Commerce records as owners, and one place for the matching rules

FeatureSecurityService
Shipped
August 26, 2026 at 6:15 AM UTC
Author
Kamo
Commit
ba477ec

The third owner the spine was widened for, and the one that was still defined and unused. A record's documents already hang off it through the document manager's (assocType, assocObjectId) pair; its traffic now does too. ContactPointRegistrar exists because the write rules are MATCHING rules. The canonical form a number is stored in and the minimum length it must reach are what decide which timeline an inbound call lands on, and they were inline in PatientCommsService. A second copy for commerce would eventually normalise differently, and the symptom is a call that matches a patient's number under one code path and nobody's under another, with nothing in either log to say why. Authorisation deliberately stays with the callers. Who may register a patient's number is a clinical question answered by a care relationship; who may register a service job's is the commerce right. Putting either rule in the registrar would have meant the other lived somewhere else. A commerce record does NOT roll up its account. That would put every job a customer ever had on the page for one of them — a different question, which the account page already answers.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing