Resolve payment credential and CRM pipeline commitment boundaries

Add research on PCI/tokenized payment references vs login Credentials (Payment
Instrument Reference, Payment Mandate) and CRM Opportunity promotion thresholds
(Pipeline Pursuit, binding_trigger). Resolve OpenQuestions for both topics.
Update glossary, conceptual model, terminology, and downstream recommendations.
This commit is contained in:
2026-06-21 23:11:00 +02:00
parent bd272151af
commit 6ea582cd9e
11 changed files with 435 additions and 19 deletions

View File

@@ -167,14 +167,18 @@ evidenced obligations that raise counterparty reliance and make identity less fl
### Commercial Commitment placement
**Status:** Tentatively resolved — first-class Relationship-layer concept.
**Status:** Resolved — first-class concept with explicit promotion thresholds.
Contracts, subscriptions, payment mandates, and regulated onboarding acceptance
map to **Commercial Commitment** attached to Commercial Relationship or
Commercial Record. See `commercial-identity-synthesis.md`.
Contracts, subscriptions, payment mandates, purchase orders, and regulated
onboarding map to **Commercial Commitment**. CRM **Opportunity** maps to
**Pipeline Pursuit** — not commitment until `binding_trigger` (signed LOI/quote,
executed PO/contract, active subscription). Salesforce Forecast "Commit" is
pipeline metadata only.
**Remaining:** Whether pipeline stages (CRM Opportunity) are commitments or
downstream-only.
**Citations:**
- `research/commercial-identity/crm-pipeline-commitment-threshold.md`
- `research/commercial-identity/commercial-identity-synthesis.md`
### Beneficial Owner modeling
@@ -245,10 +249,18 @@ OPI modeling under ISO 6523.
### Payment credential boundary
**Status:** Open (downstream-heavy).
**Status:** Resolved — Payment Instrument Reference + Payment Mandate; not Credential.
Whether payment methods on Commercial Record map to Credential in canon or remain
PCI-scoped downstream artifacts only.
**Decision:** Do not map payment methods to **Credential**. CHD (PAN, CVV) is
out of canon (PCI downstream). Tokenized provider references (`pm_xxx`) map to
**Payment Instrument Reference** on **Commercial Record**. Customer authorization
to charge maps to **Payment Mandate** (**Commercial Commitment**,
`commitment_type: payment_mandate`). Login credentials remain separate.
**Citations:**
- `research/commercial-identity/payment-credential-pci-boundary.md`
- `research/commercial-subscription/stripe-customer-billing.md`
## New Questions From Corpus Review