Email-Based Identity Verification
TC identity is verified by matching authenticated session email against the email field on the TransactionCoordinator entity. No separate credential system required.
Offer-Scoped Access
TC access is scoped exclusively to the linked offer_id. TC cannot access other listings, other offers, or any data outside the specific transaction.
Invitation Timestamping
invited_at is recorded server-side at creation. Establishes a tamper-evident invitation audit anchor for the full transaction timeline.
Access Event Logging
last_accessed_at is updated on every authenticated TC portal visit, enabling full chronological replay of coordinator access history.
Dual-Agent Invitation Authority
Either listing agent or buyer's agent may independently invite a TC. added_by and added_by_role fields preserve which agent extended each invitation.
Write-Operation Exclusion
TC role is explicitly excluded from all offer lifecycle write operations at the application layer — counter, accept, reject, amend, terminate, reinstate.