Payment Link · LPO excursions
Four process maps to refine six stories against
These maps turn the six Payment Link stories in GVI\PI 2026\4.0 into pictures a developer can argue with. They carry only what the stories, the 31 August communication flow and the 7 September decisions already say. Anything marked TBC is an open question for refinement, not a decision that has been taken.
The six stories
- 242188 Research the current state
- 240005 Send the link from TD Portal
- 242191 Backend: order, token, payment records
- 240003 CDE landing page
- 240008 Resend the link
- 240009 Payment status
The maps
What the excursion payment does today
The confirmed baseline and the three gaps 242188 has to close.
Map 2Send a link, take the payment, show the status
The European-market path end to end, across eight systems.
Map 3How payment status and token state move
Five existing payment statuses, and the token shape being recommended.
Map 4What happens when the link fails
Resend, dead link, declined card, unpaid at end of tour.
Systems in the flow
| System | Role | Where that comes from |
|---|---|---|
| TD Portal (TDP) | TD/CrD sells the excursion, sends the link, sees status | Stated in the stories |
| Enterprise | Client record; source of the lead-guest email | Confirmed in refinement, 2026-09-20 |
| Backend / Order Processing Services | Order, order items, payment records (EOPTIONAL_ORDER_PAYMENT), token store, audit log | Stated in 242191 |
| Payment Service | Receives the TrustPayments result, updates payment records | Confirmed in refinement, 2026-09-20 |
| CDE-PaymentUI | PCI-scope card entry; new unauthenticated landing page | Stated in 240003 |
| TrustPayments | Card processor | Stated in 240003 |
| Email service | Payment-link email, bounce signal, receipt (sender TBC) | Sender TBC |
Legend
- Person step
- System step
- External integration
- Decision
- Unknown or TBC
- Exception or loop-back
Colour repeats the shape, so the maps read in greyscale and in print. A dashed box is an unknown; a dashed edge is an exception or a loop back.
Questions for refinement
Every numbered marker on a map points here.
| # | Question | Story | Owner |
|---|---|---|---|
| Q1 | Token expiry rule and anchor: duration, departure date or end of tour | 242191 | Scott Sarris |
| Q2 | PCI and GDPR constraints on token content, storage, retention and audit log | 242191 | Scott Sarris |
| Q3 | Address verification on the landing page: required or not | 240003 | Scott Sarris |
| Q4 | Which system sends the GFOB receipt after TrustPayments confirms | 240003, separate story | TBC |
| Q5 | Where payment status and Resend live in TDP | 240009, 240008 | Product |
| Q6 | Whether a new payment status is needed, or link state lives on the token | 242191 | Dev |
| Q7 | Result path TrustPayments to Payment Service: callback contract, retries, idempotency | 242191 | Dev |
| Q8 | Which email service sends the link, and how bounces are received | 240005, 240008 | Dev |
| Q9 | Order creation before the market check: confirm the non-EU path is unaffected | 240005 | Dev |
| Q10 | Finance per-departure payment report: scope | 242191 | Finance |
| Q11 | Current-state research items 1 to 6 on Map 1 | 242188 | Dev |