← Documentation home

Canonical Markdown source · Oct 20, 2018

Organic campaign and consented-email readiness

ops/organic-campaign-readiness.md · 27 lines · SHA-256 78de5ab885b0

`pnpm organic:campaign-readiness` assembles the exact organic provenance-course audience, confirmation purpose, five-message copy, privacy boundary, and release digest. It writes JSON and Markdown operator artifacts under `artifacts/organic-income/campaign/`. The command is read-only with respect to people and providers: it does not enable capture or sending, contact anyone, accept terms, or authorize a campaign.

The JSON artifact carries a canonical `artifactSha256` over the complete

persisted record, including production receipts, approval, blockers, release

files, and authority boundary. The research approval register accepts its state

only after reproducing that digest; any mutation fails closed.

Audience boundary

Only a person who explicitly requests the provenance course and completes double opt-in can become eligible. Previous museum or institutional outreach recipients are not imported or reused. The free checklist remains available without email. Agents cannot broaden the audience, change copy, infer consent, approve a release, or initiate a send.

Non-compensating gate

Readiness requires all local controls plus fresh, attributable, non-synthetic production receipts for confirmation, delivery, unsubscribe, suppression, permanent-bounce handling, and aggregate measurement. An accountable human must approve the exact digest and separately attest to audience, copy, privacy, deliverability, and measurement. A passing artifact still reports `emailSendingAuthorized: false`; production configuration remains a separate operator action.

The retained evidence configuration is `config/organic-campaign-evidence.json`. Direct identifiers never belong there. Each production receipt uses an HTTPS reference, capture time, SHA-256 digest, and `synthetic: false` boundary.

Failure and suppression behavior

Failed deliveries are durably marked `failed` and stop automatic retries. Temporary failures are held for operator review. Only verified permanent bounces and complaints are eligible for automated suppression, using a SHA-256 email hash and attributable provider receipt. Raw email addresses, names, addresses, and phone numbers are rejected from the reconciliation contract. Unsubscribe-token suppression remains immediate and idempotent.

Measurement boundary

Confirmation, delivery, unsubscribe, suppression, bounce, click, and funnel counts are operational evidence only. They do not establish scholarly validation, demand, revenue, or income. Income requires provider-confirmed live settlement less refunds, fees, and attributable costs.