{"database": "audit", "table": "source_truth", "is_view": false, "human_description_en": "", "rows": [["app:bundle", 0, null, null, "2026-05-21T20:07:49Z", "manual_seed", "Live cv_bundle_app audit stream: bundle reconciliation events maintaining the singles vs multipack inventory invariant in BigCommerce. Forward-only since 2026-05-07. No finite API truth.", null, null, null, null, "live", 1440, null], ["app:scan", 0, null, null, "2026-05-21T20:07:49Z", "manual_seed", "Live cv_scan_app audit forward: packing-station barcode scan events (NADAMOO HID keyboard input via Windows agent). Forward-only since 2026-05-11. No finite API truth.", null, null, null, null, "live", 1440, null], ["authnet:batch:settled", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Settled batches \u2014 AuthNet groups daily transactions and deposits net proceeds to the merchant bank. Captured via getSettledBatchListRequest. One event per batch with settlement timestamp, payment method, market type, charge/refund totals.", "authnet:batch:settled", "batch", null, null, "poll", 2880, null], ["authnet:batch:stats", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Per-batch statistics broken down by card brand (Visa/MC/Amex/Discover/etc). Captured via getBatchStatisticsRequest per batch ID. Multiple events per settled batch (one per card type present).", "authnet:batch:stats", "batch", null, null, "poll", 2880, null], ["authnet:customer:payment_profile", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "CIM payment profiles \u2014 masked card-on-file records attached to customer profiles. Surfaced from paymentProfiles array of getCustomerProfileRequest. Required for customer migration to recreate stored payment methods.", "authnet:customer:payment_profile", "customer", null, null, "live", 2880, null], ["authnet:customer:profile", 8407, "2014-01-01", "2026-05-22", "2026-07-13T05:30:06Z", "manual_seed", "CIM customer profile shell records (customerProfileId + email + merchantCustomerId). Captured via getCustomerProfileIdsRequest then per-ID enumeration. Full nested detail lives in authnet:customer:profile:detail.", "authnet:customer:profile", "customer", null, null, "backfill", null, null], ["authnet:customer:shipping_address", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Shipping addresses attached to CIM customer profiles. Surfaced from shipToList array of getCustomerProfileRequest. Required for customer migration.", "authnet:customer:shipping_address", "customer", null, null, "live", 2880, null], ["authnet:fraud:held", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "AFDS held transactions awaiting manual review. Captured via getUnsettledTransactionListRequest with status=heldByReview. Snapshot source \u2014 transactions move in/out of held state continuously, so api_total=0 is correct semantics (no finite expected count).", "authnet:fraud:held", "fraud", null, null, "live", 2880, null], ["authnet:merchant:profile", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Merchant account configuration snapshot (gateway ID, merchant name, settings). Captured via getMerchantDetailsRequest. Single-record snapshot for change detection; api_total=0 since no finite history to compare against.", "authnet:merchant:profile", "merchant", null, null, "snapshot", null, null], ["authnet:notification_failed", 0, null, null, "2026-05-23T00:00:00Z", "bounded_known", "Failed webhook delivery records with full payload. Captured via webhook notification history endpoints. AuthNet retains delivery history for a bounded window \u2014 bounded_known will mark this as complete-within-retention rather than under-captured once api_total is set.", "authnet:notification_failed", "notification_failed", null, null, "poll", 2880, null], ["authnet:notification_history", 0, null, null, "2026-05-23T00:00:00Z", "bounded_known", "Webhook notification delivery history (successful + failed). Captured via webhook history endpoints. AuthNet retains history for a bounded window \u2014 bounded_known marks this as retention-limited.", "authnet:notification_history", "notification_history", null, null, "poll", 2880, null], ["authnet:subscription", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "ARB (Automated Recurring Billing) subscription list summaries. Captured via ARBGetSubscriptionListRequest. One event per subscription with summary fields (id, name, status, amount).", "authnet:subscription", "subscription", null, null, "poll", 2880, null], ["authnet:subscription:detail", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Full ARB subscription details (schedule, amount, customer profile link, payment schedule). Captured via ARBGetSubscriptionRequest per subscription ID. Required for subscription migration.", "authnet:subscription:detail", "subscription", null, null, "poll", 2880, null], ["authnet:subscription:status", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Current status snapshot per ARB subscription (active/cancelled/expired/terminated). Captured via ARBGetSubscriptionStatusRequest. Snapshot source refreshed per poll cycle.", "authnet:subscription:status", "subscription", null, null, "poll", 2880, null], ["authnet:transaction", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Individual transactions within each settled batch. Captured via getTransactionListRequest per batch ID. Includes auth/capture, refund, void, decline records with masked card and customer reference.", "authnet:transaction", "transaction", null, null, "poll", 2880, null], ["authnet:transaction:detail", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Selectively-fetched full transaction details \u2014 fired on demand (refunds, disputes, customer support lookups), not bulk-backfilled. Captured via getTransactionDetailsRequest. api_total=0 since this is selective, not 1:1 with all transactions.", "authnet:transaction:detail", "transaction", null, null, "poll", 2880, null], ["authnet:transaction:unsettled", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Current unsettled in-flight transactions (authorized but not yet captured/settled). Captured via getUnsettledTransactionListRequest. Snapshot source \u2014 transactions move out of unsettled into batches continuously; api_total=0 is correct semantics.", "authnet:transaction:unsettled", "transaction", null, null, "poll", 360, null], ["authnet:webhook", 0, null, null, "2026-05-23T00:00:00Z", "webhook_inbound", "Live Authorize.Net webhook events (HMAC-SHA512 verified). Routed via /ingest/authnet/<gateway_id> to support multi-account. Forward-only event stream \u2014 api_total=0 is correct semantics for a live stream with no finite expected count.", "authnet:webhook", null, null, null, "live", 1440, null], ["authnet:webhook_config", 0, null, null, "2026-05-23T00:00:00Z", "backfill_pending", "Webhook subscription configuration snapshot \u2014 which events are subscribed and to what URL. Captured via getWebhookNotificationsRequest. Snapshot source for change detection.", "authnet:webhook_config", "webhook_config", null, null, "snapshot", null, null], ["bc:account", 0, null, null, "2026-05-21T20:04:51Z", "manual_seed", "Live BC Account GraphQL API state poller (5-min cadence). State-diff derived events: user creations/disablements (category=user), auth logins from lastLoginAt diff (category=auth), permission changes (category=permission), app installs/removes (category=app). Forward-only event stream since 2026-05-05. No finite API truth (api_total=0 -> unverified gray pill). Sibling source bc:account:backfill is the one-time inventory snapshot.", null, null, null, null, "poll", 30, "bc:account"], ["bc:account:backfill", 86, "2026-05-21T19:50:30Z", "2026-05-21T19:50:34Z", "2026-05-21T20:00:55Z", "bounded_known", "One-time comprehensive snapshot of BC Account GraphQL API (accountInfo + account/store users + account/store apps + stores). 27 account-users + 26 store-users + 1 account-app + 9 store-apps + 3 stores + 2 accountInfo across centralvapors + wholesale parent accounts. BC GraphQL has no historical event log; this captures current state only. method=bounded_known reflects API enumeration limit.", null, null, null, null, "backfill", null, null], ["bc:channels:snapshot", 5, null, null, "2026-05-21T21:04:18Z", "bounded_known", "Initial snapshot of BC channels across 3 stores: retail=3 (centralvapors.com storefront, TikTok disconnected, facebookAnalytics-0 hidden from UI), wholesale=1 (cvwholesalejuice.com), sandbox=1 (prelaunch). One-shot via bc_channels_snapshot.py. Re-run to refresh count when channels added/removed.", "bc:channels:snapshot", "channel", null, null, "snapshot", null, null], ["bc:customers:backfill", 368079, null, null, "2026-05-31T08:56:52Z", "api_walk", "Two BC stores combined", "bc:customers:backfill", null, null, null, "backfill", null, null], ["bc:hooks:snapshot", 128, null, null, "2026-05-21T23:23:20Z", "bounded_known", "Security-baseline snapshot. Per-store counts: retail=64, wholesale=64. Captured at 2026-05-21T23:23:20Z.", "bc:hooks:snapshot", "webhook", null, null, "snapshot", null, null], ["bc:orders:backfill", 715212, null, null, "2026-05-20 12:28:18", "api_walk", "BigCommerce orders backfill (/v3/orders REST). 2015-01-01 onward, both CV and WS stores. [HISTORY] 2026-05-20: bc_hash=NULL bug fixed; 48,834 legacy duplicate events in audit.db are immutable (chain hash design forbids retroactive UPDATE). DISTINCT_COUNT_SOURCES workaround in refresh_coverage_snapshot.py keeps display count accurate. Forward dedup verified working (gap-close run committed 397 new orders with 705,944 dedup hits).", "bc:orders:backfill", null, null, null, "backfill", null, null], ["bc:products:backfill", 1711, null, null, "2026-05-19T13:00:00Z", "api_walk", "Two BC stores combined", "bc:products:backfill", null, null, null, "backfill", null, null], ["bc:redirects:snapshot", 1928, null, null, "2026-05-21T23:23:20Z", "bounded_known", "Security-baseline snapshot. Per-store counts: retail=1628, wholesale=300. Captured at 2026-05-21T23:23:20Z.", "bc:redirects:snapshot", "redirect", null, null, "snapshot", null, null], ["bc:settings:snapshot", 2, null, null, "2026-05-21T23:23:20Z", "bounded_known", "Security-baseline snapshot. Per-store counts: retail=1, wholesale=1. Captured at 2026-05-21T23:23:20Z.", "bc:settings:snapshot", "settings", null, null, "snapshot", null, null], ["bc:state_diff", 0, null, null, "2026-05-21T20:07:49Z", "manual_seed", "BC storefront state-diff stream: volatile fingerprint changes detected on public-facing storefront pages between polls. Forward-only since 2026-05-07. No finite API truth.", null, null, null, null, "state_diff", 2880, "bc:state_diff"], ["bc:store_info:snapshot", 2, null, null, "2026-05-21T23:23:20Z", "bounded_known", "Security-baseline snapshot. Per-store counts: retail=1, wholesale=1. Captured at 2026-05-21T23:23:20Z.", "bc:store_info:snapshot", "store_info", null, null, "snapshot", null, null], ["bc:systemlog:backfill", 29525, null, null, "2026-05-19T13:00:00Z", "bounded_known", "BC retention bounded; data starts 2025-05-07", "bc:systemlog:backfill", null, "bc:systemlog", null, "poll", 30, "bc:systemlog"], ["bc:themes:snapshot", 14, null, null, "2026-05-21T23:23:20Z", "bounded_known", "Security-baseline snapshot. Per-store counts: retail=0, wholesale=14. Captured at 2026-05-21T23:23:20Z.", "bc:themes:snapshot", "theme", null, null, "snapshot", null, null], ["bc:webhook", 0, null, null, "2026-05-21T20:07:49Z", "manual_seed", "Live BC webhook receiver: order/product/customer/cart/inventory lifecycle events from BigCommerce webhook fleet across centralvapors + wholesale stores. BC scopes mapped to events.scope column. Forward-only since 2024-10-27. No finite API truth (webhook delivery is best-effort).", null, null, null, null, "live", 360, null], ["cloudflare:access:logs", 0, null, null, "2026-05-20T03:44:41Z", "bounded_known", "CV removed Cloudflare Access from services in 2026 (CORS-on-POST limitation); 8 vestigial Access apps remain but generate no auth traffic. Poller verified 3x on 2026-05-20 returning 0 events. If Access usage resumes, install filelock in venv and schedule DSM task.", "cloudflare:access:poller", null, null, null, "poll", 2880, "cloudflare:access:poller"], ["cloudflare:audit:backfill", 10792, null, null, "2026-07-13T05:30:06Z", "bounded_known", "v1 floor 2025-03-11 (CF retains older but v1 endpoint returns 0 for 2025-05 to 2026-01; gap unrecoverable per CF v1 retention reliability). v2 floor 2026-03-10 GA; Beta floor 2026-02-08 expired 2026-04-09 per published CF v2 retention policy. v2 covers ~95% CF products vs v1 ~75%; per-month overlap shows v2 captures 6-11% more events than v1. Both coexist with same source name, distinct correlation_id formats (cf:<id> v2, raw UUID v1). Full backfill 2026-05-20.", "cloudflare:audit:backfill", null, null, null, "poll", 1440, "cloudflare:audit:poller"], ["cloudflare:ct_logs", 0, null, null, "2026-05-20T05:35:55Z", "bounded_known", "External polling of crt.sh JSON API for centralvapors.com, cvwholesalejuice.com, cvreports.com. Captures CT-logged certs. Flags certs from CAs outside allowlist. Rogue cert detection (phishing/MITM precursor).", null, null, null, null, "poll", 2880, "cloudflare:ct_logs:poller"], ["cloudflare:firewall:events", 0, null, null, "2026-05-20T05:35:55Z", "bounded_known", "Cloudflare GraphQL Analytics firewallEventsAdaptive, filtered to action_neq=allow. 30-day retention. Captures blocks, challenges, log-only, bypass. Recon and exploit-attempt forensics.", null, null, null, null, "poll", 1440, "cloudflare:firewall:poller"], ["cloudflare:nel:reports", 0, null, null, "2026-05-20T05:35:55Z", "bounded_known", "Cloudflare GraphQL Analytics nelReportsAdaptiveGroups (aggregated). Each audit event = one aggregation row with count + dimensions. TLS interception, cert errors, MITM forensics. NEL must be enabled per-zone in CF dashboard.", null, null, null, null, "poll", 2880, null], ["cloudflare:page_shield:events", 0, null, null, "2026-05-20T05:35:55Z", "bounded_known", "Page Shield events derived from REST API /scripts /connections /cookies /policies endpoints. Emits one event per entity first_seen_at + one per malicious classification (score < 10). Backfill = snapshot of all current entities. Primary Magecart/skimmer detection layer.", null, null, null, null, "poll", 2880, "cloudflare:page_shield:poller"], ["cloudflare:state_diff:access_apps", 8, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare Access application state snapshot", "cloudflare:state_diff", "access_apps", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:access_policies", 3, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare Access policy state snapshot (per-app, aggregated)", "cloudflare:state_diff", "access_policies", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:dns_records", 64, null, null, "2026-05-19T23:47:06.360Z", "bounded_known", "Cloudflare DNS record state snapshot (per-zone, aggregated)", "cloudflare:state_diff", "dns_records", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:ip_lists", 2, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare account-level IP/Rules Lists state snapshot", "cloudflare:state_diff", "ip_lists", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:page_rules", 0, null, null, "2026-05-21T20:17:23Z", "manual_seed", "Cloudflare Page Rules state-diff stream. Sibling of other cloudflare:state_diff:* sources. captured=0 indicates either no page rules currently configured or poller has not yet detected initial state.", null, null, null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:page_shield_connections", 33, null, null, "2026-05-20T00:01:45.617Z", "bounded_known", "Page Shield Connection Monitor is a Business-plan feature; only centralvapors.com entitled. Other 6 zones return 403 \"Zone not entitled to use Connection Monitor\" \u2014 expected, logged WARN.", "cloudflare:state_diff", "page_shield_connections", null, null, "state_diff", 2880, "cloudflare:page_shield:poller"], ["cloudflare:state_diff:page_shield_cookies", 51, null, null, "2026-05-20T00:01:45.617Z", "bounded_known", "Page Shield Cookie Monitor is a Business-plan feature; only centralvapors.com entitled. Other 6 zones return 403 \"Zone not entitled to use Cookie Monitor\" \u2014 expected, logged WARN.", "cloudflare:state_diff", "page_shield_cookies", null, null, "state_diff", 2880, "cloudflare:page_shield:poller"], ["cloudflare:state_diff:page_shield_scripts", 3698, null, null, "2026-05-20T00:01:45.617Z", "bounded_known", "Page Shield: detected client-side scripts (per-zone where enabled)", "cloudflare:state_diff", "page_shield_scripts", null, null, "state_diff", 2880, "cloudflare:page_shield:poller"], ["cloudflare:state_diff:tunnels", 1, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare Tunnel state snapshot (non-deleted tunnels only)", "cloudflare:state_diff", "tunnels", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:waf_rulesets", 26, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare WAF ruleset state snapshot (per-zone, includes managed)", "cloudflare:state_diff", "waf_rulesets", null, null, "state_diff", 2880, "cloudflare:state_poller"], ["cloudflare:state_diff:zones", 7, null, null, "2026-05-19T23:47:06.360Z", "api_walk", "Cloudflare zone state snapshot (all zones in account)", "cloudflare:state_diff", "zones", null, null, "state_diff", 2880, "cloudflare:state_poller"]], "truncated": false, "filtered_table_rows_count": 81, "expanded_columns": [], "expandable_columns": [], "columns": ["source", "api_total", "api_oldest", "api_newest", "measured_at", "method", "notes", "event_source", "event_category", "live_event_source", "live_event_category", "mode", "freshness_sla_minutes", "heartbeat_source"], "primary_keys": ["source"], "units": {}, "query": {"sql": "select source, api_total, api_oldest, api_newest, measured_at, method, notes, event_source, event_category, live_event_source, live_event_category, mode, freshness_sla_minutes, heartbeat_source from source_truth order by source limit 51", "params": {}}, "facet_results": {}, "suggested_facets": [], "next": "cloudflare~3Astate_diff~3Azones", "next_url": "http://db.cvreports.com/audit/source_truth.json?_next=cloudflare~3Astate_diff~3Azones", "private": false, "allow_execute_sql": true, "query_ms": 13.371797977015376}