Skip to content

Current system and audience map ​

Verified 2026-09-06. File anchors are pinned in evidence-index. [missing] means absent from current schema/code, not merely an unchecked GitHub box.

Current flow ​

mermaid
flowchart TD
  Submit[Submission create and initial scrape] --> Current[Submission mutable counters]
  Submit --> Initial[Best-effort initial ViewSnapshot]
  Schedule[Backend creation-based scheduler] --> Job[ScrapeJob]
  Job --> Worker[Scraper: YouTube / TikTok / Instagram]
  Worker --> Result[ScrapeJob.result and source scraped_at]
  Result --> Reconcile[Backend campaign lock and appliedAt guard]
  Reconcile --> Current
  Reconcile --> Snap[ViewSnapshot at reconciliation time]
  Rate[Immutable rate versions] --> Calc[Current-value earnings / CPM calculators]
  Current --> Calc
  Budget[Campaign.budget string] --> Calc
  Calc --> Reads[Creator / campaign / admin APIs]
  Snap --> Hybrid[Hybrid chart readers with fallback inference]
  Rate --> Hybrid
  Hybrid --> Reads
  Current --> Rescrape[Payout request rescrape]
  Rescrape --> Item[PayoutItem rate and amount snapshots]
  Item --> Approve[Approval increments paid counters]
  Approve --> Send[Legacy rail dispatcher]
  Send --> Pay[Payout COMPLETED / failure]
  Pay --> Report[Token-scoped sponsor report]
  Item --> Report
  Current --> Report
  Snap --> Report
  Reads --> UI[Creator and staff frontend]
  Report --> Public[Anonymous sponsor frontend]

The target inserts verified funding → attributable CPM/RPM journals → durable holds/finality → amount-level payout allocations and confirmed provider operations before financial projections. Those producers are separate dependencies. The scraper remains technical acquisition only. Analytics performs read projections, never accrual/reservation or external calls.

Persistence and authority ​

RecordWhat it proves todayWhat it does not prove
ScrapeJobTechnical request/result, lease, completion, appliedAt; result contains scraped_at.Complete normalized observation history or entitlement. Jobs are not a financial journal.
ViewSnapshotRecorded views/nullable likes/comments/shares at snapshotDate; tracking application is guarded. Tracking writes clamp.finalCurrentViews, which can be budget-clamped.Raw platform views in every row, source job identity, durable correction disposition, source-versus-ingestion time; initial write may be missing.
SubmissionCurrent moderation/metrics/overrides/caps, creator link, creation and first acceptance.Historical review sequence, immutable earning balance, provider-paid state. lastPolledAt can also be written on failure, so do not treat it as guaranteed successful-observation freshness.
Rate versionsExact effective-dated campaign/individual rates and resolver provenance contract.Posted earnings; group rates are not loaded/persisted yet.
CampaignConfiguration, string budget, lifecycle flags and tracking duration.Verified funding receipt/commitment or immutable remaining budget.
Payout / PayoutItemRecorded legacy operation and item snapshots; completed approved items support scoped gross payout reporting.Complete campaign allocation for legacy one-shot payments, exact ledger positions or Whop success. Floats and approval-advanced counters remain.
ClipperGroupMembershipCampaign group intervals [joinedAt,leftAt); historical identity may be null.A unique primary group or historical allocation of old earnings.
AuditEvent / targetsCanonical business audit envelope, with required transactional writer available.Every review mutation committed reliably; some producers remain best effort/compatibility. Not a substitute for money records.
StaffCapabilityGrantLocal grants for hybrid RBAC foundation.Final business-route permission decisions; current route guards still govern.
[missing] funding / earning / hold / allocation factsRequired target sources in financial contract.Must never be synthesized from a display or a legacy counter.

Audience / metric matrix ​

All equalities require matching scope, date basis, cutoff, currency, gross/net basis, and coverage. The rightmost column is the planned canonical source, not current implementation.

Surface and APICurrent displayed number / behaviorCanonical source and planned unit
Creator overview /stats/overviewCurrent accepted effective views; budget-capped recalculated earnings, fee applied; paid/pending split by legacy paidOut. UI sparklines are fixed artwork.Own earning positions and confirmed allocations; persisted observation series and status counts separately. A02/A03/A04/A11.
Creator /stats/campaignsCurrent accepted views times current campaign RPM; adds once; omits selected manual/frozen fields, individual/group resolution and journal attribution. No current frontend consumer found.Per-campaign sum of own entries; shared adapter retained for endpoint compatibility. A04.
Creator history /submissionsEstimated earnings from current calculator; frontend sums only loaded 10-row page, with local search.Paginated own submission positions plus separate full-filter summary; observation/latest metric coverage. A04/A12.
Creator payout balance /payouts/balanceRecalculated gross less approved items in awaiting-send/processing/completed, then current fee. Clipper-only old fields plus separate referral/combined eligibility. Overview and payout page consume different bases.Read supplied eligibility and disjoint entry balances; content/referral separate. Analytics must not replace payout policy. A04/A11/A12.
Creator payout history /payouts/meLast 50 operation rows, net amount, method, created/completed times; no campaign allocations or cursor.Own operations/events and entry allocations, gross/net/fees, explicit incomplete legacy coverage. A05/A12.
Creator campaign list/detail /campaignsPublic list computes CPM totalSpent; frontend parses configured budget and clamps remaining to zero. Detail loads the list and some legacy RPM labels say CPM.Safe existing public performance stays bounded; authenticated own/campaign-approved finance projection supplies explicit spend/expense/funding. A06/A11; access owner #50.
Creator leaderboard /stats/leaderboardCurrent estimates for submissions created in period, plus ExternalLeaderboardPayment amounts.Name earning leaderboard versus payment leaderboard explicitly; journal period/paid basis and external coverage separate. Never count external imports as campaign earnings. A04/A11.
Staff overview /admin/statsLegacy userId distinct count, current submissions/statuses, raw current views, separately capped accepted views; pending payout count uses legacy PENDING only.Canonical creator identity counts; distinguish current queue stock, review events, observation changes, and full operation statuses. A02/A06/A07/A08/A13.
Staff /admin/chartHybrid snapshot delta reader recomputes RPM earnings at daily rate; inference fallback, positive clamp, inclusive off-by-one window.Same observation reader as creator/sponsor; earning time series from postings, not views × rate. A02/A03/A06/A13.
Staff campaign list/detailList totalSpent uses CPM; detail uses RPM under the same label. Platform/status filters differ between list rows and stats. Detail sorts only the loaded frontend page.Shared campaign financial projection; explicit independent list/summary filter scopes; top accepted videos sorted/bounded server-side. A02/A06/A13.
Staff user list/detail and eligible queueMixes legacy paid flags and current calculations; broad user routes also include financial summaries.Same own/creator/campaign entry projections, under retained staff/finance route protection. A06; payout eligibility remains payout owner's service.
Staff review queue/historyCurrent status counts, heuristic signals/snapshots/track record. Views/earnings sort fetches all rows; no reliable reviewer throughput.#41/#42 committed transition events for actor/time/reason metrics; queue stock remains separate. A07/A14, #43 owns queue repair.
Staff fraud and payoutsPayout-time badge strings, decisions and operation statuses; no durable held liability/rule history.#55 evaluations/hold entries and #59 operation allocations; unique held entry amounts, unresolved signals counted separately. A08/A15.
Group/member detailCampaign-owned roster and archived intervals only.#28 membership-at-fact-time cohorts, exact member sums and group union; rate provenance separate. A09/A16.
Sponsor report /reports/:tokenCurrent accepted effective views/likes/comments/shares; all submitted count; 90-day signed snapshot changes, approved top/recent posts; approved item gross only for completed payouts.Shared matching performance/paid-gross read primitives, preserving accepted cohort, 90-day window, payout visibility and legacy coverage. No staff risk/review or unrestricted creator financial records. A10.

Current shared calculators still differ in thresholds, rate selection and fee/rounding basis. Fixing labels alone cannot reconcile them. Sponsor payouts.available only detects known linked legacy payments lacking items; it is not proof that every historical payment anywhere has complete attribution.

Protection / future RBAC attachment ​

BoundaryCurrent protection to retainPlanning marker
Own stats/submissions/payoutsrequireAuth plus own-user/verified legacy identity predicates; stats mount also has limiter.TODO(RBAC): Keep creator reads limited to the authenticated creator; any cross-creator finance variant requires the approved financial-view capability.
/admin/stats, /admin/chartrequireAuth, requireWhopStaffAction(ANALYTICS).TODO(RBAC): Require the capability for viewing cross-creator financial analytics here; totals disclose other creators' compensation and campaign liabilities.
Admin campaign list/detailrequireWhopStaffAction(CAMPAIGN_MANAGEMENT); user list/detail use requireStaffAccess.TODO(RBAC): Attach the approved campaign/financial read capability before broadening staff access to campaign spend and creator balances.
Review / group / payout readsExisting SUBMISSION_MODERATION, CLIPPER_GROUP_ADMINISTRATION, PAYOUT_REVIEW action guards respectively.TODO(RBAC): Require the approved access for reviewer accountability, group member compensation, or fraud evidence at each respective read endpoint; these are internal operational records.
Payout writesExisting payout-execution action guard and TOTP where attached.No analytics write endpoint; preserve these unrelated actions.
Sponsor management / public readManagement retains requireAuth, requireAdmin; public requires valid campaign bearer grant and post-read validity check.Preserve existing report TODO(RBAC) for link control and creator-ranking disclosure; no general creator/finance capability bypass through reports.
Creator campaign discoveryPresently public, including top submissions.Do not add liabilities/creator details. #50 owns private access enforcement; coordinate any authenticated alternative.

Frontend staff navigation currently allows only certain admin subpaths, even when a backend analytics route exists. New staff visibility must follow the separate RBAC attachment contract; client visibility cannot authorize data. Caches must not bypass guards or share sensitive payloads across scopes. No speculative permission mappings are selected in this folder.