Source: MIZOKI audit 2026-09-06 (pinned fc8b03f9) → work-order backlog 2026-09-08 (docs/audits/AUDIT_WORK_ORDERS_2026-09-08.md); WO-44..49 added 2026-09-08 from the source-verified review v1.1 (docs/reports/MIZOKI_ACQUISITION_ECONOMICS_REVIEW_v1.1_2026-09-06.md, verified on main 635318712). Findings are hypotheses until reproduced on current main (WO-00).
Finding (confirmed on main 635318712): services/measurement-rails/offline_conversions.py:30 pins GOOGLE_ADS_API_VERSION = "v22" and builds customers/{id}:uploadClickConversions payloads (line 124). Two clocks run against it: since 2026-06-15 the Ads API refuses NEW adopters of offline conversion imports (official post 2026-05-15; CUSTOMER_NOT_ALLOWLISTED_FOR_THIS_FEATURE; only developer tokens with Dec 2025–May 2026 import history keep access) — a first design partner has no such history under our token; and v22 sunsets ~2026-10-07 (secondary source; confirm on the official sunset page). This is a SECOND sunset-pinned Google site beside WO-24's google_ads.py v21. services/service-data-manager-connector already speaks datamanager.googleapis.com/v1/events:ingest (WO-25 fixes its contract).
Files: services/measurement-rails/offline_conversions.py, services/measurement-rails/test_rails_offline.py, services/measurement-rails/flags.py; connector-health panel adapter in miz-oki-command-center-ui/lib/bff/adapters/.
Fix: keep the provider-neutral front half (gclid→gbraid→wbraid precedence, 90-day window, before-click rejection — unit-tested) and route the send through the Data Manager connector; the legacy uploadClickConversions builder becomes compatibility-only behind an explicit LEGACY_ADS_API_OFFLINE=true flag that refuses when the pinned version is past its recorded sunset date or the tenant has no recorded pre-2026-06-15 import. Add Data Manager developer-token/allowlist eligibility to connector health.
Acceptance: test: default path never emits an uploadClickConversions payload; test: legacy path refuses past sunset and without allowlist evidence; validate-only events:ingest accepted in a test account (shared with WO-25); CI asserts no GOOGLE_ADS_API_VERSION literal in the tree is on Google's sunset list (extend WO-24's check to all sites).
Depends on: WO-00, WO-25.
Owning prompt: CC-4 (services/measurement-rails/**); the sunset-list CI assertion lands with CX-3/WO-24.