Start with one bounded execution path
The refund pilot submits an exact, operator-approved refund against a recorded payment in Stripe test mode. Durable operation claims and provider idempotency protect the submission path. General purchases, sales, payouts, and subscriptions remain proposal-only.
Resolve uncertainty before retrying
A provider timeout can leave an unknown outcome. Reconciliation checks the existing operation and records the provider observation. It does not create another refund. Operators can review this state in Refund operations.
Preserve what changed
An approval, submission attempt, and later provider observation are different facts. Retain the request identity so the operator can follow them together. Test-mode observations are not evidence of a live-money transfer.
Expand execution only with a complete contract
Each additional provider path needs exact authorization binding, durable duplicate prevention, uncertainty handling, reconciliation, and failure tests. A connector appearing in a menu is not enough to claim support for money movement.