# Confidence Report — TinyPOS (`tnx-pos`)

> Produced by the Reversa **Reviewer** (phase: review) · doc_level: `complete`
> Generated 2026-09-22.

Independent critical review of the 23 SDD units and the global artifacts, cross-checked against the actual Laravel 5.6 source. Confidence markers were re-verified against code; reclassifications and factual corrections were applied in-place. Human-decision items are in `questions.md`; residual gaps in `gaps.md`.

---

## Overall Summary (units)

| Level | Count | Percentage |
|-------|------:|-----------:|
| 🟢 CONFIRMED | 2283 | 83.4% |
| 🟡 INFERRED  | 287  | 10.5% |
| 🔴 GAP       | 167  | 6.1% |
| **Total**    | 2737 | 100% |

**Overall confidence (units):** **88.7%**  ( = (🟢 + ½·🟡) / total ).
Counts exclude the 4 confidence-scale legend lines per unit (one per file). Figures reflect the post-review reclassifications below.

---

## Per Spec (units)

| Unit | 🟢 | 🟡 | 🔴 | Confidence |
|------|---:|---:|---:|-----------:|
| `pos-terminal` | 142 | 5 | 3 | 96% |
| `orders-crud` | 187 | 10 | 7 | 94% |
| `customers-debt-actions` | 138 | 15 | 6 | 92% |
| `auth` | 100 | 7 | 7 | 91% |
| `dashboard` | 92 | 1 | 9 | 91% |
| `customers-purchase-history` | 95 | 7 | 6 | 91% |
| `customers-loyalty` | 133 | 13 | 7 | 91% |
| `products-catalog` | 159 | 20 | 9 | 90% |
| `orders-scan` | 86 | 7 | 7 | 90% |
| `gifts-crud` | 110 | 15 | 6 | 90% |
| `pos-scan` | 79 | 10 | 5 | 89% |
| `customers-crud` | 128 | 28 | 3 | 89% |
| `debts` | 79 | 9 | 6 | 89% |
| `customers-statistics` | 84 | 7 | 8 | 88% |
| `orders-note` | 78 | 12 | 6 | 88% |
| `brands` | 77 | 11 | 6 | 88% |
| `orders-print` | 84 | 16 | 6 | 87% |
| `customers-scan` | 69 | 7 | 8 | 86% |
| `products-pricing` | 82 | 13 | 9 | 85% |
| `units` | 79 | 20 | 6 | 85% |
| `categories` | 87 | 13 | 16 | 81% |
| `gifts-scan` | 66 | 17 | 10 | 80% |
| `artisan-migrate` | 49 | 24 | 11 | 73% |

All 23 units have the full canonical set (`requirements.md`, `design.md`, `tasks.md`) plus `contracts.md`. No canonical file is missing.

## Global artifacts

| Artifact | 🟢 | 🟡 | 🔴 | Notes |
|----------|---:|---:|---:|-------|
| `openapi/tnx-pos.yaml` | 91 | 9 | 9 | 39 path items / 54 operations; matches the live route surface 1:1; structurally valid YAML (no parser available in-env to formally parse). |
| `user-stories/` (11 files) | 133 | 58 | 37 | Story map covers all 23 units across 10 journeys; no coverage gaps. |
| `traceability/` (2 matrices) | 83 | 27 | 8 | See requalification note below (Discount). |

---

## Coverage validation

- **Route coverage:** every route in `routes/web.php` maps 1:1 to an owning unit; no live HTTP surface is un-specified.
- **Module coverage:** all 11 `surface.json` modules map to at least one unit; `artisan-migrate` covers the extra `GET /artisan` maintenance route.
- **`code-spec-matrix.md`:** complete — no real source file lacks a spec row. Requalified 2026-09-23: `Discount` model / `discounts` table are no longer marked fully "unused" — the live `orders.discount_id` FK (cascade) and `Order::discount()` relation are now noted, and the project owner confirmed the schema is kept intentionally for future use (`questions.md#question-10`), not dead.
- **`spec-impact-matrix.md`:** the high-coupling rows (`getPriceByCustomerType`, `CustomerDebt::record`/`voidForOrder`, `Order::summaryLogging`, the single `['web','admin']` group) were verified against real call sites and are accurate; the only omission is the `discounts` FK coupling above.

---

## Reclassifications applied (this review)

| From | To | Claim | Unit / evidence |
|------|----|-------|-----------------|
| 🟢 | 🔴 | Month sales-chart 5-day windows "tile the month" (BR-05, RF-08, design, tasks, contracts) | `dashboard` — `DashboardController.php:87,91,93` (cursor advances 6 days/iter; every 6th day dropped) |
| 🟡 | 🔴 → 🟢 | `gift-received` `orderBy('id')` "may raise ambiguous column on some MySQL configs" | `customers-loyalty` — `CustomerController.php:349`. Retracted 2026-09-23: empirically retested against the real MariaDB 10.11.13 database (`php artisan tinker`, `paginate(30)`), runs correctly with no error. |
| 🟢 | 🟡 | "units re-derived transactionally per save" | `products-catalog` — `ProductController.php:212-283` (no `DB::transaction`) |
| 🟢 | 🟡 | scan results "newest-first by default insertion order" | `gifts-scan` — `GiftController.php:122` (no `orderBy`; DB-defined, likely oldest-first) |
| 🟢 | 🟡 → 🟢 | "hooks run as in store (but `used` is preserved)" on edit | `gifts-crud` — `GiftController.php:103,93-95`. Restored 2026-09-25: verified via a real HTTP edit test against the running app — `used` is correctly preserved. |
| 🟢 | 🟢 (text corrected) | "`Order::find`, not `findOrFail`" | `orders-print` — `OrderController.php:396` actually uses `findOrFail` → clean 404 |
| 🟢 | 🟢 (text corrected) | category dropdown "all categories, parents included" | `customers-purchase-history` — `CustomerController.php:202` is `whereNotNull('parent_id')` (child-only) |
| 🟢 | 🟢 (text corrected) | stale contrast to "ungrouped `orWhere` in `orders-crud` index" | `orders-scan` — that index search was fixed to a grouped closure 2026-09-21 |

The three "text corrected" rows keep their marker (the underlying claim is still confirmable) but the wording was factually wrong and contradicted the code and the rest of the unit.

---

## Cross Review

- External engine consulted: **none.** The Codex plugin is not active in this session (no `codex:` tools available), so the optional cross-review (offered at `doc_level: complete`) was skipped per the Reviewer skill. All findings above are from the Reviewer's own analysis against source.

---

## Recommendations

- [x] **`customers-loyalty` gift-received page** — `questions.md#5` closed 2026-09-23: retested against the real database, the `ORDER BY id` does not error; no code change needed.
- [x] **`dashboard`** — `questions.md#1` closed 2026-09-22: the every-6th-day gap was confirmed a bug and fixed (`<` → `<=`). `questions.md#2` (chart metric: count vs revenue) was **deferred** by the owner — current legacy behaviour (order count incl. drafts) stays documented as-is; revisit before porting. A separate non-6-multiple month-boundary spillover was found during verification and left open in `gaps.md` (🟡).
- [x] **`orders-crud`** — `questions.md#11` closed 2026-09-25: `store`/`update` wrapped in `DB::transaction`, debt guard moved before pivot mutation, verified against the real app (existing test suite + tinker reproduction).
- [x] **`traceability/`** — `Discount` rows requalified 2026-09-23; `questions.md#10` closed (kept for future use, must not be dropped on migration/rewrite).
- [x] **`products-pricing`** — error contract settled 2026-09-22 (`questions.md#4`): per-kind status codes, no more leaky 400.
- [x] **Documentation quality** — done 2026-09-25: (a) translated the Portuguese Gherkin text (not just keywords — full scenario bodies were in Portuguese in 18/23 units) to English across all affected `requirements.md` files; (b) re-synced the ~2–6-line citation drift across `customers-debt-actions`, `customers-loyalty`, `orders-scan`, `pos-terminal`, `pos-scan`, `dashboard`, and `products-catalog` against current line numbers (verified by direct source reads). See `gaps.md` for the small residual note on `pos-terminal`'s deepest JS-line citations.
- [x] **`artisan-migrate`** — done 2026-09-25: `requirements.md` reconciled to the accepted-risk decision (🟢, was 🔴); the undefined `⚪` marker in `design.md`/`contracts.md`/`user-stories/maintenance.md` replaced with the standard `🟢` confidence marker.
- [ ] **Cross-cutting** — carry "no observability" as an explicit NFR for the reimplementation rather than a per-unit gap.

---

## Reviewer checkpoint

- Specs reviewed: **23 units** (92 canonical + contracts files) + **3 global artifact sets** (OpenAPI, user-stories, 2 traceability matrices).
- Cross review performed: **no** (Codex not available).
- Reclassifications: **8** claim-level changes (2× →🔴, 3× 🟢→🟡, 3× text corrections) at review time, applied across 12 files. Two were later reversed once the owner's answers came in — `customers-loyalty` gift-received (🔴→🟢, `questions.md#5`) and `gifts-crud` `used`-on-edit (🟡→🟢, `questions.md#16`).
- Questions generated: **17** (in `questions.md`) — **all 17 answered by the project owner (2026-09-22 → 2026-09-25).** Outcomes: **5 code fixes** (#1 dashboard window, #4 pricing error contract, #11 orders atomicity, plus the #17 cross-reference comments and #8/#5/#16/#7 verifications-in-place), **7 confirmed-intentional** (#9, #10, #12, #13-part1, #14, #15, #6), **3 deferred** with legacy behaviour kept (#2 chart metric, #3 `public2` unlink path, #13-part2 sale-time points snapshot). Deferred items and the residual documentation-quality gaps are carried in `gaps.md`.
- Overall confidence (units): **88.7%** at review time; the five code fixes above have since closed several of the counted 🔴/🟡 items in-place, so the live figure is higher (not recomputed — this table is the review-time snapshot).
- **Review phase (`revisao`) — COMPLETE.** All Discovery-team agents (Scout → Archaeologist → Detective → Architect → Writer → Reviewer) are done; the `_reversa_sdd/` extraction is finalised. Post-run regression check (`step-04`) was silent: no `_reversa_forward/` regression-watch history and no `_reversa_sdd/addenda/` to reconcile.
