Integration ownership
Connections attach to the business/product that owns their data and commands. A saved credential or provider-ready indicator is distinct from a successful import, signed callback, customer delivery or reconciliation result. Imports retain raw source evidence, normalization errors, mappings, watermarks and replay/correction history where supported. Extracted documents are candidates for review, not automatic financial/stock truth.
Bookings provider setup, EPOS/Tevalis mapping, payment connections and Gmail mailboxes therefore remain documented in their owning chapters. Shared settings or architecture visibility do not grant access to their underlying records.
Outbound webhooks
The Webhooks settings screen is available through Ticketing integrations and the
legacy /settings/webhooks route. Managing endpoints requires
organization.settings.manage; replay additionally requires domain_events.replay.
Create an endpoint with a name, HTTPS destination and selected supported event names. Local/private-network and nonstandard-port destinations are rejected. Store the one-time signing secret. A new endpoint is configuration only; explicitly Enable delivery after the receiving system is ready.
Endpoint cards show active/paused/archived state, configuration readiness, delivery enablement, subscribed events, signing-key version and counts for pending, delivering, dead-letter and succeeded records. Controls support secret rotation, pause, resume and archive. Previously queued deliveries may still need the previous signing secret during rotation.
Delivery is signed, retried with retained identity and moved to dead-letter review when it cannot complete. Eligible replay requires an attributable reason and current expected replay state. Health is payload-free; a successful delivery count does not expose the business payload. Credential review is a distinct investigation/recovery control.
Audit and architecture visibility
Settings → Audit exposes authorized audit history and the separate historical Loyalty ledger where applicable. The current audit screen loads up to one hundred recent records, with entity-type filtering and time, user, action, entity and detail columns. Audit records help explain actor, action and source changes; they are not a substitute for reading current business state. The detailed capability and settings-directory reference governs who may read it.
Settings → Architecture provides operational/module ownership and backend visibility for authorized people. It can expose source relationships, Loop/task projection and current expiring agent presence. A live agent indicator describes execution only, not delivery completion, deployment or acceptance. Operational health, disclosure receipts and provider evidence remain distinct from private conversation/customer content.
Demand and reports
Soupy does not collapse all reports into one universal source of truth. Ticketing owns sales/performance/attendance reports, Purchasing owns procurement reports and CRM owns its customer/audience insights. Assistant reports retain those same permissions and counting semantics.
Bookings' Arrival forecast uses saved demand runs for the selected date/scope. It distinguishes confirmed and expected demand and displays the source cutoff, missing-venue coverage and stale estimates. Build forecast / Refresh forecast refreshes saved evidence; it does not create Bookings or roster staff. Rota demand planning uses authorized source demand in its planning workflow; attendance outcomes retain separately reviewed actual work evidence.