{
  "edition": "PUPMKT Marketplace",
  "version": "1.0.27",
  "buildVersion": "1.0.27",
  "contractVersion": "2.28.0",
  "runtimeDefault": "standby",
  "generatedAt": null,
  "capabilities": [
    {
      "key": "accounts",
      "label": "Customer identity",
      "category": "Identity",
      "protocol": "OIDC or OAuth 2.1",
      "owner": "Partner identity team",
      "state": "contract-defined",
      "description": "Customer sign-in, session rotation, account ownership, and recovery.",
      "dependsOn": []
    },
    {
      "key": "employeeSso",
      "label": "Employee access",
      "category": "Identity",
      "protocol": "SAML or OIDC; LDAP stays server-side",
      "owner": "Partner identity and store operations",
      "state": "contract-defined",
      "description": "Role- and location-scoped employee sessions without exposing directory credentials to the browser.",
      "dependsOn": []
    },
    {
      "key": "privacyControls",
      "label": "Account privacy",
      "category": "Identity",
      "protocol": "PUPMKT owner-scoped privacy contract",
      "owner": "PUPMKT privacy operations and the connected identity provider",
      "state": "contract-defined",
      "description": "Verified account-closure requests, legal-hold boundaries, retention work, and provider-deletion coordination.",
      "dependsOn": [
        "accounts"
      ]
    },
    {
      "key": "liveCatalog",
      "label": "Catalog and media",
      "category": "Marketplace",
      "protocol": "PUPMKT REST adapter",
      "owner": "Partner commerce platform",
      "state": "contract-defined",
      "description": "Authoritative listings, inventory, pricing, evidence, and approved media.",
      "dependsOn": []
    },
    {
      "key": "partnerRetailInventory",
      "label": "Participating-store inventory",
      "category": "Store network",
      "protocol": "Signed inventory snapshots and PUPMKT retail projection",
      "owner": "Partner inventory and store systems",
      "state": "contract-defined",
      "description": "Eligible retail assortment, current location availability, approved prices, sales, and pickup or shipping options.",
      "dependsOn": [
        "liveCatalog"
      ]
    },
    {
      "key": "sellerInventory",
      "label": "Seller inventory",
      "category": "Marketplace",
      "protocol": "PUPMKT seller inventory contract",
      "owner": "Partner marketplace operations",
      "state": "contract-defined",
      "description": "Owner-scoped listing drafts, publication readiness, and seller inventory lifecycle.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "liveCart",
      "label": "Customer cart",
      "category": "Commerce",
      "protocol": "PUPMKT cart contract",
      "owner": "Partner commerce platform",
      "state": "contract-defined",
      "description": "Owner-scoped, versioned cart reads and item changes before checkout.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "customerMessaging",
      "label": "Marketplace messages",
      "category": "Accounts and trust",
      "protocol": "PUPMKT participant messaging contract",
      "owner": "Partner marketplace trust and support",
      "state": "contract-defined",
      "description": "Listing-scoped participant conversations, message reports, and contact blocking.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "customerSupport",
      "label": "Tracked customer support",
      "category": "Accounts and trust",
      "protocol": "PUPMKT customer-owned support contract",
      "owner": "Partner marketplace support",
      "state": "contract-defined",
      "description": "Customer-owned tickets, public replies, internal notes, governed routing, and L1/L2/L3 handoffs remain separate by audience.",
      "dependsOn": [
        "accounts",
        "employeeSso"
      ]
    },
    {
      "key": "trustSafety",
      "label": "Marketplace safety controls",
      "category": "Accounts and trust",
      "protocol": "PUPMKT owner-scoped trust contract",
      "owner": "Partner marketplace trust and support",
      "state": "contract-defined",
      "description": "Seller follows, account-level blocks, and protected listing or seller reports.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "liveBidding",
      "label": "Auctions and bids",
      "category": "Marketplace",
      "protocol": "PUPMKT command contract",
      "owner": "Partner commerce platform",
      "state": "contract-defined",
      "description": "Server-authoritative auction timing, eligibility, bid acceptance, and audit history.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "liveOffers",
      "label": "Offers",
      "category": "Marketplace",
      "protocol": "PUPMKT command contract",
      "owner": "Partner commerce platform",
      "state": "contract-defined",
      "description": "Versioned offers, counteroffers, expiry, and account authorization.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "liveCheckout",
      "label": "Payments and orders",
      "category": "Commerce",
      "protocol": "Hosted checkout and signed webhooks",
      "owner": "Partner payments, tax, and commerce teams",
      "state": "contract-defined",
      "description": "Server-priced checkout, payment finalization, tax, order creation, refunds, and disputes.",
      "dependsOn": [
        "accounts",
        "liveCatalog"
      ]
    },
    {
      "key": "sellerPayouts",
      "label": "Seller payouts",
      "category": "Commerce",
      "protocol": "Hosted onboarding and signed webhooks",
      "owner": "Partner finance and payout provider",
      "state": "contract-defined",
      "description": "Seller onboarding, holds, releases, reconciliation, and payout status.",
      "dependsOn": [
        "accounts",
        "liveCheckout"
      ]
    },
    {
      "key": "notificationCenter",
      "label": "Account notifications",
      "category": "Communications",
      "protocol": "PUPMKT owner-scoped notification contract",
      "owner": "Partner marketplace operations",
      "state": "contract-defined",
      "description": "Private in-app notification history, read state, and saved notification preferences.",
      "dependsOn": [
        "accounts"
      ]
    },
    {
      "key": "notifications",
      "label": "Outbound notifications",
      "category": "Communications",
      "protocol": "Server-side provider adapter",
      "owner": "Partner communications and compliance teams",
      "state": "contract-defined",
      "description": "Preference-aware email, text, and push delivery with bounce, complaint, and suppression handling.",
      "dependsOn": [
        "accounts",
        "notificationCenter"
      ]
    },
    {
      "key": "hubOperations",
      "label": "Store validation",
      "category": "Store network",
      "protocol": "Location-scoped operations API",
      "owner": "Partner store operations",
      "state": "contract-defined",
      "description": "Capability-tiered intake, evidence capture, item checks, and exception handling.",
      "dependsOn": [
        "employeeSso",
        "liveCatalog"
      ]
    },
    {
      "key": "securityLabels",
      "label": "Security labels and custody",
      "category": "Store network",
      "protocol": "Signed label and custody events",
      "owner": "Partner loss prevention and store operations",
      "state": "contract-defined",
      "description": "Tamper-evident label issuance, custody events, packing, and release evidence.",
      "dependsOn": [
        "hubOperations"
      ]
    },
    {
      "key": "managedShipping",
      "label": "Managed shipping",
      "category": "Store network",
      "protocol": "Carrier and custody adapters",
      "owner": "Partner logistics",
      "state": "contract-defined",
      "description": "Partner-approved labels, carrier events, packing evidence, and exception ownership.",
      "dependsOn": [
        "hubOperations",
        "securityLabels"
      ]
    },
    {
      "key": "pickupRelease",
      "label": "Store pickup release",
      "category": "Store network",
      "protocol": "Employee-authorized release command",
      "owner": "Partner store operations",
      "state": "contract-defined",
      "description": "Identity-checked pickup with scoped employee approval and immutable handoff evidence.",
      "dependsOn": [
        "employeeSso",
        "hubOperations",
        "securityLabels"
      ]
    },
    {
      "key": "digitalCatalog",
      "label": "Approved digital programs",
      "category": "Digital rights",
      "protocol": "Publisher program registry",
      "owner": "Partner publisher relations",
      "state": "contract-defined",
      "description": "Only publisher- or game-authorized transferable items can enter the marketplace.",
      "dependsOn": []
    },
    {
      "key": "digitalAccountLinks",
      "label": "Game account connections",
      "category": "Digital rights",
      "protocol": "Publisher-authorized account linking",
      "owner": "Partner identity and publisher teams",
      "state": "contract-defined",
      "description": "Consent, eligibility, ownership, and transfer-account checks stay authoritative.",
      "dependsOn": [
        "accounts",
        "digitalCatalog"
      ]
    },
    {
      "key": "digitalTransfers",
      "label": "Digital transfers",
      "category": "Digital rights",
      "protocol": "Official publisher transfer API",
      "owner": "Partner publisher relations and commerce teams",
      "state": "contract-defined",
      "description": "Settlement completes only after the official transfer is confirmed and reconciled.",
      "dependsOn": [
        "liveCheckout",
        "digitalCatalog",
        "digitalAccountLinks"
      ]
    }
  ],
  "disabledCapabilityPrerequisiteSchema": "pupmkt.production-capability-prerequisites/1",
  "disabledCapabilities": [
    {
      "id": "agent-a2a-publication",
      "title": "Agent A2A publication",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "agent-commerce-a2a-card-candidate",
        "agent-commerce-a2a-plan-adapter",
        "agent-commerce-a2a-runtime",
        "agent-commerce-public-artifact-candidate"
      ],
      "prerequisites": {
        "connector": {
          "id": "agent-a2a-publication.connector",
          "statement": "Approved agent identity, plan authority, task projection, card hosting, and protocol clients must pass A2A conformance."
        },
        "policy": {
          "id": "agent-a2a-publication.policy",
          "statement": "A2A skill publication, plan access, cancellation, human checkpoints, audit, revocation, and version policy must be approved."
        },
        "config": {
          "id": "agent-a2a-publication.config",
          "statement": "The unpublished runtime must retain empty public paths until identity, capability, card, interoperability, monitoring, and rollback gates pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Agent A2A publication is unavailable. Connector prerequisite: Approved agent identity, plan authority, task projection, card hosting, and protocol clients must pass A2A conformance. Policy prerequisite: A2A skill publication, plan access, cancellation, human checkpoints, audit, revocation, and version policy must be approved. Configuration prerequisite: The unpublished runtime must retain empty public paths until identity, capability, card, interoperability, monitoring, and rollback gates pass."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "agent-a2a-publication"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "agent-mcp-adapter",
      "title": "Agent commerce MCP adapter",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "agent-commerce-mcp-adapter",
        "agent-commerce-mcp-projection"
      ],
      "prerequisites": {
        "connector": {
          "id": "agent-mcp-adapter.connector",
          "statement": "Approved agent identity, capability, commerce, and audit services must pass MCP request and response conformance."
        },
        "policy": {
          "id": "agent-mcp-adapter.policy",
          "statement": "MCP tool publication, capability, approval, data minimization, rate, audit, and revocation policy must be approved."
        },
        "config": {
          "id": "agent-mcp-adapter.config",
          "statement": "Both enablement and approval controls must be true with an approved capability and origin set before composition."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Agent commerce MCP adapter is unavailable. Connector prerequisite: Approved agent identity, capability, commerce, and audit services must pass MCP request and response conformance. Policy prerequisite: MCP tool publication, capability, approval, data minimization, rate, audit, and revocation policy must be approved. Configuration prerequisite: Both enablement and approval controls must be true with an approved capability and origin set before composition."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "agent-mcp-adapter"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "agent-qualified-runtime",
      "title": "Qualified agent commerce runtime",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "agent-commerce-qualified-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "agent-qualified-runtime.connector",
          "statement": "Approved agent identity, authorization, catalog, cart, checkout, receipt, and policy services must pass protocol conformance."
        },
        "policy": {
          "id": "agent-qualified-runtime.policy",
          "statement": "Agent audience, mandate, capability, approval, receipt, accountability, revocation, and publication policy must be approved."
        },
        "config": {
          "id": "agent-qualified-runtime.config",
          "statement": "The isolated runtime must remain uncomposed until enablement, origin, identity, database, capability, and rollback checks pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Qualified agent commerce runtime is unavailable. Connector prerequisite: Approved agent identity, authorization, catalog, cart, checkout, receipt, and policy services must pass protocol conformance. Policy prerequisite: Agent audience, mandate, capability, approval, receipt, accountability, revocation, and publication policy must be approved. Configuration prerequisite: The isolated runtime must remain uncomposed until enablement, origin, identity, database, capability, and rollback checks pass."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "agent-qualified-runtime"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "agent-runtime-operations",
      "title": "Agent runtime operations",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "agent-commerce-plan-runner",
        "agent-commerce-receipt-signing-runner",
        "agent-dpop-replay-retention-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "agent-runtime-operations.connector",
          "statement": "Approved durable plan execution, receipt signing, replay retention, identity, and audit services must pass failure and recovery conformance."
        },
        "policy": {
          "id": "agent-runtime-operations.policy",
          "statement": "Agent execution, key custody, receipt issuance, replay retention, revocation, monitoring, and incident policy must be approved."
        },
        "config": {
          "id": "agent-runtime-operations.config",
          "statement": "Each separated runner must remain disabled until its exact role, provider, schedule, limits, monitoring, and rollback evidence pass review."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Agent runtime operations is unavailable. Connector prerequisite: Approved durable plan execution, receipt signing, replay retention, identity, and audit services must pass failure and recovery conformance. Policy prerequisite: Agent execution, key custody, receipt issuance, replay retention, revocation, monitoring, and incident policy must be approved. Configuration prerequisite: Each separated runner must remain disabled until its exact role, provider, schedule, limits, monitoring, and rollback evidence pass review."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "agent-runtime-operations"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "agent-ucp-publication",
      "title": "Agent UCP publication",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "agent-ucp-business-profile-candidate",
        "agent-ucp-cart-mcp-adapter",
        "agent-ucp-cart-rest-adapter",
        "agent-ucp-catalog-mcp-adapter",
        "agent-ucp-catalog-rest-adapter",
        "agent-ucp-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "agent-ucp-publication.connector",
          "statement": "Approved agent identity, catalog, cart, signature, profile, and capability services must pass UCP conformance."
        },
        "policy": {
          "id": "agent-ucp-publication.policy",
          "statement": "UCP profile, capability version, transport, signature, origin, cart handoff, publication, and revocation policy must be approved."
        },
        "config": {
          "id": "agent-ucp-publication.config",
          "statement": "Publication must remain off until enablement, approval, endpoint, origin, capability-version, identity, and rollback checks pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Agent UCP publication is unavailable. Connector prerequisite: Approved agent identity, catalog, cart, signature, profile, and capability services must pass UCP conformance. Policy prerequisite: UCP profile, capability version, transport, signature, origin, cart handoff, publication, and revocation policy must be approved. Configuration prerequisite: Publication must remain off until enablement, approval, endpoint, origin, capability-version, identity, and rollback checks pass."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "agent-ucp-publication"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "customer-accounts",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "commerce-maintenance",
      "title": "Commerce lifecycle maintenance",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "commerce-maintenance-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "commerce-maintenance.connector",
          "statement": "The authoritative commerce repository must pass checkout expiry, reservation release, auction restoration, concurrency, and recovery conformance."
        },
        "policy": {
          "id": "commerce-maintenance.policy",
          "statement": "Checkout expiry, inventory release, auction restoration, bounded batches, scheduling, alerting, and manual recovery policy must be approved."
        },
        "config": {
          "id": "commerce-maintenance.config",
          "statement": "The separated maintenance runner must remain disabled until its role, schedule, limits, monitoring, and rollback evidence pass review."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Commerce lifecycle maintenance is unavailable. Connector prerequisite: The authoritative commerce repository must pass checkout expiry, reservation release, auction restoration, concurrency, and recovery conformance. Policy prerequisite: Checkout expiry, inventory release, auction restoration, bounded batches, scheduling, alerting, and manual recovery policy must be approved. Configuration prerequisite: The separated maintenance runner must remain disabled until its role, schedule, limits, monitoring, and rollback evidence pass review."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "commerce-maintenance"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "customer-accounts",
      "title": "Customer accounts",
      "scope": "platform",
      "backendFeatures": [
        "accounts"
      ],
      "browserFeatures": [
        "accounts"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "customer-accounts.connector",
          "statement": "An approved customer identity service must pass sign-in, session revocation, step-up, and recovery conformance."
        },
        "policy": {
          "id": "customer-accounts.policy",
          "statement": "Customer access, assurance, recovery, suspension, and account-state policy must be approved."
        },
        "config": {
          "id": "customer-accounts.config",
          "statement": "A reviewed release must enable customer accounts only after identity readiness and rollback checks pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Customer accounts is unavailable. Connector prerequisite: An approved customer identity service must pass sign-in, session revocation, step-up, and recovery conformance. Policy prerequisite: Customer access, assurance, recovery, suspension, and account-state policy must be approved. Configuration prerequisite: A reviewed release must enable customer accounts only after identity readiness and rollback checks pass."
      },
      "disabledProbe": {
        "kind": "client-login",
        "target": "customer"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "customer-messaging",
      "title": "Customer messaging",
      "scope": "platform",
      "backendFeatures": [
        "customerMessaging"
      ],
      "browserFeatures": [
        "customerMessaging"
      ],
      "isolatedRuntimeIds": [
        "message-attachment-retention-runner",
        "message-attachment-scan-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "customer-messaging.connector",
          "statement": "Approved identity, moderation, attachment, notification, and message storage services must pass safety and delivery conformance."
        },
        "policy": {
          "id": "customer-messaging.policy",
          "statement": "Participant access, off-platform content, abuse, attachment, retention, block, and report policy must be approved."
        },
        "config": {
          "id": "customer-messaging.config",
          "statement": "A reviewed release must enable messaging only after identity, catalog, safety, storage, and notification readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Customer messaging is unavailable. Connector prerequisite: Approved identity, moderation, attachment, notification, and message storage services must pass safety and delivery conformance. Policy prerequisite: Participant access, off-platform content, abuse, attachment, retention, block, and report policy must be approved. Configuration prerequisite: A reviewed release must enable messaging only after identity, catalog, safety, storage, and notification readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/messages"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "customer-support",
      "title": "Customer support",
      "scope": "platform",
      "backendFeatures": [
        "customerSupport"
      ],
      "browserFeatures": [
        "customerSupport"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "customer-support.connector",
          "statement": "Approved identity, case, knowledge, notification, and action services must pass routing and lifecycle conformance."
        },
        "policy": {
          "id": "customer-support.policy",
          "statement": "Support scope, masking, queue, handoff, service level, customer action, escalation, and retention policy must be approved."
        },
        "config": {
          "id": "customer-support.config",
          "statement": "A reviewed release must enable support only after customer and workforce access, staffing, and monitoring readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Customer support is unavailable. Connector prerequisite: Approved identity, case, knowledge, notification, and action services must pass routing and lifecycle conformance. Policy prerequisite: Support scope, masking, queue, handoff, service level, customer action, escalation, and retention policy must be approved. Configuration prerequisite: A reviewed release must enable support only after customer and workforce access, staffing, and monitoring readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/support-tickets"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "digital-account-links",
      "title": "Digital account links",
      "scope": "platform",
      "backendFeatures": [
        "digitalAccountLinks"
      ],
      "browserFeatures": [
        "digitalAccountLinks"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "digital-account-links.connector",
          "statement": "An approved publisher authorization service must pass handoff, revocation, ownership, expiry, and recovery conformance."
        },
        "policy": {
          "id": "digital-account-links.policy",
          "statement": "Account eligibility, authorization scope, revocation, privacy, support, and prohibited credential-handling policy must be approved."
        },
        "config": {
          "id": "digital-account-links.config",
          "statement": "A reviewed release must enable account links only for approved programs, origins, scopes, and recovery paths."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Digital account links is unavailable. Connector prerequisite: An approved publisher authorization service must pass handoff, revocation, ownership, expiry, and recovery conformance. Policy prerequisite: Account eligibility, authorization scope, revocation, privacy, support, and prohibited credential-handling policy must be approved. Configuration prerequisite: A reviewed release must enable account links only for approved programs, origins, scopes, and recovery paths."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/digital/inventory"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "digital-programs",
      "title": "Digital programs and catalog",
      "scope": "platform",
      "backendFeatures": [
        "digitalPrograms"
      ],
      "browserFeatures": [
        "digitalCatalog"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "digital-programs.connector",
          "statement": "An approved publisher program and catalog source must pass authorization, eligibility, schema, and freshness conformance."
        },
        "policy": {
          "id": "digital-programs.policy",
          "statement": "Program, region, age, product, account, ownership, listing, and customer-disclosure policy must be approved."
        },
        "config": {
          "id": "digital-programs.config",
          "statement": "A reviewed release must select approved programs and enable the digital catalog only after publisher readiness passes."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Digital programs and catalog is unavailable. Connector prerequisite: An approved publisher program and catalog source must pass authorization, eligibility, schema, and freshness conformance. Policy prerequisite: Program, region, age, product, account, ownership, listing, and customer-disclosure policy must be approved. Configuration prerequisite: A reviewed release must select approved programs and enable the digital catalog only after publisher readiness passes."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/digital/programs"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "digital-transfers",
      "title": "Digital transfers",
      "scope": "platform",
      "backendFeatures": [
        "digitalTransfers"
      ],
      "browserFeatures": [
        "digitalTransfers"
      ],
      "isolatedRuntimeIds": [
        "digital-payment-capture-runner",
        "digital-payment-recovery-action-runner",
        "digital-payment-recovery-lookup-runner",
        "digital-payment-settlement-runner",
        "digital-publisher-recovery-action-runner",
        "digital-publisher-recovery-lookup-runner",
        "digital-publisher-settlement-runner",
        "digital-publisher-webhook-runtime",
        "digital-recovery-reconciliation-runner",
        "digital-settlement-reconciliation-runner",
        "digital-transfer-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "digital-transfers.connector",
          "statement": "Approved publisher transfer, payment, notification, and reconciliation services must pass completed, failed, and unknown conformance."
        },
        "policy": {
          "id": "digital-transfers.policy",
          "statement": "Ownership, transfer eligibility, payment, compensation, refund, recovery, support, and customer-disclosure policy must be approved."
        },
        "config": {
          "id": "digital-transfers.config",
          "statement": "A reviewed release must enable digital transfers only after program, account-link, checkout, recovery, and settlement readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Digital transfers is unavailable. Connector prerequisite: Approved publisher transfer, payment, notification, and reconciliation services must pass completed, failed, and unknown conformance. Policy prerequisite: Ownership, transfer eligibility, payment, compensation, refund, recovery, support, and customer-disclosure policy must be approved. Configuration prerequisite: A reviewed release must enable digital transfers only after program, account-link, checkout, recovery, and settlement readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/digital/listings"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "finance-reconciliation",
      "title": "Finance reconciliation",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "finance-reconciliation-runner",
        "payment-dispute-application-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "finance-reconciliation.connector",
          "statement": "Approved ledger, payment-provider, settlement, dispute-evidence, and reconciliation sources must pass window, duplicate, unknown-state, and recovery conformance."
        },
        "policy": {
          "id": "finance-reconciliation.policy",
          "statement": "Reconciliation and dispute windows, delay, mismatch ownership, evidence, correction, escalation, retention, and duty-separation policy must be approved."
        },
        "config": {
          "id": "finance-reconciliation.config",
          "statement": "Separated reconciliation and dispute-projection runners must remain disabled until provider, role, schedule, limits, monitoring, and rollback evidence pass review."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Finance reconciliation is unavailable. Connector prerequisite: Approved ledger, payment-provider, settlement, dispute-evidence, and reconciliation sources must pass window, duplicate, unknown-state, and recovery conformance. Policy prerequisite: Reconciliation and dispute windows, delay, mismatch ownership, evidence, correction, escalation, retention, and duty-separation policy must be approved. Configuration prerequisite: Separated reconciliation and dispute-projection runners must remain disabled until provider, role, schedule, limits, monitoring, and rollback evidence pass review."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "finance-reconciliation"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "hub-operations",
      "title": "Store and hub operations",
      "scope": "platform",
      "backendFeatures": [],
      "browserFeatures": [
        "hubOperations"
      ],
      "isolatedRuntimeIds": [
        "store-offline-continuity-worker"
      ],
      "prerequisites": {
        "connector": {
          "id": "hub-operations.connector",
          "statement": "Approved store task, inventory, evidence, custody, transfer, and exception sources must pass scoped conformance."
        },
        "policy": {
          "id": "hub-operations.policy",
          "statement": "Store assignment, training, evidence, custody, transfer, exception, reconciliation, and duty-separation policy must be approved."
        },
        "config": {
          "id": "hub-operations.config",
          "statement": "A reviewed release must enable hub operations only for approved locations, roles, devices, queues, and recovery paths."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Store and hub operations is unavailable. Connector prerequisite: Approved store task, inventory, evidence, custody, transfer, and exception sources must pass scoped conformance. Policy prerequisite: Store assignment, training, evidence, custody, transfer, exception, reconciliation, and duty-separation policy must be approved. Configuration prerequisite: A reviewed release must enable hub operations only for approved locations, roles, devices, queues, and recovery paths."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "hub.intake.create",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "live-bidding",
      "title": "Live bidding",
      "scope": "platform",
      "backendFeatures": [
        "liveBidding"
      ],
      "browserFeatures": [
        "liveBidding"
      ],
      "isolatedRuntimeIds": [
        "auction-maintenance-function",
        "auction-maintenance-runner",
        "commerce-collusion-controller"
      ],
      "prerequisites": {
        "connector": {
          "id": "live-bidding.connector",
          "statement": "Authoritative auction, eligibility, notification, checkout, and maintenance services must pass ordering and concurrency conformance."
        },
        "policy": {
          "id": "live-bidding.policy",
          "statement": "Bid eligibility, increment, proxy, tie, reserve, extension, close, cancellation, and settlement policy must be approved."
        },
        "config": {
          "id": "live-bidding.config",
          "statement": "A reviewed release must enable bidding only after auction publication, maintenance, checkout, and rollback gates pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Live bidding is unavailable. Connector prerequisite: Authoritative auction, eligibility, notification, checkout, and maintenance services must pass ordering and concurrency conformance. Policy prerequisite: Bid eligibility, increment, proxy, tie, reserve, extension, close, cancellation, and settlement policy must be approved. Configuration prerequisite: A reviewed release must enable bidding only after auction publication, maintenance, checkout, and rollback gates pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "auction.bid",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "live-cart",
      "title": "Live customer cart",
      "scope": "platform",
      "backendFeatures": [
        "liveCart"
      ],
      "browserFeatures": [
        "liveCart"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "live-cart.connector",
          "statement": "An authoritative cart and inventory service must pass ownership, pricing, version, expiry, and concurrency conformance."
        },
        "policy": {
          "id": "live-cart.policy",
          "statement": "Cart eligibility, quantity, reservation, pricing, expiry, and customer-disclosure policy must be approved."
        },
        "config": {
          "id": "live-cart.config",
          "statement": "A reviewed release must enable live cart writes only after account, catalog, and cart readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Live customer cart is unavailable. Connector prerequisite: An authoritative cart and inventory service must pass ownership, pricing, version, expiry, and concurrency conformance. Policy prerequisite: Cart eligibility, quantity, reservation, pricing, expiry, and customer-disclosure policy must be approved. Configuration prerequisite: A reviewed release must enable live cart writes only after account, catalog, and cart readiness pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "cart.add",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "live-catalog",
      "title": "Live catalog",
      "scope": "platform",
      "backendFeatures": [
        "liveCatalog"
      ],
      "browserFeatures": [
        "liveCatalog"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "live-catalog.connector",
          "statement": "An authoritative catalog source must pass schema, freshness, reconciliation, and removal conformance."
        },
        "policy": {
          "id": "live-catalog.policy",
          "statement": "Catalog publication, restricted-item, evidence, and removal policy must be approved."
        },
        "config": {
          "id": "live-catalog.config",
          "statement": "A reviewed release must select the authoritative catalog and enable live catalog reads only after readiness passes."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Live catalog is unavailable. Connector prerequisite: An authoritative catalog source must pass schema, freshness, reconciliation, and removal conformance. Policy prerequisite: Catalog publication, restricted-item, evidence, and removal policy must be approved. Configuration prerequisite: A reviewed release must select the authoritative catalog and enable live catalog reads only after readiness passes."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/listings"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-session",
        "target": "/session",
        "expectation": "customer-account-session-remains-readable"
      }
    },
    {
      "id": "live-checkout",
      "title": "Live checkout",
      "scope": "platform",
      "backendFeatures": [
        "liveCheckout"
      ],
      "browserFeatures": [
        "liveCheckout"
      ],
      "isolatedRuntimeIds": [
        "return-logistics-runner",
        "return-refund-execution-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "live-checkout.connector",
          "statement": "Approved inventory, tax, shipping, payment, and order services must pass idempotency, timeout, and reconciliation conformance."
        },
        "policy": {
          "id": "live-checkout.policy",
          "statement": "Checkout eligibility, totals, payment, fulfillment, cancellation, refund, and recovery policy must be approved."
        },
        "config": {
          "id": "live-checkout.config",
          "statement": "A reviewed release must enable checkout only after every required provider and rollback gate passes."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Live checkout is unavailable. Connector prerequisite: Approved inventory, tax, shipping, payment, and order services must pass idempotency, timeout, and reconciliation conformance. Policy prerequisite: Checkout eligibility, totals, payment, fulfillment, cancellation, refund, and recovery policy must be approved. Configuration prerequisite: A reviewed release must enable checkout only after every required provider and rollback gate passes."
      },
      "disabledProbe": {
        "kind": "client-checkout",
        "target": "checkout",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "live-offers",
      "title": "Live offers",
      "scope": "platform",
      "backendFeatures": [
        "liveOffers"
      ],
      "browserFeatures": [
        "liveOffers"
      ],
      "isolatedRuntimeIds": [
        "offer-maintenance-function",
        "offer-maintenance-handler"
      ],
      "prerequisites": {
        "connector": {
          "id": "live-offers.connector",
          "statement": "Authoritative listing, inventory, notification, checkout, and maintenance services must pass offer lifecycle conformance."
        },
        "policy": {
          "id": "live-offers.policy",
          "statement": "Offer eligibility, minimums, expiry, counter, acceptance, release, cancellation, and communication policy must be approved."
        },
        "config": {
          "id": "live-offers.config",
          "statement": "A reviewed release must enable offers and their maintenance process only after readiness and recovery pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Live offers is unavailable. Connector prerequisite: Authoritative listing, inventory, notification, checkout, and maintenance services must pass offer lifecycle conformance. Policy prerequisite: Offer eligibility, minimums, expiry, counter, acceptance, release, cancellation, and communication policy must be approved. Configuration prerequisite: A reviewed release must enable offers and their maintenance process only after readiness and recovery pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "offer.create",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "managed-shipping",
      "title": "Managed store shipping",
      "scope": "platform",
      "backendFeatures": [],
      "browserFeatures": [
        "managedShipping"
      ],
      "isolatedRuntimeIds": [
        "carrier-webhook-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "managed-shipping.connector",
          "statement": "Approved task, packing, carrier, label, tracking, evidence, and reconciliation services must pass conformance."
        },
        "policy": {
          "id": "managed-shipping.policy",
          "statement": "Packing, custody, carrier handoff, loss, damage, exception, cancellation, and recovery policy must be approved."
        },
        "config": {
          "id": "managed-shipping.config",
          "statement": "A reviewed release must enable managed shipping only for approved stores, carriers, roles, devices, and monitored workers."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Managed store shipping is unavailable. Connector prerequisite: Approved task, packing, carrier, label, tracking, evidence, and reconciliation services must pass conformance. Policy prerequisite: Packing, custody, carrier handoff, loss, damage, exception, cancellation, and recovery policy must be approved. Configuration prerequisite: A reviewed release must enable managed shipping only for approved stores, carriers, roles, devices, and monitored workers."
      },
      "disabledProbe": {
        "kind": "client-request",
        "target": "/staff/fulfillment-tasks/123e4567-e89b-42d3-a456-426614174000/packing",
        "method": "POST",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "notification-center",
      "title": "Notification center",
      "scope": "platform",
      "backendFeatures": [
        "notificationCenter"
      ],
      "browserFeatures": [
        "notificationCenter"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "notification-center.connector",
          "statement": "An authoritative notification record service must pass owner scoping, pagination, read-state, and degradation conformance."
        },
        "policy": {
          "id": "notification-center.policy",
          "statement": "Notification visibility, preference, suppression, retention, and customer-control policy must be approved."
        },
        "config": {
          "id": "notification-center.config",
          "statement": "A reviewed release must enable the notification center only after account and notification-record readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Notification center is unavailable. Connector prerequisite: An authoritative notification record service must pass owner scoping, pagination, read-state, and degradation conformance. Policy prerequisite: Notification visibility, preference, suppression, retention, and customer-control policy must be approved. Configuration prerequisite: A reviewed release must enable the notification center only after account and notification-record readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/notifications"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "operations-audit",
      "title": "Operations audit persistence",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "operations-audit-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "operations-audit.connector",
          "statement": "Approved isolated append-only audit storage and trusted time sources must pass integrity, retention, backup, and recovery conformance."
        },
        "policy": {
          "id": "operations-audit.policy",
          "statement": "Audit minimization, retention, access, export, incident review, key custody, and legal policy must be approved."
        },
        "config": {
          "id": "operations-audit.config",
          "statement": "The digest-only audit runtime must remain disabled until M176, binding, worker role, retention, trusted time, monitoring, and rollback evidence pass review."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Operations audit persistence is unavailable. Connector prerequisite: Approved isolated append-only audit storage and trusted time sources must pass integrity, retention, backup, and recovery conformance. Policy prerequisite: Audit minimization, retention, access, export, incident review, key custody, and legal policy must be approved. Configuration prerequisite: The digest-only audit runtime must remain disabled until M176, binding, worker role, retention, trusted time, monitoring, and rollback evidence pass review."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "operations-audit"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "partner-catalog-bootstrap",
      "title": "Partner catalog bootstrap",
      "scope": "platform",
      "backendFeatures": [
        "partnerCatalogBootstrap"
      ],
      "browserFeatures": [],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "partner-catalog-bootstrap.connector",
          "statement": "An approved bootstrap source must provide deterministic catalog identifiers, mappings, and reconciliation totals."
        },
        "policy": {
          "id": "partner-catalog-bootstrap.policy",
          "statement": "Bootstrap ownership, correction, rejection, and authoritative-source policy must be approved."
        },
        "config": {
          "id": "partner-catalog-bootstrap.config",
          "statement": "A reviewed one-purpose bootstrap configuration must be enabled only for an owned import window with rollback evidence."
        }
      },
      "disabledBehavior": {
        "errorCode": "BACKEND_NOT_CONFIGURED",
        "retryable": false,
        "message": "Partner catalog bootstrap is unavailable. Connector prerequisite: An approved bootstrap source must provide deterministic catalog identifiers, mappings, and reconciliation totals. Policy prerequisite: Bootstrap ownership, correction, rejection, and authoritative-source policy must be approved. Configuration prerequisite: A reviewed one-purpose bootstrap configuration must be enabled only for an owned import window with rollback evidence."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "partner-catalog-bootstrap"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "customer-accounts",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "partner-retail-inventory",
      "title": "Partner retail inventory",
      "scope": "platform",
      "backendFeatures": [
        "partnerRetailInventory"
      ],
      "browserFeatures": [
        "partnerRetailInventory"
      ],
      "isolatedRuntimeIds": [
        "retail-reservation-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "partner-retail-inventory.connector",
          "statement": "An approved retail inventory source must pass signed snapshot, store mapping, freshness, duplicate, and reconciliation conformance."
        },
        "policy": {
          "id": "partner-retail-inventory.policy",
          "statement": "Store eligibility, availability wording, reservation, pickup, and stale-inventory policy must be approved."
        },
        "config": {
          "id": "partner-retail-inventory.config",
          "statement": "A reviewed connection and release configuration must enable retail inventory only after source and worker readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Partner retail inventory is unavailable. Connector prerequisite: An approved retail inventory source must pass signed snapshot, store mapping, freshness, duplicate, and reconciliation conformance. Policy prerequisite: Store eligibility, availability wording, reservation, pickup, and stale-inventory policy must be approved. Configuration prerequisite: A reviewed connection and release configuration must enable retail inventory only after source and worker readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/hubs"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "pickup-release",
      "title": "Protected pickup release",
      "scope": "platform",
      "backendFeatures": [],
      "browserFeatures": [
        "pickupRelease"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "pickup-release.connector",
          "statement": "Approved order, pickup task, challenge, release, notification, and custody services must pass conformance."
        },
        "policy": {
          "id": "pickup-release.policy",
          "statement": "Pickup eligibility, minimum disclosure, challenge, step-up, denial, expiry, no-show, cancellation, and appeal policy must be approved."
        },
        "config": {
          "id": "pickup-release.config",
          "statement": "A reviewed release must enable pickup release only for approved locations, trained roles, devices, and current tasks."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Protected pickup release is unavailable. Connector prerequisite: Approved order, pickup task, challenge, release, notification, and custody services must pass conformance. Policy prerequisite: Pickup eligibility, minimum disclosure, challenge, step-up, denial, expiry, no-show, cancellation, and appeal policy must be approved. Configuration prerequisite: A reviewed release must enable pickup release only for approved locations, trained roles, devices, and current tasks."
      },
      "disabledProbe": {
        "kind": "client-request",
        "target": "/staff/fulfillment-tasks/123e4567-e89b-42d3-a456-426614174000/pickup-release",
        "method": "POST",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "privacy-controls",
      "title": "Customer privacy controls",
      "scope": "platform",
      "backendFeatures": [
        "privacyControls"
      ],
      "browserFeatures": [
        "privacyControls"
      ],
      "isolatedRuntimeIds": [
        "privacy-retention-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "privacy-controls.connector",
          "statement": "Approved identity, secure-delivery, and deletion providers must pass request, export, erasure, and failure conformance."
        },
        "policy": {
          "id": "privacy-controls.policy",
          "statement": "Privacy request, verification, retention, legal-hold, delivery, and appeal policy must be approved."
        },
        "config": {
          "id": "privacy-controls.config",
          "statement": "A reviewed release must enable privacy controls only after worker, retention, and secure-delivery readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Customer privacy controls is unavailable. Connector prerequisite: Approved identity, secure-delivery, and deletion providers must pass request, export, erasure, and failure conformance. Policy prerequisite: Privacy request, verification, retention, legal-hold, delivery, and appeal policy must be approved. Configuration prerequisite: A reviewed release must enable privacy controls only after worker, retention, and secure-delivery readiness pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "account.closure.request",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "seller-inventory",
      "title": "Seller inventory",
      "scope": "platform",
      "backendFeatures": [
        "sellerInventory"
      ],
      "browserFeatures": [
        "sellerInventory"
      ],
      "isolatedRuntimeIds": [
        "seller-media-maintenance-function"
      ],
      "prerequisites": {
        "connector": {
          "id": "seller-inventory.connector",
          "statement": "Approved seller identity, media, catalog, and inventory services must pass lifecycle and reconciliation conformance."
        },
        "policy": {
          "id": "seller-inventory.policy",
          "statement": "Seller eligibility, listing publication, media, prohibited-item, fee, and inventory policy must be approved."
        },
        "config": {
          "id": "seller-inventory.config",
          "statement": "A reviewed release must enable seller inventory only after account, catalog, media, and publication readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Seller inventory is unavailable. Connector prerequisite: Approved seller identity, media, catalog, and inventory services must pass lifecycle and reconciliation conformance. Policy prerequisite: Seller eligibility, listing publication, media, prohibited-item, fee, and inventory policy must be approved. Configuration prerequisite: A reviewed release must enable seller inventory only after account, catalog, media, and publication readiness pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "listing.create",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "seller-payouts",
      "title": "Seller payouts",
      "scope": "platform",
      "backendFeatures": [
        "sellerPayouts"
      ],
      "browserFeatures": [
        "sellerPayouts"
      ],
      "isolatedRuntimeIds": [
        "payout-delivery-runner",
        "seller-payout-task-connector",
        "seller-payout-webhook-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "seller-payouts.connector",
          "statement": "Approved payout onboarding, ledger, task-intake, and payout providers must pass duplicate, timeout, and reconciliation conformance."
        },
        "policy": {
          "id": "seller-payouts.policy",
          "statement": "Seller eligibility, reserves, holds, fees, payout timing, failure, and appeal policy must be approved."
        },
        "config": {
          "id": "seller-payouts.config",
          "statement": "A reviewed release must bind the isolated payout workers and enable payouts only after readiness and rollback pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Seller payouts is unavailable. Connector prerequisite: Approved payout onboarding, ledger, task-intake, and payout providers must pass duplicate, timeout, and reconciliation conformance. Policy prerequisite: Seller eligibility, reserves, holds, fees, payout timing, failure, and appeal policy must be approved. Configuration prerequisite: A reviewed release must bind the isolated payout workers and enable payouts only after readiness and rollback pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "payout.onboarding.create",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "store-ops-inventory-ingress",
      "title": "Store operations inventory ingress",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "store-fulfillment-task-connector",
        "store-intake-reservation-connector",
        "store-ops-inventory-route-core",
        "store-ops-inventory-runtime",
        "store-security-label-inventory-connector"
      ],
      "prerequisites": {
        "connector": {
          "id": "store-ops-inventory-ingress.connector",
          "statement": "Approved signed reservation, label-inventory, and fulfillment-task sources must pass purpose, replay, sequence, timeout, and reconciliation conformance."
        },
        "policy": {
          "id": "store-ops-inventory-ingress.policy",
          "statement": "Reservation, security-label, custody, packing, pickup, fulfillment, exception, and retention policy must be approved."
        },
        "config": {
          "id": "store-ops-inventory-ingress.config",
          "statement": "Each isolated purpose needs separate enablement and approval plus worker binding, key rotation, monitoring, and rollback evidence."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Store operations inventory ingress is unavailable. Connector prerequisite: Approved signed reservation, label-inventory, and fulfillment-task sources must pass purpose, replay, sequence, timeout, and reconciliation conformance. Policy prerequisite: Reservation, security-label, custody, packing, pickup, fulfillment, exception, and retention policy must be approved. Configuration prerequisite: Each isolated purpose needs separate enablement and approval plus worker binding, key rotation, monitoring, and rollback evidence."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "store-ops-inventory-ingress"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "store-security-labels",
      "title": "Store security labels",
      "scope": "platform",
      "backendFeatures": [],
      "browserFeatures": [
        "securityLabels"
      ],
      "isolatedRuntimeIds": [],
      "prerequisites": {
        "connector": {
          "id": "store-security-labels.connector",
          "statement": "Approved label inventory, assignment, scan, state, and reconciliation sources must pass signed conformance."
        },
        "policy": {
          "id": "store-security-labels.policy",
          "statement": "Label eligibility, activation, break, replacement, evidence, disclosure, and exception policy must be approved."
        },
        "config": {
          "id": "store-security-labels.config",
          "statement": "A reviewed release must enable label actions only for approved stores, trained roles, devices, and current inventory."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Store security labels is unavailable. Connector prerequisite: Approved label inventory, assignment, scan, state, and reconciliation sources must pass signed conformance. Policy prerequisite: Label eligibility, activation, break, replacement, evidence, disclosure, and exception policy must be approved. Configuration prerequisite: A reviewed release must enable label actions only for approved stores, trained roles, devices, and current inventory."
      },
      "disabledProbe": {
        "kind": "client-request",
        "target": "/staff/items/123e4567-e89b-42d3-a456-426614174000/labels",
        "method": "POST",
        "payload": {}
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "store-transfer-exception-ingress",
      "title": "Store transfer exception ingress",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "store-transfer-exception-connector"
      ],
      "prerequisites": {
        "connector": {
          "id": "store-transfer-exception-ingress.connector",
          "statement": "An approved signed transfer-exception source must pass identity, replay, sequence, evidence, timeout, and recovery conformance."
        },
        "policy": {
          "id": "store-transfer-exception-ingress.policy",
          "statement": "Transfer exception reporting, review, approval, duty separation, quarantine, recovery, and retention policy must be approved."
        },
        "config": {
          "id": "store-transfer-exception-ingress.config",
          "statement": "The isolated route must remain absent until source approval, key rotation, worker binding, monitoring, and rollback pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Store transfer exception ingress is unavailable. Connector prerequisite: An approved signed transfer-exception source must pass identity, replay, sequence, evidence, timeout, and recovery conformance. Policy prerequisite: Transfer exception reporting, review, approval, duty separation, quarantine, recovery, and retention policy must be approved. Configuration prerequisite: The isolated route must remain absent until source approval, key rotation, worker binding, monitoring, and rollback pass."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "store-transfer-exception-ingress"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "store-validation-ingress",
      "title": "Store validation policy and task ingress",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "store-validation-policy-connector",
        "store-validation-route-core",
        "store-validation-runtime",
        "store-validation-task-connector"
      ],
      "prerequisites": {
        "connector": {
          "id": "store-validation-ingress.connector",
          "statement": "Approved signed validation policy and task sources must pass purpose, replay, sequence, freshness, timeout, and reconciliation conformance."
        },
        "policy": {
          "id": "store-validation-ingress.policy",
          "statement": "Category certification, checklist, evidence, task assignment, result, exception, and retention policy must be approved."
        },
        "config": {
          "id": "store-validation-ingress.config",
          "statement": "Each isolated purpose needs separate enablement and approval plus worker binding, key rotation, monitoring, and rollback evidence."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Store validation policy and task ingress is unavailable. Connector prerequisite: Approved signed validation policy and task sources must pass purpose, replay, sequence, freshness, timeout, and reconciliation conformance. Policy prerequisite: Category certification, checklist, evidence, task assignment, result, exception, and retention policy must be approved. Configuration prerequisite: Each isolated purpose needs separate enablement and approval plus worker binding, key rotation, monitoring, and rollback evidence."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "store-validation-ingress"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "transactional-notifications",
      "title": "Transactional notification delivery",
      "scope": "platform",
      "backendFeatures": [
        "transactionalNotifications"
      ],
      "browserFeatures": [
        "notifications"
      ],
      "isolatedRuntimeIds": [
        "notification-delivery-runner",
        "notification-feedback-composition",
        "notification-feedback-runtime"
      ],
      "prerequisites": {
        "connector": {
          "id": "transactional-notifications.connector",
          "statement": "Approved template, task-intake, delivery, and feedback providers must pass idempotency, quota, failure, and suppression conformance."
        },
        "policy": {
          "id": "transactional-notifications.policy",
          "statement": "Template purpose, minimum data, destination ownership, cadence, suppression, retention, and incident policy must be approved."
        },
        "config": {
          "id": "transactional-notifications.config",
          "statement": "A reviewed release must bind isolated notification workers and enable delivery only after readiness and monitoring pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Transactional notification delivery is unavailable. Connector prerequisite: Approved template, task-intake, delivery, and feedback providers must pass idempotency, quota, failure, and suppression conformance. Policy prerequisite: Template purpose, minimum data, destination ownership, cadence, suppression, retention, and incident policy must be approved. Configuration prerequisite: A reviewed release must bind isolated notification workers and enable delivery only after readiness and monitoring pass."
      },
      "disabledProbe": {
        "kind": "client-command",
        "target": "search.update",
        "payload": {
          "alertCadence": "daily"
        }
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "transactional-outbox-delivery",
      "title": "Transactional outbox delivery",
      "scope": "isolated-ingress",
      "backendFeatures": [],
      "browserFeatures": [],
      "isolatedRuntimeIds": [
        "outbox-delivery-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "transactional-outbox-delivery.connector",
          "statement": "An approved event delivery provider and authoritative outbox must pass claim, delivery, retry, dead-letter, duplicate, and recovery conformance."
        },
        "policy": {
          "id": "transactional-outbox-delivery.policy",
          "statement": "Event purpose, destination, minimum data, retry, dead-letter, suppression, retention, monitoring, and incident policy must be approved."
        },
        "config": {
          "id": "transactional-outbox-delivery.config",
          "statement": "The separated delivery runner must remain disabled until provider, role, schedule, limits, monitoring, and rollback evidence pass review."
        }
      },
      "disabledBehavior": {
        "errorCode": "CAPABILITY_NOT_CONNECTED",
        "retryable": false,
        "message": "Transactional outbox delivery is unavailable. Connector prerequisite: An approved event delivery provider and authoritative outbox must pass claim, delivery, retry, dead-letter, duplicate, and recovery conformance. Policy prerequisite: Event purpose, destination, minimum data, retry, dead-letter, suppression, retention, monitoring, and incident policy must be approved. Configuration prerequisite: The separated delivery runner must remain disabled until provider, role, schedule, limits, monitoring, and rollback evidence pass review."
      },
      "disabledProbe": {
        "kind": "source-contract",
        "target": "transactional-outbox-delivery"
      },
      "safeUnaffectedProbe": {
        "kind": "independent-capability",
        "target": "public-catalog",
        "expectation": "retains-own-readiness"
      }
    },
    {
      "id": "trust-safety",
      "title": "Trust and safety controls",
      "scope": "platform",
      "backendFeatures": [
        "trustSafety"
      ],
      "browserFeatures": [
        "trustSafety"
      ],
      "isolatedRuntimeIds": [
        "moderation-lifecycle-evidence-runtime",
        "moderation-lifecycle-v2-application-command"
      ],
      "prerequisites": {
        "connector": {
          "id": "trust-safety.connector",
          "statement": "Approved case, moderation, risk, notice, and appeal services must pass authorization and lifecycle conformance."
        },
        "policy": {
          "id": "trust-safety.policy",
          "statement": "Report, enforcement, evidence, notice, restriction, restoration, and independent appeal policy must be approved."
        },
        "config": {
          "id": "trust-safety.config",
          "statement": "A reviewed release must enable trust controls only after staffed queues, audit, notices, and escalation readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Trust and safety controls is unavailable. Connector prerequisite: Approved case, moderation, risk, notice, and appeal services must pass authorization and lifecycle conformance. Policy prerequisite: Report, enforcement, evidence, notice, restriction, restoration, and independent appeal policy must be approved. Configuration prerequisite: A reviewed release must enable trust controls only after staffed queues, audit, notices, and escalation readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/followed-sellers"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    },
    {
      "id": "workforce-identity",
      "title": "Workforce identity and governance",
      "scope": "platform",
      "backendFeatures": [
        "workforceOperations"
      ],
      "browserFeatures": [
        "employeeSso"
      ],
      "isolatedRuntimeIds": [
        "workforce-agent-client-handler",
        "workforce-iam-assignment-principal-projection-runner",
        "workforce-iam-assignment-principal-projection-worker",
        "workforce-iam-assignment-runtime",
        "workforce-iam-fulfillment-runner",
        "workforce-iam-revocation-convergence-runner"
      ],
      "prerequisites": {
        "connector": {
          "id": "workforce-identity.connector",
          "statement": "Approved workforce identity, principal synchronization, role fulfillment, and revocation services must pass lifecycle conformance."
        },
        "policy": {
          "id": "workforce-identity.policy",
          "statement": "Role, scope, assurance, duty separation, approval, emergency, access-review, and retention policy must be approved."
        },
        "config": {
          "id": "workforce-identity.config",
          "statement": "A reviewed release must enable workforce access only after identity, role binding, revocation, audit, and operating readiness pass."
        }
      },
      "disabledBehavior": {
        "errorCode": "FEATURE_DISABLED",
        "retryable": false,
        "message": "Workforce identity and governance is unavailable. Connector prerequisite: Approved workforce identity, principal synchronization, role fulfillment, and revocation services must pass lifecycle conformance. Policy prerequisite: Role, scope, assurance, duty separation, approval, emergency, access-review, and retention policy must be approved. Configuration prerequisite: A reviewed release must enable workforce access only after identity, role binding, revocation, audit, and operating readiness pass."
      },
      "disabledProbe": {
        "kind": "client-query",
        "target": "/staff/approvals"
      },
      "safeUnaffectedProbe": {
        "kind": "browser-query",
        "target": "/categories",
        "expectation": "public-taxonomy-remains-readable"
      }
    }
  ]
}
