantis | no |
| 2026-09-29 02:31:29Z | transactional_email | new_bill_only | — | Corveta Surgical Group | — |

**Emails triggered by this step:**

*(Evidence matched by declared name — step timing not available or no events fell in window)*

**Email 1: New Bill-Only Order - 9/29/2026 - Vantis BO-1**

Template: `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1`

![New Bill-Only Order - 9/29/2026 - Vantis BO-1](screenshots/emails/2026-09-29T02-31-29-846Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1.png)

**Email 2: New Bill-Only Order - 9/29/2026 - Vantis BO-2**

Template: `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2`

![New Bill-Only Order - 9/29/2026 - Vantis BO-2](screenshots/emails/2026-09-29T02-32-03-122Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2.png)

**Screenshots:**

![step 02 account selected](screenshots/step-02-account-selected.png)

![step 02 devices selected](screenshots/step-02-devices-selected.png)

![step 02 documents](screenshots/step-02-documents.png)

![step 02 review](screenshots/step-02-review.png)

![step 02 order submitted](screenshots/step-02-order-submitted.png)

**Video recording:**

[▶ Watch step recording](videos/step-02-first-order.webm)

---

### 3. Step 3: Second order — ✅ PASS

**What this step proves:**

Submits a second bill-only order, demonstrating that each transaction is recorded independently with its own user ID and a distinct timestamp.

**Audit events generated by this step:**

*(Evidence matched by declared name — step timing not available or no events fell in window)*

| Time | Type | Action | User | Org | Performed |
|------|------|--------|------|-----|-----------|
| 2026-09-29 02:31:27Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | yes |
| 2026-09-29 02:31:27Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:32:01Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | yes |
| 2026-09-29 02:32:01Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | — |

**Emails triggered by this step:**

*(Evidence matched by declared name — step timing not available or no events fell in window)*

**Email 1: New Bill-Only Order - 9/29/2026 - Vantis BO-1**

Template: `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1`

![New Bill-Only Order - 9/29/2026 - Vantis BO-1](screenshots/emails/2026-09-29T02-31-29-846Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1.png)

**Email 2: New Bill-Only Order - 9/29/2026 - Vantis BO-2**

Template: `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2`

![New Bill-Only Order - 9/29/2026 - Vantis BO-2](screenshots/emails/2026-09-29T02-32-03-122Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2.png)

**Screenshots:**

![step 03 second order submitted](screenshots/step-03-second-order-submitted.png)

**Video recording:**

[▶ Watch step recording](videos/step-03-second-order.webm)

---

### 4. Step 4: Billing list with recorded transactions — ✅ PASS

**What this step proves:**

Views the billing list as Blair, confirming that the Submitter and Created columns expose the recorded user and timestamp for each transaction in the UI.

**Screenshots:**

![step 04 billing list](screenshots/step-04-billing-list.png)

**Video recording:**

[▶ Watch step recording](videos/step-04-billing-list.webm)

---

### 5. Step 5: Returns list — ✅ PASS

**What this step proves:**

Views the returns list, confirming that the Created By and Created columns expose user and timestamp attribution for return transactions.

**Screenshots:**

![step 05 returns list](screenshots/step-05-returns-list.png)

**Video recording:**

[▶ Watch step recording](videos/step-05-returns-list.webm)

---

### 6. Step 6a: Cross-user billing view — ✅ PASS

**What this step proves:**

Logs in as Mark Manufacturer to verify that Blair's order transactions are visible to a different authorized user with the original user attribution intact.

**Audit events generated by this step:**

*(Evidence matched by declared name — step timing not available or no events fell in window)*

| Time | Type | Action | User | Org | Performed |
|------|------|--------|------|-----|-----------|
| 2026-09-29 02:30:53Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:30:57Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:31:34Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:06Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:14Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:32:21Z | user_log | user:login | mark.manufacturer@vantismedical.com | Vantis | — |

**Screenshots:**

![step 06 cross user billing](screenshots/step-06-cross-user-billing.png)

**Video recording:**

[▶ Watch step recording](videos/step-06-cross-user.webm)

---

### 7. Step 6b: Cross-user returns view — ✅ PASS

**What this step proves:**

As Mark Manufacturer, verifies that return transactions are also visible cross-user with Created By and Created columns showing the original submitter.

**Screenshots:**

![step 06 cross user returns](screenshots/step-06-cross-user-returns.png)

---

### 8. Step 7: Combined transaction log — ✅ PASS

**What this step proves:**

Renders a live query from billing_orders, inventory_transactions, audit_events, and returns tables, proving every recorded transaction has a user and timestamp.

**Screenshots:**

![step 07 transaction log](screenshots/step-07-transaction-log.png)

**Video recording:**

[▶ Watch step recording](videos/step-07-transaction-log.webm)

---

## Database Validations

The following SQL queries ran against the application database after the Playwright scenarios completed. Each query asserts a specific condition that proves the feature under test persisted its data correctly.

### Bill-only orders recorded with user ID + timestamp — ✅ PASS

**Assertion:** At least two billing_orders created by Blair in the test window, each with created_by_user_id and created_at populated

```sql

      SELECT id, order_number, status, created_by_user_id, created_at
        FROM billing_orders
       WHERE created_by_user_id = $1
         AND created_at > NOW() - INTERVAL '30 minutes'
       ORDER BY created_at ASC
```

| id | order_number | status | created_by_user_id | created_at |
| --- | --- | --- | --- | --- |
| 01a0eb00-b65f-75e7-a132-d7f361809099 | BO-1 | submitted | 17b8c9d0-e1f2-3456-1234-567890123456 | 2026-09-29T02:31:27.240Z |
| 01a0eb01-3aa1-7080-a70b-3e8175be48aa | BO-2 | submitted | 17b8c9d0-e1f2-3456-1234-567890123456 | 2026-09-29T02:32:01.379Z |

### Inventory transactions recorded with timestamp — ✅ PASS

**Assertion:** inventory_transactions rows exist for the bill-only orders, each with a non-null created_at

```sql

      SELECT id, source_type, source_id, created_at,
             distributor_organization_id, manufacturer_organization_id
        FROM inventory_transactions
       WHERE source_type = 'bill_only_order'
         AND created_at > NOW() - INTERVAL '30 minutes'
         AND (distributor_organization_id = $1 OR manufacturer_organization_id = $1)
       ORDER BY created_at ASC
```

| id | source_type | source_id | created_at | distributor_organization_id | manufacturer_organization_id |
| --- | --- | --- | --- | --- | --- |
| 01a0eb00-b66f-76f5-ac1f-3294e85410ea | bill_only_order | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL |
| 01a0eb01-3aa9-74ef-b451-62b78b735e54 | bill_only_order | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL |

### Inventory history records each change with a timestamp — ✅ PASS

**Assertion:** inventory_history contains bill_only_order rows in the test window, each with created_at populated

```sql

      SELECT ih.id, ih.item_id, ih.quantity, ih.info, ih.created_at
        FROM inventory_history ih
       WHERE ih.created_at > NOW() - INTERVAL '30 minutes'
         AND ih.info->>'reason' = 'bill_only_order'
       ORDER BY ih.created_at ASC
       LIMIT 20
```

| id | item_id | quantity | info | created_at |
| --- | --- | --- | --- | --- |
| 01a0eb00-b684-75a7-8c7a-ce9e97e853cd | 2cc1ac87-b8a3-49b0-9224-e39f6fbdf3f5 | 2 | `{"action":"removed","reason":"bill_only_order","bestEffort":true,"billingOrderId":"01a0eb00-b65f-75e7-a132-d7f361809099","shortageQuantity":0,"requestedQuantity":2}` | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b684-75a7-8c7a-ce9feff0471e | d8d3261f-e222-4f23-bd6c-ac6f3682363b | 3 | `{"action":"removed","reason":"bill_only_order","bestEffort":true,"billingOrderId":"01a0eb00-b65f-75e7-a132-d7f361809099","shortageQuantity":0,"requestedQuantity":3}` | 2026-09-29T02:31:27.240Z |
| 01a0eb01-3aae-730e-94ca-31cbd51e36de | 2cc1ac87-b8a3-49b0-9224-e39f6fbdf3f5 | 1 | `{"action":"removed","reason":"bill_only_order","bestEffort":true,"billingOrderId":"01a0eb01-3aa1-7080-a70b-3e8175be48aa","shortageQuantity":0,"requestedQuantity":1}` | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3aae-730e-94ca-31cca8307548 | d8d3261f-e222-4f23-bd6c-ac6f3682363b | 1 | `{"action":"removed","reason":"bill_only_order","bestEffort":true,"billingOrderId":"01a0eb01-3aa1-7080-a70b-3e8175be48aa","shortageQuantity":0,"requestedQuantity":1}` | 2026-09-29T02:32:01.379Z |

### Audit events recorded with user ID + timestamp — ✅ PASS

**Assertion:** At least one audit_events row in the test window has both user_id and created_at populated, and no row is missing created_at

```sql

      SELECT id, organization_id, user_id, event_type, action,
             object_id, created_at
        FROM audit_events
       WHERE created_at > NOW() - INTERVAL '30 minutes'
         AND organization_id IN ($1, $2)
       ORDER BY created_at ASC
       LIMIT 50
```

| id | organization_id | user_id | event_type | action | object_id | created_at |
| --- | --- | --- | --- | --- | --- | --- |
| 01a0eaff-dad7-744a-b3ef-01b0d6fd2975 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | NULL | decision | return_overdue_sweep | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 2026-09-29T02:30:31.383Z |
| 01a0eaff-dba4-736c-80f1-0924770b8e94 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | decision | ensure_lot_expiration_cycle_counter_assignment | a6e7f8a9-b0c1-2345-0123-456789012345 | 2026-09-29T02:30:31.589Z |
| 01a0eaff-dbd1-7c9e-98d5-0ee4bce51a76 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | decision | ensure_lot_expiration_cycle_counter_assignment | b7f8a9b0-c1d2-3456-1234-567890123456 | 2026-09-29T02:30:31.647Z |
| 01a0eaff-dc6d-7167-87b1-e578dd2b2d93 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | checklist | checklists.create | 01a0eaff-dc0f-7e8a-98b4-12fca27f5802 | 2026-09-29T02:30:31.694Z |
| 01a0eaff-de99-7ee7-b7df-48c31471e26a | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | decision | upgrade_lot_expiration_checklist_priority | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 2026-09-29T02:30:32.362Z |
| 01a0eaff-df5d-7a56-850c-b66b7410ea3f | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | decision | ensure_lot_expiration_checklist | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 2026-09-29T02:30:32.549Z |
| 01a0eb00-2f30-78b1-a147-881747c2cfcd | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | user_log | user:login | NULL | 2026-09-29T02:30:53.046Z |
| 01a0eb00-408f-7b44-ba25-29b7bd5e2203 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | user_log | user:login | NULL | 2026-09-29T02:30:57.460Z |
| 01a0eb00-7149-71b7-89f3-d4c1b5a2e220 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.duplicate_submission_block | fea7b8c9-d0e1-2345-0123-456789012345 | 2026-09-29T02:31:09.658Z |
| 01a0eb00-b54b-7e87-a49c-d40cab34977a | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.duplicate_submission_block | fea7b8c9-d0e1-2345-0123-456789012345 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b601-75a5-9e9a-a3b92b5f5a4b | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | representatives.gate_rep_action | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b657-77c2-a4d7-bce8a391c1df | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | representatives.gate_rep_action | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b666-7d8b-88fc-99ddd4722fc1 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.inventory_items_decrement | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b698-74a0-97da-b8ce4138994a | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.direct_po_import_on_create | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6a1-7ce8-a60d-a91b21a9f2cf | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | billing_order | status_change | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6ae-709e-a290-74b7737e898d | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | basicErp.deriveSalesOrder | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6bc-757d-9608-05aae6ab9fd3 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb00-b6b6-7f70-9fb5-780d94a6b04f | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6c5-79fe-98de-1f3f3baa35f5 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb00-b6c3-7c5a-8d6a-cedbd19b38ad | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6d2-7bfd-aa73-3730d451d4a8 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb00-b6cc-7b50-915e-c5ba342b0df1 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-b6d8-721c-a455-c602332c42d0 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only.link_purchase_order | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:27.240Z |
| 01a0eb00-bd61-7c5e-9df0-bfd978684962 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | NULL | decision | bill_only.notifications.cc_incident_recipients | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:29.378Z |
| 01a0eb00-bf55-7663-b9c1-94eb6ae2874b | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | transactional_email | new_bill_only | 01a0eb00-b65f-75e7-a132-d7f361809099 | 2026-09-29T02:31:29.923Z |
| 01a0eb00-d0bb-7fbd-a8ec-e5bbdbe9019b | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | user_log | user:login | NULL | 2026-09-29T02:31:34.367Z |
| 01a0eb00-fe54-7fb1-9548-7ae19f5bdaf7 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.duplicate_submission_block | fea7b8c9-d0e1-2345-0123-456789012345 | 2026-09-29T02:31:45.986Z |
| 01a0eb01-3a6c-7045-8f84-e054646bd3a6 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.duplicate_submission_block | fea7b8c9-d0e1-2345-0123-456789012345 | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3a85-78c6-8bcd-4361d8ce448a | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | representatives.gate_rep_action | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3a9c-71a7-9484-b249692aca32 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | representatives.gate_rep_action | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3aa4-78c9-b52d-f4e834e3a9e3 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.inventory_items_decrement | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3ab3-7113-a1c8-8487f4a4f59c | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only_order.direct_po_import_on_create | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3ab6-76f0-82f8-9f6267391293 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | billing_order | status_change | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3ab9-7579-b3fe-bb5e2495ff14 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | basicErp.deriveSalesOrder | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3abf-7a0e-9b74-495a69f995e9 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb01-3abe-7ccb-98de-c2355e1b35a3 | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3ac4-702f-bbc0-40d066859c33 | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb01-3ac2-7a85-9e81-3237861c1be4 | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3ac8-7add-a5e9-481f16cb226d | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | 17b8c9d0-e1f2-3456-1234-567890123456 | scheduled_task | scheduled_task.scheduled | 01a0eb01-3ac6-7ebf-b546-f3436391ce6a | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3acb-7708-ad14-add5d90f615e | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | decision | bill_only.link_purchase_order | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:01.379Z |
| 01a0eb01-3f51-7a4e-9aa0-f8d7d29fbfbb | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | NULL | decision | bill_only.notifications.cc_incident_recipients | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:02.642Z |
| 01a0eb01-413c-7f71-9443-e81a76443f3b | b2c3d4e5-f6a7-8901-bcde-f12345678901 | NULL | transactional_email | new_bill_only | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | 2026-09-29T02:32:03.148Z |
| 01a0eb01-4feb-717a-b0a3-f7f8467970c0 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | user_log | user:login | NULL | 2026-09-29T02:32:06.898Z |
| 01a0eb01-6cc3-731d-a4b6-3020fee17f66 | b2c3d4e5-f6a7-8901-bcde-f12345678901 | 17b8c9d0-e1f2-3456-1234-567890123456 | user_log | user:login | NULL | 2026-09-29T02:32:14.285Z |
| 01a0eb01-8982-77f1-a1d9-579fbbf7e5db | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | d4e5f6a7-b8c9-0123-def1-234567890123 | user_log | user:login | NULL | 2026-09-29T02:32:21.640Z |

### Returns have created_by_user_id + created_at populated — ✅ PASS

**Assertion:** All pre-seeded returns (and any created during the test) have non-null created_by_user_id and created_at

```sql

      SELECT r.id, r.return_number, r.status, r.created_by_user_id,
             r.created_at, u.email AS created_by_email
        FROM returns r
        LEFT JOIN users u ON u.id = r.created_by_user_id
       WHERE r.return_number = ANY($1)
          OR r.created_at > NOW() - INTERVAL '30 minutes'
       ORDER BY r.created_at ASC
```

| id | return_number | status | created_by_user_id | created_at | created_by_email |
| --- | --- | --- | --- | --- | --- |
| ca000003-0000-4000-8000-000000000003 | VRI-RET-2025-003 | submitted | 17b8c9d0-e1f2-3456-1234-567890123456 | 2026-08-30T02:23:23.225Z | blair.bennett@corvetasurgical.com |
| ca000002-0000-4000-8000-000000000002 | VRI-RET-2025-002 | submitted | 28c9d0e1-f2a3-4567-2345-678901234567 | 2026-09-15T02:23:23.225Z | rana.reyes@corvetasurgical.com |
| ca000001-0000-4000-8000-000000000001 | VRI-RET-2025-001 | submitted | 17b8c9d0-e1f2-3456-1234-567890123456 | 2026-09-26T02:23:23.225Z | blair.bennett@corvetasurgical.com |

### Inventory transactions timestamped at or after their triggering order — ✅ PASS

**Assertion:** For every bill-only order in the test window, the earliest inventory_transaction linked to it has created_at >= billing_order.created_at

```sql

      SELECT bo.order_number,
             bo.created_at             AS order_created_at,
             MIN(it.created_at)        AS first_txn_created_at
        FROM billing_orders bo
        JOIN inventory_transactions it
          ON it.source_type = 'bill_only_order'
         AND it.source_id = bo.id
       WHERE bo.created_by_user_id = $1
         AND bo.created_at > NOW() - INTERVAL '30 minutes'
       GROUP BY bo.id, bo.order_number, bo.created_at
```

| order_number | order_created_at | first_txn_created_at |
| --- | --- | --- |
| BO-1 | 2026-09-29T02:31:27.240Z | 2026-09-29T02:31:27.240Z |
| BO-2 | 2026-09-29T02:32:01.379Z | 2026-09-29T02:32:01.379Z |

### Multiple distinct users represented across transactions — ✅ PASS

**Assertion:** The combined transaction set (orders, returns, audit events) contains at least two distinct user IDs

```sql

      SELECT DISTINCT user_id FROM (
        SELECT created_by_user_id AS user_id FROM billing_orders
         WHERE created_at > NOW() - INTERVAL '30 minutes'
           AND created_by_user_id IS NOT NULL
        UNION
        SELECT created_by_user_id AS user_id FROM returns
         WHERE return_number = ANY($1)
        UNION
        SELECT user_id FROM audit_events
         WHERE created_at > NOW() - INTERVAL '30 minutes'
           AND user_id IS NOT NULL
      ) u
       ORDER BY user_id
```

| user_id |
| --- |
| 17b8c9d0-e1f2-3456-1234-567890123456 |
| 28c9d0e1-f2a3-4567-2345-678901234567 |
| d4e5f6a7-b8c9-0123-def1-234567890123 |

## Audit & Email Assertion Ledger

Per-declaration outcome of every `expectedAuditActions` and `expectedEmailTemplates` entry written into the orchestrator. Missing evidence here is a real test failure, not a soft warning.

### Audit Action Assertions

Each row asserts that a declared `expectedAuditActions` entry produced a matching row in `audit_events`. A ❌ flips overall status to FAIL — the declaration is real proof, not just an annotation.

| Step | Expected Audit Action | Found |
|------|-----------------------|-------|
| Step 1: Logged in as Blair Bennett | `user_log:user:login` | ✅ |
| Step 2: First order | `decision:bill_only_order.inventory_items_decrement` | ✅ |
| Step 2: First order | `billing_order:status_change` | ✅ |
| Step 3: Second order | `decision:bill_only_order.inventory_items_decrement` | ✅ |
| Step 3: Second order | `billing_order:status_change` | ✅ |
| Step 6: Cross-user billing view | `user_log:user:login` | ✅ |

### Email Template Assertions

Each row asserts that a declared `expectedEmailTemplates` entry was matched (case-insensitive substring) by a captured email subject or template. A ❌ flips overall status to FAIL.

| Step | Expected Template | Found |
|------|-------------------|-------|
| Step 2: First order | `New Bill-Only Order` | ✅ |
| Step 3: Second order | `New Bill-Only Order` | ✅ |

## Audit Log Events

Every row written to `audit_events` while this test was running (scoped to the demo organizations). Provides compliance evidence that user actions are traced end-to-end (URS-003).

**Capture window start:** 2026-09-29T02:30:46.444Z

<details><summary>Query used to capture events</summary>

```sql
SELECT
    ae.created_at,
    ae.event_type,
    ae.action,
    ae.user_id,
    u.email AS user_email,
    ae.organization_id,
    o.name AS organization_name,
    ae.object_id,
    ae.secondary_object_id,
    ae.payload,
    ae.route,
    ae.trace_id
  FROM audit_events ae
  LEFT JOIN users u ON u.id = ae.user_id
  LEFT JOIN organizations o ON o.id = ae.organization_id
  WHERE ae.created_at >= $1
    AND ae.organization_id = ANY($2::uuid[])
  ORDER BY ae.created_at ASC
```
</details>

34 event(s) captured:

| Time | Type | Action | User | Org | Object ID | Performed | Reason |
|------|------|--------|------|-----|-----------|-----------|--------|
| 2026-09-29 02:30:53Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |  |
| 2026-09-29 02:30:57Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |  |
| 2026-09-29 02:31:09Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | no_same_day_candidates |
| 2026-09-29 02:31:27Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | no_same_day_candidates |
| 2026-09-29 02:31:27Z | decision | bill_only.link_purchase_order | blair.bennett@corvetasurgical.com | Corveta Surgical Group | 01a0eb00-b65f-75e7-a132-d7f361809099 | no | no_purchase_order_selected |
| 2026-09-29 02:31:27Z | decision | basicErp.deriveSalesOrder | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b65f-75e7-a132-d7f361809099 | no | flag_disabled |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b6c3-7c5a-8d6a-cedbd19b38ad | — |  |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b6cc-7b50-915e-c5ba342b0df1 | — |  |
| 2026-09-29 02:31:27Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b65f-75e7-a132-d7f361809099 | yes | inventory_items_decremented |
| 2026-09-29 02:31:27Z | decision | bill_only_order.direct_po_import_on_create | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b65f-75e7-a132-d7f361809099 | no | No uploaded PO documents |
| 2026-09-29 02:31:27Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b65f-75e7-a132-d7f361809099 | — |  |
| 2026-09-29 02:31:27Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb00-b6b6-7f70-9fb5-780d94a6b04f | — |  |
| 2026-09-29 02:31:27Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:31:27Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:31:29Z | decision | bill_only.notifications.cc_incident_recipients | — | Vantis | 01a0eb00-b65f-75e7-a132-d7f361809099 | no | order has no no-charge item with an incident reason |
| 2026-09-29 02:31:29Z | transactional_email | new_bill_only | — | Corveta Surgical Group | 01a0eb00-b65f-75e7-a132-d7f361809099 | — |  |
| 2026-09-29 02:31:34Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |  |
| 2026-09-29 02:31:45Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | all_candidates_vetoed |
| 2026-09-29 02:32:01Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3ac2-7a85-9e81-3237861c1be4 | — |  |
| 2026-09-29 02:32:01Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | all_candidates_vetoed |
| 2026-09-29 02:32:01Z | decision | bill_only.link_purchase_order | blair.bennett@corvetasurgical.com | Corveta Surgical Group | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | no | no_purchase_order_selected |
| 2026-09-29 02:32:01Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:32:01Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:32:01Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | yes | inventory_items_decremented |
| 2026-09-29 02:32:01Z | decision | bill_only_order.direct_po_import_on_create | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | no | No uploaded PO documents |
| 2026-09-29 02:32:01Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | — |  |
| 2026-09-29 02:32:01Z | decision | basicErp.deriveSalesOrder | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | no | flag_disabled |
| 2026-09-29 02:32:01Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3abe-7ccb-98de-c2355e1b35a3 | — |  |
| 2026-09-29 02:32:01Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb01-3ac6-7ebf-b546-f3436391ce6a | — |  |
| 2026-09-29 02:32:02Z | decision | bill_only.notifications.cc_incident_recipients | — | Vantis | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | no | order has no no-charge item with an incident reason |
| 2026-09-29 02:32:03Z | transactional_email | new_bill_only | — | Corveta Surgical Group | 01a0eb01-3aa1-7080-a70b-3e8175be48aa | — |  |
| 2026-09-29 02:32:06Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |  |
| 2026-09-29 02:32:14Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |  |
| 2026-09-29 02:32:21Z | user_log | user:login | mark.manufacturer@vantismedical.com | Vantis | — | — |  |

## Email Evidence

2 notification email(s) were captured during this test run. Each email is rendered as a screenshot for compliance review.

### 1. New Bill-Only Order - 9/29/2026 - Vantis BO-1

**Template:** `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1`

![New Bill-Only Order - 9/29/2026 - Vantis BO-1](screenshots/emails/2026-09-29T02-31-29-846Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1.png)

### 2. New Bill-Only Order - 9/29/2026 - Vantis BO-2

**Template:** `New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2`

![New Bill-Only Order - 9/29/2026 - Vantis BO-2](screenshots/emails/2026-09-29T02-32-03-122Z-New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-2.png)
