Skip to main content
Recovery continues only when the next action is proven safe. It never guesses whether a provider created a CFDI and never replaces CargoWise accounting evidence silently.

Automatic recovery

Automatic recovery resumes saved intent and saved provider evidence. It does not remap a newer source. Automatic recovery stops and opens a failure when the provider result remains unknown, state is inconsistent, the bounded budget is exhausted, or a source correction is required.

Corrective recovery

Corrective recovery is for a stopped document with a meaningful source or prerequisite change. It is not a repeat of the same failed request. A document can become eligible when:
  • corrected CargoWise data maps to different fiscal facts
  • a required parent or SAT UUID is now usable
  • a required certificate, route, or approved prerequisite is now ready
  • a verified client fiscal profile correction is available for the document
Stamped, cancelled, in-flight, waiting, or unchanged documents remain protected.
1

Build a preview

Lambda reads the immutable source, current mapping, active incident, fiscal state, and prerequisite evidence.
2

Explain the change

The preview states what changed, why the document is eligible, and which action would run.
3

Bind the decision

Lambda creates a hash of the exact preview. A source, failure, lifecycle, or prerequisite change makes the old preview stale.
4

Apply the fresh preview

Apply must present the fresh hash and a reason. Lambda checks the hash again before creating work.
The original capture remains unchanged. A stale review cannot act after the document changes.

Corrective retry is not automatic recovery

  • Corrective retry creates a new attempt only when the previous provider create is not_started or known_not_created.
  • An existing or uncertain provider result belongs to exact-attempt recovery and verification. It does not create a new retry run.
  • Retry does not send a customer notification by itself. Fiscal events, artifact results, and delivery results remain separate.
  • A replacement of a Lambda-owned CFDI is a controlled operation with an explicit SAT motive. Lambda never infers the motive. External CFDIs have no normal Lambda replacement path.

Client fiscal data correction

The native client correction flow is narrower than general recovery. It is available only when Facturapi proves that no CFDI was created and every rejected field belongs to the recipient fiscal profile, such as RFC, legal name, fiscal regime, postal code, or country. Each edit creates a new profile revision. Lambda validates the complete profile, uses it for one retry, and requires a successful canary stamp before the revision can be reused. An ambiguous CargoWise organization code keeps the correction limited to the current document. Profiles are not applied automatically to future CargoWise documents.

Choose the owning path

See Reliability for the controls that make these paths safe.