DineGlobe

V1 foundation. Liveness probe: /health/live · trusted readiness probe: /health/ready

Identity (DEV-004 panel)

Register

Sign in with credentials

One-time tokens (DEV-005 panel)

Request a one-time token

Consume a token

Sessions (DEV-006 panel)

Sign in (issues a session)

Check a session

Revoke a session

Tenancy (DEV-007 panel)

Create an organization

Assign a membership

Remove a membership

Transfer ownership

Invitations (DEV-008 panel)

Invite staff by email

Accept an invitation

Change a member's role

Venues & slugs (DEV-009 panel)

Create a venue (born DRAFT, private)

Rename the public address

Resolve a public address (no session)

Media quarantine (DEV-010 panel)

Upload an image (quarantined, re-encoded)

Authorized download

Retention cleanup

Publication & SEO (DEV-011 panel)

Request publication review

Public profile (no session)

Sitemap (published venues only)

Areas & resources (DEV-012 panel)

Save an area

Save a resource

Place a resource (list layout editor)

Read the layout (list view)

Resource combinations (DEV-013 panel)

Save a combination

List combinations

Local schedules and exceptions (DEV-014 panel)

Save an offering

List offerings

Publish the complete weekly set

Full-set publish: rows keeping their scheduleId update, rows without one are created, rows absent from the array are removed.

List published schedules

Save a date exception

Resolve a venue day (slot preview)

Version policies and price/cancel preview (DEV-015 panel)

Publish a policy version

Immutable once published — edit by retiring and publishing again. Deposits are configuration only; nothing is charged in V1.

List policy versions

Retire a version

Resolve policy + cancellation preview

The exact server-side pair the booking flow will run: resolve the most specific active rule for a candidate booking, then quote its cancellation at a chosen instant.

Availability & best fit (DEV-018 panel)

Read advisory availability

Select the best physical fit

Anonymous booking (DEV-019 panel)

Book (free instant or request)

Attempt 460370ca… key 9a390cd5… (regenerates on “New attempt”; the same key replays the same booking)

Request decisions (DEV-020 panel)

Approve or decline a pending request

Submit requests in the DEV-019 panel first. Approval re-runs the full availability checks — a sold slot conflicts honestly (the request stays pending for a decline).

Expire overdue requests (one venue)

A request expires at the earlier of its 24h review deadline and service start; the binding side is the recorded reason. Replaying the sweep expires nothing twice. (The outbox worker owns the schedule from DEV-029.)

Reschedule (DEV-021 panel)

Book through the DEV-019 panel first. The edit replaces the old/new allocation in one transaction; any failure leaves the original booking exactly as it was.

Cancel / reconfirm / no-show (DEV-022 panel)

Cancels on the ACCEPTED policy snapshot; the quote rides the booking.cancelled event as the refund-intent payload. Retrying the same request key replays the same outcome.

Marks a confirmed booking a no-show only once the ACCEPTED policy grace window has elapsed; the allocation is released, actual table occupancy is not.

Reconfirmation request — stamps the first request and queues a booking.reminder event at the new version.

Records the guest reconfirmation (staff-entered until capability sessions, DEV-023) — requires a prior request.

Guest links and portal (DEV-023 panel)

Issue a management link (rotates!)

Exchange a fragment (one-time)

Request access by email + code

Arrivals / seating / clear (DEV-024 panel)

Service view / walk-in / move table (DEV-025 panel)

Phone / walk-in booking

Move party to another table

Check-in passes / scanner (DEV-026 panel)

Issue / rotate a check-in pass

Host and above. Rotates: the issued pass is the only live one.

Scanner — scan and commit arrival

Door and above. Manual fallback: the DEV-024 arrival form takes the confirmation code and count without a pass.

Queue / ready offer (DEV-027 panel)

Join the queue (public)

Make a ready offer (host)

Accept an offer (staff or the party's queue session)

Withdraw an offer (host)

Expire overdue offers (host)

Exchange a queue token (one-time)

Message evidence / preview (DEV-028 panel)

Delivery outcomes (host)

Retry a failed message (manager)

Preview a template (manager, never sends)

Reminders & SMS gates (DEV-029 panel)

Save reminder settings (manager)

Settings & gate truth (host)

Payment account connection (DEV-030 panel)

Begin provider-hosted onboarding (owner)

Credentials live with the provider. The URL below is shown once and never stored; the country/route gate runs before any provider call.

Refresh capability truth (owner)

Stores the provider’s account state and states whether a paid offering may be activated. Capability loss and account closure are reported as they are — never papered over.

Payment holds and checkout (DEV-031 panel)

Start / recover hosted checkout (host+)

The hold and its attempt committed at booking; this only opens the provider’s hosted page. A retry after a timeout recovers the SAME checkout — never a second charge. Payment is confirmed only by provider reconciliation, never by this page or the browser return.

Expire lapsed holds (host+)

Releases expired paid holds under the venue lock: attempt EXPIRED, allocations released, booking.expired queued. Booking mutations run this sweep opportunistically too — an empty sweep is normal.

Provider event inbox (DEV-032 panel)

Ingest a signed event

The webhook endpoint simulator. The signature is verified on the RAW body before anything is parsed or stored; a valid event is stored once — redelivery answers an idempotent DUPLICATE. A stored receipt is PENDING truth: money effects belong to reconciliation.

View inbox (host+)

Newest receipt envelopes for one venue — safe references and processing checkpoints only. The encrypted payloads never leave the database.

Payment reconciliation (DEV-033 panel)

Reconcile one attempt

Drains the pending verified events about this attempt into money truth. A live hold becomes CONFIRMED with the guest confirmation; late money after a dead hold schedules a full compensation refund — the booking never resurrects. Replaying a settled attempt is a safe no-op.

Sweep account window

The worker sweep, staff-fired: every pending verified event for the venue live provider account, oldest first. Unknown provider objects land in the FAILED exception queue with their code — nothing is dropped silently.

Refund intent queue (host+)

Demands for money back on this venue bookings — system compensation for late money, and (from DEV-034) staff-initiated refunds with their approval workflow. REQUESTED rows await that workflow; nothing here calls a provider.

Refund workflow (DEV-034 panel)

Request a refund

Finance/Manager with fresh MFA, against a RECONCILED CAPTURE. The refundable balance (captured net minus settled refunds, open disputes and pending intents) bounds the amount under the venue lock. At/below the configured threshold the intent is born approved; above it (or with no threshold) it awaits an ownership-tier decision.

Decide (ownership tier)

APPROVED releases the intent for execution; DECLINED cancels it. The decision row is immutable evidence and the approver is never the requester — an owner cannot approve their own refund.

Delegation threshold

Owner/ORG_ADMIN only: refunds at/below this amount act on the delegated authority of the requester. Empty means NO threshold — the fail-closed default where every human refund needs a decision.

Run refund sweep

The worker pass, staff-fired: approved and system intents move to the provider under the stable refund key. PENDING stays visibly pending; a hard refusal fails terminally for manual resolution — never a second collection.

Reconcile one refund

Repairs a pending refund from the provider truth: settled means SUCCEEDED with its ledger row (never duplicated); still-pending stays pending with a reconciliation stamp.

Payment status and finance views (DEV-035 panel)

Reservation payment status

The money view of one booking: reservation and payment badges are separate, receipts carry the provider effect ids, and a refund pending at the provider reads PENDING — never Refunded.

Finance transactions

Settled ledger rows by TRANSACTION date and currency (never the service date). Totals aggregate per currency only — mixed currencies are never summed. The pending queue lists every unresolved refund demand: awaiting decisions, pending at the provider, and failed escalations.

Guest notes, tags and history (DEV-036 panel)

Guest search

Venue-scoped contact hints: exact email or phone, or a name fragment. Your role decides the projection — service roles see decrypted note categories and tags, Door sees arrival counts only, finance and read-only roles see identity only.

Add a guest note

Bodies are encrypted at rest and audited as field names only. The optional reservation link must belong to this same guest in this venue. Host-or-above write authority required.

Record consent evidence

An explicit staff attestation, appended to the ledger — a change of mind is a new row, never a rewrite. The raw attestation text is hashed; booking is not marketing consent and nothing here grants it implicitly.

Privacy cases and retention ledger (DEV-037 panel)

Open a privacy case

Staff intake for a venue-guest subject. Leave the verification method empty to record only (RECEIVED) — identity verification is its own stamped act, and a matching email verifies nothing.

Verify a case

The verification act on a RECEIVED case: method, instant and verifier are stamped together — verification proportionate to the data's risk.

Execute a verified deletion

Removes unnecessary PII (service notes, tag assignments, profile contact) while the justified minimum survives by name — financial references, future bookings, consent evidence, the audit trail — and every active hold is explained. Each removal writes an append-only tombstone.

Apply a legal hold

A reason and a future review date are both required — a hold is bounded by law, never a blanket never-delete switch.

Release a hold

An explicit release event stamps released_at; the hold row itself is retained evidence and is never deleted or rewritten.

Approve and run a retention sweep

Approves a venue-scoped schedule version for one data class, then sweeps against it — obligations (future bookings, open refunds) and active holds are held back and counted, never silently deleted.

Reapply the deletion ledger

After a backup restore: every tombstone executed after the checkpoint (the backup's instant) is reasserted before the restored data serves anyone. Idempotent by construction.

CSV import dry run and venue exports (DEV-038 panel)

Stage an import (the dry run)

Paste the CSV and name which header each canonical field maps to. Rows validate against typed rules and the advisory availability read — conflicts and duplicates become explicit rejected rows. Nothing is booked until the commit below.

Commit a staged import

Every valid row books through the same allocator as live intake — a conflict that appeared since the dry run fails that row with its code; a repeated external id can never become a second booking. Rerunning a completed commit replays its stable summary.

Render a venue export

Future bookings to formula-escaped CSV, encrypted at rest with a bounded download window (24h). The purpose is audited verbatim — an export is a deliberate, attributable act.

Verify an export download

Rechecks the export grant against live membership (never the requester's stored identity) and the expiry window. The panel returns a shape probe only — header and byte count, not the file.

Operational metric report (DEV-039 panel)

Aggregates only — no guest personal data is queried or returned. The service cohort keys on business dates; the money cohort is a separate settled-transaction window with per-currency totals that are never combined across currencies.

Private service sheets and metric exports (DEV-040 panel)

Queue a service-sheet PDF

The PII-bearing floor sheet (guest names, decrypted notes, placements) renders through the bounded text-only PDF writer — no browser, no outbound fetch, no executable structure. Hosts may name the CURRENT venue-local service date only.

Queue a metrics CSV

The DEV-039 aggregates as formula-escaped CSV (every cell rides the DEV-038 escaper). Manager/Finance/Read-only/ownership tier.

Render now (worker simulation)

One tick of the durable worker: renders the QUEUED job into the private artifact tree and performs the guarded QUEUED to READY transition. A replay converges; a permanent failure dead-letters with its code.

Verify an artifact download

Rechecks the kind's permission against live membership (never the stored requester), the host current-service-date bound and the 24h window. Returns a shape probe — name, type, byte count, header — never the bytes.

DEV-041 — SaaS subscription (F21)

One monthly per-venue plan, a 30-day trial and a 7-day dunning grace. Entitlements change only through signature-verified billing events — a browser success return proves nothing. When billing stops new intake, existing books, guest cancellation, refunds and export stay available (BR-064).

Start trial (owner/org-billing tier)

Cancel renewal at period end

Subscription + entitlements view

Ingest billing event (signature is the authorization)

Run reconciliation sweep now

New-booking intake probe (reservations.read)

DEV-042 — Platform tools (F22/F28)

A separate platform role axis with mandatory MFA decides publications, keeps country capabilities default-off until evidence arrives, suspends NEW intake without touching existing books, and works support cases through a PII-free safe view. No impersonation exists — the module mints nothing.

Decide publication review (trust operator)

Set country capability (trust operator)

Suspend new booking intake (trust operator)

Resume booking intake

Open support case

List support cases

Inspect case — SAFE view (TST-062)

Escalate case

Resolve case (outcome mandatory)

Grant platform role (security tier)

Activate / deactivate grant

List platform grants (security tier)

Localization & accessibility (DEV-044 panel)

Book a table

All times are the venue's local time (America/New_York).

2027-03-06 18:00 (America/New_York)

Stored exactly as 2027-03-06T23:00:00.000Z (UTC); never converted to your device time.

The clock repeats: 01:30 happens twice on this date in America/New_York. Choose the first or second occurrence.

01:30 (UTC-4)

01:30 (UTC-5)

Money formats

USD 49.50 (4950 minor units, 2 decimals)

JPY 1000 (1000 minor units, 0 decimals)

KWD 1.234 (1234 minor units, 3 decimals)

Record an arrival

Keyboard-equivalent floor commands

booking

booking.create: Request this time — Tab reaches the control; Enter or Space activates it; Shift+Tab reverses. errors via role=alert, outcome via role=status; online only

cancellation

cancellation.cancel: Cancel booking — Tab reaches the control; Enter or Space activates it; Shift+Tab reverses. errors via role=alert, outcome via role=status; online only

arrival

arrival.record: Record arrival — Tab reaches the control; Enter or Space activates it; Shift+Tab reverses. errors via role=alert, outcome via role=status; online only

arrival.scan: Scan and confirm arrival — Tab reaches the control; Enter or Space activates it; Shift+Tab reverses. errors via role=alert, outcome via role=status; online only

DEV-045 — public directory & booking launchers

Public reads of PUBLISHED venues only. Launchers are first-party links to the venue profile — no iframe checkout, no partner claims.

Directory search

Booking launcher

Booking QR

DEV-046 — health, safe logs & operational alerts

Aggregate-only operations signals: threshold alerts name a runbook action and owner; /health/ready serves the dependency summary to a trusted probe (loopback peer or DG_HEALTH_TOKEN bearer). No guest data, no tokens, no payloads.

Evaluate alerts

Readiness snapshot

Record backup evidence

DEV-049 — security & E2E correctness release suite

Executes the repository's own security/correctness battery in an isolated child run (its own scratch databases) plus live probes — permission matrix, append-only grants, secrets/cache scans, assessment gate, risk register — and persists the source-ID-mapped report. READY requires every registered check to pass in the same run; failing tests are reported, never disabled.

Run the release suite (full battery takes minutes)

Record a risk

Resolve a risk

Record third-party assessment

Recent release evidence

DEV-050 — load, concurrency & device performance

Runs the real service commands under the blueprint's declared pilot load against a throwaway scratch database (created, migrated and dropped by the runner — nothing touches this panel's database). Budgets are measured p50/p95/p99 and gaps are reported, never averaged away; the device matrix records honestly what is emulated versus not implemented (camera) versus pending real hardware.

Run the pilot workload (default scale takes minutes)

Empty fields run the blueprint's declared load (50 concurrent availability reads, a 100-request last-slot race, 30 concurrent first allocations, 4 final-scan racers, 3 degraded checkout callers). Overrides may only tighten budgets, never widen them.

Recent workload runs

DEV-051 — launch gates and pilot acceptance

Supervised first-market review: record the G-01..G-08 gate outcomes, run the four real end-to-end journeys, and sign the decision. A capability whose gates, journeys or registry row are missing stays disabled with its blocking owner and action recorded. One pilot country is not global support.

Operator session
Launch gates (default BLOCKED — approval is explicit)
Requested country capability