The baseline stayed green

CODE57 did not trade previous verification for new features. The JVM debug suite remained 148/148, the JVM release suite remained 148/148, lint passed, and debug, AndroidTest, release, R8 and AAB builds completed. On the Samsung SM-S938B, the unfiltered instrumentation suite again passed 175/175. The installed Owner APK was pulled back from the device and matched the build output byte-for-byte.

That baseline matters because a new network path and a new save contract can disturb unrelated behavior. Keeping the existing regression evidence green is necessary. It is still not the same thing as proving every release gate.

What the FX request actually sends

CODE56 had deliberately stopped at documented manual exchange-rate provenance. CODE57 adds a shared Fetch exchange rate path for only two already-supported rows: outside-EU B2B service purchases paid directly and outside-EU B2B service sales received directly.

The request goes to the official ECB Data API and contains the ISO currency plus requested date range. It does not send the transaction amount, counterparty, invoice, receipt, evidence or ledger data. FigureDesk crosses the relevant ECB observations into an SEK-per-unit rate, accepts the latest observation not after the requested date within the defined seven-day window, displays the actual source date, and stores source, rate and timestamps in a narrow cache. SEK bookkeeping makes no FX request.

When the automatic result is used, the posting snapshot freezes the original amount, currency, SEK amount, rate, effective date, actual source date, source and method. Manual documented entry remains available as the fallback.

Why automatic does not mean trusted everywhere

The technical source proof succeeded: a live ECB request returned official CSV observations. Provider, HTTP, format or missing-rate failures are fail-closed and leave the form without an automatic rate, directing the user back to manual entry.

But CODE57 still does not claim release certification for the automatic source. The requested current official-guidance reconciliation could not be completed in that run because the configured web-search provider returned HTTP 401. That limitation is kept visible rather than being converted into an assumption that technical reachability equals accounting suitability.

The product scope is also intentionally narrow. EU cases, goods, uncertain locations and every foreign invoice/settlement/credit/refund route remain fail-closed. Exchange-difference lifecycle work is not presented as supported merely because rate retrieval now works.

Saving a PDF is a lifecycle

CODE57 also changed the PDF workflow for accounting, VAT, standard, K1, NE and credit reports. Those families now prepare immutable PDF bytes before Android CreateDocument opens. The user chooses the filename and destination. Cancel is reported as cancellation, not failure or success. After a write, FigureDesk reads the destination back and byte-compares it before reporting success.

The saved content URI can then be used by the in-app viewer and explicit Android share chooser. Historical snapshot determinism and multipage rendering remained green in device tests.

That still does not mean “all PDFs are standardized.” Invoice/quote and calculator paths retain direct MediaStore export, and the complete residual scan plus exact Back-origin/scroll behavior were not physically certified. A partial migration is described as partial.

Automation is not physical certification

The Samsung instrumentation suite passed 175/175, but the manual A–T certification matrix was not completed. Several groups, including G–K and N–S, remained uncertified, and the two user-visible backup cycles were not run on the exact CODE57 build.

Automated schema-17 backup coverage is green across current and legacy restore, documents, evidence, accounting, K1/NE/year-end and corrupt/future/truncated rejection. The missing evidence is different: two complete user-visible backup → clear → restore → restart cycles on the physical build. The automated suite is evidence for one layer, not a substitute for the other.

Why CODE57 still failed the gate

The final release gate records P0: 0 and P1: 0, but five release-blocking P2 capability groups remain incomplete. The foreign invoice lifecycle is not product-complete. PDF CreateDocument is not universal. The clean-new and save-feedback physical inventories are incomplete. Two schema-17 physical backup cycles were not run. The complete A–T physical matrix was not completed.

CODE57 therefore ends with CLOSURE: FAIL. No production signing or upload was performed. That status is not a contradiction of the green tests; it is the result of requiring several kinds of evidence before calling the product ready.

The engineering lesson

CODE57 shows why “implemented,” “technically proven,” “automatically tested,” “physically certified” and “release-approved” should be separate states. The ECB request is implemented and live-proved, but its release suitability remains open. Several PDF families have verified save behavior, but the entire PDF surface is not standardized. Backup automation is green, but the required physical recovery cycles are still missing.

For high-consequence software, those distinctions are useful product information. They make it possible to add capability without quietly widening the public promise beyond the evidence.

This case study describes software-development and verification evidence from FigureDesk CODE57. It is not accounting, tax or legal advice.