Skip to main content
Recovery continues only when the next safe action is proven. It does not blindly repeat an issuance or replace CargoWise accounting decisions.

Automatic recovery

Automatic recovery resumes persisted work without changing the CargoWise source. Automatic recovery stops and opens a failure when:
  • the provider outcome remains unknown
  • the stored state is inconsistent
  • the bounded attempts are exhausted
  • a source correction is required

Corrective recovery

Corrective recovery is for a document that stopped and later received a meaningful correction. It does not repeat the same failed attempt unchanged. A document can become eligible when:
  • the saved CargoWise source now maps to different fiscal facts
  • a required parent or SAT UUID is now usable
  • a required certificate, route, or approved prerequisite is now usable
Stamped, cancelled, in-flight, waiting, or unchanged documents remain protected.
1

Build the preview

Lambda reads the immutable capture, current mapping, active failure, lifecycle, and prerequisite evidence.
2

Explain the decision

The preview shows whether the document is eligible, what changed, and which standard action would run.
3

Bind the preview

Lambda hashes the exact preview state. The hash changes if the document, source, failure, or prerequisite changes.
4

Apply the exact preview

Apply must present the fresh hash and a reason. Lambda verifies the hash again and records the result.
The original capture remains unchanged. A stale preview cannot act after the document or its prerequisites change.

Choose the owning path

Recovery never creates a second live CFDI while an earlier result may exist.