Readiness
Template marketplace runtime

Admin marketplace operations

Seller-owned and DigiShelf-owned template assets share marketplace discovery while keeping merchant routing, licensing, purchases, and delivery boundaries explicit.

Merchant contextServer

Client routing ignored.

SaaS billing mutationOff

Buyer commerce only.

InstallationEntitled

Secrets stripped.

Discovery

Public-safe marketplace shelves

Published only
ListingOwnerMerchant domainStatusRoute
Seller launch page kitseller-ownedseller marketplace commercepublishedOpen
DigiShelf first offer kitDigiShelf-ownedDigiShelf-owned buyer commercepublishedOpen
Course creator starter bundleseller-ownedseller marketplace commercereview requiredOpen
Commerce separation

Runtime state model

No fake sales
AreaBoundary
Seller-owned assetSeller is merchant of record; seller commerce and reporting only.
DigiShelf-owned assetDigiShelf is merchant of record for buyer commerce; not SaaS billing.
Listing publicationApproval-first; discoverability is separate from purchase eligibility.
Install/copyEntitlement required; destination IDs regenerated; source secrets stripped.
ReviewsVerified purchase only; zero reviews stay unrated.
Refunds/disputesConsume authoritative Module 25 state; purchases are not deleted.
Governance

Marketplace controls

Module 28
SettingStatus
marketplace.template_runtime_enabledtracked
marketplace.listing_review_requiredtracked
marketplace.seller_publication_requires_approvaltracked
marketplace.digishelf_owned_publication_requires_admintracked
marketplace.merchant_context_server_resolvedtracked
marketplace.platform_owned_buyer_commerce_boundary_readytracked
marketplace.template_install_entitlement_requiredtracked
marketplace.featured_listing_admin_onlytracked
marketplace.moderation_blocking_enabledtracked
marketplace.launch_gate_enabledtracked
Safety

Hard boundaries

Public-safe
CapabilityRuntime state
mutatesFinancialLedgerOff
mutatesPlatformSaasBillingOff
activatesSellerSubscriptionPlanOff
trustsClientMerchantRoutingOff
grantsAccessFromCheckoutRedirectOff
fabricatesSalesRevenueReviewsRatingsOff
exposesPrivateFileKeysOff
exposesProviderSecretsOff
emitsAffiliatePayablesOff
Integrations

Accepted-module boundaries

PackageBoundary
@digishelf/template-storeTemplate definitions remain reusable inputs; Module 28 records runtime ownership, merchant context, sales, licenses, and installs.
@digishelf/order-managementOrders, payments, refunds, disputes, and ledger posting remain the financial source of truth.
@digishelf/delivery-runtimeEntitlements and delivery remain authoritative; marketplace purchase records coordinate catalog/license context only.
@digishelf/platform-billingSeller SaaS subscription billing is separate and must not create marketplace purchases.
@digishelf/public-contentMarketplace SEO metadata and sitemap eligibility are public-safe and must not fabricate ratings or prices.