/admin/import (the P4 exit gate) and the P6 grill · two engineering items now carry a hard pre-North ordering: the MPA-queue entry gate and the abandon/create race residualFour pages live: /, /agents, /merchants, /about. Positioning locked, compliance pre-flight integrated.
Favicon, OG card, Vercel Analytics, Resend-backed apply forms, /thank-you confirmation. Forms verified delivering to mark@.
Positioning + content signed off 2026-05-27.
Project relocated to Mark's personal Vercel ownership before the domain swap.
ainsworthpayments.com is LIVEShipped 2026-06-06. Domain now points at the new Next.js site; old static page retired. Closed workstream.
Auth (magic-link, AES-256-GCM sessions, 5 roles), Postgres + PII encryption, Tier 1/2/3 intake, dashboard, uploads, admin flow. In production at merchants.ainsworthpayments.com since 2026-05-17.
Full loop verified end-to-end in prod: signup → 9-step canonical wizard → admin generates filled MPA → send-for-signature → embedded Dropbox Sign → webhook finalize → signed PDF auto-links to I.1 checklist. Banks wired: Merrick, Maverick/TSYS, Synovus, PB&T.
ISO residual portal shipped 2026-05-30. Single + bulk entry, month/range/CSV views, edit + list pages, atomic CTEs with diff-aware audit. Dogfooded in prod against ATR + QuickRefund books.
Tracer shipped: extraction → 7 deterministic rules → readiness verdict (GO/HOLD/NO-GO). Docs-ready workflow trigger shipped 2026-06-04 (email Mark+Jeff inline + iMessage to Mark via local launchd poller every 15 min). 57 fixture tests.
Corduro/Priority template family — 497-of-499 fields shared via corduro-base.ts. Full e-sign loop verified in prod 2026-06-03. Iron Peak's path to bank submission once he finishes the wizard.
Schema + entry pivot + agent CSV + colorblind-safe PDF shipped 2026-05-30. Agent statement = net interchange + net fee × split %. Full vertical dogfooded in prod.
"Application intake" status card on admin merchant page. Migration tool moved 4 merchants from legacy → canonical (Iron Peak, Deep Water, Alpha Peptides, test). 2 legacy remaining by design (Enhanced Wellness, Paragon — already transcribed).
Shipped + live 2026-07-05. Full /api/v1/merchants surface for partner-programmatic intake. Open follow-ups: webhooks, spec v0.2, integration guide.
Live 2026-07-06 → 07-10. Master-merchant orgs with commission-attribution invariants; sub-agents under partners with per-category splits (Model 1); referrers see their referred partner's in-progress pipeline read-only (status-only, no bank identity).
Both live 2026-07-07. Admin abandon/restore archives merchants out of every active + partner surface, restores to prior status. Partner-facing statement→savings analyzer at /partner/analyzer (PDF upload, interchange audit, flat-rate/tiered estimates).
Merged + live 2026-07-08. Placements now own the merchant-placement lifecycle end to end; the legacy bank_submissions path is retired/archived. Deferred list closed empty.
Live 2026-07-10 → 07-13. Remapped to the 6.2026 5-page TRX paper (stale 4-page blobs 409 on send); radio groups, checkboxes, and deal pricing now fill; Acrobat "error 18" fixed for good (MuPDF bake instead of pdf-lib flatten); generated MPAs ship clean (empty-field highlighting opt-in); ISO-level template resolution defaults the picker.
Live 2026-07-13, closed 07-15. TRX packages now sign in parallel: merchant (3 signature lines) + Ainsworth inspector (survey line); Personal Guarantee dropped per TRX paper. Signer resolves from the application's primary-contact party (all banks), with login fallback. First three TRX MPAs fully executed by both signers.
Live 2026-07-12 → 07-15. Partner-level default deal pricing auto-seeds new merchants (trigger, all create paths); admin per-merchant Pricing card overrides it; three models flow into the trx-v2 MPA pricing sections. Shared fieldset + save hook — both editors can't drift. Surcharge / cash-discount stay manual on the MPA.
Merged + live 2026-07-12. Bank-paper mapping fixes, 17 DB CHECK constraints + pricing trigger, load-bearing verify scripts, dual-flow (legacy vs canonical) owner surfaces. Every stored MPA now requires regenerate-before-send (canonical shape versioning).
Live 2026-07-11. Statement phone + card-present% + refund stats collected self-service in the portal and hard-gate TRX MPA generation; owner photo-ID/KYC checklist items now generate for canonical merchants (backfilled); pre-gate submitters see "Update needed" instead of a false "Complete ✓".
Live 2026-07-12 → 07-15. Merchants list gains a Signature column + Awaiting/Executed filters (third status axis); admin-only button catches up act-as-stranded merchants behind a two-layer current-executed-MPA gate; staff-only internal resource audience (also closed a download-route leak).
Live 2026-07-16 → 07-24. /admin/mpa-tracker began as the per-merchant 8-step checklist from intake review → executed MPA → bank submission (steps 1–5 derived live, 6–8 manual, every mutation a single audited CTE, generation-token guard against stale re-adds). Superseded 2026-08-05 — see the re-key card above; the manual steps are gone and the board is derived from placements. /admin/url-tracker is the matching ops board for the Add Location lifecycle.
Live 2026-07-17, deep-link 07-27. Password-gated download links at /secure-files/[token] (7-day expiry, download receipts) replace ad-hoc encrypted-zip email. /admin/secure-send handles one-off sends to bank contacts. The download-receipt email now deep-links back to its own row (?send= highlight + anchor scroll) instead of the bare creation form.
Live 2026-07-23 → 07-24. Existing merchants can add locations without a fresh full application: MCC captured at intake (trx-v2 has no MCC field — the bank assigns it), locations modeled first-class, and all location addenda go out as ONE multi-page Dropbox Sign request rather than N separate ones. Same pass closed the repo-wide gap where /api/admin/* enforced role but not the proxy's admin-domain gate.
Live 2026-07-27. New wet_signed e-sign status for MPAs signed on paper outside the portal and delivered to the bank by hand — its own admin badge + filter chip, executed-PDF download, bank-package attach, and signed-equivalent treatment in the MPA tracker. Driver was the Venture Payment Solutions TRX portfolio — now 10 entities / 30 DBAs after Flask Creative and Hillside Drift were added 07-28 — all backfilled with their real executed applications and placed TRX → Esquire.
Live 2026-07-27. The overflowing 11-link top bar is replaced by a layout-level left rail on both /admin (24 pages) and /partner, sharing one SidebarShell with the rail picked by real session role. Six previously URL-only surfaces gained nav entries. The mobile drawer is a real modal dialog (focus trap, Escape, focus return, breakpoint reset). Colorblind rule honored — every item is icon + label, never color alone.
Live 2026-07-21. Admin-only sample-data demo at /admin/oversight-demo for walking sponsor banks through the monitoring story. Source of truth is the standalone HTML under Merchant Monitoring/ — re-copy and redeploy to update it.
Live 2026-07-31. The VPS portfolio entities were also submitted through a second channel on signed paper applications while still holding in-flight TRX placements — and the old one-in-flight-per-merchant index made that unrepresentable. Migration 2026-07-30-01 (applied to prod before the deploy, since the widened index is what the new conflict arbiter targets) moves it to one in-flight per (merchant, ISO); the placement panel renders every in-flight card and offers a second channel with already-in-flight ISOs disabled; executed e-sign rows displaced by a newer channel keep their download link. Review caught a real leak — the backfill's e-sign title named the ISO and bank, and titles are merchant-visible, so wet-sign titles are now generic and channel identity lives only in placement notes + audit rows. Backfill ran post-deploy and re-verified idempotent: three second-channel placements, three added DBA locations, three paper-signed applications attached.
Live 2026-08-01. First slice of the CRM portal-extension plan. Bank pends stop living in email threads: placement_conditions makes each one placement-scoped state (open → answered → cleared/waived, optionally tagged to a single location), with response threads that carry an author, a timestamp, and an optional document. Open or answered pends now block both approve and activate — a friendly pre-check first, then the same predicate inside the atomic write so a race can't slip a placement past a live condition. /admin/pend-tracker is the work queue, sorted by due date with Eastern business-day overdue math; partners see the bank's verbatim ask on their merchant page and can respond in text (clearing stays admin-only). Placements also gained decision reason codes, reserve %, and an approved monthly cap — soft flags for now, wired to enforcement later. Fixture was the real VPS pend batch; Mark logged the first live pend on Hillside Drift.
Live 2026-08-02. A live merchant account is now a first-class row rather than an implied consequence of an approved placement: merchant_accounts holds one row per merchant account at a processor, unique on (ISO, MID), with at most one live account per merchant/DBA/processor. It carries the processor ids parsed off the VAR sheet, and informal monthly caps that require a provenance note — a cap with no stated source isn't accepted. The registry seeded from the seven Highwire TRX VAR sheets, which also flipped those seven queued TRX → Esquire placements active with their real MIDs; Mark then set all seven caps to $500k/mo. /admin/accounts is the board — live-MID tiles per processor, per-row cap editor, and an automatic flag when a statement descriptor doesn't match the DBA (the Zen Oil lesson, now caught by the tool). The Active book on /admin/placements collapsed to headline counts that click through, and the partner merchants list now shows DBA — four "Members America LLC" rows were otherwise indistinguishable.
Live 2026-08-02. The residual side of the CRM plan: runs, per-payee items, statement-level slices, payability gates, a carry chain, and post-close adjustments over frozen statements. It records payments only and never initiates one — Mark executes the transfer at the bank and keys the reference in. Every amount is integer cents, no floats anywhere. Gate order is agreement → W-9 → floor (a $100 org default, editable in settings); held items wait inside the run, and sub-floor items carry forward visibly to the payee rather than vanishing. A statement side can only be claimed once, which is the structural guard against double-paying. Surfaces: an /admin/payouts board and run detail with a reconciliation strip, W-9 receipt and encrypted payee ACH capture, and partner-visible payout lines that state a floor rollover explicitly.
Live 2026-08-03. The machinery that turns processor files into watched numbers. /admin/import takes a normalized CSV all-or-nothing — any bad row or a control total that doesn't match refuses the whole file with every problem listed — archives the original, and applies it in one transaction. Metrics land as revisioned snapshots that are never edited in place, with the grain (daily vs monthly) part of the row's identity so the two can't be silently mixed in a view; a feed that doesn't report a number leaves it null rather than faking a zero. Thresholds are sourced data, not constants in code — the TRX 1%-or-50 line is seeded with its page reference, and the Esquire program row ships deliberately empty because no bank has stated numbers in writing. Five alert kinds (cap utilization, volume swing, chargeback/refund acceleration, ratio headroom, auth-decline spike) feed an /admin/alerts queue with frozen evidence and a required note to call anything a false positive; critical ones email Mark and Jeff. The Accounts board now prefers per-MID snapshot volume over statement-derived figures.
Live 2026-08-03. The portal's fifth audience: sponsor-bank risk officers get read-only, program-scoped visibility instead of an email thread. A bank_viewer role plus per-program grants resolved fresh on every request, so revoking access beats a live cookie. The surface is a portfolio view (volume against cap, headroom, a standing chip), a merchant deep-dive with trailing-six-month metrics and the resolution history of closed alerts, and frozen monthly standing reports with a PDF. Admins get a thresholds editor, grant management, and a banner-disclosed single-program preview that audits as an admin action. What a bank cannot see is enforced by tests, not habit: economics, partner identity, other-processor volume, and the free-text internal resolution notes are all denied at the SQL level. Standing says "no data" rather than "good" when a number is missing, and an interim watch rule is labeled as Ainsworth's own, never as the bank's.
Live 2026-08-04. Admin-only surface that assembles Fiserv's New Account Credit Package Transmittal from Ainsworth intake and renders it for Fiserv's credit desk. It is deliberately not an MPA, not a bank package, and not a secure send: never signed, never merchant-facing, keyed to the placement rather than the merchant, and regeneration replaces in place. The merchant never sees Fiserv paperwork — Fiserv issues its own application separately, which is why the new fiserv ISO row carries no MPA template at all. The two gates differ on purpose: completeness is soft (Fiserv's own form allows a stated-gaps package, so it generates with an INCOMPLETE banner printed on the PDF — a screen-only marker would vanish the moment the file left the portal — and names the file -INCOMPLETE), while the SSN guard is hard (422): an incomplete package may be sent knowingly, a Social Security number may not be sent at all. Built from two real hand-filled transmittals rather than a spec.
Live 2026-08-04. Headless Chromium in-process replaced the external PDF vendor behind the identical conversion seam, so all four PDF surfaces (Fiserv credit app, bank standing reports, statement analyzer, website screening) changed one import line each. There is no external fallback by design — a render failure returns an error, and the HTML is never shipped off-box. The trigger was the Fiserv credit app: it is the first portal PDF carrying principals' dates of birth and home addresses, and the vendor's data-processing agreement covered only account-level data, not people named inside submitted documents. Page geometry parity is pinned by a script that renders through the real module and asserts the actual page size.
Live 2026-08-05. The MID registry had no creation path since it shipped three days earlier — every row came from a one-time seed, and activating a placement stamped a MID while creating nothing. Importing a bank's VAR sheet now does the whole motion at once: it creates the merchant account with its descriptor and processor ids, seeds the cap, files the PDF, and flips the placement live. That makes it the real replacement for CRM P2 slice 2 rather than a companion to it, and it arrives from the direction the work actually does. Mark's corrections shaped the scope: every channel issues VARs (not just TRX), caps are seeded per MID at the full requested amount (multi-MID exists precisely to obtain higher aggregate capacity), and pends neither block an import nor auto-resolve — a VAR is the bank's own proof the account is boarded, and conditions legitimately outlive activation. The sheet is downloadable by admin, the merchant, and the merchant's own partner; referrers are excluded by construction.
Live 2026-08-05. The Corduro/Chesapeake batch (86 pends across nine lists) proved the P1 board doesn't scale on its own: a pend is only useful where someone is already looking. The list was sorted — on legal name, while rendering "DBA (Legal Name)" — so one string had two writers and merchants filed under the wrong letter; one function now owns the label and the sort that matches it. Search and paging landed with a tiebreak on row id, because a single bank email produces a dozen rows sharing a due date, and without a total order paging repeats one row while skipping another. Pends now appear on the admin merchant page and read-only on the merchant's own dashboard. Two governance calls shaped it: merchant-facing pend text is authored, never the bank's verbatim ask — no summary means the pend is never published, enforced so that the raw ask is a compile error on that surface rather than a convention — and the merchant card shows exactly one placement, since merging across ISOs would let a merchant infer they're being shopped to several banks at once.
Live 2026-08-05, both slices. The 8-step per-merchant checklist is gone; the board is now a fully derived work queue where a row is a placement — the same merchant at TRX and at Corduro are separate chases — and nothing is ticked off by hand. A deal enters when its latest real MPA signature is executed (merchant-scoped by necessity: one signed paper serves every concurrent channel), sits in Awaiting send / Awaiting decision / Awaiting VAR buckets read straight off placement status, and exits when the VAR import takes it live. Day one it surfaced three signed-and-packaged deals that had never been sent — exactly the failure mode the board exists to catch. Slice 2 added notes and dismiss/restore, written by one planned statement shared by the route and its verifier, and removed the hand-typed Activate control entirely: VAR import is now structurally the only way a placement goes live. The legacy tracker's stubs and vocabulary were deleted later the same day; its table survives as history, read and written by nothing.
Live 2026-08-06, both slices. iBill is a new placement channel that fronts TRX's Esquire rails — deals actually run Ainsworth → iBill → TRX → Esquire, modeled as iBill → Esquire with the processor in the middle deliberately invisible. New Highwire deals now default to it; existing TRX placements stay put. The channel brings the portal's sixth MPA paper (a 4-page, 165-field application, SHA-pinned) and, hours later, guided e-sign for it: two signers like TRX — the merchant primary contact on pages 2–4, the sending admin on the page-3 survey inspector line — so iBill deals never needed the wet-sign path the first slice shipped behind. Every print name for the signer of record resolves strictly to the primary-contact party with no owner fallback, which is the first deliberate divergence from the TRX gate. Two traps are worth remembering: the paper's "Return Policy" radio options are misnamed in the form itself (the widget called Home prints NONE, Office prints EXCHANGE) so the mapper selects by render-verified position and must never be "corrected" to match the names; and the send-for-signature allowlist is now derived from the bank registry rather than hand-copied, killing a whole class of skew.
Merged 2026-08-06, backfill applied. Found by a memory sweep rather than a bug report: Enhanced Wellness sat at placement submitted for two months after the bank rejected it and the merchant was abandoned, so the portal believed a live submission existed. Twelve of sixteen abandoned merchants had the same shape. Grilling the real rows changed the design — all twelve were queued, meaning the bank had never seen those deals, so the honest close is withdrawn, not declined. That one word deleted an entire subsystem: the notification outbox fires on submitted/approved/declined/active, and withdrawn sits outside it, so the "suppress the merchant email" machinery the feature was originally framed around was never needed — and a test now counter-proves it by failing if declined ever rejoins the notify list. One writer, three callers: both abandon routes had carried separate inline SQL, so a rule implemented in one was a rule the bulk bar silently broke. Live accounts are never touched — a real MID has a registry row behind it.
Live 2026-08-06. Mark hit an "Activate partner" button on a partner that already existed, and it errored. The grill contradicted all three premises behind the obvious fix: activation had never once succeeded in production (all ten partners were hand-created), the payout engine has never run a single row, and the W-9 field everyone assumed existed was a dead foreign key pointing at a merchant-hardwired table. So activation now resolves three ways — create, link to an existing partner (no second org, no second invite), or blocked outright — and the W-9 is the actual PDF held on the partner record. A payout account name is always required with banking and never defaulted from the org name, because ACH returns on a mismatch. Nothing gates payouts yet: capture first, gate when the first real run happens. The same pass closed an orphan class where a refused activation stranded a partners row — two had reached production and were deleted here. A follow-on shipped hours later: Phase 6.5 had been storing the countersigned agreement PDF since July but nothing ever served it back, so a copy had to be pulled from Dropbox Sign by hand. It is now an audited admin-only download — admin-only because the agreement carries Schedule A, i.e. the partner's whole commission structure.
BEGIN/ROLLBACK is inert over the HTTP database driver — it is stateless and every statement autocommits, so a verify script that believed it was rolling back wrote straight to production (artifacts cleaned up; rollback verification now uses a real client). And a verify harness must execute the production statement rather than a paraphrase: writing a literal where the route binds a parameter hid a bug that 500'd every banking save. Also: the blob library's get() throws on a missing object instead of returning a status, so status-only checks leave an unhandled 500 — the same shape still exists in the VAR-sheet route and should be fixed next time that file is open.Shipped since: docs-ready choke point + MPA data-staleness gate (2026-07-11); local poller now also detects + texts act-as strands (2026-07-16, runs 3×/day). Still specced, not built: external re-upload nudges, Utah LLM judgment pass + standards.ts, scheduled sweep-job backstop, daily digest, bank-match sheet, auto-MPA trigger.
Merged + live 2026-07-04. Editable Schedule A splits, ordered Dropbox Sign agreement flow, manual activation gate. Closes the agent onboarding + payment loop. Remaining: a real signed completion + prod Dropbox Sign plan follow-ups.
With P1 through P5 live and P2 slice 2 closed by VAR sheet import, P6 (activities / the next plan phase) is the biggest remaining slice, and it gets grilled before anything is built. The whole tracker arc that ran 08-05 is finished, so nothing is sitting unmerged and nothing is queued ahead of it. The honest note is that the higher-value work right now is still operational rather than code: get the first real processor month through the import console.
Logged 2026-08-05 and 08-06, both with explicit triggers. (1) The re-keyed MPA queue admits a deal on its executed signature, but a North API submission creates a placement with no signature row — so North deals could never appear on the board at all. (2) The abandon-closes-placements ship left an accepted residual: a concurrent create in a millisecond window can still strand one in-flight placement, and North is precisely the path where a placement write sits downstream of an irreversible external call. Both are harmless today because the North integration is built but uncredentialed and inert. They stop being harmless the moment North is switched on, which is why these carry a hard ordering rather than a priority.
Fourth bank template — own form (not Corduro family). File on hand; field names are noisy auto-generated. ~1-2 hours of mapping work when prioritized.
Hagen API submission. Aaron's responses cleared the path: own production group as sandbox, IP allowlist, 120 req/min. Smallest IRIS slice — validates the integration stack before push (v1.5b).
Account activated, Postman collection saved, research at Merchant Onboarding/MAVERICK_INTEGRATION_v1.md. Integration not yet built. Replaces the PDF pipeline for Maverick-placed merchants.
Schema reconciliation can't start without a fillable Esquire PDF. Need to chase Esquire for one. Less urgent since 2026-08-06: the iBill paper now covers the iBill → Esquire channel end to end, including e-sign, so the deals actually flowing to Esquire today do get a portal-generated MPA. This card is for Esquire's own paper on a direct channel.
Shipped + verified 2026-06-10. Hosted signing (Dropbox Sign emails the merchant a secure link; API Essentials plan, $75/mo, 50 docs/mo — embedded-in-portal signing is gated to the $250/mo tier, deliberately skipped). Synovus + PB&T merchants are walked through 8 guided fields — 4 signatures (officer, personal guarantee, Program Guide confirmation, FinCEN cert) + 4 auto-dates — with print names / title / legal name pre-stamped on the PDF. Mark signed the ZZ TEST package live: all 4 signatures on their lines. Merrick + Maverick keep freeform signing until they get their own placement pass.
Next residual-automation slice — input automation (currently admin enters by hand). Framework first, then per-bank mapping. Note: CRM P4 shipped a generic CSV landing/apply console for metrics, which is a template for this one but not a substitute — residual statements are a different shape.
Three numeric IDs still needed (Tab ID, Label IDs, owners catId). All API-discoverable during v1.5a build — Aaron email is fallback only.
Corduro / TRX parsers — highest-leverage Phase 6 next step. Reuses Phase 7's lib/utah/extract.ts primitive.
Persistent project home in Co-Work. Reads PORTAL_CONTEXT_FOR_TICKETING_PROJECT.md. Resolves 9 open questions → produces PLAN.md.
Context dump at Ticketing System/PORTAL_CONTEXT_FOR_TICKETING_PROJECT.md for the Co-Work session to read cold.
Merchant + partner support tickets, role-isolated views, reuses portal's notification + UI primitives.
"Invite a teammate" inline nudge on /dashboard for primary contacts with no collaborators. Retires once they invite anyone.
6ce55d9b is still sitting at fully signed. Since the activation fix shipped, its page now offers Link agreement to VPS rather than the button that used to error. Mark presses it. (The MDS Ventures agreement was voided in the same ship — it was a real signature used to test the flow, kept as a record.)/admin/import, it clears the P4 exit gate (ingest → reconcile → review the alerts for false positives) and, with the survey below, unlocks real bank logins on /bank. Until then both surfaces are machinery running on synthetic data.Applications/Venture Payment Solutions/PENDS_TRACKER_CORDURO_2026-08-03.md), but Mark's call is that we won't be responding to them — the Pend Tracker starts from new pends going forward. The captured file stays as reference. The one item that may still deserve an answer on its own merits is the missing/incorrect MPA on the Outdoor Ready Pro lead. Note the VPS applications mailbox is only reachable from mark@ainsworthpayments.com.Ainsworth Payments/CRM/Bank_Auth_Survey_Draft_2026-08-03.md. It asks the sponsor banks what they require for logins (MFA, SSO, revocation). One of the two gates holding /bank at demo-grade; the other is the real month above./bank. → Two gates: the bank-auth expectations survey answered (Mark sends), and the P4 real month above. Internal demo grants only until both clear.* 2.tsx / * 2.ts duplicates and corrupting .git. Repo moved to ~/dev/ainsworth-merchant-portal, with feature worktrees as siblings under ~/dev/. Closed.
get() throws on a missing object rather than returning a non-200, so a status-code-only check leaves an unhandled 500 where a typed error was intended. Fixed in the two routes shipped 08-06; api/merchant-accounts/[id]/var-sheet was deliberately not touched. Fix it next time that file is open.
statements.ts, checklist-def ↔ nudge route. Deferred as a coordinated pass post Phase 7 review.
id_date_issued not collected in UI
Field is in the canonical schema + DB, preserved on edit, but no UI input. Add when a sponsor bank flags it as required.
card_types_not_accepted / refund_policy_description / product_storage_location in PDF fill + admin views must use safe text APIs (not raw HTML). Flagged at every commit.
wet_signed in their terminal exclusions. Unreachable today (synthetic wet-sign IDs never match a Dropbox event) but the DB, not the pre-read, should own it. Fold into the next webhook touch as one transition-policy/CAS helper.
reopen should be tightened to in-flight placements; the location tag can't be lane-aware until the P2 MID registry carries both foreign keys; and the edit UI for decision fields / caps plus pend email notifications are still unbuilt.
PARTNER_HANDBOOK_v1.mdAinsworth Payments rootPORTAL_HANDBOOK_v1.mdAinsworth Payments rootTECHNICAL_DOC_v1.mdAinsworth Payments rootdocs/PROJECT_STATE.mdcanonical project statedocs/POSITIONING_STRATEGY.mdaudience + pillarsdocs/AGENT_DASHBOARD_SPEC.mdUX specdocs/BANK_MPA_OPERATIONS.mdrunbook for new banksdocs/RESIDUAL_AUTOMATION_PLAN.mdPhase 8 plandocs/PHASE_7_BUILD_SPEC.mdUtah automationdocs/PHASE_6_5_AGENT_AGREEMENTS_PLAN.mdnext workstreamCANONICAL_APPLICATION_SCHEMA_v2.md7-bank reconciled supersetSTEP_B_PLAN.mdPhase 5 sequenceIRIS_INTEGRATION_v1.5.mdHagen API specMAVERICK_INTEGRATION_v1.mdMaverick API researchESIGN_OPTIONS_v1.mdDropbox Sign decisionPRD_Ainsworth_MerchantPortal_v1.mdv1 PRDDEVILS_ADVOCATE_v1.mdstress-test of v1.0