Problems stop the money clock instead of rewriting the sale.
v0.12.19 adds server-owned cancellations, refunds, returns, claims/disputes, payout holds, and exactly-once inventory compensation. Refund decisions and provider execution remain separate evidence.
TEST NOWApply migration 0018, run the disposable server self-test, then use a QA Maker session to create a visible cancellation or return fixture in Returns & Resolution.PRODUCTION LATERReal refund API calls/webhooks, chargeback provider deadlines, carrier return labels, tax/refund allocation, admin/support MFA approvals, fraud scoring, and real payout reversal/negative-balance collection remain gated.EXPECTED SCHEMAv18order exception ledgerREFUND PROVIDERNot connectedQA simulation onlyPAYOUT SAFETYHold-awarerelease blocked while activeSERVER HEALTH + LIFECYCLE
Can a problem change state without corrupting the original order?
The self-test proves payout hold placement, exactly-once cancellation restock, provider-pending refund state, provider confirmation, cross-case refund ceilings, return authorization, and dispute payout blocking.
VISIBLE MAKER TEST
Create a disposable case in the real Resolution UI
Start a QA Maker session first. Create a cancellation fixture, approve it, verify the refund stays pending-provider, then use the QA provider confirmation button. Or create a completed-order return fixture.
Resolution boundaryPassing v0.12.19 proves the server state machine and safety rails. It does not prove that money moved, a chargeback was answered, a return label was purchased, or a payout was clawed back from a real provider.