{
  "ursId": "URS-077",
  "title": "Representative certification gating per manufacturer",
  "timestamp": "2026-09-29T02:30:59.420Z",
  "durationMs": 79790,
  "config": {
    "inboxUrl": "http://localhost:44167",
    "dbHost": "localhost",
    "dbPort": 36531,
    "dbName": "cc_repinbox_dev"
  },
  "setup": {
    "status": "pass"
  },
  "scenarios": [
    {
      "name": "Step 1: Uncertified rep blocked",
      "status": "pass",
      "description": "Step 1: Uncertified rep blocked",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-01-billing-blocked.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-01-billing-picker.png"
      ],
      "explanation": "An approved representative who has not completed the manufacturer's required certification opens bill-only and order-request creation. The manufacturer is absent from both manufacturer pickers, and a 'Certification required' notice links the representative to the certification checklist. A second manufacturer without a certification requirement remains selectable.",
      "startedAt": "2026-09-29T02:31:10.858Z",
      "finishedAt": "2026-09-29T02:31:12.680Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/videos/step-01-uncertified-blocked.webm"
    },
    {
      "name": "Step 1: Trunk order requests allowed while pending",
      "status": "pass",
      "description": "Step 1: Trunk order requests allowed while pending",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-01-orders-trunk-allowed.png"
      ],
      "startedAt": "2026-09-29T02:31:18.825Z",
      "finishedAt": "2026-09-29T02:31:18.825Z"
    },
    {
      "name": "Step 2: Direct-post defense",
      "status": "pass",
      "description": "Step 2: Direct-post defense",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-02-crafted-rejected.png"
      ],
      "explanation": "A crafted submission naming the certification-gated manufacturer is sent directly to the server, bypassing the picker. The server rejects it with a certification-required error and records the gate decision; no order or billing rows are created.",
      "startedAt": "2026-09-29T02:31:28.130Z",
      "finishedAt": "2026-09-29T02:31:28.130Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/videos/step-02-direct-post-defense.webm"
    },
    {
      "name": "Step 3: Certification completion",
      "status": "pass",
      "description": "Step 3: Certification completion",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-verify-identity-gate.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-signing-code-sent.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-document-page.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-doc-acknowledged.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-quiz-failed-attempt.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-quiz-passed.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-signature.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-replay-refused.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-completed.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-certificate-status.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-03-gate-lifted.png"
      ],
      "explanation": "The representative completes the certification behind the Part 11 signing re-authentication gate: the training flow stays hidden until a one-time signing code — issued on request and read back out of the email the system sent — is verified. The representative then opens and acknowledges the training document (timestamped server-side), fails the knowledge check once (server-side grading records the attempt and allows unlimited retries), passes at 100%, signs, and receives a certificate. The completion consumes the one-time code: replaying the identical completion request — with and without the verified code — is refused with a re-authentication demand and creates no second record. The manufacturer immediately reappears in the pickers.",
      "expectedEmailTemplates": [
        "Your signing code"
      ],
      "expectedAuditActions": [
        "certification:signing_code_issued",
        "certification:signing_code_verified",
        "certification:signing_code_consumed",
        "certification:completed",
        "certification:signing_reauth_failed"
      ],
      "startedAt": "2026-09-29T02:31:35.302Z",
      "finishedAt": "2026-09-29T02:32:01.758Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/videos/step-03-certification-completion.webm"
    },
    {
      "name": "Step 4: Per-manufacturer isolation",
      "status": "pass",
      "description": "Step 4: Per-manufacturer isolation",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-04-both-manufacturers.png"
      ],
      "explanation": "The certification gate is scoped to the requiring manufacturer. The same representative could act for the second manufacturer before, during, and after certification; both manufacturers are selectable at the end of the run.",
      "startedAt": "2026-09-29T02:32:07.724Z",
      "finishedAt": "2026-09-29T02:32:07.724Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/videos/step-04-isolation.webm"
    },
    {
      "name": "Step 5: Completion-record export",
      "status": "pass",
      "description": "Step 5: Completion-record export",
      "screenshots": [
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-05-export-card.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-05-zip-requested.png",
        "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/step-05-zip-status.png"
      ],
      "explanation": "The manufacturer exports certification completion records. The CSV download contains one row per completion record — including the newly certified representative — with version, completion date, and signature integrity hash, matching the database. A background PDF bundle job is requested and completes with a downloadable ZIP.",
      "expectedAuditActions": [
        "export:export:certification-completion-records"
      ],
      "startedAt": "2026-09-29T02:32:14.013Z",
      "finishedAt": "2026-09-29T02:32:16.870Z",
      "videoPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/videos/step-05-export.webm"
    }
  ],
  "dbValidations": [
    {
      "name": "Certification block existed before it was lifted this run",
      "query": "SELECT to_status, reason_code, created_at\n     FROM organization_representation_request_status_changes\n     WHERE relationship_id = $1 AND created_at > NOW() - INTERVAL '2 hours'\n     ORDER BY created_at",
      "status": "pass",
      "rows": [
        {
          "to_status": "active",
          "reason_code": "certification_completed",
          "created_at": "2026-09-29T02:31:54.918Z"
        }
      ],
      "assertion": "A pending_certification hold is recorded earlier in the run than the active completion transition"
    },
    {
      "name": "Gate actively evaluated the representative during the run",
      "query": "SELECT action, payload->>'reason' AS reason\n     FROM audit_events\n     WHERE action = 'representatives.gate_rep_action'\n       AND user_id = $1\n       AND created_at > NOW() - INTERVAL '2 hours'\n     ORDER BY created_at DESC LIMIT 10",
      "status": "pass",
      "rows": [
        {
          "action": "representatives.gate_rep_action",
          "reason": "no_blocking_relationship"
        }
      ],
      "assertion": "The per-manufacturer action gate recorded decisions for the representative while ordering flows were exercised"
    },
    {
      "name": "No order or billing rows were created while the representative was gated",
      "query": "SELECT\n       (SELECT COUNT(*) FROM order_requests\n        WHERE requested_by_user_id = $1\n          AND created_at > NOW() - INTERVAL '2 hours') AS order_count,\n       (SELECT COUNT(*) FROM billing_orders\n        WHERE created_by_user_id = $1\n          AND created_at > NOW() - INTERVAL '2 hours') AS billing_count",
      "status": "pass",
      "rows": [
        {
          "order_count": "0",
          "billing_count": "0"
        }
      ],
      "assertion": "Zero order requests and zero billing orders exist for the gated representative"
    },
    {
      "name": "Immutable certification record created on completion",
      "query": "SELECT r.rep_user_id, r.certification_id, r.certification_version_id,\n            r.completed_at, r.expires_at, r.signature_ref, r.form_submission_id\n     FROM certification_records r\n     WHERE r.rep_user_id = $1 AND r.certification_id = $2",
      "status": "pass",
      "rows": [
        {
          "rep_user_id": "ce000001-0000-4000-8000-000000000002",
          "certification_id": "ce000100-0000-4000-8000-000000000001",
          "certification_version_id": "ce000200-0000-4000-8000-000000000002",
          "completed_at": "2026-09-29T02:31:54.929Z",
          "expires_at": "2028-09-29T00:00:00.000Z",
          "signature_ref": "01a0eb01-2132-7b31-877d-f31ae2c707f8",
          "form_submission_id": "01a0eb01-1109-70a8-a813-f763c4b01bfa"
        }
      ],
      "assertion": "Exactly one record exists for the rep, on version 2, with a completion timestamp, signature reference, and form submission"
    },
    {
      "name": "Status change recorded: pending_certification to active on completion",
      "query": "SELECT from_status, to_status, reason_code\n     FROM organization_representation_request_status_changes\n     WHERE relationship_id = $1\n       AND to_status = 'active' AND reason_code = 'certification_completed'\n       AND created_at > NOW() - INTERVAL '2 hours'",
      "status": "pass",
      "rows": [
        {
          "from_status": "pending_certification",
          "to_status": "active",
          "reason_code": "certification_completed"
        }
      ],
      "assertion": "A status-change row with reason_code certification_completed moved the relationship to active"
    },
    {
      "name": "Document acknowledgment timestamps recorded with the document ID",
      "query": "SELECT upload_id, first_viewed_at, last_viewed_at\n     FROM form_document_views\n     WHERE user_id = $1 AND form_definition_id = $2",
      "status": "pass",
      "rows": [
        {
          "upload_id": "ce000400-0000-4000-8000-000000000002",
          "first_viewed_at": "2026-09-29T02:31:41.593Z",
          "last_viewed_at": "2026-09-29T02:31:41.722Z"
        }
      ],
      "assertion": "A document view row exists for the acknowledged training document with a first-seen timestamp"
    },
    {
      "name": "Quiz graded server-side: one failed attempt then a passing attempt",
      "query": "SELECT passed, incorrect_count, form_submission_id\n     FROM form_quiz_attempts\n     WHERE user_id = $1 AND form_definition_id = $2\n     ORDER BY created_at",
      "status": "pass",
      "rows": [
        {
          "passed": false,
          "incorrect_count": 1,
          "form_submission_id": "01a0eb01-1109-70a8-a813-f763c4b01bfa"
        },
        {
          "passed": true,
          "incorrect_count": 0,
          "form_submission_id": "01a0eb01-1109-70a8-a813-f763c4b01bfa"
        },
        {
          "passed": true,
          "incorrect_count": 0,
          "form_submission_id": "01a0eb01-1109-70a8-a813-f763c4b01bfa"
        }
      ],
      "assertion": "At least one failed attempt (incorrect answers, no submission) precedes a passing attempt linked to the stored submission"
    },
    {
      "name": "Part 11 signing challenge verified, consumed, and linked to the signature",
      "query": "SELECT ch.code_hash, ch.email_sent_at, ch.verified_at, ch.signing_window_expires_at,\n            ch.consumed_at, ch.consumed_signature_id, r.signature_ref\n     FROM certification_signing_challenges ch\n     JOIN certification_records r\n       ON r.rep_user_id = ch.user_id AND r.certification_id = ch.certification_id\n     WHERE ch.user_id = $1 AND ch.certification_id = $2\n       AND ch.consumed_at IS NOT NULL",
      "status": "pass",
      "rows": [
        {
          "code_hash": "5f882cd4b24abd65c4d931c40b216400a8527c425bc0eb3471097bc30a457f74",
          "email_sent_at": "2026-09-29T02:31:37.429Z",
          "verified_at": "2026-09-29T02:31:40.853Z",
          "signing_window_expires_at": "2026-09-29T06:31:40.853Z",
          "consumed_at": "2026-09-29T02:31:54.932Z",
          "consumed_signature_id": "01a0eb01-2132-7b31-877d-f31ae2c707f8",
          "signature_ref": "01a0eb01-2132-7b31-877d-f31ae2c707f8"
        }
      ],
      "assertion": "Exactly one consumed signing challenge exists: emailed, verified (window opened), consumed by the completion, linked to the completion signature, and storing only a sha256 hash — never the raw code"
    },
    {
      "name": "Signature captured with integrity hash",
      "query": "SELECT s.meaning, s.signer_name, s.sha256_hash, s.executed_at\n     FROM signatures s\n     JOIN certification_records r ON r.signature_ref = s.id::text\n     WHERE r.rep_user_id = $1 AND r.certification_id = $2",
      "status": "pass",
      "rows": [
        {
          "meaning": "Certification completion",
          "signer_name": "Marco Silva",
          "sha256_hash": "9b34dc26b713e354e6833fbd8da8717422eb648b95c34c07f4308755197cdbf2",
          "executed_at": "2026-09-29T02:31:54.929Z"
        }
      ],
      "assertion": "The completion signature has meaning 'Certification completion', a signer name, an execution timestamp, and a SHA-256 hash"
    },
    {
      "name": "Signed-payload hash recomputes from the stored completion record and signature",
      "query": "SELECT r.id AS record_id, r.certification_id, r.certification_version_id,\n            r.form_submission_id, r.rep_user_id, r.completed_at,\n            s.meaning, s.executed_at, s.sha256_hash, s.signed_payload_sha256\n     FROM certification_records r\n     JOIN signatures s ON r.signature_ref = s.id::text\n     WHERE r.rep_user_id = $1 AND r.certification_id = $2",
      "status": "pass",
      "rows": [
        {
          "record_id": "01a0eb01-2131-737b-95f7-636028f0aaad",
          "certification_id": "ce000100-0000-4000-8000-000000000001",
          "certification_version_id": "ce000200-0000-4000-8000-000000000002",
          "form_submission_id": "01a0eb01-1109-70a8-a813-f763c4b01bfa",
          "rep_user_id": "ce000001-0000-4000-8000-000000000002",
          "completed_at": "2026-09-29T02:31:54.929Z",
          "meaning": "Certification completion",
          "executed_at": "2026-09-29T02:31:54.929Z",
          "sha256_hash": "9b34dc26b713e354e6833fbd8da8717422eb648b95c34c07f4308755197cdbf2",
          "signed_payload_sha256": "8db42d4e7b2c524d03ddac135cf729b83211019ad0184ca4b76cbaf76e87d87e"
        }
      ],
      "assertion": "signatures.signed_payload_sha256 equals the sha256 of the canonical signed payload (record id, certification, version, submission, signer, meaning, execution time, SVG hash) rebuilt from the stored rows, and the record completed_at equals the signature executed_at the hash binds (11.70)"
    },
    {
      "name": "Refused signing re-authentication attempts audited with machine-readable reasons",
      "query": "SELECT payload->>'reason' AS reason, created_at\n     FROM audit_events\n     WHERE event_type = 'certification' AND action = 'signing_reauth_failed'\n       AND user_id = $1 AND object_id = $2\n       AND created_at > NOW() - INTERVAL '2 hours'\n     ORDER BY created_at",
      "status": "pass",
      "rows": [
        {
          "reason": "missing_code_cookie",
          "created_at": "2026-09-29T02:31:56.327Z"
        },
        {
          "reason": "no_challenge",
          "created_at": "2026-09-29T02:31:56.360Z"
        }
      ],
      "assertion": "The suite's two refused completion replays are audited (11.300(d)): the replay without the signing cookie as 'missing_code_cookie', and the tampered replay with the resurrected (already-consumed) code as 'no_challenge'"
    },
    {
      "name": "Certificate and completion-record documents issued",
      "query": "SELECT document_type, status\n     FROM certification_documents\n     WHERE user_id = $1 AND organization_id = $2\n       AND created_at > NOW() - INTERVAL '2 hours'",
      "status": "pass",
      "rows": [
        {
          "document_type": "certificate",
          "status": "created"
        },
        {
          "document_type": "completion_record",
          "status": "created"
        }
      ],
      "assertion": "Both a certificate and a completion_record document were generated"
    },
    {
      "name": "Second-manufacturer relationship untouched throughout",
      "query": "SELECT status, active FROM organization_representation_relationships WHERE id = $1",
      "status": "pass",
      "rows": [
        {
          "status": "active",
          "active": true
        }
      ],
      "assertion": "The relationship with the second manufacturer remained active for the whole run"
    },
    {
      "name": "Completion-record export audited and a background bundle job was created",
      "query": "SELECT\n       (SELECT COUNT(*) FROM audit_events\n        WHERE event_type = 'export' AND action = 'export:certification-completion-records'\n          AND organization_id = $1 AND created_at > NOW() - INTERVAL '2 hours') AS csv_exports,\n       (SELECT COUNT(*) FROM bulk_exports\n        WHERE organization_id = $1 AND export_type = 'certification_completion_records'\n          AND created_at > NOW() - INTERVAL '2 hours') AS bundle_jobs",
      "status": "pass",
      "rows": [
        {
          "csv_exports": "1",
          "bundle_jobs": "1"
        }
      ],
      "assertion": "The CSV export was audited and a certification-completion-records bulk export job was created"
    },
    {
      "name": "Export rows match certification records",
      "query": "SELECT r.id, u.name AS rep_name, v.version_number, r.completed_at\n     FROM certification_records r\n     JOIN users u ON u.id = r.rep_user_id\n     JOIN certification_versions v ON v.id = r.certification_version_id\n     WHERE r.certification_id = $1\n     ORDER BY r.completed_at",
      "status": "pass",
      "rows": [
        {
          "id": "ce000700-0000-4000-8000-000000000004",
          "rep_name": "Theo Larsen",
          "version_number": 1,
          "completed_at": "2025-12-03T02:23:22.269Z"
        },
        {
          "id": "ce000700-0000-4000-8000-000000000005",
          "rep_name": "Dana Whitfield",
          "version_number": 2,
          "completed_at": "2026-08-15T02:23:22.269Z"
        },
        {
          "id": "ce000700-0000-4000-8000-000000000003",
          "rep_name": "Elena Novak",
          "version_number": 2,
          "completed_at": "2026-08-30T02:23:22.269Z"
        },
        {
          "id": "01a0eb01-2131-737b-95f7-636028f0aaad",
          "rep_name": "Marco Silva",
          "version_number": 2,
          "completed_at": "2026-09-29T02:31:54.929Z"
        }
      ],
      "assertion": "The certification records the CSV was compared against (rep, version, completion date) are present"
    }
  ],
  "overallStatus": "pass",
  "outputDir": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z",
  "auditStartTime": "2026-09-29T02:30:57.495Z",
  "emailEvidence": [
    {
      "subject": "Your signing code for LiraLock Implant System Certification",
      "template": "Your_signing_code_for_LiraLock_Implant_System_Certification",
      "screenshotPath": "/home/runner/_work/code/code/validation_test_results/urs-077-rep-certification-gating/2026-09-29T02-30-59-420Z/screenshots/emails/2026-09-29T02-31-38-320Z-Your_signing_code_for_LiraLock_Implant_System_Certification.png"
    }
  ],
  "auditEventEvidence": [
    {
      "createdAt": "2026-09-29T02:31:04.340Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "marco.silva@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:21.666Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "marco.silva@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:31.694Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "marco.silva@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:37.226Z",
      "eventType": "certification",
      "action": "signing_code_issued",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": "01a0eb00-dca4-7981-9ba0-4fb9bbb1917b",
      "payload": {
        "expiresAt": "2026-10-13T02:31:37.380Z"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:37.226Z",
      "eventType": "decision",
      "action": "certifications.signing_challenge.send_sms",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb00-dca4-7981-9ba0-4fb9bbb1917b",
      "secondaryObjectId": null,
      "payload": {
        "reason": "no_phone_channel",
        "performed": false,
        "entityType": "certification_signing_challenge"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:38.435Z",
      "eventType": "transactional_email",
      "action": "certification_signing_code",
      "userEmail": null,
      "userId": null,
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb00-dca4-7981-9ba0-4fb9bbb1917b",
      "secondaryObjectId": null,
      "payload": {
        "to": "marco.silva@corvetasurgical.com",
        "s3Path": "email-audit/a1b2c3d4-e5f6-7890-abcd-ef1234567890/01a0eb00-e07d-7d62-9fa9-10b32cd5fb6d/",
        "subject": "Your signing code for LiraLock Implant System Certification",
        "messageId": "dev-console-log",
        "relatedEntityType": "certification_signing_challenge"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:40.849Z",
      "eventType": "certification",
      "action": "signing_code_verified",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": "01a0eb00-dca4-7981-9ba0-4fb9bbb1917b",
      "payload": {
        "signingWindowExpiresAt": "2026-09-29T06:31:40.853Z"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:50.783Z",
      "eventType": "decision",
      "action": "forms.grade_submission",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000300-0000-4000-8000-000000000002",
      "secondaryObjectId": null,
      "payload": {
        "reason": "all_answers_correct",
        "stepId": "final",
        "performed": true,
        "entityType": "form_definition",
        "gradedCount": 3,
        "incorrectCount": 0
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.918Z",
      "eventType": "certification",
      "action": "completed",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-2131-737b-95f7-636028f0aaad",
      "secondaryObjectId": "ce000100-0000-4000-8000-000000000001",
      "payload": {
        "repUserId": "ce000001-0000-4000-8000-000000000002",
        "versionNumber": 2
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.918Z",
      "eventType": "decision",
      "action": "certifications.complete_certification.issue_certificate",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-2131-737b-95f7-636028f0aaad",
      "secondaryObjectId": "01a0eb01-2158-7e51-95b1-e785dfaf8208",
      "payload": {
        "reason": "quiz_backed_completion",
        "performed": true,
        "entityType": "certification_record"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.918Z",
      "eventType": "decision",
      "action": "certifications.complete_certification.mark_relationship_certified",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000002-0000-4000-8000-000000000002",
      "secondaryObjectId": "01a0eb01-2131-737b-95f7-636028f0aaad",
      "payload": {
        "reason": "relationship_pending_certification",
        "performed": true,
        "entityType": "organization_representation_relationship"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.918Z",
      "eventType": "organization_representation",
      "action": "status_change",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000002-0000-4000-8000-000000000002",
      "secondaryObjectId": null,
      "payload": {
        "reason": "Certification completed",
        "toStatus": "active",
        "fromStatus": "pending_certification",
        "reasonCode": "certification_completed",
        "requestingOrganizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.918Z",
      "eventType": "certification",
      "action": "signing_code_consumed",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": "01a0eb00-dca4-7981-9ba0-4fb9bbb1917b",
      "payload": {
        "signatureId": "01a0eb01-2132-7b31-877d-f31ae2c707f8"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:54.968Z",
      "eventType": "user_log",
      "action": "rep_relationship_certified",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "reason": "Certification completed",
        "userId": "ce000001-0000-4000-8000-000000000002",
        "userName": "Marco Silva",
        "userEmail": "marco.silva@corvetasurgical.com",
        "relationshipId": "ce000002-0000-4000-8000-000000000002",
        "distributorOrganizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
        "manufacturerOrganizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890"
      },
      "route": "/onboarding/[orgshortname]/certification",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:31:56.327Z",
      "eventType": "certification",
      "action": "signing_reauth_failed",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": null,
      "payload": {
        "reason": "missing_code_cookie"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:56.360Z",
      "eventType": "certification",
      "action": "signing_reauth_failed",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": null,
      "payload": {
        "reason": "no_challenge"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:57.206Z",
      "eventType": "certification_certificate",
      "action": "issued",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-2158-7e51-95b1-e785dfaf8208",
      "secondaryObjectId": "ce000002-0000-4000-8000-000000000002",
      "payload": null,
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:31:57.235Z",
      "eventType": "certification_completion_record",
      "action": "issued",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-215d-7731-b3c3-e203ac055bfb",
      "secondaryObjectId": "01a0eb01-2131-737b-95f7-636028f0aaad",
      "payload": {
        "relationshipId": "ce000002-0000-4000-8000-000000000002"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:32:03.468Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "marco.silva@corvetasurgical.com",
      "userId": "ce000001-0000-4000-8000-000000000002",
      "organizationName": "Corveta Surgical Group",
      "organizationId": "b2c3d4e5-f6a7-8901-bcde-f12345678901",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "marco.silva@corvetasurgical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:32:09.349Z",
      "eventType": "user_log",
      "action": "user:login",
      "userEmail": "mark.manufacturer@vantismedical.com",
      "userId": "d4e5f6a7-b8c9-0123-def1-234567890123",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": null,
      "secondaryObjectId": null,
      "payload": {
        "email": "mark.manufacturer@vantismedical.com"
      },
      "route": "/login",
      "traceId": "00000000000000000000000000000000"
    },
    {
      "createdAt": "2026-09-29T02:32:14.074Z",
      "eventType": "export",
      "action": "export:certification-completion-records",
      "userEmail": "mark.manufacturer@vantismedical.com",
      "userId": "d4e5f6a7-b8c9-0123-def1-234567890123",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "ce000100-0000-4000-8000-000000000001",
      "secondaryObjectId": null,
      "payload": {
        "dateTo": "2026-09-30",
        "dateFrom": "2026-09-29",
        "rowCount": 1,
        "exportType": "certification-completion-records"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:32:16.510Z",
      "eventType": "bulk_export",
      "action": "requested",
      "userEmail": "mark.manufacturer@vantismedical.com",
      "userId": "d4e5f6a7-b8c9-0123-def1-234567890123",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-7581-7128-b7ac-98705c5f998e",
      "secondaryObjectId": null,
      "payload": {
        "to": "2026-09-29",
        "from": "2026-06-29",
        "exportType": "certification_completion_records"
      },
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:32:17.501Z",
      "eventType": "bulk_export",
      "action": "started",
      "userEmail": "mark.manufacturer@vantismedical.com",
      "userId": "d4e5f6a7-b8c9-0123-def1-234567890123",
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-7581-7128-b7ac-98705c5f998e",
      "secondaryObjectId": null,
      "payload": null,
      "route": null,
      "traceId": null
    },
    {
      "createdAt": "2026-09-29T02:32:17.509Z",
      "eventType": "decision",
      "action": "bulk_exports.run_bulk_export.claim_job",
      "userEmail": null,
      "userId": null,
      "organizationName": "Vantis",
      "organizationId": "a1b2c3d4-e5f6-7890-abcd-ef1234567890",
      "objectId": "01a0eb01-7581-7128-b7ac-98705c5f998e",
      "secondaryObjectId": null,
      "payload": {
        "reason": "claimed_requested_job",
        "performed": true,
        "entityType": "bulk_export"
      },
      "route": null,
      "traceId": null
    }
  ],
  "auditQuery": "SELECT\n    ae.created_at,\n    ae.event_type,\n    ae.action,\n    ae.user_id,\n    u.email AS user_email,\n    ae.organization_id,\n    o.name AS organization_name,\n    ae.object_id,\n    ae.secondary_object_id,\n    ae.payload,\n    ae.route,\n    ae.trace_id\n  FROM audit_events ae\n  LEFT JOIN users u ON u.id = ae.user_id\n  LEFT JOIN organizations o ON o.id = ae.organization_id\n  WHERE ae.created_at >= $1\n    AND ae.organization_id = ANY($2::uuid[])\n  ORDER BY ae.created_at ASC",
  "auditAssertions": [
    {
      "stepName": "Step 3: Certification completion",
      "expectedAction": "certification:signing_code_issued",
      "found": true
    },
    {
      "stepName": "Step 3: Certification completion",
      "expectedAction": "certification:signing_code_verified",
      "found": true
    },
    {
      "stepName": "Step 3: Certification completion",
      "expectedAction": "certification:signing_code_consumed",
      "found": true
    },
    {
      "stepName": "Step 3: Certification completion",
      "expectedAction": "certification:completed",
      "found": true
    },
    {
      "stepName": "Step 3: Certification completion",
      "expectedAction": "certification:signing_reauth_failed",
      "found": true
    },
    {
      "stepName": "Step 5: Completion-record export",
      "expectedAction": "export:export:certification-completion-records",
      "found": true
    }
  ],
  "emailAssertions": [
    {
      "stepName": "Step 3: Certification completion",
      "expectedTemplate": "Your signing code",
      "found": true
    }
  ]
}