Multi-rooftop phase 2: inventory ownership and tracked transfers (Gitea #397) #668

Open
opened 2026-09-10 07:38:15 +00:00 by gambit-admin · 0 comments
Owner

Parent: Gitea #397 — Cards on the Harbor, Rockwall headquarters + Burleson branch.
Depends on: the headquarters/store-directory phase on codex/397-rooftop-locations.

Deliver a complete inventory-ownership and exact-copy transfer workflow before customer activation:

  • Add durable store ownership separately from shelf/bin location_code; tenant/store foreign keys prevent cross-account links.
  • Explicit audited initial stock enrollment. Unassigned stock stays visible; do not guess that all historic inventory belongs to HQ.
  • Scope all intake/import/buy/trade upserts and inventory grouping by store, so Rockwall A1 and Burleson A1 never merge.
  • Company/store availability including available, reserved, in-transit and unassigned buckets.
  • Owner-controlled request/reserve -> dispatch -> receive transfers, linked to destination customer demand when supplied. Before-dispatch cancel releases holds; after-dispatch exceptions require a recorded return or resolution.
  • Preserve GCN, acquisition date, effective original acquisition cost and provenance. Snapshot source aggregate cost when a copy uses fallback cost. No transfer revenue or changes to lifetime units sold.
  • Every stock writer must honor transfer reservations: canonical transactions, /sell/cart, legacy trade finalization, shows, inventory edits, imports, public reservations and POS webhooks. Explicitly reject unsupported legacy paths for enrolled accounts.
  • Stable lock ordering, expected versions and idempotency keys. Same exact unit cannot be transferred or sold concurrently.

Acceptance evidence: real PostgreSQL sale/transfer races; timeout/retry of dispatch and receipt moves stock once; quantity and acquisition-value conservation; source/destination and vendor permission checks; protected/listed/show-reserved stock rejected; before-dispatch cancellation and after-dispatch exceptions tested; usable owner transfer screen.

Initial pilot proposal: exact GCN inventory, all-or-nothing receipt, sale after receipt. Bulk/custom units, partial shipments and direct fulfillment before receipt are deferred unless Rudy makes them launch requirements. Attribution and staff-scope decisions remain for Rudy; the parent rollout plan records the recommended defaults.

Do not mark Gitea #397 or the customer pilot complete when only this phase is green. Checkout attribution, staff access and reporting remain a separate gate.

Gambit standard for every storefront business (Rudy, September 10, 2026)

This is the common Gambit account/location model for all storefronts we sign, from one store to 100 or more. Cards on the Harbor is the first customer rollout, not a special-case product. One Vendor owns all StoreLocation records, with one active HQ; no separate account per branch, numbered store columns, customer-name logic or fixed location-count ceiling.

The same operational paths must pass acceptance at one, two and 100 locations and remain isolated across business accounts. A directory-only 101-store check is not proof of 100-store inventory, permissions, checkout or reporting readiness. Record representative stock/staff/transaction volume, concurrent workload, response-time targets and measured results before making that capacity claim.

Source contract: docs/design/multi-rooftop-rollout.md on codex/397-rooftop-locations.

Scale acceptance: company/store availability must query within tenant and authorized stores with bounded pages and server-side summaries. Transfers reference source/destination directly; never configure every pair of stores. Test concurrent independent transfers and competing sale/transfer requests at 100 stores, including destinations beyond page one, shared shelf codes, stock/cost conservation and no permission leaks. A single-store business uses the same stock ownership model; expansion adds a branch without changing account type or moving existing stock.

Parent: Gitea #397 — Cards on the Harbor, Rockwall headquarters + Burleson branch. Depends on: the headquarters/store-directory phase on codex/397-rooftop-locations. Deliver a complete inventory-ownership and exact-copy transfer workflow before customer activation: - Add durable store ownership separately from shelf/bin location_code; tenant/store foreign keys prevent cross-account links. - Explicit audited initial stock enrollment. Unassigned stock stays visible; do not guess that all historic inventory belongs to HQ. - Scope all intake/import/buy/trade upserts and inventory grouping by store, so Rockwall A1 and Burleson A1 never merge. - Company/store availability including available, reserved, in-transit and unassigned buckets. - Owner-controlled request/reserve -> dispatch -> receive transfers, linked to destination customer demand when supplied. Before-dispatch cancel releases holds; after-dispatch exceptions require a recorded return or resolution. - Preserve GCN, acquisition date, effective original acquisition cost and provenance. Snapshot source aggregate cost when a copy uses fallback cost. No transfer revenue or changes to lifetime units sold. - Every stock writer must honor transfer reservations: canonical transactions, /sell/cart, legacy trade finalization, shows, inventory edits, imports, public reservations and POS webhooks. Explicitly reject unsupported legacy paths for enrolled accounts. - Stable lock ordering, expected versions and idempotency keys. Same exact unit cannot be transferred or sold concurrently. Acceptance evidence: real PostgreSQL sale/transfer races; timeout/retry of dispatch and receipt moves stock once; quantity and acquisition-value conservation; source/destination and vendor permission checks; protected/listed/show-reserved stock rejected; before-dispatch cancellation and after-dispatch exceptions tested; usable owner transfer screen. Initial pilot proposal: exact GCN inventory, all-or-nothing receipt, sale after receipt. Bulk/custom units, partial shipments and direct fulfillment before receipt are deferred unless Rudy makes them launch requirements. Attribution and staff-scope decisions remain for Rudy; the parent rollout plan records the recommended defaults. Do not mark Gitea #397 or the customer pilot complete when only this phase is green. Checkout attribution, staff access and reporting remain a separate gate. ## Gambit standard for every storefront business (Rudy, September 10, 2026) This is the common Gambit account/location model for all storefronts we sign, from one store to 100 or more. Cards on the Harbor is the first customer rollout, not a special-case product. One Vendor owns all StoreLocation records, with one active HQ; no separate account per branch, numbered store columns, customer-name logic or fixed location-count ceiling. The same operational paths must pass acceptance at one, two and 100 locations and remain isolated across business accounts. A directory-only 101-store check is not proof of 100-store inventory, permissions, checkout or reporting readiness. Record representative stock/staff/transaction volume, concurrent workload, response-time targets and measured results before making that capacity claim. Source contract: docs/design/multi-rooftop-rollout.md on codex/397-rooftop-locations. Scale acceptance: company/store availability must query within tenant and authorized stores with bounded pages and server-side summaries. Transfers reference source/destination directly; never configure every pair of stores. Test concurrent independent transfers and competing sale/transfer requests at 100 stores, including destinations beyond page one, shared shelf codes, stock/cost conservation and no permission leaks. A single-store business uses the same stock ownership model; expansion adds a branch without changing account type or moving existing stock.
gambit-admin added the featureuiapi labels 2026-09-10 07:38:15 +00:00
gambit-admin added the claimed:rudy2 label 2026-10-02 15:58:39 +00:00
Sign in to join this conversation.