# Briefing manual ,  three websites, one business

Companion to [`BUILD_PROMPT.md`](./BUILD_PROMPT.md). That document says *what* to
build. This one says **why each decision was made**, and **what you personally have
to do** ,  the plug-and-play actions no code can perform for you ,  before the sites
can take a customer and collect money.

---

# Part 1 ,  Why

## 1.1 Why this business, and why only this one

The scorecard (`scorecard/report.html`) ranks ten candidates. Dump-ticket charge
packets score highest at 4.13. Paper work-order missed billables score 4.02 and are
still the recommendation, because the 0.11 gap is inside the noise of a judgement-
based score and the reachability difference is not.

Dump-ticket scores 3 on customer reachability. Roll-off haulers are a short,
relationship-gated list; without an existing hauler contact you are cold-calling a
few hundred companies. Missed billables scores 5. Every state has an HVAC
contractors' association with a published member directory, and the same product
sells unchanged into plumbing, electrical, septic and landscaping.

**If you already have a hauler relationship, build the dump-ticket version instead.**
The architecture in the build prompt is unchanged ,  different documents, same
pipeline. That is the whole point of one shared backend.

Two scores deserve attention because they are the engineering risk: automation 3 and
data ease 3. Handwriting on a greasy carbon-copy form is genuinely hard to read, and
there is no API to pull it from. This is not a business where you press deploy and
walk away. Budget real time for the exceptions queue in months one through four. The
build prompt's rule ,  nothing over $500 or under 0.90 confidence is auto-accepted ,
is a deliberate throughput sacrifice in exchange for never sending a customer a
number they can disprove.

## 1.2 Why three sites instead of one

The conventional answer is one site with three landing pages. That is wrong here,
and the reason is the price spread: $750 self-serve to $3,500/month invoiced. A
single design cannot hold both ends.

A page built to convert an owner-operator on a phone ,  huge type, a calculator, a
card field ,  reads as unserious to a CFO evaluating a $42,000 annual commitment. A
page built for that CFO ,  methodology, subprocessor lists, a downloadable MSA ,
reads as slow and corporate to someone who wants a number before their next call.

Three sites, one backend. The marginal cost is CSS and copy. The marginal benefit is
that each buyer sees something built for them. The shared pipeline means a customer
from any door is fulfilled identically.

Segmentation is by **buying behaviour**, not company size:

| | Option A | Option B | Option C |
|---|---|---|---|
| Buyer | Owner | Controller / VP Ops | Portfolio CFO |
| Committee | 1 | 3 | 4+ |
| Decides in | Minutes | Weeks | A quarter |
| Reads on | Phone | Laptop | Laptop, forwards it |
| Wants first | A number | A method | A variance |
| Pays by | Card | ACH, net-15 | ACH, annual |
| Killed by | Friction | Vagueness | No benchmark |

## 1.3 Option A ,  "Yard Sign": why

**Why the calculator is the hero, not a headline.** This buyer does not read
headlines. They have been pitched software four times this year. A headline asks
them to believe a claim; a calculator asks them to enter facts they already know and
watch a number appear. The number is theirs, so it is credible. Three inputs, no
email gate ,  every gate before the number costs more than the email address is
worth at this price point.

**Why a range and not a figure.** "You are leaving $6,200 a month on the table" is a
lie ,  you have not seen their work orders. "$3,100  to  $8,600, based on a 2 to 8% miss
rate" is true, and the honest version converts better with this buyer because they
have a working detector for salesmen. The $750 audit is explicitly sold as the way
to replace the range with a real number. The estimate is the argument for the
product, not a substitute for it.

**Why safety orange on near-black.** It is the palette of the equipment they already
own ,  cones, hi-vis, compressor decals. It signals trade, not SaaS. Orange is
reserved for CTAs and money figures so that colour always means "this is the
number", never decoration.

**Why condensed uppercase and 17px body.** The buyer is typically over forty, often
outdoors, often on a cracked screen in bright sun. 17px base and 48px tap targets
are accessibility decisions that happen to also be conversion decisions.

**Why self-serve checkout with no call.** At $750, a sales call costs more than the
margin. It also selects for the wrong customer ,  anyone willing to sit through a
demo for a $750 product will be expensive to serve. Land on the upload screen, not
a thank-you page: the twenty seconds after payment are the only moment you will
reliably have their attention.

**Why square corners and no shadows.** Rounded, soft, shadowed UI reads as
consumer-app polish, which reads as expensive, which reads as not-for-me. Hard edges
read as a tool.

## 1.4 Option B ,  "The Ledger": why

**Why a document is the hero.** This buyer's job is reading documents and finding
what is wrong with them. Give them the actual artifact ,  a real redacted report,
paginated, with methodology in the margin ,  and they evaluate the product directly
instead of evaluating your marketing. It also short-circuits the demo request, which
is the slowest step in the funnel.

**Why security is top-level navigation.** The order of questions for a controller is
security, then accuracy, then price. If the security answer is a footer link, they
assume the answer is bad. Putting it in the nav answers the question before it is
asked and signals you have been through procurement before.

**Why a "What we don't claim" section.** Counter-intuitive and correct. This buyer
has read fifty vendor pages that all claim everything. A stated false-positive rate
and an honest list of what the product misses is the single strongest credibility
signal available, and it pre-empts the objection they were going to raise on the
call anyway. It also protects you: a customer who was told the limits up front does
not churn angry in month three.

**Why navy, parchment and a serif.** The register of an audit memo. It is deliberately
not exciting. Excitement is a negative signal to someone whose job is caution.

**Why invoice and not card.** Companies at this size do not put $2,500 on a card from
a website. Their AP process is net-15 ACH against an invoice with a PO number. Asking
for a card is asking them to break their own process, and they will not.

**Why the five downloadable documents.** MSA, DPA, W-9, subprocessor list, security
overview. Procurement asks for all five, always. Having them on the site
unauthenticated removes a two-week round trip and is the cheapest cycle-time
improvement available.

**On the certification question.** If you are not SOC 2 certified, say so and
describe what you do instead. This buyer will ask for the report. A bluff is
discovered in one email and costs the deal, the referral, and the reputation in a
small industry.

## 1.5 Option C ,  "The Console": why

**Why the console is the hero.** This buyer does not want to be told the product
works; they want to operate it. A live, sortable, forty-location table lets them
mentally substitute their own portfolio while they scroll. Nothing else on a page
does that.

**Why the argument is variance, not total.** A portfolio CFO already assumes some
revenue leaks. What they cannot see is that location 31 leaks four times what
location 7 does. Variance is actionable ,  it names an operator to call ,  where a
portfolio total is just another number in a deck. Selling variance also makes the
product structurally sticky: once they manage to the benchmark, they need the
benchmark.

**Why dark and dense.** They live in dashboards. Sparse marketing whitespace reads as
"this is a brochure"; density reads as "this is instrumentation".

**Why the assessment produces a forwardable URL.** This buyer never decides alone.
The output must survive being pasted into an email to three partners without you in
the room. A unique URL with their own numbers on it is a better artifact than any
PDF you could attach.

**Why billing and service entities are separable.** In roll-ups the management
company pays and the operating entities consume. Get this wrong in the data model
and you rebuild it under deadline during your largest contract. That is what
`organizations.parent_org_id` exists for, and it costs nothing to include now.

**Why "Demonstration data" is labelled in plain sight.** A prospect who briefly
believes they are seeing their own data and then realises they are not has learned
that you are willing to mislead them. Not worth it for any conversion gain.

## 1.6 Decisions that apply to all three

**Why Cloudflare Pages plus Supabase.** Cloudflare already hosts the static portfolio and Pages Functions. Supabase adds Postgres, magic-link authentication, private file storage, and row policies in one customer-data layer. This split keeps the public site simple while giving the commerce flow the organization isolation it requires.

**Why paid pilots before integrations.** Building a ServiceTitan integration before
a customer has paid means guessing at a workflow. A CSV import is 5% of the effort
and answers the same question. Build the integration when a paying customer's
renewal depends on it.

**Why a human exceptions queue from day one.** Automation scored 3, not 5. A
product that quietly guesses at illegible handwriting produces confident wrong
numbers, and one wrong number in a re-bill packet ,  sent to *their* customer ,
ends the relationship. The queue is not technical debt; it is the product working
correctly at this stage of accuracy.

**Why the refund policy is "full refund if we find less than we cost".** It is
honest, because a null result genuinely has little value. It removes the only real
objection at $750. And it is cheap: if you are frequently finding less than $750
across 250 work orders, the business does not work and you want to learn that in
month one.

**Why integer cents everywhere.** Floating-point money in a product whose entire
value proposition is arithmetic accuracy is an unforced error. One rounding
discrepancy visible to a controller undoes the credibility the whole Option B
design is built to establish.

## 1.7 Decision register for all fifteen sites

Each row records the buyer, the visual job, the rejected direction, and the scorecard factor that carried the most weight in that decision.

| Business and lane | Buyer and why this lane fits | Typography and colour job | Rejected direction and scorecard driver |
|---|---|---|---|
| Haulback, Gatehouse | A roll-off owner who can approve a $750 audit during the workday. A direct estimate and short path fit that decision. | Saira Condensed reads like yard signage, Public Sans keeps forms legible, Fragment Mono makes ticket values distinct. Concrete grey and high-vis yellow echo equipment markings. | A formal audit memo added friction. Pain and measurable ROI, 15%, calls for a visible dollar estimate. |
| Haulback, Weighbridge | A controller reconciling disposal tickets and customer invoices. A document view lets them inspect the method. | Source Serif 4 gives the report an accounting register, IBM Plex Sans supports dense explanations, and IBM Plex Mono aligns ticket data. Ledger green signals checked entries. | A large calculator looked too casual. Low legal and operational risk, 4%, requires traceable evidence and stated limits. |
| Haulback, Manifest | A multi-yard operations leader comparing routes, trucks, and locations. The console makes variance visible. | Schibsted Grotesk supports dense scanning and Red Hat Mono aligns operational values. Cobalt separates structure, coral marks leakage. | A brochure hid the cross-location pattern. Retention and recurring use, 7%, favors an operating view used every month. |
| Unbilled, Yard Sign | An HVAC, plumbing, electrical, septic, or landscaping owner with paper work orders. A fast estimate makes the missed charge concrete. | Barlow Condensed carries trade signage, Inter keeps instructions plain, and Roboto Mono isolates money. Near-black and safety orange reserve attention for action and dollars. | A gated estimate was rejected because it slowed the first result. MVP and setup speed, 10%, favors immediate self-service. |
| Unbilled, The Ledger | A controller who must validate every proposed rebill. The report page exposes source evidence and confidence. | Source Serif 4 and parchment resemble an audit packet. Inter handles navigation and IBM Plex Mono handles references. Navy signals caution. | Anonymous proof and invented performance rates were rejected. Low legal and operational risk, 4%, requires checkable claims. |
| Unbilled, The Console | A portfolio CFO looking for branches with unusual leakage. The table supports comparison before a sales conversation. | Inter Tight fits dense headings and JetBrains Mono keeps financial columns stable. Graphite reduces glare and teal marks interactive controls. | A single recovered total was rejected because it concealed variance. Scale and shared infrastructure, 5%, drives the parent and child organization view. |
| Lapsed, Route Card | A service owner with maintenance customers who quietly stopped recurring. A route-style estimate connects the problem to the weekly schedule. | Bricolage Grotesque feels operational, Atkinson Hyperlegible protects readability, and Martian Mono carries intervals. Teal and amber separate active routes from attention items. | A separate cold-sales funnel was rejected. Customer reachability, 10%, is stronger as a cross-sell to an existing Unbilled account. |
| Lapsed, Docket | A controller reviewing missed renewals and billing gaps. A docket presents each lapse as a traceable case. | Libre Caslon Text gives the case page authority, Libre Franklin keeps controls neutral, and Space Mono aligns dates. Charcoal and copper distinguish evidence from exceptions. | A promotional dashboard was rejected. Willingness to pay, 10%, depends on a document the buyer can defend internally. |
| Lapsed, Matrix | A multi-site operator comparing renewal behavior across branches. The matrix reveals outliers and recurring patterns. | Sora supports compact labels and DM Mono keeps periods aligned. Ink navy creates a restrained operating surface. | A one-time recovery report was rejected. Retention and recurring use, 7%, requires a view that stays useful after the first pass. |
| Overpaid, Counter | A small-business owner checking vendor bills against quotes. A price-counter format makes each difference easy to understand. | Anton provides price-tag force, Karla keeps explanations conversational, and Oxygen Mono aligns invoice amounts. Red flags money leaving the business. | A controller-first sales path was rejected for this lane. Sales-cycle speed, 8%, favors a quick owner decision. |
| Overpaid, Statement | A controller or outsourced accountant comparing agreements with invoice lines. The statement puts agreement, billed amount, and delta together. | Lora reads like correspondence, Figtree supports tables, and Fira Mono handles line values. Grey blue stays restrained. | Cold self-service was rejected as the primary channel. Customer reachability, 10%, is best through bookkeeping and accounting partners. |
| Overpaid, Gridbook | A portfolio finance team finding vendor drift across entities. The gridbook sorts deltas by vendor and branch. | Hanken Grotesk supports hierarchy and Chivo Mono holds numeric density. Vermilion marks adverse differences. | A consumer-style card grid was rejected. Scale and shared infrastructure, 5%, requires comparable rows across organizations. |
| Cleared, Clipboard | A facility owner holding an inspection notice and deadline. A short corrective-action pack matches the urgent task. | Oswald reads like an inspection tag, Source Sans 3 keeps instructions clear, and Courier Prime resembles field notes. Red marks cited items and green marks cleared items. | A recurring contract pitch was rejected. MVP and setup speed, 10%, is the strongest score and supports a case fee. |
| Cleared, Binder | A facilities director coordinating staff, licensed trades, and a reinspector. A binder page separates citations, fixes, and evidence. | Spectral supports long reading, Assistant keeps controls quiet, and PT Mono formats code references. Code-book blue signals administrative work. | A claimed compliance outcome was rejected. Low legal and operational risk, 4%, requires human review and clear limits. |
| Cleared, Board | A multi-site facilities leader prioritizing open items. The board summarizes status without implying that a site has passed inspection. | Familjen Grotesk works at dashboard density and Azeret Mono makes identifiers stable. Red, amber, and green chips encode state. | Automated clearance was rejected because an inspector owns that decision. Automation and low labor, 10%, stops at preparing evidence and reminders. |

## 1.8 What is deliberately not built

- **Contingency pricing.** Needs proof the customer re-billed and got paid. That is
  a collections product. Revisit at 20 customers.
- **A mobile app.** The camera roll and email already work. An app is a distribution
  problem you do not need.
- **Live FSM integrations.** CSV first. Build the integration a renewal depends on.
- **Multi-currency, non-US.** United States first, per the operating constraints.
- **A cancellation UI.** Stripe's Customer Portal does this correctly and for free.
- **A/B testing infrastructure.** At 200 visitors a month nothing reaches
  significance. Talk to customers instead.
- **Fabricated social proof of any kind.** No stock-photo testimonials, no invented
  logos, no "trusted by 500+ contractors" before it is true. The sections stay empty
  until real customers fill them.

---

# Part 2 ,  Plug and play

The current implementation checklist is section 2.10. Earlier sections preserve the original planning record and may name parked components.

Everything below requires you, a card, or a signature. None of it can be automated,
and all of it blocks revenue. Ordered so nothing waits on anything above it.

## 2.1 Accounts to open

| # | Account | Why | Cost | Watch out |
|---|---|---|---|---|
| 1 | Cloudflare | Pages hosting, functions, DNS | Current account plan | Pages Functions need the production secrets in section 2.10. |
| 2 | Supabase | Postgres, magic-link authentication, private storage | Plan selected by owner | Link the project and pass the cross-org test before customer intake. |
| 3 | Domain registrar | The domain | ~$12/yr | Register at Cloudflare to keep DNS in one place. |
| 4 | Stripe | All payments | 2.9% + 30 cents; ACH 0.8% capped at $5 | Activation needs EIN and a bank account. Start it early because review can take days. |
| 5 | Anthropic Console | Document extraction | Usage | Set a monthly spend cap before the first batch. |
| 6 | Resend | Transactional email | Free to 3k/mo | Domain verification needs DNS records. |
| 7 | Higgsfield | Photography and video | Per plan | Used for the self-hosted media in this repo. |
| 8 | Business entity | LLC, EIN, bank account | $50 to $500 by state | Stripe cannot pay you without it. Start this first because it has the longest lead time. |
| 9 | Business insurance | E&O, ~$1M | $500 to $1,500/yr | Option B and C buyers ask for a certificate. |

## 2.2 DNS

At Cloudflare, for `<domain>`:

```
A      @          192.0.2.1        proxied   (placeholder; Workers route overrides)
CNAME  www        @                proxied
CNAME  api        <worker>.workers.dev   proxied
CNAME  ledger     <worker-b>.workers.dev proxied
CNAME  console    <worker-c>.workers.dev proxied
MX     intake     route1.mx.cloudflare.net   priority 1
MX     intake     route2.mx.cloudflare.net   priority 2
MX     intake     route3.mx.cloudflare.net   priority 3
TXT    @          "v=spf1 include:_spf.resend.com ~all"
TXT    resend._domainkey   <from Resend>
TXT    _dmarc     "v=DMARC1; p=quarantine; rua=mailto:dmarc@<domain>"
```

Set DMARC to `p=none` for the first two weeks, read the reports, then move to
`quarantine`. Going straight to enforcement will silently bin your own receipts.

## 2.3 Stripe setup

1. Activate the account ,  EIN, bank details, business description. Describe the
   business accurately as a B2B document-auditing service; a vague description
   triggers manual review.
2. Create the five products and prices from §9 of the build prompt, in **test mode
   first**.
3. Enable **Stripe Tax** and register for collection in your home state. Add states
   as nexus thresholds are crossed; Stripe will warn you.
4. Enable **ACH Direct Debit** ,  Options B and C depend on it.
5. Configure the **Customer Portal**: allow plan changes and cancellation, require a
   cancellation reason, turn off invoice history if it looks cluttered.
6. Configure **Smart Retries** and three dunning emails.
7. Add the webhook endpoint `https://api.<domain>/api/stripe/webhook` subscribed to:
   `checkout.session.completed`, `invoice.paid`, `invoice.payment_failed`,
   `customer.subscription.updated`, `customer.subscription.deleted`,
   `charge.refunded`. Copy the signing secret into `STRIPE_WEBHOOK_SECRET`.
8. Set the statement descriptor to something recognisable. An unrecognised
   descriptor is the most common cause of chargebacks.
9. Test the full flow with `4242 4242 4242 4242`, then the decline card, then a
   refund. **Then** switch to live keys and run one real $1 charge on your own card
   and refund it.

## 2.4 Secrets

```sh
npx wrangler@4 pages secret put SUPABASE_URL --project-name hustle
npx wrangler@4 pages secret put SUPABASE_SERVICE_ROLE_KEY --project-name hustle
npx wrangler@4 pages secret put STRIPE_SECRET_KEY --project-name hustle
npx wrangler@4 pages secret put STRIPE_WEBHOOK_SECRET --project-name hustle
npx wrangler@4 pages secret put STRIPE_PRICE_FIRST_PASS --project-name hustle
npx wrangler@4 pages secret put STRIPE_PRICE_STANDARD --project-name hustle
npx wrangler@4 pages secret put STRIPE_PRICE_LEDGER_PILOT --project-name hustle
npx wrangler@4 pages secret put STRIPE_PRICE_LEDGER_PRO --project-name hustle
```

Never in `wrangler.toml`. Never in the repo. Separate values per environment.

## 2.5 Documents to produce

| Document | How | Blocks |
|---|---|---|
| Terms of Service | Template, then review | Any payment |
| Privacy Policy | Template ,  must name subprocessors | Any payment |
| Data Processing Addendum | Template | Option B and C deals |
| Subprocessor list | Write it: Cloudflare, Anthropic, Stripe, Resend | Option B security page |
| Sample MSA | Lawyer, once | Option B procurement |
| W-9 | IRS form, signed | Getting paid by mid-market AP |
| Security overview PDF | Write it from §11 | Option B security page |
| Certificate of insurance | From your insurer | Some contracts |
| Refund policy | Write it ,  see §1.6 | Option A pricing page |

Templates are acceptable to launch. Get the MSA reviewed before the first contract
over $10,000.

## 2.6 Content you must supply

Code cannot generate these truthfully:

1. **One real redacted work order and the line it caught.** Option A's proof section
   and Option B's hero both need it. Get written permission from the customer or
   use your own test data ,  never a real customer's document without consent.
2. **Your actual trade price book defaults**, or the decision to ship without them.
3. **Your accuracy number**, once you have run 500 work orders. Until then Option B
   says "measured on our first N work orders" with the real N, or says nothing.
4. **Real testimonials, or empty sections.** No exceptions.
5. **Your name and face on the About page.** A solo founder selling to skeptical
   trades converts better identified than anonymous.

## 2.7 Launch-day checklist

Nothing ships until every line is checked.

**Payments**
- [ ] Live Stripe keys deployed; test keys removed from all environments
- [ ] Live webhook endpoint verified, one live event received and processed
- [ ] $1 live charge made and refunded successfully
- [ ] Stripe Tax enabled, home state registered
- [ ] Statement descriptor set and recognisable

**Pipeline**
- [ ] 20 real work orders processed end to end
- [ ] Exceptions queue reachable and monitored
- [ ] Report PDF generates and totals reconcile to accepted findings
- [ ] Duplicate upload creates one document row
- [ ] Anthropic spend cap set

**Sites**
- [ ] All three deployed on custom domains with valid TLS
- [ ] Screenshots inspected at 360px and 1280px, light and dark, every page
- [ ] Lighthouse mobile ≥ 95 performance and accessibility, all three
- [ ] No horizontal overflow at 360, 390, 768, 1280, 1440
- [ ] Every form submits, is rate-limited, and rejects a missing Turnstile token
- [ ] 404 page exists and is styled
- [ ] Zero console errors

**Email**
- [ ] SPF, DKIM, DMARC verified; test to Gmail and Outlook lands in the inbox
- [ ] All six transactional templates send correctly
- [ ] Intake address receives and files an attachment
- [ ] Physical address in every marketing footer

**Legal**
- [ ] Terms, Privacy, DPA, subprocessor list live and linked in the footer
- [ ] Refund policy on the pricing page
- [ ] Delete-my-data path tested end to end, including Supabase Storage

**Operations**
- [ ] Cloudflare alerts to a phone you carry
- [ ] Stripe failed-payment alerts on
- [ ] Exceptions-queue alert when depth exceeds 20
- [ ] Supabase backup taken and a restore rehearsed once

## 2.8 Day one, actually operating

Order arrives → webhook provisions the org → customer lands on upload.

**Your loop, twice a day, roughly 30 minutes:**

1. Open `/admin/queue`. Work the exceptions oldest first.
2. For each: read the source crop, correct or reject. Corrections are training data
   ,  that is why the accept/reject signal is stored.
3. Check for batches stuck over 4 hours.
4. Approve reports awaiting release. Read the top three findings on every report
   before it goes out. In the first month, read all of them.

**Weekly:** Stripe failed payments. Anthropic spend against cap. Every new
customer's first report, personally, before it sends.

**The one thing that kills this business:** sending a customer a finding that is
wrong in a way they can see. One bad number in a re-bill packet that reaches *their*
customer costs the account and the referral. When uncertain, hold it ,  a report that
is a day late and correct beats one that is on time and wrong.

## 2.9 What has to be true to collect money

Five things. Any one missing means no revenue.

1. **A legal entity with a bank account.** Longest lead time. Start it today.
2. **An activated Stripe account.** Can take days; can require follow-up documents.
3. **A live, signature-verified, idempotent webhook.** Without it, people are charged
   and not provisioned ,  the worst possible failure.
4. **A working upload path immediately after payment.** Payment without fulfilment
   is a refund with extra steps.
5. **A report a stranger would pay for again.** Everything upstream is machinery.
   This is the product.

Everything else on this list makes the business better. Those five make it exist.

## 2.10 Current implementation go-live checklist

Do these in order. Each step names the action and its proof.

1. Create a Supabase project at `supabase.com/dashboard/new`. Choose a US region. Proof: Project Settings, General shows the project reference and selected region.
2. Run `supabase login`, then `supabase link --project-ref <project-ref>`. Proof: `supabase projects list` marks the project as linked.
3. Run `supabase db push`. Proof: Supabase Dashboard, Database, Migrations shows `202608100001_commerce` as applied.
4. Run `supabase test db supabase/tests/rls_isolation.sql`. Proof: pgTAP reports that user B sees zero findings from organization A and only organization B.
5. In Supabase Dashboard, Authentication, URL Configuration, set Site URL to `https://hustle.themonochrom.com` and add `https://hustle.themonochrom.com/onboarding/` as a redirect URL. Proof: a magic link returns to onboarding with an authenticated session.
6. In Stripe test mode, create prices for Yard Sign First Pass at `$750` one time, Yard Sign Standard at `$499` monthly, Ledger Pilot at `$2,500` one time, and Ledger Pro at `$1,200` monthly. Proof: each price page shows the intended amount, interval, currency, and test-mode badge.
7. Run `npx wrangler@4 pages secret put SUPABASE_URL --project-name hustle`, then enter the project URL. Proof: Cloudflare Dashboard, Workers and Pages, hustle, Settings, Variables and Secrets lists `SUPABASE_URL` as encrypted.
8. Repeat for `SUPABASE_SERVICE_ROLE_KEY`, `STRIPE_SECRET_KEY`, `STRIPE_WEBHOOK_SECRET`, `STRIPE_PRICE_FIRST_PASS`, `STRIPE_PRICE_STANDARD`, `STRIPE_PRICE_LEDGER_PILOT`, and `STRIPE_PRICE_LEDGER_PRO`. Proof: all eight names appear as encrypted values and none appears in `git grep`.
9. In Stripe Workbench, Webhooks, add `https://hustle.themonochrom.com/api/stripe/webhook` for `checkout.session.completed`, `invoice.paid`, `invoice.payment_failed`, and `charge.refunded`. Copy its signing secret into the Cloudflare secret from step 8. Proof: Stripe sends a test event and records HTTP 200.
10. Run `stripe listen --forward-to https://hustle.themonochrom.com/api/stripe/webhook`, then complete test Checkout with card `4242 4242 4242 4242`. Proof: the related `orders` row changes from `pending` to `paid`.
11. Run `stripe events resend <event-id>`, twice. Proof: both attempts return HTTP 200 and `processed_webhooks` contains one row for the event ID.
12. Open `https://hustle.themonochrom.com/onboarding/`, submit an intake, follow the magic link, upload each allowed format, and reject a file over 25 MB. Proof: allowed files reach the private `audit-evidence` bucket and the oversized file receives HTTP 413.
13. Create one finding with an `evidence_path`, then open its audit. Proof: the Evidence cell opens a signed URL that expires after 15 minutes.
14. In Stripe test mode, create and send a Ledger Pilot invoice with ACH. Proof: the invoice is net 15, uses the server price, and its order state follows the invoice webhook.
15. Create a scheduled deletion job for objects older than the approved retention period. Proof: seed an expired test object, run the job, and confirm both storage and database references are removed. Until this passes, do not accept customer records.
16. Add GitHub Actions secret `CLOUDFLARE_API_TOKEN` with Account Cloudflare Pages Edit and Zone DNS Edit for `themonochrom.com`. Proof: `gh workflow run publish.yml --repo Themonochrom/hustle --ref main` completes green.
17. Run `npm test`, `npm run check:scorecard`, `npm run check:contrast`, `npm run check:layout`, and `npm run check:network`. Proof: every command exits zero.
18. Run `npm run check:live`. Proof: the landing page, sites index, scorecard, and every internal portfolio link return HTTP 200.

Console checkout remains parked. Overpaid uses partner-led sales. Lapsed is an add-on to an existing Unbilled account. Automated document extraction, report PDF generation, transactional email templates, the retention deletion job, legal documents, tax setup, and customer cancellation UI remain outside this implementation.
