Pricing HQ: add an immutable per-user pricing action ledger #716

Open
opened 2026-09-17 16:03:07 +00:00 by gambit-admin · 0 comments
Owner

Goal

Keep pricing strategies company-owned while permanently recording which individual Gambit user performed every pricing action.

Current state

Creation, versioning, approval, assignment, lock, temporary override, manual ASK change, alert creation and alert acknowledgement already store user IDs. Gaps remain: unlock/return-to-automatic clears current attribution; archive/restore, assignment end, alert edits and manual evaluation triggers do not consistently retain an actor.

Work

  • Add one append-only vendor-scoped pricing action ledger.
  • Record actor user ID, actor display snapshot, role, action type, entity type/id, before/after values, reason, idempotency/request ID and timestamp.
  • Record engine and scheduled actions with an explicit system actor.
  • Cover strategy create/version/approve/activate/archive/restore; assignment create/end; lock/unlock; override/expire; return to automatic; manual buy or sell adjustment; alert create/edit/disable/acknowledge; bulk preview/confirm/cancel/retry; and manual evaluation.
  • Preserve audit identity when a teammate is later deactivated or removed.
  • Keep current specialized tables and immutable approval records; the ledger unifies activity, it does not replace financial facts.
  • Add tenant and permission tests proving no cross-vendor reads or writes.

Acceptance criteria

  • Every pricing mutation produces exactly one replay-safe ledger action.
  • Unlocking or clearing an override never erases historical attribution.
  • Automatic engine activity is distinguishable from a human user.
  • Owners can retrieve their company history; staff/viewer visibility follows explicit permissions.
  • Strategies remain vendor-owned rather than becoming conflicting per-employee strategies.

Parent: #715. Program: #554.

## Goal Keep pricing strategies company-owned while permanently recording which individual Gambit user performed every pricing action. ## Current state Creation, versioning, approval, assignment, lock, temporary override, manual ASK change, alert creation and alert acknowledgement already store user IDs. Gaps remain: unlock/return-to-automatic clears current attribution; archive/restore, assignment end, alert edits and manual evaluation triggers do not consistently retain an actor. ## Work - Add one append-only vendor-scoped pricing action ledger. - Record actor user ID, actor display snapshot, role, action type, entity type/id, before/after values, reason, idempotency/request ID and timestamp. - Record engine and scheduled actions with an explicit system actor. - Cover strategy create/version/approve/activate/archive/restore; assignment create/end; lock/unlock; override/expire; return to automatic; manual buy or sell adjustment; alert create/edit/disable/acknowledge; bulk preview/confirm/cancel/retry; and manual evaluation. - Preserve audit identity when a teammate is later deactivated or removed. - Keep current specialized tables and immutable approval records; the ledger unifies activity, it does not replace financial facts. - Add tenant and permission tests proving no cross-vendor reads or writes. ## Acceptance criteria - Every pricing mutation produces exactly one replay-safe ledger action. - Unlocking or clearing an override never erases historical attribution. - Automatic engine activity is distinguishable from a human user. - Owners can retrieve their company history; staff/viewer visibility follows explicit permissions. - Strategies remain vendor-owned rather than becoming conflicting per-employee strategies. Parent: #715. Program: #554.
gambit-admin added the featureapi03 · pricing & value labels 2026-09-17 16:03:07 +00:00
Sign in to join this conversation.