Revion Crew Board

Updated Wed 16 Sep 2026, 13:57 London, daily refresh. Partial sources: today's 12:57Z scheduled collection came back blind on Slack (the channel list and all 8 merchant and payout channels), the prod DB (all six tracked merchants, plus a JSON decode error on the raw read) and TG Core Engineering, the same missing-PATH signature yesterday's board named and asked to fix for good; nobody re-collected it by hand this time. git, Linear and BACKLOG.md answered. Every task below sourced from Slack, the DB or TG carries over unchanged from the 15 Sep 18:32Z read, and no ticks or comments were left on that board.

Top now: confirm the $2,530.07 Apex and Peptide911 payout actually went out today · Seven Sigma needs bank details before Friday's payout or it repeats today's miss · rotate the GuardedPay password after credentials and bank details were posted in Core Engineering

8–10 revenue or trust at stake now 6–7 unblocks money soon ≤5 hygiene / gated

Tim

PM · integration lead
8 Biopep: Casey is trying again, and not one checkout has reached a card
Four sessions since 13 Sep, one of them a $3,277.87 cart, all expired with no payment attempt; the latest ran at 18:33Z yesterday.
today

The domain fix landed in the blind window: the merchant row read https://biopepusa.com as of yesterday's read (it was www at the 2 Sep read). Since 13 Sep mrc_roNy1mlK9Ij5 showed four sessions and zero payment intents: cs_RVasVZH_AAxR1qMea1PK $109.00 and cs_EZO-PKMQnMyecR0VfwTx $3,277.87 (no buyer email), then cs_ZK_B_CCbydE0g6S43ljT and cs_xzPaO8-h-7F5c3TwHr1C, both $69.99 from info@biopepusa.com, the last at 18:33Z. Nobody got as far as submitting a card. That is all unverified today: the DB is down again, so none of it has been re-checked against what actually happened since.

New today, from git only: Nur shipped REV-241, allowing prohibited products at checkout by default for every merchant (PR #461), alongside REV-248, Aadil's idea to keep restricted products in a separate store rather than block them outright. If BAC Water was the wall, as Nur's REV-231 suspected, this may already be down. Nobody has re-run Biopep's cart to check.

Next action

Ask Casey to try the $69.99 cart again today now that REV-241 has shipped, and email him regardless: what he saw on the checkout screen if it still fails. Get Nur's REV-231 answer on BAC Water specifically, since REV-241 changes the default rather than confirming what Biopep actually hit.

8 Answer Jarrod: his contract ends at 8.4, and your Florida line needs checking first
Fifteen days since you promised an answer; the Florida tax code shipped today, but whether Revion is actually registered still is not.
today

As of yesterday's read, #rhp-rhpeptides ended on Jarrod's 1 Sep 05:57Z message: "that text is from the master document, not the one you signed... I will discuss with Aadil today and get back to you." Nothing after it was visible. Your 31 Aug 16:36Z answer to his Washington question rested on three things: Revion is the seller of record, "Revion is registered in Florida today", and sections 8.5 and 8.7. Settlements still carve sales tax out of every payout run (11, 14 and 15 Sep). RHP: 0 sessions since 13 Sep, fee_rate 14. None of that has been re-checked today, Slack is down again.

New today, from git: Nur merged REV-196's Florida suppression code (PR #465, "suppress configured destination states in TaxJar quotes" plus a preflight bypass fix), though the Linear ticket itself still reads [In Progress] because the refund and TaxJar-purge parts of REV-196 are unshipped. That resolves half of the contradiction this task has been chasing: Florida collection should now be off in code, regardless of what you told Jarrod about Florida registration on 31 Aug.

Next action

Check whether a fresh Florida quote now comes back at $0 before replying to Jarrod, since the code changed today. Still get the Florida registration fact and the executed RHP agreement from Aadil, since REV-196 turning tax off does not by itself answer whether Revion is registered.

8 Seven Sigma: get bank details in before Friday's payout
REV-250 gives you two days; Apex and Peptide911 already showed what happens when a merchant transacts before banking verification is on file.
fri

Filed today: REV-250 "Seven Sigma: get bank details before the 18 Sep payout" ([Todo] p1 @tim). No other detail on Seven Sigma is in any readable source today; Slack and the DB are both down, so whether they have transacted yet, what they are owed, or who the contact is stays unverified. The shape is exactly today's top item: a live merchant with a payout coming and a banking step not yet done. REV-244, filed today by Nur, separately flags that Seven Sigma's webhooks are blocked by Cloudflare, so callbacks may not even be arriving for their orders.

Next action

Get Seven Sigma's bank details in before 18 Sep. Read REV-244 alongside this: a merchant whose webhooks never arrive is also a merchant whose payout math nobody has checked.

7 Run the embedded Visa box QA with Narboto: M1 is today
REV-234 names you for it, and Apex, the merchant whose payout was missed, is due to switch to the box by Friday 18 Sep.
today · thu

Filed 15 Sep: REV-233 "Build the embedded Visa box on WooCommerce: live paid order Wed, Apex switched by Fri 18 Sep" ([Todo] p1 @nur) and REV-234 "QA: embedded Visa box on WooCommerce (REV-233) - plan now, run M1 Wed + M2 Thu with Tim" ([Todo] p1 @narbotokerimov). REV-228 keeps the box as the PRIMARY checkout with redirect as the fallback. "Apex" is almost certainly Apex Peptide Supply, live since its 3 Sep application, 19 orders settled 3 to 10 Sep, and paid late today (see Aadil's top item).

New today, from git: REV-242, the chooser card button now reads "Visa" by design (shipped, PR #460), and REV-249 gives Narboto 10 manual QA cases from Nur against the WooCommerce plugin's callback queue (plugin now at 1.2.34). REV-230 (p3) still lists cart-popup orders showing as Guest as unfixed.

Next action

Run M1 today. Before it, agree with Narboto what a pass is (paid order, receipt, Woo order status, customer name on the order, all 10 of REV-249's callback cases), and make "orders show as Guest" a blocker for the Apex switch rather than a p3.

7 REV-251: cross-check the 25 approved September payments against Matt's cancelled orders
Filed today, right after Aadil's green light on the catch-up payout; if any of the 25 overlap orders Matt says were cancelled, Apex gets paid wrong twice in one week.
this week

REV-251 "Apex: cross-check the 25 approved September payments against Matt cancelled orders" ([Todo] p2 @tim), filed today. Matt is almost certainly Matthew Jensen, the Apex contact you and Aadil are about to call (Aadil's top item, the $2,530.07 catch-up). No detail on which orders Matt disputes is in any readable source today. REV-226's webhook fix, merged but still needing a reconcile sweep per Nur's task, is the same failure class: webhook timeouts have already cancelled paid orders once.

Next action

Get the list of cancelled order numbers from Matt on your call, and check none of the 25 approved payments were built from an order Woo shows cancelled.

6 Halo: the $358.16 went out; get bank references for everything Halo was owed
Andrew confirmed "others got paid" on the 14 Sep run, but the 27 Aug $1,139.16 has no bank reference anywhere, and the 14 Sep run carried Halo at exactly the 1 Sep draft's amount.
this week

As of yesterday's read, #ach-payouts-production showed: 11 Sep run, Halo $1.32, Zen $801.06; 14 Sep run, Halo $358.16 (Mercury ••••2806), Narboto inc $0.09, Zen $2,491.16; Andrew, 15 Sep 13:12Z: "others got paid". The 1 Sep draft was also $358.16. If those are the same two orders, the 1 Sep draft was either never sent or sent and never recorded, and in the second case Halo has now been paid twice. The 27 Aug $1,139.16 (9 orders) had not appeared in any run since, and no reference for it was visible. None of this has been re-checked today; Slack is down again.

Next action

Ask Andrew for the bank references of the 27 Aug and 1 Sep Halo drafts and of the 15 Sep send, check each one is recorded in Revion, then close REV-163 with Aadil.

6 Best Peptide: their team left our Slack channel on 11 Sep
"Manconsultantsllc's Team has removed themselves from this channel", 0 sessions since 13 Sep, dev silent since 20 Aug: this looked like a merchant walking away.
today

As of yesterday's read, #best-peptide-lab: your 31 Aug 09:06Z follow-up offered 20 minutes to run the first embedded order together, no reply, then Slackbot, 11 Sep 09:44Z, the team removed themselves. Merchant row: active, banking approved 2 Sep, contact dev@guardedpaypro.com, fee 12, 0 sessions and 0 orders since 13 Sep. Halo's consultancy left its channel the same way on 23 Aug and Hudaifa came back, so it was not final as of yesterday, but nobody at Best Peptide could read that channel then. None of it has been re-checked today; Slack is down again.

New today, unconfirmed: REV-247 asks Nur to rotate a "GuardedPay" password after credentials leaked in Core Engineering. That name matches this merchant's dev@guardedpaypro.com contact, though nothing in today's sources confirms the two are the same account.

Next action

Email dev@guardedpaypro.com, since Slack no longer reaches them: ask straight whether they are still integrating, and offer a slot after Thursday's M2 to put the embedded box on bestpeptidelab.com with you watching.

6 Core Research Peptides (Sean Finck): approved at least; make sure he is not the next Apex
A #core-research-peptides channel existed as of yesterday, and today's payout miss came from merchants set live before banking verification was part of going live.
this week

app_uHyTgAc1QXxFQKBW (coreresearchpeptides.com) was under review from 1 Sep. As of yesterday's read, channels appear at approval: Synergy, Vyal and Halo Labs USA each had one while still only approved. His current status is not in any readable source today, DB is down again. REV-214 (verify callback, activate, then send portal credentials) is still open at p1.

Next action

onboarding-check.sh app_uHyTgAc1QXxFQKBW once the DB is reachable. If he is live, confirm banking_approved before his first balance matures; if he is only approved, set him live with banking verified first (REV-144 now gates this by default, see Nur's section).

5 Kiyora terminated on 13 Sep without one transaction: close it cleanly, ask why
Andrew acknowledged the termination notice, but as of yesterday's read the merchant row was still status=active with banking approved.
this week

#kiyora-peptide-llc, 13 Sep 15:30Z, Andrew: "We confirm receipt of Kiyora Peptide, LLC's notice of termination dated September 13, 2026... As Kiyora did not process any transactions through the Revion platform, there are no processed transactions, settlements, chargebacks, refunds, transaction-related losses, or termination reserve to reconcile." Yesterday's DB read: mrc_zinhzQp6eyBC status=active, 0 sessions. Setup had been verified end to end on 31 Aug (Apple Pay and card, both refunded) and her only reply after that was "Thanks so much". Why a working merchant left without trying a single sale is in no source, and the DB is down again today to check whether the row changed.

Next action

Close the account (keys off), send the effective date Andrew promised, and ask one question: what stopped Kiyora switching Revion on. The same reason may be sitting with Best Peptide and RHP.

4 Resolve QA billing ticket 4SMZBX4M… + run the REV-60 cleanup script
Test noise reached money ops yesterday: a $0.09 Narboto inc test payout landed in Andrew's 14 Sep production run.
this week

Whether the ticket is resolved is still unverified, today's read has no billing-inquiry rows either. As of yesterday's read: the 14 Sep run listed Narboto inc at $0.09 to a test bank, Andrew refused to send it, Aadil asked Nur to remove all test accounts from payouts, and Nur agreed. REV-253, today's QA daily, is filed straight to Backlog rather than Todo.

Next action

revioncaps.com/admin/billing-inquiries, Resolve, note "QA daily test, no action". Locally: source ~/RevionCaps/creds.sh && python3 ~/RevionCaps/linear_cleanup_rev60.py (idempotent; it also comments on REV-170).

3 REV-127: close it, you shipped it on 24 Aug
The ticket still says In Progress (unchanged again today), but you told Halo "done and live" on 24 Aug (plugin 1.2.27).
this week

#halo-peptides, 24 Aug 14:36Z: "done and live. Every new order now gets a private order note 'Revion payment link: <url>' plus an order meta field _revion_checkout_url that Sufyan can read programmatically... Already active on your store (plugin 1.2.27)." REV-127 is still [In Progress] p2 @tim, untouched since 2 Sep, including in today's Linear pull. Payment-link work has moved to the merchant portal: REV-235 (test Send Link end to end, p1) and REV-104 (operators create links).

Next action

Close REV-127 with that message as proof, or write on it what is left. A shipped ticket left In Progress makes the open list lie.

3 REV-252: decide on a backend reviewer, hire or interim AI review on every PR
Filed today at p3; Nur shipped six tickets alone today with nobody else reviewing the code before it reaches production merchants.
this week

REV-252 "Backend reviewer: hire, or interim AI review on every PR" ([Todo] p3 @tim), filed today. No detail beyond the title is in any readable source. Today's git alone carries eleven merges, one engineer (Nur) on all of them, into a codebase now handling live payouts for a dozen merchants.

Next action

Pick a direction, hire or an AI-review gate on every PR, and file which one under REV-252.

Done since yesterday: nothing closes for certain today, Slack and the DB stayed down so none of yesterday's open items could be re-verified. No marks were left on the 15 Sep board.

Aadil

commercial
9 Apex and Peptide911: make sure the $2,530.07 landed, then call both
Both merchants had to ask where their money was; no payout went out because their banking verification step was never run.
today

As of yesterday's read, #ach-payouts-production: Andrew 16:19Z, "when do you show payouts starting for apex peptide supply they said they had transactions sept 4-7?"; 16:22Z, "peptide 911 wants to know there status as well". Nur, TG 17:48Z: "Two merchants transacted with matured, payable balances but no payout went out because their banking verification step had not been run. Both are now verified." Apex Peptide Supply $2,267.28 (19 orders settled 3-10 Sep); Peptide911 $262.79 (3 matured entries, with about $8.3k gross still settling from their 62 orders). The payout message went up at 18:06Z ("Pay on or after: Sep 16"), and Tim gave the green light at 18:29Z. None of this has been re-checked today, Slack is down again, so whether the transfer actually landed is still open.

New today: REV-251 asks Tim to cross-check these 25 approved payments against orders Matt says were cancelled, filed right after your green light, so confirm the transfers went out AND that none of the 25 need pulling back.

Next action

Confirm with Andrew that both ACH transfers went out and the bank references are recorded in Revion. Then call Matthew Jensen (Apex) and James Votraw (Peptide911) yourself: what happened, the exact amount, and that the rest now pays automatically. Apex is also the merchant switching checkout on Friday (REV-233), so the same call sets that up.

8 Unlock non-Visa cards on the MID before Friday's Visa-only box ships wider
REV-233 puts a Visa box on Apex by Friday 18 Sep, and as of yesterday declines still told buyers "Please use another Visa card".
this week

The wall was measured on 2 Sep: $380 and $361 non-Visa declines in five days. As of yesterday's read, 15:00-18:20Z: 10 production attempts across merchants, 5 authorized, and the card declines returned "Your card was declined. Please use another Visa card or contact your card issuer." Seven merchants that applied 3-11 Sep were live as of yesterday, all behind the same wall. No brand-enablement ticket is in today's Linear pull either.

New today: REV-242 shipped, the chooser button now reads "Visa" everywhere by design, matching the wall rather than hiding it (PR #460). REV-230 keeps "merchant-configurable card label" and the Guest-order bug open as separate, unshipped asks.

Next action

With Andrew/Ignacio: what enables Mastercard, Amex and Discover on the NMI MID, and by when. Give Nur a date before Friday's Apex switch, since today's live order already ships Visa-only by design.

7 Synergy is live; Vyal and Halo Labs USA still need confirming
All three were approved in the last five days; set the remaining two live with banking verified so neither becomes the next Apex.
this week

As of yesterday's read: "Synergy Research, LLC" (synergy-labs.uswholesalepeptides.com, mrc_LLEYN7Q4l9fC) applied 10 Sep, approved; "Vyal Labs LLC" (vyallabs.com, mrc_PA2TX_ACHQq5) received 11 Sep, approved 12 Sep 13:31Z; "Halo Labs USA LLC" (halolabsusa.com, mrc_f4LFsn8VaAaJ, contact Alice Rewoldt) received 13 Sep, approved 14 Sep 07:04Z. Halo Labs USA is a different business from Halo Peptides (different contact and domain), keep the two apart in payouts and in REV-231.

New today: REV-245 confirms Synergy Labs has been live since 15 Sep and asks Nur to watch its first real order end to end, so that piece is already underway. Vyal and Halo Labs USA still have no confirmation in any readable source today, the DB is down.

Next action

For Vyal and Halo Labs USA: banking verified, fee confirmed, set live, welcome posted, first test order watched. For Synergy, already live, watch that first order lands clean (REV-245).

7 Confirm which agreement Jarrod signed, and whether Revion is registered in Florida
Tim cannot answer RHP without the executed contract, and today's code ship only answers half of what he needs.
today

As of yesterday's read: Jarrod's copy ends at 8.4 (31 Aug 23:48Z). Tim promised on 1 Sep to discuss it with you that day; the channel had been silent since. Tim's 31 Aug message told him "Revion is registered in Florida today" and tagged you to review Washington registration timing. RHP had not transacted since its $598 order on 2 Sep. None of that has been re-checked today, Slack is down again.

New today, from git only: Nur merged the Florida suppression code (PR #465, REV-196), though the ticket stays [In Progress] since the refund and TaxJar purge steps are unshipped. That is the tax-collection half of Tim's question answered from the code side; the registration fact and the executed agreement are still only yours to give him.

Next action

Send Tim the executed RHP agreement and one line on Florida, registered or not, plus your call on an addendum or accepting Jarrod's position. REV-196 shipping today does not answer either question.

7 Two merchants walked in the blind window: chase the at-risk ones by phone
Kiyora gave notice on 13 Sep and Best Peptide's team left our channel on 11 Sep, both without a real sale; Biopep and RHP were next in line as of yesterday.
today

As of yesterday's read, the first full read since 2 Sep showed: Kiyora terminated (Andrew acknowledged 13 Sep 15:30Z, "did not process any transactions"); Best Peptide's team removed themselves from #best-peptide-lab 11 Sep 09:44Z, 0 sessions since 13 Sep; Biopep had four checkouts since 13 Sep and none reached a card; RHP had 0 sessions since 13 Sep. None of it has been re-checked today, Slack is down again, so treat all four as still open until proven otherwise.

Next action

By phone this week: Best Peptide (are they still in?), Biopep's Casey (with Tim, once REV-231 says what is refused, or once REV-241's default change is confirmed as the fix), Jarrod (after the Florida answer). One call to Kiyora to ask why they left.

7 Settle Nur's pending payment
Nineteen days, and today alone he shipped six more tickets closed on top of yesterday's payout-miss cleanup.
today

Open since 28 Aug; Nur asked again on the morning of 29 Aug. Whether his payment went out is still unverified, TG is down today so the thread cannot be checked.

Today alone, from git: six more of his tickets shipped and closed, REV-191 (payout message address), REV-196's Florida suppression code, REV-241 (prohibited products default), REV-242 (Visa button label), REV-227 (checkout expired sender) and REV-144 (banking verified gate), on top of yesterday's payout-miss cleanup and REV-172's reconciliation series.

Next action

Send it, confirm in the thread.

6 VAPI outbound-calls decision (with Tim)
Prod holds live calling credentials with no TCPA gates, one env flag from a compliance incident, and it is still filed nowhere.
this week

As of yesterday's read, VAPI_PRIVATE_KEY etc. were set on revioncaps-prod; calls were held off only by VAPI_OUTBOUND_ENABLED=false, and vapi-outbound.ts had no calling-window, DNC or consent gates. No VAPI ticket appears in today's Linear pull either. The buyer base behind it keeps growing with more merchants live.

Next action

Either unset the prod keys or commission the TCPA gates, and file whichever it is.

5 REV-163: close it once Halo's bank references are confirmed
The channel is restored and Halo is being paid and trading; what is left is proof the 27 Aug draft was paid.
this week

As of yesterday's read: Hudaifa rejoined #halo-peptides on 31 Aug, no messages from Halo since; Andrew confirmed the 14 Sep run went out ("others got paid"); the 27 Aug $1,139.16 had no visible bank reference. REV-163 is still [Todo] p2 @aadil in today's Linear pull, untouched since 2 Sep.

Next action

Once Andrew confirms the references, a short note or call to Hudaifa on what was paid and when; then close REV-163.

5 REV-164: rotate the A@ Google password posted in TG
A live admin mailbox credential was posted in plain text in the group chat twenty days ago, and it is not the only leak now.
this week

REV-164 sits below today's top-50 Linear window too (last seen updated 27 Aug), so its state is unverified rather than closed. TG is down today so whether the message was deleted cannot be checked.

New today, and separate from this: REV-247 asks Nur to rotate a different leaked credential, a "GuardedPay" password plus bank details also posted in Core Engineering, filed at p1. Two live credential leaks in the same channel in three weeks is worth a word to the team about not pasting secrets there at all.

Next action

Rotate it, delete the message, close the ticket.

5 E-sign: REV-144 shipped and settled the question by default, DocuSign stays
The decided DocuSeal switch (REV-187) still has no owner, and the banking-verified gate that just shipped never waited for it.
overtaken

Decided in TG on 31 Aug: DocuSeal replaces DocuSign seats, filed as REV-187 ([Backlog] p3 @unassigned). REV-87 (move e-sign to DocuSign) is also still open. On the five 2 Sep contracts: Epic Wholesalers (epicpeptideslab.com) is live, Pura Peptides has a Slack channel, and Planet, Fit Aminos and Sports Tech appear in no readable source.

New today: REV-144 (banking verified as a gate to LIVE) shipped, closing the question by default before REV-187 or REV-87 ever got an answer. Whichever e-sign tool gates onboarding now, it is DocuSign by default since nobody picked DocuSeal in time.

Next action

Say whether DocuSign-by-default is fine to keep, or whether REV-187 still needs doing properly. Then chase Planet, Fit Aminos and Sports Tech yourself.

3 Pick the homepage variant (A/B/C), or close the tickets
REV-174 has sat at p4 since 12 Sep: either the letter stopped mattering or nobody picked one.
blocked on you

Variants live in the "Revion Home Variants" artifact (REV-101, [In Progress] @tim). No letter in any readable source. The brand-identity pass has been live since 7 Sep (#406).

Next action

Reply with a letter in Core Engineering, or say the redesign is parked so REV-174 and REV-101 can close.

Done since yesterday: nothing new closes for certain, Slack and the DB stayed down. REV-144 shipped today and settles the DocuSeal-vs-DocuSign question by default, covered above rather than closed outright. No marks were left on the 15 Sep board.

Nur

engineering
9 Payout gap: prove no other live merchant is owed money right now
Apex and Peptide911 went unpaid because banking verification was never run; today's fix (REV-144) closes the gap going forward, not the merchants already live.
today

As of yesterday's read: your TG 17:48Z, matured balances, "no payout went out because their banking verification step had not been run"; Slack 18:03Z, "i am forgot turn on banking details of this merchants"; 18:17Z, "Tripple checked only 911 and apex for today also i turn on payouts to all merchants with transactions". REV-221 shipped 14 Sep (enroll every merchant in automatic payouts). Applied before it and live as of yesterday: Apex (3 Sep), Bioscience Peptides (3 Sep), Veri 7 labs (3 Sep), Epic Wholesalers (4 Sep), Research Chemical (4 Sep), Peptide911 (6 Sep), Viltrumite (11 Sep). Zen appeared at $801.06 then $2,491.16 over overlapping windows, and Halo's 14 Sep $358.16 equalled the 1 Sep draft, both still open double-pay risks as of yesterday. None of this has been re-checked today, the DB is down again.

New today, from git: REV-144 shipped (PR #458, verify payout banking during Set live), so merchants set live from today should not repeat this failure by construction. That does not cover Seven Sigma, whose banking is still Tim's open item (REV-250, due 18 Sep), or the older cohort REV-221 already back-filled. REV-244, also filed today, separately flags Seven Sigma's and Bioscience's webhooks as Cloudflare-blocked, so "no payout went out" could be hiding behind "no callback ever arrived" for those two.

Next action

Post one list in #ach-payouts-production: every live merchant, banking_approved, matured unpaid balance, last payout reference. Confirm the Zen and Halo runs do not double-count recorded payouts. Read REV-244 first: a blocked webhook could be masking the same gap REV-144 just closed.

8 REV-233: embedded Visa box, live paid order today, Apex switched by Friday
The conversion bet now has dates, and the first merchant to get it is the one paid late today.
today

Filed 15 Sep: REV-233 "Build the embedded Visa box on WooCommerce: live paid order Wed, Apex switched by Fri 18 Sep" ([Todo] p1), with Narboto's REV-234 QA plan (M1 today, M2 Thursday with Tim). REV-228 keeps the box as the PRIMARY checkout with redirect as fallback; the CHIPS-bound embed shipped 10 Sep. "Apex" is almost certainly Apex Peptide Supply: live since its 3 Sep application, 19 orders settled 3-10 Sep, and its first payout missed until today.

Shipped today: REV-242, the chooser button now reads "Visa" by design (PR #460), and REV-241, prohibited products now allowed at checkout by default (PR #461, see REV-231 below). REV-230 (p3) still leaves the cart-popup Guest-order bug and the configurable-label ask open.

Next action

Hit Narboto's M1 today, treat Guest orders as a blocker for the Apex switch, and state before Friday what a non-Visa buyer sees in the box.

8 Your own fix may have just answered this, or contradicted REV-232
REV-241 now allows prohibited products at checkout by default, the same day REV-232 still asks Narboto to prove restricted items get refused.
today

As of yesterday's read: REV-231 "Check: Halo still shows what they sell with product names hidden; confirm Biopep's BAC Water refusals" ([Todo] p1 @nur). Biopep (mrc_roNy1mlK9Ij5) since 13 Sep: 4 sessions, all expired, 0 payment intents ($109.00, $3,277.87, and two $69.99). Halo, running with names hidden, was converting: 3 authorized orders since 13 Sep. None of that has been re-checked today, the DB is down again.

New today, and this is the one to reconcile first: you shipped REV-241, "allow prohibited products at checkout by default" (PR #461), alongside documenting a new PROHIBITED_PRODUCTS_MODE setting, and REV-248 (Aadil's idea, keep restricted products in a separate store) points the same direction. That is a plausible, deliberate fix for Biopep's stuck cart if BAC Water was the wall. It is also in direct tension with REV-232, filed yesterday and still open, which asks Narboto to prove a restricted item is STILL refused with the product-name alias on. One of those two is about to be wrong depending on what PROHIBITED_PRODUCTS_MODE actually defaults to per merchant.

Next action

Say plainly whether REV-241 was the agreed answer to REV-231, or an engineering change that got ahead of the compliance question. Then pull the refusal reason for Biopep's four sessions once the DB is back; if REV-241 already unblocked BAC Water, tell Tim so he can ask Casey to try again.

8 REV-244: Cloudflare blocks Seven Sigma's and Bioscience's webhooks, callbacks never arrive
Two live merchants, no callback delivery; REV-226 already proved a blocked webhook can cancel a paid order, and Seven Sigma is two days from its first payout deadline.
today

REV-244 "Seven Sigma and Bioscience: Cloudflare blocks our webhook, callbacks never arrive" ([Todo] p2 @nur), filed today. Bioscience Peptides (mrc_gUkKa0d4TClA) has been live since its 3 Sep application; Seven Sigma is new today, named only in Tim's REV-250 (bank details due before the 18 Sep payout). Neither merchant's order state can be trusted while their callbacks never land, the exact mechanism REV-226 already found cancelling paid Apex orders.

Next action

Find what Cloudflare is blocking (WAF rule, rate limit, bot check) and get an allowlist or bypass in today. Until then, treat both merchants' Woo order states as unverified against Revion's own records.

8 REV-247: delete the leaked credentials, rotate the GuardedPay password
Credentials and bank details sat in plain text in Core Engineering; unclear yet if this is Best Peptide's dev@guardedpaypro.com contact or a different account.
today

REV-247 "Delete the credentials and bank details posted in Core Engineering, rotate the GuardedPay password" ([Todo] p1 @nur), filed today. No detail on how long it was exposed or who posted it is in any readable source; TG is down today so the message itself cannot be checked. "GuardedPay" matches Best Peptide Lab's contact domain, dev@guardedpaypro.com, though nothing confirms the two are the same account. This is the second credential leak in Core Engineering in three weeks: REV-164 (still open, Aadil) covers an admin Google password posted twenty days ago.

Next action

Delete the message, rotate the password, and check whether anything was accessed with it while it was live. Then raise with the team: secrets do not go in that channel, full stop.

7 REV-196: the code shipped today, but is Revion actually registered in Florida?
Tim told Jarrod "Revion is registered in Florida today"; the ticket that says stop collecting until registered just shipped its suppression code.
today

REV-196 "Turn OFF Florida sales-tax collection until registered: $0 FL quotes, refund collected tax, purge TaxJar test transactions" ([In Progress] p1 @nur), still open in Linear despite today's ship. Merged today: PR #465, "suppress configured destination states in TaxJar quotes" plus a fix so the suppression is not bypassed during address preflight. That covers the "$0 FL quotes" half of the ticket; the refund and TaxJar-purge halves are not named in any commit. Sales tax has been excluded from settlements in every payout run since 11 Sep regardless, so this changes what buyers see at checkout, not what merchants were paid. Tim told Jarrod on 31 Aug that "Revion is registered in Florida today", which is what this whole ticket contradicts.

Next action

Confirm a fresh Florida quote comes back $0. Then either refund what was already collected and purge the TaxJar test transactions to close the ticket, or get the registration fact from Aadil first if the suppression turns out to be wrong.

7 REV-214 is still open; REV-144 shipping today should stop the pattern repeating
Today's fix, from git: banking verified is now a gate at Set live, so the gap that stranded Apex and Peptide911 should not recur.
this week

Correction to yesterday's board: REV-214 ("verify callback, activate, then send portal credentials") was not closed for good; as of yesterday's read it was still [Todo] p1. REV-144 ("banking verified + agreement signed as gates to LIVE") shipped today (PR #458), closing the specific gap today's missed payouts came from: merchants set live before your fix had no banking check at all. Merchants set live from today should get it by construction.

Next action

Say REV-214 is done or say what is left; it should not still be open once REV-144 covers the same ground. Add the standing Slack alert for any live merchant without banking_approved, since REV-144 gates new merchants but does not retroactively flag old ones.

7 Both halves of the webhook fix are merged now; the reconcile sweep is the missing piece
REV-226's outbox-lease bound and REV-227's expired-sender fix both shipped; nobody has yet reconciled the orders already cancelled by the bug.
this week

REV-226 ("Webhook timeouts cancel PAID Woo orders (Apex): faster retry + plugin ack-then-process + reconcile") has two merges now: #455 (ack-then-process, known yesterday) and #457, "bound delivery lifetime within outbox lease", merged today. REV-227 ("checkout.expired webhooks failing platform-wide") also shipped and closed today, PR #464. Apex is almost certainly Apex Peptide Supply, a live merchant paid late today. The reconcile sweep for orders cancelled after a successful charge is still not named in any commit.

Next action

Confirm #455 and #457 are both promoted to production, then run the one-off reconcile of Apex orders Revion shows AUTHORIZED and Woo shows cancelled, and give Aadil the result before his call to Apex.

6 REV-189 left the open list: prove an 8.5% merchant actually settles
Pura Peptides, contracted at 8.5% on 2 Sep, now has a Slack channel; at the last code read the system accepted only 12 or 14.
this week

REV-189 has been missing from the open list since the blind window, and no commit names fee rates. Code at the 2 Sep read: zod locks feeRate to 12|14 in three places, sandbox-provisioning-client.ts:66 refuses other values, and settlement.ts guards fee_rate IN (12, 14) twice. As of yesterday's read the channel list included pura-peptides; Pura's application and fee_rate were not in that read either.

New today, same merchant: REV-246 asks you to post Pura's NMI batch cutoff time in UTC, a blocked item from REV-236, filed p3. Neither ticket confirms Pura's fee_rate.

Next action

Check Pura's merchant row: if it went live at 12 or 14 against an 8.5 contract, tell Aadil before its first payout; if 8.5 is stored, prove it passes both settlement guards. Separately post Pura's NMI cutoff time for REV-246.

6 REV-169: credentials email lies about payments being off
Seven merchants that applied 3-11 Sep are live and three more are approved; unless the template changed without a commit naming it, each was told processing is disabled.
this week

emails.ts:368 carried the line at the 2 Sep read. REV-169 is [Backlog] p2 @nur in today's Linear pull too, and no commit names it. REV-214 ("...then send portal credentials") is still open on the same send path.

Next action

One template edit alongside REV-214: what is live, what is pending, what the merchant does next.

5 Domain traps: Research Chemical applied as www, and Veri 7's domain carries an invisible character
Biopep's row is fixed, but two merchants live since early September arrived with the kind of domain that broke RHP's and Kiyora's first checkouts.
this week

As of yesterday's read, Biopep now reads https://biopepusa.com. Application websites: Research Chemical LLC https://www.researchchemical.com; Veri 7 labs https://veri7labs.com followed by a zero-width U+2060 character, invisible on screen and enough to break an exact origin match if it was copied into the merchant row. Whether either row carries the application value is unverified, the DB is down again today.

Next action

Read both merchant rows once the DB is back and fix by single-field update if needed; then normalise domains at registration (strip invisible characters, fold www) so the next merchant cannot arrive broken.

5 Fix failing support admin alerts
Support pings may still be silently lost; the evidence is nineteen days old and no commit has touched it.
this week

support_admin_alert emails to support@send.revioncaps.com showed [failed] repeatedly from about 28 Aug. As of yesterday's read the email rows covered only Halo's merchant emails, which delivered, so the support path was still unverified then too. REV-146 (error log + Slack) is [Todo] p2 in today's Linear pull.

Next action

Compare the sending domain on send.revioncaps.com with the delivered revioncaps.com alerts and say which one is wrong.

5 Tim's ordered conversion list: the funnel report would have caught Biopep on day one
REV-165 (daily funnel and decline reasons per merchant) is still p2 while one merchant had 0 of 4 sessions reaching a card as of yesterday.
this week

As of yesterday's read: 10 attempts, 5 authorized, 3 card_declined, 1 insufficient funds, 1 in review; Biopep 4 sessions and 0 intents since 13 Sep. Still open in today's Linear pull: REV-165 funnel/decline report (p2), REV-146 error log (p2), REV-142 silent-merchant alert (p2), REV-145 plugins page (p2), REV-173 telemetry null (p4), REV-104 operator payment links (p2).

Next action

REV-165 first: a daily per-merchant line of sessions, intents, authorizations and decline reasons. It would also settle the REV-231/REV-241/REV-232 question above with real decline reasons instead of guesswork.

5 Fee share on partial refunds: reconciliation now acts (opt-in); does it bring the fee down?
REV-172 went from observing reversals to reconciling them; whether fee_cents drops on a partial refund is still stated nowhere.
this week

As of yesterday's read: opt-in NMI reversal reconciliation "and atomic accounting" (#443), linked reversals held before reporting to the ACH generation fence (#445), external refund parent and original payment verified (#448), an exception review queue with opt-in Slack alerts (#452). At the last code read settlement.ts deducted refunded_cents but never recalculated fee_cents down, and MFSA 16.4 argues it should. With automatic payouts on for every merchant, the first partial refund on a settled order pays out whatever that math says.

Next action

One line: does #443's accounting reduce the fee share on a partial refund? If not, add it before reconciliation is switched on for real merchants.

4 Surface Slack-channel status in admin (+ resend)
Best Peptide's team left their channel on 11 Sep and no source shows anyone noticed; admin shows neither invites nor departures.
this week

slack_provisioning_status/_error exist on the merchant row but nothing shows them. Departures are just as invisible: Halo's consultancy left #halo-peptides on 23 Aug, and Best Peptide's team left #best-peptide-lab on 11 Sep. Welcome v2 and the setup-pack email both assume the channel works.

Next action

Show invite state and external-member count per merchant in admin, and post to Slack when a merchant's last external member leaves.

4 Put the buyer's phone one click from every complaint
Aadil asked sixteen days ago; it is still not filed.
this week

Asked in Core Engineering 31 Aug 13:48Z: "Would be sick if we had the customers number ready for anyone/me/andrew/pat to call them right away too." The buyer's phone is collected at checkout; the billing-inquiry queue and its alert email do not surface it. No such ticket is in today's Linear pull either.

Next action

Show the buyer's phone on the billing-inquiry admin view and in the alert email; file it in Linear with the LLM pre-check block.

3 REV-174: homepage redesign, p4, still gated on Aadil's letter
The identity pass has been live since 7 Sep; nothing to build until the letter lands or the tickets close.
blocked · aadil

REV-174 [Todo] p4 @nur in today's Linear pull too. REV-101 (the variants, Tim) is [In Progress]. No letter in any readable source.

Next action

Nothing before Aadil's letter; if p4 means parked, say so on REV-174 so REV-101 can close too.

Done since yesterday: in git, six more tickets closed: REV-191 (address in payout messages, #459), REV-242 (chooser button reads Visa, #460), REV-241 (prohibited products allowed by default, #461), REV-217 (QA digest fixes, #462), REV-227 (checkout.expired webhook sender, #464), and REV-144 (banking verified as a gate to LIVE, #458). REV-196's Florida suppression code also merged (#465) though the ticket itself stays In Progress. Eleven merges in one day, all one engineer.

Narboto

QA
7 REV-234: M1 is today, run it with Tim; M2 is tomorrow
REV-249 hands you 10 manual test cases from Nur for the plugin's callback queue on top of the paid-order run.
today

REV-234 "QA: embedded Visa box on WooCommerce (REV-233) - plan now, run M1 Wed + M2 Thu with Tim" ([Todo] p1), filed 15 Sep. The build (REV-233) promises a live paid order today and Apex switched by Friday 18 Sep. REV-230 (p3) still lists the Apex cart-popup Guest-order defect as unfixed. Apex is a live merchant with real orders and a payout that was missed until today, so a failed switch lands on a merchant already let down once.

New today: REV-249 gives you 10 manual QA cases from Nur against the WooCommerce plugin's callback queue, plugin now at 1.2.34 ([Todo] p2 @narbotokerimov). REV-242 also shipped, the chooser button now reads "Visa" by design, so that is one less thing to flag as a defect.

Next action

Run M1 today: paid order, receipt, Woo order status, customer name, refund, one non-Visa card attempt, plus REV-249's 10 callback-queue cases. Agree pass and fail with Tim before you start.

7 PostHog replays: why Biopep's buyers never reach the card form
Four Biopep checkouts since 13 Sep, one worth $3,277.87, ended without a card, and today's engineering change may already answer part of it.
today

As of yesterday's read: Tim (2 Sep) estimated about 9 of 20 real buyers reached the page and never submitted a card, and replay review of those sessions was the next step; no result was visible in any source. Targets from yesterday's read: Biopep cs_EZO-PKMQnMyecR0VfwTx $3,277.87, cs_RVasVZH_AAxR1qMea1PK $109.00, cs_ZK_B_CCbydE0g6S43ljT and cs_xzPaO8-h-7F5c3TwHr1C (both $69.99); Halo cs_a9LY8m_tZClgk0nc2QLs $222.00, expired. None of it has been re-checked today, the DB is down again.

New today, from git: Nur shipped REV-241, prohibited products now allowed at checkout by default, a plausible answer to why Biopep's buyers never reached the card form if a restricted item was the wall. Watch the replays anyway; a policy change is not proof of what actually happened in those four sessions.

Next action

Watch the four Biopep replays first. One line each (stopped at price, trust, card form, refusal, error) to Nur for REV-231 and to Tim before today's M1.

7 REV-232: product-name alias on every screen, restricted items still refused
Today's ship may have moved the goalposts: REV-241 now allows prohibited products at checkout by default, the opposite of what this ticket asks you to prove.
this week

REV-232 "Test: product-name alias on every screen, restricted items still refused with it on" ([Todo] p1), filed 15 Sep, paired with Nur's REV-231 (Halo still shows what they sell with names hidden; Biopep's BAC Water refusals). Halo runs with names hidden and was converting as of yesterday's read: 3 orders since 13 Sep. The older p0 verify ticket for the alias, REV-134, has dropped below today's top-50 window.

New today: Nur shipped REV-241, "allow prohibited products at checkout by default" (PR #461), the same direction as REV-248 (Aadil's idea to keep restricted products in a separate store rather than block them). That may make this ticket's premise, that a restricted item should still be refused, wrong as written. Get this reconciled before you spend the week testing against a rule that just changed.

Next action

Before testing anything: ask Nur or Aadil whether REV-241 was meant to replace this ticket's assumption. If refusal is still the rule for some merchants, get the per-merchant PROHIBITED_PRODUCTS_MODE values first, then test alias on, restricted item added, confirm the refusal on every screen.

6 REV-235: test pay-by-link end to end (portal Send Link, buyer pays, merchant fulfils)
A merchant-portal payment link is money a merchant can take without a working plugin, and it has never been tested end to end.
this week

REV-235 [Todo] p1 @narbotokerimov, filed 15 Sep. REV-104 (operators create payment links) remains open, and #446, merged yesterday, shows authorized payments in the merchant dashboard before settlement, which is where a merchant looks after a link is paid.

Next action

Run it on your own test merchant, not Halo: Send Link, pay with a Visa, check the dashboard shows it (#446), mark it fulfilled, refund; file each break.

5 Test money in production: Halo's six $0.50 orders and Narboto inc's $0.09 payout
Your test merchant reached Andrew's production payout run on 14 Sep, and the six Halo test orders from 31 Aug-1 Sep have no refund on record.
this week

As of yesterday's read: 14 Sep payout run, Narboto inc $0.09 to a test bank account, Andrew refused to send it, Aadil asked for test accounts to be removed from payouts, and Nur promised the next run leaves them out. Halo orders RC-2026-1000228, -232, -233, -235, -236 and -242 (all $0.50) were unrefunded at the 2 Sep read; whether a refund landed since is still unverified, the DB is down again today.

Next action

Refund the six from admin, confirm with Nur that test merchants are flagged out of payout runs, and move $-tests to your own store.

5 /apply defects: REV-93 scanned PDFs plus REV-90, 91 and 92
Three applications came through in four days (Synergy, Vyal, Halo Labs USA), so the door works; scanned PDFs and duplicate applications are what still cost an applicant.
this week

Unchanged in today's Linear pull from yesterday: REV-93 scanned PDFs ([Todo] p2), REV-92 duplicate applications on repeated submission ([In Review]), REV-90 mobile wizard defects ([In Review]), REV-91 guest upload-session defects ([Todo]). REV-186 (store CDR rejection codes) and REV-183 are still unassigned.

Next action

Finish the REV-90 and REV-92 reviews this week; for REV-93, reproduce with a phone-scanned PDF and post the CDR rejection code, which is what REV-186 needs.

5 REV-216: build real WooCommerce + custom QA stores
Touched again today, yet this week's QA (embedded box, alias, pay-by-link) all needs a store that is not a live merchant.
this week

REV-216 [Todo] p2, touched again today in Linear; no detail beyond the status change is in any readable source. Test traffic keeps landing in production money: the $0.09 Narboto inc payout, the six $0.50 Halo orders.

Next action

One Woo store on your own account before today's M1, so REV-234, REV-232 and REV-235 run there instead of on a merchant.

4 REV-253, today's QA daily, is filed straight to Backlog; the seven older opens still make tested and skipped days look alike
Whether that is a process change or an oversight is not stated anywhere.
this week

Open: REV-215 (11 Sep, p1), REV-209 (7 Sep), REV-207 (6 Sep), REV-206 (5 Sep), REV-202 (3 Sep), REV-181 (30 Aug), REV-180 (29 Aug). REV-98 (validate merchant dashboard release 5565719) has been [In Review] since 2 Sep. REV-253 ("QA daily - 2026-09-16", [Backlog] p0) is today's instance, filed directly to Backlog rather than opened as Todo the way REV-238 was yesterday.

Next action

Close or mark-skipped every daily older than REV-253, one line each, and keep closing each daily the same day.

Done since yesterday: nothing confirms closed today; REV-253 (today's QA daily) and REV-249 (10 plugin QA cases from Nur) are both newly filed rather than finished. No marks were left on the 15 Sep board.

Claude

tooling · agents
8 The collector fix still is not permanent: it happened again today, same signature
Yesterday's board named the exact fix; today's 12:57Z run came back blind on Slack, the DB and TG exactly the same way, and nobody applied it.
today

Today's 12:57Z launchd collection came back blind again: Slack (channel list and all 8 channels), the prod DB (all six tracked merchants, plus a JSON decode error on the raw read) and TG Core Engineering all read SECTION UNAVAILABLE, and nobody re-collected by hand this time, so this board carries yesterday's 18:32Z read forward unchanged wherever those three sources are the only evidence. This is the same PATH gap this task flagged yesterday after tracing it to node: command not found in generate.sh, present on 2, 7, 8, 9, 10, 12 and 14 Sep, and the fix, export PATH at the top of collect.sh and generate.sh, was not applied before today's run. git and Linear, which do not depend on that PATH, answered clean both days.

Next action

Export the PATH fix for real this time, then confirm tomorrow's 12:57Z run comes back with Slack, the DB and TG all answering before calling this done.

7 Track the merchants that keep going live outside the collector's list
Seven Sigma and Pura both surfaced in Linear today with no matching entry in the collector's merchant or channel lists.
this week

As of yesterday's read, live merchants included Apex Peptide Supply mrc_Jj7KJ7lPbJSh, Bioscience Peptides mrc_gUkKa0d4TClA, Veri 7 labs mrc_7RFYJXz5hHPT, Epic Wholesalers mrc_i1ZcMuL8KlKJ, Research Chemical mrc_Vhs6nzY0_j-c, Peptide911 mrc_PCV1-S_xcogf, Viltrumite Lab mrc_4oOU2meLCons; none of the seven is in the collector's channel list.

New today: Seven Sigma (Tim's REV-250, Nur's REV-244) and Pura (Nur's REV-246) both surfaced in Linear with no matching entry in the collector's MERCHANTS or CHANNELS lists, the same gap this task already tracks for the other seven.

Next action

Add the seven, plus Seven Sigma and Pura, to MERCHANTS and their channels to CHANNELS in collect.sh (drop Kiyora once closed), then derive both lists from the DB so the next go-live is tracked automatically.

6 Verify today's six merges actually reached production
REV-191, REV-242, REV-241, REV-217, REV-227 and REV-196's code all merged today; whether any of them are running on revioncaps-prod is still unverified.
this week

Sandbox-to-production merges through yesterday: #373 through #453 (listed on the 15 Sep board). Since then, on today's read: #459 (REV-191), #460 (REV-242), #461 (REV-241), #462 (REV-217), #464 (REV-227) and #465 (REV-196's suppression code), all merged today per git. Whether any of them are actually running on revioncaps-prod is unverified; flyctl was unreachable today, the same PATH gap as the Slack/DB/TG collector (see the top Claude item), so a release check could not run even if this session wanted one.

Next action

Once the PATH fix lands, run flyctl releases per app plus the release tag for all six of today's merges, then the Playwright checkout E2E gate on the live sandbox channel. Never place a payment on sandbox.revioncaps.com: prod keys.

5 Live-watch today's first paid order on the embedded box
REV-245 already assigns Nur to watch Synergy's first real order, so this task's job narrows to Biopep and whatever the newer merchants throw up.
today

REV-245, filed today, assigns Nur to watch Synergy Labs' first real order end to end, live since 15 Sep, so that piece of this task is now someone else's. Still open: the embedded box's first live paid order today, Biopep's next attempt (none of four has reached a card as of yesterday), and Vyal or Halo Labs USA's first test order once live. watch-merchant.sh could not be tested today, node and flyctl were both off PATH again.

Next action

Once the PATH fix lands, watch today's embedded-box order live, confirm charge, receipt and Woo order state, and post the result on REV-234.

4 Sandbox E2E proof of billing-alert links
PR #355's deep links have been in production since 28 Aug and are still unproven end to end.

File one labelled Charge inquiry via the sandbox public support endpoint and confirm the alert email carries both admin links. (Claude's live POST was classifier-blocked, so it needs a human-run curl or Tim's go.) It pairs with Nur's failing support_admin_alert item: the same send path would carry it.

4 Daily merchant sweep + chase drafts
Today's sweep found nothing new; Slack and the DB were both down, so this ran on yesterday's read alone.

Slack, the DB and TG all read SECTION UNAVAILABLE today, so there is no fresh merchant signal to sweep; every item on this board sourced from those three carries over from the 18:32Z read on 15 Sep. What did move today came from git and Linear only: six of Nur's tickets shipped, and REV-244, REV-247, REV-250 and REV-251 are new. Drafts go to the owner on this board; nothing is sent from here.

Done since yesterday: nothing, today's blind collection was not re-run by hand, unlike yesterday's 18:32Z recovery. This board's Slack, DB and TG dependent tasks all carry forward unchanged from that 15 Sep read instead.