draftDraft
The host owns an inspection purpose, external asset/site identity, Mappls Pin or coordinate, classification, and policy version.
Qualify paid RealView entitlement, open one browser-visible-token viewer attempt, handle the documented no-imagery signal safely, and turn human observations into a reviewed business record without inventing panorama metadata.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
draftThe host owns an inspection purpose, external asset/site identity, Mappls Pin or coordinate, classification, and policy version.
entitlement_pendingPaid product access, exact host generation, browser credential class, restrictions, expiry, quota, and permitted use are being approved.
readyThe approved entitlement reference and bounded viewer configuration are current enough to open an attempt.
viewingOne browser lifecycle owns the iframe, exact origin, location/radius configuration, ephemeral token-handle reference, listener, timeout, and disposal.
coverage_unavailableThe exact Auth2 origin emitted the documented schema-valid status 204 for this attempt and configuration.
observation_recordedAn inspector saved a bounded human checklist and notes linked to the viewer attempt, without claiming provider metadata or copying imagery.
review_pendingAn immutable observation set awaits a separately authorized reviewer under the declared purpose and policy.
acceptedterminalA named reviewer accepted the observation set for the exact business decision and policy version.
rework_requiredReview retained the prior observation and reason while requiring a new viewer attempt or alternate field evidence.
cancelledterminalAn authorized actor ended the inspection with a bounded reason while preserving prior attempts and observations.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
create_inspectionHost applicationrealview_inspection.createdOne external inspection identity maps to one aggregate across retries.
request_entitlementInspectordraftrealview_inspection.entitlement_requestedThe product, environment, and account request identity is stable and contains no credential value.
confirm_entitlementPlatform administratorentitlement_pendingrealview_inspection.entitlement_confirmedCommit only entitlement reference, exact host, restrictions, and expiry metadata—not the issued token.
open_viewerInspectorreadycoverage_unavailablerework_requiredrealview_inspection.viewer_openedOne command creates one immutable attempt and one ephemeral token-handle reference.
record_no_coverageHost applicationviewingrealview_inspection.coverage_unavailableAccept one exact-origin, one-field status 204 result for the active attempt only.
record_observationInspectorviewingrealview_inspection.observation_recordedHash the bounded checklist, notes, attempt, actor, and observation time.
submit_reviewInspectorobservation_recordedrealview_inspection.review_requestedFreeze one observation set and enqueue review atomically.
acceptInspection reviewerreview_pendingrealview_inspection.acceptedBind reviewer, reason, policy version, observation IDs, and command identity.
request_reworkInspection reviewerreview_pendingrealview_inspection.rework_requestedRetain the reviewed evidence and create one attributable rework decision.
record_entitlement_expiredHost applicationreadyviewingrealview_inspection.entitlement_expiredInvalidate the active attempt once and discard only its ephemeral token handle.
cancelInspectordraftentitlement_pendingreadyviewingcoverage_unavailableobservation_recordedreview_pendingrework_requiredrealview_inspection.cancelledCommit actor, reason, cleanup, audit, and outbox exactly once.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Current purpose, asset/site and location identity, ownership, policy, state, and optimistic version.
inspectionIdexternalIdassetIdmapplsPinOrCoordinatepurposestateversionNon-secret proof of the approved product generation and credential policy.
entitlementRefproducthostenvironmentcredentialClassexpiresAtrestrictionFingerprintImmutable browser lifecycle and documented no-imagery outcome.
attemptIdconfigFingerprinttokenHandleRefopenedAtdisposedAtcoverageStatusHuman-authored evidence and separately authorized decision without copied imagery.
observationIdattemptIdchecklistnotesobservedAtreviewerdecisionpolicyVersionAppend-only transitions and exactly-once-in-effect downstream delivery.
eventIdaggregateVersionactoridempotencyKeyoutboxStatusNo server secret, browser token value, or complete token-bearing iframe URL is persisted, logged, analyzed, exported, or sent to a model.
The exact selected origin and narrow documented schema are checked before any browser message reaches domain state.
Status 204 proves only no imagery for one attempt and configuration; HTTP 200 and frame load prove only a delivered shell.
Human observation is distinct from provider imagery, panorama metadata, measurement, currentness, and inspection acceptance.
Imagery is not copied, screenshotted, exported, or retained without an explicit licensed product contract and purpose-specific policy.
Every command is idempotent, compares expected version, and commits snapshot, audit, receipt, and outbox atomically.
Reviewer acceptance is attributable and cannot be performed by the same automated actor that created the observation.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
HTTP/frame load occurred without entitled viewing or the documented 204 signal.
Keep viewing unresolved until a bounded timeout, then record a host technical outcome rather than coverage or completion.
Exact origin, object shape, field count, or integer status validation fails.
Reject before domain processing, retain only a safe rejection metric, and never store the opaque payload.
The entitlement reference is expired/revoked or the account-approved broker reports token expiry.
Dispose the viewer, remove the ephemeral handle, return to entitlement pending, and retain the incomplete attempt.
The active attempt receives the documented exact-origin status 204 message.
Record configuration-specific no coverage and offer justified radius/location retry or alternate field evidence.
Checklist is incomplete, limitations are missing, purpose changed, or stronger field evidence is required.
Request rework without overwriting the observation or prior viewer attempt.
Client lacks acknowledgement while aggregate, command key, and outbox state are durable.
Reload and replay the same command key; never create another attempt or review decision to recover transport uncertainty.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenariosmappls-app-widgetsmappls-web-maps-js10 verified tests