Skip to content

A15 — Staff risk, hold and payout-state summaries ​

Status: blocked. Updated: 2026-09-06. Assigned agent: unassigned. Implementation PR: none.

Issues and acceptance covered ​

#52. The acceptance boundary is the implementation scope and completion checks below; see the issue acceptance matrix for parent coverage. Shared definitions: financial contract; proof anchors: evidence index.

Dependencies and blockers ​

A08, A11 shared money/coverage formatter; #55 owns fraud investigation/resolution workflow and #56–#59 owns payout commands.

Repository and expected files ​

Frontend: features/admin/payout-list, features/admin/payout-detail, corresponding payout screens; small risk summary/read-only evidence module if needed.

Existing behavior and verified gap ​

Badges/manual decisions and status tabs exist, but no durable unresolved-hold amount or rule/resolution history. PageTotalAmount is page-specific; status does not prove fraud (E21).

Proposed implementation boundary ​

Display unresolved signals, unique affected holdings, held liability and uncertain operations separately with safe drilldown. Use evidence/rule-version labels and unknown coverage. Link to owning fraud/payout workflow rather than implementing clear/retry/dispatch commands.

Expected API / data contract ​

Consume A08 aggregate DTO/A03 exact amounts; server full-filter summary independent of payout page. No auto-conversion of FLAGGED/badges into holds.

Required tests ​

Multiple signals one held amount; resolution leaves second hold active; unknown transfer separate from fraud; recovery due separate from paid; paging/filter invariants; privacy/error/403/503. Focused API tests, lint/build, manual fixture.

Suggested agent tier ​

Lower-cost UI agent under smart financial/risk/security review.

Expected PR boundary and reason ​

One risk operational UI PR stacked on A08/A11; no payout state-machine or fraud workflow bundle. Unlocks A17. Keep compatibility additive, avoid unrelated cleanup, and list exact stacked commits and later units unlocked in the PR. If observed scope grows beyond this boundary, update the plan before splitting or adding work.

RBAC requirements / TODOs ​

Retain payout-review/moderation protection; execution/TOTP controls unchanged. TODO(RBAC): Require approved internal fraud-evidence and held-finance access; read access cannot imply release or transfer authority.

Completion and reconciliation checks ​

Visible held liability equals A03/A08, not badge count × amount. Page totals and global totals clearly distinct. No newly introduced mutation sends/retries money.

Record actual tests, source schema/contract versions, PR/merge SHA, manual evidence and residual coverage before changing status to review/complete. Any unexpected migration must first satisfy the migration gates; never bundle upstream financial writer work into this analytics unit.