URS-019 · Bill-Only without PO for Approved Accounts
Title: Bill-Only without PO for Approved Accounts Date: 2026-09-29T02:34:33.216Z Duration: 59.9s Overall Status: ✅ PASS
User Requirement
Section titled “User Requirement”The system shall support “Bill‑Only without PO” only for accounts approved by Vantis.
Source: User_Requirement_Specifications_Vantis_DeviceFlow.xlsx — the run below proves the system meets this requirement.
Environment
Section titled “Environment”- Inbox URL: http://localhost:39789
- Database: localhost:40949/cc_repinbox_dev
Status: ✅ PASS
Test Steps
Section titled “Test Steps”Each step below corresponds to one Playwright test that ran sequentially. Screenshots and video recordings provide visual evidence of the UI behaviour.
1. Step 1: Login — ✅ PASS
Section titled “1. Step 1: Login — ✅ PASS”What this step proves:
Proves that Blair Bennett (Corveta Sales Rep) can authenticate and reach the application. Establishes the user context for all subsequent steps.
Audit events generated by this step:
(Evidence matched by declared name — step timing not available or no events fell in window)
| Time | Type | Action | User | Org | Performed |
|---|---|---|---|---|---|
| 2026-09-29 02:34:38Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:34:43Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:34:49Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:35:00Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
| 2026-09-29 02:35:24Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — |
Screenshots:

Video recording:
2. Step 2: Billing form — ✅ PASS
Section titled “2. Step 2: Billing form — ✅ PASS”What this step proves:
Confirms Blair can navigate to the new bill-only order creation form and reach the account selection step (Step 2). Verifies the billing feature is accessible to the sales rep role.
Screenshots:

Video recording:
3. Step 3: Unapproved account hidden — ✅ PASS
Section titled “3. Step 3: Unapproved account hidden — ✅ PASS”What this step proves:
The system enforces the approval gate at the UI level: the account selector only shows accounts with status=“active” (approved by Vantis). Cedar Crest Hospital Account Request, which is set to status=“proposed” (unapproved) by the test setup, does not appear as a selectable option. ROSS Surgical Account Request (active/approved) is visible, confirming the selector works correctly. This is the negative test — it proves the approval gate is enforced.
Screenshots:



Video recording:
4. Step 4: Create order — ✅ PASS
Section titled “4. Step 4: Create order — ✅ PASS”What this step proves:
An approved account (ROSS Surgical Account Request, status=“active”) can successfully complete the full bill-only order submission flow — including leaving the PO field empty. The order is accepted and a BO-XXXX order number is assigned. This is the positive test proving that approved accounts can submit Bill-Only without PO.
Audit events generated by this step:
(Evidence scoped to step execution window: 2026-09-29T02:35:06.766Z → 2026-09-29T02:35:21.850Z)
| Time | Type | Action | User | Org | Performed |
|---|---|---|---|---|---|
| 2026-09-29 02:35:07Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:35:21Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:35:21Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:35:21Z | decision | bill_only.link_purchase_order | blair.bennett@corvetasurgical.com | Corveta Surgical Group | no |
| 2026-09-29 02:35:21Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:35:21Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:35:21Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | yes |
| 2026-09-29 02:35:21Z | decision | bill_only_order.direct_po_import_on_create | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:35:21Z | decision | basicErp.deriveSalesOrder | blair.bennett@corvetasurgical.com | Vantis | no |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | — |
| 2026-09-29 02:35:21Z | decision | bill_only.notifications.cc_incident_recipients | — | Vantis | no |
Emails triggered by this step:
(Evidence matched by declared name — step timing not available or no events fell in window)
Email 1: New Bill-Only Order - 9/29/2026 - Vantis BO-1
Template: New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1

Screenshots:






Video recording:
5. Step 5: Verify order — ✅ PASS
Section titled “5. Step 5: Verify order — ✅ PASS”What this step proves:
The newly created bill-only order appears on the billing list, confirming it was persisted correctly. The specific order number captured in Step 4 is visible, providing end-to-end traceability from form submission to database record.
Screenshots:


Video recording:
Database Validations
Section titled “Database Validations”The following SQL queries ran against the application database after the Playwright scenarios completed. Each query asserts a specific condition that proves the feature under test persisted its data correctly.
Approved account has active status — ✅ PASS
Section titled “Approved account has active status — ✅ PASS”Assertion: ROSS Hospital should have status=‘active’ (approved)
SELECT id, name, status FROM sales_accounts WHERE id = ANY($1) ORDER BY name| id | name | status |
|---|---|---|
| 1fb8c9d0-e1f2-3456-1234-567890123456 | Cedar Crest Hospital Account Request | proposed |
| fea7b8c9-d0e1-2345-0123-456789012345 | ROSS Surgical Account Request | active |
Unapproved account has proposed status — ✅ PASS
Section titled “Unapproved account has proposed status — ✅ PASS”Assertion: Cedar Healthcare should have status=‘proposed’ (unapproved)
SELECT id, name, status FROM sales_accounts WHERE id = ANY($1) ORDER BY name| id | name | status |
|---|---|---|
| 1fb8c9d0-e1f2-3456-1234-567890123456 | Cedar Crest Hospital Account Request | proposed |
| fea7b8c9-d0e1-2345-0123-456789012345 | ROSS Surgical Account Request | active |
New billing order BO-1 exists for approved account — ✅ PASS
Section titled “New billing order BO-1 exists for approved account — ✅ PASS”Assertion: Order BO-1 should exist for ROSS Hospital (approved account)
SELECT id, order_number, status, sales_account_id, created_at FROM billing_orders WHERE sales_account_id = 'fea7b8c9-d0e1-2345-0123-456789012345' AND order_number = 'BO-1'| id | order_number | status | sales_account_id | created_at |
|---|---|---|---|---|
| 01a0eb04-481b-7b04-a577-440e23849dd3 | BO-1 | submitted | fea7b8c9-d0e1-2345-0123-456789012345 | 2026-09-29T02:35:21.437Z |
No new billing orders for unapproved account — ✅ PASS
Section titled “No new billing orders for unapproved account — ✅ PASS”Assertion: No billing orders should have been created for Cedar Healthcare (unapproved account) during the test
SELECT id, order_number, status, created_at FROM billing_orders WHERE sales_account_id = '1fb8c9d0-e1f2-3456-1234-567890123456' AND created_at > NOW() - INTERVAL '10 minutes' ORDER BY created_at DESCNo rows returned
Audit & Email Assertion Ledger
Section titled “Audit & Email Assertion Ledger”Per-declaration outcome of every expectedAuditActions and expectedEmailTemplates entry written into the orchestrator. Missing evidence here is a real test failure, not a soft warning.
Audit Action Assertions
Section titled “Audit Action Assertions”Each row asserts that a declared expectedAuditActions entry produced a matching row in audit_events. A ❌ flips overall status to FAIL — the declaration is real proof, not just an annotation.
| Step | Expected Audit Action | Found |
|---|---|---|
| Step 1: Login | user_log:user:login | ✅ |
| Step 4: Create order | decision:bill_only_order.inventory_items_decrement | ✅ |
| Step 4: Create order | billing_order:status_change | ✅ |
Email Template Assertions
Section titled “Email Template Assertions”Each row asserts that a declared expectedEmailTemplates entry was matched (case-insensitive substring) by a captured email subject or template. A ❌ flips overall status to FAIL.
| Step | Expected Template | Found |
|---|---|---|
| Step 4: Create order | bill-only | ✅ |
Audit Log Events
Section titled “Audit Log Events”Every row written to audit_events while this test was running (scoped to the demo organizations). Provides compliance evidence that user actions are traced end-to-end (URS-003).
Capture window start: 2026-09-29T02:34:31.280Z
SELECT ae.created_at, ae.event_type, ae.action, ae.user_id, u.email AS user_email, ae.organization_id, o.name AS organization_name, ae.object_id, ae.secondary_object_id, ae.payload, ae.route, ae.trace_id FROM audit_events ae LEFT JOIN users u ON u.id = ae.user_id LEFT JOIN organizations o ON o.id = ae.organization_id WHERE ae.created_at >= $1 AND ae.organization_id = ANY($2::uuid[]) ORDER BY ae.created_at ASC25 event(s) captured:
| Time | Type | Action | User | Org | Object ID | Performed | Reason |
|---|---|---|---|---|---|---|---|
| 2026-09-29 02:34:31Z | decision | return_overdue_sweep | — | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | wms_feature_flag_disabled |
| 2026-09-29 02:34:31Z | decision | ensure_lot_expiration_cycle_counter_assignment | — | Corveta Surgical Group | a6e7f8a9-b0c1-2345-0123-456789012345 | no | no_latest_cycle_counter |
| 2026-09-29 02:34:31Z | decision | ensure_lot_expiration_cycle_counter_assignment | — | Corveta Surgical Group | b7f8a9b0-c1d2-3456-1234-567890123456 | no | no_latest_cycle_counter |
| 2026-09-29 02:34:31Z | checklist | checklists.create | — | Corveta Surgical Group | 01a0eb03-8525-7634-afaa-062a06774d03 | — | |
| 2026-09-29 02:34:31Z | decision | upgrade_lot_expiration_checklist_priority | — | Corveta Surgical Group | b2c3d4e5-f6a7-8901-bcde-f12345678901 | no | no_open_checklists_below_high |
| 2026-09-29 02:34:31Z | decision | ensure_lot_expiration_checklist | — | Corveta Surgical Group | b2c3d4e5-f6a7-8901-bcde-f12345678901 | yes | created_1_reopened_0_already_open_1_refreshed_1 |
| 2026-09-29 02:34:38Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — | |
| 2026-09-29 02:34:43Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — | |
| 2026-09-29 02:34:49Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — | |
| 2026-09-29 02:35:00Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — | |
| 2026-09-29 02:35:07Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | no_same_day_candidates |
| 2026-09-29 02:35:21Z | billing_order | status_change | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-481b-7b04-a577-440e23849dd3 | — | |
| 2026-09-29 02:35:21Z | decision | bill_only_order.duplicate_submission_block | blair.bennett@corvetasurgical.com | Corveta Surgical Group | fea7b8c9-d0e1-2345-0123-456789012345 | no | no_same_day_candidates |
| 2026-09-29 02:35:21Z | decision | bill_only.link_purchase_order | blair.bennett@corvetasurgical.com | Corveta Surgical Group | 01a0eb04-481b-7b04-a577-440e23849dd3 | no | no_purchase_order_selected |
| 2026-09-29 02:35:21Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:35:21Z | decision | representatives.gate_rep_action | blair.bennett@corvetasurgical.com | Vantis | a1b2c3d4-e5f6-7890-abcd-ef1234567890 | no | no_blocking_relationship |
| 2026-09-29 02:35:21Z | decision | bill_only_order.inventory_items_decrement | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-481b-7b04-a577-440e23849dd3 | yes | inventory_items_decremented |
| 2026-09-29 02:35:21Z | decision | bill_only_order.direct_po_import_on_create | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-481b-7b04-a577-440e23849dd3 | no | No uploaded PO documents |
| 2026-09-29 02:35:21Z | decision | basicErp.deriveSalesOrder | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-481b-7b04-a577-440e23849dd3 | no | flag_disabled |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-483b-7c6b-96fc-d1c7d2735245 | — | |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-483e-7382-8762-eeafcb5e616b | — | |
| 2026-09-29 02:35:21Z | scheduled_task | scheduled_task.scheduled | blair.bennett@corvetasurgical.com | Vantis | 01a0eb04-4841-7d00-9b51-2de8d67bb39a | — | |
| 2026-09-29 02:35:21Z | decision | bill_only.notifications.cc_incident_recipients | — | Vantis | 01a0eb04-481b-7b04-a577-440e23849dd3 | no | order has no no-charge item with an incident reason |
| 2026-09-29 02:35:22Z | transactional_email | new_bill_only | — | Corveta Surgical Group | 01a0eb04-481b-7b04-a577-440e23849dd3 | — | |
| 2026-09-29 02:35:24Z | user_log | user:login | blair.bennett@corvetasurgical.com | Corveta Surgical Group | — | — |
Email Evidence
Section titled “Email Evidence”1 notification email(s) were captured during this test run. Each email is rendered as a screenshot for compliance review.
1. New Bill-Only Order - 9/29/2026 - Vantis BO-1
Section titled “1. New Bill-Only Order - 9/29/2026 - Vantis BO-1”Template: New_Bill-Only_Order_-_9_29_2026_-_Vantis_BO-1
