Feature Pack: YU05-post-trade-compliance
Status: Implemented
Track: architecture
Lineage role: optional
Previous state: YU04-durable-control-feeds
This pack bundles four back-office/compliance capabilities that all consume the journal's executed-fill stream as their common source of truth: post-trade settlement + reconciliation (including full-history orphan detection), regulatory reporting (CAT/TRACE-style), TCA (transaction cost analysis), and real JWT auth/entitlements as the access-control layer gating the other three.
Primary intent:
- give a booked trade a real settlement lifecycle and a deterministic id linking its MariaDB row to the journal fill that produced it,
- reconcile the read-model projection against the authoritative journal; both a forward sweep and an on-demand full-history orphan sweep,
- expose a reproducible, journal-sourced regulatory audit export and per-trade TCA, never from the projection and never on the hot path,
- gate every new endpoint behind a real HS256-verified JWT with account-entitlement or admin checks.
Core artifacts:
spec.mdrequirements/functional-delta.mdrequirements/nonfunctional-delta.mdresearch.mddata-model.mdquickstart.mdcontracts/contract-delta.mdsystem/architecture.model.jsonsystem/architecture.mdsystem/runtime-topology.mdsystem/messaging-subject-map.mdsystem/adr-022-deterministic-trade-identity-and-settlement-recon.mdsystem/adr-023-journal-sourced-regulatory-reporting.mdsystem/adr-024-pluggable-tca-benchmark-source.mdsystem/adr-025-oidc-entitlements-gate-post-trade-apis.mdgeneration/generation-hook.mdgeneration/implementation-status.md
Target runtime behavior:
- order-matcher hosts the replay-safe trade blotter, the shadow-replay full-history reindex and regulatory report, and its own JWT authenticator.
- trade-processor hosts settlement, reconciliation, TCA, dev-token minting, and its own JWT authenticator.
- Everything else (deploy/runtime harness, BLP admission pipeline, observability stack) is inherited
unchanged from
YU04-durable-control-feeds.