Customer email → identity/trust boundary → classifier → CRM contact → consent → queue/message → audit trail
At every arrow, ask: what can fail, repeat, delay, or be misunderstood?
Test redirects, state, expired authorization, denial, and recovery with dedicated synthetic identities.
Do not put secrets in prompts, recordings, screenshots, tickets, or chat.
Real systems retry.
One event may arrive twice. A success response may be lost. A webhook may be delayed. Correct behavior must remain safe.
Inspect stored event count, consent/confidence, processing state and queued decision.
Contact updates, classifier accuracy and real delivery are not implemented.
“Webhook returned 200” is only one piece of evidence.
Use the supplied healthy JSON and one failure/recovery card. Mark implemented, simulated and absent components separately.
Deliver: integration map, evidence packet, recovery decision, regression candidate.
AI can classify, summarize, and route low-risk work.
Low confidence, ambiguity, consent, financial commitments, and external sends belong in a controlled review path.
Why is a technical success status not sufficient proof of business success?