Transaction proof
A successful charge is not the whole Estonia transaction.
The useful unit of design is the complete commercial record: offer, consent, provider response, confirmation, invoice or receipt, fulfilment, failure, refund, support, and reconciliation.
| Moment | Product decision | Evidence after release |
|---|---|---|
| Before payment | Currency display, item or service definition, customer details, consent, and approved terms. | Reviewed copy and test record. |
| Provider handoff | Supported country/account combination, authentication, idempotency, timeouts, and duplicate protection. | Provider response and safe retry test. |
| Confirmation | What the customer sees, what the organisation records, and what triggers fulfilment. | Order state, message, receipt path, audit entry. |
| Failure and refund | Declines, abandoned sessions, delayed callbacks, partial fulfilment, cancellation, and support ownership. | Recovery test and reconciled final state. |
| Accounting handoff | Invoice or receipt needs, VAT/tax review, settlement records, fees, and daily reconciliation. | Export or report accepted by the accountable finance owner. |
Scope boundary
Software can enforce an approved transaction model. It cannot invent one.
- Client confirms merchant and provider eligibility
- Qualified reviewers decide VAT, tax, invoicing, and disclosures
- Test environment covers duplicate and delayed responses
- Customer support owns failed and disputed cases
- Production reconciliation has a named human owner
Build the record