Files
LWLT-AIBOT/.project-docs/40-domain/business-rules.md
T

2.4 KiB

Business Rules

Durable Rules

  • agent设计规范/business-adaptation-registry.md is the cross-session business entry; each business maps user input, Skill/action, ERP flow, contracts, implementation, fixtures, and verification status.
  • Manual and AgentBus tasks share the same 18 machine routes, task-scoped parser mode snapshot, and organization automation rules.
  • The two passenger-list import routes are Program-only and wait for exactly one .xls or .xlsx attachment before deterministic normalization.
  • A WeChat attachment card is transport placeholder text, not file content. Only a structured payload.attachments[] entry can resume a roster task; missing metadata fails before ingestion and leaves the original task in awaiting_attachment instead of creating a new task.
  • The trusted internal deployment accepts credential-free HTTPS roster attachment URLs whose host is internal, private/reserved IPv4/IPv6, or localhost. DNS pinning, redirect revalidation, download timeout, byte limits, declared-size checks, and optional SHA-256 verification remain mandatory.
  • AgentBus attachment diagnostics may record stage, address count/family, status, byte count, code, outcome, and duration, but never URL, hostname, IP, file name, bytes, message text, or roster values.
  • Passenger overwrite requires confirmation when target ERP rows are occupied; after full_replace + confirmed=true, every attachment-specified sequence is written even when values are unchanged.
  • A single strict 领队 row supplies leader contact; ambiguous, incomplete, duplicate, or structurally inconsistent leader data fails closed.
  • Shared-mother-plan 整团游客信息 export is only shared_plan + visitor-list + tid-only; independent and concrete shared-child visitor lists remain did+tid.
  • Real writes require unique resolution, exact page identity, ownership, write projection, explicit server response, and action-specific completion evidence.
  • Current business capability and verification status come from active source/contracts and the lifecycle release gate, never from archive wording.

Open Questions

  • Fresh authorized runtime read verification remains for the shared-mother-plan whole-visitor export branch.
  • Authorized current-version ERP write verification remains for SGL/TWN and four independent-order headcount categories.
  • Deployment/restart and one live internal attachment verification still require separate authorization.

Last Reviewed

2026-08-31