| Tenant context is required and ordinary queries are tenant-filtered | Commands/query filters | Missing tenant blocks commands; cross-tenant rows are excluded. Implemented. |
| Code, name, and type must be valid | Registration/domain value objects | Invalid input blocks creation. Implemented. |
| Normalized asset code is tenant-unique | Registration/application repository check | Duplicate returns conflict. Implemented at application layer; no matching tenant+code unique database constraint. |
| Serial number need not be unique | Registration | No conflict check or unique constraint. Unenforced expectation if uniqueness is desired. |
| Request needs a positive requesting user | Request/domain | Missing resolvable user blocks request. Implemented. |
| Assignment requires eligible status and a holder reference | Assignment/domain | Invalid status or empty assignee blocks issue. Implemented. |
| One active assignment per aggregate | Assignment/status model | Issued cannot be issued again. Implemented, without a separate assignment table. |
| Workflow-managed request is decided through workflow | Direct assign/reject/application guard | Direct operation conflicts until callback. Transitional/configuration-dependent. |
| Return requires Issued | Return/domain | Other status blocks; holder and dates clear on success. Implemented. |
| Returned is not automatically Available | Return/domain | Explicit mark-available or direct reassignment follows. Implemented. |
| Rejection requires Requested and a reason | Reject/application+domain | Invalid request blocks. Implemented. |
| Damage/loss cannot follow Retired or Rejected | Incident/domain | Invalid transition blocks. Implemented. |
| Retirement cannot repeat | Retire/domain | Second attempt blocks. Implemented. |
| Only Available, Requested, or Rejected can be deleted | Delete/domain | Other statuses conflict. Implemented. |
| Employee must exist/own request | Assignment/request | No Employee Service validation or resource ownership check. Not implemented. |
| UI type/condition choices and role visibility | Portal | UI-only, not canonical API enforcement. Transitional. |