partner.payout (faults.failAt). It ran three times on testnet; each run compensated cleanly.
The run
EUR → NGN, 4 pathUSD, recorded on 29 September 2026:Fig. 07 · Forward legs, a failure at the partner, and compensation in reverse order with an on-chain refund.
Why reverse order
Compensations run from the last completed step to the first. Unwinding the hold before the bridge refund would let the customer’s balance show funds that are still in the escrow, and the ledger would balance while describing a sequence that never happened. In reverse order, every intermediate state is one that really existed.When not to compensate
If the partner fails after it was funded, the money is at the partner, not with Corridor. Reversing Corridor’s books at that point would be wrong until the partner’s refund is confirmed, so the payout leg throwsManualReviewError: no retries, no automatic compensation, and the saga waits in manual_review for a person to close it against the partner’s refund.
The result
The Tempo deposit and its refund both carry the payout’s reference, so reconciliation matches both movements to the forward and compensating entries.