VisaReady Development Dependency & Blocker Assessment

Project: VisaReady — Customer App, Agency Dashboard, Superadmin Portal and Cross-App Services   Generated: 2026-07-18T14:25:43+00:00

This assessment identifies development gates caused by external services, missing artifacts, unresolved business rules, policy decisions, architecture, security, delivery, and test-environment dependencies.

No credential values, API keys, tokens, or secrets are included.

Executive summary

Consolidated dependencies62
External integration families12
Exact $cred queries52
Exact credential matches0
Raw requirement gap rows185
Known open defects8

Dependencies by gate

Program start blocker9
Core feature blocker25
Feature blocker7
Partial development blocker7
Pre-UAT blocker6
Pre-release dependency6
Non-blocking / out of scope2
$cred conclusion: No requirement-listed service name, provider alias, VisaReady project identifier, project folder ID/URL, project credential-sheet ID/URL, APM label, or approved review URL produced an exact registry match. Credential availability is therefore unconfirmed; a canonical service-to-environment mapping is required before any secret can be consumed.
Separate project credential workbook: A separate Google Sheet titled 'Visa ready Api Creds' exists in the project Drive, but it was not opened: the user invoked the configured $cred registry, and the Master registry contains no exact mapping to that workbook. This is a source-of-truth dependency.

What blocks development now

Credentials are not the first blocker. The supplied workspace has no application source/build definitions, and the Drive Content and Configurations folder is empty. Integration credentials cannot be safely wired until repositories, platform identities, environment topology, canonical APIs/data ownership, and a versioned configuration bundle are supplied.
IDDependencyAppsCurrent gapExit criteriaOwner
VR-BLK-013Application repositories, target revisions, build definitions, and dependency manifests for every deployableCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: the workspace contains only .tcgen test-design artifacts and no application source, package/build manifest, dependency lockfile, Dockerfile, infrastructure definition, environment template, or build instructions. Architectural inference: implementation requires the repository location, target branch or commit, technology stack, dependency installation method, build commands, and owning team for each deployable.All in-scope repositories are accessible at approved revisions; every deployable has reproducible install, build, test, and local-run instructions; dependency manifests and lockfiles are present; and repository ownership is recorded.Engineering Program Lead and Application Engineering Leads
VR-BLK-014Approved deployable and supported-platform matrixCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login WebEvidence-backed absence: requirements name Customer mobile and web channels, Agency and Superadmin web portals, a shared login URL, and a signed target APK, but no authoritative deployable list or supported OS, browser, device, and version matrix is supplied. Architectural inference: the team must decide whether mobile scope is Android only or Android and iOS, whether web surfaces are independent deployments, and which responsive and accessibility targets apply.A signed release-scope matrix identifies every deployable, platform, minimum OS/browser version, supported device class, responsive breakpoint expectation, release channel, and accountable engineering owner.Product Owner, Solution Architect, Mobile Lead, and Web Lead
VR-BLK-015Mobile application identity, signing, versioning, permissions, and distribution artifactsCustomer Mobile AppEvidence-backed absence: BUG-CUS-001 requires an approved package, launcher, splash identity, and signed target APK, while the requirements need camera, file or storage, and notification permissions; no Gradle project, AndroidManifest, package ID, keystore reference, signing configuration, version scheme, or release channel is present. Architectural inference: Android app-link configuration and signing custody are required, and equivalent iOS identifiers and signing artifacts are required only if iOS is confirmed in DEL-02.The approved mobile application ID, signing-custody process, non-secret signing reference, version and build numbering policy, permission manifest, launcher and splash asset package, app-link scheme, and internal or store distribution path are documented and usable in a reproducible signed build.Mobile Engineering Lead, Security, and Release Manager
VR-BLK-017Canonical API contract, identity model, shared application schema, and migration strategyCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: requirements mandate one shared Customer, Agency, and Admin application record, identity linking, ownership isolation, immediate role enforcement, synchronized status and report state, and immutable audit, but no API schema, canonical identifier model, database schema, or migration definition is available. Architectural inference: the solution needs a versioned API contract, tenant and object-ownership model, identity-resolution rules, optimistic or equivalent concurrency control, schema migrations, cache invalidation, and backward-compatibility strategy.Approved API and event contracts, canonical entity and identifier model, tenant and ownership rules, database schema and migration path, concurrency policy, synchronization SLA, cache policy, and compatibility/versioning rules are implementation-ready.Backend Architect, Data Architect, and Identity Lead
VR-BLK-029Data export, deletion, anonymization, retention, and recovery contractCustomer App, Agency, Superadmin, Cross-App E2EThe data map, export contents and delivery, deletion state machine, retention schedule, erasure SLA, retained legal and audit evidence, dependency failures, retry ownership, and exception handling are unspecified.The DPO and Legal approve the data map and retention schedule, and Data Operations approves executable export and irreversible erasure state machines with verification, SLA, recovery, exception ownership, and customer communications.DPO, Legal, Data Architecture, and Data Operations
VR-BLK-030Encryption, residency, masking, tenancy, and third-party data boundariesCustomer App, Agency, Superadmin, Cross-App E2EEncryption standards, residency region, field-by-role masking across UI, export, logs and messages, financial-data sharing boundaries, transport baseline, and explicit agency tenant-isolation requirements are not approved.Security and Privacy approve a measurable control baseline and field-by-role data-access matrix covering storage, transit, UI, APIs, exports, logs, notifications, tenancy, and third-party disclosures.Security Architect and DPO
VR-BLK-031Atomic, durable, and recoverable audit contractSuperadmin, Cross-App E2EThe event schema, time and correlation standard, previous and new state capture, masking, retention, export, transactional persistence, fail-closed behavior, and audit recovery runbook are not defined.Architecture, Security, and Compliance approve an atomic audit design and event contract that prevents an unaudited successful write and supports investigation and recovery.Platform Architect, Security, and Compliance
VR-BLK-032Shared-application ownership, identity linking, drafts, offline behavior, and concurrent updatesCustomer App, Agency, Superadmin, Cross-App E2EField ownership, verified-identity matching precedence, collision review, blank-field behavior when edits are disabled, optimistic locking or merge rules, draft retention, offline persistence, and cross-channel synchronization SLA are unresolved.Product and Data Architecture approve one shared-record ownership and concurrency matrix, including identity collision, review, merge, version, draft, offline, and synchronization rules.Product Owner and Data Architect
VR-BLK-033Authoritative RBAC, agency tenancy, sensitive permissions, and role presetsAgency, Superadmin, Cross-App E2EThe final capability list, default sub-user template, preset-to-permission mapping, application-detail access, sensitive export, branding, billing, promo, and direct-object authorization rules are incomplete.Security and Product approve a server-enforced role, permission, tenancy, object-scope, masking, and export-access matrix for every administrative and agency role.Security, Product, and Agency Operations
VR-BLK-001Razorpay payment gateway provider/account/configuration bindingCustomer App, Agency, Superadmin, Shared Backend['Sandbox, UAT, and production account mapping', 'Signed webhook and callback configuration', 'Payment, refund, settlement, fee, tax, and invoice rules', 'Idempotency, retry, and reconciliation operating contract'] Credential audit: No exact match in Master registry; availability unconfirmedApprove environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership.Finance, Product, Backend, DevOps
VR-BLK-003OCR and document intelligence provider/account/configuration bindingCustomer App, Agency, Superadmin, Shared Backend['Provider and environment accounts', 'Supported document/layout catalogue and field map', 'Confidence thresholds and customer/reviewer correction rules', 'Retry, manual review, permanent-failure, retention, and audit contract'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements.Product, Data or AI Lead, Compliance, Backend
VR-BLK-004SMS and OTP service provider/account/configuration bindingCustomer App, Agency, Superadmin, Shared Identity['Provider and environment sender configuration', 'OTP validity, resend interval, attempt reset, cooldown, and rate limits', 'Template, delivery-state, retry, and outage fallback rules', 'Security monitoring and abuse controls'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership.Identity, Security, Product, Backend
VR-BLK-008Cloud object storage provider/account/configuration bindingCustomer App, Agency, Superadmin, Shared Backend['Provider, region, environments, buckets, and tenancy layout', 'Encryption and key-management design', 'Malware scanning, content validation, and access controls', 'Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policy'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior.Platform, Security, Privacy, Backend
VR-BLK-010GST and PAN validation provider/account/configuration bindingAgency, Superadmin, Shared Backend['Authoritative decision between format/checksum and live verification', 'Provider and environment configuration if live verification is required', 'Timeout, outage, retry, manual-review, and fail-open or fail-closed policy', 'Verification evidence and retention requirements'] Credential audit: No exact match in Master registry; availability unconfirmedApprove format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency.KYC, Product, Compliance, Backend
VR-BLK-018Queue, worker, scheduler, retry, idempotency, and dead-letter execution modelCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: requirements explicitly require delayed and duplicate webhook handling, notification retry and dead-letter ownership, OCR retry, an erasure worker, effective-time publication, and scheduled maintenance, but no queue, worker, scheduler, retry table, or recovery runbook is supplied. Architectural inference: a durable event or job mechanism with correlation, idempotency, poison-message handling, replay authorization, scheduling, monitoring, and atomic state-transition rules is necessary; no specific technology is mandated.The asynchronous architecture, job and event schemas, idempotency keys, retry and timeout limits, dead-letter ownership, scheduler and timezone behavior, replay controls, failure-state semantics, and operational recovery runbooks are approved and testable.Platform Engineering Lead and Backend Engineering Lead
VR-BLK-020Versioned, approved release configuration and content seed packageCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: the project Drive Content and Configurations folder is empty, while the requirements need a launch-country catalogue, visa purposes, forms and ranges, document checklists, scoring weights and bands, risk rules and penalties, plan and credit packs, prices and taxes, promo rules, notification mappings and templates, support contacts, SLAs, and official URLs. Architectural inference: these values require a versioned, environment-promotable seed package with validation, effective dates, rollback, cache invalidation, migration behavior, and accountable content owners.An approved release configuration package contains every required catalogue and rule, passes schema and cross-reference validation, identifies its source owner and effective date, can be promoted by environment, supports safe rollback, and defines treatment of in-flight and historical records.Product Owner, Business Analyst, Configuration Owner, and Finance Owner
VR-BLK-023Production data protection, storage, backup, recovery, and audit controlsCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: encryption, residency, retention, malware scanning, signed-link lifetime, deletion propagation, audit retention and export, and fail-closed audit persistence remain unresolved, and no database, storage, backup, or recovery configuration is present. Architectural inference: the platform needs KMS-backed encryption, service and tenant authorization, backup and restore objectives, disaster recovery, object scanning and lifecycle jobs, PII masking, immutable audit storage, security testing, and an approved incident and recovery model.The data classification and residency decision, encryption and key-management design, tenant and object access controls, storage lifecycle and malware policy, backup and tested restore targets, disaster-recovery objectives, audit-store controls, erasure propagation, security-test plan, and accountable recovery owners are approved and verified.Security Architect, Data Platform Lead, Privacy Owner, and Operations
VR-BLK-026Structured runtime evidence, immutable audit persistence, correlation, alerting, and recovery runbooksCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIEvidence-backed absence: full APM and System Health are explicitly outside Lite, but requirements still mandate immutable audit, correlation, provider-delivery status, payment reconciliation, export, failure visibility, and fail-closed writes; no audit schema, log standard, telemetry destination, alert policy, retention rule, or runbook is supplied. Architectural inference: Lite still needs structured logs, correlation IDs, immutable audit persistence, critical service and job metrics, security-safe masking, alerts for money, messaging, erasure and audit failures, and operational ownership without claiming the deferred AD-60 dashboard.The audit event schema, atomic persistence behavior, clock and correlation standard, masking and retention, authorized export, structured logging, minimum critical metrics and alerts, incident ownership, and recovery runbooks are approved and testable; AD-60 remains clearly excluded unless separately authorized.Backend Engineering Lead, Security or Compliance, and Operations
VR-BLK-027OTP, lockout, session, password, and restricted-account policyCustomer App, Agency, SuperadminOTP validity, resend and attempt limits, cooldown and reset behavior, alternate recovery, inactivity timeout, JWT rotation or revocation, password expiry, and restricted-user remediation are not fully fixed.Product Security approves one production authentication-policy matrix covering every customer, agency, and admin channel, including customer-facing restriction and recovery behavior.Product Security and Identity Owner
VR-BLK-034Agency KYC evidence, review outcomes, rejection recovery, and initial creditsAgency, Superadmin, Cross-App E2EMandatory onboarding evidence, GST and PAN validation policy, failure handling, More Information behavior, appeal or resubmission versus terminal rejection, initial-credit amount, credit recurrence, and default edit rights are not settled.Agency Product, Compliance, and Finance approve the KYC checklist, validation contract, review state machine, rejection recovery policy, initial-credit amount and recurrence, and default customer-edit setting.Agency Product Owner, KYC or Compliance, and Finance
VR-BLK-035Canonical six-digit agency-code namespace, rendering, uniqueness, and lifecycleCustomer App, Agency, Superadmin, Cross-App E2EMocks contain prefixed, alphanumeric, and variable-length codes while the requirement confirms six numeric digits; namespace capacity, reserved values, collision retry, uniqueness scope, retirement, and recycling are undefined.Product and Data Architecture approve the raw stored and displayed format, generation algorithm, capacity forecast, uniqueness boundary, collision handling, and code lifecycle.Product Owner and Data Architect
VR-BLK-037Suspension and permanent-blacklist effects across agency, customer, and shared casesCustomer App, Agency, Superadmin, Cross-App E2ECustomer read and write rights, payments, documents, reports, existing-case behavior, notification audiences, and remediation during agency suspension or blacklist are not approved.Product, Operations, and Security approve an atomic state-impact matrix for agency users, agency codes, customer cases, financial actions, communications, reinstatement, and permanent blacklist.Product, Operations, and Security
VR-BLK-039Document capture, correction authority, review, permanent failure, and version retentionCustomer App, Agency, Superadmin, Cross-App E2ERequirements conflict on whether manual passport entry is permitted; low-confidence review, manual fallback, retry limits, permanent failure, correction precedence, latest versus retained versions, and safe retry behavior are undefined.Product, Document Data, and Compliance approve the field-authority, review, correction, retry, fallback, version-retention, and no-silent-overwrite contract.Product, Document Data SME, and Compliance
VR-BLK-040Party capacity, relationships, mandatory evidence, primary-only scoring, charging, reporting, and invoicingCustomer App, Agency, Superadmin, Cross-App E2ESources conflict on five co-applicants plus primary versus five total, one primary score and token versus one token per passport or combo reports, while relationship proofs, required fields, removal, and invoice entitlements are open.Product, Finance, and Scoring approve one party-capacity, relationship, mandatory-field, completion, removal, score, token, price, report, and invoice-entitlement matrix.Product, Finance, and Scoring Owner
VR-BLK-042Versioned dynamic forms, validation ranges, and destination or user-type document checklistsCustomer App, Agency, Superadmin, Cross-App E2EThe field catalogue, ranges, dropdowns, conditional visibility, mandatory base checklist, seven user-type overlays, destination and visa variants, ordering, publication, rebuild, and in-flight migration rules are not supplied.Visa SME and Configuration Product approve the complete field, validation, condition, checklist, ordering, mandatory, publication, version, and migration catalogue.Visa SME and Configuration Product Owner
VR-BLK-043Effective dating, version pinning, publication atomicity, propagation, caching, and record migrationCustomer App, Agency, Superadmin, Cross-App E2EThere is no cross-module contract for effective timezone, publication atomicity, cache invalidation, propagation SLA, record-version pinning, drafts, or treatment of in-flight applications and orders.Platform Architecture and Product approve a uniform configuration version, effective-time, publication, propagation, cache, rollback, and in-flight migration policy.Platform Architect and Product Owner
VR-BLK-045Authoritative Lite and Final scoring semantics, factors, bands, penalties, and customer presentationCustomer App, Agency, Superadmin, Cross-App E2EThe Lite factor split and thresholds are open while mocks incorrectly show numeric Lite scores; Final Others rules, redistribution, ordered score-band boundaries, penalties, party scope, and customer labels are unresolved.Product and Scoring approve the five-factor non-numeric Lite contract and the complete seven-factor Final formula, normalization, bands, penalties, scope, reason codes, and presentation.Product Owner and Scoring SME
VR-BLK-046Risk catalogue, FraudShield, fund-parking calculation, evidence review, waiver, appeal, and disclosureCustomer App, Agency, Superadmin, Cross-App E2ELookback, aggregation, timezone, exact thresholds, combinations, severities, penalties, proof catalogue, reviewer authority, waiver audit, appeal path, customer disclosure, and rescore trigger are unresolved.Risk, Compliance, and Product approve a complete effective-dated trigger, formula, threshold, severity, penalty, evidence, review, waiver, appeal, disclosure, and rescore matrix.Risk SME, Compliance, and Product Owner
VR-BLK-047Score-regeneration allowance, charging, idempotency, rollback, party scope, and improvement recommendationsCustomer App, Agency, Superadmin, Cross-App E2ESources conflict between one free then paid regenerations and a strict two-total limit; qualifying changes, counter reset, failure rollback, party scope, pricing, recommendation catalogue, impact mapping, and detail-section access are incomplete.Product, Finance, and Scoring approve the original, free, paid, terminal, qualifying-change, counter-reset, compensation, party, recommendation, and display contract.Product, Finance, and Scoring Owner
VR-BLK-048B2C and B2B plans, prices, taxes, credits, quotas, renewal, expiry, carry-forward, and overridesCustomer App, Agency, Superadmin, Cross-App E2ECore ranges, appended fixed and combo INR prices, USD mocks, credit-token semantics, permitted deductions, pack values, taxes, currencies, low-credit thresholds, renewal, expiry, carry-forward, auto-recharge, plan switching, usage fields, and override proration conflict or remain inputs.Commercial Product, Finance, and Tax approve a versioned B2C and B2B catalogue and lifecycle matrix covering price, currency, tax, quota, token, deduction, period, renewal, expiry, carry-forward, upgrade, override, and visible usage.Commercial Product, Finance, and Tax
VR-BLK-049Payment state, refund eligibility, entitlement reversal, accounting documents, and reconciliation operationsCustomer App, Agency, Superadmin, Cross-App E2ERefund eligibility, partial amounts and fees, consumed-credit treatment, entitlement reversal, invoice or credit-note and tax handling, payment purpose and state model, settlement cadence, matching keys and tolerances, mismatch owner, and closing evidence are unspecified.Finance, Accounting, and Support Operations approve the end-to-end payment, refund, entitlement, accounting-document, reconciliation, exception, ownership, and closure state machines.Finance, Accounting, and Support Operations
VR-BLK-050Promo semantics, allocation, binding, use limits, expiry, failure recovery, waiver, and invoice treatmentCustomer App, Agency, Superadmin, Cross-App E2ERequirements define a customer transaction fee waiver while mocks show an agency recharge bonus; waived items, agency and customer binding, caps, single or multi-use behavior, expiry timezone, allocation commit on notification failure, fallback, and invoice treatment are unresolved.Commercial Product and Finance approve one promo semantic and complete generation, allocation, binding, distribution, redemption, cap, expiry, failure, waiver, accounting, and audit contract.Commercial Product and Finance
VR-BLK-051Application-status transitions, authority precedence, corrections, conclusion, and review-link behaviorCustomer App, Agency, Superadmin, Cross-App E2EThe full prior-to-new state matrix, agency versus Admin authority, rollback and correction rights, terminal reason and decision-document rules, notification mapping, and review-link placement, copy, target, and eligible outcomes are not specified.Product and Operations approve one cross-app state machine with transition authority, precedence, reasons, corrections, reversals, disclosure, documents, notifications, and conclusion review-link behavior.Product and Operations
VR-BLK-056VisaMatrix sections, factor presentation, branding, watermark, QR verification, and secure sharingCustomer App, Agency, Superadmin, Cross-App E2EFinal section order, factor display, reason codes, intelligence configuration, watermark and logo assets, file type and size policy, agency co-branding, passport footer, QR destination and access security, share authentication, expiry, revocation, delivery history, and mock metric counts are unresolved.Product, Brand, and Security approve the versioned report template, assets, file policy, identity and footer rules, QR verification contract, and secure share-link lifecycle.Product, Brand, and Security

Recommended owner actions

  1. Engineering Lead: provide repository URLs/paths, target branches/commits, build commands, dependency lockfiles and ownership for every deployable.
  2. Product and Architecture: approve the deployable/platform matrix, including Customer Android/iOS/web scope, Agency/Admin web scope, minimum versions and release channels.
  3. Solution Architecture: approve the canonical API, shared data/identity model, tenancy, field ownership, concurrency/versioning and asynchronous processing design.
  4. DevOps and Security: publish the Dev/Test/UAT/Prod URL matrix, callback/redirect endpoints, DNS/TLS ownership, secret-manager paths and environment-to-provider account mapping.
  5. Product, Finance and Scoring: sign the B2C/B2B price/plan/credit catalogue, co-applicant entitlement model, scoring/risk rules, rescore limits, refund/reconciliation and promo semantics.
  6. Product and Visa SMEs: deliver the versioned launch countries, visa purposes, forms, ranges, document checklists, official URLs and content package.
  7. Legal and DPO: approve final legal copy, consent/re-consent, data inventory, export/deletion/retention and third-party processing boundaries.
  8. Integration Owners: select and provision sandbox/UAT accounts for Razorpay, WABA, OCR, SMS/OTP, email, OAuth, push and secure object storage; add canonical exact identifiers to $cred.
  9. QA/DevOps: provision isolated UAT URLs, synthetic role/tenant data, provider sandboxes, reset tools, safe test documents and failure-injection controls.
  10. Customer Engineering and QA: fix and retest BUG-CUS-001 through BUG-CUS-008; keep them separate from client/architecture dependencies.

External integration dependency matrix

The registry result is intentionally conservative: “no exact mapping” is not proof that a credential does not exist. It means development lacks a safe, canonical identifier-to-environment mapping.

IntegrationGateAppsWorkflow/UAT impactEvidence$cred aliases checked$cred resultMissing inputsExit criteriaOwner
Razorpay payment gatewayCore feature blockerCustomer App, Agency, Superadmin, Shared BackendReal purchase, recharge, delayed or duplicate webhook, refund, entitlement, invoice, and reconciliation journeys cannot be accepted.CUS-EXT-RAZORPAY, AG-R030, AG-R031, AD-50, AD-52, AD-53, EXT-RAZORPAYRazorpayNo exact match in Master registry; availability unconfirmedSandbox, UAT, and production account mapping, Signed webhook and callback configuration, Payment, refund, settlement, fee, tax, and invoice rules, Idempotency, retry, and reconciliation operating contractApprove environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership.Finance, Product, Backend, DevOps
WhatsApp Business APIFeature blockerCustomer App, Agency, Superadmin, Shared BackendReferral attribution, support launch, status notifications, report sharing, consent, retry, and delivery-status flows cannot be proven end to end.CUS-EXT-WHATSAPP, CUS-PRD-4.6.9, AG-R012, AD-48, AD-49, EXT-WHATSAPPWhatsApp Business API, WhatsApp Business, WhatsApp, WABANo exact match in Master registry; availability unconfirmedApproved WABA account and sender number, Consent source and evidence, Approved templates and bot script, Signed referral/share-link format, expiry, replay controls, retry, and fallbackApprove the WABA account, sender identity, consent evidence, template catalogue, bot and support scripts, signed-link security contract, provider delivery states, retry, idempotency, and fallback behavior.Communications, Product, Compliance, Backend
OCR and document intelligenceCore feature blockerCustomer App, Agency, Superadmin, Shared BackendPassport, bank-statement, supporting-document, and fund-parking evidence cannot be extracted, reviewed, corrected, or failure-tested against an approved contract.CUS-EXT-OCR, CUS-PRD-4.7-OCR, AG-R021, AG-R024, AD-32, EXT-OCROCR / Document Intelligence Engine, OCR, Document Intelligence, OCR/Document IntelligenceNo exact match in Master registry; availability unconfirmedProvider and environment accounts, Supported document/layout catalogue and field map, Confidence thresholds and customer/reviewer correction rules, Retry, manual review, permanent-failure, retention, and audit contractApprove the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements.Product, Data or AI Lead, Compliance, Backend
SMS and OTP serviceCore feature blockerCustomer App, Agency, Superadmin, Shared IdentityPhone verification, agency registration, login, resend, expiry, lockout, throttling, and provider-outage recovery cannot be accepted.CUS-PRD-4.3-OTP, AG-R002, AG-R007, AD-48, AD-49, EXT-SMS-OTP, NFR-SECSMS / OTP Provider, SMS/OTP, SMS, OTPNo exact match in Master registry; availability unconfirmedProvider and environment sender configuration, OTP validity, resend interval, attempt reset, cooldown, and rate limits, Template, delivery-state, retry, and outage fallback rules, Security monitoring and abuse controlsApprove the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership.Identity, Security, Product, Backend
Transactional emailFeature blockerCustomer App, Agency, Superadmin, Shared BackendAuthentication and business notifications, exports, reports, deletion notices, promo delivery, retry, suppression, and delivery evidence cannot be validated.CUS-EXT-OTP-EMAIL-PUSH, AG-R049, AD-47, AD-48, AD-49, EXT-EMAILEmail Service (transactional), Transactional Email, Email, SendGrid, SES, Amazon SESNo exact match in Master registry; availability unconfirmedProvider and environment account mapping, Verified sender domains and identities, Approved templates, subjects, and merge fields, Delivery SLA, bounce/suppression, retry, fallback, and dead-letter ownershipApprove the provider, verified domain and sender identities, template and merge-field catalogue, delivery states and SLA, idempotency, retry, suppression, fallback, and dead-letter runbook.Communications, Product, DevOps, Backend
Google OAuthFeature blockerCustomer App, Shared IdentityGoogle sign-in, consent, redirect, identity linking, collision handling, revocation, and single-customer resolution cannot be accepted.CUS-PRD-4.3-AUTH, CUS-PRD-4.13-LINK, EXT-OOS-001Google OAuth (Sign-In), Google OAuth, Google Sign-InNo exact match in Master registry; availability unconfirmedOAuth clients for each environment and platform, Authorized origins and redirect URIs, Consent-screen ownership and publication status, Identity-linking, collision, account-recovery, and revocation policySupply approved environment clients and redirect URIs, publish the consent configuration, and approve linking precedence, collision review, account recovery, revocation, and audit behavior.Identity, Security, Product, DevOps
Push notifications through FCM and APNsFeature blockerCustomer App, Superadmin, Shared BackendDevice registration, customer preferences, push delivery, token retirement, deep links, authorization, retry, and fallback cannot be validated.CUS-EXT-OTP-EMAIL-PUSH, CUS-PRD-4.6.2, AD-48, AD-49, EXT-PUSHPush Notification Service, Push Notification, FCM, Firebase Cloud Messaging, APNsNo exact match in Master registry; availability unconfirmedProvider projects, app identifiers, and environment mapping, Signing-key and service-identity ownership, Device-token registration and retirement policy, Authorized deep-link, delivery-state, retry, and fallback contractApprove provider projects and application identifiers, secure key custody, token lifecycle, preference enforcement, authorized deep links, observable delivery states, retry, and fallback.Mobile Lead, Notifications Owner, Security, Backend
Cloud object storageCore feature blockerCustomer App, Agency, Superadmin, Shared BackendOwned uploads, reports, branding assets, secure downloads, malware handling, retention, deletion propagation, and recovery cannot be accepted.CUS-EXT-STORAGE, CUS-PRD-4.14-UPLOAD, CUS-PRD-6.2, AG-R048, AD-65, EXT-STORAGECloud File Storage, Cloud StorageNo exact match in Master registry; availability unconfirmedProvider, region, environments, buckets, and tenancy layout, Encryption and key-management design, Malware scanning, content validation, and access controls, Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policyApprove the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior.Platform, Security, Privacy, Backend
Official embassy and VFS URLsPre-UAT blockerCustomer App, SuperadminCountry configuration and safe external tracking or guidance navigation cannot be accepted for launch destinations.CUS-PRD-4.17-EMBASSY, AD-20, EXT-EMBASSYEmbassy / Official Visa Portal URLs, Embassy URLsNo exact match in Master registry; availability unconfirmedApproved launch-country URL catalogue, Official-domain and content ownership, URL validation and review cadence, In-app browser controls, allowlisting, and external-failure fallbackProvide and approve the launch-country official-domain catalogue, owner, review and health-check cadence, allowlisting and navigation policy, and safe fallback content.Product, Visa Content Operations, Compliance
GST and PAN validationCore feature blockerAgency, Superadmin, Shared BackendAgency KYC adequacy, approval, failure handling, and verification evidence cannot be accepted against one authoritative rule.CUS-EXT-GSTPAN, AG-R003, AD-07, EXT-GST-PANGST / PAN validation, GSTIN, PAN, GSTIN/PAN verification APINo exact match in Master registry; availability unconfirmedAuthoritative decision between format/checksum and live verification, Provider and environment configuration if live verification is required, Timeout, outage, retry, manual-review, and fail-open or fail-closed policy, Verification evidence and retention requirementsApprove format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency.KYC, Product, Compliance, Backend
System health and APM monitoringNon-blocking / out of scopeAll applications, Platform OperationsAD-60 is not a VisaReady Lite acceptance feature, but the separate 99.5 percent availability target cannot be objectively evidenced without an approved telemetry source and calculation contract.AD-60, NFR-AVAILAnalytics/monitoring, APMNo exact match in Master registry; availability unconfirmedExplicit Lite exclusion and future-phase ownership, Availability SLI, measurement window, and exclusions, Future monitoring provider, alerting, and evidence policyKeep AD-60 explicitly excluded from Lite and separate it from current acceptance, or approve a future provider, SLIs, measurement window, exclusions, alert ownership, and evidence method.Product, SRE, Operations
Approved external review link at qr.linkPre-UAT blockerCustomer AppThe amended Conclusion journey cannot be accepted because the exact display, eligible outcomes, navigation, availability, ownership, and failure behavior are unresolved.AMEND-S-1, CUS-PRD-4.17-CONCLUSION, AD-65https://qr.link/9bpJ5LNo exact match in Master registry; availability unconfirmedBusiness owner and availability commitment, Exact placement and display copy, Eligible granted or rejected Conclusion outcomes, Browser or deep-link behavior, security allowlisting, analytics, and fallbackConfirm the URL owner and availability, exact placement and copy, eligible outcomes, navigation behavior, security allowlisting, tracking expectations, and safe fallback.Product, Content Owner, Customer App Lead

Consolidated blocker and dependency register

IDCategoryDependencyGateSeverityAppsEvidenceCurrent gapExit criteriaOwnerSafe parallel work
VR-BLK-013Repository & DeliveryApplication repositories, target revisions, build definitions, and dependency manifests for every deployableProgram start blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIWORKSPACE-OBS-NO-APP-SOURCE, CUS-SRC-001, AG-PRD, SRC-SA-REQ, E2E-SRC-003Evidence-backed absence: the workspace contains only .tcgen test-design artifacts and no application source, package/build manifest, dependency lockfile, Dockerfile, infrastructure definition, environment template, or build instructions. Architectural inference: implementation requires the repository location, target branch or commit, technology stack, dependency installation method, build commands, and owning team for each deployable.All in-scope repositories are accessible at approved revisions; every deployable has reproducible install, build, test, and local-run instructions; dependency manifests and lockfiles are present; and repository ownership is recorded.Engineering Program Lead and Application Engineering LeadsRequirements clarification, architecture planning, UX review, data modeling, and provider onboarding can continue, but implementation against the actual products cannot.
VR-BLK-014Release ScopeApproved deployable and supported-platform matrixProgram start blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login WebBUG-CUS-001, CUS-PRD-4.4-PERM, AG-R008, AG-R046Evidence-backed absence: requirements name Customer mobile and web channels, Agency and Superadmin web portals, a shared login URL, and a signed target APK, but no authoritative deployable list or supported OS, browser, device, and version matrix is supplied. Architectural inference: the team must decide whether mobile scope is Android only or Android and iOS, whether web surfaces are independent deployments, and which responsive and accessibility targets apply.A signed release-scope matrix identifies every deployable, platform, minimum OS/browser version, supported device class, responsive breakpoint expectation, release channel, and accountable engineering owner.Product Owner, Solution Architect, Mobile Lead, and Web LeadShared domain modeling and provider evaluation can proceed; platform-specific project setup and acceptance baselines should wait for the matrix.
VR-BLK-015Mobile & ReleaseMobile application identity, signing, versioning, permissions, and distribution artifactsProgram start blockerCriticalCustomer Mobile AppBUG-CUS-001, CUS-PRD-4.4-PERM, WORKSPACE-OBS-NO-MOBILE-MANIFESTEvidence-backed absence: BUG-CUS-001 requires an approved package, launcher, splash identity, and signed target APK, while the requirements need camera, file or storage, and notification permissions; no Gradle project, AndroidManifest, package ID, keystore reference, signing configuration, version scheme, or release channel is present. Architectural inference: Android app-link configuration and signing custody are required, and equivalent iOS identifiers and signing artifacts are required only if iOS is confirmed in DEL-02.The approved mobile application ID, signing-custody process, non-secret signing reference, version and build numbering policy, permission manifest, launcher and splash asset package, app-link scheme, and internal or store distribution path are documented and usable in a reproducible signed build.Mobile Engineering Lead, Security, and Release ManagerMobile UX and business-domain code can be designed; a real installable release and platform integrations cannot be completed.
VR-BLK-017Architecture & Shared DataCanonical API contract, identity model, shared application schema, and migration strategyProgram start blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APICUS-PRD-4.13-LINK, AG-R013, AG-R046, AD-57, AD-58, CUS-PRD-6.2Evidence-backed absence: requirements mandate one shared Customer, Agency, and Admin application record, identity linking, ownership isolation, immediate role enforcement, synchronized status and report state, and immutable audit, but no API schema, canonical identifier model, database schema, or migration definition is available. Architectural inference: the solution needs a versioned API contract, tenant and object-ownership model, identity-resolution rules, optimistic or equivalent concurrency control, schema migrations, cache invalidation, and backward-compatibility strategy.Approved API and event contracts, canonical entity and identifier model, tenant and ownership rules, database schema and migration path, concurrency policy, synchronization SLA, cache policy, and compatibility/versioning rules are implementation-ready.Backend Architect, Data Architect, and Identity LeadFrontend mock flows and isolated component work can proceed; persistent cross-app journeys and authorization cannot.
VR-BLK-029Legal & PrivacyData export, deletion, anonymization, retention, and recovery contractProgram start blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.6.3-EXPORT, CUS-PRD-4.6.3-DELETE, AG-R040, AD-15, AD-16, NFR-DPDPAThe data map, export contents and delivery, deletion state machine, retention schedule, erasure SLA, retained legal and audit evidence, dependency failures, retry ownership, and exception handling are unspecified.The DPO and Legal approve the data map and retention schedule, and Data Operations approves executable export and irreversible erasure state machines with verification, SLA, recovery, exception ownership, and customer communications.DPO, Legal, Data Architecture, and Data OperationsBuild queued export and erasure orchestration behind feature flags; disable irreversible production purge until legal approval.
VR-BLK-030Security & PrivacyEncryption, residency, masking, tenancy, and third-party data boundariesProgram start blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-6.2, AG-R011, AG-R040, NFR-PRIVACY, NFR-SECEncryption standards, residency region, field-by-role masking across UI, export, logs and messages, financial-data sharing boundaries, transport baseline, and explicit agency tenant-isolation requirements are not approved.Security and Privacy approve a measurable control baseline and field-by-role data-access matrix covering storage, transit, UI, APIs, exports, logs, notifications, tenancy, and third-party disclosures.Security Architect and DPOUse least privilege, tenant-scoped authorization, encryption, masked logs, and synthetic data by default; do not load production PII.
VR-BLK-031Audit & OperationsAtomic, durable, and recoverable audit contractProgram start blockerCriticalSuperadmin, Cross-App E2ENFR-AUDIT, AD-15, AD-16, AD-19, AD-45, AD-52The event schema, time and correlation standard, previous and new state capture, masking, retention, export, transactional persistence, fail-closed behavior, and audit recovery runbook are not defined.Architecture, Security, and Compliance approve an atomic audit design and event contract that prevents an unaudited successful write and supports investigation and recovery.Platform Architect, Security, and ComplianceImplement a transactional audit or outbox boundary before enabling mutable administrative operations.
VR-BLK-032Architecture & Shared DataShared-application ownership, identity linking, drafts, offline behavior, and concurrent updatesProgram start blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-5.2, CUS-PRD-4.6.1-7, CUS-PRD-4.13-LINK, CUS-UI-RECOVERY, AG-R013, AG-R019, AG-R046Field ownership, verified-identity matching precedence, collision review, blank-field behavior when edits are disabled, optimistic locking or merge rules, draft retention, offline persistence, and cross-channel synchronization SLA are unresolved.Product and Data Architecture approve one shared-record ownership and concurrency matrix, including identity collision, review, merge, version, draft, offline, and synchronization rules.Product Owner and Data ArchitectUse one versioned aggregate, reject stale writes, and route identity collisions to manual review instead of automatically linking.
VR-BLK-033Authorization & TenancyAuthoritative RBAC, agency tenancy, sensitive permissions, and role presetsProgram start blockerCriticalAgency, Superadmin, Cross-App E2EAG-R011, AG-R035, AG-R036, AG-UI-013, AD-18, NFR-PRIVACYThe final capability list, default sub-user template, preset-to-permission mapping, application-detail access, sensitive export, branding, billing, promo, and direct-object authorization rules are incomplete.Security and Product approve a server-enforced role, permission, tenancy, object-scope, masking, and export-access matrix for every administrative and agency role.Security, Product, and Agency OperationsDeny by default, enforce tenant scope server-side, and omit mock role presets until their permissions are approved.
VR-BLK-001External IntegrationRazorpay payment gateway provider/account/configuration bindingCore feature blockerCriticalCustomer App, Agency, Superadmin, Shared BackendCUS-EXT-RAZORPAY, AG-R030, AG-R031, AD-50, AD-52, AD-53, EXT-RAZORPAY['Sandbox, UAT, and production account mapping', 'Signed webhook and callback configuration', 'Payment, refund, settlement, fee, tax, and invoice rules', 'Idempotency, retry, and reconciliation operating contract'] Credential audit: No exact match in Master registry; availability unconfirmedApprove environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership.Finance, Product, Backend, DevOpsBuild a provider-neutral payment adapter and deterministic payment/webhook simulator without using real funds or credentials.
VR-BLK-003External IntegrationOCR and document intelligence provider/account/configuration bindingCore feature blockerCriticalCustomer App, Agency, Superadmin, Shared BackendCUS-EXT-OCR, CUS-PRD-4.7-OCR, AG-R021, AG-R024, AD-32, EXT-OCR['Provider and environment accounts', 'Supported document/layout catalogue and field map', 'Confidence thresholds and customer/reviewer correction rules', 'Retry, manual review, permanent-failure, retention, and audit contract'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements.Product, Data or AI Lead, Compliance, BackendDefine a versioned OCR interface and use synthetic fixture responses plus a manual-review queue.
VR-BLK-004External IntegrationSMS and OTP service provider/account/configuration bindingCore feature blockerCriticalCustomer App, Agency, Superadmin, Shared IdentityCUS-PRD-4.3-OTP, AG-R002, AG-R007, AD-48, AD-49, EXT-SMS-OTP, NFR-SEC['Provider and environment sender configuration', 'OTP validity, resend interval, attempt reset, cooldown, and rate limits', 'Template, delivery-state, retry, and outage fallback rules', 'Security monitoring and abuse controls'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership.Identity, Security, Product, BackendUse a fake OTP service limited to synthetic local and UAT identities, with configurable expiry and failure fixtures.
VR-BLK-008External IntegrationCloud object storage provider/account/configuration bindingCore feature blockerCriticalCustomer App, Agency, Superadmin, Shared BackendCUS-EXT-STORAGE, CUS-PRD-4.14-UPLOAD, CUS-PRD-6.2, AG-R048, AD-65, EXT-STORAGE['Provider, region, environments, buckets, and tenancy layout', 'Encryption and key-management design', 'Malware scanning, content validation, and access controls', 'Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policy'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior.Platform, Security, Privacy, BackendUse a storage abstraction backed by an isolated local or UAT object store with synthetic files only.
VR-BLK-010External IntegrationGST and PAN validation provider/account/configuration bindingCore feature blockerCriticalAgency, Superadmin, Shared BackendCUS-EXT-GSTPAN, AG-R003, AD-07, EXT-GST-PAN['Authoritative decision between format/checksum and live verification', 'Provider and environment configuration if live verification is required', 'Timeout, outage, retry, manual-review, and fail-open or fail-closed policy', 'Verification evidence and retention requirements'] Credential audit: No exact match in Master registry; availability unconfirmedApprove format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency.KYC, Product, Compliance, BackendImplement a validation interface and an explicitly provisional format-only validator without claiming live verification.
VR-BLK-018Architecture & OperationsQueue, worker, scheduler, retry, idempotency, and dead-letter execution modelCore feature blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APICUS-EXT-RAZORPAY, AG-R031, EXT-EMAIL, CUS-EXT-OCR, AD-16, AD-49, AD-53, AD-70Evidence-backed absence: requirements explicitly require delayed and duplicate webhook handling, notification retry and dead-letter ownership, OCR retry, an erasure worker, effective-time publication, and scheduled maintenance, but no queue, worker, scheduler, retry table, or recovery runbook is supplied. Architectural inference: a durable event or job mechanism with correlation, idempotency, poison-message handling, replay authorization, scheduling, monitoring, and atomic state-transition rules is necessary; no specific technology is mandated.The asynchronous architecture, job and event schemas, idempotency keys, retry and timeout limits, dead-letter ownership, scheduler and timezone behavior, replay controls, failure-state semantics, and operational recovery runbooks are approved and testable.Platform Engineering Lead and Backend Engineering LeadSynchronous domain logic and provider adapters can be scaffolded; reliable payment, messaging, OCR, erasure, and scheduled-state completion cannot.
VR-BLK-020Product ConfigurationVersioned, approved release configuration and content seed packageCore feature blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIDRIVE-OBS-CONTENT-CONFIG-EMPTY, AD-20, AD-26, AD-32, AD-34, AD-42, AD-49, AD-62, CUS-PRD-4.15-PRICEEvidence-backed absence: the project Drive Content and Configurations folder is empty, while the requirements need a launch-country catalogue, visa purposes, forms and ranges, document checklists, scoring weights and bands, risk rules and penalties, plan and credit packs, prices and taxes, promo rules, notification mappings and templates, support contacts, SLAs, and official URLs. Architectural inference: these values require a versioned, environment-promotable seed package with validation, effective dates, rollback, cache invalidation, migration behavior, and accountable content owners.An approved release configuration package contains every required catalogue and rule, passes schema and cross-reference validation, identifies its source owner and effective date, can be promoted by environment, supports safe rollback, and defines treatment of in-flight and historical records.Product Owner, Business Analyst, Configuration Owner, and Finance OwnerGeneric configuration engines and placeholder fixtures can be developed; authoritative calculations, forms, prices, notifications, and release acceptance cannot.
VR-BLK-023Security & ResilienceProduction data protection, storage, backup, recovery, and audit controlsCore feature blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APICUS-PRD-6.2, CUS-EXT-STORAGE, AG-R048, EXT-STORAGE, AD-58, AD-59, NFR-AUDIT, NFR-DPDPA, NFR-PRIVACYEvidence-backed absence: encryption, residency, retention, malware scanning, signed-link lifetime, deletion propagation, audit retention and export, and fail-closed audit persistence remain unresolved, and no database, storage, backup, or recovery configuration is present. Architectural inference: the platform needs KMS-backed encryption, service and tenant authorization, backup and restore objectives, disaster recovery, object scanning and lifecycle jobs, PII masking, immutable audit storage, security testing, and an approved incident and recovery model.The data classification and residency decision, encryption and key-management design, tenant and object access controls, storage lifecycle and malware policy, backup and tested restore targets, disaster-recovery objectives, audit-store controls, erasure propagation, security-test plan, and accountable recovery owners are approved and verified.Security Architect, Data Platform Lead, Privacy Owner, and OperationsNon-sensitive local fixtures and interface design can proceed; production persistence, sensitive documents, tenant isolation, erasure, and audit-sensitive writes cannot be completed safely.
VR-BLK-026Audit & OperationsStructured runtime evidence, immutable audit persistence, correlation, alerting, and recovery runbooksCore feature blockerCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIAD-58, AD-59, AD-60, AD-53, NFR-AUDIT, NFR-AVAIL, E2E-WF-19Evidence-backed absence: full APM and System Health are explicitly outside Lite, but requirements still mandate immutable audit, correlation, provider-delivery status, payment reconciliation, export, failure visibility, and fail-closed writes; no audit schema, log standard, telemetry destination, alert policy, retention rule, or runbook is supplied. Architectural inference: Lite still needs structured logs, correlation IDs, immutable audit persistence, critical service and job metrics, security-safe masking, alerts for money, messaging, erasure and audit failures, and operational ownership without claiming the deferred AD-60 dashboard.The audit event schema, atomic persistence behavior, clock and correlation standard, masking and retention, authorized export, structured logging, minimum critical metrics and alerts, incident ownership, and recovery runbooks are approved and testable; AD-60 remains clearly excluded unless separately authorized.Backend Engineering Lead, Security or Compliance, and OperationsApplication features can be prototyped, but audit-sensitive writes and production operations cannot be accepted without durable evidence and recovery behavior.
VR-BLK-027Identity & SecurityOTP, lockout, session, password, and restricted-account policyCore feature blockerCriticalCustomer App, Agency, SuperadminCUS-PRD-4.3-OTP, CUS-PRD-5.1-RESTRICT, AG-R002, AD-01, NFR-SECOTP validity, resend and attempt limits, cooldown and reset behavior, alternate recovery, inactivity timeout, JWT rotation or revocation, password expiry, and restricted-user remediation are not fully fixed.Product Security approves one production authentication-policy matrix covering every customer, agency, and admin channel, including customer-facing restriction and recovery behavior.Product Security and Identity OwnerCentralize the controls as environment configuration and keep provider adapters separate; production authentication signoff remains blocked.
VR-BLK-034Agency OperationsAgency KYC evidence, review outcomes, rejection recovery, and initial creditsCore feature blockerCriticalAgency, Superadmin, Cross-App E2EAG-R003, AG-R004, AG-R005, AG-UI-008, AD-07Mandatory onboarding evidence, GST and PAN validation policy, failure handling, More Information behavior, appeal or resubmission versus terminal rejection, initial-credit amount, credit recurrence, and default edit rights are not settled.Agency Product, Compliance, and Finance approve the KYC checklist, validation contract, review state machine, rejection recovery policy, initial-credit amount and recurrence, and default customer-edit setting.Agency Product Owner, KYC or Compliance, and FinanceImplement explicit review states and configurable validation; prevent automatic approval and initial-credit allocation.
VR-BLK-035Identity & ReferralsCanonical six-digit agency-code namespace, rendering, uniqueness, and lifecycleCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.13-CODE, AG-R005, AG-R047, AG-UI-002, AG-GAP-001Mocks contain prefixed, alphanumeric, and variable-length codes while the requirement confirms six numeric digits; namespace capacity, reserved values, collision retry, uniqueness scope, retirement, and recycling are undefined.Product and Data Architecture approve the raw stored and displayed format, generation algorithm, capacity forecast, uniqueness boundary, collision handling, and code lifecycle.Product Owner and Data ArchitectUse an immutable internal agency identifier plus the canonical six-digit code and remove all conflicting mock examples.
VR-BLK-037Agency OperationsSuspension and permanent-blacklist effects across agency, customer, and shared casesCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2EAD-10, AG-R006Customer read and write rights, payments, documents, reports, existing-case behavior, notification audiences, and remediation during agency suspension or blacklist are not approved.Product, Operations, and Security approve an atomic state-impact matrix for agency users, agency codes, customer cases, financial actions, communications, reinstatement, and permanent blacklist.Product, Operations, and SecurityFreeze agency login, code use, and agency writes while preserving records; default affected customer cases to read-only pending a decision.
VR-BLK-039Document ProcessingDocument capture, correction authority, review, permanent failure, and version retentionCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.7-OCR, CUS-PRD-4.14-UPLOAD, AG-R021, CUS-UI-RECOVERYRequirements conflict on whether manual passport entry is permitted; low-confidence review, manual fallback, retry limits, permanent failure, correction precedence, latest versus retained versions, and safe retry behavior are undefined.Product, Document Data, and Compliance approve the field-authority, review, correction, retry, fallback, version-retention, and no-silent-overwrite contract.Product, Document Data SME, and CompliancePersist original and customer-confirmed values separately and route uncertain or failed extraction to manual review.
VR-BLK-040Co-applicant DomainParty capacity, relationships, mandatory evidence, primary-only scoring, charging, reporting, and invoicingCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.7A, CUS-PRD-4.7A-TOKEN, AG-R014, AG-R020, BUG-CUS-006Sources conflict on five co-applicants plus primary versus five total, one primary score and token versus one token per passport or combo reports, while relationship proofs, required fields, removal, and invoice entitlements are open.Product, Finance, and Scoring approve one party-capacity, relationship, mandatory-field, completion, removal, score, token, price, report, and invoice-entitlement matrix.Product, Finance, and Scoring OwnerModel party members independently but block party checkout and scoring until the entitlement matrix is signed.
VR-BLK-042Product ConfigurationVersioned dynamic forms, validation ranges, and destination or user-type document checklistsCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.14-CHECKLIST, AD-23, AD-26, AD-33, AD-34The field catalogue, ranges, dropdowns, conditional visibility, mandatory base checklist, seven user-type overlays, destination and visa variants, ordering, publication, rebuild, and in-flight migration rules are not supplied.Visa SME and Configuration Product approve the complete field, validation, condition, checklist, ordering, mandatory, publication, version, and migration catalogue.Visa SME and Configuration Product OwnerBuild immutable versioned definitions and pin each application to the version used when it began.
VR-BLK-043Product ConfigurationEffective dating, version pinning, publication atomicity, propagation, caching, and record migrationCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2EAG-R034, AG-R044, AD-20, AD-23, AD-24, AD-25, AD-26, AD-30, AD-33, AD-42, AD-46, AD-64, AD-70There is no cross-module contract for effective timezone, publication atomicity, cache invalidation, propagation SLA, record-version pinning, drafts, or treatment of in-flight applications and orders.Platform Architecture and Product approve a uniform configuration version, effective-time, publication, propagation, cache, rollback, and in-flight migration policy.Platform Architect and Product OwnerVersion every configuration, use UTC effective timestamps, and avoid retroactive mutation of existing records.
VR-BLK-045Scoring & RiskAuthoritative Lite and Final scoring semantics, factors, bands, penalties, and customer presentationCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.13-LITE, CUS-PRD-4.16-SCORE, AG-R022, AD-27, AD-28The Lite factor split and thresholds are open while mocks incorrectly show numeric Lite scores; Final Others rules, redistribution, ordered score-band boundaries, penalties, party scope, and customer labels are unresolved.Product and Scoring approve the five-factor non-numeric Lite contract and the complete seven-factor Final formula, normalization, bands, penalties, scope, reason codes, and presentation.Product Owner and Scoring SMEKeep Lite non-numeric according to the PRD and feature-flag both scoring stages until approved configuration exists.
VR-BLK-046Scoring & RiskRisk catalogue, FraudShield, fund-parking calculation, evidence review, waiver, appeal, and disclosureCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.14-FUND, CUS-PRD-4.20-RISK, AG-R024, AD-30, AD-31, AD-32Lookback, aggregation, timezone, exact thresholds, combinations, severities, penalties, proof catalogue, reviewer authority, waiver audit, appeal path, customer disclosure, and rescore trigger are unresolved.Risk, Compliance, and Product approve a complete effective-dated trigger, formula, threshold, severity, penalty, evidence, review, waiver, appeal, disclosure, and rescore matrix.Risk SME, Compliance, and Product OwnerImplement explainable inactive rules and a manual-review path; do not automatically hard-reject applicants using unapproved criteria.
VR-BLK-047Scoring & RiskScore-regeneration allowance, charging, idempotency, rollback, party scope, and improvement recommendationsCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-5.3-RESCORE, CUS-PRD-4.16A, AG-R023, AD-18Sources conflict between one free then paid regenerations and a strict two-total limit; qualifying changes, counter reset, failure rollback, party scope, pricing, recommendation catalogue, impact mapping, and detail-section access are incomplete.Product, Finance, and Scoring approve the original, free, paid, terminal, qualifying-change, counter-reset, compensation, party, recommendation, and display contract.Product, Finance, and Scoring OwnerCreate an idempotent rescore ledger and recommendation framework, but do not charge during development.
VR-BLK-048Commercial & FinanceB2C and B2B plans, prices, taxes, credits, quotas, renewal, expiry, carry-forward, and overridesCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.6.8, CUS-PRD-4.15-PRICE, AG-R014, AG-R028, AG-R029, AG-R030, AG-R033, AG-R034, AG-UI-003, AG-UI-007, AG-UI-009, AD-09, AD-42, AD-45, AD-50Core ranges, appended fixed and combo INR prices, USD mocks, credit-token semantics, permitted deductions, pack values, taxes, currencies, low-credit thresholds, renewal, expiry, carry-forward, auto-recharge, plan switching, usage fields, and override proration conflict or remain inputs.Commercial Product, Finance, and Tax approve a versioned B2C and B2B catalogue and lifecycle matrix covering price, currency, tax, quota, token, deduction, period, renewal, expiry, carry-forward, upgrade, override, and visible usage.Commercial Product, Finance, and TaxBuild a versioned catalogue and entitlement ledger, keep auto-recharge disabled, and use non-production sandbox values.
VR-BLK-049Commercial & FinancePayment state, refund eligibility, entitlement reversal, accounting documents, and reconciliation operationsCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.15-PRICE, AG-R031, AD-50, AD-52, AD-53Refund eligibility, partial amounts and fees, consumed-credit treatment, entitlement reversal, invoice or credit-note and tax handling, payment purpose and state model, settlement cadence, matching keys and tolerances, mismatch owner, and closing evidence are unspecified.Finance, Accounting, and Support Operations approve the end-to-end payment, refund, entitlement, accounting-document, reconciliation, exception, ownership, and closure state machines.Finance, Accounting, and Support OperationsBuild an idempotent financial ledger and manual reconciliation queue; do not automate refunds before policy approval.
VR-BLK-050Commercial & FinancePromo semantics, allocation, binding, use limits, expiry, failure recovery, waiver, and invoice treatmentCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.15-PROMO, AG-R042, AG-R043, AG-UI-004, AD-62Requirements define a customer transaction fee waiver while mocks show an agency recharge bonus; waived items, agency and customer binding, caps, single or multi-use behavior, expiry timezone, allocation commit on notification failure, fallback, and invoice treatment are unresolved.Commercial Product and Finance approve one promo semantic and complete generation, allocation, binding, distribution, redemption, cap, expiry, failure, waiver, accounting, and audit contract.Commercial Product and FinanceRemove recharge-bonus behavior and build an inactive generic promo ledger pending approval.
VR-BLK-051Workflow & LifecycleApplication-status transitions, authority precedence, corrections, conclusion, and review-link behaviorCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.17-TIMELINE, CUS-PRD-4.17-CONCLUSION, AMEND-S-1, AG-R026, AD-19The full prior-to-new state matrix, agency versus Admin authority, rollback and correction rights, terminal reason and decision-document rules, notification mapping, and review-link placement, copy, target, and eligible outcomes are not specified.Product and Operations approve one cross-app state machine with transition authority, precedence, reasons, corrections, reversals, disclosure, documents, notifications, and conclusion review-link behavior.Product and OperationsImplement a central state machine and reject transitions outside the currently approved subset.
VR-BLK-056Reporting & SharingVisaMatrix sections, factor presentation, branding, watermark, QR verification, and secure sharingCore feature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.16-REPORT, CUS-PRD-4.16-SHARE, AG-R025, AG-R038, AG-UI-005, AD-65Final section order, factor display, reason codes, intelligence configuration, watermark and logo assets, file type and size policy, agency co-branding, passport footer, QR destination and access security, share authentication, expiry, revocation, delivery history, and mock metric counts are unresolved.Product, Brand, and Security approve the versioned report template, assets, file policy, identity and footer rules, QR verification contract, and secure share-link lifecycle.Product, Brand, and SecurityBuild a versioned non-public preview renderer and use opaque authenticated links; do not publish reports until approved.
VR-BLK-036Agency OperationsPhase-1 lead ownership, manual allocation, invitation limits, notification, and SLA behaviorFeature blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.13-ROUTE, AG-R012, AG-R016, AG-R017, AD-08, AG-UI-010, AG-UI-012The notification channel and audience, SLA clock, warning and return-to-pool behavior, invitation resend and abuse controls, and distinction between mock-only New Lead and Add New Client are unresolved; transfer and automatic assignment are Phase 2.Agency Product and Sales Operations approve the Phase-1 pool, visibility, manual-allocation, invitation, notification, SLA, expiry, and recovery contract and explicitly defer Phase-2 transfer and automation.Agency Product Owner and Sales OperationsShip the Admin-owned unassigned pool with manual allocation; remove auto-transfer, ambiguous New Lead, and unlimited-send claims.
VR-BLK-052Admin OperationsSafe bulk agency and customer status operationsFeature blockerCriticalSuperadminAD-06, AD-13Bulk selection limits, source-to-target eligibility, preview and confirmation, atomic versus partial processing, partial-failure reporting, retry, and audit behavior are undefined.Admin Product, Operations, and Security approve an eligibility and execution matrix for every bulk action, including validation, confirmation, atomicity, partial failure, recovery, and audit.Admin Product, Operations, and SecurityShip audited individual actions first and leave bulk status and deactivation operations disabled.
VR-BLK-002External IntegrationWhatsApp Business API provider/account/configuration bindingFeature blockerHighCustomer App, Agency, Superadmin, Shared BackendCUS-EXT-WHATSAPP, CUS-PRD-4.6.9, AG-R012, AD-48, AD-49, EXT-WHATSAPP['Approved WABA account and sender number', 'Consent source and evidence', 'Approved templates and bot script', 'Signed referral/share-link format, expiry, replay controls, retry, and fallback'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the WABA account, sender identity, consent evidence, template catalogue, bot and support scripts, signed-link security contract, provider delivery states, retry, idempotency, and fallback behavior.Communications, Product, Compliance, BackendUse a mock messaging adapter that records intended payloads and delivery states without sending external messages.
VR-BLK-005External IntegrationTransactional email provider/account/configuration bindingFeature blockerHighCustomer App, Agency, Superadmin, Shared BackendCUS-EXT-OTP-EMAIL-PUSH, AG-R049, AD-47, AD-48, AD-49, EXT-EMAIL['Provider and environment account mapping', 'Verified sender domains and identities', 'Approved templates, subjects, and merge fields', 'Delivery SLA, bounce/suppression, retry, fallback, and dead-letter ownership'] Credential audit: No exact match in Master registry; availability unconfirmedApprove the provider, verified domain and sender identities, template and merge-field catalogue, delivery states and SLA, idempotency, retry, suppression, fallback, and dead-letter runbook.Communications, Product, DevOps, BackendUse a local mail-capture adapter with deterministic success, bounce, delay, and duplicate-event fixtures.
VR-BLK-006External IntegrationGoogle OAuth provider/account/configuration bindingFeature blockerHighCustomer App, Shared IdentityCUS-PRD-4.3-AUTH, CUS-PRD-4.13-LINK, EXT-OOS-001['OAuth clients for each environment and platform', 'Authorized origins and redirect URIs', 'Consent-screen ownership and publication status', 'Identity-linking, collision, account-recovery, and revocation policy'] Credential audit: No exact match in Master registry; availability unconfirmedSupply approved environment clients and redirect URIs, publish the consent configuration, and approve linking precedence, collision review, account recovery, revocation, and audit behavior.Identity, Security, Product, DevOpsUse a mock OIDC provider behind a provider-neutral identity adapter and synthetic identities.
VR-BLK-007External IntegrationPush notifications through FCM and APNs provider/account/configuration bindingFeature blockerHighCustomer App, Superadmin, Shared BackendCUS-EXT-OTP-EMAIL-PUSH, CUS-PRD-4.6.2, AD-48, AD-49, EXT-PUSH['Provider projects, app identifiers, and environment mapping', 'Signing-key and service-identity ownership', 'Device-token registration and retirement policy', 'Authorized deep-link, delivery-state, retry, and fallback contract'] Credential audit: No exact match in Master registry; availability unconfirmedApprove provider projects and application identifiers, secure key custody, token lifecycle, preference enforcement, authorized deep links, observable delivery states, retry, and fallback.Mobile Lead, Notifications Owner, Security, BackendImplement an in-app notification inbox and a no-send push adapter using synthetic device tokens.
VR-BLK-054Support OperationsPhase-1 support scope, ticket operating model, contacts, SLAs, premium claims, and analyticsFeature blockerHighCustomer App, AgencyCUS-PRD-4.6.9, AG-R041, AG-UI-006, AG-UI-011Customer requirements specify WhatsApp-only Phase-1 support while a mock exposes AI chat and FAQ; agency ticket categories, priority SLAs, contacts, help content, premium support, account-manager actions, and regional-analytics sources are not approved.Support Operations and Product approve the Phase-1 channels, ticket categories and states, priorities, SLA matrix, contacts, help content, entitlements, data sources, and customer-facing claims.Support Operations and Product OwnerRemove AI, FAQ, unsupported SLA, premium-support, account-manager, and regional-trend claims and show only approved contacts.
VR-BLK-038Customer Data RulesPassport boundaries, guardian handling, applicant terminology, booking states, and identity validationPartial development blockerCriticalCustomer AppCUS-PRD-4.7-VALID, CUS-PRD-4.8-TRIP, CUS-PRD-4.9-BASE, CUS-PRD-4.9-TYPES, BUG-CUS-002, BUG-CUS-003, BUG-CUS-004, BUG-CUS-007The exact six-month passport boundary, country overrides, guardian path, user-type terminology and configured values, booking statuses, name and mobile validation policy, trip-step labeling, and scan-tip copy are not fully settled.Customer Product, Visa SME, and UX approve a field, validation, boundary, terminology, conditional-routing, guardian, booking-status, and customer-copy matrix.Customer Product Owner, Visa SME, and UXKeep validations and value sets configurable, use PRD terminology, and avoid hard-coding disputed country and date boundaries.
VR-BLK-044Scoring & RiskFinancial ranges, country benchmarks, operators, tiers, bands, boosters, and funds modifiersPartial development blockerCriticalCustomer App, Agency, SuperadminCUS-PRD-4.10, AD-24, AD-25, AD-39Release financial ranges, destination benchmarks, supported operators and value types, overlap precedence, country tiers, experience and salary bands, boosters, and the approximate funds modifier are not final.Scoring and Visa or Finance SMEs approve one complete effective-dated parameter, type, operator, value, scope, and precedence matrix with reproducible examples.Scoring SME and Visa or Finance SMEBuild the rule schema and simulator, but keep unapproved values inactive.
VR-BLK-053CommunicationsNotification events, recipients, preferences, essential overrides, templates, and delivery lifecyclePartial development blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.6.2, AG-R039, AD-46, AD-47, AD-48, AD-49The business-event and category catalogue, recipients, role visibility, essential preference overrides, channel defaults, master-toggle exceptions, template and merge-field ownership, consent source, publication, retention, delivery states, retry, idempotency, and dead-letter ownership are incomplete.Product Communications, Legal, and Operations approve the event, audience, preference, consent, channel, template, publication, delivery, retry, retention, and ownership matrices.Product Communications, Legal or Consent, and OperationsBuild an event outbox and draft template framework, but suppress unapproved production communications.
VR-BLK-016Environment & InfrastructureDevelopment, test, UAT, and production topology with approved URLs and routing contractsPartial development blockerHighCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login Web, Shared Backend/APIAG-R008, CUS-PRD-4.16-SHARE, CUS-PRD-4.17-EMBASSY, CUS-EXT-RAZORPAY, AD-70Evidence-backed absence: requirements depend on a shared login URL, cross-app handoffs, report and notification deep links, embassy links, provider callbacks, and API behavior during maintenance, but no environment URL matrix or routing document is supplied. Architectural inference: each environment needs approved web and API base URLs, DNS and TLS ownership, provider callback and OAuth redirect URLs, mobile app links, CORS and CSP policy, session-cookie scope, and ingress or API-gateway routing.An approved environment matrix defines every public and internal base URL, DNS owner, TLS lifecycle, API origin, login and deep-link route, callback and redirect URI, cookie boundary, CORS and CSP rule, and environment promotion boundary.Platform Engineering Lead and Solution ArchitectLocal UI and domain logic can use placeholders; authentication handoff, provider registration, deep links, integrated testing, and deployment remain blocked.
VR-BLK-019Security & SecretsEnvironment-scoped secret delivery, non-secret configuration, rotation, and ownershipPartial development blockerHighCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APICUS-EXT-RAZORPAY, CUS-EXT-WHATSAPP, CUS-EXT-OCR, CUS-EXT-OTP-EMAIL-PUSH, CUS-EXT-STORAGE, SRC-SA-EXTEvidence-backed absence: external-provider credentials and configuration are repeatedly identified as client inputs, while no environment mapping or runtime configuration template is present in the workspace. Architectural inference: credential availability by itself is insufficient; separate sandbox, UAT, and production accounts, a secret-manager delivery model, least-privilege service identities, non-secret configuration schemas, rotation and revocation procedures, and accountable owners are required. No credential values are included in this record.Every required integration has an approved provider and environment account, a documented non-secret configuration schema, a secret-manager reference and runtime injection path, least-privilege access, rotation and revocation ownership, and a safe local or mocked fallback.Security Lead, Platform Engineering, and Integration OwnersAdapters and mocks can proceed without secrets; live sandbox, UAT, and production connectivity cannot.
VR-BLK-022Content & AssetsProduction branding assets, report template, PDF rendering, watermark, and QR verification contractPartial development blockerHighCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin PortalBUG-CUS-001, CUS-PRD-4.16-REPORT, CUS-PRD-4.16-SHARE, CUS-PRD-4.16-FOOTER, AD-65, AMEND-S-1, DRIVE-OBS-CONTENT-CONFIG-EMPTYEvidence-backed absence: requirements need approved launcher and splash branding, VisaReady and agency logos, an every-page watermark, ordered report sections, passport footer, report ID and QR, secure sharing, and the Conclusion review link, but no production asset pack or approved report template exists in the empty Content and Configurations folder. Architectural inference: implementation also needs an approved PDF renderer or service, font and asset licensing, template versioning, QR verification route, link authentication and expiry or revocation, and deterministic rendering tests.Approved source assets and usage rules, file constraints, launcher and splash package, report schema and ordered template, watermark and co-branding specification, PDF rendering approach, QR destination and security contract, secure-link lifecycle, and deterministic reference outputs are supplied.Product Design or Brand Owner, Reporting Engineering Lead, and SecurityLayout scaffolding, generic PDF generation, and asset slots can proceed; production identity, report acceptance, and secure verification cannot.
VR-BLK-057UX & DesignCanonical mocks, product naming, complete customer flows, and mobile or web parityPartial development blockerHighCustomer App, AgencyCUS-PRD-4.2, CUS-PRD-4.5, CUS-PRD-4.8-TRIP, CUS-PRD-4.11, CUS-PRD-4.13-LITE, CUS-PRD-4.19, CUS-PRD-4-SCOPE, CUS-UI-INCOMPLETE-001, AG-UI-001, AG-R047, BUG-CUS-001Home, onboarding, trip, Travel History, Lite score, Library, product and agency naming, code rendering, APK identity, and one incomplete Stitch item have conflicting variants; only mobile Customer mocks exist despite required web parity.Product, UX, and Brand approve one canonical mock per flow, VisaReady naming and branding tokens, the incomplete-item disposition, and responsive customer-web parity criteria.Product, UX, and BrandApply PRD precedence, remove conflicting variants and mock-only branding, and avoid pixel-final work until the UX baseline is signed.
VR-BLK-041Product ConfigurationLaunch-country, city, Schengen, visa-purpose, metadata, and official-link cataloguePre-UAT blockerCriticalCustomer App, Agency, Superadmin, Cross-App E2ECUS-PRD-4.8-COUNTRY, CUS-PRD-4.8-VISA, CUS-PRD-4.17-EMBASSY, AD-20, AD-21Launch countries, cities, ordering, Schengen rules, visa purposes, mandatory metadata, official URL inventory, content ownership, URL-health policy, and catalogue approval are missing or conflicting.Visa and Content owners approve the complete launch catalogue, ordering, purpose matrix, Schengen treatment, metadata, active states, official URLs, ownership, review, and health-check policy.Visa SME and Content or Product OwnerBuild draft and active catalogue management and expose only approved active records.
VR-BLK-009External IntegrationOfficial embassy and VFS URLs provider/account/configuration bindingPre-UAT blockerHighCustomer App, SuperadminCUS-PRD-4.17-EMBASSY, AD-20, EXT-EMBASSY['Approved launch-country URL catalogue', 'Official-domain and content ownership', 'URL validation and review cadence', 'In-app browser controls, allowlisting, and external-failure fallback'] Credential audit: No exact match in Master registry; availability unconfirmedProvide and approve the launch-country official-domain catalogue, owner, review and health-check cadence, allowlisting and navigation policy, and safe fallback content.Product, Visa Content Operations, ComplianceBuild a disabled, configuration-driven link component using non-production allowlisted fixtures.
VR-BLK-012External IntegrationApproved external review link at qr.link provider/account/configuration bindingPre-UAT blockerHighCustomer AppAMEND-S-1, CUS-PRD-4.17-CONCLUSION, AD-65['Business owner and availability commitment', 'Exact placement and display copy', 'Eligible granted or rejected Conclusion outcomes', 'Browser or deep-link behavior, security allowlisting, analytics, and fallback'] Credential audit: No exact match in Master registry; availability unconfirmedConfirm the URL owner and availability, exact placement and copy, eligible outcomes, navigation behavior, security allowlisting, tracking expectations, and safe fallback.Product, Content Owner, Customer App LeadImplement a feature-flagged configurable link component that remains hidden until the content and navigation contract is approved.
VR-BLK-024Testing & UATIsolated, resettable UAT environment with seeded identities, provider sandboxes, and controlled-failure capabilityPre-UAT blockerHighCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIE2E-WF-05, E2E-WF-06, E2E-WF-14, E2E-WF-15, E2E-WF-16, E2E-WF-19, WORKSPACE-OBS-NO-UAT-ENVIRONMENTEvidence-backed absence: no deployed UAT URLs, seeded role accounts, synthetic customer and agency identities, test documents, provider sandbox mapping, reset procedure, or fault controls are supplied. The designed E2E cases explicitly require delayed and duplicate webhooks, provider outages and recovery, OCR and storage timeouts, authorization-negative paths, and audit-store failure. Architectural inference: safe execution requires an isolated environment, test-data factory, reset and cleanup controls, observability, provider simulators or sandbox controls, and a rule prohibiting production identities and probing.All application and API UAT endpoints are deployed; approved synthetic role accounts, agencies, customers, plans, configurations, files, and provider sandboxes are seeded; repeatable reset and cleanup are documented; controlled failure and replay are safe and observable; and execution access is granted to the UAT team.UAT Lead, QA Environment Manager, Platform Engineering, and Integration OwnersTest-case review, automation planning, synthetic-data design, and simulator development can proceed; execution and acceptance cannot.
VR-BLK-059Non-functional AcceptancePerformance dataset and load profile plus supported browser, OS, device, and network matrixPre-UAT blockerHighSuperadminNFR-PERF, NFR-RESPThe three-second and 50-row targets lack dataset size, concurrency, geography, network profile, percentile, and controlled environment; desktop and tablet widths are stated but browser and OS support are not.QA Performance, Product, and Platform approve the test environment, data volume, concurrency, geography, network, percentile, measurement method, and supported browser, OS, and device matrix.QA Performance, Product, and PlatformCreate a controlled performance environment; treat provisional development measurements as diagnostic rather than acceptance evidence.
VR-BLK-060Testing & UATCross-app UAT environment, synthetic seed data, deterministic controls, observability, and recovery toolingPre-UAT blockerHighCustomer App, Agency, Superadmin, Cross-App E2ENFR-PERF, NFR-AUDIT, AD-53, AD-70, CUS-UI-RECOVERYNo approved UAT package is evidenced for role and tenant accounts, lifecycle states, versioned configurations, safe passports and bank data, payment and promo states, deterministic time, job and queue control, failure injection, reset and reconciliation, audit access, log correlation, or notification sinks.QA or UAT, DevOps, and Operations provide a documented isolated environment, synthetic fixture catalogue, role and tenant accounts, deterministic controls, reset and recovery tooling, observability, and execution runbook for all 19 E2E workflows.QA or UAT Lead, DevOps, and OperationsDevelop reusable synthetic fixtures and reset tools alongside features; never use live credentials or production PII.
VR-BLK-021Legal & PrivacyApproved legal documents, consent lifecycle, retention schedule, and erasure policyPre-release dependencyCriticalCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APICUS-PRD-4.4, CUS-PRD-4.6.3-DELETE, AD-15, AD-16, AD-64, NFR-DPDPAEvidence-backed absence: final Terms, Privacy Policy, Disclaimer, effective timezone, re-consent behavior, decline or defer experience, retention categories, erasure scope, evidence retention, and deletion SLA are unresolved and no legal content package exists in the empty Content and Configurations folder. Architectural inference: the implementation needs versioned legal content, durable consent evidence, session gating, a category-level erase, anonymize, retain, or unlink map, and legally reviewed operational ownership.Legal and Privacy approve final versioned copy, effective time, re-consent and decline behavior, consent evidence fields and retention, the complete data-retention and erasure matrix, deletion SLA, exceptions, customer communication, and accountable operators.Legal Counsel, Data Protection or Privacy Owner, and Product OwnerVersioned content and consent frameworks can be built with placeholders; production publication, defensible consent, and terminal erasure behavior cannot be accepted.
VR-BLK-028Legal & PrivacyFinal legal content, consent evidence, and forced re-consent lifecyclePre-release dependencyCriticalCustomer App, Superadmin, Cross-App E2ECUS-PRD-4.4, AD-64, NFR-DPDPAFinal Terms, Privacy Policy, and Disclaimer conflict with wording that calls the copy confirmed while also listing it as outstanding; effective timing, decline or defer behavior, re-consent, and evidence retention remain unresolved.Legal and the DPO sign off the final versioned documents, effective timezone, publication and re-consent rules, decline or defer behavior, and durable consent evidence.Legal, DPO, and Product OwnerBuild versioned draft, preview, publish, and consent-log mechanics, but do not publish placeholder legal content.
VR-BLK-058Platform OperationsMaintenance-mode boundary behavior and measurable platform availabilityPre-release dependencyCriticalCustomer App, Agency, Superadmin, Cross-App E2EAD-70, NFR-AVAIL, AD-60Maintenance timezone, active-session treatment, API and cache behavior at enable and disable boundaries, break-glass access, availability measurement window, exclusions, telemetry source, and acceptance evidence are unresolved while dedicated APM is outside Lite scope.SRE, Platform, and Product approve the maintenance-mode access and write boundary, schedule and recovery policy, and the 99.5 percent SLI or SLO measurement and evidence contract.SRE, Platform, and ProductImplement gateway-level write blocking with Admin break-glass and UTC scheduling; do not claim availability acceptance without approved telemetry.
VR-BLK-025Delivery & DevOpsCI/CD, artifact provenance, environment promotion, migration, deployment, and rollback capabilityPre-release dependencyHighCustomer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/APIWORKSPACE-OBS-NO-CICD, WORKSPACE-OBS-NO-DEPLOYMENT-MANIFEST, AD-70, NFR-AVAILEvidence-backed absence: no CI definition, Dockerfile, infrastructure-as-code, artifact registry configuration, deployment manifest, database migration command, release versioning, or rollback instruction is visible. Architectural inference: repeatable delivery requires build, test, scan, sign, package, provenance, environment-promotion and approval stages, migration gates, deployment health checks, rollback, and release ownership.Each deployable has a reproducible CI/CD pipeline with dependency and security checks, versioned immutable artifacts, signing where applicable, approved environment promotion, secret-safe deployment, database migration and rollback gates, health verification, release approvals, and a tested rollback procedure.DevOps or Platform Engineering Lead and Release ManagerLocal development can proceed once source is available; controlled UAT and production delivery cannot.
VR-BLK-055Content & AssetsKnowledge library, country guidance, cover letters, itineraries, editorial ownership, and publication governancePre-release dependencyHighCustomer App, Agency, SuperadminCUS-PRD-4.19, CUS-PRD-4.17-EMBASSY, AD-33, AD-41, AD-63Library versus Knowledge Base naming and navigation, launch inventory and ordering, country guidance, official links, editorial owner and review cadence, UK, Canada, Australia, and Schengen cover-letter or itinerary copy, merge fields, and publication rules are missing.Content, Visa, and Legal owners approve the label and navigation, launch inventory, country copy and links, templates, merge-field catalogue, editorial workflow, publication rules, and review cadence.Content Owner, Visa SME, and LegalKeep all content in draft and never expose placeholder or unpublished guidance.
VR-BLK-061Known DefectsEight pending Customer application defects require implementation and regression evidencePre-release dependencyHighCustomer AppBUG-CUS-001, BUG-CUS-002, BUG-CUS-003, BUG-CUS-004, BUG-CUS-005, BUG-CUS-006, BUG-CUS-007, BUG-CUS-008The reported Customer build still has pending issues for package or splash identity, numeric names, invalid mobile length, save confirmation, Single or Multiple selection, scan tips, and Destination Save and Continue behavior.Customer Engineering provides a signed target build and QA verifies all eight fixes, including persistence, downstream routing, double-submit protection, and no regression to the related workflows.Customer Engineering, QA, and ProductUnrelated development may continue, but the affected workflows cannot receive release signoff until the defects are fixed and retested.
VR-BLK-011External IntegrationSystem health and APM monitoring provider/account/configuration bindingNon-blocking / out of scopeMediumAll applications, Platform OperationsAD-60, NFR-AVAIL['Explicit Lite exclusion and future-phase ownership', 'Availability SLI, measurement window, and exclusions', 'Future monitoring provider, alerting, and evidence policy'] Credential audit: No exact match in Master registry; availability unconfirmedKeep AD-60 explicitly excluded from Lite and separate it from current acceptance, or approve a future provider, SLIs, measurement window, exclusions, alert ownership, and evidence method.Product, SRE, OperationsProvide structured logs and basic critical-failure alerts without implementing or presenting the out-of-scope AD-60 dashboard.
VR-BLK-062Scope GovernanceExplicit Phase-2 and future-scope features must not create active MVP behaviorNon-blocking / out of scopeHighAgency, SuperadminAG-R050, AD-08, AD-60Pay-Per-Use, a public agency directory, lead transfer and automatic assignment, and dedicated APM or System Health are stated as Phase 2 or outside Lite, but some designs or calls to action can imply they are available.Product and Program Management confirm the MVP exclusion list, remove or visibly disable unsupported actions, and create a separate approved Phase-2 baseline before implementing those behaviors.Product Owner and Program ManagerKeep the features absent or explicitly non-operational; do not create unsupported financial, ownership, or monitoring states.

Known implementation defects

These are known work items and release risks, not missing external dependencies. They are kept separate so they are not confused with client/architecture blockers.

IDAreaIssueStatusImpactRequired outcome
BUG-CUS-001Launcher / brandingLogo is missing; only the APK file is shown.PendingRelease packaging and brand acceptance remain incomplete.Produce a signed build with the approved launcher identity, icon, splash, and version metadata.
BUG-CUS-002Edit profileFirst name accepts numeric values.PendingInvalid identity data can enter the shared customer record.Apply the approved name validation and error handling consistently on client and server.
BUG-CUS-003Edit profileLast name accepts numeric values.PendingInvalid identity data can enter the shared customer record.Apply the approved optional-last-name validation consistently on client and server.
BUG-CUS-004Edit profileMobile number accepts 13 digits.PendingInvalid contact and OTP identities may be stored or linked.Apply the approved country-code/mobile-length policy with normalized storage and server validation.
BUG-CUS-005Edit profileSuccessful save does not show the required confirmation.PendingUsers cannot distinguish committed changes from failed or pending saves.Show one accessible success notification only after durable persistence; preserve safe retry on failure.
BUG-CUS-006Passport detailsSingle/Multiple applicant toggle is missing.PendingThe family/multi-applicant journey cannot be selected from the evidenced screen.Restore the selector after the approved party-capacity and entitlement model is signed.
BUG-CUS-007Passport detailsPassport scanning tips are missing.PendingPoor captures may increase OCR failure and manual-review volume.Publish approved capture guidance aligned with the chosen OCR provider and supported document set.
BUG-CUS-008Destination and tripSave and Continue is not working.PendingA core readiness-assessment workflow cannot progress.Persist the step idempotently, prevent duplicate submission, advance once, and support safe retry.

Evidence and method

Primary sources

IDTypeTitleModifiedUse
SRC-CUS-REQPrimary requirementsVisaReady Final Doc Customer application.docx2026-07-13T18:56:18ZCustomer workflows, rules, client-input questions, security and commercial behavior.
SRC-AG-REQPrimary requirementsVisaReady Final Doc Agency with ui.docx2026-07-13T18:57:46ZAgency onboarding, shared record, wallet, roles, support and UI evidence.
SRC-SA-REQPrimary requirementsVisaReady Final Doc Admin.docx2026-07-13T18:57:18ZAdmin configuration, governance, finance, audit, privacy and NFR requirements.
SRC-EXTExternal integration requirementsVisaReady Final Doc External api list.docx2026-07-13T18:57:35ZAuthoritative list of MVP and supporting integration families and client inputs.
SRC-AMENDApproved amendmentAmendment sheetReviewed 2026-07-18Adds the external review link at Customer Conclusion.
SRC-UATTraceability baselineVisaReady Test cases2026-07-18T12:45:51Z326 UAT cases, 280 requirement/gap rows, 68 workflows and 203 evidence records.
SRC-UI-MAPUI project mapVisaready UIReviewed 2026-07-18Resolves the Customer, Agency and Superadmin Stitch projects used for conflict evidence.
SRC-BUGSReported issuesCustomerApp BugsReviewed 2026-07-18Eight pending Customer implementation defects; Agency/Admin registers are header-only.
SRC-CONFIGDrive folderContent and ConfigurationsVerified empty 2026-07-18Evidence that the required versioned business configuration release bundle has not been supplied.
SRC-CREDCredential registryMaster external api sheetRead-only exact lookup 2026-07-1852 exact requirement/provider/project identifier checks; zero exact matches; no values revealed.
SRC-PROJECT-CREDMetadata-only evidenceVisa ready Api Creds2026-07-14T17:15:02ZSeparate project workbook exists, but was not opened because it is not the configured $cred registry and no exact registry mapping was found.
SRC-WORKSPACEWorkspace inventory/home/usr1/code2/visaready3Verified 2026-07-18Contains test-design artifacts only; no application source, build manifest, lockfile, deployment definition or environment template.
Show all 185 non-Covered requirement traceability rows
ApplicationRequirement / Evidence IDRequirement / RuleSource EvidenceActorsWorkflowsTest Case IDsCoverage StatusConflict / Gap / AssumptionBusiness RiskRecommended Clarification
Customer AppCUS-PRD-4.3-OTPOTP is four digits, resend waits 30 seconds, and attempts are limited to three.Customer PRD §4.3 Stitch OTP screenCustomerCUS-WF-02UAT-CUS-008, UAT-CUS-098Partially CoveredWording 'up to three attempts, then account verification' is ambiguous about lock duration/recovery.OTP abuse or legitimate-user lockout.Define attempt reset, cooldown, OTP validity, and alternate-method rules.
Customer AppCUS-PRD-4.4Current Terms, Privacy Policy, and Disclaimer require full scroll plus one consent checkbox; acceptance version/time/user are logged.Customer PRD §4.4 and appended legal copyNew User, Returning UserCUS-WF-02UAT-CUS-005, UAT-CUS-010, UAT-CUS-011Partially CoveredThe document calls copy confirmed but also lists final legal copy as outstanding.Invalid consent and DPDPA exposure.Approve final legal versions and re-consent policy.
Customer AppCUS-PRD-4.5Home supports new/returning users, application resume, quick actions, latest readiness, required bottom navigation, and primary-only co-applicant score explanation.Customer PRD §4.5 Stitch Home variantsCustomerCUS-WF-03UAT-CUS-003, UAT-CUS-012, UAT-CUS-013, UAT-CUS-044, UAT-CUS-073Partially CoveredStitch variants alternately remove/restore score and quick actions and disagree on percent formatting/navigation.Core journeys become undiscoverable or score meaning becomes misleading.Approve one canonical Home mock aligned to the PRD.
Customer AppCUS-PRD-4.6.1-7Profile photo, contact, personal, passport, address, and travel preferences are editable/reusable without OTP reverification.Customer PRD §4.6.1 and §4.6.4-4.6.7CustomerCUS-WF-04UAT-CUS-015, UAT-CUS-092, UAT-CUS-094Partially CoveredFinal editable-field list is still marked client input.Stale identity data or unintended application changes.Approve the final editable-field matrix and propagation rules.
Customer AppCUS-PRD-4.6.2Notification categories and in-app/WhatsApp/email channels can be independently toggled with a master toggle; documented events generate messages.Customer PRD §4.6.2 External API document: WhatsApp/email/pushCustomerCUS-WF-17UAT-CUS-016, UAT-CUS-085, UAT-CUS-099, UAT-CUS-102Partially CoveredEssential-message override rules and final templates/channel defaults are open.Missed critical updates or unwanted communication.Approve event/channel matrix, templates, and master-toggle exceptions.
Customer AppCUS-PRD-4.6.3-EXPORTCustomer can request an export of all stored data.Customer PRD §4.6.3 Customer PRD §6.2Customer, Data OperationsCUS-WF-05UAT-CUS-018, UAT-CUS-103Needs clarificationFormat, secure delivery, SLA, retention, and duplicate-request behavior are unspecified.DPDPA right cannot be accepted or verified consistently.Define export contents, format, authentication, delivery, expiry, and SLA.
Customer AppCUS-PRD-4.6.3-DELETEDeletion is a reviewed admin request, not immediate; customer is notified on submission and completion.Customer PRD §4.6.3 pf_delete External API document: deletion confirmationsCustomer, Super AdminCUS-WF-05UAT-CUS-019Needs clarificationRetention, erasure SLA, pending-account behavior, and retained audit fields are open.Incomplete erasure or accidental account loss.Approve deletion state machine and DPDPA retention/SLA.
Customer AppCUS-PRD-4.6.8Profile Plan shows current plan/status/validity/usage/history and supports renew, upgrade/change, and invoices.Customer PRD §4.6.8CustomerCUS-WF-04, CUS-WF-12UAT-CUS-020, UAT-CUS-062, UAT-CUS-063, UAT-CUS-100Partially CoveredFinal displayed status/usage fields are a client input.Customers cannot understand entitlement or billing.Approve plan-status field set.
Customer AppCUS-PRD-4.6.9Phase-1 support is a single WhatsApp action; in-app FAQ and other contact options are deferred.Customer PRD §4.6.9 External API document: WhatsApp support Stitch Support Assistant and WhatsApp-only redesignCustomerCUS-WF-04, CUS-WF-18UAT-CUS-021Partially CoveredSupport Assistant mock contains AI chat and FAQ that directly conflicts with PRD; WhatsApp-only redesign aligns.Unapproved support scope and misleading AI guidance.Supersede/remove the AI Support Assistant mock and publish support number/message.
Customer AppCUS-PRD-4.7-OCRPassport may be OCR-scanned, reviewed with confidence, corrected, or manually entered and reused downstream.Customer PRD §4.7 External API document: passport OCRCustomerCUS-WF-06UAT-CUS-023, UAT-CUS-024, UAT-CUS-025, UAT-CUS-093Partially Covered§4.1 says first-run details are populated via OCR with no manual key-in, while §4.7 explicitly allows manual entry.Customers may be blocked by OCR or inconsistent identity data.Confirm when manual entry is permitted and authoritative.
Customer AppCUS-PRD-4.7-VALIDPassport format/date rules and six-month validity beyond return are enforced/advised.Customer PRD §4.7, §4.20, §5.6CustomerCUS-WF-06UAT-CUS-026Partially CoveredBoundary wording alternates under six months and six months or less.Incorrect visa-readiness risk.Define exact date boundary and country overrides.
Customer AppCUS-PRD-4.7AMulti mode supports spouse/child/parent/other forms, completion hub, removal, primary protection, seat limit, and pre-payment completion gate.Customer PRD §4.7a Stitch Family ManagementPrimary Applicant, Co-ApplicantCUS-WF-08UAT-CUS-041, UAT-CUS-042, UAT-CUS-043, UAT-CUS-093Needs clarificationMaximum is described as five co-applicants plus primary but UI text/seat wording can imply five total; proof/mandatory fields are open.Wrong party capacity or incomplete travel-party evidence.Confirm capacity and relationship-proof/mandatory matrix.
Customer AppCUS-PRD-4.7A-TOKENOnly primary is scored and co-applicant completion percentages are not VisaScores; party charging follows the approved model.Customer PRD §4.7a, §4.15, §5.3, appended PricingPrimary Applicant, Co-ApplicantCUS-WF-08, CUS-WF-12UAT-CUS-044Needs clarificationCore PRD says one primary score/token; companion says one token per passport; appended pricing offers combo separate scores/reports.Material over/undercharging and wrong customer results.Approve one primary/co-applicant scoring, token, price, and report entitlement table.
Customer AppCUS-PRD-4.8-COUNTRYConfigured active/popular/all destinations, multiple country selection, Schengen jurisdiction guidance, and city lists drive the trip.Customer PRD §4.8 and appended country/Schengen inputCustomerCUS-WF-06UAT-CUS-027, UAT-CUS-028Partially CoveredFinal MVP country/city lists and ordering remain configuration inputs.Wrong jurisdiction or unavailable destinations.Approve launch country/city lists and ordering.
Customer AppCUS-PRD-4.8-VISAA mandatory visa type/purpose drives forms and documents; Work/Employment is not offered in the original version.Customer PRD §4.8 Appended Client Input §7.2CustomerCUS-WF-06UAT-CUS-027, UAT-CUS-028Needs clarificationCore PRD allows Tourist/Visitor, Student, Business; appended input lists Tourism, Business, Family Visit, Student, Transit, Conference, Cruise.Wrong workflow/checklist and pricing.Approve MVP purposes and their destination-specific forms/checklists.
Customer AppCUS-PRD-4.8-TRIPTravel dates, computed duration, destination cities, booking statuses, summary, and save controls are validated.Customer PRD §4.8 Step 2c Stitch Travel Details screenCustomerCUS-WF-06UAT-CUS-027, UAT-CUS-028Partially CoveredStitch labels Travel Details as Step 5 though PRD places it in Step 2c; booking-option confirmation is open.Incorrect sequence and score/document inputs.Correct mock step label and approve booking statuses.
Customer AppCUS-PRD-4.9-TYPESEight user types route to their type-specific profile data and document evidence.Customer PRD §4.9 and §4.14All Applicant TypesCUS-WF-07UAT-CUS-030, UAT-CUS-031, UAT-CUS-032, UAT-CUS-033, UAT-CUS-034Partially CoveredMock uses Housewife vs PRD Homemaker; final configured value sets remain open.Applicants see the wrong path or checklist.Approve terminology and value sets.
Customer AppCUS-PRD-4.10Financial profile uses configured ranges with conditional FD/investment/ITR values and feeds Financial Strength.Customer PRD §4.10, §5.3, appended financial matrixCustomerCUS-WF-06UAT-CUS-036Partially CoveredRelease range definitions remain editable/config-dependent.Inaccurate affordability/readiness score.Publish release range and destination benchmark configuration.
Customer AppCUS-PRD-4.11Visited countries, held/current visas, refusal, overstay, and immigration violations feed travel scoring and risk.Customer PRD §4.11 and §5.3CustomerCUS-WF-06UAT-CUS-037, UAT-CUS-038Partially CoveredThree Stitch variants each omit or restore different required fields; no single canonical mock contains the full set.Missing travel history changes the score materially.Consolidate and approve one complete Travel History screen.
Customer AppCUS-PRD-4.13-CODEOptional agency code is exactly six numeric digits, validates active agency, maps the whole application at any step, and pre-fills from referral.Customer PRD §4.13 and appended code-capacity answer Stitch Agent ID/Referral screensCustomer, Agency User, Super AdminCUS-WF-09UAT-CUS-045, UAT-CUS-046, UAT-CUS-048Partially CoveredStitch uses alphanumeric examples such as 56001ZY8 and GTS-IND-4429, conflicting with confirmed numeric 100000-999999 rule.Wrong lead ownership and referral failures.Replace mock examples with valid six-digit numeric codes.
Customer AppCUS-PRD-4.13-LINKAgent-created applications link to a later matching verified email/mobile account and remain one shared record.Customer PRD §4.13 Account Linking and §4.17 shared recordCustomer, Agency UserCUS-WF-09UAT-CUS-049, UAT-CUS-050, UAT-CUS-096Needs clarificationIdentity collision and simultaneous-edit conflict resolution are unspecified.Duplicate accounts, wrong customer linkage, or data corruption.Define matching precedence, collision handling, field ownership, and concurrency policy.
Customer AppCUS-PRD-4.13-LITELite uses five factors and outputs Low/Medium/High only with disclaimer; no numeric score, flags, risk levels, Document Readiness, Others, or penalties.Customer PRD §4.13 and §5.3 Stitch Preliminary Eligibility ScoreCustomerCUS-WF-10UAT-CUS-051, UAT-CUS-052, UAT-CUS-053Needs clarificationStitch exposes numeric 72 and numeric factor scores; exact Lite thresholds are still open.Misleading readiness claim and incorrect product entitlement.Approve thresholds and redesign Lite mock to PRD output.
Customer AppCUS-PRD-5.3-RESCOREA data change is required; the post-original regeneration allowance and charging limit are application-scoped.Customer PRD §4.13, §4.16a, §5.3 and appended answersCustomerCUS-WF-14UAT-CUS-074, UAT-CUS-075, UAT-CUS-076Needs clarificationMain text says one free then second onward paid; appended answer says ONLY 2 TIME/TOTAL 2 and not more.Surprise charges or unlimited/blocked scoring.Approve exact terminal state after the one free regeneration and counter-reset behavior.
Customer AppCUS-PRD-4.14-CHECKLISTPaid checklist is derived from visa/user type with common and type-specific mandatory evidence.Customer PRD §4.14CustomerCUS-WF-11UAT-CUS-054, UAT-CUS-060Partially CoveredPer-destination checklists and mandatory matrix remain Admin/client inputs.Verified score based on wrong/missing evidence.Approve all destination/visa/user-type checklists.
Customer AppCUS-PRD-4.14-FUNDSudden deposit detection uses configured history/thresholds; valid source proof waives fund-parking penalty.Customer PRD §4.14 and appended 45-day/50% recurring-deposit answerCustomerCUS-WF-11UAT-CUS-058Partially CoveredLow-balance/large-credit thresholds remain open; phrase '50% of correct balance' needs normalization.False fraud/risk penalty or missed funds parking.Approve exact formula, time zone/date handling, recurrence, and proof validation.
Customer AppCUS-PRD-4.20-RISKCustomer sees advisory passport/travel/salary warnings; Final alone shows penalties and FraudShield hard flag.Customer PRD §4.20 and §5.3CustomerCUS-WF-06, CUS-WF-11, CUS-WF-13UAT-CUS-026, UAT-CUS-038, UAT-CUS-058, UAT-CUS-059Partially CoveredManual review/appeal and some risk values are unspecified.Incorrect rejection guidance and inability to correct false positives.Approve final risk catalogue, values, customer copy, and review path.
Customer AppCUS-PRD-4.15-PRICECustomer selects Lite/Starter/Advance with configured visa/pack pricing; direct B2C is separate from agency wallet.Customer PRD §4.15 and §5.7, appended Pricing Stitch Subscription Plans and PaymentCustomerCUS-WF-12UAT-CUS-062, UAT-CUS-068, UAT-CUS-100Needs clarificationCore ranges, appended fixed/combo INR prices, fixed-fee checkout mock, and USD annual-plan mock conflict.Material financial and entitlement error.Approve one B2C price/pack/entitlement catalogue and update mocks.
Customer AppCUS-EXT-RAZORPAYRazorpay handles customer payment, webhook reconciliation, and refunds idempotently.External API document: Razorpay Customer PRD §4.15Customer, Billing OperationsCUS-WF-12UAT-CUS-063, UAT-CUS-066, UAT-CUS-097Needs clarificationKeys/webhooks are client inputs; refund eligibility, entitlement reversal, and credit-note rules are absent.Double charge, unreconciled money, or incorrect entitlement.Approve payment/refund state machine, webhook idempotency, and accounting documents.
Customer AppCUS-PRD-4.15-PROMOPromo must exist, be valid/unused, and match the application's agency; eligible amount is waived and invoiced.Customer PRD §4.15 and appended promo answerAgency-Referred Customer, AgencyCUS-WF-12UAT-CUS-064, UAT-CUS-065, UAT-CUS-067Needs clarificationWaiver scope and single/multi-use allocation are not consistently defined.Promo abuse or incorrect revenue.Define waived line items, code lifecycle, limits, and delivery template.
Customer AppCUS-PRD-4.16-SCOREFinal score uses seven weighted factors minus penalties, clamped 0-100 with configured bands and primary-applicant scope.Customer PRD §4.16 and §5.3CustomerCUS-WF-13UAT-CUS-069Needs clarificationOthers 5% subrules are undefined; band text overlaps below 58/below 40; party scoring conflicts elsewhere.Nonreproducible or misleading score.Approve Others rules, ordered band boundaries, penalty values, and party scope.
Customer AppCUS-PRD-4.16-REPORTAdvance VisaMatrix contains required intelligence/recommendation sections, is non-guaranteeing, branded, watermarked, and verifiable by ID/QR.Customer PRD §4.16, §5.4-5.5CustomerCUS-WF-13UAT-CUS-068, UAT-CUS-070, UAT-CUS-101Partially CoveredTemplate order, intelligence config, watermark asset, and some mock metric counts are unresolved.Wrong entitlement, unverifiable report, or unapproved claims.Approve template, seven-factor display, reason codes, and branding assets.
Customer AppCUS-PRD-4.16-SHAREVisaMatrix supports WhatsApp, email, copy link, and PDF with consistent identity and secure storage/delivery.Customer PRD §4.16 and §4.18 External API document: WhatsApp/email/storageCustomerCUS-WF-13UAT-CUS-071, UAT-CUS-072Needs clarificationShare-link authentication, expiry, revocation, and delivery history are unspecified; 30 days exists only in mock.Report leakage or failed delivery.Approve link access/expiry/revocation and channel templates.
Customer AppCUS-PRD-4.16AScore Improvement is application-scoped, impact-ordered, non-guaranteeing, change-gated, and linked to relevant actions.Customer PRD §4.16aReturning UserCUS-WF-14UAT-CUS-073, UAT-CUS-074, UAT-CUS-076Partially CoveredRecommendation catalogue, impact mapping, target copy, and fully-optimized empty state are open.Misleading uplift or changes applied to wrong application.Approve recommendation/impact catalogue and target copy.
Customer AppCUS-PRD-4.17-TIMELINESystem/agency stages produce ordered completed/current/pending timeline states, details, documents, and notifications.Customer PRD §4.17 timeline Stitch tracking/status screensCustomer, Agency UserCUS-WF-15UAT-CUS-078, UAT-CUS-080, UAT-CUS-081, UAT-CUS-102Partially CoveredComplete allowed-transition/rollback matrix and status authority are not fully specified.Customer sees false case progress.Approve status transition/authority matrix and correction policy.
Customer AppCUS-PRD-4.17-CONCLUSIONSelf-applied users record Yes/No receipt; agency applications show agency Accepted/Rejected plus decision document.Customer PRD §4.17 ConclusionSelf-Applied Customer, Agency-Referred Customer, Agency UserCUS-WF-15UAT-CUS-079, UAT-CUS-080Partially CoveredEdit/reversal behavior and reason constraints are unspecified.Incorrect terminal outcome.Define conclusion correction/reversal permissions.
Customer AppAMEND-S-1Phase-1 Conclusion includes review link https://qr.link/9bpJ5L.Amendment sheet Sheet1 row 3, s-1, 15/07/26CustomerCUS-WF-15UAT-CUS-082Needs clarificationDisplay copy, target behavior, and applicability to rejected customers are not stated.Approved amendment may be omitted or shown inappropriately.Confirm exact placement/copy and eligible conclusion outcomes.
Customer AppCUS-PRD-4.17-EMBASSYSubmitted application opens the configured official embassy/VFS URL in an in-app browser.Customer PRD §4.17 External API document embassy URLsCustomerCUS-WF-15UAT-CUS-081Needs clarificationPer-country official URLs are a client input.Customer is sent to wrong or unsafe tracking site.Provide and approve launch-country URL catalogue.
Customer AppCUS-PRD-4.19Bottom navigation includes Library/Knowledge Base with published per-country guidance and safe unpublished state.Customer PRD §4.19 and appended Library answer Stitch Visa Library and Home variantsCustomerCUS-WF-16UAT-CUS-084Needs clarificationPRD names Library and fixed five-item nav; client suggests Knowledge Base/alternate placement; mocks inconsistently omit it.Important guidance is undiscoverable or draft content leaks.Approve final label, nav position, country list, and content ownership.
Customer AppCUS-PRD-6.2Personal/financial data is encrypted, financial data is not shared with third parties, document integrity is checked, and data-residency/DPDPA rules apply.Customer PRD §6.2Customer, OperationsCUS-WF-05, CUS-WF-20UAT-CUS-003, UAT-CUS-014, UAT-CUS-018, UAT-CUS-019, UAT-CUS-050, UAT-CUS-076, UAT-CUS-083, UAT-CUS-096, UAT-CUS-101, UAT-CUS-103, UAT-CUS-104Needs clarificationEncryption standards, residency region, retention, third-party boundaries, and audit acceptance evidence are not specified.Severe privacy/compliance exposure.Approve measurable security, residency, retention, and audit controls for UAT/security acceptance.
Customer AppCUS-EXT-WHATSAPPWhatsApp Business API supports referral/bot, status notifications, customer support, and report sharing with recoverable failures.External API document: WhatsApp Business API Customer PRD §3, §4.6.9, §4.16Customer, Agency UserCUS-WF-09, CUS-WF-17, CUS-WF-18UAT-CUS-021, UAT-CUS-045, UAT-CUS-071, UAT-CUS-089, UAT-CUS-090, UAT-CUS-099Needs clarificationCredentials, templates, bot script, and signed-link format are client inputs.Attribution loss, failed communication, or unapproved messaging.Provide approved WABA account, templates, bot script, and referral-link security contract.
Customer AppCUS-EXT-OTP-EMAIL-PUSHOTP/email/push services deliver authentication and business events according to identity and preferences with retry/deduplication.External API document: SMS/OTP, transactional email, FCM/APNsCustomerCUS-WF-02, CUS-WF-17UAT-CUS-005, UAT-CUS-006, UAT-CUS-008, UAT-CUS-016, UAT-CUS-095, UAT-CUS-098, UAT-CUS-099Needs clarificationProviders, templates, retry/dead-letter behavior, and essential-event overrides are not specified.Failed login or missed critical events.Approve provider/configuration and event-delivery contract.
Customer AppCUS-EXT-STORAGECloud storage persists owned uploads/reports securely and supports retry without duplication.External API document: cloud storage Customer PRD §4.14 and §4.16CustomerCUS-WF-11, CUS-WF-13UAT-CUS-055, UAT-CUS-057, UAT-CUS-061, UAT-CUS-070, UAT-CUS-072, UAT-CUS-103Needs clarificationStorage provider, encryption, URL expiry, malware handling, retention, and deletion propagation are unspecified.Sensitive document leakage or loss.Approve storage security/lifecycle and signed-link requirements.
Customer AppCUS-EXT-OCRPassport, bank-statement, and supporting-document OCR extracts usable structured data, exposes low-confidence or failed extraction for review, and never silently overwrites customer-confirmed values.External API document: passport, bank-statement, and fund-parking OCR Customer PRD §4.7, §4.14, and §4.20Customer, OCR/Document Intelligence ServiceCUS-WF-06, CUS-WF-11UAT-CUS-024, UAT-CUS-025, UAT-CUS-057, UAT-CUS-058, UAT-CUS-059, UAT-CUS-061Needs clarificationProvider, confidence thresholds, supported statement layouts, review routing, and extraction-failure behavior are not specified.Incorrect identity, financial evidence, or fraud-risk outcomes may be accepted without customer visibility.Approve OCR provider, field map, confidence thresholds, review controls, supported documents, and failure contract.
Customer AppCUS-UI-INCOMPLETE-001Stitch source item 3e93ad3ac3bd4fcb84a4eee1d183e8b8 must be finalized or identified as obsolete.Stitch project 3025077632249781985 / screen 3e93ad3ac3bd4fcb84a4eee1d183e8b8 titled Generating Screen...Needs clarificationNo finalized title, prompt, HTML, or usable behavior exists.A missing intended UI flow could remain untested.Finalize the item with a named requirement/flow or remove it as obsolete.
Customer AppCUS-UI-ASSETSTwenty standalone images/SVG/uploaded screenshots are visual assets, not independently testable functional screens.Stitch project 3025077632249781985: 20 asset-only items inventoried in screens[]No testable behaviorTheir owning UI behavior is covered through functional screens where relevant.Assets could be double-counted as screens and inflate false coverage.
Customer AppCUS-SRC-002-NOTEThe Customer UI DOCX is reference-only and does not override the requirements document.VisaReady Customer ui.docx: 'These are just ui reference screen will be according to doc'No testable behaviorMock conflicts are therefore recorded against PRD precedence.Outdated mock behavior could be accepted as a requirement.
AgencyAG-R003GST/PAN and onboarding evidence are validated using the client-approved mandatory-document and verification rules.AG-PRD Screen 1 client-input note AG-PRD Section 9.1 EXT-API GST/PAN noteProspective Agency Admin, Super Admin ReviewerAG-WF-01UAT-AGREG-002Needs clarificationMandatory document list and format/checksum/live verification choice are unset.Fraudulent or valid agencies may be incorrectly accepted or rejected.Approve mandatory documents and whether GSTIN/PAN use format-only or live registry verification.
AgencyAG-R005Approval issues one unique read-only 6-digit agency code and initial credits; the active code maps customers to the agency.AG-PRD Screens 1-2 reg_code/apr_grant AG-PRD Sections 2.3 and 5.1Super Admin, Agency Admin, CustomerAG-WF-01, AG-WF-05UAT-AGREG-006, UAT-AGLEAD-001Partially CoveredInitial-credit recurrence is open and mock code formats conflict with the PRD.Wrong attribution or duplicate/free credit allocation.Confirm one-time versus renewal allocation and enforce the approved raw 6-digit code format.
AgencyAG-R012WhatsApp outreach generates a unique agency-code link, maps the customer, and prefills overlapping conversational data.AG-PRD Screen 7 new_wa_num/new_wa_link/new_wa_populate EXT-API item 2Agency Staff, CustomerAG-WF-04UAT-AGINTK-001, UAT-AGINTK-002Partially CoveredCredentials, templates, and final link format are client inputs.Referral attribution or customer data continuity fails.Approve link format and WhatsApp templates.
AgencyAG-R017Lead access follows permission; configured notification channel and SLA govern new or unworked leads.AG-PRD Screen 16 lead_process and client-input note AG-PRD Section 9.3Agency Staff, Super AdminAG-WF-05UAT-AGLEAD-003Needs clarificationNotification channel and return-to-pool SLA are unset.Valuable leads remain unactioned or are reassigned unexpectedly.Approve channel, recipients, SLA clock, warning, and return behavior.
AgencyAG-R019Super Admin edit toggle controls whether Agency may overwrite customer-entered fields while review/continue remain available.AG-PRD Screen 6 AD-07 edit-toggle noteSuper Admin, Agency StaffAG-WF-06UAT-AGAPP-003, UAT-AGAPP-004Partially CoveredWhether filling a previously blank field counts as Continue when edit is disabled is ambiguous.Agency overwrites customer-owned data or cannot provide intended assistance.Define edit-disabled behavior per field ownership and blank field.
AgencyAG-R020Agency may add/edit up to five co-applicants; only the primary applicant is individually scored.AG-PRD Screen 6 det_coapp AG-PRD Section 4.2Agency StaffAG-WF-06UAT-AGAPP-005, UAT-AGAPP-006Partially CoveredPrimary-only scoring is confirmed, but Section 9 still requests final per-credit treatment confirmation.Group applicants are lost or overcharged.Close the co-applicant credit-treatment open item.
AgencyAG-R021Documents are stored on the shared record with OCR state; valid OCR pre-fills fields and failed OCR remains recoverable.AG-PRD Screen 6 det_docs and Screen 7 new_indash EXT-API items 3 and 8Agency Staff, CustomerAG-WF-04, AG-WF-06, AG-WF-07UAT-AGINTK-004, UAT-AGAPP-007, UAT-AGAPP-008, UAT-AGAPP-013, UAT-AGSTAT-002Partially CoveredPermanent OCR failure/manual fallback is not defined.Unverified document data drives scoring.Define manual review/fallback and OCR retry limits.
AgencyAG-R024Risk engine shows fund-parking and other flags; valid source-of-funds proof can clear the relevant flag.AG-PRD Screen 6 det_flags AG-PRD Appendix B AD-30/31/32 EXT-API item 3Agency Staff, CustomerAG-WF-06UAT-AGAPP-013Partially CoveredAutomatic versus explicit rescore after proof is not stated.Financial risk remains falsely flagged or is cleared without evidence.Define flag-clear approval and rescore trigger.
AgencyAG-R026Agency-set application statuses drive Customer timeline and status communications across WhatsApp, app, and web.AG-PRD Screen 6 status table/det_status and notification ruleAgency Staff, Customer, Super AdminAG-WF-07UAT-AGSTAT-001, UAT-AGSTAT-002, UAT-AGSTAT-003, UAT-AGSTAT-004, UAT-AGSTAT-005Partially CoveredComplete allowed-transition matrix is absent.Impossible or inconsistent case states.Approve allowed prior/new state matrix and reversal rules.
AgencyAG-R029Configured low-credit threshold warns on dashboard/wallet and zero balance blocks scoring until recharge.AG-PRD Section 5.3 and Screens 4/8Agency StaffAG-WF-08UAT-AGWORK-002, UAT-AGAPP-010, UAT-AGCRED-002Partially CoveredThreshold value is unset.Processing stops unexpectedly or allows unpaid work.Approve threshold and warning recipients.
AgencyAG-R030Authorized user purchases Super-Admin-configured packs through the payment gateway; success updates balance immediately and creates an invoice.AG-PRD Screen 9 rec_pack/rec_pay/rec_invoice EXT-API item 1Agency Admin, Billing-Permitted Sub-UserAG-WF-08UAT-AGCRED-002, UAT-AGCRED-003, UAT-AGCRED-004Partially CoveredPack, tax, credential, and payment-method configuration are client inputs.Paid credits or invoices are wrong.Approve packs, taxes, currencies, and Razorpay configuration.
AgencyAG-R031Razorpay callbacks and refunds reconcile idempotently across payment, wallet, invoice, and Admin monitoring.EXT-API item 1 Razorpay webhooks/refunds AG-PRD Screen 9 and Appendix B AD-50/AD-51Finance Operator, Agency AdminAG-WF-08UAT-AGCRED-003, UAT-AGCRED-004, UAT-AGCRED-005, UAT-AGCRED-006Needs clarificationRefund eligibility, consumed-credit treatment, credit notes, and partial refund rules are unspecified.Duplicate or incorrect financial value.Approve end-to-end refund and reconciliation policy.
AgencyAG-R033Standard/Growth/Professional plans apply documented tokens and carry-forward; Pay-Per-Use is Phase 2.AG-PRD Section 5.4 plan table and Screen 10 model tableAgency Admin, Super AdminAG-WF-08UAT-AGBILL-002Needs clarificationInitial allocation recurrence and self-switch authority are open; mock says credits never expire, conflicting with Standard no carry-forward.Renewal destroys or wrongly carries financial value.Approve renewal timing, expiry, carry-forward, and switch authority.
AgencyAG-R034Credit packs, scoring/processing fees, and billing configuration originate in Super Admin and may vary by country/visa type.AG-PRD Sections 5.2/9.2 and Appendix BSuper Admin, Agency StaffAG-WF-08, AG-WF-14UAT-AGCRED-003, UAT-AGBILL-002, UAT-AGCFG-001Partially CoveredActual fees/packs are unset.Agency is charged under stale or wrong pricing.Approve configuration values and effective-date/version rules.
AgencyAG-R035Agency Admin has full access; sub-users have default operational access and only explicitly granted sensitive capabilities.AG-PRD Sections 2.1-2.2 powers matrixAgency Admin, Agency Sub-UserAG-WF-02, AG-WF-03, AG-WF-05, AG-WF-09, AG-WF-10UAT-AGAUTH-002, UAT-AGWORK-002, UAT-AGWORK-004, UAT-AGLEAD-003, UAT-AGAPP-004, UAT-AGSTAT-005, UAT-AGBILL-001, UAT-AGUSER-001, UAT-AGUSER-003, UAT-AGUSER-004, UAT-AGUSER-005, UAT-AGPROMO-003Partially CoveredFinal granular/default permission template remains a client input.Privilege escalation or blocked staff work.Approve final capability list and default template.
AgencyAG-R038Authorized branding user manages logo, display name, and customer support contact; invalid assets do not publish.AG-PRD Screen 12 br_logo/br_name/br_support EXT-API item 8Agency Admin, Branding-Permitted Sub-UserAG-WF-06, AG-WF-11UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGBRAND-002Partially CoveredPRD says PNG/JPG and unspecified size; mock adds SVG and 2 MB.Broken or unsafe customer-facing branding.Approve file types, dimensions, and size limit.
AgencyAG-R040Agency profile supports validated Admin updates, requested tax-document re-upload, read-only code, logout, and consented/audited passport-data email export.AG-PRD Screen 14 prof_details through prof_exportAgency Admin, Agency Sub-UserAG-WF-11UAT-AGPROF-001, UAT-AGPROF-002, UAT-AGPROF-003Needs clarificationExport recipient, format, consent, retention, and audit policy are unset.Passport data is exported unlawfully or cannot be audited.Approve the complete passport-export policy.
AgencyAG-R041Agency can raise validated case-linked support tickets, exchange replies/attachments, and progress Open, In Progress, Awaiting Agency Response, Resolved, and Closed states.AG-PRD Screen 15 field and element tablesAgency Staff, Super Admin SupportAG-WF-13UAT-AGSUP-001, UAT-AGSUP-002, UAT-AGSUP-003Needs clarificationFinal categories, priority SLAs, support contacts, and help content are client inputs.Support expectations are misleading or tickets cannot be resolved.Approve categories, SLA matrix, WhatsApp/email contacts, and help URL/content.
AgencyAG-R042Super Admin allocates promo; Agency receives and emails it; Customer redeems for a free transaction; usage is tracked.AG-PRD Section 6.1 flow and Appendix B AD-62Super Admin, Agency User, CustomerAG-WF-10UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROMO-004Partially CoveredAllocation defaults and email template are unset; Stitch shows a conflicting recharge-bonus promo.Wrong customer benefit or attribution.Confirm promo semantic is customer fee waiver and approve allocation/template defaults.
AgencyAG-R044Super-Admin changes to agency edit rights, status, pricing, scoring/risk, forms/ranges, document checklists, countries/visas, reports, and help content propagate consistently.AG-PRD Appendix B tables B.1/B.3Super Admin, Agency Staff, CustomerAG-WF-06, AG-WF-07, AG-WF-14UAT-AGAPP-003, UAT-AGAPP-013, UAT-AGSTAT-004, UAT-AGCFG-001Partially CoveredEffective-time, caching, and in-progress-record versioning are unspecified.Products apply different rules to the same case.Define configuration version/effective-time and cache invalidation rules.
AgencyAG-R045External provider failures are visible, recoverable, secure, and do not create duplicate or false business outcomes.EXT-API integration list AG-PRD integration error/fallback fieldsAgency Staff, Customer, OperationsAG-WF-04, AG-WF-06, AG-WF-07, AG-WF-13UAT-AGINTK-002, UAT-AGAPP-012, UAT-AGAPP-015, UAT-AGSTAT-005, UAT-AGPROF-003, UAT-AGSUP-003Needs clarificationProvider credentials/templates, retry limits, idempotency, and operational recovery are client/config inputs.Partial integration failure corrupts cases or finances.Approve provider configuration, retry, idempotency, timeout, and support runbooks.
AgencyAG-R047A raw 6-digit Agency Code is always visible/read-only and agency display name/report branding always retains Powered by VisaReady; B2C reports remain VisaReady-only.AG-PRD Section 7 and Screens 12/14Agency Staff, CustomerAG-WF-06, AG-WF-11UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGPROF-001Needs clarificationStitch shows inconsistent prefixed/variable-length codes and product names.Customer attribution and platform trust are ambiguous.Confirm canonical code rendering and product/agency naming tokens.
AgencyAG-R048Cloud storage securely stores registration evidence, passports, reports, logos, decisions, exports, and ticket attachments with correct ownership and recoverable failure.EXT-API item 8 AG-PRD Screens 1, 6, 12, 14, 15Agency Staff, CustomerAG-WF-04, AG-WF-06, AG-WF-11, AG-WF-13UAT-AGREG-002, UAT-AGREG-005, UAT-AGINTK-004, UAT-AGAPP-007, UAT-AGAPP-008, UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGBRAND-002, UAT-AGPROF-001, UAT-AGSUP-001, UAT-AGSUP-002Partially CoveredStorage provider, encryption, retention, malware scanning, and signed-link expiry are not specified.Sensitive documents leak, disappear, or are misattributed.Approve storage security, retention, scanning, and access-link policy.
AgencyAG-R049SMS/OTP, transactional email, WhatsApp, push, and in-app services deliver required login, invite, promo, invoice, report, status, and operational communications to the correct audience.EXT-API items 2, 4, 5, 7 AG-PRD Screens 3, 6, 9, 11, 13Agency Staff, CustomerAG-WF-01, AG-WF-02, AG-WF-04, AG-WF-07, AG-WF-08, AG-WF-09, AG-WF-10, AG-WF-12UAT-AGREG-003, UAT-AGAUTH-001, UAT-AGAUTH-002, UAT-AGAUTH-003, UAT-AGINTK-001, UAT-AGAPP-014, UAT-AGAPP-015, UAT-AGSTAT-001, UAT-AGSTAT-002, UAT-AGSTAT-003, UAT-AGSTAT-005, UAT-AGCRED-003, UAT-AGUSER-001, UAT-AGUSER-006, UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROF-002, UAT-AGNOTIF-001Partially CoveredTemplates, recipient rules, delivery SLA, and provider configuration are not finalized.Users miss access, decision, payment, or action communications.Approve templates, audience rules, retry, and delivery SLAs.
AgencyAG-R050Pay-Per-Use, public agency directory, lead transfer, and dedicated APM/System Health are not Agency MVP behavior.AG-PRD Screens 10/12 and Section 8 Phase-2 notes EXT-API analytics/monitoring noteAgency Staff, Super AdminAG-WF-08UAT-AGBILL-002Out of ScopeMocks may display Phase-2 calls to action but must not activate unsupported behavior.Unapproved features create unsupported financial or ownership states.Keep visible Phase-2 actions explicitly non-operational or remove them from MVP.
AgencyAG-UI-001UI mocks use VisaReady and approved agency branding consistently.AG-STITCH visible HTML across screensAll Agency UsersAG-WF-01, AG-WF-03, AG-WF-11UAT-AGBRAND-001Needs clarificationMocks alternate VisaReady, VisaPro, VisaGlobal, VisaPro Global, and B2B Pulse.Users cannot identify the platform or trusted agency.Approve canonical product, portal, and sample-agency naming.
AgencyAG-UI-002UI renders the PRD-mandated 6-digit agency code consistently.AG-PRD Section 7 AG-STITCH screens showing VR-882931, VP-8821, VPA-88291, VP-7724X, and 882931Agency Staff, CustomerAG-WF-01, AG-WF-05, AG-WF-11UAT-AGREG-006, UAT-AGBRAND-001, UAT-AGPROF-001Needs clarificationMost mock codes are prefixed or variable-length and conflict with the raw 6-digit PRD rule.Referral links and manual code entry fail.Approve one canonical stored and displayed format.
AgencyAG-UI-003Mock credit quantities, currency display, and deductions align to one-credit-per-primary-score requirements.AG-STITCH Dashboard, Clients, Wallet, Approved, and Recharge screens AG-PRD Section 5.1Agency StaffAG-WF-03, AG-WF-06, AG-WF-08UAT-AGAPP-009, UAT-AGCRED-001Needs clarificationMocks mix monetary balances, large per-client credit counts, OCR/verification deductions, and an approved $500 allocation.Agency cannot understand or reconcile charges.Replace mock values with the approved token unit and deduction events.
AgencyAG-UI-004Promo UI represents Super-Admin-allocated customer fee-waiver codes, not agency recharge bonuses.AG-PRD Section 6 AG-STITCH Notifications WELCOME50 recharge bonus and Recharge promo fieldAgency User, CustomerAG-WF-10UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROMO-003, UAT-AGPROMO-004, UAT-AGPROMO-005Needs clarificationMock promo semantics conflict with approved Agency PRD flow.Wrong financial benefit is issued or redeemed.Approve whether recharge promos are separate, out of scope, or should be removed.
AgencyAG-UI-005Branding upload types and size limits are identical in requirements and UI.AG-PRD Screen 12 br_logo AG-STITCH Branding screenBranding-Permitted UserAG-WF-11UAT-AGBRAND-002Needs clarificationPRD lists PNG/JPG with unspecified size; mock lists PNG/SVG/JPG at 2 MB.A UI-accepted asset fails server-side or unsafe SVG is stored.Approve exact types, sanitization, dimensions, and size.
AgencyAG-UI-006Support mock displays only client-approved contacts and SLA claims.AG-PRD Screen 15 client-input note AG-STITCH Support screen under-4-hours, 24/7, and support email copyAgency StaffAG-WF-13UAT-AGSUP-003Needs clarificationMock hard-codes claims while PRD leaves them open.Contractual support expectations are misstated.Approve or remove every SLA/contact claim.
AgencyAG-UI-007Auto-recharge shown in Wallet has an approved requirement, permissions, threshold, payment consent, and failure behavior.AG-STITCH Wallet screen Auto-Recharge Active No matching AG-PRD requirementAgency AdminAG-WF-08Needs clarificationAuto-recharge is mock-only and unsupported by the PRD.Unexpected automatic financial charges.Remove from MVP or add an approved auto-recharge requirement and controls.
AgencyAG-UI-008Rejected registration correction or appeal behavior is explicitly approved.AG-STITCH Rejected screen Appeal Decision/Modify Application AG-PRD Screen 2 only specifies Rejected status/noteRejected Agency Admin, Super AdminAG-WF-01UAT-AGREG-007Needs clarificationMock-only appeal/resubmission route.Rejected agencies encounter a dead or unauthorized action.Approve appeal, edit/resubmit, or terminal rejection behavior.
AgencyAG-UI-009Billing mock expiry language agrees with plan carry-forward rules.AG-STITCH Billing screen Credits never expire AG-PRD Section 5.4 Standard no carry-forwardAgency AdminAG-WF-08UAT-AGBILL-002Needs clarificationNever-expire copy conflicts with a non-carry-forward plan.Agency loses value contrary to displayed promise.Define expiry/carry-forward per plan and align the copy.
AgencyAG-UI-010Manual New Lead action in the mock is either defined or removed.AG-STITCH Leads screen New Lead button AG-PRD Screen 16 supports code-mapped and Admin-allocated leadsAgency StaffAG-WF-05Needs clarificationMock-only manual lead creation duplicates or overlaps Add New Client.Duplicate customers and ambiguous lead ownership.Remove the action or define how it differs from Add New Client.
AgencyAG-UI-011Dashboard regional trends, Premium Agency Support, and Contact Account Manager content is approved, sourced, and permission-scoped or removed.AG-STITCH Dashboard screen regional trends and Premium Agency Support No matching AG-PRD Screen 4 requirementAgency StaffAG-WF-03Needs clarificationMock-only analytics and premium-support content have no data source, entitlement, or action rule.Agency sees unsupported analytics or support promises.Define source, refresh, entitlement, and account-manager action or remove these components from MVP.
AgencyAG-UI-012The mock claim that agencies can send unlimited invitation links is approved with abuse, rate-limit, and duplicate-recipient behavior.AG-STITCH Add New Client screen Unlimited invitation links copy AG-PRD only states no credit is deducted for sending a linkAgency StaffAG-WF-04UAT-AGINTK-001, UAT-AGINTK-002Needs clarificationNo approved unlimited-send or abuse-prevention rule exists.Spam, provider cost, account blocking, or duplicate customers.Approve send limits, resend/idempotency, consent, and abuse controls or remove the unlimited claim.
AgencyAG-UI-013Mock sub-user roles such as Senior Agent, Junior Agent, Support Staff, and Finance Manager map explicitly to the granular PRD permission model.AG-STITCH User Management role options AG-PRD Sections 2.1-2.2 define Agency Admin/Sub-User plus granular permissionsAgency Admin, Agency Sub-UserAG-WF-09UAT-AGUSER-001, UAT-AGUSER-003Needs clarificationRole presets, their permissions, and whether they are labels only are undefined.Displayed role implies access that differs from enforced permissions.Publish an authoritative role-preset-to-permission matrix or remove presets.
AgencyAG-GAP-001The 6-digit agency-code namespace has sufficient uniqueness capacity and a defined exhaustion/collision policy.AG-PRD Section 9.5 Open Question 7Super Admin, Agency Admin, CustomerAG-WF-01, AG-WF-05Needs clarificationProjected agency volume, reserved values, recycling, and exhaustion behavior are not defined.Code collision maps customers to the wrong agency or blocks onboarding.Approve capacity forecast, uniqueness scope, generation algorithm, collision retry, and code-retirement policy.
AgencyEXT-OOS-001Google OAuth customer login is not an Agency Dashboard acceptance behavior.EXT-API item 6CustomerOut of ScopeCovered by Customer Application suite.
AgencyEXT-OOS-002Embassy/official visa portal URLs are not evidenced as an Agency screen flow.EXT-API item 9CustomerOut of ScopeCovered by the application that exposes the embassy link.
SuperadminAD-06Agency directory supports defined statuses, search/filter, bulk actions and export.VisaReady Final Doc Admin.docx §5 AD-06 Stitch AD06 agency-directory variantsAdmin, Support, AnalystWF-SA-04UAT-SA-ANL-008, UAT-SA-AGY-001, UAT-SA-AGY-014Partially CoveredThe exact eligibility and atomicity matrix for each bulk status transition is not stated.Unsafe bulk transitions could suspend or activate the wrong agencies.Approve allowed source-to-target transitions and partial-failure behavior.
SuperadminAD-07Agency KYC validates GST/PAN, approval activates with initial credits, rejection records reason, and customer-data editing defaults off.VisaReady Final Doc Admin.docx §5 AD-07Admin, Agency AdminWF-SA-04UAT-SA-AGY-001, UAT-SA-AGY-002, UAT-SA-AGY-011Partially CoveredThe source does not resolve whether GST/PAN must use live government verification or only format/checksum validation.Weak identity validation could activate fraudulent agencies.Confirm verification provider, failure policy and approved initial-credit amount.
SuperadminAD-08Phase 1 supports lead visibility and manual follow-up; automatic assignment, transfer and SLA return are Phase 2.VisaReady Final Doc Admin.docx §5 AD-08Admin, Agency StaffWF-SA-04UAT-SA-AGY-012, UAT-SA-AGY-013Partially CoveredPhase-2 assignment, transfer and SLA rules are explicitly outside the immediate Phase-1 scope.Claiming Phase-2 behavior as delivered would create incorrect lead ownership expectations.Create a separate Phase-2 acceptance baseline when assignment roles and SLAs are approved.
SuperadminAD-09Plan purchase auto-assigns entitlement while manual override is exceptional, reasoned and time-bound.VisaReady Final Doc Admin.docx §5 AD-09Admin, Agency Admin, CustomerWF-SA-04, WF-SA-10UAT-SA-AGY-007, UAT-SA-PLAN-003, UAT-SA-PLAN-006, UAT-SA-PLAN-007Partially CoveredProration and carry-forward during override are identified as client inputs.Ambiguous override economics can overgrant entitlement or misstate billing.Approve proration, usage, renewal and carry-forward rules for every override transition.
SuperadminAD-13B2C user directory supports safe search, filters, export and bulk operations.VisaReady Final Doc Admin.docx §5 AD-13Admin, Support, AnalystWF-SA-05UAT-SA-ANL-008, UAT-SA-USR-001, UAT-SA-USR-009Partially CoveredExact bulk-deactivation eligibility and atomicity are not defined.Incorrect bulk processing could lock out unintended customers.Approve the bulk selection, eligibility and partial-failure model.
SuperadminAD-15Verified deletion requests are queued, processed through deletion/anonymization and communicated to the customer.VisaReady Final Doc Admin.docx §5 AD-15Admin, CustomerWF-SA-05UAT-SA-USR-004, UAT-SA-USR-006Partially CoveredRetention categories, deletion SLA and dependency-resolution policy are not final.Incomplete deletion can breach privacy law; over-deletion can destroy required evidence.Approve retention schedule, verification evidence, SLA and exception owner.
SuperadminAD-16DPDPA erasure is an irreversible, cross-module controlled job with customer notification and audit.VisaReady Final Doc Admin.docx §5 AD-16Admin, CustomerWF-SA-05UAT-SA-USR-005, UAT-SA-USR-006Partially CoveredRetained legal records, completion SLA and retry ownership are unspecified.An incomplete or repeated erasure job creates severe compliance and integrity exposure.Obtain legal approval for scope/retention and operational approval for job recovery.
SuperadminAD-18Application detail connects documents/OCR, scoring reasons, timeline, audit, report and fraud context.VisaReady Final Doc Admin.docx §5 AD-18Admin, Support, AnalystWF-SA-06UAT-SA-CASE-002, UAT-SA-CASE-003, UAT-SA-CASE-008, UAT-SA-CASE-009, UAT-SA-CASE-010Partially CoveredScore-regeneration price and evidence-change eligibility are not finalized.A fragmented or unreproducible case view undermines UAT decision confidence.Approve regeneration commercial rules and final detail-section access matrix.
SuperadminAD-19Reasoned Admin status override propagates across channels, updates timeline/notifications and takes precedence over agency updates.VisaReady Final Doc Admin.docx §5 AD-19Admin, Support, Analyst, Agency Staff, CustomerWF-SA-06UAT-SA-RBAC-006, UAT-SA-CASE-003, UAT-SA-CASE-004, UAT-SA-CASE-005, UAT-SA-CASE-006, UAT-SA-CASE-007, UAT-SA-CASE-008Partially CoveredThe complete allowed status-transition matrix is not stated.Contradictory or invalid status changes mislead customers and operations.Approve allowed transitions, disclosure rules and conflict-handling mechanics.
SuperadminAD-20Country catalogue uses unique ISO identity, flag, processing/appointment data, active state and embassy URL; inactive countries hide from new journeys.VisaReady Final Doc Admin.docx §5 AD-20Admin, Customer, Agency StaffWF-SA-07UAT-SA-CFG-001, UAT-SA-CFG-002, UAT-SA-CFG-003, UAT-SA-CFG-004Partially CoveredFinal country list, URL ownership and URL-health policy are client inputs.Incorrect catalogue data can launch unsupported or misleading journeys.Approve launch catalogue and content/URL owner.
SuperadminAD-21Admin can add a valid unique country with all required metadata.VisaReady Final Doc Admin.docx §5 AD-21AdminWF-SA-07UAT-SA-CFG-001, UAT-SA-CFG-002Partially CoveredMandatory-field detail and final approved countries are not exhaustively enumerated.Incomplete country creation can break downstream forms and content.Confirm mandatory fields and approval workflow.
SuperadminAD-23Adding/editing a supported visa type triggers the corresponding checklist rebuild.VisaReady Final Doc Admin.docx §5 AD-23AdminWF-SA-07UAT-SA-CFG-005, UAT-SA-CFG-006Partially CoveredIn-flight application migration behavior is not specified.Checklist/version mismatch can request the wrong documents.Approve checklist rebuild scope for drafts and in-flight cases.
SuperadminAD-24Country-specific scoring rules are unique, effective-dated and rebuild the scoring engine.VisaReady Final Doc Admin.docx §5 AD-24Admin, AnalystWF-SA-07, WF-SA-08UAT-SA-CFG-010, UAT-SA-CFG-011, UAT-SA-CFG-012Partially CoveredFinal country parameters and modifiers are client inputs.Ambiguous country policy can create inconsistent applicant scoring.Approve parameter catalogue, precedence and country values.
SuperadminAD-25Admin can add/edit one unambiguous country/visa scoring rule per parameter.VisaReady Final Doc Admin.docx §5 AD-25AdminWF-SA-07UAT-SA-CFG-010, UAT-SA-CFG-011Partially CoveredSupported operators and effects are not exhaustively listed.Invalid rule semantics can make scores irreproducible.Approve operator/value types and overlap/precedence rules.
SuperadminAD-26Dynamic forms support fields, ranges, dropdowns, validation, conditional visibility, preview, version/effective date and cross-channel propagation.VisaReady Final Doc Admin.docx §5 AD-26 Stitch AD26 original and regenerated variantsAdmin, Customer, Agency StaffWF-SA-07UAT-SA-CFG-008, UAT-SA-CFG-009Partially CoveredExact field catalogue, numeric ranges and in-flight migration policy are client inputs.Broken form configuration can block intake or feed invalid scoring data.Approve the field/range catalogue and version migration rules.
SuperadminAD-27Seven factor weights total exactly 100 using approved defaults; Others may be zero only with rebalance.VisaReady Final Doc Admin.docx §5 AD-27Admin, AnalystWF-SA-08UAT-SA-CFG-012, UAT-SA-SCR-001, UAT-SA-SCR-002, UAT-SA-SCR-003, UAT-SA-SCR-004Partially CoveredAllowed redistribution and Others subrules are not finalized.Invalid normalization can distort every applicant result.Approve redistribution constraints and any Others factor subrules.
SuperadminAD-28Lite uses five factors and Low/Medium/High without risks; Final uses seven factors, risk and defined score bands.VisaReady Final Doc Admin.docx §5 AD-28Admin, Analyst, CustomerWF-SA-06, WF-SA-08UAT-SA-CASE-002, UAT-SA-CASE-010, UAT-SA-SCR-004, UAT-SA-SCR-005, UAT-SA-SCR-006, UAT-SA-SCR-013Partially CoveredExact Lite factor split/thresholds and display of nested below-40 guidance are unresolved.Incorrect stage logic or band boundaries can mislead applicants.Approve Lite configuration and precise customer labels at every boundary.
SuperadminAD-30Risk rules are versioned, editable/active and apply to Final scoring only.VisaReady Final Doc Admin.docx §5 AD-30Admin, AnalystWF-SA-08UAT-SA-SCR-005, UAT-SA-SCR-009, UAT-SA-SCR-010Partially CoveredFinal trigger catalogue and penalty values are client inputs.Unapproved or unexplained risk penalties can unfairly alter outcomes.Approve triggers, severities, penalties and effective-date rules.
SuperadminAD-31Risk triggers include refusal, unexplained credit, passport/travel expiry proximity and missing documents, with Final-only propagation.VisaReady Final Doc Admin.docx §5 AD-31Admin, CustomerWF-SA-08UAT-SA-SCR-005, UAT-SA-SCR-009Partially CoveredSome exact trigger thresholds and penalties are not final.Incorrect triggers can create false high-risk decisions.Approve all threshold, combination and disclosure rules.
SuperadminAD-32Fund-parking detection uses OCR evidence, large recent-credit threshold, penalty and valid-proof waiver.VisaReady Final Doc Admin.docx §5 AD-32Admin, CustomerWF-SA-08UAT-SA-SCR-011, UAT-SA-SCR-012, UAT-SA-SCR-013Partially CoveredLookback, aggregation, exact penalty and accepted proof types are not final.False fund-parking classification can materially and unfairly lower a score.Approve threshold calculation, proof catalogue, reviewer and waiver audit policy.
SuperadminAD-33Country requirements remain hidden as drafts and become immediately visible only after publication.VisaReady Final Doc Admin.docx §5 AD-33Admin, Customer, Agency StaffWF-SA-09UAT-SA-CMS-001, UAT-SA-CMS-010Partially CoveredFinal country content and editorial approval owner are client inputs.Draft or stale requirements can cause incomplete applications.Approve content inventory and publication governance.
SuperadminAD-34Document checklists combine ordered mandatory base documents with the applicable user-type overlay and rebuild consuming journeys.VisaReady Final Doc Admin.docx §5 AD-34Admin, Customer, Agency StaffWF-SA-07, WF-SA-09UAT-SA-CFG-005, UAT-SA-CMS-002Partially CoveredFinal base and seven user-type overlay lists are not supplied.Wrong checklists cause avoidable rejection or unnecessary PII collection.Approve checklist content for Salaried, Business, Student, Retired, Unemployed, Homemaker and Freelancer.
SuperadminAD-39Country tiers, experience/salary bands, boosters and funds modifiers influence only their intended scoring scope.VisaReady Final Doc Admin.docx §5 AD-39Admin, AnalystWF-SA-07, WF-SA-08UAT-SA-CFG-012Partially CoveredExact tiers, bands, booster values and approximately €100 funds rule are not final.Unapproved modifiers can materially distort country-specific outcomes.Approve complete parameter/value matrix and precedence.
SuperadminAD-41Country-specific cover letters and versioned itineraries render approved merge data and publish safely.VisaReady Final Doc Admin.docx §5 AD-41Admin, CustomerWF-SA-09UAT-SA-CMS-006Partially CoveredFinal UK, Canada, Australia and Schengen copy, merge fields and publication rules are inputs.Incorrect document templates can harm an applicant submission.Approve final copy, ownership and supported merge-field catalogue.
SuperadminAD-42B2B/B2C plan catalogue controls price, period, quota, carry-forward, activation and deactivation behavior.VisaReady Final Doc Admin.docx §5 AD-42Admin, Agency Admin, CustomerWF-SA-04, WF-SA-10UAT-SA-AGY-007, UAT-SA-PLAN-001, UAT-SA-PLAN-002, UAT-SA-PLAN-003, UAT-SA-PLAN-004Partially CoveredProvided default prices/quotas coexist with a statement that final plan values and carry-forward are client inputs.Wrong plan economics cause entitlement leakage and billing disputes.Approve final catalogue, taxes, quotas, renewal and carry-forward policy.
SuperadminAD-45Manual plan override requires authorization, reason and expiry and is fully audited.VisaReady Final Doc Admin.docx §5 AD-45Admin, SubscriberWF-SA-05, WF-SA-10UAT-SA-USR-007, UAT-SA-PLAN-006, UAT-SA-PLAN-007Partially CoveredProration, usage and carry-forward across override transitions are not specified.Uncontrolled overrides create unapproved commercial concessions.Approve entitlement fallback and financial treatment for grant, expiry and revocation.
SuperadminAD-46Notification template inventory supports status, channel governance and safe production use.VisaReady Final Doc Admin.docx §5 AD-46AdminWF-SA-12UAT-SA-NOTIF-001, UAT-SA-NOTIF-005, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007Partially CoveredFinal template inventory and event/channel ownership are not supplied.Uncontrolled templates can send incorrect or unapproved communications.Approve template inventory, owners and review/publish workflow.
SuperadminAD-47Email editor requires subject, validates merge fields, supports preview/test and versions publication.VisaReady Final Doc Admin.docx §5 AD-47Admin, RecipientWF-SA-12UAT-SA-NOTIF-001, UAT-SA-NOTIF-005, UAT-SA-NOTIF-007Partially CoveredApproved sender identities, subjects and merge-field catalogue are client inputs.Malformed email can expose bad data or fail a critical notice.Approve sender/domain, subject rules and merge-field catalogue.
SuperadminAD-48SMS, WhatsApp and push templates support preview/test, active state and channel-safe delivery.VisaReady Final Doc Admin.docx §5 AD-48Admin, RecipientWF-SA-12UAT-SA-NOTIF-002, UAT-SA-NOTIF-003, UAT-SA-NOTIF-004, UAT-SA-NOTIF-005, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007Partially CoveredProvider-specific template approval, consent and fallback policies are not final.Invalid multi-channel messaging can breach consent or miss critical updates.Approve consent source, provider template IDs and fallback behavior per channel.
SuperadminAD-49Business events map deterministically to active notification channels and templates.VisaReady Final Doc Admin.docx §5 AD-49Admin, RecipientWF-SA-12UAT-SA-NOTIF-002, UAT-SA-NOTIF-003, UAT-SA-NOTIF-004, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007Partially CoveredExact business-event-to-channel matrix is explicitly unresolved.Missing or duplicate trigger mappings can omit or duplicate customer communication.Approve event catalogue, recipients, channels, idempotency and retry owner.
SuperadminAD-50Transactions and agency recharges expose accurate lifecycle, gateway reference, invoice, entitlement and financial state.VisaReady Final Doc Admin.docx §5 AD-50Admin, Support, Analyst, BuyerWF-SA-03, WF-SA-06, WF-SA-10, WF-SA-13UAT-SA-RBAC-007, UAT-SA-CASE-010, UAT-SA-PLAN-004, UAT-SA-PAY-001, UAT-SA-PAY-002, UAT-SA-PAY-003, UAT-SA-PAY-004, UAT-SA-PAY-010Partially CoveredFinal Razorpay environment/configuration, taxes, invoice and regeneration-price details remain inputs.Transaction inconsistency creates financial loss or entitlement disputes.Approve final payment purposes, invoice/tax treatment and operational status model.
SuperadminAD-52Authorized refund decisions require eligibility/reason, execute through the gateway and update customer and financial state.VisaReady Final Doc Admin.docx §5 AD-52Support, Admin, CustomerWF-SA-02, WF-SA-13UAT-SA-RBAC-006, UAT-SA-PAY-005, UAT-SA-PAY-006, UAT-SA-PAY-007, UAT-SA-PAY-008Partially CoveredPartial-refund, fee, entitlement reversal and eligibility policies are not fully specified.Incorrect refund handling can over-refund or retain customer funds improperly.Approve eligibility, partial amount, fee, entitlement and notification rules.
SuperadminAD-53Razorpay reconciliation classifies matched, mismatch and pending records, supports export and handles delayed/duplicate events.VisaReady Final Doc Admin.docx §5 AD-53Admin, AnalystWF-SA-03, WF-SA-13UAT-SA-RBAC-007, UAT-SA-PAY-004, UAT-SA-PAY-009, UAT-SA-PAY-010Partially CoveredSettlement cadence, matching tolerance and mismatch owner are not defined.Unresolved discrepancies hide missing or duplicated money movement.Approve cadence, tolerance, resolution workflow and closing evidence.
SuperadminAD-60System-health/APM monitoring is referenced but explicitly outside the VisaReady Lite scope.VisaReady Final Doc Admin.docx §5 AD-60 List of external APIs or third-party integrations required.docx states system health/APM out of scope Stitch AD60 System Health screenSuper Admin, OperationsOut of ScopeThe design exists, but the integration requirements document explicitly excludes APM/system health from Lite.Operational monitoring remains a future-release dependency and must not be misrepresented as accepted.Create a future-release baseline when monitoring provider, SLIs, alerting and ownership are approved.
SuperadminAD-62Super Admin generates/allocates promo codes, agency distributes them and eligible redemption fully waives one transaction under use/cap/expiry rules.VisaReady Final Doc Admin.docx §5 AD-62Super Admin, Agency Admin, CustomerWF-SA-11UAT-SA-PROMO-001, UAT-SA-PROMO-002, UAT-SA-PROMO-003, UAT-SA-PROMO-004, UAT-SA-PROMO-005Partially CoveredAllocation commit-on-notification-failure, customer binding, timezone and final copy are unresolved.Promo ambiguity can exceed approved financial liability.Approve allocation model, code scope, expiry timezone, caps and email-recovery owner.
SuperadminAD-63Country library content supports ordered drafts and controlled publication across channels.VisaReady Final Doc Admin.docx §5 AD-63Admin, Customer, Agency StaffWF-SA-09UAT-SA-CMS-007Partially CoveredInitial country/article inventory and editorial owner are not supplied.Uncontrolled guidance can be stale or contradictory.Approve launch inventory, ordering and review cadence.
SuperadminAD-64Terms, Privacy and Disclaimer are versioned/effective/published and can force reconsent with durable consent logs.VisaReady Final Doc Admin.docx §5 AD-64Admin, CustomerWF-SA-09UAT-SA-CMS-008Partially CoveredFinal legal copy and the permitted experience after decline require legal approval.Unprovable or stale consent creates material privacy/compliance exposure.Obtain legal signoff for copy, effective timezone, decline handling and consent retention.
SuperadminAD-65Reports apply every-page watermark, ordered sections, agency co-branding, VisaReady identity, report ID/QR and passport footer.VisaReady Final Doc Admin.docx §5 AD-65Admin, Customer, Agency StaffWF-SA-06, WF-SA-09UAT-SA-CASE-002, UAT-SA-CMS-009, UAT-SA-CMS-011Partially CoveredFinal watermark opacity/placement, section order, asset constraints and QR destination are inputs.Incorrect branding or identity controls can produce unauthentic or misleading reports.Approve layout, section order, QR security/destination and logo file policy.
SuperadminAD-70Super-Admin-only maintenance mode blocks non-admin channels, preserves Admin access, displays custom message and auto-disables at scheduled end.VisaReady Final Doc Admin.docx §5 AD-70Super Admin, Admin, Customer, Agency StaffWF-SA-02, WF-SA-15UAT-SA-RBAC-005, UAT-SA-OPS-001, UAT-SA-OPS-002, UAT-SA-OPS-003, UAT-SA-OPS-004Partially CoveredTimezone and treatment of sessions active at enable/disable boundaries are not defined.Unsafe maintenance control can block recovery access or leave public writes active.Approve timezone, active-session, API and cache behavior at both boundaries.
SuperadminEXT-EMAILTransactional email supports business notifications with observable delivery and recoverable failure.List of external APIs or third-party integrations required.docx transactional-email entryAdmin, RecipientWF-SA-11, WF-SA-12UAT-SA-PROMO-005, UAT-SA-NOTIF-001, UAT-SA-NOTIF-006Partially CoveredProvider, sender identities, retry and fallback are not final.Undetected email failure can leave agencies or customers unaware of critical events.Approve provider, domain, delivery SLA, retry and dead-letter ownership.
SuperadminEXT-EMBASSYCountry guidance links to approved official embassy URLs without external failure breaking VisaReady.List of external APIs or third-party integrations required.docx embassy URLsAdmin, CustomerWF-SA-07UAT-SA-CFG-004Partially CoveredFinal URL inventory, owner and health-check cadence are not supplied.Broken or unsafe links misdirect applicants.Approve official domains, validation cadence and fallback content.
SuperadminEXT-OCROCR/document intelligence produces traceable evidence and exposes safe retryable failure.List of external APIs or third-party integrations required.docx OCR/document-intelligence entryAdmin, Support, CustomerWF-SA-06, WF-SA-08UAT-SA-CASE-009, UAT-SA-SCR-013Partially CoveredProvider, confidence thresholds, manual-review path and retry limits are not final.Incorrect or invented OCR values can cause unsupported scoring decisions.Approve provider, confidence threshold, review owner, retention and recovery policy.
SuperadminEXT-PUSHPush integration delivers configured events and deep-links only after normal authorization.List of external APIs or third-party integrations required.docx push-notification entryAdmin, CustomerWF-SA-12UAT-SA-NOTIF-004, UAT-SA-NOTIF-006Partially CoveredProvider, token retirement and fallback are not final.Bad deep links or stale tokens can leak data or miss updates.Approve provider, token lifecycle and deep-link authorization contract.
SuperadminEXT-RAZORPAYRazorpay supports purchase, recharge, refund, webhook idempotency and reconciliation.List of external APIs or third-party integrations required.docx Razorpay entryBuyer, Admin, Support, AnalystWF-SA-10, WF-SA-13UAT-SA-PLAN-003, UAT-SA-PLAN-004, UAT-SA-PAY-002, UAT-SA-PAY-003, UAT-SA-PAY-004, UAT-SA-PAY-005, UAT-SA-PAY-008, UAT-SA-PAY-010Partially CoveredProduction credentials/config, webhook SLA, fee/tax and settlement policies are not final.Gateway integration defects directly affect funds and entitlements.Approve environments, signed webhook contract, idempotency keys, fees, settlements and operational SLAs.
SuperadminEXT-SMS-OTPSMS/OTP integration securely delivers messages and expiring one-time challenges.List of external APIs or third-party integrations required.docx SMS/OTP entryAdmin user, Customer, RecipientWF-SA-01, WF-SA-12UAT-SA-NOTIF-002, UAT-SA-NOTIF-006Partially CoveredProvider, OTP TTL, resend/rate limits and fallback are not specified.Weak OTP controls enable takeover; outages block access.Approve provider and complete OTP security/availability policy.
SuperadminEXT-STORAGECloud storage protects documents/assets and exposes recoverable upload/read failure without broken publication.List of external APIs or third-party integrations required.docx cloud-storage entryAdmin, Support, CustomerWF-SA-06, WF-SA-09UAT-SA-CASE-009, UAT-SA-CMS-011Partially CoveredProvider, encryption, retention, malware scan and retry policy are not final.Storage failure can lose evidence or expose PII.Approve provider, security controls, file policy, retention and recovery targets.
SuperadminEXT-WHATSAPPWhatsApp Business sends approved consented event templates once with observable status.List of external APIs or third-party integrations required.docx WhatsApp Business entryAdmin, RecipientWF-SA-12UAT-SA-NOTIF-003, UAT-SA-NOTIF-006Partially CoveredProvider account, consent source, approved template IDs and fallback are not final.Unapproved or duplicate messaging can breach consent and trust.Approve consent evidence, template catalogue, provider statuses and retry/fallback.
SuperadminEXT-GST-PANAgency GST/PAN validation must be either live verification or a clearly approved format/checksum validation policy.VisaReady Final Doc Admin.docx §5 AD-07 List of external APIs or third-party integrations required.docx GST/PAN ambiguityAdmin, Agency AdminWF-SA-04Needs clarificationThe sources conflict/are ambiguous on whether live government verification is required.UAT cannot prove identity-verification adequacy without the authoritative validation contract.Decide live API versus format/checksum validation, provider, outage handling and evidence retention before execution.
SuperadminNFR-AUDITEvery write is durably audited and an audit failure cannot produce an unaudited success.VisaReady Final Doc Admin.docx §10 audit requirementAll administrative rolesWF-SA-14UAT-SA-AUD-001, UAT-SA-AUD-004Partially CoveredAtomic persistence architecture is not specified, but fail-closed business outcome is mandatory.Unaudited writes create compliance and investigation gaps.Confirm atomic/transactional audit mechanism and recovery runbook.
SuperadminNFR-DPDPAPersonal-data erasure and legal consent are controlled, irreversible/versioned and evidentially logged.VisaReady Final Doc Admin.docx §10 DPDPA requirementAdmin, CustomerWF-SA-05, WF-SA-09UAT-SA-USR-005, UAT-SA-CMS-008Partially CoveredLegal retention, erasure SLA and final legal copy require approval.Incomplete privacy fulfillment can breach DPDPA obligations.Obtain legal approval for data map, retention, consent and erasure evidence.
SuperadminNFR-PERFDashboard loads within three seconds and list views support at least 50 rows under agreed UAT conditions.VisaReady Final Doc Admin.docx §10 performance requirementsAdmin, AnalystWF-SA-03UAT-SA-ANL-007Partially CoveredDataset size, concurrency, geography and percentile are not specified.An unbounded performance criterion cannot be objectively accepted.Approve environment, dataset, concurrent users, network profile and percentile.
SuperadminNFR-PRIVACYPII is masked in lists and fully visible only in authorized detail contexts.VisaReady Final Doc Admin.docx §10 privacy requirementsAdmin, Support, AnalystWF-SA-03, WF-SA-05UAT-SA-ANL-008, UAT-SA-USR-001, UAT-SA-USR-002Partially CoveredThe field-level masking matrix by role/export is not supplied.Excess list/export disclosure exposes customer PII at scale.Approve field-by-role masking matrix for UI, CSV, logs and notifications.
SuperadminNFR-SECHTTPS, JWT, RBAC and inactivity controls protect privileged sessions.VisaReady Final Doc Admin.docx §10 security requirementsAll admin rolesWF-SA-01UAT-SA-AUTH-008Partially CoveredInactivity timeout, token lifetime/refresh and supported TLS policy are not fixed.Weak session controls expose privileged access.Approve timeout, token rotation/revocation and transport-security baseline.
SuperadminNFR-AVAILThe platform targets 99.5% availability, but system-health/APM implementation is excluded from Lite.VisaReady Final Doc Admin.docx §10 99.5% availability List of external APIs or third-party integrations required.docx system health/APM out of scopeBusiness Owner, OperationsNeeds clarificationNo measurement window, exclusions, monitoring source or evidence method is approved in the current scope.Availability cannot be objectively accepted without telemetry and a calculation contract.Approve SLI/SLO window, exclusions, telemetry source and future monitoring scope.
Cross-App E2EAD-07Agency KYC validation and approval activate the agency with initial credits while customer-data editing remains off by default.VisaReady Final Doc Admin.docx §5 AD-07Authorized Admin, Prospective Agency AdminE2E-WF-01UAT-E2E-001Partially CoveredGST/PAN verification method and approved initial-credit amount are not final.Incorrect approval can activate an unverified agency or grant the wrong commercial value.Approve the KYC verification policy, failure handling, initial-credit amount, and default edit-right state.
Cross-App E2EAD-15Verified customer deletion requests enter a reviewed queue, progress through deletion or anonymization, and are communicated to the customer.VisaReady Final Doc Admin.docx §5 AD-15Customer, Authorized Privacy AdminE2E-WF-08UAT-E2E-008Partially CoveredRetention categories, verification evidence, deletion SLA, and dependency-exception policy are open.A request can be lost, prematurely erased, or falsely reported complete.Approve the deletion request state machine, verification evidence, SLA, retention schedule, and exception owner.
Cross-App E2EAD-16DPDPA erasure is an irreversible cross-module controlled job with customer notification and audit evidence.VisaReady Final Doc Admin.docx §5 AD-16Authorized Privacy Admin, Erasure Worker, CustomerE2E-WF-08UAT-E2E-008Needs clarificationLegally retained records, derived-data scope, completion SLA, and retry ownership are unspecified.Incomplete or excessive erasure creates serious privacy, legal, and operational exposure.Obtain legal approval for the data map and retention and operational approval for job recovery.
Cross-App E2EAD-20The country catalogue uses unique identity, active state, and approved metadata, and inactive countries are hidden from new journeys.VisaReady Final Doc Admin.docx §5 AD-20Configuration Admin, Customer, Agency UserE2E-WF-10UAT-E2E-010Partially CoveredThe launch catalogue, URL owner, propagation boundary, and in-flight behavior are client inputs.Channels can offer unsupported destinations or disagree on active configuration.Approve the launch catalogue, metadata owner, effective-time policy, and in-flight migration behavior.
Cross-App E2EAD-26Dynamic forms support validation, conditions, preview, version and effective date, with consistent cross-channel propagation.VisaReady Final Doc Admin.docx §5 AD-26 Admin Stitch AD26 variantsConfiguration Admin, Customer, Agency UserE2E-WF-10UAT-E2E-010Partially CoveredFinal field catalogue, ranges, cache SLA, and in-flight migration policy are open.Different channels can collect inconsistent or invalid application data.Approve field/range content, effective timezone, cache behavior, and record-version migration.
Cross-App E2EAD-32Fund-parking detection uses OCR evidence, an approved recent-credit threshold, a penalty, and a valid-proof waiver.VisaReady Final Doc Admin.docx §5 AD-32Customer, Agency User, Authorized Admin, OCR and Scoring ServicesE2E-WF-11UAT-E2E-011Needs clarificationLookback, aggregation, threshold, penalty, proof types, reviewer, and waiver audit policy are not final.Wrong risk treatment can materially distort a customer's score and report.Approve the calculation, proof catalogue, review authority, penalty, and waiver/rescore trigger.
Cross-App E2EAD-34Published document checklists combine ordered mandatory base documents with the applicable user-type overlay across consuming journeys.VisaReady Final Doc Admin.docx §5 AD-34Configuration Admin, Customer, Agency UserE2E-WF-10UAT-E2E-010Needs clarificationThe final base and user-type overlay lists and in-flight checklist policy are not supplied.Missing or inconsistent checklists can block valid applications or permit incomplete evidence.Approve all checklist content, ordering, mandatory flags, and version-migration behavior.
Cross-App E2EAD-42The B2B and B2C plan catalogue controls price, period, quota, carry-forward, activation, and deactivation behavior.VisaReady Final Doc Admin.docx §5 AD-42Plan Admin, Existing Customer Subscriber, Prospective CustomerE2E-WF-18UAT-E2E-018Needs clarificationFinal catalogue values, renewal, carry-forward, deactivation boundary, and existing-entitlement treatment remain inputs.Deactivation can wrongly remove paid value or continue selling an unavailable product.Approve the complete plan lifecycle, effective boundary, in-flight orders, successor plans, expiry, and carry-forward.
Cross-App E2EAD-49Business events map deterministically to approved active notification channels and templates.VisaReady Final Doc Admin.docx §5 AD-49Notification Admin, Agency User, CustomerE2E-WF-14UAT-E2E-014Needs clarificationThe final event, recipient, channel, idempotency, and retry matrix is unresolved.Wrong or duplicate communications can expose data or misstate application status.Approve the event catalogue, audience, channel, preference override, retry, and delivery-state contract.
Cross-App E2EAD-52Authorized refund decisions require eligibility and reason, execute through the gateway, and update customer and financial state.VisaReady Final Doc Admin.docx §5 AD-52Authorized Support User, Customer, Finance UserE2E-WF-06UAT-E2E-006Needs clarificationPartial-refund eligibility, fees, entitlement reversal, accounting documents, and notification rules are incomplete.Refund errors can duplicate money movement or leave customer, invoice, and entitlement states inconsistent.Approve refund eligibility, amount, fee, entitlement, invoice or credit-note, and notification policy.
Cross-App E2EAD-53Razorpay reconciliation classifies matched, mismatched, and pending records and safely handles delayed or duplicate events.VisaReady Final Doc Admin.docx §5 AD-53Finance or Support User, Razorpay, CustomerE2E-WF-05UAT-E2E-005Partially CoveredSettlement cadence, tolerance, mismatch owner, and closing evidence are not defined.Delayed or duplicate events can grant duplicate entitlement or leave paid customers without value.Approve reconciliation cadence, match keys and tolerance, resolution ownership, and closure evidence.
Cross-App E2EAD-62Super Admin generates and allocates promo codes, Agency distributes them, and eligible Customer redemption waives one configured transaction under use, cap, and expiry rules.VisaReady Final Doc Admin.docx §5 AD-62Super Admin, Agency User, CustomerE2E-WF-09UAT-E2E-009Needs clarificationAllocation commitment, customer binding, timezone, caps, waiver scope, and delivery recovery are unresolved.Weak promo controls can create unauthorized free transactions or inaccurate usage.Approve allocation semantics, code scope, customer and agency binding, caps, expiry timezone, waiver, and notification recovery.
Cross-App E2EAD-64Terms, Privacy Policy, and Disclaimer are versioned, effective, published, and capable of forcing durable customer re-consent.VisaReady Final Doc Admin.docx §5 AD-64Content Admin, Existing Customer, New CustomerE2E-WF-12UAT-E2E-012Needs clarificationFinal copy, effective timezone, decline experience, session boundary, and retention need legal approval.Users may continue under stale legal terms or lack defensible consent evidence.Obtain legal signoff for copy, effective time, decline/defer handling, session gating, and consent retention.
Cross-App E2EAD-70Super-Admin-only maintenance mode blocks non-admin business channels, preserves recovery access, shows an approved message, and auto-disables at scheduled end.VisaReady Final Doc Admin.docx §5 AD-70Super Admin, Lower Admin, Agency User, CustomerE2E-WF-13UAT-E2E-013Needs clarificationTimezone, active-session, lower-Admin, API, drain-versus-reject, and cache behavior are not final.Inconsistent maintenance enforcement can allow partial writes or prevent recovery access.Approve role access, session and API handling, write boundary, timezone, message, and cache invalidation.
Cross-App E2EAG-R011Agency data and direct record actions are tenant- and permission-scoped with no cross-agency disclosure.Agency PRD role and ownership model and Screens 5-6 shared-record mappingsAgency A User, Agency B User, Agency Sub-UserE2E-WF-16UAT-E2E-016Partially CoveredTenant isolation is implicit rather than stated as one atomic requirement.Cross-agency leakage exposes customer identity, documents, scores, and commercial data.Add an explicit agency-tenancy and direct-object-access security requirement.
Cross-App E2EAG-R012WhatsApp outreach generates a unique agency-code link, maps the customer, and pre-fills permitted conversational data.Agency PRD Screen 7 External API document: WhatsApp Business APIAgency User, CustomerE2E-WF-01UAT-E2E-001Partially CoveredCredentials, templates, final signed-link format, expiry, and abuse controls are client inputs.A weak or incorrect referral link can misattribute customers or expose application data.Approve link signing, expiry, replay, templates, consent, and provider configuration.
Cross-App E2EAG-R020Agency can manage the approved maximum co-applicants while only the primary applicant is individually scored.Agency PRD Screen 6 co-applicant controls and §4.2Primary Customer, Agency UserE2E-WF-17UAT-E2E-017Needs clarificationMaximum party size and final per-credit treatment remain unresolved across sources.Incorrect limits or scoring can block families or create unauthorized charges and reports.Approve one maximum party size and one primary/co-applicant score, credit, and report model.
Cross-App E2EAG-R021Documents remain on one shared record with visible OCR state; valid extraction may prefill and failed extraction remains recoverable.Agency PRD Screen 6 and Screen 7 External API document: OCR and cloud storageCustomer, Agency User, Authorized AdminE2E-WF-15UAT-E2E-015Needs clarificationPermanent OCR failure, manual fallback, retry limit, and confidence review thresholds are not final.Integration failure can falsely complete evidence or overwrite customer-confirmed identity data.Approve OCR review, retry, permanent-failure fallback, and manual correction rules.
Cross-App E2EAG-R026Agency-set application statuses drive the Customer timeline and approved cross-channel status communications.Agency PRD Screen 6 status table and notification ruleAgency User, Customer, Authorized AdminE2E-WF-01UAT-E2E-001Partially CoveredThe complete allowed-transition and reversal matrix is absent.Out-of-order or inconsistent status can mislead customers and operations.Approve allowed prior/new state transitions, correction authority, and event notification mapping.
Cross-App E2EAG-R030An authorized Agency user purchases a configured credit pack through the payment gateway; success updates wallet and creates an invoice.Agency PRD Screen 9 External API document: RazorpayAgency Admin, Razorpay, Finance UserE2E-WF-01UAT-E2E-001Partially CoveredFinal packs, tax, currency, gateway configuration, and payment methods are client inputs.Incorrect recharge can grant wrong credits or create unreconciled financial records.Approve release pack values, taxes, currencies, payment methods, and Razorpay configuration.
Cross-App E2EAG-R042Super Admin allocates a promo, Agency receives and distributes it, and an eligible Customer redeems it for the configured fee waiver with tracked usage.Agency PRD §6.1 flow and Appendix B AD-62Super Admin, Agency User, CustomerE2E-WF-09UAT-E2E-009Needs clarificationAllocation defaults, email template, code scope, and mock recharge-bonus conflict remain unresolved.An ambiguous promo model can create unauthorized discounts and inaccurate agency attribution.Confirm the customer fee-waiver semantic and approve allocation, delivery, code scope, and usage rules.
Cross-App E2EAG-R044Super Admin configuration changes propagate consistently to Agency and Customer journeys.Agency PRD Appendix B tables B.1 and B.3Configuration Admin, Agency User, CustomerE2E-WF-10UAT-E2E-010Needs clarificationEffective time, caching, propagation SLA, and in-progress versioning are unspecified.Different application channels can apply contradictory requirements and calculations.Define configuration versioning, effective time, cache invalidation, propagation SLA, and record migration.
Cross-App E2EAG-R046Agency, Customer mobile and web, and Super Admin use one shared application record with consistent ownership, fields, states, score, report, and co-applicants.Agency PRD product overview, §§4 and 8, and Appendix BCustomer, Agency User, Authorized AdminE2E-WF-01, E2E-WF-03UAT-E2E-001, UAT-E2E-003Partially CoveredSimultaneous-edit conflict policy and synchronization SLA remain unspecified.Forked or stale shared records can corrupt applications, scores, reports, and ownership.Approve field ownership, concurrency conflict, synchronization SLA, and offline reconciliation.
Cross-App E2EAMEND-S-1Phase-1 Customer Conclusion includes the approved review link https://qr.link/9bpJ5L.Amendment sheet Sheet1 row 3, s-1, 15/07/26CustomerE2E-WF-01UAT-E2E-001Needs clarificationPlacement copy, target behavior, and eligible Conclusion outcomes are not stated.An incorrectly placed or exposed review link can confuse customers or solicit reviews at the wrong outcome.Confirm exact placement, display copy, navigation behavior, and eligible granted or rejected outcomes.
Cross-App E2ECUS-EXT-OCROCR extracts supported passport and financial evidence, exposes reviewable confidence or failure, and never silently overwrites customer-confirmed values.External API document: passport, bank-statement, and fund-parking OCR Customer PRD §4.7, §4.14, and §4.20Customer, Agency User, Authorized Admin, OCR ServiceE2E-WF-15UAT-E2E-015Needs clarificationProvider, field map, confidence thresholds, supported layouts, retry, review routing, and permanent-failure behavior are unspecified.False or silent extraction can corrupt identity, evidence, risk, and scoring outcomes.Approve OCR provider, field map, thresholds, review controls, supported documents, retry, and fallback.
Cross-App E2ECUS-EXT-RAZORPAYRazorpay handles customer payment, delayed and duplicate webhook reconciliation, and refunds idempotently.External API document: Razorpay Customer PRD §4.15Customer, Razorpay, Support or Finance UserE2E-WF-02, E2E-WF-05, E2E-WF-06UAT-E2E-002, UAT-E2E-005, UAT-E2E-006Needs clarificationFinal gateway configuration, payment state machine, refund policy, entitlement reversal, tax, and accounting documents are incomplete.Payment integration errors can charge without value, duplicate value, or misstate refunds and revenue.Approve the payment and refund state machines, idempotency keys, entitlement rules, tax, invoice or credit-note treatment, and reconciliation operations.
Cross-App E2ECUS-EXT-STORAGECloud storage protects owned uploads and reports and supports recoverable failure without duplicate or false business completion.External API document: cloud storage Customer PRD §4.14 and §4.16Customer, Agency User, Authorized Admin, Cloud StorageE2E-WF-15UAT-E2E-015Needs clarificationProvider, encryption, malware controls, URL expiry, retention, deletion propagation, and retry contract are unspecified.Storage failure or weak ownership can lose evidence, leak PII, or falsely complete a checklist.Approve storage provider, security, lifecycle, malware, signed-link, retention, deletion, and retry requirements.
Cross-App E2ECUS-PRD-4.13-CODEAn optional active six-digit numeric agency code maps the whole existing application at any step and referral links prefill that attribution.Customer PRD §4.13 and appended code answer Customer Stitch Agent ID and Referral screensCustomer, Agency User, Authorized AdminE2E-WF-03UAT-E2E-003Partially CoveredStitch uses alphanumeric examples that conflict with the approved six-digit numeric rule.Inconsistent code format or partial mapping can misattribute or fork a customer's application.Replace mock examples and enforce one six-digit numeric namespace across all channels.
Cross-App E2ECUS-PRD-4.13-LINKAn agent-created application links to a later matching verified customer identity and remains one shared record.Customer PRD §4.13 Account Linking and §4.17 shared recordAgency User, Customer, Support or AdminE2E-WF-04UAT-E2E-004Needs clarificationEmail/mobile precedence, identity collision, field ownership, review owner, and concurrency policy are unspecified.Unsafe matching can cause account takeover, data disclosure, or duplicate applications.Approve matching precedence, collision hold/review, resolution evidence, customer messaging, and concurrency rules.
Cross-App E2ECUS-PRD-4.13-LITELite uses five factors and returns only Low, Medium, or High with a disclaimer, without Final-only numeric score, risks, flags, penalties, or paid report content.Customer PRD §4.13 and §5.3 Customer Stitch Preliminary Eligibility ScoreDirect Customer, Scoring Service, Authorized AdminE2E-WF-02UAT-E2E-002Needs clarificationExact Lite thresholds are open and the mock incorrectly exposes numeric score and factor values.A numeric or risk-bearing Lite result can mislead customers and leak paid functionality.Approve thresholds and align every Customer and Admin representation to the non-numeric Lite rule.
Cross-App E2ECUS-PRD-4.14-FUNDConfigured recent-deposit analysis raises fund-parking risk and valid source-of-funds proof can waive the corresponding penalty.Customer PRD §4.14 and appended fund-parking answerCustomer, Agency User, Authorized AdminE2E-WF-11UAT-E2E-011Needs clarificationThreshold wording, lookback, recurring-deposit treatment, timezone, proof validation, and flag-clear trigger remain open.Incorrect detection or waiver can unfairly lower or inflate a customer's Final outcome.Approve the formula, lookback, timezone, recurrence, accepted proof, reviewer, and rescore trigger.
Cross-App E2ECUS-PRD-4.15-PROMOA promo must be valid, available, and correctly scoped to waive the configured customer transaction and produce proper usage and invoice evidence.Customer PRD §4.15 and appended promo answerCustomer, Agency User, Super AdminE2E-WF-09UAT-E2E-009Needs clarificationWaived line items, code lifecycle, agency/customer binding, single/multi-use caps, expiry timezone, and delivery template are inconsistent or absent.Weak validation can permit unauthorized free transactions or wrong-agency redemption.Approve waiver scope, binding, caps, lifecycle, expiry timezone, fallback, and invoice treatment.
Cross-App E2ECUS-PRD-4.16-REPORTAdvance VisaMatrix contains approved intelligence and recommendations, is non-guaranteeing, branded, watermarked, and verifiable by report ID and QR.Customer PRD §4.16 and §5.4-5.5Direct Customer, Agency User, Authorized AdminE2E-WF-02UAT-E2E-002Partially CoveredTemplate order, intelligence configuration, watermark asset, metric counts, and verification access rules are not final.An incorrect or unverifiable report can misstate readiness and damage customer trust.Approve the complete report template, factor presentation, reason codes, branding, QR access, and verification contract.
Cross-App E2ECUS-PRD-4.4Current legal documents require full review and one consent, with customer, policy version, and timestamp durably recorded.Customer PRD §4.4 and appended legal contentExisting Customer, New Customer, Content AdminE2E-WF-12UAT-E2E-012Needs clarificationFinal copy, re-consent policy, effective timezone, and decline/defer behavior need legal approval.Incomplete consent evidence creates compliance exposure and permits use under stale terms.Approve final versions, effective boundary, re-consent, decline/defer experience, and evidence retention.
Cross-App E2ECUS-PRD-4.6.2Customer notification categories and in-app, WhatsApp, and email channels can be independently controlled while approved business events generate communications.Customer PRD §4.6.2 External API document: WhatsApp, email, and pushCustomer, Agency User, Notification AdminE2E-WF-14UAT-E2E-014Needs clarificationEssential-message overrides, templates, channel defaults, and event/channel mapping remain open.Ignoring preferences can breach trust, while suppressing essential messages can hide material events.Approve event and category catalogue, essential overrides, channel defaults, templates, and retry behavior.
Cross-App E2ECUS-PRD-4.6.3-DELETECustomer deletion is a reviewed request, not immediate, and submission and completion are communicated.Customer PRD §4.6.3 External API document: deletion confirmationsCustomer, Authorized Privacy AdminE2E-WF-08UAT-E2E-008Needs clarificationRetention, SLA, pending-account behavior, verification evidence, and retained audit fields are open.Immediate, incomplete, or uncommunicated deletion can violate DPDPA and break customer records.Approve the complete request, review, queue, erasure, retention, failure, and notification state machine.
Cross-App E2ECUS-PRD-4.6.8Customer Plan shows current state, validity, usage, history, renewal or change entry points, and invoices.Customer PRD §4.6.8Existing Customer Subscriber, Support User, Plan AdminE2E-WF-18UAT-E2E-018Partially CoveredFinal displayed fields and inactive-plan renewal, upgrade, expiry, and successor behavior are not approved.Customers can lose paid entitlement or receive misleading plan and invoice information.Approve status and usage fields plus inactive-plan expiry, renewal, upgrade, and successor behavior.
Cross-App E2ECUS-PRD-4.7AMulti-applicant mode captures supported relationships, completion, removal protection, capacity, and a pre-commercial completion gate.Customer PRD §4.7a Customer Stitch Family ManagementPrimary Customer, Agency UserE2E-WF-17UAT-E2E-017Needs clarificationFive co-applicants plus primary versus five total, relationship proof, and mandatory fields are unresolved.Wrong capacity or completion rules can block a family or permit incomplete paid processing.Approve the maximum party size and full relationship, proof, mandatory-field, removal, and completion matrix.
Cross-App E2ECUS-PRD-4.7A-TOKENOnly the primary receives an individual score and co-applicant completion is not a VisaScore; commercial treatment follows one approved party model.Customer PRD §4.7a, §4.15, §5.3, and appended pricingPrimary Customer, Agency User, Finance UserE2E-WF-17UAT-E2E-017Needs clarificationSources conflict among primary-only token, per-passport token, and combo separate-score/report models.Ambiguous commercial treatment can overcharge, undercharge, or produce unauthorized scores and reports.Approve one primary/co-applicant score, token, price, report, and invoice entitlement table.
Cross-App E2ECUS-PRD-5.3-RESCOREA material application data change is required before rescore and the application-scoped allowance and charging limit are enforced.Customer PRD §4.13, §4.16a, §5.3, and appended answersCustomer, Agency User, Scoring ServiceE2E-WF-11UAT-E2E-011Needs clarificationMain text and appended answer conflict on paid and terminal behavior after the one free regeneration.Wrong counters can create free misuse, overcharging, or blocked remediation.Approve the exact original/free/paid/terminal count, qualifying changes, counter reset, failure rollback, and party scope.
Cross-App E2ECUS-PRD-6.2Customer personal and financial data is ownership-scoped, protected, integrity-checked, and handled under approved privacy, residency, and retention controls.Customer PRD §6.2Customer, Agency User, Authorized AdminE2E-WF-04, E2E-WF-16UAT-E2E-004, UAT-E2E-016Needs clarificationEncryption standards, residency, retention, third-party boundaries, identity collision, and measurable security evidence are incomplete.Weak identity or ownership controls can expose high-risk personal, financial, and document data.Approve measurable identity, encryption, residency, retention, third-party, signed-link, and security-audit controls.
Cross-App E2EEXT-EMAILTransactional email supports observable business delivery and recoverable failure without duplicating the underlying event.External API document: transactional emailCustomer, Notification Admin, Email ProviderE2E-WF-14UAT-E2E-014Needs clarificationProvider, sender domain, templates, delivery SLA, retry, and dead-letter ownership are not final.False success or uncontrolled retry can hide failed communication or send duplicates.Approve provider, sender identity, templates, delivery states, retry SLA, idempotency, and dead-letter owner.
Cross-App E2ENFR-AUDITEvery committed write is durably audited, and audit persistence failure cannot produce an unaudited business success.VisaReady Final Doc Admin.docx §10 audit requirementCustomer, Agency User, Support User, Super Admin, AnalystE2E-WF-13, E2E-WF-19UAT-E2E-013, UAT-E2E-019Partially CoveredAtomic persistence architecture, retention, masking, clock, correlation, export, and recovery runbook are not specified.Unaudited success or mutable evidence prevents accountability for sensitive cross-application actions.Approve the atomic audit mechanism, event schema, clock and correlation standard, masking, retention, export, and recovery runbook.
Cross-App E2ENFR-DPDPAPersonal-data erasure and legal consent are controlled, irreversible or versioned as applicable, and evidentially logged.VisaReady Final Doc Admin.docx §10 DPDPA requirementCustomer, Privacy Admin, Content AdminE2E-WF-08, E2E-WF-12UAT-E2E-008, UAT-E2E-012Needs clarificationFinal legal copy, data inventory, retention, erasure SLA, decline behavior, and evidence retention require legal approval.Weak consent or erasure controls create serious DPDPA and privacy exposure.Obtain legal approval for the data map, retention, legal versions, consent lifecycle, erasure scope, SLA, and retained evidence.