Evidence packet

Fill the launch proof with owner-approved evidence.

This packet gives the exact fields and artifacts needed to prove the remaining activation gates. It is not a credential request, seed script, payment authorization, media license, monitoring change, or permission to mutate provider state.

Record separately

Keep source, build, deploy, runtime, browser, provider, and manual interaction proof as separate facts.

Redact secrets

Use aliases for accounts, keys, object names, webhooks, sessions, and screenshots when durable notes do not need raw values.

Stop at gates

When a lane requires owner approval, record the missing approval instead of mutating data or providers.

Packet lane

Source and runtime

gated proof

Tie every launch claim to a source commit, built image, deployed revision, routed traffic, fresh health probe, and browser-visible route.

Fields to capture

  • Source commit SHA and evidence commit SHA
  • Cloud Build ID, image tag, Cloud Run revision, and traffic percent
  • Production URL, health probe timestamp, HTTP status, and response byte count
  • Browser route, viewport, interaction checked, and screenshot filename when captured

Artifacts to attach

  • Cloud Build result URL or ID
  • Cloud Run service metadata readback
  • Fresh curl or browser proof for tiredevents.com and tired.events
  • Any screenshot with route, viewport, and timestamp in the note

Stop condition

A 200 response or matching image tag is not enough by itself; record source, deploy, runtime, and user-visible proof separately.

Packet lane

Operator-owned event

gated proof

Prove discovery, event detail, checkout quote, ticket wallet, scanner, gallery, reviews, and host analytics against a real approved event.

Fields to capture

  • Event id, slug, host account, published or scheduled state, start date, venue, city, and coordinates
  • Ticket tier id, price, available quantity, cart quote subtotal, fee, estimated total, and no-order boundary
  • Event detail metadata and Event JSON-LD fields observed in production
  • Host workspace, analytics, sales, scan, review, and buyer visibility routes checked

Artifacts to attach

  • Public event list and detail screenshots
  • Cart quote response with non-secret identifiers redacted where needed
  • Host analytics or ticket wallet screenshots approved for notes
  • Access-denied proof for accounts that should not manage the event

Stop condition

Do not seed fake public inventory, fabricate tickets, or run a charge only to make event proof pass.

Packet lane

Operator-owned service

gated proof

Prove services marketplace list, detail metadata, provider ownership, booking boundary, and Connect readiness with an approved provider record.

Fields to capture

  • Service id, slug, provider account, listed or draft state, category, city, and pricing model
  • Public list/detail visibility and Service JSON-LD fields for listed records
  • Provider workspace route and owner account used for readback
  • Booking or Connect boundary reached, including fail-closed copy when payable state is unavailable

Artifacts to attach

  • Public services list and detail screenshots
  • Provider dashboard readback with secrets hidden
  • Connect or booking boundary screenshot
  • Draft/private denial proof from a non-provider account

Stop condition

Do not invent provider rows, imply Connect readiness from source checks, or expose draft services as payable.

Packet lane

Authorized role accounts

gated proof

Record which approved sessions proved buyer, host, provider, promoter, manager, scanner, and admin access without preserving reusable credentials.

Fields to capture

  • Role name, account alias, approval source, auth method, and verified or unverified state
  • Allowed routes reached and denied routes confirmed
  • Account switching, onboarding, posting, collaboration, scanning, settings, and admin preview checks performed
  • Evidence storage location with tokens, passwords, cookies, and private owner identifiers excluded

Artifacts to attach

  • Route screenshots with account identifiers minimized
  • Denied-route screenshots for role boundaries
  • Auth state notes that do not include credentials
  • Manual session log with operator present when private accounts are used

Stop condition

Do not store reusable credentials, session tokens, cookies, or private owner account screenshots in repo or durable notes.

Packet lane

Stripe and Connect proof

gated proof

Capture owner-approved payment, webhook, refund, Connect, Tax, Radar, KYC, payout, and balance evidence without treating source readiness as financial proof.

Fields to capture

  • Stripe account, mode, Connect account, webhook endpoint alias, and signing-secret confirmation without secret values
  • Checkout session id, payment intent id, order id, ticket fulfillment id, and webhook delivery id
  • Refund id, refund state, balance transaction, transfer or payout boundary, and settlement view
  • Tax, Radar, KYC, Connect onboarding, and payout evidence source with timestamp

Artifacts to attach

  • Stripe dashboard screenshots approved by the owner
  • Webhook delivery readback with secrets redacted
  • Application order/ticket readback after webhook fulfillment
  • Refund, Connect, payout, Tax, Radar, or KYC screenshots when authorized

Stop condition

Do not run charges, refunds, transfers, payouts, or bank-affecting checks without explicit owner approval for exact mode and scope.

Packet lane

Media grants and exports

gated proof

Prove approved public, unlisted, private, protected grant, signed URL, manifest, ZIP, and native save/share behavior against real media without mutating originals.

Fields to capture

  • Gallery id, owner account, visibility mode, object aliases, and non-owner account used for denial checks
  • Signed upload URL expiry, signed read URL expiry, protected grant claim, and denied private access result
  • Manifest record count, ZIP filename, ZIP SHA-256, and included visibility set
  • Native share, copy, save, or download behavior checked on approved desktop/mobile devices

Artifacts to attach

  • Gallery list/detail screenshots by visibility mode
  • Signed URL success and expiry-denial notes
  • Manifest and ZIP integrity readback
  • Native share/save screenshots using approved media only

Stop condition

Do not upload, expose, merge, delete, transform, or redistribute real media without explicit approval and preservation of originals.

Packet lane

Operational monitoring

gated proof

Turn FE-11/FE-12 from read-only readiness into owner-approved alert, SLO, error, trace, and rollback proof.

Fields to capture

  • Alert policy ids, channel ids, recipients, escalation path, and owner approval
  • Uptime, 5xx/error rate, latency, failed deploy, checkout/webhook, and media-delivery test timestamps
  • SLO names, error budget posture, Error Reporting window, trace window, and log query references
  • Rollback or traffic-shift runbook revision, image, reason, operator, and post-change behavior

Artifacts to attach

  • Provider metadata readback for alert policies and channels
  • Notification delivery proof to approved recipients
  • SLO, error, trace, and logging screenshots
  • Rollback drill or traffic-shift evidence note

Stop condition

Do not create channels, page people, mutate provider monitoring, or run drills that affect users without owner sign-off.

Activation evidence packet · Studio