Command center migration receipt — 7 October 2026
Target: Debelu Supabase project havugmqmyplqgbrlthhs. The user renewed standing authorization to apply migrations through MCP.
Applied successfully with Supabase MCP, and confirmed in migration history:
| File | Hosted history version |
|---|---|
| 20261011002200_atomic_return_case_governance.sql | 20261007065328 |
| 20261011002300_granular_command_capabilities.sql | 20261007065339 |
| 20261011002500_subject_privacy_export_delivery.sql | 20261007065344 |
| 20261011002600_guard_internal_wallet_refund_snapshot.sql | 20261007065346 |
| 20261011002700_staff_invitation_delivery_outbox.sql | 20261007065717 |
| 20261011002800_vendor_kyc_governance.sql | 20261007070519 |
| 20261011002900_vendor_kyc_onboarding_control_guard.sql | 20261007072902 |
| 20261011003000_governed_whatsapp_replies.sql | 20261007082935 |
| 20261011003100_governed_vendor_sanctions.sql | 20261007081924 |
| 20261011003200_close_vendor_strike_truncate_boundary.sql | 20261007085423 |
Migration 024 was already recorded and was not replayed. MCP assigns hosted timestamps and descriptive names; the table maps hosted versions to the checked-in filenames. The hosted name for 030 is governed_whatsapp_replies.
Readback through Supabase MCP on 7 October 2026 confirmed all ten records above. Migration 030 was applied after independent review of its messaging-pause, definitive-rejection, and command-table permission fixes. Its browser RPC execution grants are disabled and the necessary service-role RPC execution grants are enabled. Migration 031 was applied before 030 because it is independent. Backend, admin and storefront were deployed and verified against application commit 1a89a969. Database application alone does not verify a provider delivery.
Local checks passed: 14 atomic return checks, 12 subject-export checks, 36 staff-access/invitation checks, and 14 vendor-identity checks. Production readback confirmed the restrictive identity-document read/update/delete policies. Application deployment and actual invitation delivery are separate steps; this receipt does not certify provider delivery. No live email, WhatsApp message, or sanction was issued.
Migration 029 also passed five local SQL checks covering paused, null, and missing controls, rejection during a pause, and approval after restoration. The migration serializes seller enrollment against the settings row used by the onboarding circuit breaker. The verified application revision and release checks are recorded below.
Invitation delivery stays disabled until its Edge Function and matching encryption/worker secrets and SES sender are configured. See the release runbook in docs/operations/command-center-release-runbook.md.
The deliver-staff-invitation Edge Function was deployed through Supabase MCP as active version 1 with JWT verification enabled. An unauthenticated POST returned HTTP 401. Sending secrets and backend worker enablement were not changed, and no invitation was sent.
Railway backend deployment d37bad72-40c3-4d54-9be6-599ff4a4ce03 succeeded after a fresh source build recovered a provider snapshot-fetch failure. The service settings were identical before and after recovery. Production health reported full commit 1a89a969437fe92f6987c3b3070c7c363d053162 and /health/ready returned HTTP 200 with ready; Redis and Supabase checks passed. Overall health still classifies Paystack as unverified; this is not payment delivery evidence.
Application release verification completed successfully:
- Monorepo CI 37620321609: database replay/concurrency, production dependency audit, typechecks, lint, full tests, every application build, React runtime consistency and accessibility/route smoke tests passed.
- Production release 37620321690: test gate, storefront/admin builds, both Cloudflare production deployments and post-deployment checks passed.
admin.debelu.comandapp.debelu.comreturned HTTP 200. Their delivered JavaScript embeds the full application SHA1a89a969437fe92f6987c3b3070c7c363d053162.- Production protected KYC, sanctions and WhatsApp API requests without authentication returned HTTP 401. This is an unauthorized-access smoke check, not a live privileged decision or provider-send test.
WhatsApp verification passed: 17 SQL behavior checks, 17 backend tests, 7 admin workflow tests, and backend/admin typechecks. Coverage includes inherited service-role mutation/truncate grants, the authoritative messaging-breaker row, paused queue preservation, fenced provider attempts, definitive rejection recovery, and uncertain receipt reconciliation. Native full-schema replay and the exact release SHA must still pass the release gates before deployment.
Migration 032 closes the vendor-strike truncate boundary. Supabase MCP applied its hosted record as 20261007085423, named close_vendor_strike_truncate_boundary. Hosted readback confirmed can_truncate=false for anon, authenticated, and service_role. All 12 SQL vendor-sanction checks passed. The native return concurrency fixture was also corrected to use canonical refund_status='requested' rather than the invalid pending value; this preserves the intended race test. Exact-release CI and application deployment passed as recorded above.