Stripe Test Mode
Payment Recovery Admin
Review refunded and disputed payment cases, record operator notes, restore or deny access, and preview customer-safe status messaging.
Recovery Queue
Cases are generated from Stripe test refund and dispute ledger events. No card data, customer email, provider secret, or coordinate material is shown.
Payment Recovery Readiness Rollup
Latest public-safe evidence from hosted smoke, entitlement audit, rollback proof, Stripe checkout, and webhook checks.
Stripe Webhook Review Rollup
Connects signed Stripe test events to recovery cases, notification status, and operator review. This is public-safe status only; no keys, card data, or customer secrets are shown.
Saved Queue Views
Switch between operator-safe filters for all cases, review work, refunds, disputes, restored accounts, held reviews, denied access, and high-priority cases.
Decision Workbench
Choose one case, add a short internal note, then restore, deny, or hold for more review.
Customer-Safe Status Preview
This is the type of message a user can see without exposing payment internals.
Recovery Policy Controls
Operator-editable defaults for refunded, disputed, restored, denied, and held accounts. These are public-safe policy drafts, not legal advice and not live payment actions.
Recovery Notification Drafts
Customer-safe messages for payment recovery states. These drafts avoid provider IDs, secrets, card details, private emails, wallet keys, and coordinates.
Template Version History
Each saved recovery-message draft creates a public-safe version snapshot with changed fields, operator notes, and exportable evidence. No live email is sent.
Test-Safe Notification Pipeline
Generate operator-approved customer messages from recovery cases, approve them, and release them to the test outbox. This does not send real email yet.
Outbox Retention And Redaction Report
Summarizes what notification evidence is retained, what is redacted, and whether any unsafe material is present. This report is exportable and does not send email.
Notification Provider Readiness Sync
Shows the currently recognized provider registry, live-send gate, and setup checklist next to recovery notifications. Secret values remain in Render or the provider dashboard only.
Notification Preference Rules
Control which recovery and account messages are required transactional notices versus optional updates. This only changes delivery rules; real provider sending remains locked.
Delivery Attempt Audit
Shows blocked and test-outbox delivery attempts. It proves whether any customer-visible notification was only recorded, blocked, or held. Real email remains disabled.
Stripe Recovery Drill Runner
Runs a public-safe test chain: completed payment, refund, completed replacement payment, dispute, operator restore. It exports evidence without secrets or raw payment data.