Automatic recovery
Automatic recovery resumes saved intent and saved provider evidence. It does not remap a newer source.
Automatic recovery stops and opens a failure when the provider result remains unknown, state is
inconsistent, the bounded budget is exhausted, or a source correction is required.
Corrective recovery
Corrective recovery is for a stopped document with a meaningful source or prerequisite change. It is not a repeat of the same failed request. A document can become eligible when:- corrected CargoWise data maps to different fiscal facts
- a required parent or SAT UUID is now usable
- a required certificate, route, or approved prerequisite is now ready
- a verified client fiscal profile correction is available for the document
1
Build a preview
Lambda reads the immutable source, current mapping, active incident, fiscal state, and
prerequisite evidence.
2
Explain the change
The preview states what changed, why the document is eligible, and which action would run.
3
Bind the decision
Lambda creates a hash of the exact preview. A source, failure, lifecycle, or prerequisite change
makes the old preview stale.
4
Apply the fresh preview
Apply must present the fresh hash and a reason. Lambda checks the hash again before creating
work.
Corrective retry is not automatic recovery
- Corrective retry creates a new attempt only when the previous provider create is
not_startedorknown_not_created. - An existing or uncertain provider result belongs to exact-attempt recovery and verification. It does not create a new retry run.
- Retry does not send a customer notification by itself. Fiscal events, artifact results, and delivery results remain separate.
- A replacement of a Lambda-owned CFDI is a controlled operation with an explicit SAT motive. Lambda never infers the motive. External CFDIs have no normal Lambda replacement path.
Client fiscal data correction
The native client correction flow is narrower than general recovery. It is available only when Facturapi proves that no CFDI was created and every rejected field belongs to the recipient fiscal profile, such as RFC, legal name, fiscal regime, postal code, or country. Each edit creates a new profile revision. Lambda validates the complete profile, uses it for one retry, and requires a successful canary stamp before the revision can be reused. An ambiguous CargoWise organization code keeps the correction limited to the current document. Profiles are not applied automatically to future CargoWise documents.Choose the owning path
See Reliability for the controls that make these paths safe.