Executive summary
Consolidated dependencies62
External integration families12
Exact $cred queries52
Exact credential matches0
Raw requirement gap rows185
Known open defects8
Dependencies by gate
Program start blocker9
Core feature blocker25
Feature blocker7
Partial development blocker7
Pre-UAT blocker6
Pre-release dependency6
Non-blocking / out of scope2
$cred conclusion: No requirement-listed service name, provider alias, VisaReady project identifier, project folder ID/URL, project credential-sheet ID/URL, APM label, or approved review URL produced an exact registry match. Credential availability is therefore unconfirmed; a canonical service-to-environment mapping is required before any secret can be consumed.
Separate project credential workbook: A separate Google Sheet titled 'Visa ready Api Creds' exists in the project Drive, but it was not opened: the user invoked the configured $cred registry, and the Master registry contains no exact mapping to that workbook. This is a source-of-truth dependency.
Separate project credential workbook: A separate Google Sheet titled 'Visa ready Api Creds' exists in the project Drive, but it was not opened: the user invoked the configured $cred registry, and the Master registry contains no exact mapping to that workbook. This is a source-of-truth dependency.
What blocks development now
Credentials are not the first blocker. The supplied workspace has no application source/build definitions, and the Drive Content and Configurations folder is empty. Integration credentials cannot be safely wired until repositories, platform identities, environment topology, canonical APIs/data ownership, and a versioned configuration bundle are supplied.
| ID | Dependency | Apps | Current gap | Exit criteria | Owner |
|---|---|---|---|---|---|
| VR-BLK-013 | Application repositories, target revisions, build definitions, and dependency manifests for every deployable | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: the workspace contains only .tcgen test-design artifacts and no application source, package/build manifest, dependency lockfile, Dockerfile, infrastructure definition, environment template, or build instructions. Architectural inference: implementation requires the repository location, target branch or commit, technology stack, dependency installation method, build commands, and owning team for each deployable. | All in-scope repositories are accessible at approved revisions; every deployable has reproducible install, build, test, and local-run instructions; dependency manifests and lockfiles are present; and repository ownership is recorded. | Engineering Program Lead and Application Engineering Leads |
| VR-BLK-014 | Approved deployable and supported-platform matrix | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login Web | Evidence-backed absence: requirements name Customer mobile and web channels, Agency and Superadmin web portals, a shared login URL, and a signed target APK, but no authoritative deployable list or supported OS, browser, device, and version matrix is supplied. Architectural inference: the team must decide whether mobile scope is Android only or Android and iOS, whether web surfaces are independent deployments, and which responsive and accessibility targets apply. | A signed release-scope matrix identifies every deployable, platform, minimum OS/browser version, supported device class, responsive breakpoint expectation, release channel, and accountable engineering owner. | Product Owner, Solution Architect, Mobile Lead, and Web Lead |
| VR-BLK-015 | Mobile application identity, signing, versioning, permissions, and distribution artifacts | Customer Mobile App | Evidence-backed absence: BUG-CUS-001 requires an approved package, launcher, splash identity, and signed target APK, while the requirements need camera, file or storage, and notification permissions; no Gradle project, AndroidManifest, package ID, keystore reference, signing configuration, version scheme, or release channel is present. Architectural inference: Android app-link configuration and signing custody are required, and equivalent iOS identifiers and signing artifacts are required only if iOS is confirmed in DEL-02. | The approved mobile application ID, signing-custody process, non-secret signing reference, version and build numbering policy, permission manifest, launcher and splash asset package, app-link scheme, and internal or store distribution path are documented and usable in a reproducible signed build. | Mobile Engineering Lead, Security, and Release Manager |
| VR-BLK-017 | Canonical API contract, identity model, shared application schema, and migration strategy | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: requirements mandate one shared Customer, Agency, and Admin application record, identity linking, ownership isolation, immediate role enforcement, synchronized status and report state, and immutable audit, but no API schema, canonical identifier model, database schema, or migration definition is available. Architectural inference: the solution needs a versioned API contract, tenant and object-ownership model, identity-resolution rules, optimistic or equivalent concurrency control, schema migrations, cache invalidation, and backward-compatibility strategy. | Approved API and event contracts, canonical entity and identifier model, tenant and ownership rules, database schema and migration path, concurrency policy, synchronization SLA, cache policy, and compatibility/versioning rules are implementation-ready. | Backend Architect, Data Architect, and Identity Lead |
| VR-BLK-029 | Data export, deletion, anonymization, retention, and recovery contract | Customer App, Agency, Superadmin, Cross-App E2E | The data map, export contents and delivery, deletion state machine, retention schedule, erasure SLA, retained legal and audit evidence, dependency failures, retry ownership, and exception handling are unspecified. | The DPO and Legal approve the data map and retention schedule, and Data Operations approves executable export and irreversible erasure state machines with verification, SLA, recovery, exception ownership, and customer communications. | DPO, Legal, Data Architecture, and Data Operations |
| VR-BLK-030 | Encryption, residency, masking, tenancy, and third-party data boundaries | Customer App, Agency, Superadmin, Cross-App E2E | Encryption standards, residency region, field-by-role masking across UI, export, logs and messages, financial-data sharing boundaries, transport baseline, and explicit agency tenant-isolation requirements are not approved. | Security and Privacy approve a measurable control baseline and field-by-role data-access matrix covering storage, transit, UI, APIs, exports, logs, notifications, tenancy, and third-party disclosures. | Security Architect and DPO |
| VR-BLK-031 | Atomic, durable, and recoverable audit contract | Superadmin, Cross-App E2E | The event schema, time and correlation standard, previous and new state capture, masking, retention, export, transactional persistence, fail-closed behavior, and audit recovery runbook are not defined. | Architecture, Security, and Compliance approve an atomic audit design and event contract that prevents an unaudited successful write and supports investigation and recovery. | Platform Architect, Security, and Compliance |
| VR-BLK-032 | Shared-application ownership, identity linking, drafts, offline behavior, and concurrent updates | Customer App, Agency, Superadmin, Cross-App E2E | Field ownership, verified-identity matching precedence, collision review, blank-field behavior when edits are disabled, optimistic locking or merge rules, draft retention, offline persistence, and cross-channel synchronization SLA are unresolved. | Product and Data Architecture approve one shared-record ownership and concurrency matrix, including identity collision, review, merge, version, draft, offline, and synchronization rules. | Product Owner and Data Architect |
| VR-BLK-033 | Authoritative RBAC, agency tenancy, sensitive permissions, and role presets | Agency, Superadmin, Cross-App E2E | The final capability list, default sub-user template, preset-to-permission mapping, application-detail access, sensitive export, branding, billing, promo, and direct-object authorization rules are incomplete. | Security and Product approve a server-enforced role, permission, tenancy, object-scope, masking, and export-access matrix for every administrative and agency role. | Security, Product, and Agency Operations |
| VR-BLK-001 | Razorpay payment gateway provider/account/configuration binding | Customer App, Agency, Superadmin, Shared Backend | ['Sandbox, UAT, and production account mapping', 'Signed webhook and callback configuration', 'Payment, refund, settlement, fee, tax, and invoice rules', 'Idempotency, retry, and reconciliation operating contract'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership. | Finance, Product, Backend, DevOps |
| VR-BLK-003 | OCR and document intelligence provider/account/configuration binding | Customer App, Agency, Superadmin, Shared Backend | ['Provider and environment accounts', 'Supported document/layout catalogue and field map', 'Confidence thresholds and customer/reviewer correction rules', 'Retry, manual review, permanent-failure, retention, and audit contract'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements. | Product, Data or AI Lead, Compliance, Backend |
| VR-BLK-004 | SMS and OTP service provider/account/configuration binding | Customer App, Agency, Superadmin, Shared Identity | ['Provider and environment sender configuration', 'OTP validity, resend interval, attempt reset, cooldown, and rate limits', 'Template, delivery-state, retry, and outage fallback rules', 'Security monitoring and abuse controls'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership. | Identity, Security, Product, Backend |
| VR-BLK-008 | Cloud object storage provider/account/configuration binding | Customer App, Agency, Superadmin, Shared Backend | ['Provider, region, environments, buckets, and tenancy layout', 'Encryption and key-management design', 'Malware scanning, content validation, and access controls', 'Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policy'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior. | Platform, Security, Privacy, Backend |
| VR-BLK-010 | GST and PAN validation provider/account/configuration binding | Agency, Superadmin, Shared Backend | ['Authoritative decision between format/checksum and live verification', 'Provider and environment configuration if live verification is required', 'Timeout, outage, retry, manual-review, and fail-open or fail-closed policy', 'Verification evidence and retention requirements'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency. | KYC, Product, Compliance, Backend |
| VR-BLK-018 | Queue, worker, scheduler, retry, idempotency, and dead-letter execution model | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: requirements explicitly require delayed and duplicate webhook handling, notification retry and dead-letter ownership, OCR retry, an erasure worker, effective-time publication, and scheduled maintenance, but no queue, worker, scheduler, retry table, or recovery runbook is supplied. Architectural inference: a durable event or job mechanism with correlation, idempotency, poison-message handling, replay authorization, scheduling, monitoring, and atomic state-transition rules is necessary; no specific technology is mandated. | The asynchronous architecture, job and event schemas, idempotency keys, retry and timeout limits, dead-letter ownership, scheduler and timezone behavior, replay controls, failure-state semantics, and operational recovery runbooks are approved and testable. | Platform Engineering Lead and Backend Engineering Lead |
| VR-BLK-020 | Versioned, approved release configuration and content seed package | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: the project Drive Content and Configurations folder is empty, while the requirements need a launch-country catalogue, visa purposes, forms and ranges, document checklists, scoring weights and bands, risk rules and penalties, plan and credit packs, prices and taxes, promo rules, notification mappings and templates, support contacts, SLAs, and official URLs. Architectural inference: these values require a versioned, environment-promotable seed package with validation, effective dates, rollback, cache invalidation, migration behavior, and accountable content owners. | An approved release configuration package contains every required catalogue and rule, passes schema and cross-reference validation, identifies its source owner and effective date, can be promoted by environment, supports safe rollback, and defines treatment of in-flight and historical records. | Product Owner, Business Analyst, Configuration Owner, and Finance Owner |
| VR-BLK-023 | Production data protection, storage, backup, recovery, and audit controls | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: encryption, residency, retention, malware scanning, signed-link lifetime, deletion propagation, audit retention and export, and fail-closed audit persistence remain unresolved, and no database, storage, backup, or recovery configuration is present. Architectural inference: the platform needs KMS-backed encryption, service and tenant authorization, backup and restore objectives, disaster recovery, object scanning and lifecycle jobs, PII masking, immutable audit storage, security testing, and an approved incident and recovery model. | The data classification and residency decision, encryption and key-management design, tenant and object access controls, storage lifecycle and malware policy, backup and tested restore targets, disaster-recovery objectives, audit-store controls, erasure propagation, security-test plan, and accountable recovery owners are approved and verified. | Security Architect, Data Platform Lead, Privacy Owner, and Operations |
| VR-BLK-026 | Structured runtime evidence, immutable audit persistence, correlation, alerting, and recovery runbooks | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | Evidence-backed absence: full APM and System Health are explicitly outside Lite, but requirements still mandate immutable audit, correlation, provider-delivery status, payment reconciliation, export, failure visibility, and fail-closed writes; no audit schema, log standard, telemetry destination, alert policy, retention rule, or runbook is supplied. Architectural inference: Lite still needs structured logs, correlation IDs, immutable audit persistence, critical service and job metrics, security-safe masking, alerts for money, messaging, erasure and audit failures, and operational ownership without claiming the deferred AD-60 dashboard. | The audit event schema, atomic persistence behavior, clock and correlation standard, masking and retention, authorized export, structured logging, minimum critical metrics and alerts, incident ownership, and recovery runbooks are approved and testable; AD-60 remains clearly excluded unless separately authorized. | Backend Engineering Lead, Security or Compliance, and Operations |
| VR-BLK-027 | OTP, lockout, session, password, and restricted-account policy | Customer App, Agency, Superadmin | OTP validity, resend and attempt limits, cooldown and reset behavior, alternate recovery, inactivity timeout, JWT rotation or revocation, password expiry, and restricted-user remediation are not fully fixed. | Product Security approves one production authentication-policy matrix covering every customer, agency, and admin channel, including customer-facing restriction and recovery behavior. | Product Security and Identity Owner |
| VR-BLK-034 | Agency KYC evidence, review outcomes, rejection recovery, and initial credits | Agency, Superadmin, Cross-App E2E | Mandatory onboarding evidence, GST and PAN validation policy, failure handling, More Information behavior, appeal or resubmission versus terminal rejection, initial-credit amount, credit recurrence, and default edit rights are not settled. | Agency Product, Compliance, and Finance approve the KYC checklist, validation contract, review state machine, rejection recovery policy, initial-credit amount and recurrence, and default customer-edit setting. | Agency Product Owner, KYC or Compliance, and Finance |
| VR-BLK-035 | Canonical six-digit agency-code namespace, rendering, uniqueness, and lifecycle | Customer App, Agency, Superadmin, Cross-App E2E | Mocks contain prefixed, alphanumeric, and variable-length codes while the requirement confirms six numeric digits; namespace capacity, reserved values, collision retry, uniqueness scope, retirement, and recycling are undefined. | Product and Data Architecture approve the raw stored and displayed format, generation algorithm, capacity forecast, uniqueness boundary, collision handling, and code lifecycle. | Product Owner and Data Architect |
| VR-BLK-037 | Suspension and permanent-blacklist effects across agency, customer, and shared cases | Customer App, Agency, Superadmin, Cross-App E2E | Customer read and write rights, payments, documents, reports, existing-case behavior, notification audiences, and remediation during agency suspension or blacklist are not approved. | Product, Operations, and Security approve an atomic state-impact matrix for agency users, agency codes, customer cases, financial actions, communications, reinstatement, and permanent blacklist. | Product, Operations, and Security |
| VR-BLK-039 | Document capture, correction authority, review, permanent failure, and version retention | Customer App, Agency, Superadmin, Cross-App E2E | Requirements conflict on whether manual passport entry is permitted; low-confidence review, manual fallback, retry limits, permanent failure, correction precedence, latest versus retained versions, and safe retry behavior are undefined. | Product, Document Data, and Compliance approve the field-authority, review, correction, retry, fallback, version-retention, and no-silent-overwrite contract. | Product, Document Data SME, and Compliance |
| VR-BLK-040 | Party capacity, relationships, mandatory evidence, primary-only scoring, charging, reporting, and invoicing | Customer App, Agency, Superadmin, Cross-App E2E | Sources conflict on five co-applicants plus primary versus five total, one primary score and token versus one token per passport or combo reports, while relationship proofs, required fields, removal, and invoice entitlements are open. | Product, Finance, and Scoring approve one party-capacity, relationship, mandatory-field, completion, removal, score, token, price, report, and invoice-entitlement matrix. | Product, Finance, and Scoring Owner |
| VR-BLK-042 | Versioned dynamic forms, validation ranges, and destination or user-type document checklists | Customer App, Agency, Superadmin, Cross-App E2E | The field catalogue, ranges, dropdowns, conditional visibility, mandatory base checklist, seven user-type overlays, destination and visa variants, ordering, publication, rebuild, and in-flight migration rules are not supplied. | Visa SME and Configuration Product approve the complete field, validation, condition, checklist, ordering, mandatory, publication, version, and migration catalogue. | Visa SME and Configuration Product Owner |
| VR-BLK-043 | Effective dating, version pinning, publication atomicity, propagation, caching, and record migration | Customer App, Agency, Superadmin, Cross-App E2E | There is no cross-module contract for effective timezone, publication atomicity, cache invalidation, propagation SLA, record-version pinning, drafts, or treatment of in-flight applications and orders. | Platform Architecture and Product approve a uniform configuration version, effective-time, publication, propagation, cache, rollback, and in-flight migration policy. | Platform Architect and Product Owner |
| VR-BLK-045 | Authoritative Lite and Final scoring semantics, factors, bands, penalties, and customer presentation | Customer App, Agency, Superadmin, Cross-App E2E | The Lite factor split and thresholds are open while mocks incorrectly show numeric Lite scores; Final Others rules, redistribution, ordered score-band boundaries, penalties, party scope, and customer labels are unresolved. | Product and Scoring approve the five-factor non-numeric Lite contract and the complete seven-factor Final formula, normalization, bands, penalties, scope, reason codes, and presentation. | Product Owner and Scoring SME |
| VR-BLK-046 | Risk catalogue, FraudShield, fund-parking calculation, evidence review, waiver, appeal, and disclosure | Customer App, Agency, Superadmin, Cross-App E2E | Lookback, aggregation, timezone, exact thresholds, combinations, severities, penalties, proof catalogue, reviewer authority, waiver audit, appeal path, customer disclosure, and rescore trigger are unresolved. | Risk, Compliance, and Product approve a complete effective-dated trigger, formula, threshold, severity, penalty, evidence, review, waiver, appeal, disclosure, and rescore matrix. | Risk SME, Compliance, and Product Owner |
| VR-BLK-047 | Score-regeneration allowance, charging, idempotency, rollback, party scope, and improvement recommendations | Customer App, Agency, Superadmin, Cross-App E2E | Sources conflict between one free then paid regenerations and a strict two-total limit; qualifying changes, counter reset, failure rollback, party scope, pricing, recommendation catalogue, impact mapping, and detail-section access are incomplete. | Product, Finance, and Scoring approve the original, free, paid, terminal, qualifying-change, counter-reset, compensation, party, recommendation, and display contract. | Product, Finance, and Scoring Owner |
| VR-BLK-048 | B2C and B2B plans, prices, taxes, credits, quotas, renewal, expiry, carry-forward, and overrides | Customer App, Agency, Superadmin, Cross-App E2E | Core ranges, appended fixed and combo INR prices, USD mocks, credit-token semantics, permitted deductions, pack values, taxes, currencies, low-credit thresholds, renewal, expiry, carry-forward, auto-recharge, plan switching, usage fields, and override proration conflict or remain inputs. | Commercial Product, Finance, and Tax approve a versioned B2C and B2B catalogue and lifecycle matrix covering price, currency, tax, quota, token, deduction, period, renewal, expiry, carry-forward, upgrade, override, and visible usage. | Commercial Product, Finance, and Tax |
| VR-BLK-049 | Payment state, refund eligibility, entitlement reversal, accounting documents, and reconciliation operations | Customer App, Agency, Superadmin, Cross-App E2E | Refund eligibility, partial amounts and fees, consumed-credit treatment, entitlement reversal, invoice or credit-note and tax handling, payment purpose and state model, settlement cadence, matching keys and tolerances, mismatch owner, and closing evidence are unspecified. | Finance, Accounting, and Support Operations approve the end-to-end payment, refund, entitlement, accounting-document, reconciliation, exception, ownership, and closure state machines. | Finance, Accounting, and Support Operations |
| VR-BLK-050 | Promo semantics, allocation, binding, use limits, expiry, failure recovery, waiver, and invoice treatment | Customer App, Agency, Superadmin, Cross-App E2E | Requirements define a customer transaction fee waiver while mocks show an agency recharge bonus; waived items, agency and customer binding, caps, single or multi-use behavior, expiry timezone, allocation commit on notification failure, fallback, and invoice treatment are unresolved. | Commercial Product and Finance approve one promo semantic and complete generation, allocation, binding, distribution, redemption, cap, expiry, failure, waiver, accounting, and audit contract. | Commercial Product and Finance |
| VR-BLK-051 | Application-status transitions, authority precedence, corrections, conclusion, and review-link behavior | Customer App, Agency, Superadmin, Cross-App E2E | The full prior-to-new state matrix, agency versus Admin authority, rollback and correction rights, terminal reason and decision-document rules, notification mapping, and review-link placement, copy, target, and eligible outcomes are not specified. | Product and Operations approve one cross-app state machine with transition authority, precedence, reasons, corrections, reversals, disclosure, documents, notifications, and conclusion review-link behavior. | Product and Operations |
| VR-BLK-056 | VisaMatrix sections, factor presentation, branding, watermark, QR verification, and secure sharing | Customer App, Agency, Superadmin, Cross-App E2E | Final section order, factor display, reason codes, intelligence configuration, watermark and logo assets, file type and size policy, agency co-branding, passport footer, QR destination and access security, share authentication, expiry, revocation, delivery history, and mock metric counts are unresolved. | Product, Brand, and Security approve the versioned report template, assets, file policy, identity and footer rules, QR verification contract, and secure share-link lifecycle. | Product, Brand, and Security |
Recommended owner actions
- Engineering Lead: provide repository URLs/paths, target branches/commits, build commands, dependency lockfiles and ownership for every deployable.
- Product and Architecture: approve the deployable/platform matrix, including Customer Android/iOS/web scope, Agency/Admin web scope, minimum versions and release channels.
- Solution Architecture: approve the canonical API, shared data/identity model, tenancy, field ownership, concurrency/versioning and asynchronous processing design.
- DevOps and Security: publish the Dev/Test/UAT/Prod URL matrix, callback/redirect endpoints, DNS/TLS ownership, secret-manager paths and environment-to-provider account mapping.
- Product, Finance and Scoring: sign the B2C/B2B price/plan/credit catalogue, co-applicant entitlement model, scoring/risk rules, rescore limits, refund/reconciliation and promo semantics.
- Product and Visa SMEs: deliver the versioned launch countries, visa purposes, forms, ranges, document checklists, official URLs and content package.
- Legal and DPO: approve final legal copy, consent/re-consent, data inventory, export/deletion/retention and third-party processing boundaries.
- Integration Owners: select and provision sandbox/UAT accounts for Razorpay, WABA, OCR, SMS/OTP, email, OAuth, push and secure object storage; add canonical exact identifiers to $cred.
- QA/DevOps: provision isolated UAT URLs, synthetic role/tenant data, provider sandboxes, reset tools, safe test documents and failure-injection controls.
- Customer Engineering and QA: fix and retest BUG-CUS-001 through BUG-CUS-008; keep them separate from client/architecture dependencies.
External integration dependency matrix
The registry result is intentionally conservative: “no exact mapping” is not proof that a credential does not exist. It means development lacks a safe, canonical identifier-to-environment mapping.
| Integration | Gate | Apps | Workflow/UAT impact | Evidence | $cred aliases checked | $cred result | Missing inputs | Exit criteria | Owner |
|---|---|---|---|---|---|---|---|---|---|
| Razorpay payment gateway | Core feature blocker | Customer App, Agency, Superadmin, Shared Backend | Real purchase, recharge, delayed or duplicate webhook, refund, entitlement, invoice, and reconciliation journeys cannot be accepted. | CUS-EXT-RAZORPAY, AG-R030, AG-R031, AD-50, AD-52, AD-53, EXT-RAZORPAY | Razorpay | No exact match in Master registry; availability unconfirmed | Sandbox, UAT, and production account mapping, Signed webhook and callback configuration, Payment, refund, settlement, fee, tax, and invoice rules, Idempotency, retry, and reconciliation operating contract | Approve environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership. | Finance, Product, Backend, DevOps |
| WhatsApp Business API | Feature blocker | Customer App, Agency, Superadmin, Shared Backend | Referral attribution, support launch, status notifications, report sharing, consent, retry, and delivery-status flows cannot be proven end to end. | CUS-EXT-WHATSAPP, CUS-PRD-4.6.9, AG-R012, AD-48, AD-49, EXT-WHATSAPP | WhatsApp Business API, WhatsApp Business, WhatsApp, WABA | No exact match in Master registry; availability unconfirmed | Approved WABA account and sender number, Consent source and evidence, Approved templates and bot script, Signed referral/share-link format, expiry, replay controls, retry, and fallback | Approve the WABA account, sender identity, consent evidence, template catalogue, bot and support scripts, signed-link security contract, provider delivery states, retry, idempotency, and fallback behavior. | Communications, Product, Compliance, Backend |
| OCR and document intelligence | Core feature blocker | Customer App, Agency, Superadmin, Shared Backend | Passport, bank-statement, supporting-document, and fund-parking evidence cannot be extracted, reviewed, corrected, or failure-tested against an approved contract. | CUS-EXT-OCR, CUS-PRD-4.7-OCR, AG-R021, AG-R024, AD-32, EXT-OCR | OCR / Document Intelligence Engine, OCR, Document Intelligence, OCR/Document Intelligence | No exact match in Master registry; availability unconfirmed | Provider and environment accounts, Supported document/layout catalogue and field map, Confidence thresholds and customer/reviewer correction rules, Retry, manual review, permanent-failure, retention, and audit contract | Approve the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements. | Product, Data or AI Lead, Compliance, Backend |
| SMS and OTP service | Core feature blocker | Customer App, Agency, Superadmin, Shared Identity | Phone verification, agency registration, login, resend, expiry, lockout, throttling, and provider-outage recovery cannot be accepted. | CUS-PRD-4.3-OTP, AG-R002, AG-R007, AD-48, AD-49, EXT-SMS-OTP, NFR-SEC | SMS / OTP Provider, SMS/OTP, SMS, OTP | No exact match in Master registry; availability unconfirmed | Provider and environment sender configuration, OTP validity, resend interval, attempt reset, cooldown, and rate limits, Template, delivery-state, retry, and outage fallback rules, Security monitoring and abuse controls | Approve the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership. | Identity, Security, Product, Backend |
| Transactional email | Feature blocker | Customer App, Agency, Superadmin, Shared Backend | Authentication and business notifications, exports, reports, deletion notices, promo delivery, retry, suppression, and delivery evidence cannot be validated. | CUS-EXT-OTP-EMAIL-PUSH, AG-R049, AD-47, AD-48, AD-49, EXT-EMAIL | Email Service (transactional), Transactional Email, Email, SendGrid, SES, Amazon SES | No exact match in Master registry; availability unconfirmed | Provider and environment account mapping, Verified sender domains and identities, Approved templates, subjects, and merge fields, Delivery SLA, bounce/suppression, retry, fallback, and dead-letter ownership | Approve the provider, verified domain and sender identities, template and merge-field catalogue, delivery states and SLA, idempotency, retry, suppression, fallback, and dead-letter runbook. | Communications, Product, DevOps, Backend |
| Google OAuth | Feature blocker | Customer App, Shared Identity | Google sign-in, consent, redirect, identity linking, collision handling, revocation, and single-customer resolution cannot be accepted. | CUS-PRD-4.3-AUTH, CUS-PRD-4.13-LINK, EXT-OOS-001 | Google OAuth (Sign-In), Google OAuth, Google Sign-In | No exact match in Master registry; availability unconfirmed | OAuth clients for each environment and platform, Authorized origins and redirect URIs, Consent-screen ownership and publication status, Identity-linking, collision, account-recovery, and revocation policy | Supply approved environment clients and redirect URIs, publish the consent configuration, and approve linking precedence, collision review, account recovery, revocation, and audit behavior. | Identity, Security, Product, DevOps |
| Push notifications through FCM and APNs | Feature blocker | Customer App, Superadmin, Shared Backend | Device registration, customer preferences, push delivery, token retirement, deep links, authorization, retry, and fallback cannot be validated. | CUS-EXT-OTP-EMAIL-PUSH, CUS-PRD-4.6.2, AD-48, AD-49, EXT-PUSH | Push Notification Service, Push Notification, FCM, Firebase Cloud Messaging, APNs | No exact match in Master registry; availability unconfirmed | Provider projects, app identifiers, and environment mapping, Signing-key and service-identity ownership, Device-token registration and retirement policy, Authorized deep-link, delivery-state, retry, and fallback contract | Approve provider projects and application identifiers, secure key custody, token lifecycle, preference enforcement, authorized deep links, observable delivery states, retry, and fallback. | Mobile Lead, Notifications Owner, Security, Backend |
| Cloud object storage | Core feature blocker | Customer App, Agency, Superadmin, Shared Backend | Owned uploads, reports, branding assets, secure downloads, malware handling, retention, deletion propagation, and recovery cannot be accepted. | CUS-EXT-STORAGE, CUS-PRD-4.14-UPLOAD, CUS-PRD-6.2, AG-R048, AD-65, EXT-STORAGE | Cloud File Storage, Cloud Storage | No exact match in Master registry; availability unconfirmed | Provider, region, environments, buckets, and tenancy layout, Encryption and key-management design, Malware scanning, content validation, and access controls, Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policy | Approve the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior. | Platform, Security, Privacy, Backend |
| Official embassy and VFS URLs | Pre-UAT blocker | Customer App, Superadmin | Country configuration and safe external tracking or guidance navigation cannot be accepted for launch destinations. | CUS-PRD-4.17-EMBASSY, AD-20, EXT-EMBASSY | Embassy / Official Visa Portal URLs, Embassy URLs | No exact match in Master registry; availability unconfirmed | Approved launch-country URL catalogue, Official-domain and content ownership, URL validation and review cadence, In-app browser controls, allowlisting, and external-failure fallback | Provide and approve the launch-country official-domain catalogue, owner, review and health-check cadence, allowlisting and navigation policy, and safe fallback content. | Product, Visa Content Operations, Compliance |
| GST and PAN validation | Core feature blocker | Agency, Superadmin, Shared Backend | Agency KYC adequacy, approval, failure handling, and verification evidence cannot be accepted against one authoritative rule. | CUS-EXT-GSTPAN, AG-R003, AD-07, EXT-GST-PAN | GST / PAN validation, GSTIN, PAN, GSTIN/PAN verification API | No exact match in Master registry; availability unconfirmed | Authoritative decision between format/checksum and live verification, Provider and environment configuration if live verification is required, Timeout, outage, retry, manual-review, and fail-open or fail-closed policy, Verification evidence and retention requirements | Approve format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency. | KYC, Product, Compliance, Backend |
| System health and APM monitoring | Non-blocking / out of scope | All applications, Platform Operations | AD-60 is not a VisaReady Lite acceptance feature, but the separate 99.5 percent availability target cannot be objectively evidenced without an approved telemetry source and calculation contract. | AD-60, NFR-AVAIL | Analytics/monitoring, APM | No exact match in Master registry; availability unconfirmed | Explicit Lite exclusion and future-phase ownership, Availability SLI, measurement window, and exclusions, Future monitoring provider, alerting, and evidence policy | Keep AD-60 explicitly excluded from Lite and separate it from current acceptance, or approve a future provider, SLIs, measurement window, exclusions, alert ownership, and evidence method. | Product, SRE, Operations |
| Approved external review link at qr.link | Pre-UAT blocker | Customer App | The amended Conclusion journey cannot be accepted because the exact display, eligible outcomes, navigation, availability, ownership, and failure behavior are unresolved. | AMEND-S-1, CUS-PRD-4.17-CONCLUSION, AD-65 | https://qr.link/9bpJ5L | No exact match in Master registry; availability unconfirmed | Business owner and availability commitment, Exact placement and display copy, Eligible granted or rejected Conclusion outcomes, Browser or deep-link behavior, security allowlisting, analytics, and fallback | Confirm the URL owner and availability, exact placement and copy, eligible outcomes, navigation behavior, security allowlisting, tracking expectations, and safe fallback. | Product, Content Owner, Customer App Lead |
Consolidated blocker and dependency register
| ID | Category | Dependency | Gate | Severity | Apps | Evidence | Current gap | Exit criteria | Owner | Safe parallel work |
|---|---|---|---|---|---|---|---|---|---|---|
| VR-BLK-013 | Repository & Delivery | Application repositories, target revisions, build definitions, and dependency manifests for every deployable | Program start blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | WORKSPACE-OBS-NO-APP-SOURCE, CUS-SRC-001, AG-PRD, SRC-SA-REQ, E2E-SRC-003 | Evidence-backed absence: the workspace contains only .tcgen test-design artifacts and no application source, package/build manifest, dependency lockfile, Dockerfile, infrastructure definition, environment template, or build instructions. Architectural inference: implementation requires the repository location, target branch or commit, technology stack, dependency installation method, build commands, and owning team for each deployable. | All in-scope repositories are accessible at approved revisions; every deployable has reproducible install, build, test, and local-run instructions; dependency manifests and lockfiles are present; and repository ownership is recorded. | Engineering Program Lead and Application Engineering Leads | Requirements clarification, architecture planning, UX review, data modeling, and provider onboarding can continue, but implementation against the actual products cannot. |
| VR-BLK-014 | Release Scope | Approved deployable and supported-platform matrix | Program start blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login Web | BUG-CUS-001, CUS-PRD-4.4-PERM, AG-R008, AG-R046 | Evidence-backed absence: requirements name Customer mobile and web channels, Agency and Superadmin web portals, a shared login URL, and a signed target APK, but no authoritative deployable list or supported OS, browser, device, and version matrix is supplied. Architectural inference: the team must decide whether mobile scope is Android only or Android and iOS, whether web surfaces are independent deployments, and which responsive and accessibility targets apply. | A signed release-scope matrix identifies every deployable, platform, minimum OS/browser version, supported device class, responsive breakpoint expectation, release channel, and accountable engineering owner. | Product Owner, Solution Architect, Mobile Lead, and Web Lead | Shared domain modeling and provider evaluation can proceed; platform-specific project setup and acceptance baselines should wait for the matrix. |
| VR-BLK-015 | Mobile & Release | Mobile application identity, signing, versioning, permissions, and distribution artifacts | Program start blocker | Critical | Customer Mobile App | BUG-CUS-001, CUS-PRD-4.4-PERM, WORKSPACE-OBS-NO-MOBILE-MANIFEST | Evidence-backed absence: BUG-CUS-001 requires an approved package, launcher, splash identity, and signed target APK, while the requirements need camera, file or storage, and notification permissions; no Gradle project, AndroidManifest, package ID, keystore reference, signing configuration, version scheme, or release channel is present. Architectural inference: Android app-link configuration and signing custody are required, and equivalent iOS identifiers and signing artifacts are required only if iOS is confirmed in DEL-02. | The approved mobile application ID, signing-custody process, non-secret signing reference, version and build numbering policy, permission manifest, launcher and splash asset package, app-link scheme, and internal or store distribution path are documented and usable in a reproducible signed build. | Mobile Engineering Lead, Security, and Release Manager | Mobile UX and business-domain code can be designed; a real installable release and platform integrations cannot be completed. |
| VR-BLK-017 | Architecture & Shared Data | Canonical API contract, identity model, shared application schema, and migration strategy | Program start blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | CUS-PRD-4.13-LINK, AG-R013, AG-R046, AD-57, AD-58, CUS-PRD-6.2 | Evidence-backed absence: requirements mandate one shared Customer, Agency, and Admin application record, identity linking, ownership isolation, immediate role enforcement, synchronized status and report state, and immutable audit, but no API schema, canonical identifier model, database schema, or migration definition is available. Architectural inference: the solution needs a versioned API contract, tenant and object-ownership model, identity-resolution rules, optimistic or equivalent concurrency control, schema migrations, cache invalidation, and backward-compatibility strategy. | Approved API and event contracts, canonical entity and identifier model, tenant and ownership rules, database schema and migration path, concurrency policy, synchronization SLA, cache policy, and compatibility/versioning rules are implementation-ready. | Backend Architect, Data Architect, and Identity Lead | Frontend mock flows and isolated component work can proceed; persistent cross-app journeys and authorization cannot. |
| VR-BLK-029 | Legal & Privacy | Data export, deletion, anonymization, retention, and recovery contract | Program start blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.6.3-EXPORT, CUS-PRD-4.6.3-DELETE, AG-R040, AD-15, AD-16, NFR-DPDPA | The data map, export contents and delivery, deletion state machine, retention schedule, erasure SLA, retained legal and audit evidence, dependency failures, retry ownership, and exception handling are unspecified. | The DPO and Legal approve the data map and retention schedule, and Data Operations approves executable export and irreversible erasure state machines with verification, SLA, recovery, exception ownership, and customer communications. | DPO, Legal, Data Architecture, and Data Operations | Build queued export and erasure orchestration behind feature flags; disable irreversible production purge until legal approval. |
| VR-BLK-030 | Security & Privacy | Encryption, residency, masking, tenancy, and third-party data boundaries | Program start blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-6.2, AG-R011, AG-R040, NFR-PRIVACY, NFR-SEC | Encryption standards, residency region, field-by-role masking across UI, export, logs and messages, financial-data sharing boundaries, transport baseline, and explicit agency tenant-isolation requirements are not approved. | Security and Privacy approve a measurable control baseline and field-by-role data-access matrix covering storage, transit, UI, APIs, exports, logs, notifications, tenancy, and third-party disclosures. | Security Architect and DPO | Use least privilege, tenant-scoped authorization, encryption, masked logs, and synthetic data by default; do not load production PII. |
| VR-BLK-031 | Audit & Operations | Atomic, durable, and recoverable audit contract | Program start blocker | Critical | Superadmin, Cross-App E2E | NFR-AUDIT, AD-15, AD-16, AD-19, AD-45, AD-52 | The event schema, time and correlation standard, previous and new state capture, masking, retention, export, transactional persistence, fail-closed behavior, and audit recovery runbook are not defined. | Architecture, Security, and Compliance approve an atomic audit design and event contract that prevents an unaudited successful write and supports investigation and recovery. | Platform Architect, Security, and Compliance | Implement a transactional audit or outbox boundary before enabling mutable administrative operations. |
| VR-BLK-032 | Architecture & Shared Data | Shared-application ownership, identity linking, drafts, offline behavior, and concurrent updates | Program start blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-5.2, CUS-PRD-4.6.1-7, CUS-PRD-4.13-LINK, CUS-UI-RECOVERY, AG-R013, AG-R019, AG-R046 | Field ownership, verified-identity matching precedence, collision review, blank-field behavior when edits are disabled, optimistic locking or merge rules, draft retention, offline persistence, and cross-channel synchronization SLA are unresolved. | Product and Data Architecture approve one shared-record ownership and concurrency matrix, including identity collision, review, merge, version, draft, offline, and synchronization rules. | Product Owner and Data Architect | Use one versioned aggregate, reject stale writes, and route identity collisions to manual review instead of automatically linking. |
| VR-BLK-033 | Authorization & Tenancy | Authoritative RBAC, agency tenancy, sensitive permissions, and role presets | Program start blocker | Critical | Agency, Superadmin, Cross-App E2E | AG-R011, AG-R035, AG-R036, AG-UI-013, AD-18, NFR-PRIVACY | The final capability list, default sub-user template, preset-to-permission mapping, application-detail access, sensitive export, branding, billing, promo, and direct-object authorization rules are incomplete. | Security and Product approve a server-enforced role, permission, tenancy, object-scope, masking, and export-access matrix for every administrative and agency role. | Security, Product, and Agency Operations | Deny by default, enforce tenant scope server-side, and omit mock role presets until their permissions are approved. |
| VR-BLK-001 | External Integration | Razorpay payment gateway provider/account/configuration binding | Core feature blocker | Critical | Customer App, Agency, Superadmin, Shared Backend | CUS-EXT-RAZORPAY, AG-R030, AG-R031, AD-50, AD-52, AD-53, EXT-RAZORPAY | ['Sandbox, UAT, and production account mapping', 'Signed webhook and callback configuration', 'Payment, refund, settlement, fee, tax, and invoice rules', 'Idempotency, retry, and reconciliation operating contract'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve environment accounts, signed webhook contract, complete payment and refund state machines, idempotency keys, entitlement treatment, taxes, accounting documents, settlements, and operational ownership. | Finance, Product, Backend, DevOps | Build a provider-neutral payment adapter and deterministic payment/webhook simulator without using real funds or credentials. |
| VR-BLK-003 | External Integration | OCR and document intelligence provider/account/configuration binding | Core feature blocker | Critical | Customer App, Agency, Superadmin, Shared Backend | CUS-EXT-OCR, CUS-PRD-4.7-OCR, AG-R021, AG-R024, AD-32, EXT-OCR | ['Provider and environment accounts', 'Supported document/layout catalogue and field map', 'Confidence thresholds and customer/reviewer correction rules', 'Retry, manual review, permanent-failure, retention, and audit contract'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider, extraction schema, supported documents, confidence thresholds, review and correction authority, retry limits, permanent-failure fallback, retention, and traceability requirements. | Product, Data or AI Lead, Compliance, Backend | Define a versioned OCR interface and use synthetic fixture responses plus a manual-review queue. |
| VR-BLK-004 | External Integration | SMS and OTP service provider/account/configuration binding | Core feature blocker | Critical | Customer App, Agency, Superadmin, Shared Identity | CUS-PRD-4.3-OTP, AG-R002, AG-R007, AD-48, AD-49, EXT-SMS-OTP, NFR-SEC | ['Provider and environment sender configuration', 'OTP validity, resend interval, attempt reset, cooldown, and rate limits', 'Template, delivery-state, retry, and outage fallback rules', 'Security monitoring and abuse controls'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider, environment setup, OTP state machine, validity, resend and attempt policy, throttling, templates, observable delivery states, fallback, and abuse-response ownership. | Identity, Security, Product, Backend | Use a fake OTP service limited to synthetic local and UAT identities, with configurable expiry and failure fixtures. |
| VR-BLK-008 | External Integration | Cloud object storage provider/account/configuration binding | Core feature blocker | Critical | Customer App, Agency, Superadmin, Shared Backend | CUS-EXT-STORAGE, CUS-PRD-4.14-UPLOAD, CUS-PRD-6.2, AG-R048, AD-65, EXT-STORAGE | ['Provider, region, environments, buckets, and tenancy layout', 'Encryption and key-management design', 'Malware scanning, content validation, and access controls', 'Signed-link lifetime, retention, deletion propagation, backup, restore, and retry policy'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider and region, bucket and ownership model, encryption and KMS, malware controls, file policy, signed links, retention and erasure, backup and recovery targets, and retry behavior. | Platform, Security, Privacy, Backend | Use a storage abstraction backed by an isolated local or UAT object store with synthetic files only. |
| VR-BLK-010 | External Integration | GST and PAN validation provider/account/configuration binding | Core feature blocker | Critical | Agency, Superadmin, Shared Backend | CUS-EXT-GSTPAN, AG-R003, AD-07, EXT-GST-PAN | ['Authoritative decision between format/checksum and live verification', 'Provider and environment configuration if live verification is required', 'Timeout, outage, retry, manual-review, and fail-open or fail-closed policy', 'Verification evidence and retention requirements'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve format/checksum-only versus live verification, the provider if applicable, validation rules, outage and manual-review behavior, evidence retention, and agency-approval dependency. | KYC, Product, Compliance, Backend | Implement a validation interface and an explicitly provisional format-only validator without claiming live verification. |
| VR-BLK-018 | Architecture & Operations | Queue, worker, scheduler, retry, idempotency, and dead-letter execution model | Core feature blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | CUS-EXT-RAZORPAY, AG-R031, EXT-EMAIL, CUS-EXT-OCR, AD-16, AD-49, AD-53, AD-70 | Evidence-backed absence: requirements explicitly require delayed and duplicate webhook handling, notification retry and dead-letter ownership, OCR retry, an erasure worker, effective-time publication, and scheduled maintenance, but no queue, worker, scheduler, retry table, or recovery runbook is supplied. Architectural inference: a durable event or job mechanism with correlation, idempotency, poison-message handling, replay authorization, scheduling, monitoring, and atomic state-transition rules is necessary; no specific technology is mandated. | The asynchronous architecture, job and event schemas, idempotency keys, retry and timeout limits, dead-letter ownership, scheduler and timezone behavior, replay controls, failure-state semantics, and operational recovery runbooks are approved and testable. | Platform Engineering Lead and Backend Engineering Lead | Synchronous domain logic and provider adapters can be scaffolded; reliable payment, messaging, OCR, erasure, and scheduled-state completion cannot. |
| VR-BLK-020 | Product Configuration | Versioned, approved release configuration and content seed package | Core feature blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | DRIVE-OBS-CONTENT-CONFIG-EMPTY, AD-20, AD-26, AD-32, AD-34, AD-42, AD-49, AD-62, CUS-PRD-4.15-PRICE | Evidence-backed absence: the project Drive Content and Configurations folder is empty, while the requirements need a launch-country catalogue, visa purposes, forms and ranges, document checklists, scoring weights and bands, risk rules and penalties, plan and credit packs, prices and taxes, promo rules, notification mappings and templates, support contacts, SLAs, and official URLs. Architectural inference: these values require a versioned, environment-promotable seed package with validation, effective dates, rollback, cache invalidation, migration behavior, and accountable content owners. | An approved release configuration package contains every required catalogue and rule, passes schema and cross-reference validation, identifies its source owner and effective date, can be promoted by environment, supports safe rollback, and defines treatment of in-flight and historical records. | Product Owner, Business Analyst, Configuration Owner, and Finance Owner | Generic configuration engines and placeholder fixtures can be developed; authoritative calculations, forms, prices, notifications, and release acceptance cannot. |
| VR-BLK-023 | Security & Resilience | Production data protection, storage, backup, recovery, and audit controls | Core feature blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | CUS-PRD-6.2, CUS-EXT-STORAGE, AG-R048, EXT-STORAGE, AD-58, AD-59, NFR-AUDIT, NFR-DPDPA, NFR-PRIVACY | Evidence-backed absence: encryption, residency, retention, malware scanning, signed-link lifetime, deletion propagation, audit retention and export, and fail-closed audit persistence remain unresolved, and no database, storage, backup, or recovery configuration is present. Architectural inference: the platform needs KMS-backed encryption, service and tenant authorization, backup and restore objectives, disaster recovery, object scanning and lifecycle jobs, PII masking, immutable audit storage, security testing, and an approved incident and recovery model. | The data classification and residency decision, encryption and key-management design, tenant and object access controls, storage lifecycle and malware policy, backup and tested restore targets, disaster-recovery objectives, audit-store controls, erasure propagation, security-test plan, and accountable recovery owners are approved and verified. | Security Architect, Data Platform Lead, Privacy Owner, and Operations | Non-sensitive local fixtures and interface design can proceed; production persistence, sensitive documents, tenant isolation, erasure, and audit-sensitive writes cannot be completed safely. |
| VR-BLK-026 | Audit & Operations | Structured runtime evidence, immutable audit persistence, correlation, alerting, and recovery runbooks | Core feature blocker | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | AD-58, AD-59, AD-60, AD-53, NFR-AUDIT, NFR-AVAIL, E2E-WF-19 | Evidence-backed absence: full APM and System Health are explicitly outside Lite, but requirements still mandate immutable audit, correlation, provider-delivery status, payment reconciliation, export, failure visibility, and fail-closed writes; no audit schema, log standard, telemetry destination, alert policy, retention rule, or runbook is supplied. Architectural inference: Lite still needs structured logs, correlation IDs, immutable audit persistence, critical service and job metrics, security-safe masking, alerts for money, messaging, erasure and audit failures, and operational ownership without claiming the deferred AD-60 dashboard. | The audit event schema, atomic persistence behavior, clock and correlation standard, masking and retention, authorized export, structured logging, minimum critical metrics and alerts, incident ownership, and recovery runbooks are approved and testable; AD-60 remains clearly excluded unless separately authorized. | Backend Engineering Lead, Security or Compliance, and Operations | Application features can be prototyped, but audit-sensitive writes and production operations cannot be accepted without durable evidence and recovery behavior. |
| VR-BLK-027 | Identity & Security | OTP, lockout, session, password, and restricted-account policy | Core feature blocker | Critical | Customer App, Agency, Superadmin | CUS-PRD-4.3-OTP, CUS-PRD-5.1-RESTRICT, AG-R002, AD-01, NFR-SEC | OTP validity, resend and attempt limits, cooldown and reset behavior, alternate recovery, inactivity timeout, JWT rotation or revocation, password expiry, and restricted-user remediation are not fully fixed. | Product Security approves one production authentication-policy matrix covering every customer, agency, and admin channel, including customer-facing restriction and recovery behavior. | Product Security and Identity Owner | Centralize the controls as environment configuration and keep provider adapters separate; production authentication signoff remains blocked. |
| VR-BLK-034 | Agency Operations | Agency KYC evidence, review outcomes, rejection recovery, and initial credits | Core feature blocker | Critical | Agency, Superadmin, Cross-App E2E | AG-R003, AG-R004, AG-R005, AG-UI-008, AD-07 | Mandatory onboarding evidence, GST and PAN validation policy, failure handling, More Information behavior, appeal or resubmission versus terminal rejection, initial-credit amount, credit recurrence, and default edit rights are not settled. | Agency Product, Compliance, and Finance approve the KYC checklist, validation contract, review state machine, rejection recovery policy, initial-credit amount and recurrence, and default customer-edit setting. | Agency Product Owner, KYC or Compliance, and Finance | Implement explicit review states and configurable validation; prevent automatic approval and initial-credit allocation. |
| VR-BLK-035 | Identity & Referrals | Canonical six-digit agency-code namespace, rendering, uniqueness, and lifecycle | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.13-CODE, AG-R005, AG-R047, AG-UI-002, AG-GAP-001 | Mocks contain prefixed, alphanumeric, and variable-length codes while the requirement confirms six numeric digits; namespace capacity, reserved values, collision retry, uniqueness scope, retirement, and recycling are undefined. | Product and Data Architecture approve the raw stored and displayed format, generation algorithm, capacity forecast, uniqueness boundary, collision handling, and code lifecycle. | Product Owner and Data Architect | Use an immutable internal agency identifier plus the canonical six-digit code and remove all conflicting mock examples. |
| VR-BLK-037 | Agency Operations | Suspension and permanent-blacklist effects across agency, customer, and shared cases | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | AD-10, AG-R006 | Customer read and write rights, payments, documents, reports, existing-case behavior, notification audiences, and remediation during agency suspension or blacklist are not approved. | Product, Operations, and Security approve an atomic state-impact matrix for agency users, agency codes, customer cases, financial actions, communications, reinstatement, and permanent blacklist. | Product, Operations, and Security | Freeze agency login, code use, and agency writes while preserving records; default affected customer cases to read-only pending a decision. |
| VR-BLK-039 | Document Processing | Document capture, correction authority, review, permanent failure, and version retention | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.7-OCR, CUS-PRD-4.14-UPLOAD, AG-R021, CUS-UI-RECOVERY | Requirements conflict on whether manual passport entry is permitted; low-confidence review, manual fallback, retry limits, permanent failure, correction precedence, latest versus retained versions, and safe retry behavior are undefined. | Product, Document Data, and Compliance approve the field-authority, review, correction, retry, fallback, version-retention, and no-silent-overwrite contract. | Product, Document Data SME, and Compliance | Persist original and customer-confirmed values separately and route uncertain or failed extraction to manual review. |
| VR-BLK-040 | Co-applicant Domain | Party capacity, relationships, mandatory evidence, primary-only scoring, charging, reporting, and invoicing | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.7A, CUS-PRD-4.7A-TOKEN, AG-R014, AG-R020, BUG-CUS-006 | Sources conflict on five co-applicants plus primary versus five total, one primary score and token versus one token per passport or combo reports, while relationship proofs, required fields, removal, and invoice entitlements are open. | Product, Finance, and Scoring approve one party-capacity, relationship, mandatory-field, completion, removal, score, token, price, report, and invoice-entitlement matrix. | Product, Finance, and Scoring Owner | Model party members independently but block party checkout and scoring until the entitlement matrix is signed. |
| VR-BLK-042 | Product Configuration | Versioned dynamic forms, validation ranges, and destination or user-type document checklists | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.14-CHECKLIST, AD-23, AD-26, AD-33, AD-34 | The field catalogue, ranges, dropdowns, conditional visibility, mandatory base checklist, seven user-type overlays, destination and visa variants, ordering, publication, rebuild, and in-flight migration rules are not supplied. | Visa SME and Configuration Product approve the complete field, validation, condition, checklist, ordering, mandatory, publication, version, and migration catalogue. | Visa SME and Configuration Product Owner | Build immutable versioned definitions and pin each application to the version used when it began. |
| VR-BLK-043 | Product Configuration | Effective dating, version pinning, publication atomicity, propagation, caching, and record migration | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | AG-R034, AG-R044, AD-20, AD-23, AD-24, AD-25, AD-26, AD-30, AD-33, AD-42, AD-46, AD-64, AD-70 | There is no cross-module contract for effective timezone, publication atomicity, cache invalidation, propagation SLA, record-version pinning, drafts, or treatment of in-flight applications and orders. | Platform Architecture and Product approve a uniform configuration version, effective-time, publication, propagation, cache, rollback, and in-flight migration policy. | Platform Architect and Product Owner | Version every configuration, use UTC effective timestamps, and avoid retroactive mutation of existing records. |
| VR-BLK-045 | Scoring & Risk | Authoritative Lite and Final scoring semantics, factors, bands, penalties, and customer presentation | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.13-LITE, CUS-PRD-4.16-SCORE, AG-R022, AD-27, AD-28 | The Lite factor split and thresholds are open while mocks incorrectly show numeric Lite scores; Final Others rules, redistribution, ordered score-band boundaries, penalties, party scope, and customer labels are unresolved. | Product and Scoring approve the five-factor non-numeric Lite contract and the complete seven-factor Final formula, normalization, bands, penalties, scope, reason codes, and presentation. | Product Owner and Scoring SME | Keep Lite non-numeric according to the PRD and feature-flag both scoring stages until approved configuration exists. |
| VR-BLK-046 | Scoring & Risk | Risk catalogue, FraudShield, fund-parking calculation, evidence review, waiver, appeal, and disclosure | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.14-FUND, CUS-PRD-4.20-RISK, AG-R024, AD-30, AD-31, AD-32 | Lookback, aggregation, timezone, exact thresholds, combinations, severities, penalties, proof catalogue, reviewer authority, waiver audit, appeal path, customer disclosure, and rescore trigger are unresolved. | Risk, Compliance, and Product approve a complete effective-dated trigger, formula, threshold, severity, penalty, evidence, review, waiver, appeal, disclosure, and rescore matrix. | Risk SME, Compliance, and Product Owner | Implement explainable inactive rules and a manual-review path; do not automatically hard-reject applicants using unapproved criteria. |
| VR-BLK-047 | Scoring & Risk | Score-regeneration allowance, charging, idempotency, rollback, party scope, and improvement recommendations | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-5.3-RESCORE, CUS-PRD-4.16A, AG-R023, AD-18 | Sources conflict between one free then paid regenerations and a strict two-total limit; qualifying changes, counter reset, failure rollback, party scope, pricing, recommendation catalogue, impact mapping, and detail-section access are incomplete. | Product, Finance, and Scoring approve the original, free, paid, terminal, qualifying-change, counter-reset, compensation, party, recommendation, and display contract. | Product, Finance, and Scoring Owner | Create an idempotent rescore ledger and recommendation framework, but do not charge during development. |
| VR-BLK-048 | Commercial & Finance | B2C and B2B plans, prices, taxes, credits, quotas, renewal, expiry, carry-forward, and overrides | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.6.8, CUS-PRD-4.15-PRICE, AG-R014, AG-R028, AG-R029, AG-R030, AG-R033, AG-R034, AG-UI-003, AG-UI-007, AG-UI-009, AD-09, AD-42, AD-45, AD-50 | Core ranges, appended fixed and combo INR prices, USD mocks, credit-token semantics, permitted deductions, pack values, taxes, currencies, low-credit thresholds, renewal, expiry, carry-forward, auto-recharge, plan switching, usage fields, and override proration conflict or remain inputs. | Commercial Product, Finance, and Tax approve a versioned B2C and B2B catalogue and lifecycle matrix covering price, currency, tax, quota, token, deduction, period, renewal, expiry, carry-forward, upgrade, override, and visible usage. | Commercial Product, Finance, and Tax | Build a versioned catalogue and entitlement ledger, keep auto-recharge disabled, and use non-production sandbox values. |
| VR-BLK-049 | Commercial & Finance | Payment state, refund eligibility, entitlement reversal, accounting documents, and reconciliation operations | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.15-PRICE, AG-R031, AD-50, AD-52, AD-53 | Refund eligibility, partial amounts and fees, consumed-credit treatment, entitlement reversal, invoice or credit-note and tax handling, payment purpose and state model, settlement cadence, matching keys and tolerances, mismatch owner, and closing evidence are unspecified. | Finance, Accounting, and Support Operations approve the end-to-end payment, refund, entitlement, accounting-document, reconciliation, exception, ownership, and closure state machines. | Finance, Accounting, and Support Operations | Build an idempotent financial ledger and manual reconciliation queue; do not automate refunds before policy approval. |
| VR-BLK-050 | Commercial & Finance | Promo semantics, allocation, binding, use limits, expiry, failure recovery, waiver, and invoice treatment | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.15-PROMO, AG-R042, AG-R043, AG-UI-004, AD-62 | Requirements define a customer transaction fee waiver while mocks show an agency recharge bonus; waived items, agency and customer binding, caps, single or multi-use behavior, expiry timezone, allocation commit on notification failure, fallback, and invoice treatment are unresolved. | Commercial Product and Finance approve one promo semantic and complete generation, allocation, binding, distribution, redemption, cap, expiry, failure, waiver, accounting, and audit contract. | Commercial Product and Finance | Remove recharge-bonus behavior and build an inactive generic promo ledger pending approval. |
| VR-BLK-051 | Workflow & Lifecycle | Application-status transitions, authority precedence, corrections, conclusion, and review-link behavior | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.17-TIMELINE, CUS-PRD-4.17-CONCLUSION, AMEND-S-1, AG-R026, AD-19 | The full prior-to-new state matrix, agency versus Admin authority, rollback and correction rights, terminal reason and decision-document rules, notification mapping, and review-link placement, copy, target, and eligible outcomes are not specified. | Product and Operations approve one cross-app state machine with transition authority, precedence, reasons, corrections, reversals, disclosure, documents, notifications, and conclusion review-link behavior. | Product and Operations | Implement a central state machine and reject transitions outside the currently approved subset. |
| VR-BLK-056 | Reporting & Sharing | VisaMatrix sections, factor presentation, branding, watermark, QR verification, and secure sharing | Core feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.16-REPORT, CUS-PRD-4.16-SHARE, AG-R025, AG-R038, AG-UI-005, AD-65 | Final section order, factor display, reason codes, intelligence configuration, watermark and logo assets, file type and size policy, agency co-branding, passport footer, QR destination and access security, share authentication, expiry, revocation, delivery history, and mock metric counts are unresolved. | Product, Brand, and Security approve the versioned report template, assets, file policy, identity and footer rules, QR verification contract, and secure share-link lifecycle. | Product, Brand, and Security | Build a versioned non-public preview renderer and use opaque authenticated links; do not publish reports until approved. |
| VR-BLK-036 | Agency Operations | Phase-1 lead ownership, manual allocation, invitation limits, notification, and SLA behavior | Feature blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.13-ROUTE, AG-R012, AG-R016, AG-R017, AD-08, AG-UI-010, AG-UI-012 | The notification channel and audience, SLA clock, warning and return-to-pool behavior, invitation resend and abuse controls, and distinction between mock-only New Lead and Add New Client are unresolved; transfer and automatic assignment are Phase 2. | Agency Product and Sales Operations approve the Phase-1 pool, visibility, manual-allocation, invitation, notification, SLA, expiry, and recovery contract and explicitly defer Phase-2 transfer and automation. | Agency Product Owner and Sales Operations | Ship the Admin-owned unassigned pool with manual allocation; remove auto-transfer, ambiguous New Lead, and unlimited-send claims. |
| VR-BLK-052 | Admin Operations | Safe bulk agency and customer status operations | Feature blocker | Critical | Superadmin | AD-06, AD-13 | Bulk selection limits, source-to-target eligibility, preview and confirmation, atomic versus partial processing, partial-failure reporting, retry, and audit behavior are undefined. | Admin Product, Operations, and Security approve an eligibility and execution matrix for every bulk action, including validation, confirmation, atomicity, partial failure, recovery, and audit. | Admin Product, Operations, and Security | Ship audited individual actions first and leave bulk status and deactivation operations disabled. |
| VR-BLK-002 | External Integration | WhatsApp Business API provider/account/configuration binding | Feature blocker | High | Customer App, Agency, Superadmin, Shared Backend | CUS-EXT-WHATSAPP, CUS-PRD-4.6.9, AG-R012, AD-48, AD-49, EXT-WHATSAPP | ['Approved WABA account and sender number', 'Consent source and evidence', 'Approved templates and bot script', 'Signed referral/share-link format, expiry, replay controls, retry, and fallback'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the WABA account, sender identity, consent evidence, template catalogue, bot and support scripts, signed-link security contract, provider delivery states, retry, idempotency, and fallback behavior. | Communications, Product, Compliance, Backend | Use a mock messaging adapter that records intended payloads and delivery states without sending external messages. |
| VR-BLK-005 | External Integration | Transactional email provider/account/configuration binding | Feature blocker | High | Customer App, Agency, Superadmin, Shared Backend | CUS-EXT-OTP-EMAIL-PUSH, AG-R049, AD-47, AD-48, AD-49, EXT-EMAIL | ['Provider and environment account mapping', 'Verified sender domains and identities', 'Approved templates, subjects, and merge fields', 'Delivery SLA, bounce/suppression, retry, fallback, and dead-letter ownership'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve the provider, verified domain and sender identities, template and merge-field catalogue, delivery states and SLA, idempotency, retry, suppression, fallback, and dead-letter runbook. | Communications, Product, DevOps, Backend | Use a local mail-capture adapter with deterministic success, bounce, delay, and duplicate-event fixtures. |
| VR-BLK-006 | External Integration | Google OAuth provider/account/configuration binding | Feature blocker | High | Customer App, Shared Identity | CUS-PRD-4.3-AUTH, CUS-PRD-4.13-LINK, EXT-OOS-001 | ['OAuth clients for each environment and platform', 'Authorized origins and redirect URIs', 'Consent-screen ownership and publication status', 'Identity-linking, collision, account-recovery, and revocation policy'] Credential audit: No exact match in Master registry; availability unconfirmed | Supply approved environment clients and redirect URIs, publish the consent configuration, and approve linking precedence, collision review, account recovery, revocation, and audit behavior. | Identity, Security, Product, DevOps | Use a mock OIDC provider behind a provider-neutral identity adapter and synthetic identities. |
| VR-BLK-007 | External Integration | Push notifications through FCM and APNs provider/account/configuration binding | Feature blocker | High | Customer App, Superadmin, Shared Backend | CUS-EXT-OTP-EMAIL-PUSH, CUS-PRD-4.6.2, AD-48, AD-49, EXT-PUSH | ['Provider projects, app identifiers, and environment mapping', 'Signing-key and service-identity ownership', 'Device-token registration and retirement policy', 'Authorized deep-link, delivery-state, retry, and fallback contract'] Credential audit: No exact match in Master registry; availability unconfirmed | Approve provider projects and application identifiers, secure key custody, token lifecycle, preference enforcement, authorized deep links, observable delivery states, retry, and fallback. | Mobile Lead, Notifications Owner, Security, Backend | Implement an in-app notification inbox and a no-send push adapter using synthetic device tokens. |
| VR-BLK-054 | Support Operations | Phase-1 support scope, ticket operating model, contacts, SLAs, premium claims, and analytics | Feature blocker | High | Customer App, Agency | CUS-PRD-4.6.9, AG-R041, AG-UI-006, AG-UI-011 | Customer requirements specify WhatsApp-only Phase-1 support while a mock exposes AI chat and FAQ; agency ticket categories, priority SLAs, contacts, help content, premium support, account-manager actions, and regional-analytics sources are not approved. | Support Operations and Product approve the Phase-1 channels, ticket categories and states, priorities, SLA matrix, contacts, help content, entitlements, data sources, and customer-facing claims. | Support Operations and Product Owner | Remove AI, FAQ, unsupported SLA, premium-support, account-manager, and regional-trend claims and show only approved contacts. |
| VR-BLK-038 | Customer Data Rules | Passport boundaries, guardian handling, applicant terminology, booking states, and identity validation | Partial development blocker | Critical | Customer App | CUS-PRD-4.7-VALID, CUS-PRD-4.8-TRIP, CUS-PRD-4.9-BASE, CUS-PRD-4.9-TYPES, BUG-CUS-002, BUG-CUS-003, BUG-CUS-004, BUG-CUS-007 | The exact six-month passport boundary, country overrides, guardian path, user-type terminology and configured values, booking statuses, name and mobile validation policy, trip-step labeling, and scan-tip copy are not fully settled. | Customer Product, Visa SME, and UX approve a field, validation, boundary, terminology, conditional-routing, guardian, booking-status, and customer-copy matrix. | Customer Product Owner, Visa SME, and UX | Keep validations and value sets configurable, use PRD terminology, and avoid hard-coding disputed country and date boundaries. |
| VR-BLK-044 | Scoring & Risk | Financial ranges, country benchmarks, operators, tiers, bands, boosters, and funds modifiers | Partial development blocker | Critical | Customer App, Agency, Superadmin | CUS-PRD-4.10, AD-24, AD-25, AD-39 | Release financial ranges, destination benchmarks, supported operators and value types, overlap precedence, country tiers, experience and salary bands, boosters, and the approximate funds modifier are not final. | Scoring and Visa or Finance SMEs approve one complete effective-dated parameter, type, operator, value, scope, and precedence matrix with reproducible examples. | Scoring SME and Visa or Finance SME | Build the rule schema and simulator, but keep unapproved values inactive. |
| VR-BLK-053 | Communications | Notification events, recipients, preferences, essential overrides, templates, and delivery lifecycle | Partial development blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.6.2, AG-R039, AD-46, AD-47, AD-48, AD-49 | The business-event and category catalogue, recipients, role visibility, essential preference overrides, channel defaults, master-toggle exceptions, template and merge-field ownership, consent source, publication, retention, delivery states, retry, idempotency, and dead-letter ownership are incomplete. | Product Communications, Legal, and Operations approve the event, audience, preference, consent, channel, template, publication, delivery, retry, retention, and ownership matrices. | Product Communications, Legal or Consent, and Operations | Build an event outbox and draft template framework, but suppress unapproved production communications. |
| VR-BLK-016 | Environment & Infrastructure | Development, test, UAT, and production topology with approved URLs and routing contracts | Partial development blocker | High | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Login Web, Shared Backend/API | AG-R008, CUS-PRD-4.16-SHARE, CUS-PRD-4.17-EMBASSY, CUS-EXT-RAZORPAY, AD-70 | Evidence-backed absence: requirements depend on a shared login URL, cross-app handoffs, report and notification deep links, embassy links, provider callbacks, and API behavior during maintenance, but no environment URL matrix or routing document is supplied. Architectural inference: each environment needs approved web and API base URLs, DNS and TLS ownership, provider callback and OAuth redirect URLs, mobile app links, CORS and CSP policy, session-cookie scope, and ingress or API-gateway routing. | An approved environment matrix defines every public and internal base URL, DNS owner, TLS lifecycle, API origin, login and deep-link route, callback and redirect URI, cookie boundary, CORS and CSP rule, and environment promotion boundary. | Platform Engineering Lead and Solution Architect | Local UI and domain logic can use placeholders; authentication handoff, provider registration, deep links, integrated testing, and deployment remain blocked. |
| VR-BLK-019 | Security & Secrets | Environment-scoped secret delivery, non-secret configuration, rotation, and ownership | Partial development blocker | High | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | CUS-EXT-RAZORPAY, CUS-EXT-WHATSAPP, CUS-EXT-OCR, CUS-EXT-OTP-EMAIL-PUSH, CUS-EXT-STORAGE, SRC-SA-EXT | Evidence-backed absence: external-provider credentials and configuration are repeatedly identified as client inputs, while no environment mapping or runtime configuration template is present in the workspace. Architectural inference: credential availability by itself is insufficient; separate sandbox, UAT, and production accounts, a secret-manager delivery model, least-privilege service identities, non-secret configuration schemas, rotation and revocation procedures, and accountable owners are required. No credential values are included in this record. | Every required integration has an approved provider and environment account, a documented non-secret configuration schema, a secret-manager reference and runtime injection path, least-privilege access, rotation and revocation ownership, and a safe local or mocked fallback. | Security Lead, Platform Engineering, and Integration Owners | Adapters and mocks can proceed without secrets; live sandbox, UAT, and production connectivity cannot. |
| VR-BLK-022 | Content & Assets | Production branding assets, report template, PDF rendering, watermark, and QR verification contract | Partial development blocker | High | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal | BUG-CUS-001, CUS-PRD-4.16-REPORT, CUS-PRD-4.16-SHARE, CUS-PRD-4.16-FOOTER, AD-65, AMEND-S-1, DRIVE-OBS-CONTENT-CONFIG-EMPTY | Evidence-backed absence: requirements need approved launcher and splash branding, VisaReady and agency logos, an every-page watermark, ordered report sections, passport footer, report ID and QR, secure sharing, and the Conclusion review link, but no production asset pack or approved report template exists in the empty Content and Configurations folder. Architectural inference: implementation also needs an approved PDF renderer or service, font and asset licensing, template versioning, QR verification route, link authentication and expiry or revocation, and deterministic rendering tests. | Approved source assets and usage rules, file constraints, launcher and splash package, report schema and ordered template, watermark and co-branding specification, PDF rendering approach, QR destination and security contract, secure-link lifecycle, and deterministic reference outputs are supplied. | Product Design or Brand Owner, Reporting Engineering Lead, and Security | Layout scaffolding, generic PDF generation, and asset slots can proceed; production identity, report acceptance, and secure verification cannot. |
| VR-BLK-057 | UX & Design | Canonical mocks, product naming, complete customer flows, and mobile or web parity | Partial development blocker | High | Customer App, Agency | CUS-PRD-4.2, CUS-PRD-4.5, CUS-PRD-4.8-TRIP, CUS-PRD-4.11, CUS-PRD-4.13-LITE, CUS-PRD-4.19, CUS-PRD-4-SCOPE, CUS-UI-INCOMPLETE-001, AG-UI-001, AG-R047, BUG-CUS-001 | Home, onboarding, trip, Travel History, Lite score, Library, product and agency naming, code rendering, APK identity, and one incomplete Stitch item have conflicting variants; only mobile Customer mocks exist despite required web parity. | Product, UX, and Brand approve one canonical mock per flow, VisaReady naming and branding tokens, the incomplete-item disposition, and responsive customer-web parity criteria. | Product, UX, and Brand | Apply PRD precedence, remove conflicting variants and mock-only branding, and avoid pixel-final work until the UX baseline is signed. |
| VR-BLK-041 | Product Configuration | Launch-country, city, Schengen, visa-purpose, metadata, and official-link catalogue | Pre-UAT blocker | Critical | Customer App, Agency, Superadmin, Cross-App E2E | CUS-PRD-4.8-COUNTRY, CUS-PRD-4.8-VISA, CUS-PRD-4.17-EMBASSY, AD-20, AD-21 | Launch countries, cities, ordering, Schengen rules, visa purposes, mandatory metadata, official URL inventory, content ownership, URL-health policy, and catalogue approval are missing or conflicting. | Visa and Content owners approve the complete launch catalogue, ordering, purpose matrix, Schengen treatment, metadata, active states, official URLs, ownership, review, and health-check policy. | Visa SME and Content or Product Owner | Build draft and active catalogue management and expose only approved active records. |
| VR-BLK-009 | External Integration | Official embassy and VFS URLs provider/account/configuration binding | Pre-UAT blocker | High | Customer App, Superadmin | CUS-PRD-4.17-EMBASSY, AD-20, EXT-EMBASSY | ['Approved launch-country URL catalogue', 'Official-domain and content ownership', 'URL validation and review cadence', 'In-app browser controls, allowlisting, and external-failure fallback'] Credential audit: No exact match in Master registry; availability unconfirmed | Provide and approve the launch-country official-domain catalogue, owner, review and health-check cadence, allowlisting and navigation policy, and safe fallback content. | Product, Visa Content Operations, Compliance | Build a disabled, configuration-driven link component using non-production allowlisted fixtures. |
| VR-BLK-012 | External Integration | Approved external review link at qr.link provider/account/configuration binding | Pre-UAT blocker | High | Customer App | AMEND-S-1, CUS-PRD-4.17-CONCLUSION, AD-65 | ['Business owner and availability commitment', 'Exact placement and display copy', 'Eligible granted or rejected Conclusion outcomes', 'Browser or deep-link behavior, security allowlisting, analytics, and fallback'] Credential audit: No exact match in Master registry; availability unconfirmed | Confirm the URL owner and availability, exact placement and copy, eligible outcomes, navigation behavior, security allowlisting, tracking expectations, and safe fallback. | Product, Content Owner, Customer App Lead | Implement a feature-flagged configurable link component that remains hidden until the content and navigation contract is approved. |
| VR-BLK-024 | Testing & UAT | Isolated, resettable UAT environment with seeded identities, provider sandboxes, and controlled-failure capability | Pre-UAT blocker | High | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | E2E-WF-05, E2E-WF-06, E2E-WF-14, E2E-WF-15, E2E-WF-16, E2E-WF-19, WORKSPACE-OBS-NO-UAT-ENVIRONMENT | Evidence-backed absence: no deployed UAT URLs, seeded role accounts, synthetic customer and agency identities, test documents, provider sandbox mapping, reset procedure, or fault controls are supplied. The designed E2E cases explicitly require delayed and duplicate webhooks, provider outages and recovery, OCR and storage timeouts, authorization-negative paths, and audit-store failure. Architectural inference: safe execution requires an isolated environment, test-data factory, reset and cleanup controls, observability, provider simulators or sandbox controls, and a rule prohibiting production identities and probing. | All application and API UAT endpoints are deployed; approved synthetic role accounts, agencies, customers, plans, configurations, files, and provider sandboxes are seeded; repeatable reset and cleanup are documented; controlled failure and replay are safe and observable; and execution access is granted to the UAT team. | UAT Lead, QA Environment Manager, Platform Engineering, and Integration Owners | Test-case review, automation planning, synthetic-data design, and simulator development can proceed; execution and acceptance cannot. |
| VR-BLK-059 | Non-functional Acceptance | Performance dataset and load profile plus supported browser, OS, device, and network matrix | Pre-UAT blocker | High | Superadmin | NFR-PERF, NFR-RESP | The three-second and 50-row targets lack dataset size, concurrency, geography, network profile, percentile, and controlled environment; desktop and tablet widths are stated but browser and OS support are not. | QA Performance, Product, and Platform approve the test environment, data volume, concurrency, geography, network, percentile, measurement method, and supported browser, OS, and device matrix. | QA Performance, Product, and Platform | Create a controlled performance environment; treat provisional development measurements as diagnostic rather than acceptance evidence. |
| VR-BLK-060 | Testing & UAT | Cross-app UAT environment, synthetic seed data, deterministic controls, observability, and recovery tooling | Pre-UAT blocker | High | Customer App, Agency, Superadmin, Cross-App E2E | NFR-PERF, NFR-AUDIT, AD-53, AD-70, CUS-UI-RECOVERY | No approved UAT package is evidenced for role and tenant accounts, lifecycle states, versioned configurations, safe passports and bank data, payment and promo states, deterministic time, job and queue control, failure injection, reset and reconciliation, audit access, log correlation, or notification sinks. | QA or UAT, DevOps, and Operations provide a documented isolated environment, synthetic fixture catalogue, role and tenant accounts, deterministic controls, reset and recovery tooling, observability, and execution runbook for all 19 E2E workflows. | QA or UAT Lead, DevOps, and Operations | Develop reusable synthetic fixtures and reset tools alongside features; never use live credentials or production PII. |
| VR-BLK-021 | Legal & Privacy | Approved legal documents, consent lifecycle, retention schedule, and erasure policy | Pre-release dependency | Critical | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | CUS-PRD-4.4, CUS-PRD-4.6.3-DELETE, AD-15, AD-16, AD-64, NFR-DPDPA | Evidence-backed absence: final Terms, Privacy Policy, Disclaimer, effective timezone, re-consent behavior, decline or defer experience, retention categories, erasure scope, evidence retention, and deletion SLA are unresolved and no legal content package exists in the empty Content and Configurations folder. Architectural inference: the implementation needs versioned legal content, durable consent evidence, session gating, a category-level erase, anonymize, retain, or unlink map, and legally reviewed operational ownership. | Legal and Privacy approve final versioned copy, effective time, re-consent and decline behavior, consent evidence fields and retention, the complete data-retention and erasure matrix, deletion SLA, exceptions, customer communication, and accountable operators. | Legal Counsel, Data Protection or Privacy Owner, and Product Owner | Versioned content and consent frameworks can be built with placeholders; production publication, defensible consent, and terminal erasure behavior cannot be accepted. |
| VR-BLK-028 | Legal & Privacy | Final legal content, consent evidence, and forced re-consent lifecycle | Pre-release dependency | Critical | Customer App, Superadmin, Cross-App E2E | CUS-PRD-4.4, AD-64, NFR-DPDPA | Final Terms, Privacy Policy, and Disclaimer conflict with wording that calls the copy confirmed while also listing it as outstanding; effective timing, decline or defer behavior, re-consent, and evidence retention remain unresolved. | Legal and the DPO sign off the final versioned documents, effective timezone, publication and re-consent rules, decline or defer behavior, and durable consent evidence. | Legal, DPO, and Product Owner | Build versioned draft, preview, publish, and consent-log mechanics, but do not publish placeholder legal content. |
| VR-BLK-058 | Platform Operations | Maintenance-mode boundary behavior and measurable platform availability | Pre-release dependency | Critical | Customer App, Agency, Superadmin, Cross-App E2E | AD-70, NFR-AVAIL, AD-60 | Maintenance timezone, active-session treatment, API and cache behavior at enable and disable boundaries, break-glass access, availability measurement window, exclusions, telemetry source, and acceptance evidence are unresolved while dedicated APM is outside Lite scope. | SRE, Platform, and Product approve the maintenance-mode access and write boundary, schedule and recovery policy, and the 99.5 percent SLI or SLO measurement and evidence contract. | SRE, Platform, and Product | Implement gateway-level write blocking with Admin break-glass and UTC scheduling; do not claim availability acceptance without approved telemetry. |
| VR-BLK-025 | Delivery & DevOps | CI/CD, artifact provenance, environment promotion, migration, deployment, and rollback capability | Pre-release dependency | High | Customer Mobile App, Customer Web App, Agency Dashboard Web, Superadmin Portal, Shared Backend/API | WORKSPACE-OBS-NO-CICD, WORKSPACE-OBS-NO-DEPLOYMENT-MANIFEST, AD-70, NFR-AVAIL | Evidence-backed absence: no CI definition, Dockerfile, infrastructure-as-code, artifact registry configuration, deployment manifest, database migration command, release versioning, or rollback instruction is visible. Architectural inference: repeatable delivery requires build, test, scan, sign, package, provenance, environment-promotion and approval stages, migration gates, deployment health checks, rollback, and release ownership. | Each deployable has a reproducible CI/CD pipeline with dependency and security checks, versioned immutable artifacts, signing where applicable, approved environment promotion, secret-safe deployment, database migration and rollback gates, health verification, release approvals, and a tested rollback procedure. | DevOps or Platform Engineering Lead and Release Manager | Local development can proceed once source is available; controlled UAT and production delivery cannot. |
| VR-BLK-055 | Content & Assets | Knowledge library, country guidance, cover letters, itineraries, editorial ownership, and publication governance | Pre-release dependency | High | Customer App, Agency, Superadmin | CUS-PRD-4.19, CUS-PRD-4.17-EMBASSY, AD-33, AD-41, AD-63 | Library versus Knowledge Base naming and navigation, launch inventory and ordering, country guidance, official links, editorial owner and review cadence, UK, Canada, Australia, and Schengen cover-letter or itinerary copy, merge fields, and publication rules are missing. | Content, Visa, and Legal owners approve the label and navigation, launch inventory, country copy and links, templates, merge-field catalogue, editorial workflow, publication rules, and review cadence. | Content Owner, Visa SME, and Legal | Keep all content in draft and never expose placeholder or unpublished guidance. |
| VR-BLK-061 | Known Defects | Eight pending Customer application defects require implementation and regression evidence | Pre-release dependency | High | Customer App | BUG-CUS-001, BUG-CUS-002, BUG-CUS-003, BUG-CUS-004, BUG-CUS-005, BUG-CUS-006, BUG-CUS-007, BUG-CUS-008 | The reported Customer build still has pending issues for package or splash identity, numeric names, invalid mobile length, save confirmation, Single or Multiple selection, scan tips, and Destination Save and Continue behavior. | Customer Engineering provides a signed target build and QA verifies all eight fixes, including persistence, downstream routing, double-submit protection, and no regression to the related workflows. | Customer Engineering, QA, and Product | Unrelated development may continue, but the affected workflows cannot receive release signoff until the defects are fixed and retested. |
| VR-BLK-011 | External Integration | System health and APM monitoring provider/account/configuration binding | Non-blocking / out of scope | Medium | All applications, Platform Operations | AD-60, NFR-AVAIL | ['Explicit Lite exclusion and future-phase ownership', 'Availability SLI, measurement window, and exclusions', 'Future monitoring provider, alerting, and evidence policy'] Credential audit: No exact match in Master registry; availability unconfirmed | Keep AD-60 explicitly excluded from Lite and separate it from current acceptance, or approve a future provider, SLIs, measurement window, exclusions, alert ownership, and evidence method. | Product, SRE, Operations | Provide structured logs and basic critical-failure alerts without implementing or presenting the out-of-scope AD-60 dashboard. |
| VR-BLK-062 | Scope Governance | Explicit Phase-2 and future-scope features must not create active MVP behavior | Non-blocking / out of scope | High | Agency, Superadmin | AG-R050, AD-08, AD-60 | Pay-Per-Use, a public agency directory, lead transfer and automatic assignment, and dedicated APM or System Health are stated as Phase 2 or outside Lite, but some designs or calls to action can imply they are available. | Product and Program Management confirm the MVP exclusion list, remove or visibly disable unsupported actions, and create a separate approved Phase-2 baseline before implementing those behaviors. | Product Owner and Program Manager | Keep the features absent or explicitly non-operational; do not create unsupported financial, ownership, or monitoring states. |
Known implementation defects
These are known work items and release risks, not missing external dependencies. They are kept separate so they are not confused with client/architecture blockers.
| ID | Area | Issue | Status | Impact | Required outcome |
|---|---|---|---|---|---|
| BUG-CUS-001 | Launcher / branding | Logo is missing; only the APK file is shown. | Pending | Release packaging and brand acceptance remain incomplete. | Produce a signed build with the approved launcher identity, icon, splash, and version metadata. |
| BUG-CUS-002 | Edit profile | First name accepts numeric values. | Pending | Invalid identity data can enter the shared customer record. | Apply the approved name validation and error handling consistently on client and server. |
| BUG-CUS-003 | Edit profile | Last name accepts numeric values. | Pending | Invalid identity data can enter the shared customer record. | Apply the approved optional-last-name validation consistently on client and server. |
| BUG-CUS-004 | Edit profile | Mobile number accepts 13 digits. | Pending | Invalid contact and OTP identities may be stored or linked. | Apply the approved country-code/mobile-length policy with normalized storage and server validation. |
| BUG-CUS-005 | Edit profile | Successful save does not show the required confirmation. | Pending | Users cannot distinguish committed changes from failed or pending saves. | Show one accessible success notification only after durable persistence; preserve safe retry on failure. |
| BUG-CUS-006 | Passport details | Single/Multiple applicant toggle is missing. | Pending | The family/multi-applicant journey cannot be selected from the evidenced screen. | Restore the selector after the approved party-capacity and entitlement model is signed. |
| BUG-CUS-007 | Passport details | Passport scanning tips are missing. | Pending | Poor captures may increase OCR failure and manual-review volume. | Publish approved capture guidance aligned with the chosen OCR provider and supported document set. |
| BUG-CUS-008 | Destination and trip | Save and Continue is not working. | Pending | A core readiness-assessment workflow cannot progress. | Persist the step idempotently, prevent duplicate submission, advance once, and support safe retry. |
Evidence and method
- Reviewed the current primary Customer, Agency, Superadmin and External API requirement artifacts; their Drive modified timestamps predate the completed traceability baseline.
- Used the validated tcgen baseline: 326 workflow-based UAT cases, 68 workflows, 280 coverage rows, 150 functional screens, 22 asset-only items and 2 incomplete/out-of-scope UI items.
- Included all 185 traceability rows whose status is not Covered: 103 Partially Covered, 76 Needs clarification, 4 Out of Scope and 2 No testable behavior.
- Consolidated provider/account dependencies separately from provider-neutral business/policy decisions so a credential cannot be mistaken for a complete integration contract.
- Ran 52 exact, case-insensitive, trimmed `$cred` lookups against the configured read-only Master registry. Every lookup returned zero exact matches; no secret value was retrieved.
- Did not open the separate project credential workbook because it is not the configured `$cred` registry and no exact registry mapping selected it.
- Inspected the active workspace and verified that no application source/build/deployment artifacts are present and the Drive Content and Configurations folder is empty.
- Gate classifications distinguish work that prevents implementation start, blocks only an affected feature, blocks integrated UAT, blocks production release, or is explicitly outside Lite scope.
- Reasonable architectural prerequisites that are absent from the requirements are labelled as delivery/environment dependencies rather than asserted product requirements.
- Known pending Customer defects are listed separately because they are implementation work/release risks, not missing external dependencies.
Primary sources
| ID | Type | Title | Modified | Use |
|---|---|---|---|---|
| SRC-CUS-REQ | Primary requirements | VisaReady Final Doc Customer application.docx | 2026-07-13T18:56:18Z | Customer workflows, rules, client-input questions, security and commercial behavior. |
| SRC-AG-REQ | Primary requirements | VisaReady Final Doc Agency with ui.docx | 2026-07-13T18:57:46Z | Agency onboarding, shared record, wallet, roles, support and UI evidence. |
| SRC-SA-REQ | Primary requirements | VisaReady Final Doc Admin.docx | 2026-07-13T18:57:18Z | Admin configuration, governance, finance, audit, privacy and NFR requirements. |
| SRC-EXT | External integration requirements | VisaReady Final Doc External api list.docx | 2026-07-13T18:57:35Z | Authoritative list of MVP and supporting integration families and client inputs. |
| SRC-AMEND | Approved amendment | Amendment sheet | Reviewed 2026-07-18 | Adds the external review link at Customer Conclusion. |
| SRC-UAT | Traceability baseline | VisaReady Test cases | 2026-07-18T12:45:51Z | 326 UAT cases, 280 requirement/gap rows, 68 workflows and 203 evidence records. |
| SRC-UI-MAP | UI project map | Visaready UI | Reviewed 2026-07-18 | Resolves the Customer, Agency and Superadmin Stitch projects used for conflict evidence. |
| SRC-BUGS | Reported issues | CustomerApp Bugs | Reviewed 2026-07-18 | Eight pending Customer implementation defects; Agency/Admin registers are header-only. |
| SRC-CONFIG | Drive folder | Content and Configurations | Verified empty 2026-07-18 | Evidence that the required versioned business configuration release bundle has not been supplied. |
| SRC-CRED | Credential registry | Master external api sheet | Read-only exact lookup 2026-07-18 | 52 exact requirement/provider/project identifier checks; zero exact matches; no values revealed. |
| SRC-PROJECT-CRED | Metadata-only evidence | Visa ready Api Creds | 2026-07-14T17:15:02Z | Separate project workbook exists, but was not opened because it is not the configured $cred registry and no exact registry mapping was found. |
| SRC-WORKSPACE | Workspace inventory | /home/usr1/code2/visaready3 | Verified 2026-07-18 | Contains test-design artifacts only; no application source, build manifest, lockfile, deployment definition or environment template. |
Show all 185 non-Covered requirement traceability rows
| Application | Requirement / Evidence ID | Requirement / Rule | Source Evidence | Actors | Workflows | Test Case IDs | Coverage Status | Conflict / Gap / Assumption | Business Risk | Recommended Clarification |
|---|---|---|---|---|---|---|---|---|---|---|
| Customer App | CUS-PRD-4.3-OTP | OTP is four digits, resend waits 30 seconds, and attempts are limited to three. | Customer PRD §4.3 Stitch OTP screen | Customer | CUS-WF-02 | UAT-CUS-008, UAT-CUS-098 | Partially Covered | Wording 'up to three attempts, then account verification' is ambiguous about lock duration/recovery. | OTP abuse or legitimate-user lockout. | Define attempt reset, cooldown, OTP validity, and alternate-method rules. |
| Customer App | CUS-PRD-4.4 | Current Terms, Privacy Policy, and Disclaimer require full scroll plus one consent checkbox; acceptance version/time/user are logged. | Customer PRD §4.4 and appended legal copy | New User, Returning User | CUS-WF-02 | UAT-CUS-005, UAT-CUS-010, UAT-CUS-011 | Partially Covered | The document calls copy confirmed but also lists final legal copy as outstanding. | Invalid consent and DPDPA exposure. | Approve final legal versions and re-consent policy. |
| Customer App | CUS-PRD-4.5 | Home supports new/returning users, application resume, quick actions, latest readiness, required bottom navigation, and primary-only co-applicant score explanation. | Customer PRD §4.5 Stitch Home variants | Customer | CUS-WF-03 | UAT-CUS-003, UAT-CUS-012, UAT-CUS-013, UAT-CUS-044, UAT-CUS-073 | Partially Covered | Stitch variants alternately remove/restore score and quick actions and disagree on percent formatting/navigation. | Core journeys become undiscoverable or score meaning becomes misleading. | Approve one canonical Home mock aligned to the PRD. |
| Customer App | CUS-PRD-4.6.1-7 | Profile photo, contact, personal, passport, address, and travel preferences are editable/reusable without OTP reverification. | Customer PRD §4.6.1 and §4.6.4-4.6.7 | Customer | CUS-WF-04 | UAT-CUS-015, UAT-CUS-092, UAT-CUS-094 | Partially Covered | Final editable-field list is still marked client input. | Stale identity data or unintended application changes. | Approve the final editable-field matrix and propagation rules. |
| Customer App | CUS-PRD-4.6.2 | Notification categories and in-app/WhatsApp/email channels can be independently toggled with a master toggle; documented events generate messages. | Customer PRD §4.6.2 External API document: WhatsApp/email/push | Customer | CUS-WF-17 | UAT-CUS-016, UAT-CUS-085, UAT-CUS-099, UAT-CUS-102 | Partially Covered | Essential-message override rules and final templates/channel defaults are open. | Missed critical updates or unwanted communication. | Approve event/channel matrix, templates, and master-toggle exceptions. |
| Customer App | CUS-PRD-4.6.3-EXPORT | Customer can request an export of all stored data. | Customer PRD §4.6.3 Customer PRD §6.2 | Customer, Data Operations | CUS-WF-05 | UAT-CUS-018, UAT-CUS-103 | Needs clarification | Format, secure delivery, SLA, retention, and duplicate-request behavior are unspecified. | DPDPA right cannot be accepted or verified consistently. | Define export contents, format, authentication, delivery, expiry, and SLA. |
| Customer App | CUS-PRD-4.6.3-DELETE | Deletion is a reviewed admin request, not immediate; customer is notified on submission and completion. | Customer PRD §4.6.3 pf_delete External API document: deletion confirmations | Customer, Super Admin | CUS-WF-05 | UAT-CUS-019 | Needs clarification | Retention, erasure SLA, pending-account behavior, and retained audit fields are open. | Incomplete erasure or accidental account loss. | Approve deletion state machine and DPDPA retention/SLA. |
| Customer App | CUS-PRD-4.6.8 | Profile Plan shows current plan/status/validity/usage/history and supports renew, upgrade/change, and invoices. | Customer PRD §4.6.8 | Customer | CUS-WF-04, CUS-WF-12 | UAT-CUS-020, UAT-CUS-062, UAT-CUS-063, UAT-CUS-100 | Partially Covered | Final displayed status/usage fields are a client input. | Customers cannot understand entitlement or billing. | Approve plan-status field set. |
| Customer App | CUS-PRD-4.6.9 | Phase-1 support is a single WhatsApp action; in-app FAQ and other contact options are deferred. | Customer PRD §4.6.9 External API document: WhatsApp support Stitch Support Assistant and WhatsApp-only redesign | Customer | CUS-WF-04, CUS-WF-18 | UAT-CUS-021 | Partially Covered | Support Assistant mock contains AI chat and FAQ that directly conflicts with PRD; WhatsApp-only redesign aligns. | Unapproved support scope and misleading AI guidance. | Supersede/remove the AI Support Assistant mock and publish support number/message. |
| Customer App | CUS-PRD-4.7-OCR | Passport may be OCR-scanned, reviewed with confidence, corrected, or manually entered and reused downstream. | Customer PRD §4.7 External API document: passport OCR | Customer | CUS-WF-06 | UAT-CUS-023, UAT-CUS-024, UAT-CUS-025, UAT-CUS-093 | Partially Covered | §4.1 says first-run details are populated via OCR with no manual key-in, while §4.7 explicitly allows manual entry. | Customers may be blocked by OCR or inconsistent identity data. | Confirm when manual entry is permitted and authoritative. |
| Customer App | CUS-PRD-4.7-VALID | Passport format/date rules and six-month validity beyond return are enforced/advised. | Customer PRD §4.7, §4.20, §5.6 | Customer | CUS-WF-06 | UAT-CUS-026 | Partially Covered | Boundary wording alternates under six months and six months or less. | Incorrect visa-readiness risk. | Define exact date boundary and country overrides. |
| Customer App | CUS-PRD-4.7A | Multi mode supports spouse/child/parent/other forms, completion hub, removal, primary protection, seat limit, and pre-payment completion gate. | Customer PRD §4.7a Stitch Family Management | Primary Applicant, Co-Applicant | CUS-WF-08 | UAT-CUS-041, UAT-CUS-042, UAT-CUS-043, UAT-CUS-093 | Needs clarification | Maximum is described as five co-applicants plus primary but UI text/seat wording can imply five total; proof/mandatory fields are open. | Wrong party capacity or incomplete travel-party evidence. | Confirm capacity and relationship-proof/mandatory matrix. |
| Customer App | CUS-PRD-4.7A-TOKEN | Only primary is scored and co-applicant completion percentages are not VisaScores; party charging follows the approved model. | Customer PRD §4.7a, §4.15, §5.3, appended Pricing | Primary Applicant, Co-Applicant | CUS-WF-08, CUS-WF-12 | UAT-CUS-044 | Needs clarification | Core PRD says one primary score/token; companion says one token per passport; appended pricing offers combo separate scores/reports. | Material over/undercharging and wrong customer results. | Approve one primary/co-applicant scoring, token, price, and report entitlement table. |
| Customer App | CUS-PRD-4.8-COUNTRY | Configured active/popular/all destinations, multiple country selection, Schengen jurisdiction guidance, and city lists drive the trip. | Customer PRD §4.8 and appended country/Schengen input | Customer | CUS-WF-06 | UAT-CUS-027, UAT-CUS-028 | Partially Covered | Final MVP country/city lists and ordering remain configuration inputs. | Wrong jurisdiction or unavailable destinations. | Approve launch country/city lists and ordering. |
| Customer App | CUS-PRD-4.8-VISA | A mandatory visa type/purpose drives forms and documents; Work/Employment is not offered in the original version. | Customer PRD §4.8 Appended Client Input §7.2 | Customer | CUS-WF-06 | UAT-CUS-027, UAT-CUS-028 | Needs clarification | Core PRD allows Tourist/Visitor, Student, Business; appended input lists Tourism, Business, Family Visit, Student, Transit, Conference, Cruise. | Wrong workflow/checklist and pricing. | Approve MVP purposes and their destination-specific forms/checklists. |
| Customer App | CUS-PRD-4.8-TRIP | Travel dates, computed duration, destination cities, booking statuses, summary, and save controls are validated. | Customer PRD §4.8 Step 2c Stitch Travel Details screen | Customer | CUS-WF-06 | UAT-CUS-027, UAT-CUS-028 | Partially Covered | Stitch labels Travel Details as Step 5 though PRD places it in Step 2c; booking-option confirmation is open. | Incorrect sequence and score/document inputs. | Correct mock step label and approve booking statuses. |
| Customer App | CUS-PRD-4.9-TYPES | Eight user types route to their type-specific profile data and document evidence. | Customer PRD §4.9 and §4.14 | All Applicant Types | CUS-WF-07 | UAT-CUS-030, UAT-CUS-031, UAT-CUS-032, UAT-CUS-033, UAT-CUS-034 | Partially Covered | Mock uses Housewife vs PRD Homemaker; final configured value sets remain open. | Applicants see the wrong path or checklist. | Approve terminology and value sets. |
| Customer App | CUS-PRD-4.10 | Financial profile uses configured ranges with conditional FD/investment/ITR values and feeds Financial Strength. | Customer PRD §4.10, §5.3, appended financial matrix | Customer | CUS-WF-06 | UAT-CUS-036 | Partially Covered | Release range definitions remain editable/config-dependent. | Inaccurate affordability/readiness score. | Publish release range and destination benchmark configuration. |
| Customer App | CUS-PRD-4.11 | Visited countries, held/current visas, refusal, overstay, and immigration violations feed travel scoring and risk. | Customer PRD §4.11 and §5.3 | Customer | CUS-WF-06 | UAT-CUS-037, UAT-CUS-038 | Partially Covered | Three Stitch variants each omit or restore different required fields; no single canonical mock contains the full set. | Missing travel history changes the score materially. | Consolidate and approve one complete Travel History screen. |
| Customer App | CUS-PRD-4.13-CODE | Optional agency code is exactly six numeric digits, validates active agency, maps the whole application at any step, and pre-fills from referral. | Customer PRD §4.13 and appended code-capacity answer Stitch Agent ID/Referral screens | Customer, Agency User, Super Admin | CUS-WF-09 | UAT-CUS-045, UAT-CUS-046, UAT-CUS-048 | Partially Covered | Stitch uses alphanumeric examples such as 56001ZY8 and GTS-IND-4429, conflicting with confirmed numeric 100000-999999 rule. | Wrong lead ownership and referral failures. | Replace mock examples with valid six-digit numeric codes. |
| Customer App | CUS-PRD-4.13-LINK | Agent-created applications link to a later matching verified email/mobile account and remain one shared record. | Customer PRD §4.13 Account Linking and §4.17 shared record | Customer, Agency User | CUS-WF-09 | UAT-CUS-049, UAT-CUS-050, UAT-CUS-096 | Needs clarification | Identity collision and simultaneous-edit conflict resolution are unspecified. | Duplicate accounts, wrong customer linkage, or data corruption. | Define matching precedence, collision handling, field ownership, and concurrency policy. |
| Customer App | CUS-PRD-4.13-LITE | Lite uses five factors and outputs Low/Medium/High only with disclaimer; no numeric score, flags, risk levels, Document Readiness, Others, or penalties. | Customer PRD §4.13 and §5.3 Stitch Preliminary Eligibility Score | Customer | CUS-WF-10 | UAT-CUS-051, UAT-CUS-052, UAT-CUS-053 | Needs clarification | Stitch exposes numeric 72 and numeric factor scores; exact Lite thresholds are still open. | Misleading readiness claim and incorrect product entitlement. | Approve thresholds and redesign Lite mock to PRD output. |
| Customer App | CUS-PRD-5.3-RESCORE | A data change is required; the post-original regeneration allowance and charging limit are application-scoped. | Customer PRD §4.13, §4.16a, §5.3 and appended answers | Customer | CUS-WF-14 | UAT-CUS-074, UAT-CUS-075, UAT-CUS-076 | Needs clarification | Main text says one free then second onward paid; appended answer says ONLY 2 TIME/TOTAL 2 and not more. | Surprise charges or unlimited/blocked scoring. | Approve exact terminal state after the one free regeneration and counter-reset behavior. |
| Customer App | CUS-PRD-4.14-CHECKLIST | Paid checklist is derived from visa/user type with common and type-specific mandatory evidence. | Customer PRD §4.14 | Customer | CUS-WF-11 | UAT-CUS-054, UAT-CUS-060 | Partially Covered | Per-destination checklists and mandatory matrix remain Admin/client inputs. | Verified score based on wrong/missing evidence. | Approve all destination/visa/user-type checklists. |
| Customer App | CUS-PRD-4.14-FUND | Sudden deposit detection uses configured history/thresholds; valid source proof waives fund-parking penalty. | Customer PRD §4.14 and appended 45-day/50% recurring-deposit answer | Customer | CUS-WF-11 | UAT-CUS-058 | Partially Covered | Low-balance/large-credit thresholds remain open; phrase '50% of correct balance' needs normalization. | False fraud/risk penalty or missed funds parking. | Approve exact formula, time zone/date handling, recurrence, and proof validation. |
| Customer App | CUS-PRD-4.20-RISK | Customer sees advisory passport/travel/salary warnings; Final alone shows penalties and FraudShield hard flag. | Customer PRD §4.20 and §5.3 | Customer | CUS-WF-06, CUS-WF-11, CUS-WF-13 | UAT-CUS-026, UAT-CUS-038, UAT-CUS-058, UAT-CUS-059 | Partially Covered | Manual review/appeal and some risk values are unspecified. | Incorrect rejection guidance and inability to correct false positives. | Approve final risk catalogue, values, customer copy, and review path. |
| Customer App | CUS-PRD-4.15-PRICE | Customer selects Lite/Starter/Advance with configured visa/pack pricing; direct B2C is separate from agency wallet. | Customer PRD §4.15 and §5.7, appended Pricing Stitch Subscription Plans and Payment | Customer | CUS-WF-12 | UAT-CUS-062, UAT-CUS-068, UAT-CUS-100 | Needs clarification | Core ranges, appended fixed/combo INR prices, fixed-fee checkout mock, and USD annual-plan mock conflict. | Material financial and entitlement error. | Approve one B2C price/pack/entitlement catalogue and update mocks. |
| Customer App | CUS-EXT-RAZORPAY | Razorpay handles customer payment, webhook reconciliation, and refunds idempotently. | External API document: Razorpay Customer PRD §4.15 | Customer, Billing Operations | CUS-WF-12 | UAT-CUS-063, UAT-CUS-066, UAT-CUS-097 | Needs clarification | Keys/webhooks are client inputs; refund eligibility, entitlement reversal, and credit-note rules are absent. | Double charge, unreconciled money, or incorrect entitlement. | Approve payment/refund state machine, webhook idempotency, and accounting documents. |
| Customer App | CUS-PRD-4.15-PROMO | Promo must exist, be valid/unused, and match the application's agency; eligible amount is waived and invoiced. | Customer PRD §4.15 and appended promo answer | Agency-Referred Customer, Agency | CUS-WF-12 | UAT-CUS-064, UAT-CUS-065, UAT-CUS-067 | Needs clarification | Waiver scope and single/multi-use allocation are not consistently defined. | Promo abuse or incorrect revenue. | Define waived line items, code lifecycle, limits, and delivery template. |
| Customer App | CUS-PRD-4.16-SCORE | Final score uses seven weighted factors minus penalties, clamped 0-100 with configured bands and primary-applicant scope. | Customer PRD §4.16 and §5.3 | Customer | CUS-WF-13 | UAT-CUS-069 | Needs clarification | Others 5% subrules are undefined; band text overlaps below 58/below 40; party scoring conflicts elsewhere. | Nonreproducible or misleading score. | Approve Others rules, ordered band boundaries, penalty values, and party scope. |
| Customer App | CUS-PRD-4.16-REPORT | Advance VisaMatrix contains required intelligence/recommendation sections, is non-guaranteeing, branded, watermarked, and verifiable by ID/QR. | Customer PRD §4.16, §5.4-5.5 | Customer | CUS-WF-13 | UAT-CUS-068, UAT-CUS-070, UAT-CUS-101 | Partially Covered | Template order, intelligence config, watermark asset, and some mock metric counts are unresolved. | Wrong entitlement, unverifiable report, or unapproved claims. | Approve template, seven-factor display, reason codes, and branding assets. |
| Customer App | CUS-PRD-4.16-SHARE | VisaMatrix supports WhatsApp, email, copy link, and PDF with consistent identity and secure storage/delivery. | Customer PRD §4.16 and §4.18 External API document: WhatsApp/email/storage | Customer | CUS-WF-13 | UAT-CUS-071, UAT-CUS-072 | Needs clarification | Share-link authentication, expiry, revocation, and delivery history are unspecified; 30 days exists only in mock. | Report leakage or failed delivery. | Approve link access/expiry/revocation and channel templates. |
| Customer App | CUS-PRD-4.16A | Score Improvement is application-scoped, impact-ordered, non-guaranteeing, change-gated, and linked to relevant actions. | Customer PRD §4.16a | Returning User | CUS-WF-14 | UAT-CUS-073, UAT-CUS-074, UAT-CUS-076 | Partially Covered | Recommendation catalogue, impact mapping, target copy, and fully-optimized empty state are open. | Misleading uplift or changes applied to wrong application. | Approve recommendation/impact catalogue and target copy. |
| Customer App | CUS-PRD-4.17-TIMELINE | System/agency stages produce ordered completed/current/pending timeline states, details, documents, and notifications. | Customer PRD §4.17 timeline Stitch tracking/status screens | Customer, Agency User | CUS-WF-15 | UAT-CUS-078, UAT-CUS-080, UAT-CUS-081, UAT-CUS-102 | Partially Covered | Complete allowed-transition/rollback matrix and status authority are not fully specified. | Customer sees false case progress. | Approve status transition/authority matrix and correction policy. |
| Customer App | CUS-PRD-4.17-CONCLUSION | Self-applied users record Yes/No receipt; agency applications show agency Accepted/Rejected plus decision document. | Customer PRD §4.17 Conclusion | Self-Applied Customer, Agency-Referred Customer, Agency User | CUS-WF-15 | UAT-CUS-079, UAT-CUS-080 | Partially Covered | Edit/reversal behavior and reason constraints are unspecified. | Incorrect terminal outcome. | Define conclusion correction/reversal permissions. |
| Customer App | AMEND-S-1 | Phase-1 Conclusion includes review link https://qr.link/9bpJ5L. | Amendment sheet Sheet1 row 3, s-1, 15/07/26 | Customer | CUS-WF-15 | UAT-CUS-082 | Needs clarification | Display copy, target behavior, and applicability to rejected customers are not stated. | Approved amendment may be omitted or shown inappropriately. | Confirm exact placement/copy and eligible conclusion outcomes. |
| Customer App | CUS-PRD-4.17-EMBASSY | Submitted application opens the configured official embassy/VFS URL in an in-app browser. | Customer PRD §4.17 External API document embassy URLs | Customer | CUS-WF-15 | UAT-CUS-081 | Needs clarification | Per-country official URLs are a client input. | Customer is sent to wrong or unsafe tracking site. | Provide and approve launch-country URL catalogue. |
| Customer App | CUS-PRD-4.19 | Bottom navigation includes Library/Knowledge Base with published per-country guidance and safe unpublished state. | Customer PRD §4.19 and appended Library answer Stitch Visa Library and Home variants | Customer | CUS-WF-16 | UAT-CUS-084 | Needs clarification | PRD names Library and fixed five-item nav; client suggests Knowledge Base/alternate placement; mocks inconsistently omit it. | Important guidance is undiscoverable or draft content leaks. | Approve final label, nav position, country list, and content ownership. |
| Customer App | CUS-PRD-6.2 | Personal/financial data is encrypted, financial data is not shared with third parties, document integrity is checked, and data-residency/DPDPA rules apply. | Customer PRD §6.2 | Customer, Operations | CUS-WF-05, CUS-WF-20 | UAT-CUS-003, UAT-CUS-014, UAT-CUS-018, UAT-CUS-019, UAT-CUS-050, UAT-CUS-076, UAT-CUS-083, UAT-CUS-096, UAT-CUS-101, UAT-CUS-103, UAT-CUS-104 | Needs clarification | Encryption standards, residency region, retention, third-party boundaries, and audit acceptance evidence are not specified. | Severe privacy/compliance exposure. | Approve measurable security, residency, retention, and audit controls for UAT/security acceptance. |
| Customer App | CUS-EXT-WHATSAPP | WhatsApp Business API supports referral/bot, status notifications, customer support, and report sharing with recoverable failures. | External API document: WhatsApp Business API Customer PRD §3, §4.6.9, §4.16 | Customer, Agency User | CUS-WF-09, CUS-WF-17, CUS-WF-18 | UAT-CUS-021, UAT-CUS-045, UAT-CUS-071, UAT-CUS-089, UAT-CUS-090, UAT-CUS-099 | Needs clarification | Credentials, templates, bot script, and signed-link format are client inputs. | Attribution loss, failed communication, or unapproved messaging. | Provide approved WABA account, templates, bot script, and referral-link security contract. |
| Customer App | CUS-EXT-OTP-EMAIL-PUSH | OTP/email/push services deliver authentication and business events according to identity and preferences with retry/deduplication. | External API document: SMS/OTP, transactional email, FCM/APNs | Customer | CUS-WF-02, CUS-WF-17 | UAT-CUS-005, UAT-CUS-006, UAT-CUS-008, UAT-CUS-016, UAT-CUS-095, UAT-CUS-098, UAT-CUS-099 | Needs clarification | Providers, templates, retry/dead-letter behavior, and essential-event overrides are not specified. | Failed login or missed critical events. | Approve provider/configuration and event-delivery contract. |
| Customer App | CUS-EXT-STORAGE | Cloud storage persists owned uploads/reports securely and supports retry without duplication. | External API document: cloud storage Customer PRD §4.14 and §4.16 | Customer | CUS-WF-11, CUS-WF-13 | UAT-CUS-055, UAT-CUS-057, UAT-CUS-061, UAT-CUS-070, UAT-CUS-072, UAT-CUS-103 | Needs clarification | Storage provider, encryption, URL expiry, malware handling, retention, and deletion propagation are unspecified. | Sensitive document leakage or loss. | Approve storage security/lifecycle and signed-link requirements. |
| Customer App | CUS-EXT-OCR | Passport, bank-statement, and supporting-document OCR extracts usable structured data, exposes low-confidence or failed extraction for review, and never silently overwrites customer-confirmed values. | External API document: passport, bank-statement, and fund-parking OCR Customer PRD §4.7, §4.14, and §4.20 | Customer, OCR/Document Intelligence Service | CUS-WF-06, CUS-WF-11 | UAT-CUS-024, UAT-CUS-025, UAT-CUS-057, UAT-CUS-058, UAT-CUS-059, UAT-CUS-061 | Needs clarification | Provider, confidence thresholds, supported statement layouts, review routing, and extraction-failure behavior are not specified. | Incorrect identity, financial evidence, or fraud-risk outcomes may be accepted without customer visibility. | Approve OCR provider, field map, confidence thresholds, review controls, supported documents, and failure contract. |
| Customer App | CUS-UI-INCOMPLETE-001 | Stitch source item 3e93ad3ac3bd4fcb84a4eee1d183e8b8 must be finalized or identified as obsolete. | Stitch project 3025077632249781985 / screen 3e93ad3ac3bd4fcb84a4eee1d183e8b8 titled Generating Screen... | Needs clarification | No finalized title, prompt, HTML, or usable behavior exists. | A missing intended UI flow could remain untested. | Finalize the item with a named requirement/flow or remove it as obsolete. | |||
| Customer App | CUS-UI-ASSETS | Twenty standalone images/SVG/uploaded screenshots are visual assets, not independently testable functional screens. | Stitch project 3025077632249781985: 20 asset-only items inventoried in screens[] | No testable behavior | Their owning UI behavior is covered through functional screens where relevant. | Assets could be double-counted as screens and inflate false coverage. | ||||
| Customer App | CUS-SRC-002-NOTE | The Customer UI DOCX is reference-only and does not override the requirements document. | VisaReady Customer ui.docx: 'These are just ui reference screen will be according to doc' | No testable behavior | Mock conflicts are therefore recorded against PRD precedence. | Outdated mock behavior could be accepted as a requirement. | ||||
| Agency | AG-R003 | GST/PAN and onboarding evidence are validated using the client-approved mandatory-document and verification rules. | AG-PRD Screen 1 client-input note AG-PRD Section 9.1 EXT-API GST/PAN note | Prospective Agency Admin, Super Admin Reviewer | AG-WF-01 | UAT-AGREG-002 | Needs clarification | Mandatory document list and format/checksum/live verification choice are unset. | Fraudulent or valid agencies may be incorrectly accepted or rejected. | Approve mandatory documents and whether GSTIN/PAN use format-only or live registry verification. |
| Agency | AG-R005 | Approval issues one unique read-only 6-digit agency code and initial credits; the active code maps customers to the agency. | AG-PRD Screens 1-2 reg_code/apr_grant AG-PRD Sections 2.3 and 5.1 | Super Admin, Agency Admin, Customer | AG-WF-01, AG-WF-05 | UAT-AGREG-006, UAT-AGLEAD-001 | Partially Covered | Initial-credit recurrence is open and mock code formats conflict with the PRD. | Wrong attribution or duplicate/free credit allocation. | Confirm one-time versus renewal allocation and enforce the approved raw 6-digit code format. |
| Agency | AG-R012 | WhatsApp outreach generates a unique agency-code link, maps the customer, and prefills overlapping conversational data. | AG-PRD Screen 7 new_wa_num/new_wa_link/new_wa_populate EXT-API item 2 | Agency Staff, Customer | AG-WF-04 | UAT-AGINTK-001, UAT-AGINTK-002 | Partially Covered | Credentials, templates, and final link format are client inputs. | Referral attribution or customer data continuity fails. | Approve link format and WhatsApp templates. |
| Agency | AG-R017 | Lead access follows permission; configured notification channel and SLA govern new or unworked leads. | AG-PRD Screen 16 lead_process and client-input note AG-PRD Section 9.3 | Agency Staff, Super Admin | AG-WF-05 | UAT-AGLEAD-003 | Needs clarification | Notification channel and return-to-pool SLA are unset. | Valuable leads remain unactioned or are reassigned unexpectedly. | Approve channel, recipients, SLA clock, warning, and return behavior. |
| Agency | AG-R019 | Super Admin edit toggle controls whether Agency may overwrite customer-entered fields while review/continue remain available. | AG-PRD Screen 6 AD-07 edit-toggle note | Super Admin, Agency Staff | AG-WF-06 | UAT-AGAPP-003, UAT-AGAPP-004 | Partially Covered | Whether filling a previously blank field counts as Continue when edit is disabled is ambiguous. | Agency overwrites customer-owned data or cannot provide intended assistance. | Define edit-disabled behavior per field ownership and blank field. |
| Agency | AG-R020 | Agency may add/edit up to five co-applicants; only the primary applicant is individually scored. | AG-PRD Screen 6 det_coapp AG-PRD Section 4.2 | Agency Staff | AG-WF-06 | UAT-AGAPP-005, UAT-AGAPP-006 | Partially Covered | Primary-only scoring is confirmed, but Section 9 still requests final per-credit treatment confirmation. | Group applicants are lost or overcharged. | Close the co-applicant credit-treatment open item. |
| Agency | AG-R021 | Documents are stored on the shared record with OCR state; valid OCR pre-fills fields and failed OCR remains recoverable. | AG-PRD Screen 6 det_docs and Screen 7 new_indash EXT-API items 3 and 8 | Agency Staff, Customer | AG-WF-04, AG-WF-06, AG-WF-07 | UAT-AGINTK-004, UAT-AGAPP-007, UAT-AGAPP-008, UAT-AGAPP-013, UAT-AGSTAT-002 | Partially Covered | Permanent OCR failure/manual fallback is not defined. | Unverified document data drives scoring. | Define manual review/fallback and OCR retry limits. |
| Agency | AG-R024 | Risk engine shows fund-parking and other flags; valid source-of-funds proof can clear the relevant flag. | AG-PRD Screen 6 det_flags AG-PRD Appendix B AD-30/31/32 EXT-API item 3 | Agency Staff, Customer | AG-WF-06 | UAT-AGAPP-013 | Partially Covered | Automatic versus explicit rescore after proof is not stated. | Financial risk remains falsely flagged or is cleared without evidence. | Define flag-clear approval and rescore trigger. |
| Agency | AG-R026 | Agency-set application statuses drive Customer timeline and status communications across WhatsApp, app, and web. | AG-PRD Screen 6 status table/det_status and notification rule | Agency Staff, Customer, Super Admin | AG-WF-07 | UAT-AGSTAT-001, UAT-AGSTAT-002, UAT-AGSTAT-003, UAT-AGSTAT-004, UAT-AGSTAT-005 | Partially Covered | Complete allowed-transition matrix is absent. | Impossible or inconsistent case states. | Approve allowed prior/new state matrix and reversal rules. |
| Agency | AG-R029 | Configured low-credit threshold warns on dashboard/wallet and zero balance blocks scoring until recharge. | AG-PRD Section 5.3 and Screens 4/8 | Agency Staff | AG-WF-08 | UAT-AGWORK-002, UAT-AGAPP-010, UAT-AGCRED-002 | Partially Covered | Threshold value is unset. | Processing stops unexpectedly or allows unpaid work. | Approve threshold and warning recipients. |
| Agency | AG-R030 | Authorized user purchases Super-Admin-configured packs through the payment gateway; success updates balance immediately and creates an invoice. | AG-PRD Screen 9 rec_pack/rec_pay/rec_invoice EXT-API item 1 | Agency Admin, Billing-Permitted Sub-User | AG-WF-08 | UAT-AGCRED-002, UAT-AGCRED-003, UAT-AGCRED-004 | Partially Covered | Pack, tax, credential, and payment-method configuration are client inputs. | Paid credits or invoices are wrong. | Approve packs, taxes, currencies, and Razorpay configuration. |
| Agency | AG-R031 | Razorpay callbacks and refunds reconcile idempotently across payment, wallet, invoice, and Admin monitoring. | EXT-API item 1 Razorpay webhooks/refunds AG-PRD Screen 9 and Appendix B AD-50/AD-51 | Finance Operator, Agency Admin | AG-WF-08 | UAT-AGCRED-003, UAT-AGCRED-004, UAT-AGCRED-005, UAT-AGCRED-006 | Needs clarification | Refund eligibility, consumed-credit treatment, credit notes, and partial refund rules are unspecified. | Duplicate or incorrect financial value. | Approve end-to-end refund and reconciliation policy. |
| Agency | AG-R033 | Standard/Growth/Professional plans apply documented tokens and carry-forward; Pay-Per-Use is Phase 2. | AG-PRD Section 5.4 plan table and Screen 10 model table | Agency Admin, Super Admin | AG-WF-08 | UAT-AGBILL-002 | Needs clarification | Initial allocation recurrence and self-switch authority are open; mock says credits never expire, conflicting with Standard no carry-forward. | Renewal destroys or wrongly carries financial value. | Approve renewal timing, expiry, carry-forward, and switch authority. |
| Agency | AG-R034 | Credit packs, scoring/processing fees, and billing configuration originate in Super Admin and may vary by country/visa type. | AG-PRD Sections 5.2/9.2 and Appendix B | Super Admin, Agency Staff | AG-WF-08, AG-WF-14 | UAT-AGCRED-003, UAT-AGBILL-002, UAT-AGCFG-001 | Partially Covered | Actual fees/packs are unset. | Agency is charged under stale or wrong pricing. | Approve configuration values and effective-date/version rules. |
| Agency | AG-R035 | Agency Admin has full access; sub-users have default operational access and only explicitly granted sensitive capabilities. | AG-PRD Sections 2.1-2.2 powers matrix | Agency Admin, Agency Sub-User | AG-WF-02, AG-WF-03, AG-WF-05, AG-WF-09, AG-WF-10 | UAT-AGAUTH-002, UAT-AGWORK-002, UAT-AGWORK-004, UAT-AGLEAD-003, UAT-AGAPP-004, UAT-AGSTAT-005, UAT-AGBILL-001, UAT-AGUSER-001, UAT-AGUSER-003, UAT-AGUSER-004, UAT-AGUSER-005, UAT-AGPROMO-003 | Partially Covered | Final granular/default permission template remains a client input. | Privilege escalation or blocked staff work. | Approve final capability list and default template. |
| Agency | AG-R038 | Authorized branding user manages logo, display name, and customer support contact; invalid assets do not publish. | AG-PRD Screen 12 br_logo/br_name/br_support EXT-API item 8 | Agency Admin, Branding-Permitted Sub-User | AG-WF-06, AG-WF-11 | UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGBRAND-002 | Partially Covered | PRD says PNG/JPG and unspecified size; mock adds SVG and 2 MB. | Broken or unsafe customer-facing branding. | Approve file types, dimensions, and size limit. |
| Agency | AG-R040 | Agency profile supports validated Admin updates, requested tax-document re-upload, read-only code, logout, and consented/audited passport-data email export. | AG-PRD Screen 14 prof_details through prof_export | Agency Admin, Agency Sub-User | AG-WF-11 | UAT-AGPROF-001, UAT-AGPROF-002, UAT-AGPROF-003 | Needs clarification | Export recipient, format, consent, retention, and audit policy are unset. | Passport data is exported unlawfully or cannot be audited. | Approve the complete passport-export policy. |
| Agency | AG-R041 | Agency can raise validated case-linked support tickets, exchange replies/attachments, and progress Open, In Progress, Awaiting Agency Response, Resolved, and Closed states. | AG-PRD Screen 15 field and element tables | Agency Staff, Super Admin Support | AG-WF-13 | UAT-AGSUP-001, UAT-AGSUP-002, UAT-AGSUP-003 | Needs clarification | Final categories, priority SLAs, support contacts, and help content are client inputs. | Support expectations are misleading or tickets cannot be resolved. | Approve categories, SLA matrix, WhatsApp/email contacts, and help URL/content. |
| Agency | AG-R042 | Super Admin allocates promo; Agency receives and emails it; Customer redeems for a free transaction; usage is tracked. | AG-PRD Section 6.1 flow and Appendix B AD-62 | Super Admin, Agency User, Customer | AG-WF-10 | UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROMO-004 | Partially Covered | Allocation defaults and email template are unset; Stitch shows a conflicting recharge-bonus promo. | Wrong customer benefit or attribution. | Confirm promo semantic is customer fee waiver and approve allocation/template defaults. |
| Agency | AG-R044 | Super-Admin changes to agency edit rights, status, pricing, scoring/risk, forms/ranges, document checklists, countries/visas, reports, and help content propagate consistently. | AG-PRD Appendix B tables B.1/B.3 | Super Admin, Agency Staff, Customer | AG-WF-06, AG-WF-07, AG-WF-14 | UAT-AGAPP-003, UAT-AGAPP-013, UAT-AGSTAT-004, UAT-AGCFG-001 | Partially Covered | Effective-time, caching, and in-progress-record versioning are unspecified. | Products apply different rules to the same case. | Define configuration version/effective-time and cache invalidation rules. |
| Agency | AG-R045 | External provider failures are visible, recoverable, secure, and do not create duplicate or false business outcomes. | EXT-API integration list AG-PRD integration error/fallback fields | Agency Staff, Customer, Operations | AG-WF-04, AG-WF-06, AG-WF-07, AG-WF-13 | UAT-AGINTK-002, UAT-AGAPP-012, UAT-AGAPP-015, UAT-AGSTAT-005, UAT-AGPROF-003, UAT-AGSUP-003 | Needs clarification | Provider credentials/templates, retry limits, idempotency, and operational recovery are client/config inputs. | Partial integration failure corrupts cases or finances. | Approve provider configuration, retry, idempotency, timeout, and support runbooks. |
| Agency | AG-R047 | A raw 6-digit Agency Code is always visible/read-only and agency display name/report branding always retains Powered by VisaReady; B2C reports remain VisaReady-only. | AG-PRD Section 7 and Screens 12/14 | Agency Staff, Customer | AG-WF-06, AG-WF-11 | UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGPROF-001 | Needs clarification | Stitch shows inconsistent prefixed/variable-length codes and product names. | Customer attribution and platform trust are ambiguous. | Confirm canonical code rendering and product/agency naming tokens. |
| Agency | AG-R048 | Cloud storage securely stores registration evidence, passports, reports, logos, decisions, exports, and ticket attachments with correct ownership and recoverable failure. | EXT-API item 8 AG-PRD Screens 1, 6, 12, 14, 15 | Agency Staff, Customer | AG-WF-04, AG-WF-06, AG-WF-11, AG-WF-13 | UAT-AGREG-002, UAT-AGREG-005, UAT-AGINTK-004, UAT-AGAPP-007, UAT-AGAPP-008, UAT-AGAPP-014, UAT-AGBRAND-001, UAT-AGBRAND-002, UAT-AGPROF-001, UAT-AGSUP-001, UAT-AGSUP-002 | Partially Covered | Storage provider, encryption, retention, malware scanning, and signed-link expiry are not specified. | Sensitive documents leak, disappear, or are misattributed. | Approve storage security, retention, scanning, and access-link policy. |
| Agency | AG-R049 | SMS/OTP, transactional email, WhatsApp, push, and in-app services deliver required login, invite, promo, invoice, report, status, and operational communications to the correct audience. | EXT-API items 2, 4, 5, 7 AG-PRD Screens 3, 6, 9, 11, 13 | Agency Staff, Customer | AG-WF-01, AG-WF-02, AG-WF-04, AG-WF-07, AG-WF-08, AG-WF-09, AG-WF-10, AG-WF-12 | UAT-AGREG-003, UAT-AGAUTH-001, UAT-AGAUTH-002, UAT-AGAUTH-003, UAT-AGINTK-001, UAT-AGAPP-014, UAT-AGAPP-015, UAT-AGSTAT-001, UAT-AGSTAT-002, UAT-AGSTAT-003, UAT-AGSTAT-005, UAT-AGCRED-003, UAT-AGUSER-001, UAT-AGUSER-006, UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROF-002, UAT-AGNOTIF-001 | Partially Covered | Templates, recipient rules, delivery SLA, and provider configuration are not finalized. | Users miss access, decision, payment, or action communications. | Approve templates, audience rules, retry, and delivery SLAs. |
| Agency | AG-R050 | Pay-Per-Use, public agency directory, lead transfer, and dedicated APM/System Health are not Agency MVP behavior. | AG-PRD Screens 10/12 and Section 8 Phase-2 notes EXT-API analytics/monitoring note | Agency Staff, Super Admin | AG-WF-08 | UAT-AGBILL-002 | Out of Scope | Mocks may display Phase-2 calls to action but must not activate unsupported behavior. | Unapproved features create unsupported financial or ownership states. | Keep visible Phase-2 actions explicitly non-operational or remove them from MVP. |
| Agency | AG-UI-001 | UI mocks use VisaReady and approved agency branding consistently. | AG-STITCH visible HTML across screens | All Agency Users | AG-WF-01, AG-WF-03, AG-WF-11 | UAT-AGBRAND-001 | Needs clarification | Mocks alternate VisaReady, VisaPro, VisaGlobal, VisaPro Global, and B2B Pulse. | Users cannot identify the platform or trusted agency. | Approve canonical product, portal, and sample-agency naming. |
| Agency | AG-UI-002 | UI renders the PRD-mandated 6-digit agency code consistently. | AG-PRD Section 7 AG-STITCH screens showing VR-882931, VP-8821, VPA-88291, VP-7724X, and 882931 | Agency Staff, Customer | AG-WF-01, AG-WF-05, AG-WF-11 | UAT-AGREG-006, UAT-AGBRAND-001, UAT-AGPROF-001 | Needs clarification | Most mock codes are prefixed or variable-length and conflict with the raw 6-digit PRD rule. | Referral links and manual code entry fail. | Approve one canonical stored and displayed format. |
| Agency | AG-UI-003 | Mock credit quantities, currency display, and deductions align to one-credit-per-primary-score requirements. | AG-STITCH Dashboard, Clients, Wallet, Approved, and Recharge screens AG-PRD Section 5.1 | Agency Staff | AG-WF-03, AG-WF-06, AG-WF-08 | UAT-AGAPP-009, UAT-AGCRED-001 | Needs clarification | Mocks mix monetary balances, large per-client credit counts, OCR/verification deductions, and an approved $500 allocation. | Agency cannot understand or reconcile charges. | Replace mock values with the approved token unit and deduction events. |
| Agency | AG-UI-004 | Promo UI represents Super-Admin-allocated customer fee-waiver codes, not agency recharge bonuses. | AG-PRD Section 6 AG-STITCH Notifications WELCOME50 recharge bonus and Recharge promo field | Agency User, Customer | AG-WF-10 | UAT-AGPROMO-001, UAT-AGPROMO-002, UAT-AGPROMO-003, UAT-AGPROMO-004, UAT-AGPROMO-005 | Needs clarification | Mock promo semantics conflict with approved Agency PRD flow. | Wrong financial benefit is issued or redeemed. | Approve whether recharge promos are separate, out of scope, or should be removed. |
| Agency | AG-UI-005 | Branding upload types and size limits are identical in requirements and UI. | AG-PRD Screen 12 br_logo AG-STITCH Branding screen | Branding-Permitted User | AG-WF-11 | UAT-AGBRAND-002 | Needs clarification | PRD lists PNG/JPG with unspecified size; mock lists PNG/SVG/JPG at 2 MB. | A UI-accepted asset fails server-side or unsafe SVG is stored. | Approve exact types, sanitization, dimensions, and size. |
| Agency | AG-UI-006 | Support mock displays only client-approved contacts and SLA claims. | AG-PRD Screen 15 client-input note AG-STITCH Support screen under-4-hours, 24/7, and support email copy | Agency Staff | AG-WF-13 | UAT-AGSUP-003 | Needs clarification | Mock hard-codes claims while PRD leaves them open. | Contractual support expectations are misstated. | Approve or remove every SLA/contact claim. |
| Agency | AG-UI-007 | Auto-recharge shown in Wallet has an approved requirement, permissions, threshold, payment consent, and failure behavior. | AG-STITCH Wallet screen Auto-Recharge Active No matching AG-PRD requirement | Agency Admin | AG-WF-08 | Needs clarification | Auto-recharge is mock-only and unsupported by the PRD. | Unexpected automatic financial charges. | Remove from MVP or add an approved auto-recharge requirement and controls. | |
| Agency | AG-UI-008 | Rejected registration correction or appeal behavior is explicitly approved. | AG-STITCH Rejected screen Appeal Decision/Modify Application AG-PRD Screen 2 only specifies Rejected status/note | Rejected Agency Admin, Super Admin | AG-WF-01 | UAT-AGREG-007 | Needs clarification | Mock-only appeal/resubmission route. | Rejected agencies encounter a dead or unauthorized action. | Approve appeal, edit/resubmit, or terminal rejection behavior. |
| Agency | AG-UI-009 | Billing mock expiry language agrees with plan carry-forward rules. | AG-STITCH Billing screen Credits never expire AG-PRD Section 5.4 Standard no carry-forward | Agency Admin | AG-WF-08 | UAT-AGBILL-002 | Needs clarification | Never-expire copy conflicts with a non-carry-forward plan. | Agency loses value contrary to displayed promise. | Define expiry/carry-forward per plan and align the copy. |
| Agency | AG-UI-010 | Manual New Lead action in the mock is either defined or removed. | AG-STITCH Leads screen New Lead button AG-PRD Screen 16 supports code-mapped and Admin-allocated leads | Agency Staff | AG-WF-05 | Needs clarification | Mock-only manual lead creation duplicates or overlaps Add New Client. | Duplicate customers and ambiguous lead ownership. | Remove the action or define how it differs from Add New Client. | |
| Agency | AG-UI-011 | Dashboard regional trends, Premium Agency Support, and Contact Account Manager content is approved, sourced, and permission-scoped or removed. | AG-STITCH Dashboard screen regional trends and Premium Agency Support No matching AG-PRD Screen 4 requirement | Agency Staff | AG-WF-03 | Needs clarification | Mock-only analytics and premium-support content have no data source, entitlement, or action rule. | Agency sees unsupported analytics or support promises. | Define source, refresh, entitlement, and account-manager action or remove these components from MVP. | |
| Agency | AG-UI-012 | The mock claim that agencies can send unlimited invitation links is approved with abuse, rate-limit, and duplicate-recipient behavior. | AG-STITCH Add New Client screen Unlimited invitation links copy AG-PRD only states no credit is deducted for sending a link | Agency Staff | AG-WF-04 | UAT-AGINTK-001, UAT-AGINTK-002 | Needs clarification | No approved unlimited-send or abuse-prevention rule exists. | Spam, provider cost, account blocking, or duplicate customers. | Approve send limits, resend/idempotency, consent, and abuse controls or remove the unlimited claim. |
| Agency | AG-UI-013 | Mock sub-user roles such as Senior Agent, Junior Agent, Support Staff, and Finance Manager map explicitly to the granular PRD permission model. | AG-STITCH User Management role options AG-PRD Sections 2.1-2.2 define Agency Admin/Sub-User plus granular permissions | Agency Admin, Agency Sub-User | AG-WF-09 | UAT-AGUSER-001, UAT-AGUSER-003 | Needs clarification | Role presets, their permissions, and whether they are labels only are undefined. | Displayed role implies access that differs from enforced permissions. | Publish an authoritative role-preset-to-permission matrix or remove presets. |
| Agency | AG-GAP-001 | The 6-digit agency-code namespace has sufficient uniqueness capacity and a defined exhaustion/collision policy. | AG-PRD Section 9.5 Open Question 7 | Super Admin, Agency Admin, Customer | AG-WF-01, AG-WF-05 | Needs clarification | Projected agency volume, reserved values, recycling, and exhaustion behavior are not defined. | Code collision maps customers to the wrong agency or blocks onboarding. | Approve capacity forecast, uniqueness scope, generation algorithm, collision retry, and code-retirement policy. | |
| Agency | EXT-OOS-001 | Google OAuth customer login is not an Agency Dashboard acceptance behavior. | EXT-API item 6 | Customer | Out of Scope | Covered by Customer Application suite. | ||||
| Agency | EXT-OOS-002 | Embassy/official visa portal URLs are not evidenced as an Agency screen flow. | EXT-API item 9 | Customer | Out of Scope | Covered by the application that exposes the embassy link. | ||||
| Superadmin | AD-06 | Agency directory supports defined statuses, search/filter, bulk actions and export. | VisaReady Final Doc Admin.docx §5 AD-06 Stitch AD06 agency-directory variants | Admin, Support, Analyst | WF-SA-04 | UAT-SA-ANL-008, UAT-SA-AGY-001, UAT-SA-AGY-014 | Partially Covered | The exact eligibility and atomicity matrix for each bulk status transition is not stated. | Unsafe bulk transitions could suspend or activate the wrong agencies. | Approve allowed source-to-target transitions and partial-failure behavior. |
| Superadmin | AD-07 | Agency KYC validates GST/PAN, approval activates with initial credits, rejection records reason, and customer-data editing defaults off. | VisaReady Final Doc Admin.docx §5 AD-07 | Admin, Agency Admin | WF-SA-04 | UAT-SA-AGY-001, UAT-SA-AGY-002, UAT-SA-AGY-011 | Partially Covered | The source does not resolve whether GST/PAN must use live government verification or only format/checksum validation. | Weak identity validation could activate fraudulent agencies. | Confirm verification provider, failure policy and approved initial-credit amount. |
| Superadmin | AD-08 | Phase 1 supports lead visibility and manual follow-up; automatic assignment, transfer and SLA return are Phase 2. | VisaReady Final Doc Admin.docx §5 AD-08 | Admin, Agency Staff | WF-SA-04 | UAT-SA-AGY-012, UAT-SA-AGY-013 | Partially Covered | Phase-2 assignment, transfer and SLA rules are explicitly outside the immediate Phase-1 scope. | Claiming Phase-2 behavior as delivered would create incorrect lead ownership expectations. | Create a separate Phase-2 acceptance baseline when assignment roles and SLAs are approved. |
| Superadmin | AD-09 | Plan purchase auto-assigns entitlement while manual override is exceptional, reasoned and time-bound. | VisaReady Final Doc Admin.docx §5 AD-09 | Admin, Agency Admin, Customer | WF-SA-04, WF-SA-10 | UAT-SA-AGY-007, UAT-SA-PLAN-003, UAT-SA-PLAN-006, UAT-SA-PLAN-007 | Partially Covered | Proration and carry-forward during override are identified as client inputs. | Ambiguous override economics can overgrant entitlement or misstate billing. | Approve proration, usage, renewal and carry-forward rules for every override transition. |
| Superadmin | AD-13 | B2C user directory supports safe search, filters, export and bulk operations. | VisaReady Final Doc Admin.docx §5 AD-13 | Admin, Support, Analyst | WF-SA-05 | UAT-SA-ANL-008, UAT-SA-USR-001, UAT-SA-USR-009 | Partially Covered | Exact bulk-deactivation eligibility and atomicity are not defined. | Incorrect bulk processing could lock out unintended customers. | Approve the bulk selection, eligibility and partial-failure model. |
| Superadmin | AD-15 | Verified deletion requests are queued, processed through deletion/anonymization and communicated to the customer. | VisaReady Final Doc Admin.docx §5 AD-15 | Admin, Customer | WF-SA-05 | UAT-SA-USR-004, UAT-SA-USR-006 | Partially Covered | Retention categories, deletion SLA and dependency-resolution policy are not final. | Incomplete deletion can breach privacy law; over-deletion can destroy required evidence. | Approve retention schedule, verification evidence, SLA and exception owner. |
| Superadmin | AD-16 | DPDPA erasure is an irreversible, cross-module controlled job with customer notification and audit. | VisaReady Final Doc Admin.docx §5 AD-16 | Admin, Customer | WF-SA-05 | UAT-SA-USR-005, UAT-SA-USR-006 | Partially Covered | Retained legal records, completion SLA and retry ownership are unspecified. | An incomplete or repeated erasure job creates severe compliance and integrity exposure. | Obtain legal approval for scope/retention and operational approval for job recovery. |
| Superadmin | AD-18 | Application detail connects documents/OCR, scoring reasons, timeline, audit, report and fraud context. | VisaReady Final Doc Admin.docx §5 AD-18 | Admin, Support, Analyst | WF-SA-06 | UAT-SA-CASE-002, UAT-SA-CASE-003, UAT-SA-CASE-008, UAT-SA-CASE-009, UAT-SA-CASE-010 | Partially Covered | Score-regeneration price and evidence-change eligibility are not finalized. | A fragmented or unreproducible case view undermines UAT decision confidence. | Approve regeneration commercial rules and final detail-section access matrix. |
| Superadmin | AD-19 | Reasoned Admin status override propagates across channels, updates timeline/notifications and takes precedence over agency updates. | VisaReady Final Doc Admin.docx §5 AD-19 | Admin, Support, Analyst, Agency Staff, Customer | WF-SA-06 | UAT-SA-RBAC-006, UAT-SA-CASE-003, UAT-SA-CASE-004, UAT-SA-CASE-005, UAT-SA-CASE-006, UAT-SA-CASE-007, UAT-SA-CASE-008 | Partially Covered | The complete allowed status-transition matrix is not stated. | Contradictory or invalid status changes mislead customers and operations. | Approve allowed transitions, disclosure rules and conflict-handling mechanics. |
| Superadmin | AD-20 | Country catalogue uses unique ISO identity, flag, processing/appointment data, active state and embassy URL; inactive countries hide from new journeys. | VisaReady Final Doc Admin.docx §5 AD-20 | Admin, Customer, Agency Staff | WF-SA-07 | UAT-SA-CFG-001, UAT-SA-CFG-002, UAT-SA-CFG-003, UAT-SA-CFG-004 | Partially Covered | Final country list, URL ownership and URL-health policy are client inputs. | Incorrect catalogue data can launch unsupported or misleading journeys. | Approve launch catalogue and content/URL owner. |
| Superadmin | AD-21 | Admin can add a valid unique country with all required metadata. | VisaReady Final Doc Admin.docx §5 AD-21 | Admin | WF-SA-07 | UAT-SA-CFG-001, UAT-SA-CFG-002 | Partially Covered | Mandatory-field detail and final approved countries are not exhaustively enumerated. | Incomplete country creation can break downstream forms and content. | Confirm mandatory fields and approval workflow. |
| Superadmin | AD-23 | Adding/editing a supported visa type triggers the corresponding checklist rebuild. | VisaReady Final Doc Admin.docx §5 AD-23 | Admin | WF-SA-07 | UAT-SA-CFG-005, UAT-SA-CFG-006 | Partially Covered | In-flight application migration behavior is not specified. | Checklist/version mismatch can request the wrong documents. | Approve checklist rebuild scope for drafts and in-flight cases. |
| Superadmin | AD-24 | Country-specific scoring rules are unique, effective-dated and rebuild the scoring engine. | VisaReady Final Doc Admin.docx §5 AD-24 | Admin, Analyst | WF-SA-07, WF-SA-08 | UAT-SA-CFG-010, UAT-SA-CFG-011, UAT-SA-CFG-012 | Partially Covered | Final country parameters and modifiers are client inputs. | Ambiguous country policy can create inconsistent applicant scoring. | Approve parameter catalogue, precedence and country values. |
| Superadmin | AD-25 | Admin can add/edit one unambiguous country/visa scoring rule per parameter. | VisaReady Final Doc Admin.docx §5 AD-25 | Admin | WF-SA-07 | UAT-SA-CFG-010, UAT-SA-CFG-011 | Partially Covered | Supported operators and effects are not exhaustively listed. | Invalid rule semantics can make scores irreproducible. | Approve operator/value types and overlap/precedence rules. |
| Superadmin | AD-26 | Dynamic forms support fields, ranges, dropdowns, validation, conditional visibility, preview, version/effective date and cross-channel propagation. | VisaReady Final Doc Admin.docx §5 AD-26 Stitch AD26 original and regenerated variants | Admin, Customer, Agency Staff | WF-SA-07 | UAT-SA-CFG-008, UAT-SA-CFG-009 | Partially Covered | Exact field catalogue, numeric ranges and in-flight migration policy are client inputs. | Broken form configuration can block intake or feed invalid scoring data. | Approve the field/range catalogue and version migration rules. |
| Superadmin | AD-27 | Seven factor weights total exactly 100 using approved defaults; Others may be zero only with rebalance. | VisaReady Final Doc Admin.docx §5 AD-27 | Admin, Analyst | WF-SA-08 | UAT-SA-CFG-012, UAT-SA-SCR-001, UAT-SA-SCR-002, UAT-SA-SCR-003, UAT-SA-SCR-004 | Partially Covered | Allowed redistribution and Others subrules are not finalized. | Invalid normalization can distort every applicant result. | Approve redistribution constraints and any Others factor subrules. |
| Superadmin | AD-28 | Lite uses five factors and Low/Medium/High without risks; Final uses seven factors, risk and defined score bands. | VisaReady Final Doc Admin.docx §5 AD-28 | Admin, Analyst, Customer | WF-SA-06, WF-SA-08 | UAT-SA-CASE-002, UAT-SA-CASE-010, UAT-SA-SCR-004, UAT-SA-SCR-005, UAT-SA-SCR-006, UAT-SA-SCR-013 | Partially Covered | Exact Lite factor split/thresholds and display of nested below-40 guidance are unresolved. | Incorrect stage logic or band boundaries can mislead applicants. | Approve Lite configuration and precise customer labels at every boundary. |
| Superadmin | AD-30 | Risk rules are versioned, editable/active and apply to Final scoring only. | VisaReady Final Doc Admin.docx §5 AD-30 | Admin, Analyst | WF-SA-08 | UAT-SA-SCR-005, UAT-SA-SCR-009, UAT-SA-SCR-010 | Partially Covered | Final trigger catalogue and penalty values are client inputs. | Unapproved or unexplained risk penalties can unfairly alter outcomes. | Approve triggers, severities, penalties and effective-date rules. |
| Superadmin | AD-31 | Risk triggers include refusal, unexplained credit, passport/travel expiry proximity and missing documents, with Final-only propagation. | VisaReady Final Doc Admin.docx §5 AD-31 | Admin, Customer | WF-SA-08 | UAT-SA-SCR-005, UAT-SA-SCR-009 | Partially Covered | Some exact trigger thresholds and penalties are not final. | Incorrect triggers can create false high-risk decisions. | Approve all threshold, combination and disclosure rules. |
| Superadmin | AD-32 | Fund-parking detection uses OCR evidence, large recent-credit threshold, penalty and valid-proof waiver. | VisaReady Final Doc Admin.docx §5 AD-32 | Admin, Customer | WF-SA-08 | UAT-SA-SCR-011, UAT-SA-SCR-012, UAT-SA-SCR-013 | Partially Covered | Lookback, aggregation, exact penalty and accepted proof types are not final. | False fund-parking classification can materially and unfairly lower a score. | Approve threshold calculation, proof catalogue, reviewer and waiver audit policy. |
| Superadmin | AD-33 | Country requirements remain hidden as drafts and become immediately visible only after publication. | VisaReady Final Doc Admin.docx §5 AD-33 | Admin, Customer, Agency Staff | WF-SA-09 | UAT-SA-CMS-001, UAT-SA-CMS-010 | Partially Covered | Final country content and editorial approval owner are client inputs. | Draft or stale requirements can cause incomplete applications. | Approve content inventory and publication governance. |
| Superadmin | AD-34 | Document checklists combine ordered mandatory base documents with the applicable user-type overlay and rebuild consuming journeys. | VisaReady Final Doc Admin.docx §5 AD-34 | Admin, Customer, Agency Staff | WF-SA-07, WF-SA-09 | UAT-SA-CFG-005, UAT-SA-CMS-002 | Partially Covered | Final base and seven user-type overlay lists are not supplied. | Wrong checklists cause avoidable rejection or unnecessary PII collection. | Approve checklist content for Salaried, Business, Student, Retired, Unemployed, Homemaker and Freelancer. |
| Superadmin | AD-39 | Country tiers, experience/salary bands, boosters and funds modifiers influence only their intended scoring scope. | VisaReady Final Doc Admin.docx §5 AD-39 | Admin, Analyst | WF-SA-07, WF-SA-08 | UAT-SA-CFG-012 | Partially Covered | Exact tiers, bands, booster values and approximately €100 funds rule are not final. | Unapproved modifiers can materially distort country-specific outcomes. | Approve complete parameter/value matrix and precedence. |
| Superadmin | AD-41 | Country-specific cover letters and versioned itineraries render approved merge data and publish safely. | VisaReady Final Doc Admin.docx §5 AD-41 | Admin, Customer | WF-SA-09 | UAT-SA-CMS-006 | Partially Covered | Final UK, Canada, Australia and Schengen copy, merge fields and publication rules are inputs. | Incorrect document templates can harm an applicant submission. | Approve final copy, ownership and supported merge-field catalogue. |
| Superadmin | AD-42 | B2B/B2C plan catalogue controls price, period, quota, carry-forward, activation and deactivation behavior. | VisaReady Final Doc Admin.docx §5 AD-42 | Admin, Agency Admin, Customer | WF-SA-04, WF-SA-10 | UAT-SA-AGY-007, UAT-SA-PLAN-001, UAT-SA-PLAN-002, UAT-SA-PLAN-003, UAT-SA-PLAN-004 | Partially Covered | Provided default prices/quotas coexist with a statement that final plan values and carry-forward are client inputs. | Wrong plan economics cause entitlement leakage and billing disputes. | Approve final catalogue, taxes, quotas, renewal and carry-forward policy. |
| Superadmin | AD-45 | Manual plan override requires authorization, reason and expiry and is fully audited. | VisaReady Final Doc Admin.docx §5 AD-45 | Admin, Subscriber | WF-SA-05, WF-SA-10 | UAT-SA-USR-007, UAT-SA-PLAN-006, UAT-SA-PLAN-007 | Partially Covered | Proration, usage and carry-forward across override transitions are not specified. | Uncontrolled overrides create unapproved commercial concessions. | Approve entitlement fallback and financial treatment for grant, expiry and revocation. |
| Superadmin | AD-46 | Notification template inventory supports status, channel governance and safe production use. | VisaReady Final Doc Admin.docx §5 AD-46 | Admin | WF-SA-12 | UAT-SA-NOTIF-001, UAT-SA-NOTIF-005, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007 | Partially Covered | Final template inventory and event/channel ownership are not supplied. | Uncontrolled templates can send incorrect or unapproved communications. | Approve template inventory, owners and review/publish workflow. |
| Superadmin | AD-47 | Email editor requires subject, validates merge fields, supports preview/test and versions publication. | VisaReady Final Doc Admin.docx §5 AD-47 | Admin, Recipient | WF-SA-12 | UAT-SA-NOTIF-001, UAT-SA-NOTIF-005, UAT-SA-NOTIF-007 | Partially Covered | Approved sender identities, subjects and merge-field catalogue are client inputs. | Malformed email can expose bad data or fail a critical notice. | Approve sender/domain, subject rules and merge-field catalogue. |
| Superadmin | AD-48 | SMS, WhatsApp and push templates support preview/test, active state and channel-safe delivery. | VisaReady Final Doc Admin.docx §5 AD-48 | Admin, Recipient | WF-SA-12 | UAT-SA-NOTIF-002, UAT-SA-NOTIF-003, UAT-SA-NOTIF-004, UAT-SA-NOTIF-005, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007 | Partially Covered | Provider-specific template approval, consent and fallback policies are not final. | Invalid multi-channel messaging can breach consent or miss critical updates. | Approve consent source, provider template IDs and fallback behavior per channel. |
| Superadmin | AD-49 | Business events map deterministically to active notification channels and templates. | VisaReady Final Doc Admin.docx §5 AD-49 | Admin, Recipient | WF-SA-12 | UAT-SA-NOTIF-002, UAT-SA-NOTIF-003, UAT-SA-NOTIF-004, UAT-SA-NOTIF-006, UAT-SA-NOTIF-007 | Partially Covered | Exact business-event-to-channel matrix is explicitly unresolved. | Missing or duplicate trigger mappings can omit or duplicate customer communication. | Approve event catalogue, recipients, channels, idempotency and retry owner. |
| Superadmin | AD-50 | Transactions and agency recharges expose accurate lifecycle, gateway reference, invoice, entitlement and financial state. | VisaReady Final Doc Admin.docx §5 AD-50 | Admin, Support, Analyst, Buyer | WF-SA-03, WF-SA-06, WF-SA-10, WF-SA-13 | UAT-SA-RBAC-007, UAT-SA-CASE-010, UAT-SA-PLAN-004, UAT-SA-PAY-001, UAT-SA-PAY-002, UAT-SA-PAY-003, UAT-SA-PAY-004, UAT-SA-PAY-010 | Partially Covered | Final Razorpay environment/configuration, taxes, invoice and regeneration-price details remain inputs. | Transaction inconsistency creates financial loss or entitlement disputes. | Approve final payment purposes, invoice/tax treatment and operational status model. |
| Superadmin | AD-52 | Authorized refund decisions require eligibility/reason, execute through the gateway and update customer and financial state. | VisaReady Final Doc Admin.docx §5 AD-52 | Support, Admin, Customer | WF-SA-02, WF-SA-13 | UAT-SA-RBAC-006, UAT-SA-PAY-005, UAT-SA-PAY-006, UAT-SA-PAY-007, UAT-SA-PAY-008 | Partially Covered | Partial-refund, fee, entitlement reversal and eligibility policies are not fully specified. | Incorrect refund handling can over-refund or retain customer funds improperly. | Approve eligibility, partial amount, fee, entitlement and notification rules. |
| Superadmin | AD-53 | Razorpay reconciliation classifies matched, mismatch and pending records, supports export and handles delayed/duplicate events. | VisaReady Final Doc Admin.docx §5 AD-53 | Admin, Analyst | WF-SA-03, WF-SA-13 | UAT-SA-RBAC-007, UAT-SA-PAY-004, UAT-SA-PAY-009, UAT-SA-PAY-010 | Partially Covered | Settlement cadence, matching tolerance and mismatch owner are not defined. | Unresolved discrepancies hide missing or duplicated money movement. | Approve cadence, tolerance, resolution workflow and closing evidence. |
| Superadmin | AD-60 | System-health/APM monitoring is referenced but explicitly outside the VisaReady Lite scope. | VisaReady Final Doc Admin.docx §5 AD-60 List of external APIs or third-party integrations required.docx states system health/APM out of scope Stitch AD60 System Health screen | Super Admin, Operations | Out of Scope | The design exists, but the integration requirements document explicitly excludes APM/system health from Lite. | Operational monitoring remains a future-release dependency and must not be misrepresented as accepted. | Create a future-release baseline when monitoring provider, SLIs, alerting and ownership are approved. | ||
| Superadmin | AD-62 | Super Admin generates/allocates promo codes, agency distributes them and eligible redemption fully waives one transaction under use/cap/expiry rules. | VisaReady Final Doc Admin.docx §5 AD-62 | Super Admin, Agency Admin, Customer | WF-SA-11 | UAT-SA-PROMO-001, UAT-SA-PROMO-002, UAT-SA-PROMO-003, UAT-SA-PROMO-004, UAT-SA-PROMO-005 | Partially Covered | Allocation commit-on-notification-failure, customer binding, timezone and final copy are unresolved. | Promo ambiguity can exceed approved financial liability. | Approve allocation model, code scope, expiry timezone, caps and email-recovery owner. |
| Superadmin | AD-63 | Country library content supports ordered drafts and controlled publication across channels. | VisaReady Final Doc Admin.docx §5 AD-63 | Admin, Customer, Agency Staff | WF-SA-09 | UAT-SA-CMS-007 | Partially Covered | Initial country/article inventory and editorial owner are not supplied. | Uncontrolled guidance can be stale or contradictory. | Approve launch inventory, ordering and review cadence. |
| Superadmin | AD-64 | Terms, Privacy and Disclaimer are versioned/effective/published and can force reconsent with durable consent logs. | VisaReady Final Doc Admin.docx §5 AD-64 | Admin, Customer | WF-SA-09 | UAT-SA-CMS-008 | Partially Covered | Final legal copy and the permitted experience after decline require legal approval. | Unprovable or stale consent creates material privacy/compliance exposure. | Obtain legal signoff for copy, effective timezone, decline handling and consent retention. |
| Superadmin | AD-65 | Reports apply every-page watermark, ordered sections, agency co-branding, VisaReady identity, report ID/QR and passport footer. | VisaReady Final Doc Admin.docx §5 AD-65 | Admin, Customer, Agency Staff | WF-SA-06, WF-SA-09 | UAT-SA-CASE-002, UAT-SA-CMS-009, UAT-SA-CMS-011 | Partially Covered | Final watermark opacity/placement, section order, asset constraints and QR destination are inputs. | Incorrect branding or identity controls can produce unauthentic or misleading reports. | Approve layout, section order, QR security/destination and logo file policy. |
| Superadmin | AD-70 | Super-Admin-only maintenance mode blocks non-admin channels, preserves Admin access, displays custom message and auto-disables at scheduled end. | VisaReady Final Doc Admin.docx §5 AD-70 | Super Admin, Admin, Customer, Agency Staff | WF-SA-02, WF-SA-15 | UAT-SA-RBAC-005, UAT-SA-OPS-001, UAT-SA-OPS-002, UAT-SA-OPS-003, UAT-SA-OPS-004 | Partially Covered | Timezone and treatment of sessions active at enable/disable boundaries are not defined. | Unsafe maintenance control can block recovery access or leave public writes active. | Approve timezone, active-session, API and cache behavior at both boundaries. |
| Superadmin | EXT-EMAIL | Transactional email supports business notifications with observable delivery and recoverable failure. | List of external APIs or third-party integrations required.docx transactional-email entry | Admin, Recipient | WF-SA-11, WF-SA-12 | UAT-SA-PROMO-005, UAT-SA-NOTIF-001, UAT-SA-NOTIF-006 | Partially Covered | Provider, sender identities, retry and fallback are not final. | Undetected email failure can leave agencies or customers unaware of critical events. | Approve provider, domain, delivery SLA, retry and dead-letter ownership. |
| Superadmin | EXT-EMBASSY | Country guidance links to approved official embassy URLs without external failure breaking VisaReady. | List of external APIs or third-party integrations required.docx embassy URLs | Admin, Customer | WF-SA-07 | UAT-SA-CFG-004 | Partially Covered | Final URL inventory, owner and health-check cadence are not supplied. | Broken or unsafe links misdirect applicants. | Approve official domains, validation cadence and fallback content. |
| Superadmin | EXT-OCR | OCR/document intelligence produces traceable evidence and exposes safe retryable failure. | List of external APIs or third-party integrations required.docx OCR/document-intelligence entry | Admin, Support, Customer | WF-SA-06, WF-SA-08 | UAT-SA-CASE-009, UAT-SA-SCR-013 | Partially Covered | Provider, confidence thresholds, manual-review path and retry limits are not final. | Incorrect or invented OCR values can cause unsupported scoring decisions. | Approve provider, confidence threshold, review owner, retention and recovery policy. |
| Superadmin | EXT-PUSH | Push integration delivers configured events and deep-links only after normal authorization. | List of external APIs or third-party integrations required.docx push-notification entry | Admin, Customer | WF-SA-12 | UAT-SA-NOTIF-004, UAT-SA-NOTIF-006 | Partially Covered | Provider, token retirement and fallback are not final. | Bad deep links or stale tokens can leak data or miss updates. | Approve provider, token lifecycle and deep-link authorization contract. |
| Superadmin | EXT-RAZORPAY | Razorpay supports purchase, recharge, refund, webhook idempotency and reconciliation. | List of external APIs or third-party integrations required.docx Razorpay entry | Buyer, Admin, Support, Analyst | WF-SA-10, WF-SA-13 | UAT-SA-PLAN-003, UAT-SA-PLAN-004, UAT-SA-PAY-002, UAT-SA-PAY-003, UAT-SA-PAY-004, UAT-SA-PAY-005, UAT-SA-PAY-008, UAT-SA-PAY-010 | Partially Covered | Production credentials/config, webhook SLA, fee/tax and settlement policies are not final. | Gateway integration defects directly affect funds and entitlements. | Approve environments, signed webhook contract, idempotency keys, fees, settlements and operational SLAs. |
| Superadmin | EXT-SMS-OTP | SMS/OTP integration securely delivers messages and expiring one-time challenges. | List of external APIs or third-party integrations required.docx SMS/OTP entry | Admin user, Customer, Recipient | WF-SA-01, WF-SA-12 | UAT-SA-NOTIF-002, UAT-SA-NOTIF-006 | Partially Covered | Provider, OTP TTL, resend/rate limits and fallback are not specified. | Weak OTP controls enable takeover; outages block access. | Approve provider and complete OTP security/availability policy. |
| Superadmin | EXT-STORAGE | Cloud storage protects documents/assets and exposes recoverable upload/read failure without broken publication. | List of external APIs or third-party integrations required.docx cloud-storage entry | Admin, Support, Customer | WF-SA-06, WF-SA-09 | UAT-SA-CASE-009, UAT-SA-CMS-011 | Partially Covered | Provider, encryption, retention, malware scan and retry policy are not final. | Storage failure can lose evidence or expose PII. | Approve provider, security controls, file policy, retention and recovery targets. |
| Superadmin | EXT-WHATSAPP | WhatsApp Business sends approved consented event templates once with observable status. | List of external APIs or third-party integrations required.docx WhatsApp Business entry | Admin, Recipient | WF-SA-12 | UAT-SA-NOTIF-003, UAT-SA-NOTIF-006 | Partially Covered | Provider account, consent source, approved template IDs and fallback are not final. | Unapproved or duplicate messaging can breach consent and trust. | Approve consent evidence, template catalogue, provider statuses and retry/fallback. |
| Superadmin | EXT-GST-PAN | Agency GST/PAN validation must be either live verification or a clearly approved format/checksum validation policy. | VisaReady Final Doc Admin.docx §5 AD-07 List of external APIs or third-party integrations required.docx GST/PAN ambiguity | Admin, Agency Admin | WF-SA-04 | Needs clarification | The sources conflict/are ambiguous on whether live government verification is required. | UAT cannot prove identity-verification adequacy without the authoritative validation contract. | Decide live API versus format/checksum validation, provider, outage handling and evidence retention before execution. | |
| Superadmin | NFR-AUDIT | Every write is durably audited and an audit failure cannot produce an unaudited success. | VisaReady Final Doc Admin.docx §10 audit requirement | All administrative roles | WF-SA-14 | UAT-SA-AUD-001, UAT-SA-AUD-004 | Partially Covered | Atomic persistence architecture is not specified, but fail-closed business outcome is mandatory. | Unaudited writes create compliance and investigation gaps. | Confirm atomic/transactional audit mechanism and recovery runbook. |
| Superadmin | NFR-DPDPA | Personal-data erasure and legal consent are controlled, irreversible/versioned and evidentially logged. | VisaReady Final Doc Admin.docx §10 DPDPA requirement | Admin, Customer | WF-SA-05, WF-SA-09 | UAT-SA-USR-005, UAT-SA-CMS-008 | Partially Covered | Legal retention, erasure SLA and final legal copy require approval. | Incomplete privacy fulfillment can breach DPDPA obligations. | Obtain legal approval for data map, retention, consent and erasure evidence. |
| Superadmin | NFR-PERF | Dashboard loads within three seconds and list views support at least 50 rows under agreed UAT conditions. | VisaReady Final Doc Admin.docx §10 performance requirements | Admin, Analyst | WF-SA-03 | UAT-SA-ANL-007 | Partially Covered | Dataset size, concurrency, geography and percentile are not specified. | An unbounded performance criterion cannot be objectively accepted. | Approve environment, dataset, concurrent users, network profile and percentile. |
| Superadmin | NFR-PRIVACY | PII is masked in lists and fully visible only in authorized detail contexts. | VisaReady Final Doc Admin.docx §10 privacy requirements | Admin, Support, Analyst | WF-SA-03, WF-SA-05 | UAT-SA-ANL-008, UAT-SA-USR-001, UAT-SA-USR-002 | Partially Covered | The field-level masking matrix by role/export is not supplied. | Excess list/export disclosure exposes customer PII at scale. | Approve field-by-role masking matrix for UI, CSV, logs and notifications. |
| Superadmin | NFR-SEC | HTTPS, JWT, RBAC and inactivity controls protect privileged sessions. | VisaReady Final Doc Admin.docx §10 security requirements | All admin roles | WF-SA-01 | UAT-SA-AUTH-008 | Partially Covered | Inactivity timeout, token lifetime/refresh and supported TLS policy are not fixed. | Weak session controls expose privileged access. | Approve timeout, token rotation/revocation and transport-security baseline. |
| Superadmin | NFR-AVAIL | The platform targets 99.5% availability, but system-health/APM implementation is excluded from Lite. | VisaReady Final Doc Admin.docx §10 99.5% availability List of external APIs or third-party integrations required.docx system health/APM out of scope | Business Owner, Operations | Needs clarification | No measurement window, exclusions, monitoring source or evidence method is approved in the current scope. | Availability cannot be objectively accepted without telemetry and a calculation contract. | Approve SLI/SLO window, exclusions, telemetry source and future monitoring scope. | ||
| Cross-App E2E | AD-07 | Agency KYC validation and approval activate the agency with initial credits while customer-data editing remains off by default. | VisaReady Final Doc Admin.docx §5 AD-07 | Authorized Admin, Prospective Agency Admin | E2E-WF-01 | UAT-E2E-001 | Partially Covered | GST/PAN verification method and approved initial-credit amount are not final. | Incorrect approval can activate an unverified agency or grant the wrong commercial value. | Approve the KYC verification policy, failure handling, initial-credit amount, and default edit-right state. |
| Cross-App E2E | AD-15 | Verified customer deletion requests enter a reviewed queue, progress through deletion or anonymization, and are communicated to the customer. | VisaReady Final Doc Admin.docx §5 AD-15 | Customer, Authorized Privacy Admin | E2E-WF-08 | UAT-E2E-008 | Partially Covered | Retention categories, verification evidence, deletion SLA, and dependency-exception policy are open. | A request can be lost, prematurely erased, or falsely reported complete. | Approve the deletion request state machine, verification evidence, SLA, retention schedule, and exception owner. |
| Cross-App E2E | AD-16 | DPDPA erasure is an irreversible cross-module controlled job with customer notification and audit evidence. | VisaReady Final Doc Admin.docx §5 AD-16 | Authorized Privacy Admin, Erasure Worker, Customer | E2E-WF-08 | UAT-E2E-008 | Needs clarification | Legally retained records, derived-data scope, completion SLA, and retry ownership are unspecified. | Incomplete or excessive erasure creates serious privacy, legal, and operational exposure. | Obtain legal approval for the data map and retention and operational approval for job recovery. |
| Cross-App E2E | AD-20 | The country catalogue uses unique identity, active state, and approved metadata, and inactive countries are hidden from new journeys. | VisaReady Final Doc Admin.docx §5 AD-20 | Configuration Admin, Customer, Agency User | E2E-WF-10 | UAT-E2E-010 | Partially Covered | The launch catalogue, URL owner, propagation boundary, and in-flight behavior are client inputs. | Channels can offer unsupported destinations or disagree on active configuration. | Approve the launch catalogue, metadata owner, effective-time policy, and in-flight migration behavior. |
| Cross-App E2E | AD-26 | Dynamic forms support validation, conditions, preview, version and effective date, with consistent cross-channel propagation. | VisaReady Final Doc Admin.docx §5 AD-26 Admin Stitch AD26 variants | Configuration Admin, Customer, Agency User | E2E-WF-10 | UAT-E2E-010 | Partially Covered | Final field catalogue, ranges, cache SLA, and in-flight migration policy are open. | Different channels can collect inconsistent or invalid application data. | Approve field/range content, effective timezone, cache behavior, and record-version migration. |
| Cross-App E2E | AD-32 | Fund-parking detection uses OCR evidence, an approved recent-credit threshold, a penalty, and a valid-proof waiver. | VisaReady Final Doc Admin.docx §5 AD-32 | Customer, Agency User, Authorized Admin, OCR and Scoring Services | E2E-WF-11 | UAT-E2E-011 | Needs clarification | Lookback, aggregation, threshold, penalty, proof types, reviewer, and waiver audit policy are not final. | Wrong risk treatment can materially distort a customer's score and report. | Approve the calculation, proof catalogue, review authority, penalty, and waiver/rescore trigger. |
| Cross-App E2E | AD-34 | Published document checklists combine ordered mandatory base documents with the applicable user-type overlay across consuming journeys. | VisaReady Final Doc Admin.docx §5 AD-34 | Configuration Admin, Customer, Agency User | E2E-WF-10 | UAT-E2E-010 | Needs clarification | The final base and user-type overlay lists and in-flight checklist policy are not supplied. | Missing or inconsistent checklists can block valid applications or permit incomplete evidence. | Approve all checklist content, ordering, mandatory flags, and version-migration behavior. |
| Cross-App E2E | AD-42 | The B2B and B2C plan catalogue controls price, period, quota, carry-forward, activation, and deactivation behavior. | VisaReady Final Doc Admin.docx §5 AD-42 | Plan Admin, Existing Customer Subscriber, Prospective Customer | E2E-WF-18 | UAT-E2E-018 | Needs clarification | Final catalogue values, renewal, carry-forward, deactivation boundary, and existing-entitlement treatment remain inputs. | Deactivation can wrongly remove paid value or continue selling an unavailable product. | Approve the complete plan lifecycle, effective boundary, in-flight orders, successor plans, expiry, and carry-forward. |
| Cross-App E2E | AD-49 | Business events map deterministically to approved active notification channels and templates. | VisaReady Final Doc Admin.docx §5 AD-49 | Notification Admin, Agency User, Customer | E2E-WF-14 | UAT-E2E-014 | Needs clarification | The final event, recipient, channel, idempotency, and retry matrix is unresolved. | Wrong or duplicate communications can expose data or misstate application status. | Approve the event catalogue, audience, channel, preference override, retry, and delivery-state contract. |
| Cross-App E2E | AD-52 | Authorized refund decisions require eligibility and reason, execute through the gateway, and update customer and financial state. | VisaReady Final Doc Admin.docx §5 AD-52 | Authorized Support User, Customer, Finance User | E2E-WF-06 | UAT-E2E-006 | Needs clarification | Partial-refund eligibility, fees, entitlement reversal, accounting documents, and notification rules are incomplete. | Refund errors can duplicate money movement or leave customer, invoice, and entitlement states inconsistent. | Approve refund eligibility, amount, fee, entitlement, invoice or credit-note, and notification policy. |
| Cross-App E2E | AD-53 | Razorpay reconciliation classifies matched, mismatched, and pending records and safely handles delayed or duplicate events. | VisaReady Final Doc Admin.docx §5 AD-53 | Finance or Support User, Razorpay, Customer | E2E-WF-05 | UAT-E2E-005 | Partially Covered | Settlement cadence, tolerance, mismatch owner, and closing evidence are not defined. | Delayed or duplicate events can grant duplicate entitlement or leave paid customers without value. | Approve reconciliation cadence, match keys and tolerance, resolution ownership, and closure evidence. |
| Cross-App E2E | AD-62 | Super Admin generates and allocates promo codes, Agency distributes them, and eligible Customer redemption waives one configured transaction under use, cap, and expiry rules. | VisaReady Final Doc Admin.docx §5 AD-62 | Super Admin, Agency User, Customer | E2E-WF-09 | UAT-E2E-009 | Needs clarification | Allocation commitment, customer binding, timezone, caps, waiver scope, and delivery recovery are unresolved. | Weak promo controls can create unauthorized free transactions or inaccurate usage. | Approve allocation semantics, code scope, customer and agency binding, caps, expiry timezone, waiver, and notification recovery. |
| Cross-App E2E | AD-64 | Terms, Privacy Policy, and Disclaimer are versioned, effective, published, and capable of forcing durable customer re-consent. | VisaReady Final Doc Admin.docx §5 AD-64 | Content Admin, Existing Customer, New Customer | E2E-WF-12 | UAT-E2E-012 | Needs clarification | Final copy, effective timezone, decline experience, session boundary, and retention need legal approval. | Users may continue under stale legal terms or lack defensible consent evidence. | Obtain legal signoff for copy, effective time, decline/defer handling, session gating, and consent retention. |
| Cross-App E2E | AD-70 | Super-Admin-only maintenance mode blocks non-admin business channels, preserves recovery access, shows an approved message, and auto-disables at scheduled end. | VisaReady Final Doc Admin.docx §5 AD-70 | Super Admin, Lower Admin, Agency User, Customer | E2E-WF-13 | UAT-E2E-013 | Needs clarification | Timezone, active-session, lower-Admin, API, drain-versus-reject, and cache behavior are not final. | Inconsistent maintenance enforcement can allow partial writes or prevent recovery access. | Approve role access, session and API handling, write boundary, timezone, message, and cache invalidation. |
| Cross-App E2E | AG-R011 | Agency data and direct record actions are tenant- and permission-scoped with no cross-agency disclosure. | Agency PRD role and ownership model and Screens 5-6 shared-record mappings | Agency A User, Agency B User, Agency Sub-User | E2E-WF-16 | UAT-E2E-016 | Partially Covered | Tenant isolation is implicit rather than stated as one atomic requirement. | Cross-agency leakage exposes customer identity, documents, scores, and commercial data. | Add an explicit agency-tenancy and direct-object-access security requirement. |
| Cross-App E2E | AG-R012 | WhatsApp outreach generates a unique agency-code link, maps the customer, and pre-fills permitted conversational data. | Agency PRD Screen 7 External API document: WhatsApp Business API | Agency User, Customer | E2E-WF-01 | UAT-E2E-001 | Partially Covered | Credentials, templates, final signed-link format, expiry, and abuse controls are client inputs. | A weak or incorrect referral link can misattribute customers or expose application data. | Approve link signing, expiry, replay, templates, consent, and provider configuration. |
| Cross-App E2E | AG-R020 | Agency can manage the approved maximum co-applicants while only the primary applicant is individually scored. | Agency PRD Screen 6 co-applicant controls and §4.2 | Primary Customer, Agency User | E2E-WF-17 | UAT-E2E-017 | Needs clarification | Maximum party size and final per-credit treatment remain unresolved across sources. | Incorrect limits or scoring can block families or create unauthorized charges and reports. | Approve one maximum party size and one primary/co-applicant score, credit, and report model. |
| Cross-App E2E | AG-R021 | Documents remain on one shared record with visible OCR state; valid extraction may prefill and failed extraction remains recoverable. | Agency PRD Screen 6 and Screen 7 External API document: OCR and cloud storage | Customer, Agency User, Authorized Admin | E2E-WF-15 | UAT-E2E-015 | Needs clarification | Permanent OCR failure, manual fallback, retry limit, and confidence review thresholds are not final. | Integration failure can falsely complete evidence or overwrite customer-confirmed identity data. | Approve OCR review, retry, permanent-failure fallback, and manual correction rules. |
| Cross-App E2E | AG-R026 | Agency-set application statuses drive the Customer timeline and approved cross-channel status communications. | Agency PRD Screen 6 status table and notification rule | Agency User, Customer, Authorized Admin | E2E-WF-01 | UAT-E2E-001 | Partially Covered | The complete allowed-transition and reversal matrix is absent. | Out-of-order or inconsistent status can mislead customers and operations. | Approve allowed prior/new state transitions, correction authority, and event notification mapping. |
| Cross-App E2E | AG-R030 | An authorized Agency user purchases a configured credit pack through the payment gateway; success updates wallet and creates an invoice. | Agency PRD Screen 9 External API document: Razorpay | Agency Admin, Razorpay, Finance User | E2E-WF-01 | UAT-E2E-001 | Partially Covered | Final packs, tax, currency, gateway configuration, and payment methods are client inputs. | Incorrect recharge can grant wrong credits or create unreconciled financial records. | Approve release pack values, taxes, currencies, payment methods, and Razorpay configuration. |
| Cross-App E2E | AG-R042 | Super Admin allocates a promo, Agency receives and distributes it, and an eligible Customer redeems it for the configured fee waiver with tracked usage. | Agency PRD §6.1 flow and Appendix B AD-62 | Super Admin, Agency User, Customer | E2E-WF-09 | UAT-E2E-009 | Needs clarification | Allocation defaults, email template, code scope, and mock recharge-bonus conflict remain unresolved. | An ambiguous promo model can create unauthorized discounts and inaccurate agency attribution. | Confirm the customer fee-waiver semantic and approve allocation, delivery, code scope, and usage rules. |
| Cross-App E2E | AG-R044 | Super Admin configuration changes propagate consistently to Agency and Customer journeys. | Agency PRD Appendix B tables B.1 and B.3 | Configuration Admin, Agency User, Customer | E2E-WF-10 | UAT-E2E-010 | Needs clarification | Effective time, caching, propagation SLA, and in-progress versioning are unspecified. | Different application channels can apply contradictory requirements and calculations. | Define configuration versioning, effective time, cache invalidation, propagation SLA, and record migration. |
| Cross-App E2E | AG-R046 | Agency, Customer mobile and web, and Super Admin use one shared application record with consistent ownership, fields, states, score, report, and co-applicants. | Agency PRD product overview, §§4 and 8, and Appendix B | Customer, Agency User, Authorized Admin | E2E-WF-01, E2E-WF-03 | UAT-E2E-001, UAT-E2E-003 | Partially Covered | Simultaneous-edit conflict policy and synchronization SLA remain unspecified. | Forked or stale shared records can corrupt applications, scores, reports, and ownership. | Approve field ownership, concurrency conflict, synchronization SLA, and offline reconciliation. |
| Cross-App E2E | AMEND-S-1 | Phase-1 Customer Conclusion includes the approved review link https://qr.link/9bpJ5L. | Amendment sheet Sheet1 row 3, s-1, 15/07/26 | Customer | E2E-WF-01 | UAT-E2E-001 | Needs clarification | Placement copy, target behavior, and eligible Conclusion outcomes are not stated. | An incorrectly placed or exposed review link can confuse customers or solicit reviews at the wrong outcome. | Confirm exact placement, display copy, navigation behavior, and eligible granted or rejected outcomes. |
| Cross-App E2E | CUS-EXT-OCR | OCR extracts supported passport and financial evidence, exposes reviewable confidence or failure, and never silently overwrites customer-confirmed values. | External API document: passport, bank-statement, and fund-parking OCR Customer PRD §4.7, §4.14, and §4.20 | Customer, Agency User, Authorized Admin, OCR Service | E2E-WF-15 | UAT-E2E-015 | Needs clarification | Provider, field map, confidence thresholds, supported layouts, retry, review routing, and permanent-failure behavior are unspecified. | False or silent extraction can corrupt identity, evidence, risk, and scoring outcomes. | Approve OCR provider, field map, thresholds, review controls, supported documents, retry, and fallback. |
| Cross-App E2E | CUS-EXT-RAZORPAY | Razorpay handles customer payment, delayed and duplicate webhook reconciliation, and refunds idempotently. | External API document: Razorpay Customer PRD §4.15 | Customer, Razorpay, Support or Finance User | E2E-WF-02, E2E-WF-05, E2E-WF-06 | UAT-E2E-002, UAT-E2E-005, UAT-E2E-006 | Needs clarification | Final gateway configuration, payment state machine, refund policy, entitlement reversal, tax, and accounting documents are incomplete. | Payment integration errors can charge without value, duplicate value, or misstate refunds and revenue. | Approve the payment and refund state machines, idempotency keys, entitlement rules, tax, invoice or credit-note treatment, and reconciliation operations. |
| Cross-App E2E | CUS-EXT-STORAGE | Cloud storage protects owned uploads and reports and supports recoverable failure without duplicate or false business completion. | External API document: cloud storage Customer PRD §4.14 and §4.16 | Customer, Agency User, Authorized Admin, Cloud Storage | E2E-WF-15 | UAT-E2E-015 | Needs clarification | Provider, encryption, malware controls, URL expiry, retention, deletion propagation, and retry contract are unspecified. | Storage failure or weak ownership can lose evidence, leak PII, or falsely complete a checklist. | Approve storage provider, security, lifecycle, malware, signed-link, retention, deletion, and retry requirements. |
| Cross-App E2E | CUS-PRD-4.13-CODE | An optional active six-digit numeric agency code maps the whole existing application at any step and referral links prefill that attribution. | Customer PRD §4.13 and appended code answer Customer Stitch Agent ID and Referral screens | Customer, Agency User, Authorized Admin | E2E-WF-03 | UAT-E2E-003 | Partially Covered | Stitch uses alphanumeric examples that conflict with the approved six-digit numeric rule. | Inconsistent code format or partial mapping can misattribute or fork a customer's application. | Replace mock examples and enforce one six-digit numeric namespace across all channels. |
| Cross-App E2E | CUS-PRD-4.13-LINK | An agent-created application links to a later matching verified customer identity and remains one shared record. | Customer PRD §4.13 Account Linking and §4.17 shared record | Agency User, Customer, Support or Admin | E2E-WF-04 | UAT-E2E-004 | Needs clarification | Email/mobile precedence, identity collision, field ownership, review owner, and concurrency policy are unspecified. | Unsafe matching can cause account takeover, data disclosure, or duplicate applications. | Approve matching precedence, collision hold/review, resolution evidence, customer messaging, and concurrency rules. |
| Cross-App E2E | CUS-PRD-4.13-LITE | Lite uses five factors and returns only Low, Medium, or High with a disclaimer, without Final-only numeric score, risks, flags, penalties, or paid report content. | Customer PRD §4.13 and §5.3 Customer Stitch Preliminary Eligibility Score | Direct Customer, Scoring Service, Authorized Admin | E2E-WF-02 | UAT-E2E-002 | Needs clarification | Exact Lite thresholds are open and the mock incorrectly exposes numeric score and factor values. | A numeric or risk-bearing Lite result can mislead customers and leak paid functionality. | Approve thresholds and align every Customer and Admin representation to the non-numeric Lite rule. |
| Cross-App E2E | CUS-PRD-4.14-FUND | Configured recent-deposit analysis raises fund-parking risk and valid source-of-funds proof can waive the corresponding penalty. | Customer PRD §4.14 and appended fund-parking answer | Customer, Agency User, Authorized Admin | E2E-WF-11 | UAT-E2E-011 | Needs clarification | Threshold wording, lookback, recurring-deposit treatment, timezone, proof validation, and flag-clear trigger remain open. | Incorrect detection or waiver can unfairly lower or inflate a customer's Final outcome. | Approve the formula, lookback, timezone, recurrence, accepted proof, reviewer, and rescore trigger. |
| Cross-App E2E | CUS-PRD-4.15-PROMO | A promo must be valid, available, and correctly scoped to waive the configured customer transaction and produce proper usage and invoice evidence. | Customer PRD §4.15 and appended promo answer | Customer, Agency User, Super Admin | E2E-WF-09 | UAT-E2E-009 | Needs clarification | Waived line items, code lifecycle, agency/customer binding, single/multi-use caps, expiry timezone, and delivery template are inconsistent or absent. | Weak validation can permit unauthorized free transactions or wrong-agency redemption. | Approve waiver scope, binding, caps, lifecycle, expiry timezone, fallback, and invoice treatment. |
| Cross-App E2E | CUS-PRD-4.16-REPORT | Advance VisaMatrix contains approved intelligence and recommendations, is non-guaranteeing, branded, watermarked, and verifiable by report ID and QR. | Customer PRD §4.16 and §5.4-5.5 | Direct Customer, Agency User, Authorized Admin | E2E-WF-02 | UAT-E2E-002 | Partially Covered | Template order, intelligence configuration, watermark asset, metric counts, and verification access rules are not final. | An incorrect or unverifiable report can misstate readiness and damage customer trust. | Approve the complete report template, factor presentation, reason codes, branding, QR access, and verification contract. |
| Cross-App E2E | CUS-PRD-4.4 | Current legal documents require full review and one consent, with customer, policy version, and timestamp durably recorded. | Customer PRD §4.4 and appended legal content | Existing Customer, New Customer, Content Admin | E2E-WF-12 | UAT-E2E-012 | Needs clarification | Final copy, re-consent policy, effective timezone, and decline/defer behavior need legal approval. | Incomplete consent evidence creates compliance exposure and permits use under stale terms. | Approve final versions, effective boundary, re-consent, decline/defer experience, and evidence retention. |
| Cross-App E2E | CUS-PRD-4.6.2 | Customer notification categories and in-app, WhatsApp, and email channels can be independently controlled while approved business events generate communications. | Customer PRD §4.6.2 External API document: WhatsApp, email, and push | Customer, Agency User, Notification Admin | E2E-WF-14 | UAT-E2E-014 | Needs clarification | Essential-message overrides, templates, channel defaults, and event/channel mapping remain open. | Ignoring preferences can breach trust, while suppressing essential messages can hide material events. | Approve event and category catalogue, essential overrides, channel defaults, templates, and retry behavior. |
| Cross-App E2E | CUS-PRD-4.6.3-DELETE | Customer deletion is a reviewed request, not immediate, and submission and completion are communicated. | Customer PRD §4.6.3 External API document: deletion confirmations | Customer, Authorized Privacy Admin | E2E-WF-08 | UAT-E2E-008 | Needs clarification | Retention, SLA, pending-account behavior, verification evidence, and retained audit fields are open. | Immediate, incomplete, or uncommunicated deletion can violate DPDPA and break customer records. | Approve the complete request, review, queue, erasure, retention, failure, and notification state machine. |
| Cross-App E2E | CUS-PRD-4.6.8 | Customer Plan shows current state, validity, usage, history, renewal or change entry points, and invoices. | Customer PRD §4.6.8 | Existing Customer Subscriber, Support User, Plan Admin | E2E-WF-18 | UAT-E2E-018 | Partially Covered | Final displayed fields and inactive-plan renewal, upgrade, expiry, and successor behavior are not approved. | Customers can lose paid entitlement or receive misleading plan and invoice information. | Approve status and usage fields plus inactive-plan expiry, renewal, upgrade, and successor behavior. |
| Cross-App E2E | CUS-PRD-4.7A | Multi-applicant mode captures supported relationships, completion, removal protection, capacity, and a pre-commercial completion gate. | Customer PRD §4.7a Customer Stitch Family Management | Primary Customer, Agency User | E2E-WF-17 | UAT-E2E-017 | Needs clarification | Five co-applicants plus primary versus five total, relationship proof, and mandatory fields are unresolved. | Wrong capacity or completion rules can block a family or permit incomplete paid processing. | Approve the maximum party size and full relationship, proof, mandatory-field, removal, and completion matrix. |
| Cross-App E2E | CUS-PRD-4.7A-TOKEN | Only the primary receives an individual score and co-applicant completion is not a VisaScore; commercial treatment follows one approved party model. | Customer PRD §4.7a, §4.15, §5.3, and appended pricing | Primary Customer, Agency User, Finance User | E2E-WF-17 | UAT-E2E-017 | Needs clarification | Sources conflict among primary-only token, per-passport token, and combo separate-score/report models. | Ambiguous commercial treatment can overcharge, undercharge, or produce unauthorized scores and reports. | Approve one primary/co-applicant score, token, price, report, and invoice entitlement table. |
| Cross-App E2E | CUS-PRD-5.3-RESCORE | A material application data change is required before rescore and the application-scoped allowance and charging limit are enforced. | Customer PRD §4.13, §4.16a, §5.3, and appended answers | Customer, Agency User, Scoring Service | E2E-WF-11 | UAT-E2E-011 | Needs clarification | Main text and appended answer conflict on paid and terminal behavior after the one free regeneration. | Wrong counters can create free misuse, overcharging, or blocked remediation. | Approve the exact original/free/paid/terminal count, qualifying changes, counter reset, failure rollback, and party scope. |
| Cross-App E2E | CUS-PRD-6.2 | Customer personal and financial data is ownership-scoped, protected, integrity-checked, and handled under approved privacy, residency, and retention controls. | Customer PRD §6.2 | Customer, Agency User, Authorized Admin | E2E-WF-04, E2E-WF-16 | UAT-E2E-004, UAT-E2E-016 | Needs clarification | Encryption standards, residency, retention, third-party boundaries, identity collision, and measurable security evidence are incomplete. | Weak identity or ownership controls can expose high-risk personal, financial, and document data. | Approve measurable identity, encryption, residency, retention, third-party, signed-link, and security-audit controls. |
| Cross-App E2E | EXT-EMAIL | Transactional email supports observable business delivery and recoverable failure without duplicating the underlying event. | External API document: transactional email | Customer, Notification Admin, Email Provider | E2E-WF-14 | UAT-E2E-014 | Needs clarification | Provider, sender domain, templates, delivery SLA, retry, and dead-letter ownership are not final. | False success or uncontrolled retry can hide failed communication or send duplicates. | Approve provider, sender identity, templates, delivery states, retry SLA, idempotency, and dead-letter owner. |
| Cross-App E2E | NFR-AUDIT | Every committed write is durably audited, and audit persistence failure cannot produce an unaudited business success. | VisaReady Final Doc Admin.docx §10 audit requirement | Customer, Agency User, Support User, Super Admin, Analyst | E2E-WF-13, E2E-WF-19 | UAT-E2E-013, UAT-E2E-019 | Partially Covered | Atomic persistence architecture, retention, masking, clock, correlation, export, and recovery runbook are not specified. | Unaudited success or mutable evidence prevents accountability for sensitive cross-application actions. | Approve the atomic audit mechanism, event schema, clock and correlation standard, masking, retention, export, and recovery runbook. |
| Cross-App E2E | NFR-DPDPA | Personal-data erasure and legal consent are controlled, irreversible or versioned as applicable, and evidentially logged. | VisaReady Final Doc Admin.docx §10 DPDPA requirement | Customer, Privacy Admin, Content Admin | E2E-WF-08, E2E-WF-12 | UAT-E2E-008, UAT-E2E-012 | Needs clarification | Final legal copy, data inventory, retention, erasure SLA, decline behavior, and evidence retention require legal approval. | Weak consent or erasure controls create serious DPDPA and privacy exposure. | Obtain legal approval for the data map, retention, legal versions, consent lifecycle, erasure scope, SLA, and retained evidence. |