Skip to content

URS-055 · Restrict uncertified reps from actions until approved

Title: Restrict uncertified reps from actions until approved Date: 2026-09-29T02:25:14.883Z Duration: 194.5s Overall Status: ✅ PASS

The system shall restrict regulated sales actions to authorized and approved rep users only

Source: User_Requirement_Specifications_Vantis_DeviceFlow.xlsx — the run below proves the system meets this requirement.

Status: ✅ PASS

Each step below corresponds to one Playwright test that ran sequentially. Screenshots and video recordings provide visual evidence of the UI behaviour.

What this step proves:

A sales rep who has not completed the manufacturer’s required certification attempts to create a bill-only order. The form shows a “Certification required” notice linking to the certification checklist, and the gated manufacturer is absent from the manufacturer picker — confirming that the certification requirement is enforced before any order can be submitted.

Screenshots:

step 01 ryan dashboard

step 01 billing blocked

Video recording:


2. Step 2: Order request trunk allowed — ✅ PASS

Section titled “2. Step 2: Order request trunk allowed — ✅ PASS”

Screenshots:

step 02 order request trunk allowed

Video recording:


3. Step 3: Certified rep control — ✅ PASS

Section titled “3. Step 3: Certified rep control — ✅ PASS”

What this step proves:

A certified sales rep navigates through the bill-only form without being blocked. The form heading and step indicator both render, and the certification-required notice is absent — confirming the restriction is applied only to uncertified reps.

Blair’s relationship row has active = true in the fixtures, which is the column the gating logic (getAvailableFulfillingOrganizations) consults. The status column in the demo data may read proposed_pending_onboarding rather than active because the seed set preserves the original onboarding history — but the boolean active flag is authoritative for whether the rep may place orders, which is why the DB assertion in this run checks active = true for the control case rather than the status string.

Screenshots:

step 03 bob billing form

Video recording:


4. Step 4: Rep completes certification — ✅ PASS

Section titled “4. Step 4: Rep completes certification — ✅ PASS”

What this step proves:

The gated rep opens the manufacturer’s required certification and completes it in the UI: opens and acknowledges the training document (timestamped server-side), passes the knowledge check (graded server-side), and signs. Completion activates the representation relationship (status=‘active’, reason_code=‘certification_completed’) — this is what lifts both order gates.

Audit events generated by this step:

(Evidence scoped to step execution window: 2026-09-29T02:26:47.210Z → 2026-09-29T02:26:58.286Z)

TimeTypeActionUserOrgPerformed
2026-09-29 02:26:54Zdecisionforms.grade_submissionrana.reyes@corvetasurgical.comVantisyes
2026-09-29 02:26:58Zcertificationsigning_code_consumedrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:26:58Zdecisioncertifications.complete_certification.issue_certificaterana.reyes@corvetasurgical.comVantisyes
2026-09-29 02:26:58Zdecisioncertifications.complete_certification.mark_relationship_certifiedrana.reyes@corvetasurgical.comVantisyes
2026-09-29 02:26:58Zorganization_representationstatus_changerana.reyes@corvetasurgical.comVantis—
2026-09-29 02:26:58Zcertificationcompletedrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:26:58Zuser_logrep_relationship_certifiedrana.reyes@corvetasurgical.comVantis—

Screenshots:

step 04 identity verified

step 04 doc acknowledged

step 04 quiz answers

step 04 signature

step 04 completed

Video recording:


5. Step 5: Bill-only after certification — ✅ PASS

Section titled “5. Step 5: Bill-only after certification — ✅ PASS”

What this step proves:

The newly certified rep navigates to the bill-only form and is no longer blocked. The form is accessible and the order is submitted successfully, confirming that certification takes immediate effect.

Audit events generated by this step:

(Evidence scoped to step execution window: 2026-09-29T02:27:05.940Z → 2026-09-29T02:27:29.775Z)

TimeTypeActionUserOrgPerformed
2026-09-29 02:27:13Zdecisionbill_only_order.duplicate_submission_blockrana.reyes@corvetasurgical.comCorveta Surgical Groupno
2026-09-29 02:27:27Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisno
2026-09-29 02:27:27Zdecisionbill_only_order.inventory_items_decrementrana.reyes@corvetasurgical.comVantisyes
2026-09-29 02:27:27Zdecisionbill_only_order.direct_po_import_on_createrana.reyes@corvetasurgical.comVantisno
2026-09-29 02:27:27Zbilling_orderstatus_changerana.reyes@corvetasurgical.comVantis—
2026-09-29 02:27:27ZdecisionbasicErp.deriveSalesOrderrana.reyes@corvetasurgical.comVantisno
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:27:27Zdecisionbill_only.link_purchase_orderrana.reyes@corvetasurgical.comCorveta Surgical Groupno
2026-09-29 02:27:27Zdecisionbill_only_order.duplicate_submission_blockrana.reyes@corvetasurgical.comCorveta Surgical Groupno
2026-09-29 02:27:27Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisno
2026-09-29 02:27:28Zdecisionbill_only.notifications.cc_incident_recipients—Vantisno
2026-09-29 02:27:28Ztransactional_emailnew_bill_only—Corveta Surgical Group—

Screenshots:

step 05 billing form accessible

step 05 devices selected

step 05 review

step 05 order submitted

Video recording:


6. Step 6: Order request after certification — ✅ PASS

Section titled “6. Step 6: Order request after certification — ✅ PASS”

What this step proves:

The certified rep navigates to the standard order request form without the approval warning, then submits a consignment order end-to-end. A DB assertion subsequently confirms that a row was persisted to the order_requests table — proving the post-certification path is unlocked at the database level, not just the UI level.

Audit events generated by this step:

(Evidence scoped to step execution window: 2026-09-29T02:28:07.880Z → 2026-09-29T02:28:26.526Z)

TimeTypeActionUserOrgPerformed
2026-09-29 02:28:24Zdecisionorder_request_createdrana.reyes@corvetasurgical.comVantisyes
2026-09-29 02:28:24Zchecklistchecklists.createrana.reyes@corvetasurgical.comVantis—
2026-09-29 02:28:24Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisno

Screenshots:

step 06 order request form accessible

step 06 order request product

step 06 order request review

step 06 order request submitted

Video recording:


The following SQL queries ran against the application database after the Playwright scenarios completed. Each query asserts a specific condition that proves the feature under test persisted its data correctly.

Assertion: Rana’s representation relationship should be active after certification completion

SELECT id, status, active, responded_at, responded_by_user_id
FROM organization_representation_relationships
WHERE id = $1
idstatusactiveresponded_atresponded_by_user_id
95d6e7f8-a9b0-1234-9012-345678901234activetrueNULLNULL

Blair relationship still active (control) — ✅ PASS

Section titled “Blair relationship still active (control) — ✅ PASS”

Assertion: Blair’s relationship should remain active = true (the column the certification gate actually reads) and be unaffected by Rana’s approval. The status string in this row is informational only and may read proposed_pending_onboarding from the seed data.

SELECT id, status, active
FROM organization_representation_relationships
WHERE id = $1
idstatusactive
84c5d6e7-f8a9-0123-8901-234567890123proposed_pending_onboardingtrue

Certification completion status change recorded — ✅ PASS

Section titled “Certification completion status change recorded — ✅ PASS”

Assertion: A status change to ‘active’ with reason_code ‘certification_completed’ should be recorded in the history table

SELECT id, to_status, from_status, reason_code, changed_by_user_id, created_at
FROM organization_representation_request_status_changes
WHERE relationship_id = $1
AND created_at > NOW() - INTERVAL '30 minutes'
ORDER BY created_at DESC
LIMIT 5
idto_statusfrom_statusreason_codechanged_by_user_idcreated_at
01a0eafc-9a1a-7ced-b964-aee406836e38activepending_certificationcertification_completed28c9d0e1-f2a3-4567-2345-6789012345672026-09-29T02:26:58.172Z

Rana’s certification record created on completion — ✅ PASS

Section titled “Rana’s certification record created on completion — ✅ PASS”

Assertion: Exactly one certification record should exist for Rana, on the current version, with a completion timestamp and a signature reference

SELECT rep_user_id, certification_id, certification_version_id,
completed_at, signature_ref
FROM certification_records
WHERE rep_user_id = $1 AND certification_id = $2
rep_user_idcertification_idcertification_version_idcompleted_atsignature_ref
28c9d0e1-f2a3-4567-2345-678901234567ce000100-0000-4000-8000-000000000001ce000200-0000-4000-8000-0000000000022026-09-29T02:26:58.181Z01a0eafc-9a05-76de-8074-2067c5092048

Bill-only order created by Rana after certification — ✅ PASS

Section titled “Bill-only order created by Rana after certification — ✅ PASS”

Assertion: At least one bill-only order should have been created by Rana after being certified

SELECT bo.id, bo.order_number, bo.status, bo.created_at, bo.created_by_user_id
FROM billing_orders bo
WHERE bo.created_by_user_id = $1
AND bo.created_at > NOW() - INTERVAL '30 minutes'
ORDER BY bo.created_at DESC
LIMIT 5
idorder_numberstatuscreated_atcreated_by_user_id
01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2BO-1submitted2026-09-29T02:27:27.320Z28c9d0e1-f2a3-4567-2345-678901234567

Order request created by Rana after certification — ✅ PASS

Section titled “Order request created by Rana after certification — ✅ PASS”

Assertion: A standard order request should have been persisted by Rana after certification (Step 6) — tagged with the URS-055 notes marker

SELECT id, request_number, order_type, status, sales_account_id, notes, created_at
FROM order_requests
WHERE requested_by_user_id = $1
AND notes LIKE $2
AND created_at > NOW() - INTERVAL '30 minutes'
ORDER BY created_at DESC
LIMIT 5
idrequest_numberorder_typestatussales_account_idnotescreated_at
01a0eafd-eacb-7a28-b19c-2d5dd0fa2596OR-2dropshipsubmittedfea7b8c9-d0e1-2345-0123-456789012345URS-055: post-certification order request2026-09-29T02:28:24.367Z

Audit trail for certification completion — ✅ PASS

Section titled “Audit trail for certification completion — ✅ PASS”

Assertion: Audit/decision events should exist referencing Rana or his relationship after the certification completion

SELECT ae.id, ae.event_type, ae.action, ae.created_at, ae.user_id, ae.object_id,
substring(ae.payload::text, 1, 500) as payload_preview
FROM audit_events ae
WHERE ae.created_at > NOW() - INTERVAL '30 minutes'
AND (ae.object_id = $1 OR ae.object_id = $2)
ORDER BY ae.created_at DESC
LIMIT 10
idevent_typeactioncreated_atuser_idobject_idpayload_preview
01a0eafc-9a1e-7c54-919b-96deb2953d4dorganization_representationstatus_change2026-09-29T02:26:58.172Z28c9d0e1-f2a3-4567-2345-67890123456795d6e7f8-a9b0-1234-9012-345678901234{“reason”: “Certification completed”, “toStatus”: “active”, “fromStatus”: “pending_certification”, “reasonCode”: “certification_completed”, “requestingOrganizationId”: “b2c3d4e5-f6a7-8901-bcde-f12345678901”}
01a0eafc-9a24-7566-a684-5c2d868c37d7decisioncertifications.complete_certification.mark_relationship_certified2026-09-29T02:26:58.172Z28c9d0e1-f2a3-4567-2345-67890123456795d6e7f8-a9b0-1234-9012-345678901234{“reason”: “relationship_pending_certification”, “performed”: true, “entityType”: “organization_representation_relationship”}

Per-declaration outcome of every expectedAuditActions and expectedEmailTemplates entry written into the orchestrator. Missing evidence here is a real test failure, not a soft warning.

Each row asserts that a declared expectedAuditActions entry produced a matching row in audit_events. A ❌ flips overall status to FAIL — the declaration is real proof, not just an annotation.

StepExpected Audit ActionFound
Step 4: Rep completes certificationcertification:completed✅

Every row written to audit_events while this test was running (scoped to the demo organizations). Provides compliance evidence that user actions are traced end-to-end (URS-003).

Capture window start: 2026-09-29T02:25:13.558Z

SELECT
ae.created_at,
ae.event_type,
ae.action,
ae.user_id,
u.email AS user_email,
ae.organization_id,
o.name AS organization_name,
ae.object_id,
ae.secondary_object_id,
ae.payload,
ae.route,
ae.trace_id
FROM audit_events ae
LEFT JOIN users u ON u.id = ae.user_id
LEFT JOIN organizations o ON o.id = ae.organization_id
WHERE ae.created_at >= $1
AND ae.organization_id = ANY($2::uuid[])
ORDER BY ae.created_at ASC

36 event(s) captured:

TimeTypeActionUserOrgObject IDPerformedReason
2026-09-29 02:25:23Zuser_loguser:loginrana.reyes@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:25:37Zuser_loguser:loginrana.reyes@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:25:48Zuser_loguser:loginblair.bennett@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:26:39Zuser_loguser:loginrana.reyes@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:26:43Zcertificationsigning_code_issuedrana.reyes@corvetasurgical.comVantisce000100-0000-4000-8000-000000000001—
2026-09-29 02:26:43Zdecisioncertifications.signing_challenge.send_smsrana.reyes@corvetasurgical.comVantis01a0eafc-6225-7d53-8233-cb1833f8f9cdnono_phone_channel
2026-09-29 02:26:45Ztransactional_emailcertification_signing_code—Vantis01a0eafc-6225-7d53-8233-cb1833f8f9cd—
2026-09-29 02:26:47Zcertificationsigning_code_verifiedrana.reyes@corvetasurgical.comVantisce000100-0000-4000-8000-000000000001—
2026-09-29 02:26:54Zdecisionforms.grade_submissionrana.reyes@corvetasurgical.comVantisce000300-0000-4000-8000-000000000002yesall_answers_correct
2026-09-29 02:26:58Zcertificationsigning_code_consumedrana.reyes@corvetasurgical.comVantisce000100-0000-4000-8000-000000000001—
2026-09-29 02:26:58Zdecisioncertifications.complete_certification.issue_certificaterana.reyes@corvetasurgical.comVantis01a0eafc-9a05-76de-8074-2066a386833dyesquiz_backed_completion
2026-09-29 02:26:58Zdecisioncertifications.complete_certification.mark_relationship_certifiedrana.reyes@corvetasurgical.comVantis95d6e7f8-a9b0-1234-9012-345678901234yesrelationship_pending_certification
2026-09-29 02:26:58Zorganization_representationstatus_changerana.reyes@corvetasurgical.comVantis95d6e7f8-a9b0-1234-9012-345678901234—Certification completed
2026-09-29 02:26:58Zcertificationcompletedrana.reyes@corvetasurgical.comVantis01a0eafc-9a05-76de-8074-2066a386833d—
2026-09-29 02:26:58Zuser_logrep_relationship_certifiedrana.reyes@corvetasurgical.comVantis——Certification completed
2026-09-29 02:26:59Zcertification_certificateissuedrana.reyes@corvetasurgical.comVantis01a0eafc-9a28-78a1-b912-357c24cfdb65—
2026-09-29 02:26:59Zcertification_completion_recordissuedrana.reyes@corvetasurgical.comVantis01a0eafc-9a2b-708c-9bd8-16e676557758—
2026-09-29 02:27:01Zuser_loguser:loginrana.reyes@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:27:13Zdecisionbill_only_order.duplicate_submission_blockrana.reyes@corvetasurgical.comCorveta Surgical Groupfea7b8c9-d0e1-2345-0123-456789012345nono_same_day_candidates
2026-09-29 02:27:27Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisa1b2c3d4-e5f6-7890-abcd-ef1234567890nono_blocking_relationship
2026-09-29 02:27:27Zdecisionbill_only_order.inventory_items_decrementrana.reyes@corvetasurgical.comVantis01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2yesinventory_items_decremented
2026-09-29 02:27:27Zdecisionbill_only_order.direct_po_import_on_createrana.reyes@corvetasurgical.comVantis01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2noNo uploaded PO documents
2026-09-29 02:27:27Zbilling_orderstatus_changerana.reyes@corvetasurgical.comVantis01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2—
2026-09-29 02:27:27ZdecisionbasicErp.deriveSalesOrderrana.reyes@corvetasurgical.comVantis01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2noflag_disabled
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis01a0eafd-0c46-7466-8402-7d347ba2f96e—
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis01a0eafd-0c4a-7714-b545-9bcd8ac33a5f—
2026-09-29 02:27:27Zscheduled_taskscheduled_task.scheduledrana.reyes@corvetasurgical.comVantis01a0eafd-0c4d-745e-a2e6-2d9ad2b546b9—
2026-09-29 02:27:27Zdecisionbill_only.link_purchase_orderrana.reyes@corvetasurgical.comCorveta Surgical Group01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2nono_purchase_order_selected
2026-09-29 02:27:27Zdecisionbill_only_order.duplicate_submission_blockrana.reyes@corvetasurgical.comCorveta Surgical Groupfea7b8c9-d0e1-2345-0123-456789012345nono_same_day_candidates
2026-09-29 02:27:27Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisa1b2c3d4-e5f6-7890-abcd-ef1234567890nono_blocking_relationship
2026-09-29 02:27:28Zdecisionbill_only.notifications.cc_incident_recipients—Vantis01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2noorder has no no-charge item with an incident reason
2026-09-29 02:27:28Ztransactional_emailnew_bill_only—Corveta Surgical Group01a0eafd-0c1b-770f-8f1c-80b4c85d3fb2—
2026-09-29 02:28:03Zuser_loguser:loginrana.reyes@corvetasurgical.comCorveta Surgical Group——
2026-09-29 02:28:24Zdecisionorder_request_createdrana.reyes@corvetasurgical.comVantis01a0eafd-eacb-7a28-b19c-2d5dd0fa2596yesOrder request OR-2 created (importSource=manual)
2026-09-29 02:28:24Zchecklistchecklists.createrana.reyes@corvetasurgical.comVantis01a0eafd-ead8-7ebf-ad80-4d4ed7ee4bfc—
2026-09-29 02:28:24Zdecisionrepresentatives.gate_rep_actionrana.reyes@corvetasurgical.comVantisa1b2c3d4-e5f6-7890-abcd-ef1234567890nono_blocking_relationship

2 notification email(s) were captured during this test run. Each email is rendered as a screenshot for compliance review.

1. Your signing code for LiraLock Implant System Certification

Section titled “1. Your signing code for LiraLock Implant System Certification”

Template: Your_signing_code_for_LiraLock_Implant_System_Certification

Your signing code for LiraLock Implant System Certification

2. New Bill-Only Order - 9/28/2026 - Vantis BO-1

Section titled “2. New Bill-Only Order - 9/28/2026 - Vantis BO-1”

Template: New_Bill-Only_Order_-_9_28_2026_-_Vantis_BO-1

New Bill-Only Order - 9/28/2026 - Vantis BO-1