How should an order system connect review, payment confirmation, and fulfilment?
Use a state machine, but never treat an uploaded remittance slip as confirmed funds. Operations verifies that the order can be fulfilled; finance allocates a trusted bank transaction or payment callback; only then does the system release the warehouse according to policy. Payments, shipments, refunds, and amendments remain separate entries rather than overwritten history.
The workflow is not a straight line. Every release needs an accountable role, reliable evidence, and an exception route. Wavesteam stores commercial, payment, and fulfilment states separately: an approved order may be partly paid, and a partly shipped order may have an overdue balance. One generic status field cannot describe these combinations.
When decomposing features, data, and acceptance scenarios, also compare How should a B2B sales system separate leads, contracts, deposits, procurement, and delivery?; the linked guidance adds context that should be considered in the same decision.
| Step | Authorized role | Evidence | Result | Insufficient evidence |
|---|---|---|---|---|
| Order review | Operations; manager for exceptional discount | Customer, items, price, stock policy, date, tax, destination | Draft becomes approved or rejected | Verbal sales confirmation |
| Payment allocation | Finance or trusted payment service | Bank reference, amount, currency, payer, time, unallocated balance | Payment and allocation entries | Customer screenshot |
| Warehouse release | Policy engine decides; warehouse executes | Allocated amount, credit, hold status, releasable quantity | Outbound task | “Paid” label on a page |
| Shipment | Warehouse | Dispatch, lot/serial, quantity, carrier, tracking | Shipment ledger and reduced balance | Tracking number alone |
| Receipt / completion | Carrier callback, client, or operations | Delivery, refusal/damage, invoice, after-sales state | Complete or exception | Arrival in destination city |
The order header stores stable commercial terms; lines store item, quantity, price, and tax; payment records store actual receipts; allocations link receipts to one or more orders; shipment documents support splits; and the state log retains actor, transition, reason, and evidence. This supports one payment across orders, overpayment, partial payment, split shipment, and refund without repeatedly editing summary fields.
Review separates completeness from authority. Standard price and terms may pass once; exceptional discount, credit, region, or delivery date escalates. A change to item, amount, payment terms, or legal recipient invalidates the earlier approval. The state/event/transition concepts in W3C SCXML are useful, although a business system need not implement that specification directly.
Trusted payment facts come from bank integration, payment callbacks, or finance-imported statements. Matching uses reference, amount, payer, and time and supports fees, short payment, unidentified funds, and one payment for several orders. A remittance image only indicates possible payment. Automated callbacks still require signature, amount and merchant-order checks plus idempotency.
Release policies may require full payment, a configured percentage, or approved credit. Warehouse users see only necessary fulfilment data. Dispatch never exceeds the approved and unshipped quantity. Cancellation, amendment, and refund create voids, reversals, or new documents rather than deleting the audit trail. OWASP ASVS provides relevant authorization and business-logic controls.
Acceptance covers full and partial payments, duplicate callbacks, one-to-many allocation, overpayment, rejected discount, reapproval, split shipment, shortage, repeated carrier events, refusal, refund, and cancellation. Reconcile order total with allocated and outstanding amounts, enforce releasable quantities, preserve reversals, and deny unauthorized APIs. An OpenAPI contract fixes fields, idempotency, and errors.
Wavesteam models states and responsibilities from the client's real documents and finance policy before implementing screens. Our AI order OCR solution can assist entry; OCR never replaces approval or proof of cleared funds.