{
  "schema_version": 1,
  "status": "proposed",
  "scope": "weekly-care transaction integrity; architecture model only, not production enums",
  "authority": "FRESH-DELIVERY.md",
  "global_guards": [
    "authenticated_scoped_actor",
    "matching_revision",
    "stable_operation_identity",
    "no_conflicting_committed_effect"
  ],
  "persistence": "Owner-local atomic revision, state, facts, audit and outbox; cross-owner receipts are durable, not a distributed transaction",
  "default_rejection": "No business mutation; audit reason; exact duplicate returns committed receipt without a new transition",
  "machines": [
    {
      "id": "order",
      "owner": "Commerce",
      "initial": "created",
      "terminal": [
        "cancelled",
        "expired",
        "completed",
        "resolved"
      ],
      "states": {
        "created": {
          "meaning": "明确购买意图建立的订单；未形成可执行商业接受",
          "recovery": "查原购买/付款/取消流程，不再造同来源单",
          "timeout": "purchase_acceptance_policy: UNRESOLVED"
        },
        "open": {
          "meaning": "商业接受已成立；资金、每日确认与执行状态分别保存",
          "recovery": "回源协调未决安排/履约/资金；不得据此直接派工",
          "timeout": "order_obligation_policy: UNRESOLVED"
        },
        "cancelled": {
          "meaning": "合法取消的商业终态；包含配送时间确认超时自动取消",
          "recovery": "只推进关联资金/善后，不改本单",
          "timeout": "terminal: no reopening"
        },
        "expired": {
          "meaning": "其他明确商业受理过期的终态；非已付款未确认配送时间的取消路径",
          "recovery": "查关单和退款回执；新购新身份",
          "timeout": "terminal: no reopening"
        },
        "completed": {
          "meaning": "实际交付及本单商业完成条件核实",
          "recovery": "关联售后/调整独立运行",
          "timeout": "terminal: no reopening"
        },
        "resolved": {
          "meaning": "非正常完整交付，实际发生及处置范围已核实关闭",
          "recovery": "后续资金与更正独立记录，不假装全部送达",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "created",
          "event": "accept",
          "to": "open",
          "guard": "accepted_quote_and_verified_funding",
          "effect": "freeze_trade_snapshot"
        },
        {
          "from": "created",
          "event": "cancel",
          "to": "cancelled",
          "guard": "legal_cancel_and_durable_stop_and_instruction_ended",
          "effect": "record_closure_and_release_only_eligible_allocations"
        },
        {
          "from": "created",
          "event": "expire",
          "to": "expired",
          "guard": "non_confirmation_expiry_policy_and_durable_stop_and_no_accepted_delivery",
          "effect": "record_expiry_and_schedule_settlement"
        },
        {
          "from": "open",
          "event": "cancel",
          "to": "cancelled",
          "guard": "legal_cancel_and_durable_stop_and_instruction_ended",
          "effect": "record_closure_and_release_only_eligible_allocations"
        },
        {
          "from": "open",
          "event": "expire",
          "to": "expired",
          "guard": "non_confirmation_expiry_policy_and_durable_stop_and_no_accepted_delivery",
          "effect": "record_expiry_and_schedule_settlement"
        },
        {
          "from": "open",
          "event": "complete",
          "to": "completed",
          "guard": "verified_delivery_and_commercial_closure_conditions",
          "effect": "record_completion_without_asserting_refund_success"
        },
        {
          "from": "open",
          "event": "resolve",
          "to": "resolved",
          "guard": "verified_actuals_and_authorized_nonstandard_disposition",
          "effect": "record_partial_or_exception_disposition"
        }
      ]
    },
    {
      "id": "delivery_instruction",
      "owner": "Demand",
      "initial": "pending",
      "terminal": [
        "expired",
        "withdrawn",
        "revoked",
        "closed"
      ],
      "states": {
        "pending": {
          "meaning": "付款依据核验且订单成立后可提前确认本次范围；不必等到配送前一天",
          "recovery": "回查原确认，按持久截止补扫",
          "timeout": "persisted confirmation_deadline; default delivery date 16:00 Asia/Shanghai"
        },
        "accepted": {
          "meaning": "本版本内容/地址/时间/费用明确确认已接受；无需每日再次确认",
          "recovery": "发布原接受事实；开工仍需执行门禁",
          "timeout": "delivery_window_and_escalation: UNRESOLVED"
        },
        "revoking": {
          "meaning": "要求停止，尚未证实可撤销",
          "recovery": "查同一停止请求；不假称已取消，不再扩大执行范围",
          "timeout": "stop_receipt_deadline: UNRESOLVED"
        },
        "expired": {
          "meaning": "未确认到期；不可复活",
          "recovery": "保持不可执行，协调order.cancel到cancelled及独立资金处置；拒绝补确认",
          "timeout": "terminal: no reopening"
        },
        "withdrawn": {
          "meaning": "待确认安排合法撤销",
          "recovery": "协调原单合法停止/关闭",
          "timeout": "terminal: no reopening"
        },
        "revoked": {
          "meaning": "已接受安排在安全停止后撤销",
          "recovery": "保留原确认记录及停止证据",
          "timeout": "terminal: no reopening"
        },
        "closed": {
          "meaning": "实际履约或异常处置结束",
          "recovery": "保留实际结果，不等同全部送达",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "pending",
          "event": "confirm",
          "to": "accepted",
          "guard": "current_scope_and_explicit_consent_and_funding_and_time_policy",
          "effect": "persist_immutable_consent_and_acceptance"
        },
        {
          "from": "pending",
          "event": "expire",
          "to": "expired",
          "guard": "authoritative_expiry_predicate_and_no_committed_acceptance",
          "effect": "publish_confirmation_timeout_for_order_cancel_without_claiming_money_returned"
        },
        {
          "from": "pending",
          "event": "withdraw",
          "to": "withdrawn",
          "guard": "authorized_withdrawal_and_no_execution_right",
          "effect": "record_withdrawal"
        },
        {
          "from": "accepted",
          "event": "request_revoke",
          "to": "revoking",
          "guard": "authorized_stop_request",
          "effect": "coordinate_stop_no_claim_of_success"
        },
        {
          "from": "revoking",
          "event": "prove_stop",
          "to": "revoked",
          "guard": "durable_fulfillment_stop_receipt",
          "effect": "record_revocation"
        },
        {
          "from": "accepted",
          "event": "close",
          "to": "closed",
          "guard": "verified_execution_terminal_outcome",
          "effect": "record_actual_delivery_or_disposition"
        },
        {
          "from": "revoking",
          "event": "close",
          "to": "closed",
          "guard": "verified_execution_terminal_outcome",
          "effect": "record_actual_delivery_or_disposition"
        }
      ]
    },
    {
      "id": "execution_gate",
      "owner": "Fulfillment",
      "initial": "blocked",
      "terminal": [
        "stopped",
        "finished",
        "resolved"
      ],
      "states": {
        "blocked": {
          "meaning": "有执行范围但条件不足；可为预建记录",
          "recovery": "核验原授权资金和前驱；终止墓碑优先",
          "timeout": "readiness_deadline: UNRESOLVED"
        },
        "ready": {
          "meaning": "范围及依赖已核验，尚未开工",
          "recovery": "开工再核验 fence/质量；不凭旧预览执行",
          "timeout": "scheduled_start_policy: UNRESOLVED"
        },
        "frozen": {
          "meaning": "取得停止优先权，禁止旧执行权继续使用",
          "recovery": "核对全部子任务/现场，再出停止证据；不可静默解冻",
          "timeout": "stop_receipt_deadline: UNRESOLVED"
        },
        "executing": {
          "meaning": "唯一执行权已取得；现场可能正在发生",
          "recovery": "查原作业证据；未知隔离，不重新切配",
          "timeout": "physical_observation_deadline: UNRESOLVED"
        },
        "stopped": {
          "meaning": "该范围永久停止，包括尚未派生任务",
          "recovery": "墓碑拒绝迟到事件/旧 token",
          "timeout": "terminal: no reopening"
        },
        "finished": {
          "meaning": "已核实该范围完整执行结果",
          "recovery": "交付证据发布重试不重复实体动作",
          "timeout": "terminal: no reopening"
        },
        "resolved": {
          "meaning": "已执行部分/异常按实际证据处置关闭",
          "recovery": "不可伪写未发生或恢复旧权利",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "blocked",
          "event": "enable",
          "to": "ready",
          "guard": "valid_consent_and_funding_and_lineage_quota_and_predecessor_stop_if_replacement",
          "effect": "record_generation_and_authorized_scope"
        },
        {
          "from": "blocked",
          "event": "freeze",
          "to": "frozen",
          "guard": "same_gate_revision_and_authorized_stop",
          "effect": "advance_fence_and_block_descendant_start"
        },
        {
          "from": "ready",
          "event": "freeze",
          "to": "frozen",
          "guard": "same_gate_revision_and_authorized_stop",
          "effect": "advance_fence_and_block_descendant_start"
        },
        {
          "from": "frozen",
          "event": "prove_stop",
          "to": "stopped",
          "guard": "all_children_stopped_and_no_unknown_physical_effect",
          "effect": "persist_permanent_stop_receipt"
        },
        {
          "from": "ready",
          "event": "start",
          "to": "executing",
          "guard": "current_fence_and_dependencies_and_quality_and_exclusive_quantity",
          "effect": "consume_execution_right_and_record_attempt"
        },
        {
          "from": "executing",
          "event": "finish",
          "to": "finished",
          "guard": "verified_complete_physical_and_delivery_evidence",
          "effect": "record_actual_quantities_and_proof"
        },
        {
          "from": "executing",
          "event": "resolve",
          "to": "resolved",
          "guard": "authorized_partial_or_exception_disposition_with_verified_actuals",
          "effect": "record_actuals_without_reversing_physical_history"
        }
      ]
    },
    {
      "id": "money_operation",
      "owner": "Commerce",
      "initial": "prepared",
      "terminal": [
        "succeeded",
        "failed_final",
        "abandoned"
      ],
      "states": {
        "prepared": {
          "meaning": "已持久目标及适用额度预留，尚未派发",
          "recovery": "由原目标派发，若放弃需证明无出站可能",
          "timeout": "dispatch_deadline: UNRESOLVED"
        },
        "in_flight": {
          "meaning": "已登记可能产生外部效果的派发",
          "recovery": "查询原目标或幂等投递；不得先标失败释放",
          "timeout": "provider_response_deadline: UNRESOLVED"
        },
        "unknown": {
          "meaning": "外部效果未知；保留资金预留",
          "recovery": "原目标查询、账单核验、限时升级；不盲重发",
          "timeout": "reconciliation_escalation_policy: UNRESOLVED"
        },
        "succeeded": {
          "meaning": "外部资金结果已验证成功",
          "recovery": "通知/记账可重放，资金效果不可重做",
          "timeout": "terminal: no reopening"
        },
        "failed_final": {
          "meaning": "已验证确定失败且排除仍会成功的在途效果",
          "recovery": "受控释放额度；若需再试另建尝试并保护同一业务目标",
          "timeout": "terminal: no reopening"
        },
        "abandoned": {
          "meaning": "未可能产生外部效果的目标被放弃",
          "recovery": "保留放弃证据，旧出站消息不能再发送",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "prepared",
          "event": "dispatch",
          "to": "in_flight",
          "guard": "durable_budget_and_dispatch_intent",
          "effect": "persist_dispatch_intent_before_network_effect"
        },
        {
          "from": "prepared",
          "event": "abandon",
          "to": "abandoned",
          "guard": "no_possible_external_effect_and_dispatch_fenced",
          "effect": "release_eligible_reservation"
        },
        {
          "from": "in_flight",
          "event": "lose_certainty",
          "to": "unknown",
          "guard": "timeout_or_ambiguous_observation",
          "effect": "retain_reservation_and_schedule_query"
        },
        {
          "from": "in_flight",
          "event": "verify_success",
          "to": "succeeded",
          "guard": "authenticated_authoritative_success_for_same_target",
          "effect": "record_money_fact_and_consume_reservation"
        },
        {
          "from": "in_flight",
          "event": "verify_failure",
          "to": "failed_final",
          "guard": "authoritative_final_failure_and_no_inflight_success_possible",
          "effect": "record_failure_and_release_eligible_reservation"
        },
        {
          "from": "unknown",
          "event": "verify_success",
          "to": "succeeded",
          "guard": "authenticated_authoritative_success_for_same_target",
          "effect": "record_money_fact_and_consume_reservation"
        },
        {
          "from": "unknown",
          "event": "verify_failure",
          "to": "failed_final",
          "guard": "authoritative_final_failure_and_no_inflight_success_possible",
          "effect": "record_failure_and_release_eligible_reservation"
        }
      ]
    },
    {
      "id": "replacement",
      "owner": "Commerce",
      "initial": "requested",
      "terminal": [
        "rejected",
        "completed",
        "compensated"
      ],
      "states": {
        "requested": {
          "meaning": "替换请求已登记，原单未必受影响",
          "recovery": "按前驱守卫检查原请求",
          "timeout": "proposal_deadline: UNRESOLVED"
        },
        "stopping": {
          "meaning": "已开始取得并核验旧单停止权",
          "recovery": "查原 gate；冻结成功后不静默恢复旧菜",
          "timeout": "stop_receipt_deadline: UNRESOLVED"
        },
        "old_closed": {
          "meaning": "旧单永久关闭，后继未激活",
          "recovery": "查原资金分配与后继来源；不复活旧单",
          "timeout": "replacement_funding_deadline: UNRESOLVED"
        },
        "funding": {
          "meaning": "已登记后继订单及资金目标，等待条件核实",
          "recovery": "核验原补款、分配与报价；新单不执行",
          "timeout": "replacement_funding_deadline: UNRESOLVED"
        },
        "compensating": {
          "meaning": "停止推进新替换，核验和补偿必要副作用",
          "recovery": "查全部资金/订单/执行效果并升级",
          "timeout": "compensation_deadline: UNRESOLVED"
        },
        "rejected": {
          "meaning": "未改变原执行义务的请求已拒绝",
          "recovery": "展示原单真实仍有效状态",
          "timeout": "terminal: no reopening"
        },
        "completed": {
          "meaning": "后继商业条件已接受，替换完成不等于每日确认",
          "recovery": "查后继独立每日授权和执行结果",
          "timeout": "terminal: no reopening"
        },
        "compensated": {
          "meaning": "无后继执行，必要补偿已验证完成",
          "recovery": "后续重新购买创建新意图",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "requested",
          "event": "reject",
          "to": "rejected",
          "guard": "no_changed_old_obligation_or_external_effect",
          "effect": "record_reason_and_original_obligation"
        },
        {
          "from": "requested",
          "event": "begin_stop",
          "to": "stopping",
          "guard": "unique_predecessor_replacement_right_and_accepted_proposal",
          "effect": "request_fenced_stop"
        },
        {
          "from": "stopping",
          "event": "reject",
          "to": "rejected",
          "guard": "stop_rejected_and_no_old_obligation_changed_and_no_money_effect",
          "effect": "record_actual_execution_progress"
        },
        {
          "from": "stopping",
          "event": "close_old",
          "to": "old_closed",
          "guard": "permanent_stop_and_ended_instruction_and_terminal_old_order",
          "effect": "record_irreversible_predecessor_closure"
        },
        {
          "from": "old_closed",
          "event": "fund_successor",
          "to": "funding",
          "guard": "unique_successor_and_eligible_funding_allocation",
          "effect": "persist_successor_and_funding_goal"
        },
        {
          "from": "funding",
          "event": "complete",
          "to": "completed",
          "guard": "verified_successor_commercial_acceptance_and_predecessor_stop",
          "effect": "expose_successor_waiting_for_its_own_consent"
        },
        {
          "from": "old_closed",
          "event": "compensate",
          "to": "compensating",
          "guard": "authorized_abandonment_or_unrecoverable_successor_conditions",
          "effect": "fence_successor_and_reconcile_original_money_goals"
        },
        {
          "from": "funding",
          "event": "compensate",
          "to": "compensating",
          "guard": "authorized_abandonment_or_unrecoverable_successor_conditions",
          "effect": "fence_successor_and_reconcile_original_money_goals"
        },
        {
          "from": "compensating",
          "event": "verify_compensation",
          "to": "compensated",
          "guard": "successor_absent_or_stopped_and_all_required_compensations_verified",
          "effect": "record_closed_replacement_without_reviving_predecessor"
        }
      ]
    },
    {
      "id": "purchase_batch",
      "owner": "Commerce",
      "initial": "collecting",
      "terminal": [
        "closed"
      ],
      "states": {
        "collecting": {
          "meaning": "已接受购买范围及关联变更，未达范围结束条件",
          "recovery": "推进各订单，不以自然周强制结束",
          "timeout": "batch_end_policy: UNRESOLVED"
        },
        "reconciling": {
          "meaning": "冻结结算范围，核对实际应收/分配/在途资金",
          "recovery": "查原结算目标；未知部分有负责人，可分项核验",
          "timeout": "settlement_deadline: UNRESOLVED"
        },
        "refunding": {
          "meaning": "已确定应退分项，退款结果未全部验证",
          "recovery": "查原退款目标，未知预留不释放",
          "timeout": "refund_escalation_policy: UNRESOLVED"
        },
        "closed": {
          "meaning": "必要交易及退款事实全收敛并核对结清",
          "recovery": "迟到经济事实另建 Adjustment，不重开原批次",
          "timeout": "terminal: no reopening"
        }
      },
      "transitions": [
        {
          "from": "collecting",
          "event": "begin_settlement",
          "to": "reconciling",
          "guard": "defined_batch_end_and_stable_scope_and_replacement_barrier",
          "effect": "freeze_settlement_basis_and_identity"
        },
        {
          "from": "reconciling",
          "event": "refund",
          "to": "refunding",
          "guard": "verified_refundable_allocations_and_unique_refund_goals",
          "effect": "reserve_and_dispatch_original_source_refunds"
        },
        {
          "from": "reconciling",
          "event": "close",
          "to": "closed",
          "guard": "all_obligations_known_and_balanced_and_no_refund_due",
          "effect": "record_verified_zero_refund_settlement"
        },
        {
          "from": "refunding",
          "event": "close",
          "to": "closed",
          "guard": "all_obligations_known_and_balanced_and_required_refunds_verified",
          "effect": "record_verified_settlement"
        }
      ]
    }
  ],
  "policy_revision": "2026-09-29-confirmation-v2",
  "confirmation_policy": {
    "timezone": "Asia/Shanghai",
    "default_cutoff_local_time": "16:00",
    "configurable": true,
    "opens_when": "verified_payment_or_valid_zero_due_and_commercial_acceptance",
    "acceptance_time_relation": "strictly_before_deadline",
    "expiry_time_relation": "at_or_after_deadline",
    "requires_daily_reconfirmation": false,
    "deadline_basis": "delivery_date_and_persisted_policy_snapshot",
    "accepted_instructions_expire": false,
    "timeout_order_event": "cancel",
    "timeout_order_state": "cancelled",
    "timeout_reason": "delivery_time_confirmation_timeout",
    "timeout_service_label": "未正常履约",
    "refund_policy_status": "UNRESOLVED"
  },
  "guard_semantics": {
    "current_scope_and_explicit_consent_and_funding_and_time_policy": "pending; accepted commercial order and verified funding (or valid zero due); current scope/version and explicit consent; authoritative decision time strictly before persisted deadline; selected slot serviceable with enough preparation time; current fee basis valid",
    "authoritative_expiry_predicate_and_no_committed_acceptance": "pending; authoritative decision time at or after persisted deadline; no committed acceptance on same revision; only this instruction/order scope",
    "legal_cancel_and_durable_stop_and_instruction_ended": "user cancellation under pre-cut policy OR persisted confirmation-timeout instruction.expired; in both cases require durable non-executable range and ended instruction; no cancelled order reopening",
    "non_confirmation_expiry_policy_and_durable_stop_and_no_accepted_delivery": "Only a separately defined commercial expiry policy, explicitly excluding delivery_time_confirmation_timeout; require durable stop and no accepted delivery. Undefined other expiry policy does not authorize this transition."
  }
}
