Per-loan third-party (LOAN) document viewer — appraisal/title/flood
Completes the doc-review byte path started with the vault viewer. LOAN-collection imgs (appraisal/title/flood) are refused by the generic imaging endpoints (per...
View/Download vault documents in the account docs tab
Turns the conditions/docs stage into a real review loop. The member-documents proxy route now passes through non-JSON (binary) upstream responses instead of tex...
Per-party vault document viewer — bytes were write-only, now review-able
Uploaded vault documents (pay stub / Gov ID / bank statement) were write-only: the generic imaging byte endpoints refuse ACCOUNT_MEMBER_VAULT (per-party PII loc...
Steward Catalog tab — seed a priceable bundle + inspect the catalog
New Catalog tab in the mortgage steward console: seed a tenant's first priceable bundle with REAL investor + product identities (unblocks pricing), and inspect ...
Catalog gateway — the missing proxy that blocked tenant pricing
Catalog was the ONLY MLOS bounded context with no SecurityService gateway, so a tenant's catalog could never be authored/seeded from the console and BorrowerQuo...
Loan-sale desk UI — the terminal capital-markets steward screen
LoanSaleDeskPanel in the Capital & Risk Command Center: list investor delivery commitments (status filter), open a commitment **************** and per-commitmen...
Durable consumer forwards investor purchase to loan-file FUNDED
MlosLoanFundedConsumer subscribes **************** (durable daemon-mlos-loan-funded) and forwards each purchase to SecurityService's /funded pipeline endpoint v...
Loan-sale desk proxy + CLOSED->FUNDED pipeline seam
- **************** generalized the eClose seam to a shared advance() + added POST /funded (CLOSED -> FUNDED on investor purchase). Same idempotent/at-least-on...
Commitment boardedAt + loan-funded event type (loan-sale desk)
- MlosCommitment.boardedAt: in-system marker for a PURCHASED commitment's loans boarded to servicing (the external servicing-system handoff is the blocked leg...
Commitment/loan-sale desk entities (runtime consumer for the shipped investor config)
Slice 2 foundation for the capital-markets loan-sale desk (doc 08) — the terminal origination stage. The shipped **************** had NO runtime consumer; these...
Durable consumer forwards eClose completion to the loan-file pipeline
The DaemonService half of the eClose -> loan-file status seam. New MlosClosingCompletedConsumer subscribes **************** (durable daemon-mlos-closing-complet...
EClose completion advances the loan-file status machine (CLEAR_TO_CLOSE -> CLOSED)
Closes the terminal lifecycle seam: a fully executed/notarized/sealed eClose package emitted **************** but NOTHING consumed it, so the loan sat at CLEAR_...
ClosingArtifact provenance = one-time null->value stamp (enables after-commit eClose dispatch)
Splits the ClosingArtifact @PreUpdate WORM guard so the eClose vendor dispatch can move OUT of the assemble/advance transaction (doc 05 §6): the node commits FI...
Per-loan lock recommendation on the lock desk
Surfaces the RCE lock-vs-wait recommendation (Lock / Lock-with-steward-override / Do-not-lock) with rationale + a 'model uncalibrated -> steward decides' note w...
Proxy the per-loan lock recommendation (read-only)
GET **************** (operator+org gated, org server-stamped) -> the RCE per-loan LOCK/WAIT/BLOCKED recommendation. The commit stays the existing human /locks a...
EClose vendor categories on the integrations tab (RON/eNote/eVault/MERS)
Surfaces the four notarized-leg categories with their vendor options (Proof/ DocuSign Notary, DocMagic/Snapdocs, eOriginal/DocMagic, MERS eRegistry/DocMagic) so...
EClose vendor categories (RON/ENOTE/EVAULT/MERS) + artifact-by-externalRef finder
- VendorCategory gains the four notarized-leg rails so the integrations tab can configure a per-org RON/eNote/eVault/MERS vendor (additive STRING enum, no CHE...
Steward audit/write surfaces — signed-doc download, delegation chips, vendor event timeline, AUS waiver/validation, non-QM stipulations, eligible-investor board, funding histogram, closing audit trail, catalog provenance, composer catalog
Residual-sweep UI: executed-PDF Download + delegation display + vendor-order event timeline; Offer-waiver/Record-validation actions on the AUS drawer; non-QM de...
Proxy signed-doc download, delegation passthrough, vendor events, AUS waiver/validation write, non-QM detail, condition-template write
- Disclosure: GET **************** (steward, LOS_VIEW_PIPELINE) + GET **************** (borrower party-scoped), both byte-relaying the executed PDF from ESi...
Internal signed-document download + recipient delegation fields
- GET **************** streams the executed (flattened) PDF for an org-owned envelope (404 until fully signed). - RecipientSummary carries **************** ...
Product picker for the non-QM run trigger
Replaces the plain productId input with a product selector populated from the org's active catalog (non-QM products first, NON-QM chip), falling back to the pla...
Proxy the org product catalog for the run-trigger picker
GET **************** (operator+org gated; org-scoped by the downstream query, passthrough) → MLOSPricingService product list.
Disclosure void/sync/resend UI, workflow-template authoring, non-QM run, non-doc vendor orders, in-place config edit
Steward console UI for the remaining audited gaps: - #3/#8/#12/#17 DisclosuresSection: Void live native envelopes; 'Refresh status' hydrates per-recipient sta...
Steward disclosure void + status-sync + resend (native eSign)
- Void (#3): POST /esign-envelopes/{id}/void voids the live KAMO_NATIVE envelope in ESigService THEN mirrors the local stub to EsignStatus.VOIDED (stub demote...
Proxy vendor-order cancel (staff, loan-bound)
Expose POST **************** — staff-only, org resolved server-side, and the order must belong to THIS application's loan (verified against the loan's order lis...
Surface recipient decoder reason + internal resend endpoint
- RecipientSummary now carries decoderReason + decoderdAt (persisted by the decoder ceremony but previously omitted from every projection), so a compliance-...
Proxy steward write/read gaps — AUS **************** lock lifecycle events, LLPA blast-radius, eClose RON-fallback + workflow-template publish/detail, loan clearability
Closes the SecurityService side of a batch of verified proxy gaps where an MLOS engine capability existed but no browser-reachable proxy did: - underwriting: G...
Proxy closing-package assemble (light up the eClose write side)
POST **************** (operator-gated, org-stamped) → MLOSDocOrchestration assembler: resolves the tenant closing-workflow template as of the closing date + mat...
Transparent loan close-readiness endpoint (real milestones)
GET /mortgage-apps/{uid}/readiness (party-gated) → a weighted composite of REAL, explainable milestones (submitted / documents satisfied / conditions cleared / ...
Borrower payment-estimate endpoint (full PITIA, safe subset)
GET **************** (party-gated) → the borrower's estimated full monthly housing payment + components, a BORROWER-SAFE subset of the underwriting qualificatio...
Extract self-employment income from K-1 and P&L statements
K1 and PL_STMT previously returned DOC_TYPE_NOT_SUPPORTED; add vision prompts (employment.employerName + employment.wagesAnnual) so a self-employed borrower's K...
Borrower request-rate-lock → steward pipeline queue
POST **************** (party-gated): the borrower asks to lock their rate; recorded as an OPEN non-blocking PRICING LoanCondition so it lands in the steward's p...
Borrower rate-lock status endpoint (LOCKED/FLOATING)
GET /mortgage-apps/{uid}/rate-lock (party-gated) → the loan's SAFE lock posture: LOCKED (rate + expiry) when an active, non-expired commitment exists, else FLOA...
Lock lookup by loan file (join through scenario)
**************** — locks key on scenario, so resolve a loan's locks via MlosLoanScenario.loanFileUid. Backs the borrower/steward 'is this loan rate-locked?' rea...
Steward rate-lock proxy — lock-decision + commit an eligible result
MlosCapitalMarketsController gains POST /lock-decision (preview) and POST /locks (commit) via MlosCapitalMarketsClient; the commit is a deliberate HUMAN steward...
Borrower e-signature surface — real native sign links, no stub
GET **************** (party-gated) lists the loan's real KAMO_NATIVE disclosure/closing envelopes + recipient status via ESigService; POST **************** mint...
Internal mint-sign-link primitive for first-party signing surfaces
POST **************** re-mints a recipient's access token and RETURNS the signing deep-link (no invite-email round-trip), so the MLOS borrower portal can hand a...
WS3 vendor-order proxy — steward places/reads third-party orders
Add MlosVendorClient (X-Internal-Auth → MLOSVendorService /api/vendor) + mlos.vendor.url config, and app-scoped endpoints: GET /{uid}/vendor-orders (operator vi...
Borrower-safe my-conditions projection for the portal conditions view
GET /{uid}/my-conditions (party- or operator-gated) returns a narrow BorrowerConditionView **************** — never the internal actor/notes fields the steward ...
Per-borrower section GET endpoints to hydrate the capture UIs
Add listPerBorrower (requireView, party-gated) + GET list endpoints for **************** returning {rows:[...]}. These back the new URLA borrower capture sectio...
Borrower section read methods for other-income/expense/REO/gift capture
The per-borrower repeating sections were write-only; add read projections **************** so the borrower capture UIs can hydrate existing rows via GET endpoin...
Full credit-vendor abstraction + real reseller adapters
Production tri-merge credit rail. The abstraction now passes the FULL 9-digit SSN (decrypted at order time from the borrower's encrypted record) + co-borrower f...
Borrower clear-to-close proxy
GET **************** — party-gated; resolves loanFileUid from the app and relays MLOSDocService's clear-to-close readiness.
Accept X-***-Token for mobile clients in OTKPreAuthFilter
per-tab session id as X-***-Token (matching **************** When present (and no X-OTK), resolve the session non-consumingly and set the same request attribute...
Route /api/email + /api/support through the api host
(EmailService) and Support (MediaService, same upstream as /api/media) were unrouted → 404. Add both forwards and fix email.service.url from a localhost default...
Steward-triggered agency-AUS run proxy
Adds POST **************** — the steward "Run AUS" trigger the read-only underwriting console lacked. Gated on operator (GD); the organizationId and acting memb...
Self-hosted expo-updates headers for Mobile Copilot OTA
expo-protocol-version:1 + expo-sfv-version:0 response headers that the expo-updates client requires and static MinIO cannot emit. Longer path prefix wins over t...
Like what you see shipping?
Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.