Reference
AMS Security, Roles, and Certification
Understand tenant isolation, actor locking, retry safety, and the current certification envelope.
First created Last updated
Controls
Every AMS record is partner-scoped. All exposed AMS tables have RLS enabled, explicit grants are used, public and anonymous access are revoked, and privileged helpers remain private with an empty search path. Mutations use the signed-in user’s JWT so auth.uid() supplies the actor.
Capabilities separate view, request, custody, transit, adjustment, audit, agreements, identity, hub, quality, maintenance, interoperability, finance view/policy/propose/approve/close/export/reconcile/audit, and administration. Event access does not grant AMS access.
Certified invariants
- idempotent create;
- server-locked actor and self-checkout custodian;
- quantity bounds and partial return;
- bulk transit pack/repack/dispatch/handoff/receive/unpack/return-to-sender;
- append-only movements and value entries;
- maker-checker finance and open-period posting;
- RLS enabled across 72 AMS relations;
- identifier verify/lock lifecycle, reservations, due-date extension, transit exceptions and unpacking;
- maintenance start/completion and count-to-post audit workflow;
- deterministic golden fixtures for depreciation, impairment, cost allocation, currency, inventory layers, disposal, and present value;
- lossless versioned snapshot validation and explicitly non-filing accounting adapters;
- bounded CSV dry-run and atomic idempotent commit with invalid-row rejection;
- Worker-mediated Sanity evidence, 25 MiB allowlist, server-verified SHA-256, AES-GCM ciphertext for private/restricted content, leased malware/MIME review, quarantine, immutable metadata, opaque authorized content paths, retention, legal hold, and access history;
- minute-scheduled, fingerprint-idempotent operational alerts with actor-locked acknowledgement;
- EPCIS 2.0.1 validation against GS1’s official draft-07 JSON Schema and all 17 mapped CBV 2.0 terms against the normative ontology;
- transactionally durable webhook outbox with AES-GCM-protected secrets, HMAC-SHA256 signatures, no redirects, retry/backoff, and terminal failure state;
- assigned hub work, quality-hold completion gates, dock state transitions, scheduled min/max replenishment, and evidence-backed RTO/RPO exercises;
- component replacement, prospective estimate changes, complete depreciation schedules, NRV posting, TCO sensitivity, and receipt-balanced journal reconciliation;
- recent AAL2 step-up for sensitive exports, webhook mutations, and capability configuration;
- actor-scoped, partner/route/workflow-scoped, versioned and expiring server drafts that cannot submit or mutate operations;
- typed finance proposal and independent approval with active-book/open-period/policy validation, atomic append-only posting, durable receipt, and idempotent replay;
- typed identity/custody/depreciation/permissions policy submission, independent approval/rejection, one-active-version activation/supersession, immutable history, durable receipt, conflict protection, and idempotent replay;
- capability-filtered active-partner user choices that show human identity while keeping immutable IDs internal and exclude the current maker where an independent audit reviewer is required;
- 115 required route contracts and 80 server-side commands with owned/loaned separation; the public metadata-only OpenAPI document covers all 126 actually mounted AMS operations by exact method/path pair.
Phase-gated claims
Do not claim external GS1 certification, offline sync, or high-volume production performance until third-party/production evidence passes. Official GS1 JSON Schema and CBV ontology fixtures pass locally; that is interoperability evidence, not certification by GS1. Protected attachment delivery is certified at contract/database level; deployment must still verify Sanity access, Worker encryption/scanner bindings, retention operations, and opaque download behavior. The accounting adapters remain internal mappings only—not statutory reporting or a filing opinion.