WI-063 · Platform & Contracts · tracking-identity-ingestion

Tracking identity & ingestion physical (QR/aliases/bindings/labels/scans/checkout + P5 ingestion tables + promotion RPC + direct-write prevention + scan/validation storage)

queued P1 medium risk   Owner: Paul   Reviewer: Mark Hilleary   0% · 0/1 tasks complete

Gates: P6 Requirements: Updated: 2026-06-22
Evidence
queued (P6 identity+ingestion)

Goals

Physically realize the P5 one-door ingestion (tables + promotion RPC + grants that block direct canonical writes) and the first-class tracking-identity domain (QR/aliases/bindings/labels/scans/checkout), plus durable storage for the P3 scan/validation audit chain.

Implementation — what to build

Ingestion physical (P5)

  • Realize P5 tables + composite tenant FKs; promoteInventoryCandidate RPC (atomic, idempotent); connector/MCP/harness/buyer roles granted candidate+event writes only - direct canonical writes revoked + tested.

Tracking identity

  • qr_codes (opaque public_code), external_item_aliases (source: estatesail), item_identity_bindings + binding events (one-active-binding partial unique), label_batches/items, qr_scan_events, checkout_scan_events; resolve_public_qr returns buyer-safe projection.

Scan storage (P3)

  • scan_requests/provider_attempts/canonical_drafts/validation_receipts + recovery chain, append-only, tenant-scoped, replayable.

Checklist

  • P6 Data-model layers are consolidated (canonical, marketplace, seller-intelligence, tracking-identity, disposition, ingestion) with a documented RLS owner-scoped upgrade path.

Gates & testing

  • P6 Data-model layers are consolidated (canonical, marketplace, seller-intelligence, tracking-identity, disposition, ingestion) with a documented RLS owner-scoped upgrade path.
    CODE TEST HITL QA

Requirements

No linked requirements.

Verify (done when)

P5 tables (connections/runs/records/candidates/reviews/promotions/provenance/plugin_events) physical with promoteInventoryCandidate RPC as the only canonical writer + direct-write prevention tested; QR codes (opaque) / external_item_aliases (estatesail) / item_identity_bindings + history / label batches / qr+checkout scan events; P3 scan_requests/provider_attempts/canonical_drafts/validation_receipts append-only storage. Unblocks Spine. Per spec section 18-25, 61 #1.

Cost triggers

No paid API / infra spend triggered by this item.

Status & editing

queued   Sprint: P&C Wave 4: Data & Surfaces

Edit status / sprint on the ★ Live Board → — changes are logged live with who / when / why.

Human-in-the-loop

No human tasks linked.

Findings

None recorded yet.

Concerns

None recorded yet.

Risks

None recorded yet.

Tech debt

None recorded yet.

Tools used

No tool calls recorded.

Files & artifacts

No files / artifacts recorded.

Update log

No log entries yet.