{
  "standard_version": "RPS-1.0.0",
  "report_id": "SC-RPS-2026-08-15-01",
  "certified_at": "2026-08-15",
  "certification_expires_at": "2027-02-15",
  "certifier": {
    "name": "Staycore Product & Controls Team",
    "type": "first_party"
  },
  "product_revision": "abb13ae6f274010763c86fc8cacbc2f3f6e5cfd5",
  "measurement_basis": "applicable_scenarios",
  "minimum_coverage_rate": 0.97,
  "result": {
    "applicable_scenarios": 40,
    "passed_scenarios": 40,
    "failed_scenarios": 0,
    "coverage_rate": 1
  },
  "plans": {
    "hotel_essential": { "applicable_scenarios": 40, "passed_scenarios": 40, "coverage_rate": 1 },
    "hotel_growth": { "applicable_scenarios": 40, "passed_scenarios": 40, "coverage_rate": 1 },
    "hotel_business_plus": { "applicable_scenarios": 40, "passed_scenarios": 40, "coverage_rate": 1 },
    "hotel_enterprise": { "applicable_scenarios": 40, "passed_scenarios": 40, "coverage_rate": 1 }
  },
  "conditions": [
    "All four current hotel plans use the same standard hotel operations feature set.",
    "Door-lock software controls are included in every current hotel plan; door-access outcomes require supported hardware to be installed, configured, and connected.",
    "The certification used controlled automated product scenarios and a supported access-provider test configuration.",
    "Scenario coverage is not a monetary recovery rate and does not represent every form of theft, collusion, physical loss, or off-system activity."
  ],
  "scenarios": [
    { "id": "RPS-ROOM-01", "area": "rooms_access", "outcome": "prevent", "title": "Guest room entry requires an active room booking", "result": "pass" },
    { "id": "RPS-ROOM-02", "area": "rooms_access", "outcome": "prevent", "title": "Incorrect guest identity data is rejected at room entry", "result": "pass" },
    { "id": "RPS-ROOM-03", "area": "rooms_access", "outcome": "reconcile", "title": "A room move follows the current stay and retires the old route", "result": "pass" },
    { "id": "RPS-ROOM-04", "area": "rooms_access", "outcome": "prevent", "title": "A last-name-only session cannot retrieve a mobile key", "result": "pass" },
    { "id": "RPS-ROOM-05", "area": "rooms_access", "outcome": "prevent", "title": "A booking-token-only session cannot retrieve a loyalty-member mobile key", "result": "pass", "observed": "The controlled request denied key delivery; mobile-key retrieval requires a signed-in loyalty-member identity." },
    { "id": "RPS-ROOM-06", "area": "rooms_access", "outcome": "prevent", "title": "A later booking cannot reuse an older room credential", "result": "pass" },
    { "id": "RPS-ROOM-07", "area": "rooms_access", "outcome": "prevent", "title": "Front-desk room locks remain property scoped", "result": "pass" },
    { "id": "RPS-ROOM-08", "area": "rooms_access", "outcome": "prevent", "title": "Random room assignment does not reuse a reserved room", "result": "pass" },

    { "id": "RPS-PAY-01", "area": "payments_accounts", "outcome": "prevent", "title": "A property without Paystack cannot silently offer online prepayment", "result": "pass" },
    { "id": "RPS-PAY-02", "area": "payments_accounts", "outcome": "reconcile", "title": "A non-refundable prepay booking creates a payment link", "result": "pass" },
    { "id": "RPS-PAY-03", "area": "payments_accounts", "outcome": "prevent", "title": "Pay-now is rejected when the property has no payment processor", "result": "pass" },
    { "id": "RPS-PAY-04", "area": "payments_accounts", "outcome": "reconcile", "title": "Exact provider references create matched settlement cases", "result": "pass" },
    { "id": "RPS-PAY-05", "area": "payments_accounts", "outcome": "detect", "title": "Settlement imports classify matched and variance outcomes", "result": "pass" },
    { "id": "RPS-PAY-06", "area": "payments_accounts", "outcome": "detect", "title": "Duplicate provider references are detected", "result": "pass" },
    { "id": "RPS-PAY-07", "area": "payments_accounts", "outcome": "audit", "title": "A reconciliation resolution changes status and writes an audit record", "result": "pass" },
    { "id": "RPS-PAY-08", "area": "payments_accounts", "outcome": "prevent", "title": "A payment reference from another property remains unmatched", "result": "pass" },
    { "id": "RPS-PAY-09", "area": "payments_accounts", "outcome": "prevent", "title": "Corporate invoice payments reject duplicate references", "result": "pass" },
    { "id": "RPS-PAY-10", "area": "payments_accounts", "outcome": "audit", "title": "Corporate credit, debit, and write-off actions emit audit evidence", "result": "pass" },

    { "id": "RPS-FNB-01", "area": "fnb_pos", "outcome": "detect", "title": "Expired POS drafts are hidden from the active work queue", "result": "pass" },
    { "id": "RPS-FNB-02", "area": "fnb_pos", "outcome": "prevent", "title": "An expired POS draft cannot be completed", "result": "pass" },
    { "id": "RPS-FNB-03", "area": "fnb_pos", "outcome": "prevent", "title": "A waiter cannot self-approve a forged manager discount", "result": "pass" },
    { "id": "RPS-FNB-04", "area": "fnb_pos", "outcome": "reconcile", "title": "A KOT amendment keeps completed tickets closed and settles once", "result": "pass" },
    { "id": "RPS-FNB-05", "area": "fnb_pos", "outcome": "prevent", "title": "Full-service tabs cannot settle while a KOT remains open", "result": "pass" },
    { "id": "RPS-FNB-06", "area": "fnb_pos", "outcome": "detect", "title": "Completed unpaid tabs are surfaced and can be restored", "result": "pass" },
    { "id": "RPS-FNB-07", "area": "fnb_pos", "outcome": "prevent", "title": "Offline POS drafts reject cross-owner update and completion", "result": "pass" },
    { "id": "RPS-FNB-08", "area": "fnb_pos", "outcome": "prevent", "title": "POS terminal sync rejects refund and back-office events", "result": "pass" },
    { "id": "RPS-FNB-09", "area": "fnb_pos", "outcome": "prevent", "title": "Operator PINs are verified without storing the raw PIN", "result": "pass" },
    { "id": "RPS-FNB-10", "area": "fnb_pos", "outcome": "audit", "title": "Paid tabs leave the active queue but remain in manager history", "result": "pass" },

    { "id": "RPS-INV-01", "area": "inventory_approvals", "outcome": "prevent", "title": "Purchase-order transitions enforce separation of duties", "result": "pass" },
    { "id": "RPS-INV-02", "area": "inventory_approvals", "outcome": "prevent", "title": "Free-receipt GRNs require an owner or administrator", "result": "pass" },
    { "id": "RPS-INV-03", "area": "inventory_approvals", "outcome": "detect", "title": "Purchase price variance rules are enforced", "result": "pass" },
    { "id": "RPS-INV-04", "area": "inventory_approvals", "outcome": "reconcile", "title": "Supplier invoices reconcile to purchasing and receipt records", "result": "pass" },
    { "id": "RPS-INV-05", "area": "inventory_approvals", "outcome": "audit", "title": "Wastage adjustments retain a normalized reason", "result": "pass" },
    { "id": "RPS-INV-06", "area": "inventory_approvals", "outcome": "prevent", "title": "Inventory checks reject permissions outside the central role map", "result": "pass" },

    { "id": "RPS-GOV-01", "area": "access_governance", "outcome": "prevent", "title": "Managers can decommission locks but cannot delete bound access points", "result": "pass" },
    { "id": "RPS-GOV-02", "area": "access_governance", "outcome": "audit", "title": "Lock deletion preserves historical attendance and provider resolution", "result": "pass" },
    { "id": "RPS-GOV-03", "area": "access_governance", "outcome": "prevent", "title": "Hardware provisioning is atomic, idempotent, and secret-free", "result": "pass" },
    { "id": "RPS-GOV-04", "area": "access_governance", "outcome": "prevent", "title": "Mobile-key payloads exclude unneeded hotel credentials", "result": "pass" },
    { "id": "RPS-GOV-05", "area": "access_governance", "outcome": "prevent", "title": "Senior operational roles preserve inherited permission boundaries", "result": "pass" },
    { "id": "RPS-GOV-06", "area": "access_governance", "outcome": "audit", "title": "Property state snapshots retain stable audit identifiers", "result": "pass" }
  ]
}
