Controlled Auto-Bid Policy
Auto-Bid runs only when verified cost, sales-price, authorization, and exposure gates are complete; a PDF is not an intake prerequisite.
Controlled Auto-Bid Policy
Auto-Bid is a controlled pilot capability for explicitly authorized organizations. It operates only for predefined products, quantities, pricing authorities, and production relationships. Other approved print shops continue to use the canonical manual quote flow. Bulut Dijital is the first real Auto-Bid member, and the three providers registered in its Master Data are real subcontractors rather than pilot fixtures.
Organization-scoped control
Shadow mode never publishes a customer quote. Canary or live execution requires the organization setting, platform kill switch, and every safety gate. Bulut Dijital operates in live mode with a 100-percent canary; automatic price acceptance is outside this scope.
Current Behavior
1. Request and Optional PDF
The buyer opens an RFQ with whatever information is available. A PDF and
preflight are not prerequisites for RFQ intake or quoting. If a PDF is attached,
malware screening and server-authoritative preflight findings remain enforced
at acceptance, order, and production gates. A page or size conflict requires
buyer revision and a measured colour conflict requires operations review.
For book, novel, poetry, and story requests, missing fields may use the Bulut
pilot example profile for non-critical details such as pages, size, paper,
colour, and binding. Explicit product intent and a positive buyer-supplied
quantity must already be present. Every inferred field is marked in assumptionFields;
these fields are not presented as buyer declarations. If every pricing,
authority, and exposure gate passes, an exact Auto-Bid price is bound only to
those visible assumptions and the current RFQ revision. A correction in the
same mail thread makes the old quote stale and reprices the new revision. A
missing requested finishing rate fails closed to manual review.
Paper stock and grammage are never inferred from PDF content.
In the mail-first pilot, an empty or generic quote-request email does not enter
the book example. Product type and real quantity are requested before an RFQ
is created. Values written by the buyer in the subject or body always win; the
profile fills only non-critical missing fields. The RFQ cannot enter
the Auto-Bid example lane unless it carries the published profile digest and
snapshot-bound authority receipt. If Gemini is unavailable, a deterministic
subject/body fallback preserves only explicit facts and book intent; it does
not invent a category or quantity.
The controlled Bulut candidate added when generic matching has no supplier is
not a general fallback. It requires the hash-bound code authority scoped to the
email channel, book/booklet, and at most 1000 copies. Bulut's persisted
organization settings must also be readable and enabled, with an explicit pilot
mode, real subcontract provider, and an explicit quantity ceiling no greater
than 1000. A tariff by itself is never routing or trust approval.
For Gmail requests with attachments, the original file must first receive a
hash-bound clean receipt from the private scanner before AI or preflight can
read its bytes. If the scanner is unavailable, a single unambiguous filename
declaration such as 56 PAGES may replace an assumed page count as buyer input.
It is not measured PDF evidence and does not prove the file size; any remaining
price-critical assumption keeps Auto-Bid fail-closed.
This lane tolerates only a missing optional catalog snapshot/handoff. An explicit catalog rule, publication decision, field/spec blocker, or missing subcontract cost/sales authority still fails closed; the exception never replaces the real Master Data execution authority.
2. Price and Capacity Gates
Only jobs with an exact product/spec mapping or an explicitly labelled assumption example, approved provider cost, active subcontract relationship, independent customer sales price, margin floor, customer-price ceiling, and current operational authorization can proceed. A missing binding or lamination cost is never derived from another provider row or from the sales price; the RFQ stays open for manual print-shop review.
3. Exposure Reservation
Before publication, the platform atomically reserves the daily live-bid count, commission-inclusive gross exposure, and per-provider concentration. Retries do not spend the same RFQ budget twice, and store failures stop publication.
4. Immutable Decision Evidence
Every shadow, blocked, or placed Auto-Bid decision is appended as hash-bound, immutable safety evidence. An exact retry returns the existing observation; a later evaluation creates a new observation and never overwrites prior evidence. Raw RFQ and organization identifiers are not stored in this audit record. For a placed bid, the observation and quote commit in the same transaction, so neither can exist without the other. The evidence also carries hash-only policy and pricing-authority provenance, the evaluator version, and currency so a later safety review can reproduce the authority used for the decision.
Each RFQ revision and supplier organization also receives a deterministic
auto-bid business-key claim in the same transaction. Concurrent or delayed
retries of the same revision replay the existing quote; a material RFQ
amendment receives a new revision key and is priced again. Buyer notification
is no longer written as a post-commit best effort: the
marketplace.quote.submitted outbox event is consumed by an event-id-
deduplicated notification bridge. For an email RFQ, the buyer-safe summary,
PDF, and signed review link are delivered idempotently in the original Gmail
thread; the private cost ledger and Bulut operations report stay separate. A
missing thread route, requester email, quote, or revision fails the consumer
for retry rather than acknowledging a silent success.
For a manual quote, the RFQ revision is persisted from the canonical RFQ inside
the transaction and cannot be overridden by client input. Before delivery, the
bridge requires the event quote/RFQ identities, the quote's RFQ binding, the
current and reply-route revisions, and the requester/route email addresses to
match exactly. A malformed or cross-bound event creates no notification,
capability, or customer email and remains retryable, then dead-lettered if the
bounded attempts are exhausted.
After eight failed delivery attempts, the immutable event is retained as
dead_letter and exposed as a separate Ops Cockpit signal. Authorized operators
inspect a bounded, payload-free projection at
/api/admin/marketplace/outbox/dead-letters. It includes sanitized per-consumer
status, attempts, stable error classification and last transition, but never a
provider body, stack trace or customer payload.
Replay is available only when the current canonical RFQ/quote evidence still
classifies the failure as transient. The screen shows the full event,
business-evidence, consumer-evidence and operator-decision digests. The last
digest binds the policy schema, evidence scope, disposition and exact sorted
consumer targets. The transaction recomputes all four before it reopens only
those failed consumers. Expired RFQs, RFQs with an existing quote,
manual-pricing outcomes, obsolete quote notifications and malformed poison rows
cannot be replayed. They can only receive the server-recommended, immutable
operator disposition through
/api/admin/marketplace/outbox/{eventId}/resolve. Resolution records the actor,
reason, evidence scope, exact targets, all four digests and sideEffect=none;
it does not send email, create a quote or claim delivery. A cursor-less legacy
row can be closed at source_event scope only when it is corrupt or current
evidence proves its expired commercial effect obsolete. Active manual-review
and transient legacy rows without consumer evidence remain blocked. There is no
bulk-replay authority.
Production must invoke both the domain-event drain and
/api/cron/notifications/dispatch every five minutes; otherwise quote and email
outbox records remain pending. Already delivered consumers are never reopened.
5. Buyer Comparison
The buyer compares quotes in a standard format. Internal cost, subcontractor identity, and profit evidence remain restricted to authorized organization or admin roles.
Guest quote access
Exact manual and Auto-Bid emails for an email RFQ use a signed capability bound
to the quote, RFQ, revision, and requester email.
The persisted capability is stored as active and rechecked against its token hash, lifetime and
status on every guest tracking read. Operations can revoke a compromised link
with a required reason at POST /api/admin/marketplace/quote-access/{quoteId}/revoke;
the audit record is retained as revoked while the lookup index is removed, so a revoked
link fails closed instead of exposing the RFQ.
Wider Availability Gate
Enabling Auto-Bid for another print shop requires separate approval for supplier opt-in, production capacity, pricing authority, audit/outbox proof, abuse controls, recovery UX, and measured service-level evidence.
Cet article vous a-t-il été utile?
Last updated on