One current execution context
People do not have to rebuild order, inventory, machine, shipment, and cost state from separate exports after the fact.
Operational mechanisms
See who owns each decision, what happens after a duplicate or disconnect, whether a machine acknowledged work, how money reconciles, and how your data can leave.
Operational continuity
The mechanisms below reduce reconciliation work, preserve failure ownership, and keep evidence portable.
People do not have to rebuild order, inventory, machine, shipment, and cost state from separate exports after the fact.
Duplicate, disconnected, rejected, timed-out, and physically contradictory states identify the affected work and authorized recovery path.
Audit, connector scope, transaction proof, and tenant export make important limits and ownership testable before contract signature.
Delivery layers
Product mechanisms are implemented once; equipment, credentials, topology, operating policy, and measured outcomes are established for each deployment.
The state, authorization guard, workflow, evidence, and automated validation ship with the platform.
Equipment dialect, credentials, topology, carrier account, and operating policy must be configured and qualified.
Throughput, uptime, implementation duration, and operating outcomes are recorded from the deployed environment.
Trace 01 / merchant shipment
The useful difference is not another dashboard. It is keeping client identity, warehouse execution, carrier purchase, and money movement correlated without exposing internal buy cost or warehouse controls.
Merchant SKU and barcode aliases bind to packaging, lot, serial, and expiry rules.
Cartons, labels, booking, documents, amendments, and discrepancy responses retain versions.
Receipt, quality, ownership, location, holds, reservations, and availability govern promise.
Carrier, service, parcels, expiry, price lines, total, and signature are snapshotted for the client.
One idempotency key joins funding reserve, carrier request, capture, receipt, and transition history.
Tracking, download, reprint, void, provider refund, reconciliation credit, and ledger remain explicit.
What the merchant actually sees
The client sees carrier service, surcharge and tax lines, total, quote expiry, proof reference, wallet coverage, and allowed funding choices. Carrier buy cost and operator margin stay outside the client-owned quote.

Trace 02 / human or robot
The arbiter can compare eligible human and robot candidates. A typed resource reservation is handed to the canonical operator queue or robot mission, then released from terminal state.
Domain task, priority, warehouse, source, destination, capability, and business context.
Role, robot capability, queue state, availability, location, safety, and operating policy.
Typed resource, holder, priority, TTL, state, source, and decision correlation.
Human queue assignment or AGV mission is created or recovered idempotently.
Mission reports or semantic command ack/complete tags advance observed state under a watchdog.
Terminal work releases the hold; occupancy mismatch raises a de-duplicated alert until clean.
Machine authority
XMS can issue governed mission or semantic command intent. Vendor controllers and safety PLCs retain device motion and interlocks. A missing permissive, poor tag quality, timeout, or unclassified fault blocks blind progression.

Nine operating mechanisms
Each mechanism exposes its state, edge conditions, recovery path, and resulting operational artifact.
Inventory, bins, lanes, docks, lift cells, traffic zones, work items, robots, and operators share a typed hold shape. Existing silo leases are projected read-only; native arbiter claims use priority, TTL, lifecycle, and correlation.
Contend one human and one robot for eligible work. Inspect the winning decision, one hold, canonical handoff, crash recovery, and release.
Occupied-without-reservation, reserved-without-occupancy, and over-capacity observations create one evolving alert. A clean rescan resolves it automatically rather than hiding drift behind a green mission state.
Occupy a lane without a hold, scan twice, clear it, and verify one alert is updated then resolved.
A named command checks configured permissives and tag quality before issue. A watchdog then records acknowledgement, completion, rejection, or timeout. PLC and safety logic remain final authority.
Remove a permissive, degrade a tag, and withhold acknowledgement. Verify no blind write and an observable timeout.
Warehouse designs retain immutable revisions, lineage, checksums, row versions, review, and separate approval. Materialization previews structural adds, updates, deletes, coordinate change, and excluded operational state before apply or rollback.
Branch a published design, edit a rack, attempt self-approval, preview the diff, apply as a second user, then roll back.
Devices queue ordered events. Replay verifies registered device, operator, warehouse, source type, session, sequence, age, payload bounds, and idempotency. Unsupported mutations require reconnection.
Disconnect during supported work, retry an event, skip a sequence, attempt a blocked action, reconnect, and inspect each result.
Catalog entries bind to adapter class, protocol, version range, owner, lifecycle, limitations, and build. Validation reports Passed, Failed, or ScopeLimited with skipped scenarios, uncovered capability, artifacts, and version drift.
Run contract and emulator validation for the proposed build, then inspect covered, skipped, and unsupported scope.
The takeout manifest identifies datasets and entities with schema versions, row counts, sizes, SHA-256 hashes, product version, and an audited download path.
Request an export, reconcile counts and hashes, then import selected files into an independent data store.
The client sell quote is snapshotted and signed. Purchase retains one idempotency key, funding and carrier states, transition history, receipt, evidence, void reason, and explicit provider-refund reconciliation.
Submit twice, interrupt after reserve, resume card action, reprint, void, and post a confirmed carrier refund. Demand one trace.
The backend authorizes business jobs and artifacts. The bound workstation or handheld owns local scanner, camera, BLE/GATT, or printer transport, checks payload compatibility, and returns acknowledgement as evidence.
Remove WAN, retain the local station, reject a mismatched printer payload, and show there is no backend-to-printer socket.
Failure behavior
Each scenario links the trigger to expected system state, operator guidance, and recovery evidence.
The same operator event or purchase key must resolve to the existing outcome; a cross-user key collision must be rejected.
Only approved offline actions continue. Pending events retain order, poison events cannot starve the queue, and reconnection reconciles visibly.
The semantic command must stop before write, identify the blocked condition, and never infer that an unknown fault is safe.
Reservation and occupancy disagreement must raise a persistent operational alert and clear only after observation or explicit resolution.
Row-version or checksum drift must invalidate stale approval/materialization rather than silently overwrite the newer design.
The run must report ScopeLimited and list what was skipped or not covered—not convert missing evidence into a pass.
Migration continuity
Daily operational workspaces are kept apart from migration-only import, reconciliation, and finalization controls, so migrated and new tenants use the same contracts, permissions, and evidence.
Back Market, WiziShop, Boostmyshop, Winpharma, Market Invaders, StoreFactory, Magento, Shopify, and relay-point mappings live in Integrations with per-connector readiness status.
Weight × zone grids, fuel indices, remote-zone fees, insurance, client assignments, and known-carrier sell pricing live in transport network and rating.
Freight audit, carrier invoices, allocation, settlement, invoice runs, detail annexes, credit notes, payments, and GL output use canonical finance workspaces.
Legacy source-file ingestion, source reconciliation, and bounded draft-transaction finalization remain governed migration controls rather than everyday navigation.
Deployment validation
Use your data shape and target build, then retain the screen, API response, event, audit, or export produced by each scenario.
Import demand, reserve stock, assign human or robot work, pack, buy a label, dispatch, receive a carrier event, and trace cost and evidence without spreadsheet correlation.
Run supported mobile work offline, attempt a prohibited mutation, reconnect, and reconcile ordered events without duplicates or hidden loss.
Fail a permissive and an acknowledgement. Verify command refusal, watchdog state, operator context, and manual safe restart boundaries.
Use a valid client A identity against client B inventory, order, quote, ledger, and export identifiers. Require denial below UI filtering.
Change adapter build, show certification drift, run conformance with a failure injection, and inspect covered, skipped, and unsupported capability.
Generate a tenant takeout, validate manifest hashes and row counts, and load representative datasets independently before contract signature.
Deployment results
Compare volume, automation, regions, tenancy, and operating model with relevant deployment references.
Benchmark throughput, latency, recovery, queue depth, and data growth on the proposed deployment architecture.
Bind timeline, custom-code share, integration ownership, data migration, training, and cutover gates to a statement of work.
Validate certifications, residency, SLA, support, incident, retention, export, and deletion terms separately.
Validate a difficult state
Choose one merchant shipment, warehouse move, robot mission, integration failure, tenant boundary, or export and define the expected artifact.