Reports as contracts
Every report family, KPI and period preset is declared once in a shared @repo/api contracts package. The NestJS side dispatches on those types — a coordinator resolves the caller’s scope and returns 403 before any SQL runs, then a typed computer per family produces the payload. The Next.js side derives its catalogue from the same contracts, so a KPI added to the registry appears in the UI, the role checks and the PDF template without three separate edits.
Auditability
Exports are evidence. Each PDF goes through Gotenberg, and every export writes an audit-log row with the requesting user, scope, period and a hash of the file, so a report can be matched to exactly what was generated. The auditor review runtime is a state machine over review bundles: transitions, gates and claims are covered by tests, and the review’s outcome gates what the client can see of their Diet Rx.
Money
Refunds are a ledger, not a flag. A payment_refunds table with transactional writes, a tolerant backfill for historical rows, and a seed invariant that checks the ledger balances against refunded payments — so the finance reports can be trusted.
