PASS: legacy task status catalogue is present PASS: required workflow actions are catalogued PASS: shared CORS explicitly permits Idempotency-Key PASS: CORS preflight exits before authentication PASS: CORS uses a configurable origin allowlist and cache-aware response PASS: LiteSpeed CORS explicitly permits Idempotency-Key PASS: LiteSpeed CORS uses the explicit development origin and varies by origin PASS: PHP errors are not rendered publicly PASS: authentication resolves the current Dolibarr user PASS: actor mapping uses the stable Dolibarr user ID PASS: actor mapping is independent of token values PASS: all complementary module permissions are resolved PASS: authenticated readiness endpoint exposes safe actor context PASS: shared audit identity helper derives server-side actors PASS: workflow transition has commit and rollback paths PASS: all assigned-task workflow actions are covered by the ownership policy PASS: task ownership is checked against the locked task_id and k_form_id row PASS: ownership compares task_assignee with the server-resolved application actor PASS: ownership never trusts payload identities or business target/resource IDs PASS: task ownership is enforced before every stage mutation PASS: administrators do not silently bypass assigned-task ownership PASS: optimistic concurrency is atomically enforced PASS: task context exposes the authoritative K-form row version at data.row_version PASS: transition requires a non-negative expected row version PASS: transition returns the incremented version and next allowed actions PASS: idempotency conflict handling is present PASS: duplicate active task creation is guarded PASS: driver and vehicle overlap blockers are present PASS: application-user assignment validation does not require legacy driver_id PASS: standalone assignment pre-validation can run before the Driver user is selected PASS: transport validation requires an active synchronized Transport Driver application user PASS: application-user and vehicle schedule conflicts remain protected PASS: optional legacy driver references never masquerade application users as physical Drivers PASS: transport validation accepts browser datetime-local values PASS: transport persistence uses normalized validated assignment timestamps PASS: licence and permit expiry blockers are present PASS: fleet maintenance and tyre blockers are present PASS: driver mileage regression is rejected PASS: driver completion creates a guarded HR task PASS: commission resolves container and location from K-form PASS: commission explicitly uses location tariff source PASS: missing rate configuration produces a safe 422 contract PASS: missing location tariff is handled safely PASS: commission snapshot reference is persisted PASS: inactive container size is rejected PASS: location-to-zone conflict is rejected PASS: workflow audit actor is not accepted from request body PASS: audit and transactional outbox migrations exist PASS: immutable commission snapshot migration exists PASS: database active-task uniqueness protection is staged PASS: stable Dolibarr identity mapping is unique PASS: ambiguous legacy identities are reported instead of guessed PASS: stable actors persist normalized Dolibarr module snapshots FAIL: Document access authorizes Operations candidate lookup PASS: Operations access authorizes Transport Manager candidate lookup PASS: Transport Driver access authorizes HR candidate lookup FAIL: Operations candidate stage requires Document access from the caller PASS: Dolibarr truthy and active-state string values are normalized PASS: authenticated options_ops_module is synchronized to the stable actor mapping FAIL: authentication remains compatible while migration 010 is pending PASS: missing stable actor schema returns an actionable service-unavailable error PASS: Operations candidates use the normalized Dolibarr extrafield instead of local group/module assignment PASS: Transport Manager candidates use the normalized Dolibarr module snapshot PASS: Transport Driver users are discovered directly from active synchronized application actors PASS: Driver eligibility never requires or infers a physical Driver identity PASS: Driver candidate results use the data.assignees contract PASS: unlinked Transport Driver users remain eligible while driver_id stays optional PASS: development Driver diagnostics depend only on application-user eligibility PASS: Driver mapping migration adds the nullable unique link without prematurely adding a foreign key PASS: optional Driver actor foreign key is isolated behind reviewed orphan checks PASS: HR candidates use the normalized Dolibarr module snapshot PASS: transition validates the selected Transport Manager against the same eligibility source PASS: Driver assignment uses next_assignee_id without requiring a physical Driver link PASS: transport assignment persists the authoritative application-user recipient independently PASS: created Driver task stores next_assignee_id as task_assignee PASS: Driver trip processing tolerates a null legacy physical Driver reference PASS: migration 013 stores the Driver application user and keeps legacy driver_id nullable PASS: Operations eligibility fails safely when migration 010 is pending PASS: candidate response contains active mapped users and the assignment identifier PASS: candidate eligibility does not depend on Dolibarr groups PASS: safe exclusion diagnostics require an explicit non-production environment PASS: initial assignment verifies that the caller may initiate the K-form PASS: initial assignment rejects conflicting workflow state PASS: duplicate initial Operations tasks return a conflict PASS: selected candidate cannot override the authenticated actor PASS: task assignee and server-derived assigning actor are persisted separately PASS: assignment validates the same normalized Operations eligibility source 84 checks passed; 3 failed.