Developer reference
Import lifecycle and export boundaries
Keep uploaded evidence, reviewed interpretation, consent and committed money separate.
An import captures source evidence, interprets it for review, and records accepted money only after explicit consent. Uploading a statement or storing messages must not itself create transactions.
Lifecycle responsibilities
- Receive the source and retain its identity.
- Configure account, mapping and source purpose.
- Generate a preview for that interpretation.
- Review ambiguous rows, balances and original-currency evidence.
- Obtain explicit consent for the intended reviewed version.
- Start processing and retain durable progress.
Changing source or configuration invalidates assumptions behind an earlier preview. Require fresh review and consent rather than silently processing a new interpretation.
Recovery
Continue an existing job after interruption. Cancellation stops further work once observed and does not pretend already committed work vanished. Undo is bounded to eligible unchanged owned financial units; linked or changed units can be refused.
Source restoration requires the intended original evidence and matching configuration. Reprocessing is another reviewed decision, not unconditional deletion and replay.
Export boundary
Full history export and self-service account deletion are planned. Import review pages, stored source files and paginated movement reads are not complete export facilities. Reserved scopes do not implement missing operations.
Read customer import steps, registered lifecycle actions and destructive controls.