WI-059 · Platform & Contracts · scan-recovery

Scan recovery & salvage — orchestrator, cause-based matrix, retry/fallback (through P2), partial results

queued P1 medium risk   Owner: Paul   Reviewer: Mark Hilleary   0% · 0/1 tasks complete

Gates: P3 Requirements: Updated: 2026-06-22

At a glance

CodeWI-059
PhasePlatform & Contracts
Order20 of 93
Story points8
Primary surfaceScanRecoveryOrchestrator + recovery policy
Retires
Depends onOutput validation core — trust pipeline (stages 0–9, issue/receipt model, rule registry, deterministic repair, branded TrustedScanResult)
Blocks
Evidence
queued (P3 recovery)

Goals

Turn validation outcomes into bounded, audited recovery: deterministic repair, same-provider correction/clean retry, cross-provider fallback (executed through P2), and safe partial-result salvage — all attempt/cost/deadline-bounded with P8 authorization.

Implementation — what to build

Build (recovery)

  • ScanRecoveryOrchestrator; cause-based recovery matrix; recovery classes (no-call repair, same-provider correction/clean retry, fallback-provider via P2 exclusion list); partial-result policy registry; recovery-chain audit.

Limits + budget

  • max total/same-route/fallback attempts, cumulative cost, deadline; P8 budget authorization per billable attempt; stop_on valid retake / insufficient evidence / cancel / privacy block / budget exhausted.

Test

  • Mock P2 gateways: repair-succeeds, correction-succeeds, fallback-succeeds, all-fail, budget/deadline exhausted, privacy blocks fallback, retake stops retries. Live integration: valid item_scan/table_hunt/room_scan pass through P2+P3 with usage+cost.

Checklist

  • P3 Output pipeline (syntax -> schema -> enum -> coordinate -> business-rule validation) with retry/fallback policy is defined and tested.

Gates & testing

  • P3 Output pipeline (syntax -> schema -> enum -> coordinate -> business-rule validation) with retry/fallback policy is defined and tested.
    CODE TEST

Requirements

No linked requirements.

Verify (done when)

ScanRecoveryOrchestrator drives recovery by failure cause (cause-based matrix); retries + fallback executed THROUGH P2 (adapters never self-switch); partial-result policy registry emits explicit partial status with removed-nodes/limitations; every billable attempt P8-authorized; attempt/cost/deadline/privacy/cancellation limits enforced; valid retake/insufficient-evidence stop recovery; mock-gateway recovery tests + live integration pass. Per spec §26/§27 (recovery rows).

Cost triggers

No paid API / infra spend triggered by this item.

Status & editing

queued   Sprint: P&C Wave 3: Vision Pipeline & Cost

Edit status / sprint on the ★ Live Board → — changes are logged live with who / when / why.

Human-in-the-loop

No human tasks linked.

Findings

None recorded yet.

Concerns

None recorded yet.

Risks

None recorded yet.

Tech debt

None recorded yet.

Tools used

No tool calls recorded.

Files & artifacts

No files / artifacts recorded.

Update log

No log entries yet.