# Ferry Sales edition handover

## Shared refactor — 14 September 2026

Ferry owns its complete authoring source and exact retained origins. Sales no longer exports or publishes it. Runtime, tests, core migrations and dependency selections are preserved by this conversion. Authoring1.1 includes changed-input diagnostics, retained baseline extraction, mapped comparison and portable adjacent release receipts verified against a clean clone. Source integrity does not establish product or deployment acceptance; the remaining obligations below are preserved.


Read [first-release acceptance](ACCEPTANCE.md) for purpose, unmet release obligations, preserved requirements and the evidence decision rule.

## Current implementation — 12 September 2026

Ferry is the Sales family's intervention-first pipeline edition. Imported source
is `runeditrun/sales-ferry` commit `514272889eab89556e270adf48c3d459e64cbb50`,
with canonical guidance from `f861a0fd43a92eec3b080f66184de386ef6b156e`.
The existing clean-yellow/Roboto Focus and dark rail remain the selected UI.
The earlier `visual/` captures show the pre-improvement shell and are historical,
not a replacement target. The complete source handover remains in
`research/MIGRATION-SOURCE-HANDOVER.md`; `CONTRACT.md` is unchanged.

TanStack Start now owns React documents and `/_serverFn/`; Hono owns `/health`,
`/api` and descendants, `/auth` and descendants, and the loopback demo seed route.
The custom Worker retains scheduled-event ownership. Every protected document
receives the native 302 `/signin` gate. The generated operator loader repeats
native session validation before reading the operator, including client navigation.
Production host validation uses `APP_URL`; unknown documents and missing assets
return real 404s. Development asset paths are explicit and removed from the
production dispatch. No prerender pages are enabled because owner configuration
and native session identity are deployment-dependent.

Production sign-in uses one-use hashed 15-minute magic links, a durable request
throttle, active-operator validation, and signed eight-hour HttpOnly sessions.
GET link inspection does not consume the token: an explicit same-origin POST
confirms it. Removing an operator invalidates their session. Logging out durably revokes that token, including copied-cookie replay. SendGrid is the selected Base module and only
transports sign-in mail; Ferry owns auth semantics and persistence.

Fresh deployments bootstrap an explicit owner, business time zone/currency and
four stages. Pipeline has expandable contact and deal creation forms. Deal Story
has activity planning and qualified customer-commitment forms, all backed by D1. Concurrent activity completion
produces one event and keeps the earliest planned activity after a concurrent
creation.
Contact email normalization and relationship-link validation use the shared
Sales core. Contact collisions are visible; dangling links do not create deals.
New deal, activity and commitment writes reassess health. A scheduled handler
reassesses open deals every 15 minutes. Due entry uses the configured business
time zone and rejects ambiguous/nonexistent daylight-saving times.

## Commands and verification

Use Node 26.8.1 and pnpm 8.15.6. In this edition checkout:

- `pnpm install --frozen-lockfile && pnpm verify`: typecheck, lint, actual shared
  Sales/SendGrid tests, Workers D1/API/auth tests, and Start build.
- `pnpm exec playwright install chromium && pnpm test:browser`: starts the local
  demo, exercises contact → deal → activity → qualified commitment, verifies one
  document across internal navigation, and captures desktop/mobile screenshots.
  `FERRY_BROWSER_URL` targets an already-running local instance; optional
  `PLAYWRIGHT_CHANNEL=chrome` uses installed Chrome.
- `FERRY_OWNER_EMAIL=… FERRY_OWNER_NAME=… pnpm dev`: initializes an empty local owner workspace.
  `pnpm dev:test --port 8798` is the explicit fixture-backed test runtime.
- Production-artifact proof: build with `FERRY_USE_LOCAL_WRANGLER=1 pnpm build`,
  apply local migrations with `pnpm exec wrangler d1 migrations apply DB --local
  --config dist/server/wrangler.json`, run `pnpm exec wrangler dev --local
  --config dist/server/wrangler.json --port 8800`, POST `/__ferry/local-seed`, then
  `pnpm test:artifact` and `FERRY_BROWSER_URL=http://127.0.0.1:8800 pnpm test:browser`.
- `pnpm run setup` and `pnpm run deploy` provision and publish the real deployment.
  Required settings and secret names are in README. They were first checked locally; the subsequent JustEvery pilot below adds
  deployment and one authorized sign-in-email acceptance proof.

Local evidence: 29 Workers tests passed, including the empty-install API journey,
contact collision/dangling-link rejection and concurrent one-use auth redemption;
7 shared component tests passed. The empty ordinary-dev workspace, explicit test runtime, and emitted-Worker browser journeys all
passed with stable `performance.timeOrigin`, no page errors and no failed
responses. Artifact proof passed missing/expired/logged-out/removed-operator/valid sessions
for five document routes, known/unknown APIs and the actual generated no-input
operator function; changed D1 operator data appeared in the next SSR response.
Unknown documents, missing assets, development-only paths and client-bundle
server boundaries passed. These results are executable checks, not a claim that
the entire baseline or contract is satisfied.

The exact current Focus LayerDoc was recovered from the selected source worktree.
A 12ui target alignment run completed with 91.4% DOM coverage; the supplied
artwork and yellow/Roboto style were retained. This coverage measure is not a
pixel-fidelity acceptance result. Browser captures of the new record journey are
in `visual/migration/`. No obsolete blue-shell changes were applied.

## Remaining acceptance

The contract is much broader than this usable initial journey. Stage management,
deal editing/close/reopen, complete activity and commitment lifecycle/version
conflicts, merges/import/export/custom fields, operator settings/invitations,
email reminders, and confirmed follow-up message outbox/dispatch/reconciliation
remain incomplete. The existing Follow-up Send control remains honestly disabled.
Some existing timestamps/displays still need full business-zone coverage.

Health failure visibility, reassessment load limits, all concurrency and idempotency
clauses, complete baseline registration, per-clause reporting, accessibility and
load acceptance remain open. The generated-loader transport matrix is reproducible
but is not yet registered to the shared baseline reporter. There is no release claim. The pilot below adds bounded provider and live-host
evidence; production-load acceptance remains open.

## JustEvery pilot deployed — 12 September 2026

[Live Ferry](https://ferry-sales-pilot-20260912.james-d16.workers.dev) was deployed
from Sales `b32166f4b183431397ea3f9d62cca27d9ff93f9b` / Base
`976859c9c7b50f6e8456d89ba21c975fd4d4e96d`, with a private JustEvery/James owner
identity override. A repeat deployment reused the database and preserved the
real API/browser workflow records. Native auth redemption, session boundaries,
logout revocation, 404s and the persisted activity-completion journey passed.
One authorized sign-in email took the provider-acceptance path; mailbox delivery
is not verified. See `verification/2026-09-12-justevery-pilot/README.md` and its
sanitized `proof.json` for exact resource/version IDs, evidence and limits.

Use **`pnpm run setup`** and **`pnpm run deploy`**: pnpm 8 reserves the shorter
commands for its own built-ins. The full contract acceptance gaps above remain;
the pilot proof adds remote evidence without marking those clauses satisfied.

Pilot follow-up fixes are deployed and verified: operator dates use the authenticated business time zone with zone labels and local “Due today”; changed activity completion immediately reassesses health. All 30 Workers tests, typecheck, lint and production build pass. Live v2 source Sales `8e5e2a4f249e4fc87a794ab796b72d89e2902b74` / Base `1d3ce621240460baa029370b7ef001c4ec67930a` is Worker version `9b5ae1fa-29ca-43d7-9c01-3ea77ef4c72d`. Follow-up browser verification displayed 10:00 am AEST and observed On track → Watching after completion, preserved existing records and revoked harness sessions; no further email was sent. See [final pilot evidence](verification/2026-09-12-justevery-pilot/README.md). Private reusable resource configuration and signing-secret locations are recorded there; no secret values are included.

## Edition source custody — 14 September 2026

This repository now owns Ferry's complete editable source and releases.
`edition.json` selects local components with Base
`bc27ecf55693a68bfa7e8a6aba9fe3ce8883bcfe` and Sales
`b3b195939af1cdfdef3008d878c6cb945e3e0cd6` as exact comparison origins.
`sources.lock.json` retains effective source and tool identity; historical
`composition.lock.json` remains provenance for the original assembly and
existing checks. Sales no longer writes or publishes Ferry. Newer Sales/Base
runtime changes were not adopted during this cutover.

An isolated candidate checkout at `/private/tmp/ferry-cutover-20260914-verify`
installed its frozen lockfile with Node 26.8.1/pnpm 8.15.6. `pnpm verify` passed
(typecheck, lint, manifest, bootstrap, shared components, all 30 Workers tests
in 12 files, and build). `pnpm test:browser` passed contact → deal → activity →
qualified commitment, preserved client navigation, and reported no page errors
or failed responses, with desktop/mobile captures. Canonical local database and
preview state were untouched. Source parity preserves all runtime, tests,
migrations and dependency-lock bytes from canonical
`260ab4993b3b8cf69a137ca287b549cbd71b0680`; only authoring, guidance and package
script metadata change. The final committed source/tool check and clean-clone
release proof belong to the integrated cutover receipt.

Evidence: `/Users/zemaj/.orchestrator/evidence/runeditrun/shared-refactor-20260914/ferry/`.
These local checks do not change first-release gaps, historical pilot evidence,
or establish a new deployment, provider delivery or full contract acceptance.

## Shared onboarding adoption — 18 September 2026

Ferry now adopts Base's standalone onboarding as byte-identical local source in
`scripts/base-onboarding/`. Ferry owns the fields, native local-install adapter,
agent instructions and harbor SVG in `scripts/installer/` and `public/setup/`.
`node scripts/install.mjs` needs no application dependencies to open. One approval
runs the frozen install and ordinary no-fixture `pnpm dev`; sign-in uses Ferry's
existing loopback owner session. Existing bootstrap data remains preserved.
Website evidence may inform a missing business name through agent prefill;
explicit owner edits survive. Currency stays an explicit business choice unless
known from owner configuration. Artwork and remote provider controls are absent:
Ferry has no workspace-art consumer, and deployment remains the existing CLI.

Executed on Node 26.8.1 / pnpm 8.15.6: `pnpm verify` passed types, lint (warnings),
manifest, bootstrap, 7 shared tests, 30 Workers tests and production build.
`pnpm test:onboarding` passed 2 tests. The isolated onboarding browser test passed
empty answers (desktop/mobile), missing-owner-only prefill, and all-answer review
through an actual frozen dependency install, no-fixture development startup,
local sign-in, empty records and exact persisted D1 owner/business/zone/currency.
Screenshots are in `test-results/onboarding/`; temporary apps were stopped.
This verification performed no remote deployment, email or artwork generation.
The source manifest records local components without fabricating a published Base
revision. These checks do not close the first-release acceptance gaps above.

The 18 September launcher acceptance also verified exact acquisition of the
current Beacon and Ferry source snapshots, dependency-free setup awaiting owner
approval, session-bound agent fill, refusal to overwrite an existing destination,
and offline resume preserving answers and owner files. Ferry additionally passed
a fresh install, native local sign-in and empty real database through the launcher.
This is local package acceptance, not public package publication or hosted product
acceptance. The next launch work must preserve these journeys while addressing
the first-release obligations in `ACCEPTANCE.md`; neither edition is release-ready.
