Release archive
3.2.316

REVENUE-OS-INTEROPERABILITY (Private Operations) & REVENUE-OPS-SCOPED-HMAC (Internal Security)

Release v3.2.316 focuses on REVENUE-OS-INTEROPERABILITY (Private Operations) and REVENUE-OPS-SCOPED-HMAC (Internal Security).

AddedInternal
REVENUE-OS-INTEROPERABILITY (Private Operations) & REVENUE-OPS-SCOPED-HMAC (Internal Security)

Release digest

Added

  • REVENUE-OS-INTEROPERABILITY (Private Operations) — Added canonical growth_operations.v1 JSON Schema and golden aggregate fixture, the closed destination-aware campaign_link.v2 builder, and a read-only pilot_intake_sync.v1 cursor endpoint for the separate private Revenue OS.
  • REVENUE-OPS-SCOPED-HMAC (Internal Security) — Added an exact revenue_ops key scope whose signature covers the request method, path, raw query, timestamp, nonce, and body hash while preserving the existing bridge canonical payload for current consumers.

Internal

  • Added the canonical Revenue Operations architecture, time-bounded sprint exception, environment inventory, and private integration/operator runbook.
  • No user-facing documentation update is required because this is a private founder-only integration. The public offer, pricing, intake form, security_readiness.v1, audit_scope_readiness.v1, and dashboard behavior remain unchanged.
  • Added cross-runtime positive/negative schema parity, HTTP(S), timezone, whitespace and privacy-pattern validation, legacy campaign-link goldens, stable cursor pagination, scoped auth, query tampering, bounded headers, signature-before-nonce handling, shared-store fail-closed behavior, hidden FastAPI OpenAPI operation coverage, full-window future-timestamp replay rejection, strict absolute HTTP(S) evidence URLs, no-log checks, and legacy bridge compatibility coverage.

Technical notes