# Warehouse Final Role-Based QA Evidence

Date: 2026-08-29

## Scope

Final production-demo validation for Warehouse / Fulfillment:

- Warehouse master records
- Locations, zones, racks, shelves, and bins
- Receiving from Purchase Orders and Transfers
- QA-aware putaway
- Picking with allocation evidence
- Dispatch and delivery confirmation
- Transfers
- Bin movement audit
- Stock reconciliation
- Picking exceptions
- Backorders
- Substitutions
- Analytics

## Automated RBAC Evidence

Command:

```powershell
php tools\warehouse-rbac-qa.php
```

Expected result: all middleware checks pass.

Covered personas:

- Warehouse Manager
- Warehouse Clerk
- QA Inspector
- Sales/Fulfillment User
- Read-only Viewer

Covered permissions:

- `warehouse.view`
- `warehouse.warehouses.create`
- `warehouse.warehouses.update`
- `warehouse.warehouses.delete`
- `warehouse.locations.create`
- `warehouse.locations.update`
- `warehouse.locations.delete`
- `warehouse.receiving.confirm`
- `warehouse.transfers.receive`
- `warehouse.putaway.complete`
- `warehouse.picking.reserve`
- `warehouse.picking.exceptions.view`
- `warehouse.picking.exceptions.manage`
- `warehouse.picking.override`
- `warehouse.dispatch.post`
- `warehouse.delivery.confirm`
- `warehouse.reconciliation.resolve`

## Browser QA Checklist

### Warehouse Manager

1. Open `/warehouse/outbound/sales`.
2. Confirm manager can view allocation evidence on pick lists.
3. Resolve picking exceptions with:
   - backorder
   - approve partial dispatch
   - request substitution
   - cancel remaining quantity
   - fulfillment hold
   - QA or scrap review
   - close as corrected
4. Open `/warehouse/backorders`.
5. Confirm manager can reallocate, close, and cancel backorders.
6. Open `/warehouse/substitutions`.
7. Confirm manager can select substitute item, approve, and reject requests.
8. Open `/warehouse/reconciliation`.
9. Confirm manager can resolve reconciliation cases.

### Warehouse Clerk

1. Open `/warehouse/inbound/po`.
2. Confirm clerk can confirm receiving when permitted.
3. Open `/warehouse/putaway`.
4. Confirm clerk can complete putaway for QA-released stock only.
5. Open `/warehouse/outbound/sales`.
6. Confirm clerk can pick and dispatch allowed work.
7. Confirm clerk can view picking exceptions but cannot resolve manager-only exception workflows.
8. Confirm clerk cannot manage warehouses, locations, or reconciliation resolution.

### QA Inspector

1. Open warehouse pages allowed by `warehouse.view`.
2. Confirm QA inspector can view QA-related warehouse flow and exception evidence.
3. Confirm QA inspector cannot:
   - resolve pick exceptions
   - approve partial dispatch
   - reallocate backorders
   - approve substitutions
   - manage warehouse/bin setup
   - resolve reconciliation cases

### Sales/Fulfillment User

1. Open `/warehouse/outbound/sales`.
2. Confirm fulfillment status, allocation evidence, dispatch state, and delivery state are visible.
3. Confirm permitted fulfillment actions match backend permissions.
4. Confirm manager-only exception actions are hidden or disabled.

### Read-only Viewer

1. Open `/warehouse/list`, `/warehouse/locations`, `/warehouse/outbound/sales`, `/warehouse/backorders`, `/warehouse/substitutions`, `/warehouse/movements`, `/warehouse/reconciliation`, and `/warehouse/analytics`.
2. Confirm data is visible where `warehouse.view` allows it.
3. Confirm all mutation actions are hidden or disabled.
4. Attempt direct action URLs/API calls and confirm 403 responses.

## Direct API Permission Checks

Confirm non-manager personas are blocked from:

- `PATCH /api/v1/warehouse/pick-exceptions/{id}/resolve`
- `PATCH /api/v1/warehouse/pick-backorders/{id}/reallocate`
- `PATCH /api/v1/warehouse/pick-substitutions/{id}/decision`
- `PATCH /api/v1/warehouse/reconciliation-cases/{id}/resolve`

Confirm warehouse clerks without setup permissions are blocked from:

- `POST /api/v1/warehouse/warehouses`
- `PUT /api/v1/warehouse/warehouses/{id}`
- `DELETE /api/v1/warehouse/warehouses/{id}`
- `POST /api/v1/warehouse/bin-locations`
- `PUT /api/v1/warehouse/bin-locations/{id}`
- `DELETE /api/v1/warehouse/bin-locations/{id}`

## Readiness Call

Warehouse / Fulfillment is production-demo ready after the browser checklist passes with persisted demo records for:

- one clean pick/dispatch flow
- one short-pick backorder flow
- one substitution approval flow
- one fulfillment hold flow
- one reconciliation resolution flow

Known non-blocker:

- Frontend route-level code splitting is still needed to reduce bundle size.
