PRISM Signals by Cambridge TCG is a branded reading of the public opportunity-signal contract. Its narrow promise is: Potential deals, with the risks attached. The product wraps a bounded signal; it does not sell a raw source archive or reveal the private decision engine.
Current boundary — 2 September 2026. Synthetic preview · no live market data · no payment. A revocable closed-beta-interest path, extraction package, durable runtime schema, and provider normalizers exist, but there is no live offer, purchasable price, production signal feed, accepted payment, active paid entitlement, subscribed channel, or outbound delivery path.
You can inspect the branded test at /prism-signals and its plain-language preview terms. Visiting either page creates no account, order, subscription, reservation, or access. Signed-in account holders may separately open the closed-beta-interest page; that request is not access or a purchase.
The page renders fixed copy, not a database result. It contains no real card, listing, seller, source URL, source row, or exact valuation. It demonstrates the information hierarchy a future signal must preserve:
unknown;For the detailed signal economics, expiry, confidence, liquidity, and six fixed signal refusals, read opportunity-signal methodology.
The beta page stores only the existing account id, product id, bounded web/Telegram preferences, consent-wording version, and request, update, and expiry times. Its checkbox starts unticked and specifically asks Cambridge TCG to store the request and use the account email only for a PRISM beta invitation or status contact. It is not general marketing consent; a Telegram preference neither supplies a Telegram identity nor permits a bot message.
The owner can inspect the bounded state and delete the complete row without penalty. A new affirmative submission is required to update it or refresh its 180-day expiry. A daily authenticated sweep deletes expired or superseded-wording rows. The new-intake posture is exactly PRISM_SIGNALS_BETA_MODE=closed-beta-v1. Without it the public request invitation is hidden and POST is unavailable, while the signed-in management page, owner GET/DELETE, and retention sweep remain available so existing consent cannot be stranded.
Once a beta-interest row exists, rollback means pausing new intake while this management and retention release stays live. Removing owner GET/DELETE or the retention cron requires a prior complete purge or an equivalent withdrawal and expiry procedure.
rights-cleared evidence
→ private engine
→ opportunity-signal/v1
→ PRISM presentation
provider-confirmed payment
→ bounded entitlement
→ web or Telegram deliveryThe upper line asks whether Cambridge may derive this signal from this evidence. The lower line asks whether this person may receive an already-lawful product through this channel. Neither line can prove the other.
A future subscriber can therefore receive no signal when evidence rights, identity, costs, freshness, or provider checks fail. Paying for access is not a promise that Cambridge will manufacture a decision from ineligible evidence or find a guaranteed number of deals.
The app-neutral @cambridge-tcg/product-flow package defines cambridgetcg.product-offer/1. PRISM uses the product id prism-signals. Preview and test offers belong to the test environment; a live offer belongs to production and requires an explicitly granted rights decision. The package validates that catalogue assertion's shape; it does not authenticate a rights authority, evidence binding, issuance, expiry, or signature. A live host must verify a separate bound attestation before composing the offer.
Every offer declares both delivery channels and all payment rails. Inactive rails say off instead of disappearing:
| Context | Rail | PRISM now |
|---|---|---|
| Independent web purchase | stripe_web | Off |
| Purchase initiated and fulfilled inside Telegram | telegram_stars | Off |
| Additional independent web purchase | paypal_web | Later / off |
| Additional independent web purchase | crypto_web | Later / off |
Stripe is the intended future rail for an independent web checkout. A digital product bought and fulfilled inside Telegram uses Telegram Stars only, subject to a fresh review of Telegram's then-current platform requirements before activation. PayPal and crypto remain web-only candidates and are not accepted here.
The product-flow reducer records distinct event meanings. checkout_started, browser_return, Telegram precheckout_approved, channel_linked, and payment_failed can advance an audit cursor. None can create or extend paid access.
Only provider-confirmed payment or renewal evidence, bound to the same environment, offer, version, channel, rail, and price reference, may activate a time-bounded entitlement. Access then separately checks the offer status, rights, delivery availability, entitlement scope, time window, rail, and price reference.
@cambridge-tcg/product-flow-runtimecomposes the pure reducer with a lock-first transaction contract, in-memory reference store, provider normalizers, and adapter conformance suite. The storefront's thin Postgres adapter reuses its existing persistent transaction pool. Its additive schema separates append-only canonical events from current entitlement snapshots.
The entitlement scope is locked before event allocation. Event id, provider-event ref, and rail/payment grant identity are unique within an environment. Exact duplicate provider Events return the stored canonical event; conflicting reuse—including one payment aimed at two entitlements—rolls back. A callback that would newly make a healthy projection terminally blocked also rolls back for reconciliation, so a delayed provider event cannot permanently erase valid access.
Refunds bind to the latest/current confirmed payment. Refunding an older billing period cannot cancel a newer paid period, and a partial Stripe refund is not treated as complete entitlement reversal. Stripe and Telegram Stars are normalizer-only capabilities for facts a host has already authenticated and mapped. PayPal and crypto remain disabled.
No public route consumes the runtime. PRISM still has no checkout, provider webhook, price catalogue, account/channel binding, reconciliation UI, delivery worker, or paid revocation workflow. A browser return, bot link, synthetic reply, page reload, or beta request creates no entitlement.
The test handler is disabled unless an explicit fixture-test mode and a valid Telegram webhook secret are configured. Before parsing an update it verifies the secret; it bounds request bodies, accepts only a small private-chat shape, returns no-store responses, and emits fixed synthetic copy.
It reads no market data, invokes no private scorer, calls no payment provider, persists no update, and grants no entitlement. Pre-checkout is rejected while payment is off. Unexpected payment or refund updates get a retryable non-success response: the preview cannot persist, fulfil, or safely acknowledge a provider receipt. No bot is advertised unless the operator declares a new invoice-free bot, dropped pending updates, and a BotFather privacy URL. No registration, durable update ledger, paid-channel link, scheduler, retry queue, or outbound sender is claimed.
Telegram and the Vercel-hosted route process the bounded identifiers and command needed to answer. The preview creates no application record, but provider records and infrastructure logs can still exist. Read the Telegram preview privacy notice; persistence, account linking, payment, profiling, or outbound alerts require a fresh lawful-basis and privacy review.
The extraction unit now starts with @cambridge-tcg/prism-signals-core: PRISM brand and host-bound links/privacy copy, versioned preview offer, strict public signal presentation, and pure Telegram planner. It composes with the generic product-flow contracts, framework-neutral runtime, public opportunity-signal parser/projector, and channel hosts that enforce the same access decision.
It is not the storefront database, raw price history, source credentials, seller identity, marketplace URLs, or the private engine's weights, mappings, thresholds, and outcome corpus. The purpose-specific rights decision stays bound to its evidence inside a trusted server boundary. Payment and delivery adapters remain channel-specific.
Later products can reuse the sequence—versioned offer → verified provider evidence → bounded entitlement → channel-specific delivery— without inheriting PRISM's trade secret. Each product still owns its rights purpose, terms, price evidence, refund behavior, and delivery adapter.
The PRISM package is currently unpublished workspace TypeScript in this public monorepo, not an independently published artifact. Compiled output, an explicit package file allowlist, tarball inspection, and a clean-consumer install/run smoke remain gates before a separate repository or npm release.
Provider-policy, consumer-terms, tax, privacy, payment-support, and operational review are also required before activating Stripe, Telegram Stars, PayPal, or crypto. Until then: Synthetic preview · no live market data · no payment. There is no active paid entitlement, accepted payment, or promised delivery. Beta interest changes none of those facts.
v1 — 2026-09-02. Published the branded preview, reusable product-flow boundary, channel-specific future rails, extraction seam, and closed launch gates. No live product was activated.
v2 — 2026-09-02. Added the unpublished workspace extraction package, revocable closed-beta interest with bounded retention, atomic runtime and durable schema, current-grant refund binding, and pure Stripe/Stars normalizers. No payment or live signal was activated.