Skip to main content

Monitoring

Admin → Monitoring (https://admin.finmatch.io/monitoring/).

Operational health for finance test workflows and runtime checks — not the Analytics KPI page.

Modes​

ModeUse
Global MonitoringCross-system cards (default).
Merchant MonitoringPick a merchant by ID or name, then inspect that merchant’s five live checks. Search placeholder: Search merchant by ID or name (e.g. M281700). Idle picker: Select merchant…. Clear returns to Global. If merchant M281700 is in the directory, first load opens that merchant instead of Global.
Scheduled TasksScheduled monitor runs. Idle meta: Scheduled tasks: Cloud Scheduler jobs and GitHub Actions cron workflows.

Idle Global meta: Global mode: cross-system monitoring cards.

Refresh reloads the cards. Finance live-check cards include Re-run Live Check (busy rerun: Running…). Open Raw JSON / Open History Path point at gs://finmatch-admin/monitoring/finance-runtime-guard/. Placeholder global cards show Awaiting report publisher integration. instead of Latest JSON. Scheduled-task cards link Latest JSON and View Runs. When a global or live-check card cannot load its report, the pill is UNAVAILABLE. Merchant-mode cards use PASS / FAIL / WARN, not UNAVAILABLE — see Merchant Monitoring. Merchant Domain Whitelist cards can Fix CORS now (hover Force CORS reconciliation for this merchant). Busy: Fixing....

UNAVAILABLE​

UNAVAILABLE means the card could not load its report (fetch / compute error). It is not FAIL. FAIL is the pill on a report that did load.

  1. Read the error meta under the pill. The same text is also listed in Current Failures as monitor unavailable: plus the error. Treat that list row as "could not load", not as a failed check.
  2. Click page Refresh to retry every Global card. An UNAVAILABLE live-check card has no Re-run Live Check button — that control appears only after the card has loaded.
  3. Once a live-check card has loaded (pill PASS or FAIL), use Re-run Live Check to recompute. Busy: Running….
  4. Domain Whitelist Coverage uses its own card Refresh. Load failure: pill UNAVAILABLE, summary Failed to load CORS summary: plus the error. That is also not FAIL.

Do not treat UNAVAILABLE as FAIL. Fix the load error, then re-read PASS / FAIL. Merchant-mode cards never show UNAVAILABLE; a down snippet monitor on those cards is FAIL with summary Header snippet monitor unavailable.

Failures and notes​

Current Failures lists active guard failures. Idle empty: No active failures. After scheduled tasks load: No issues. Notes and Warnings is the non-fatal list. Idle empty: No current notes. After scheduled tasks load: No notes. Empty means none right now, not that monitoring is off.

Domain Whitelist refresh status: idle Loading..., then Loading whitelist.... Those two strings are distinct.

Quote comparison (lender benchmark vs Partner API vs runtime) feeds this page and merchant quote tools. ⓘ What do these columns mean? Drift between those three stacks is the thing to investigate, not a missing sidebar item.

Full column legend: Quote comparison.

Partner API Cloud Run stdout and request IPs are not this page. Use Partner API Cloud Run logs (project finmatch-finance-mkt, service finmatch-partner-api, europe-west2).

In Merchant Monitoring, Current Failures and Notes and Warnings are rebuilt from the five cards below. Each row is prefixed with the card title in brackets (for example [Header Snippet Detection]). FAIL cards write the Current Failures list. WARN and non-fatal mismatches write Notes and Warnings. Empty lists still mean none right now.

In Global Monitoring, the same two lists are rebuilt from the Global cards. Each row is prefixed with the card title in brackets (for example [Finance Runtime Guard]). Load errors write monitor unavailable: — see UNAVAILABLE.

Global Monitoring​

Global Monitoring is the default mode. Page Refresh reloads every card below, then the Domain Whitelist Coverage and Mirror panels.

These cards are fleet / test-merchant reports. They are not the per-merchant five-card set — see Merchant Monitoring.

Global pills​

PillMeaning
PASSThe report loaded and overall_status is pass.
FAILThe report loaded and overall_status is anything else (fail, warn, empty). Read Current Failures and the card metrics.
UNAVAILABLEThe report did not load. Not a failed check. See UNAVAILABLE.

Placeholder cards always paint PASS plus Awaiting report publisher integration. — treat that PASS as chrome, not a green check.

JSON cards (when not placeholder) expose Latest JSON and, when the monitor defines a history path, History. Live-check cards expose Re-run Live Check instead.

Finance Runtime Guard​

Loads the published GCS report (gs://finmatch-admin/monitoring/finance-runtime-guard/). The card description: Checks test merchant finance settings, quote availability, and repayment field consistency. The published summary is Checks test merchant finance settings, quote outputs, and lender-originated alignment.

It is a JSON card, not a live recompute. Test merchants in the published report are M000100–M000105. Per-merchant checks in that report: merchant_config_load, partner_quote, products_returned, lender_originated_compared.

PillWhen
PASSPublished overall_status is pass.
FAILPublished overall_status is not pass. Current Failures lists the report failures (for example a test merchant whose partner quote returned no products).
UNAVAILABLElatest.json could not be fetched.

Latest JSON opens the published report. History opens the merchant-api monitoring-history path for this monitor.

What to do:

  1. UNAVAILABLE — page Refresh. If it stays down, the GCS publisher or the latest.json object is the outage, not a merchant storefront.
  2. FAIL — read Current Failures, then Latest JSON. Fix the named test merchant (config / Partner API products / lender benchmark), then wait for the next published report (this card has no Re-run Live Check).
  3. Notes such as missing lender-originated benchmarks go to Notes and Warnings, not Current Failures. Investigate those as coverage gaps, not as the pill reason.

Transaction Event Preflight​

Loads the published GCS report (gs://finmatch-admin/monitoring/transaction-event-preflight/). The card description: Fails on quote drift between Partner API output and transaction-event-based calculation engine. The published summary is Verifies Partner API quote values match transaction-event calculation outputs.

JSON card. The live report checks test merchant M000106 (product / event-product counts on the merchant row).

PillWhen
PASSPublished overall_status is pass.
FAILPublished overall_status is not pass. Current Failures lists quote-drift rows from the report.
UNAVAILABLElatest.json could not be fetched.

Latest JSON / History as on Finance Runtime Guard.

What to do:

  1. UNAVAILABLE — page Refresh.
  2. FAIL — Latest JSON, then compare Partner API vs transaction-event math for the named product. This is the same three-stack family as Quote comparison, on a published preflight rather than the interactive live-check card.

Quote Comparison Monitor​

Interactive live check (not a GCS JSON file). Description: Interactive 3-way comparison: lender-originated vs Partner API vs runtime calc for test merchants.

It runs QuoteMonitor against test merchants M000100–M000106. Merchants with no assigned rate-card products are skipped (row PASS, note no assigned products — skipped).

PillWhen
PASSNo red diffs and no merchant fetch errors. Amber-only drift does not flip the overall pill.
FAILAt least one red field-diff or a merchant request error. Current Failures lists those rows.
UNAVAILABLEQuoteMonitor is missing (QuoteMonitor not loaded — ensure quote.js and quote-monitor.js are included.) or the rate card failed to load.

Per-merchant rows inside the card: the small pill is PASS only when that merchant’s status is pass. Amber and fail both paint FAIL on the row even if the overall card is still PASS. Expand a row to see Product / Field / Lender / Partner / Runtime and ⓘ What do these columns mean?

This card has no Latest JSON. Controls: Re-run Live Check (busy: Running…) and Advanced / Simple (Advanced adds P↔R / P↔L; Simple keeps R↔L).

What to do:

  1. UNAVAILABLE with QuoteMonitor missing — reload Monitoring; the quote scripts did not load. Same copy as Merchant Quotes.
  2. UNAVAILABLE rate-card load — Refresh, then Re-run Live Check.
  3. FAIL — expand the red merchant, read R↔L (and Advanced P↔R / P↔L). Column legend: Quote comparison.
  4. After a product / benchmark fix, click Re-run Live Check (do not wait for GCS). Busy: Running….

Placeholder cards​

Three Global cards are live chrome with no publisher yet. Each loads as PASS, shows Awaiting report publisher integration. instead of Latest JSON, and writes the note UI tile is ready. JSON publishing is not wired for this test yet.

CardDescription on the tile
Snap Rate Card Regression TestCovers Snap lender repayment and first-payment scenarios (legacy vs API source parity).
Workflow Drift CheckProtects workflow consistency and guardrail alignment across environment branches.
Centralized Sync to GCSEnsures deployment sync jobs complete and protected runtime files are not overwritten.

What to do:

  1. Do not treat PASS as a completed Snap / workflow / sync check.
  2. There is nothing to refresh except the tile itself. Use page Refresh only if the card is UNAVAILABLE (that would be a UI exception, not a missing report).
  3. For real sync / mirror work, use Mirror Admin Configs Across Environments. For Snap quote parity on test merchants, use Quote Comparison Monitor.

Merchant Router Coverage​

Computed in the browser. Description: Checks merchants in Merchant API are present in merchant-router with consistent environments.

It compares merchant-api /api/merchants to the public merchant-router.json object. FAIL when a merchant record is missing from the router, or the profile environment disagrees with the router environment. Router ids that are not in merchants.json become Notes and Warnings parity warnings ([stale-router]), not FAIL.

PillWhen
PASSEvery merchant-api merchant is in the router, and environments match.
FAILCurrent Failures has [missing-router] and/or [env-mismatch] rows.
UNAVAILABLEEither fetch failed. If the public router object is not readable in the browser, this card stays UNAVAILABLE — that is a load error, not a missing merchant.

This card has no Latest JSON.

What to do:

  1. UNAVAILABLE — page Refresh. If it stays UNAVAILABLE, do not treat the fleet as unrouted. Switch to Merchant Monitoring and use Merchant Router Assignment, which asks the getMerchantConfig resolver instead of the public file.
  2. FAIL [missing-router] — open that merchant, confirm Environment, then Check env on the App card.
  3. FAIL [env-mismatch] — profile env and router env disagree. Fix Environment, then Check env / Refresh.
  4. Note [stale-router] — router has an id with no merchant-api record. Investigate leftover router rows; they do not fail the pill.

Merchant Identity Integrity​

Computed from auth-api /admin/merchant-integrity. Description: Checks merchant profiles against merchant auth users, API keys, and ID mapping consistency. The report title/summary may read Checks merchant profiles against merchant auth users and Finance Assistant API key readiness.

Requires a signed-in admin (x-username). Missing username: UNAVAILABLE with Missing local username. Please sign in again.

PillWhen
PASSReport overall_status is pass (no integrity failures).
FAILCurrent Failures lists [missing-user], [id-mismatch], [missing-key], [inactive-user], [duplicate-users], and/or [orphan-user] rows.
UNAVAILABLENot signed in, or auth-api did not return the report.

Latest JSON opens the auth-api integrity endpoint. No History link on this card.

What to do:

  1. UNAVAILABLE Missing local username — sign in, then Refresh.
  2. FAIL [missing-user] / [missing-key] — the merchant auth user or Finance Assistant API key is missing. Open the merchant Admin / App card; do not paste keys into these docs.
  3. FAIL [id-mismatch] — the auth user’s merchantId does not match the profile id.
  4. FAIL [duplicate-users] / [orphan-user] — extra or unlinked merchant-role users. Resolve in Users, then Refresh.

Merchant Config Drift Alarm​

Computed from merchant-api /admin/merchant-config-integrity?env=p. Description: Alarms when production merchants are missing from live runtime merchant config. The report title is Merchant Config Drift (P).

Requires sign-in. Same Missing local username UNAVAILABLE as Identity.

PillWhen
PASSEvery live production profile exists in runtime merchant lender config, and there is no domain/id mismatch.
FAILCurrent Failures has [missing-in-config] (profile not in runtime) and/or [id-mismatch] (runtime row domain matches a different profile id).
UNAVAILABLENot signed in, or merchant-api integrity call failed.

Latest JSON / History. Scheduled Merchant Config Monitoring publishes this same integrity payload to GCS every 30 minutes — see Scheduled Tasks.

Orphans in runtime (no matching profile) and sentinel ids go to Notes and Warnings as parity warnings ([orphan-in-config], [sentinel-in-config]), not FAIL.

What to do:

  1. UNAVAILABLE — sign in if needed, then Refresh.
  2. FAIL [missing-in-config] — that merchant has a production profile but no runtime config row. Open the merchant, Check env, then confirm Features / lenders / credit products. The per-merchant view is Merchant Configuration Quality.
  3. FAIL [id-mismatch] — runtime id and profile id disagree for the same domain. Do not “fix” by creating a second merchant. Raise with engineering; the scheduled workflow also classifies these.
  4. After a write, Refresh this card (live compute) and/or wait for the next scheduled publish, then Latest JSON.

Merchant Config Write Audit​

Computed from merchant-api /admin/merchant-config-audit?limit=100. Description: Shows recent merchant config write events and flags non-admin-ui change sources.

Requires sign-in.

PillWhen
PASSEvery fetched event has source admin-ui.
FAILAt least one fetched event is not admin-ui. Current Failures lists [non-admin-ui] rows with merchant, event name, source, and actor.
UNAVAILABLENot signed in, or the audit endpoint failed.

Latest JSON / History. Metrics include events fetched and last-24h counts.

A Mirror from this page sends x-finmatch-source: admin-ui so it should not appear here as non-admin. Unexpected sources are the alarm.

What to do:

  1. UNAVAILABLE — sign in, then Refresh.
  2. FAIL — read the [non-admin-ui] rows. If the actor is a known admin session that omitted headers, that is still a signal: the write path did not tag admin-ui. If the source is unexpected, stop and inspect Latest JSON before writing more config.
  3. Notes include the audit file path and 24h counts — use those for volume, not as FAIL.

Merchant Writer Attribution Regression​

Computed from the same audit endpoint (limit=200), filtered to merchant_lender_config_saved events. Description: Correlates writer attribution with merchant-count before/after to detect mass-drop regression writes.

Requires sign-in.

The renderer paints PASS only when overall_status is pass. A warn (unknown actor, no count-drop) still shows FAIL on the card.

PillWhen
PASSNo count-drop (delta <= -2) and no unknown-actor writes.
FAILCount-drop events ([count-drop] in Current Failures), or unknown-actor writes (warn internally — the pill is still FAIL). Unknown actors also appear as Notes and Warnings parity warnings ([unknown-actor]).
UNAVAILABLENot signed in, or the audit endpoint failed.

Latest JSON / History. Notes include last-3 writes and count metadata coverage.

What to do:

  1. UNAVAILABLE — sign in, then Refresh.
  2. FAIL [count-drop] — a save reduced merchant-count by two or more. Do not Mirror or Save features until you read Latest JSON and the last-3 write notes. This is the mass-drop alarm.
  3. FAIL with only [unknown-actor] — the write succeeded but actor headers were missing. Confirm who saved, then fix the client that omitted x-username / source headers.
  4. Non-admin-ui writer events are noted in metrics; the dedicated pill for those sources is Merchant Config Write Audit.

merchant_id Migration Monitor​

Computed from merchant-api /api/merchants. Description: Tracks the finmatchId → merchant_id migration. Passes when all profiles have merchant_id and no new profiles are created with finmatchId only.

The card summary is the migration phase string (not the description):

  • Phase 1: migration in progress
  • Phase 2: all profiles have merchant_id, finmatchId still present on legacy profiles
  • Phase 3: ready to remove finmatchId

No Latest JSON / History. Internal warn (still missing merchant_id) paints FAIL on the card.

PillWhen
PASSEvery profile has merchant_id (Phase 2 or 3).
FAILAt least one profile is missing merchant_id (internal warn). Metrics: missing merchant_id / has both ids / mismatched ids.
UNAVAILABLE/api/merchants failed.

What to do:

  1. UNAVAILABLE — Refresh. If merchant-api directory load is also down, the rest of Monitoring will struggle too.
  2. FAIL / Phase 1 — new or legacy profiles still lack merchant_id. Do not create merchants that only have finmatchId. Open the named merchant and confirm the id on the record; engineering owns the backfill.
  3. PASS Phase 2 — migration of the field is done; finmatchId may still exist on legacy rows. No operator action.
  4. PASS Phase 3 — finmatchId is gone. No operator action.

Merchant Monitoring​

Click Merchant Monitoring, then pick a merchant (or type an exact ID such as M281700 in the search box). Refresh re-runs every card for the selected merchant. Clear drops the selection and returns to Global.

These five cards are live checks for that merchant. They are not the Global Finance Runtime Guard / Quote Comparison Monitor reports.

Merchant-mode pills​

PillMeaning
PASSThe check succeeded for this merchant.
FAILThe check failed. Read the bullets on the card and the matching Current Failures row, then use the card’s link (if any).
WARNSomething is unverified or incomplete. Treat Notes and Warnings as the to-do, not Current Failures.
UNAVAILABLEDoes not appear on merchant-mode cards. See UNAVAILABLE for Global / live-check load failures.

A down snippet monitor is FAIL on Header Snippet Detection, not UNAVAILABLE.

Header Snippet Detection​

Asks 1) Is header snippet on the merchant's site? It posts a snippet snapshot for this merchant (the same merchant-api snapshot family as Check snippet on the App card).

PillWhen
PASSSource verification found the header snippet, or the monitor status is deployed (Snippet found on the App card).
WARNHeader not confirmed, but the monitor listed page-specific embed snippets.
FAILNeither of those. Includes a down monitor (summary Header snippet monitor unavailable).

Open Merchant Domain opens the merchant’s configured domain in a new tab so you can confirm the live <head> yourself.

Bullets on a loaded card:

  • Monitor status / Monitor details / Monitor detected environment
  • Source verification: checked N URL(s), detected on M, or Source verification: not run
  • Source detected environment
  • 1b) Page-specific snippets detected on N page(s) or 1b) No page-specific snippets detected by monitor

What to do:

  1. FAIL and the details say the snippet is missing — paste the Header snippet into the merchant <head>, then Check snippet on the merchant App card, then Refresh this page.
  2. FAIL with No domain / No domain configured — set Domain on the merchant, then re-check.
  3. FAIL with Header snippet monitor unavailable — click Refresh. If it stays down, merchant-api / the snippet monitor is the outage, not the merchant site.
  4. WARN — header not confirmed, but embeds were found. Open Open Merchant Domain, then compare Pages with embed snippets on the merchant App card.
  5. Note Source verification confirms snippet, but monitor reported not_deployed. — treat the snippet as present; re-run Check snippet so the shared snapshot catches up. Badge meanings: Snippet status.
  6. Note Known test URLs: — this merchant has extra scan URLs (today: M281700 → https://www.finmatch.io/docs).

Embed Snippet Presence​

Asks 2) Are FinMatch embed snippets present? This is the calculator / modal embed scan, not the header SDK.

PillWhen
PASSThe monitor listed pages with embed snippets, or source verification found embed markers.
FAILNeither source. Current Failures gets No embed snippets detected by monitor or source verification.

There is no link on this card. Empty bullets: None detected. This mirrors the merchant detail message: "Run Check snippet to scan for embed codes." Loaded bullets list each URL with calc= / modal= lender names.

What to do:

  1. FAIL — the storefront still needs calculator or modal embed mounts. Use the merchant App card Pages with embed snippets and Check snippet, then Refresh Monitoring.
  2. Note Source verification found embed markers while monitor returned zero pages. — treat embeds as present; re-run Check snippet so the page list fills in.

A header-only install PASSes Header Snippet Detection and FAILs this card until product / cart / modal embeds exist. That is expected on a new merchant.

Merchant Router Assignment​

Asks 3) Is the merchant assigned to an environment in merchant-router? The card does not download a public router file. It asks the getMerchantConfig resolver (fresh=1) which environment that merchant is routed to.

PillWhen
PASSResolver returned an environment other than shared, and it matches the merchant profile environment.
WARNResolver unreachable (Could not reach the resolver — routing not verified), or profile env and resolver env disagree.
FAILResolver answered, but the merchant is absent from the router (environment is shared / empty). Current Failures gets missing in merchant-router.json.

Open Resolver Response opens that live JSON in a new tab.

Loaded bullets when assigned: Resolved environment, Merchant profile environment, Resolver domain, Storefront SDK enabled: yes or no (kill switch set in router), Runtime source.

What to do:

  1. FAIL missing from the router — open the merchant, confirm Environment, then Check env on the App card. Create / save should have written the router entry; if it is still missing, that is a routing write failure, not a snippet miss. See Environment and integrity and Storefront runtime.
  2. WARN environment mismatch — profile env and resolver env disagree. Fix Environment on the merchant, then Check env / Refresh.
  3. WARN unreachable — Refresh, then Open Resolver Response to read the HTTP / JSON error. Routing is unverified until that call works.
  4. Storefront SDK enabled: no — the router kill switch is on. Shoppers will not load the SDK. Use the Features sdkEnabled toggle on the merchant App card, not Merchant Status.

Domain Whitelist Coverage (merchant card)​

Asks 4) Is the merchant whitelisted? This is the per-merchant CORS check, not the Global add-domain panel. Required hosts come from merchant.domain and the resolver domain. Optional hosts come from testing_domain.

PillWhen
PASSEvery checked host is on the CORS allow-list (https://host or https://www.host).
WARNCORS summary could not be fetched, or only an optional testing domain is missing.
FAILA required host is missing. Current Failures gets Missing required CORS allow-list entry for that host.

Fix CORS now (hover Force CORS reconciliation for this merchant) posts ensure-cors for this merchant, then reloads Monitoring. Busy: Fixing....

The card also has a CORS config link. Use the Global card’s Open CORS Config when you need the allow-list itself — see Domain Whitelist Coverage.

What to do:

  1. FAIL missing required host — click Fix CORS now. If it still fails, switch to Global Domain Whitelist Coverage and Add domain to whitelist for that host, then Refresh.
  2. WARN missing optional testing domain — add that host only if you actually serve finance on the testing domain.
  3. WARN could not fetch CORS — Refresh. If the Global card is also UNAVAILABLE, merchant-api /admin/cors/summary is down.

Merchant Configuration Quality​

Asks 5) Valid config + enabled app features + lenders + credit products. It loads this merchant’s runtime config from merchant-api.

PillWhen
PASSConfig loaded, profile domain matches config merchantDomain, and at least one lender is enabled.
WARNConfig loaded, but profile vs config domain disagree, or no lenders are enabled.
FAILConfig lookup failed, or the response has no config entry.

Open Merchant Config Endpoint opens the merchant-api admin config JSON for this merchant.

Loaded bullets:

  • 5a) Config entry present: yes / no
  • 5b) App features enabled: Finance Assistant / Modal surfaces, or none detected
  • 5c) Lenders enabled (N): lender names, or none
  • 5d) Credit products enabled: count of assigned rate-card products
  • Profile domain and Config merchantDomain

What to do:

  1. FAIL lookup / no config entry — Open Merchant Config Endpoint to read the error. Then Check env on the merchant App card. Global Merchant Config Drift Alarm is the fleet view of the same gap. 5a) Config entry present: no can FAIL the pill without a Current Failures row — use the card, not the list.
  2. WARN / note Domain mismatch — profile domain and config merchantDomain differ. Fix Domain on the merchant and re-save.
  3. Note No lenders currently enabled — assign lenders on the merchant Credit Products accordion, then Save credit products.
  4. Note No credit products assigned — assign products on those lender rows.
  5. Note No financeFeaturesVisibility features detected — enable Features (Pay monthly / modal / Finance Assistant) on Overview, then Save features.

Notes 3–5 do not flip the pill to FAIL on their own. A merchant with a valid config and lenders still PASSes while those notes tell you the app is not fully wired.

Domain Whitelist Coverage​

Domain Whitelist Coverage is the Global-mode card for gs://finmatch-shared/cors.json (merchant-api is the only writer). Merchant Monitoring has a separate per-merchant card of the same name — see Domain Whitelist Coverage (merchant card).

  • Filter hosts searches the loaded allow-list. Search placeholder: Filter by host.
  • Add domain to whitelist accepts one or more raw domains (comma or newline). Placeholder: example.com, another-shop.co.uk. Save writes both https://host and https://www.host.
  • Add to whitelist submits. Empty-add status: Enter one or more domains. All-invalid: All inputs rejected client-side; nothing sent. Busy: Adding.... Open CORS Config / Refresh reload the card.

Do not paste partner keys into these docs.

Mirror Admin Configs Across Environments​

Mirror Admin Configs Across Environments copies admin-managed config files that sync-to-gcs.yml excludes. It is a Global-mode panel (bottom of the grid), not a MONITORS card. Backed by merchant-api /admin/mirror-configs. Preview uses ?dry_run=true. Writes use atomic GCS preconditions.

FieldMeaning
Source env (authoritative)Read from this env (default p). Options: p — production, s — staging/canary, t — test.
Target env (will be overwritten)Write destination (default t). Same three options.

Files to mirror​

Files to mirror is the checkbox list. Each row is a path plus an em-dash caption. All three start checked. Uncheck any file you do not want copied. No files checked: Select at least one file to mirror.

CaptionPathWhat the operator is copying
Merchant runtime configconfigs/finmatch-merchant-config.jsonPer-env merchant lender / runtime config (the file Merchant Config Drift Alarm and Merchant Configuration Quality read).
Lender stylingconfigs/lender-styling.jsonLender-level styling (Lender Settings styles), not merchant Pay Monthly CSS.
Lender overridesconfigs/lender-overrides.jsonLender override JSON for that env.

What to do:

  1. Set Source env (authoritative) to the env that already has the good files. Set Target env (will be overwritten) to the env you are filling. Same-env status: Source and target environments must differ.
  2. Leave checked only the captions you intend to replace on the target. Untick Merchant runtime config if you only want styling / overrides.
  3. Click Preview (dry-run) first. Busy: Previewing.... Read source → target buckets and item counts. Confirm dismiss is not needed for preview.
  4. Click Mirror (write to target) only after the preview looks right. Confirm the replace dialog. Busy: Mirroring.... Confirm dismiss: Cancelled.
  5. Do not use this to bulk-promote t → p. Storefront runtime still authors on finmatch-p. See Source of Truth.
  6. After a write, open Global Monitoring and Refresh Merchant Config Write Audit — a tagged admin-ui mirror should PASS; an untagged write would FAIL.

Scheduled Tasks​

Click Scheduled Tasks. Idle meta: Scheduled tasks: Cloud Scheduler jobs and GitHub Actions cron workflows. Empty lists after load: No issues. / No notes.

This mode is not the Global card grid. It lists scheduled jobs. Today there is one card.

Merchant Config Monitoring​

GitHub Actions cron. Description: Fetches drift and audit reports from merchant-api, publishes to GCS monitoring bucket, alarms on config drift or non-admin writes.

ChromeMeaning
Job pill ENABLEDThe workflow is listed as enabled in this UI (not the last-run result).
GitHub ActionsSource. Schedule Every 30 minutes (*/30 * * * *, UTC).
TargetGitHub Actions cron merchant-config-monitoring.yml.
Last-run pillPASS / FAIL / other, from published latest.json (overall_status or report.overall_status). Last run: plus the timestamp.
Latest JSONOpens gs://finmatch-admin/monitoring/merchant-config-drift/latest.json (the published integrity payload).
View RunsOpens the GitHub Actions workflow run list.

The job fetches production drift (/admin/merchant-config-integrity?env=p) and audit (limit=250), publishes both under gs://finmatch-admin/monitoring/, then classifies / alerts. The card’s Latest JSON is the drift object. Live Global Merchant Config Drift Alarm and Merchant Config Write Audit recompute the same endpoints in the browser.

If latest.json is missing, the card shows No results yet (HTTP …) and Notes and Warnings gets No monitoring results available yet.

What to do:

  1. Read the last-run pill, not the ENABLED pill, for whether the last publish was green.
  2. FAIL last run — Latest JSON, then the matching Global card (Merchant Config Drift Alarm). Fix missing runtime rows / id mismatches the same way as that card.
  3. To see whether the cron actually ran, click View Runs. Use workflow_dispatch there only if you intend to publish a fresh GCS snapshot; page Refresh on Scheduled Tasks only re-reads latest.json.
  4. After a merchant-config write, either wait for the next 30-minute publish or Refresh the live Global drift/audit cards.