Active sources: zyndex === Scenario 1 — anonymous advisor search === [tool] search_products -> {"count":2,"products":[{"id":"zx-1002","source":"zyndex","name":"947 \u2014 30s Generic Advert","category":"radio","mediaType":"Radio","province":"Gauteng","area":"Johannesburg","price":3800,"unit":"per spot","url":"https://admart.co.za/radio","summary":"Pre-recorded 30-second generic advert on 947 in Joburg."},{"id":"zx-1001","source":"zyndex","name":"Jacaranda FM \u2014 30s Live Read","category":"radio","mediaType":"Radio","province":"Gauteng","area":"Pretoria","price":4500,"unit":"per spot","url":"https://admart.co.za/radio","summary":"A 30-second live read by the DJ during drive-time on Jacaranda FM."}]} [bot ] For a Pretoria launch under R5k, I'd look at the Jacaranda FM live read (R4 500) or the 947 generic spot (R3 800). Want me to add one to your order? === Scenario 2 — anonymous order attempt (must be blocked) === [tool] add_to_order -> {"error":"auth_required","message":"Please log in on the site to manage or place an order \u2014 I can still help you find products."} [bot ] You'll need to log in on the site so I can hold your order — I can keep helping meanwhile. === Scenario 3 — logged-in add + confirm + place === [tool] add_to_order -> {"added":{"id":"zx-1001","name":"Jacaranda FM \u2014 30s Live Read","qty":1,"lineTotal":4500},"note":"Draft held. Call place_order only after the user confirms."} [bot ] Added the Jacaranda FM 30s live read — R4 500. Shall I place the order? === Scenario 4 — JWT verify === valid token -> user-42 tampered token -> rejected (correct) All scenarios executed.