Sign-ready checks passed
Technical details
brand_pointerpartner://innovate/brand/lab/v2026-05-01asset_pointerhttps://assets.innovate.test/pci/brand_reasonsnone
Partner brand service
Loading partner-owned brand manifest from /api/session/brand.
- Brand API
/api/session/brand- Boundary
- No browser tenant authority, brand override authority, theme mutation, asset upload, endpoint value, account identifier, physical id, secret, live-data path, or fallback browser storage.
Trusted tenant context
Tenant authority: trusted API session
Tenant: pci_tnt_innovate_lab; partner: innovate; stage: lab; registry version: 3.
No viewer authority inputs were used.
auth.session_refreshed
Module status
- Data Collection enabled / primary Data Collection is enabled by trusted session context.
- Monitoring enabled / integrated Monitoring is enabled by trusted session context.
AOC follow-up needed
Needs attentionOpen AOC reason codes
reason_code_1correction_required_before_signaturereason_code_2service_scope_addendum_pendingreason_code_3signature_confirmation_pendingreason_code_4assessment_not_ready_for_aoc_signaturereason_code_5scanner_verdict_pendingreason_code_6restricted_cardholder_data_refusedreason_code_7parent_evidence_visibility_requires_operator_reviewreason_code_8parent_evidence_visibility_degradedreason_code_9evidence_scanner_pendingreason_code_10evidence_scanner_refusedreason_code_11pan_or_track_pattern_detectedreason_code_12metadata_ref_withheldreason_code_13scanner_pendingreason_code_14refused_metadatareason_code_15sign_ready_check_warningreason_code_16evidence_scanner_or_parent_visibility_pendingreason_code_17sign_ready_check_blockedreason_code_18signer_authority_review_pendingreason_code_19needs_correctionreason_code_20signer_authority_pending_reviewreason_code_21signer_reauth_requiredreason_code_22signature_correction_requiredreason_code_23export_package_blockedreason_code_24correction_required_before_exportreason_code_25correction_openreason_code_26executive_signer_legal_name_mismatchreason_code_27addendum_addendum_pending
AOC service details
AOC services
Live AOC review workspace
Loading AOC review, document preview, sign-ready, signer, signature request, correction, export package, attestation summary, and attestation export state from same-origin APIs.
- Request policy
- trusted-session-no-query-no-body-no-viewer-authority-aoc-review
- Read APIs
/api/documents/aoc/review-state/api/documents/aoc/preview-metadata/api/documents/aoc/sign-ready/api/attestations/summary/api/attestations/export-metadata
- Boundary
- No browser tenant, entity, cycle, evidence, document, signature, signer, correction, or export authority; no request bodies, endpoint values, account identifiers, physical ids, restricted text, evidence content, document content, signed artifacts, attestation bodies, export bodies, live-data paths, or browser storage fallback.
| Area | State | Next signal |
|---|
| Check | State | Source refs | Safe message |
|---|
| Signer | Role | Review | Authority | Browser signature |
|---|
| Signer | State | Re-auth | Browser material |
|---|
| Export | State | Manifest | Browser download |
|---|
| Correction | State | Safe message |
|---|
| Area | Status | Readiness | Record ref | Unsafe content |
|---|
AOC review, signing, and export
Review the service-authored AOC package, signer readiness, correction queue, and export status. Authorship remains separate from the executive signer; signing and export generation stay server-side.
Executive signer review is display-only and signer authority remains distinct from package authorship.
- Authority
- Document service Needs attention
- Display policy
- Record-only document preview
- Signature policy
- Server-authorized signing only
- Client signing
- Browser signing disabled Accepted
AOC service refs
package_refaoc-package://cycle_lab_2026_readiness/submerchant-a/m8-reviewapi_shape_refservice-ref://api/document-service/aoc-review/m8.9tenant_stagepci_tnt_innovate_lab / labauthoritydocument-servicedisplay_policyrecord-only-no-document-bodysignature_policyserver-authorized-signing-onlybrowser_signing_statenot_allowedsigner_refsigner-ref://innovate/lab/executive-signer-primaryprincipal_refprincipal-ref://pci_prn_innovate_operator_001signer_review_stateneeds_correctionsigner_authority_statepending_review
Open correction/addendum flows
Correction requiredSignature confirmation
Signature state token
signature_statecorrection_required
Export readiness
Export state token
export_stateblocked
AOC actions
Finalize AOC package
Operators can request server-side signature confirmation, record correction/addendum actions, and request an export package manifest. Signing, document editing, signed artifacts, and document/export identity stay server-side.
- Signature API
/api/documents/aoc/signatures- Correction API
/api/documents/aoc/corrections- Export API
/api/documents/aoc/export-package-requests- CSRF cookie
__Host-pt_pci_csrfdouble-submit session check for unsafe methods.
Work signature and export readiness
Sign-ready checklist, Correction and addendum flows, Export package status, and Unsigned attestation and export readiness are handled from one record-only workspace. The browser never signs, downloads, edits, or stores document/export bodies.
| Package item | State | Details | Server action |
|---|---|---|---|
Assessment readiness accepted by server stateCheck refs
| Accepted State token
| Check reason codes
| |
Evidence bundle metadata current and scanner-gatedCheck refs
| Needs attention State token
| Check reason codes
| |
TPSP AOC metadata has current coverage refsCheck refs
| Accepted State token
| Check reason codes
| |
Executive signer authority verified by serverCheck refs
| Blocked — action needed State token
| Check reason codes
| |
CorrectionFlow refs
| Correction required State token
| Correction is displayed as server-owned metadata; no editable document body or signing control is mounted. Correction refs
Correction reason codes
| |
AddendumFlow refs
| Correction required State token
| Addendum package state is record-only until the document service produces an immutable export ref. Correction refs
Correction reason codes
| |
Export package statusExport refs and hashes
| Blocked — action needed State token
| Export reason codes
| |
Unsigned attestationSignature refs and hashes
| Correction required State token
| Unsigned attestation and export readiness are record-only; no attestation body, document body, or signer material is created in the browser.Signature reason codes
|
Sign-ready checks passed
Open correction/addendum flows
Correction requiredSignature confirmation
Signature state token
signature_statecorrection_required
Export readiness
Export state token
export_stateblocked
Last AOC API result
Waiting for operator action.