Appearance
Current system and audience map
Verified 2026-09-06. File anchors are pinned in evidence-index. [missing] means absent from current schema/code, not merely an unchecked GitHub box.
Current flow
mermaid
flowchart TD
Submit[Submission create and initial scrape] --> Current[Submission mutable counters]
Submit --> Initial[Best-effort initial ViewSnapshot]
Schedule[Backend creation-based scheduler] --> Job[ScrapeJob]
Job --> Worker[Scraper: YouTube / TikTok / Instagram]
Worker --> Result[ScrapeJob.result and source scraped_at]
Result --> Reconcile[Backend campaign lock and appliedAt guard]
Reconcile --> Current
Reconcile --> Snap[ViewSnapshot at reconciliation time]
Rate[Immutable rate versions] --> Calc[Current-value earnings / CPM calculators]
Current --> Calc
Budget[Campaign.budget string] --> Calc
Calc --> Reads[Creator / campaign / admin APIs]
Snap --> Hybrid[Hybrid chart readers with fallback inference]
Rate --> Hybrid
Hybrid --> Reads
Current --> Rescrape[Payout request rescrape]
Rescrape --> Item[PayoutItem rate and amount snapshots]
Item --> Approve[Approval increments paid counters]
Approve --> Send[Legacy rail dispatcher]
Send --> Pay[Payout COMPLETED / failure]
Pay --> Report[Token-scoped sponsor report]
Item --> Report
Current --> Report
Snap --> Report
Reads --> UI[Creator and staff frontend]
Report --> Public[Anonymous sponsor frontend]The target inserts verified funding → attributable CPM/RPM journals → durable holds/finality → amount-level payout allocations and confirmed provider operations before financial projections. Those producers are separate dependencies. The scraper remains technical acquisition only. Analytics performs read projections, never accrual/reservation or external calls.
Persistence and authority
| Record | What it proves today | What it does not prove |
|---|---|---|
ScrapeJob | Technical request/result, lease, completion, appliedAt; result contains scraped_at. | Complete normalized observation history or entitlement. Jobs are not a financial journal. |
ViewSnapshot | Recorded views/nullable likes/comments/shares at snapshotDate; tracking application is guarded. Tracking writes clamp.finalCurrentViews, which can be budget-clamped. | Raw platform views in every row, source job identity, durable correction disposition, source-versus-ingestion time; initial write may be missing. |
Submission | Current moderation/metrics/overrides/caps, creator link, creation and first acceptance. | Historical review sequence, immutable earning balance, provider-paid state. lastPolledAt can also be written on failure, so do not treat it as guaranteed successful-observation freshness. |
| Rate versions | Exact effective-dated campaign/individual rates and resolver provenance contract. | Posted earnings; group rates are not loaded/persisted yet. |
Campaign | Configuration, string budget, lifecycle flags and tracking duration. | Verified funding receipt/commitment or immutable remaining budget. |
Payout / PayoutItem | Recorded legacy operation and item snapshots; completed approved items support scoped gross payout reporting. | Complete campaign allocation for legacy one-shot payments, exact ledger positions or Whop success. Floats and approval-advanced counters remain. |
ClipperGroupMembership | Campaign group intervals [joinedAt,leftAt); historical identity may be null. | A unique primary group or historical allocation of old earnings. |
AuditEvent / targets | Canonical business audit envelope, with required transactional writer available. | Every review mutation committed reliably; some producers remain best effort/compatibility. Not a substitute for money records. |
StaffCapabilityGrant | Local grants for hybrid RBAC foundation. | Final business-route permission decisions; current route guards still govern. |
[missing] funding / earning / hold / allocation facts | Required target sources in financial contract. | Must never be synthesized from a display or a legacy counter. |
Audience / metric matrix
All equalities require matching scope, date basis, cutoff, currency, gross/net basis, and coverage. The rightmost column is the planned canonical source, not current implementation.
| Surface and API | Current displayed number / behavior | Canonical source and planned unit |
|---|---|---|
Creator overview /stats/overview | Current accepted effective views; budget-capped recalculated earnings, fee applied; paid/pending split by legacy paidOut. UI sparklines are fixed artwork. | Own earning positions and confirmed allocations; persisted observation series and status counts separately. A02/A03/A04/A11. |
Creator /stats/campaigns | Current accepted views times current campaign RPM; adds once; omits selected manual/frozen fields, individual/group resolution and journal attribution. No current frontend consumer found. | Per-campaign sum of own entries; shared adapter retained for endpoint compatibility. A04. |
Creator history /submissions | Estimated earnings from current calculator; frontend sums only loaded 10-row page, with local search. | Paginated own submission positions plus separate full-filter summary; observation/latest metric coverage. A04/A12. |
Creator payout balance /payouts/balance | Recalculated gross less approved items in awaiting-send/processing/completed, then current fee. Clipper-only old fields plus separate referral/combined eligibility. Overview and payout page consume different bases. | Read supplied eligibility and disjoint entry balances; content/referral separate. Analytics must not replace payout policy. A04/A11/A12. |
Creator payout history /payouts/me | Last 50 operation rows, net amount, method, created/completed times; no campaign allocations or cursor. | Own operations/events and entry allocations, gross/net/fees, explicit incomplete legacy coverage. A05/A12. |
Creator campaign list/detail /campaigns | Public list computes CPM totalSpent; frontend parses configured budget and clamps remaining to zero. Detail loads the list and some legacy RPM labels say CPM. | Safe existing public performance stays bounded; authenticated own/campaign-approved finance projection supplies explicit spend/expense/funding. A06/A11; access owner #50. |
Creator leaderboard /stats/leaderboard | Current estimates for submissions created in period, plus ExternalLeaderboardPayment amounts. | Name earning leaderboard versus payment leaderboard explicitly; journal period/paid basis and external coverage separate. Never count external imports as campaign earnings. A04/A11. |
Staff overview /admin/stats | Legacy userId distinct count, current submissions/statuses, raw current views, separately capped accepted views; pending payout count uses legacy PENDING only. | Canonical creator identity counts; distinguish current queue stock, review events, observation changes, and full operation statuses. A02/A06/A07/A08/A13. |
Staff /admin/chart | Hybrid snapshot delta reader recomputes RPM earnings at daily rate; inference fallback, positive clamp, inclusive off-by-one window. | Same observation reader as creator/sponsor; earning time series from postings, not views × rate. A02/A03/A06/A13. |
| Staff campaign list/detail | List totalSpent uses CPM; detail uses RPM under the same label. Platform/status filters differ between list rows and stats. Detail sorts only the loaded frontend page. | Shared campaign financial projection; explicit independent list/summary filter scopes; top accepted videos sorted/bounded server-side. A02/A06/A13. |
| Staff user list/detail and eligible queue | Mixes legacy paid flags and current calculations; broad user routes also include financial summaries. | Same own/creator/campaign entry projections, under retained staff/finance route protection. A06; payout eligibility remains payout owner's service. |
| Staff review queue/history | Current status counts, heuristic signals/snapshots/track record. Views/earnings sort fetches all rows; no reliable reviewer throughput. | #41/#42 committed transition events for actor/time/reason metrics; queue stock remains separate. A07/A14, #43 owns queue repair. |
| Staff fraud and payouts | Payout-time badge strings, decisions and operation statuses; no durable held liability/rule history. | #55 evaluations/hold entries and #59 operation allocations; unique held entry amounts, unresolved signals counted separately. A08/A15. |
| Group/member detail | Campaign-owned roster and archived intervals only. | #28 membership-at-fact-time cohorts, exact member sums and group union; rate provenance separate. A09/A16. |
Sponsor report /reports/:token | Current accepted effective views/likes/comments/shares; all submitted count; 90-day signed snapshot changes, approved top/recent posts; approved item gross only for completed payouts. | Shared matching performance/paid-gross read primitives, preserving accepted cohort, 90-day window, payout visibility and legacy coverage. No staff risk/review or unrestricted creator financial records. A10. |
Current shared calculators still differ in thresholds, rate selection and fee/rounding basis. Fixing labels alone cannot reconcile them. Sponsor payouts.available only detects known linked legacy payments lacking items; it is not proof that every historical payment anywhere has complete attribution.
Protection / future RBAC attachment
| Boundary | Current protection to retain | Planning marker |
|---|---|---|
| Own stats/submissions/payouts | requireAuth plus own-user/verified legacy identity predicates; stats mount also has limiter. | TODO(RBAC): Keep creator reads limited to the authenticated creator; any cross-creator finance variant requires the approved financial-view capability. |
/admin/stats, /admin/chart | requireAuth, requireWhopStaffAction(ANALYTICS). | TODO(RBAC): Require the capability for viewing cross-creator financial analytics here; totals disclose other creators' compensation and campaign liabilities. |
| Admin campaign list/detail | requireWhopStaffAction(CAMPAIGN_MANAGEMENT); user list/detail use requireStaffAccess. | TODO(RBAC): Attach the approved campaign/financial read capability before broadening staff access to campaign spend and creator balances. |
| Review / group / payout reads | Existing SUBMISSION_MODERATION, CLIPPER_GROUP_ADMINISTRATION, PAYOUT_REVIEW action guards respectively. | TODO(RBAC): Require the approved access for reviewer accountability, group member compensation, or fraud evidence at each respective read endpoint; these are internal operational records. |
| Payout writes | Existing payout-execution action guard and TOTP where attached. | No analytics write endpoint; preserve these unrelated actions. |
| Sponsor management / public read | Management retains requireAuth, requireAdmin; public requires valid campaign bearer grant and post-read validity check. | Preserve existing report TODO(RBAC) for link control and creator-ranking disclosure; no general creator/finance capability bypass through reports. |
| Creator campaign discovery | Presently public, including top submissions. | Do not add liabilities/creator details. #50 owns private access enforcement; coordinate any authenticated alternative. |
Frontend staff navigation currently allows only certain admin subpaths, even when a backend analytics route exists. New staff visibility must follow the separate RBAC attachment contract; client visibility cannot authorize data. Caches must not bypass guards or share sensitive payloads across scopes. No speculative permission mappings are selected in this folder.