Choose an enforceable source#
The proposed architecture supports a restricted merchant account, a reusable reserve, or an integrated provider balance that can actually honor bounded refund authority. An accounting record or signed promise alone cannot debit funds.
This sandbox illustrates a merchant-level reserve. It is reusable across obligations and does not require every purchase to be fully escrowed. The live collection architecture is still to be selected.
Represent the funding outcome#
| Approved | Eligible funds | Paid | Still owed |
|---|---|---|---|
| 100 | 100 | 100 | 0 |
| 100 | 40 | 40 | 60 |
| 100 | 0 | 0 | 100 |
These examples use fictional DEMO units and a policy allowing partial collection. For an unchanged award: paid + outstanding = approved. A funding snapshot is not reserved liquidity or a reimbursement guarantee.
Recover from newly eligible funds#
The demo top-up adds exactly the outstanding amount to the enrolled reserve and pays it once. This illustrates reserve recovery. It does not prove access to merchant revenue, unrelated wallets or future inflows.
Where contracts are needed#
The documentation and browser simulation need no onchain deployment. The proposed testnet reserve approach needs an enforceable contract or restricted account module to hold or access enrolled funds and execute bounded refunds. A provider integration is an alternative only if it can enforce equivalent restrictions.
Exact contract structure, network, verifier, deployment addresses and live token support remain undecided. No deployment address exists for this preview.
Enforce at the money-moving boundary#
- Authenticate the decision and exact purchase/policy.
- Check beneficiary, asset/network, amount and cumulative purchase/merchant limits.
- Prevent replay and concurrent duplicate collection.
- Restrict withdrawals, account upgrades and offboarding so accepted obligations are not silently bypassed.
- Reconcile actual transfers, failed attempts and outstanding amounts.
The saved sandbox checks beneficiary, cap and replay constraints in its backend. Those checks apply to simulated accounting; they do not establish enforcement by a deployed contract.