# Cortexico — Meta App Review Submission Pack

## 1. Reviewer access

Provide Meta with a dedicated Cortexico reviewer user. The user must belong to a test tenant and must not require OTP, VPN, IP allow-listing, payment, or manual activation.

```text
Application URL: https://cortexico.com/nedmin/production/meta-review-center.php
Username: [META_REVIEW_USERNAME]
Password: [META_REVIEW_PASSWORD]
Language: Turkish UI; English testing instructions are provided below.
```

Test assets must remain available during the entire review:

- One Facebook Page with a visible test post and test-user comment
- One Instagram professional account with a test media comment and DM thread
- One WhatsApp Cloud API test number with an active webhook subscription
- One Meta test ad account with at least one campaign and recent insight data
- One Lead Ads form with a retrievable test lead, only if `leads_retrieval` is submitted

## 2. Common reviewer instructions

1. Sign in to Cortexico with the credentials above.
2. Open **Meta Review Center** from the application menu or use the direct URL.
3. Enable **Recording Mode** to hide internal readiness notes.
4. Select the relevant connected channel or Meta Ads account.
5. Follow the steps for the requested permission.
6. Every button calls the real Cortexico backend and Meta Graph API. No mock data is used.
7. The **Evidence Log** displays a sanitized result and never exposes access tokens.

## 3. Permission and feature requests

### `pages_show_list`

**How Cortexico uses this permission**

Cortexico uses `pages_show_list` to list the Facebook Pages managed by the authenticated business user. The user explicitly selects which Page to connect to their Cortexico tenant. Cortexico does not connect or process Pages that the user did not select.

**How to test**

1. Open Meta Review Center.
2. Click **Connected Assets**.
3. Confirm that the selected Facebook Page name and Page ID are displayed.
4. Open **Channel Management** and confirm that the Page is stored only under the current tenant.

### `pages_manage_metadata`

**How Cortexico uses this permission**

Cortexico uses `pages_manage_metadata` to subscribe the selected Page to the application's webhooks, check current subscribed fields, and unsubscribe the Page when the user disables the integration. This is required to receive Page messaging and feed events in real time.

**How to test**

1. Select the Facebook channel in Meta Review Center.
2. Click **Check Status**.
3. Click **Subscribe** and confirm the subscribed fields are displayed.
4. Click **Check Status** again.
5. The destructive **Unsubscribe** operation always asks for explicit confirmation and preserves previously imported history.

### `pages_read_engagement`

**How Cortexico uses this permission**

Cortexico uses `pages_read_engagement` to read posts and engagement metadata belonging to the Page selected by the business user. This data is displayed in the social content inbox and used for tenant-scoped reporting.

**How to test**

1. Select the Facebook channel.
2. Click **Fetch Posts and Comments**.
3. Confirm the returned post and comment counts.
4. Click **Open Results** and view the synchronized Page posts.

### `pages_read_user_content`

**How Cortexico uses this permission**

Cortexico uses `pages_read_user_content` to read user-generated content and comments published on the connected Page. Authorized team members use this information to monitor customer feedback and respond from a shared workspace.

**How to test**

1. From the supplied test Facebook user, add a comment to the test Page post.
2. In Meta Review Center, click **Fetch Posts and Comments**.
3. Open the results and open the comments for the test post.
4. Confirm that the exact test-user comment is displayed.

### `pages_messaging`

**How Cortexico uses this permission**

Cortexico uses `pages_messaging` to receive and respond to Messenger conversations sent to the Facebook Page selected by the business user. Messages are available only to authorized users of the same Cortexico tenant.

**How to test**

1. From a separate test Facebook account, send a Messenger message to the connected Page.
2. Select the Facebook channel and click **Fetch Messages**.
3. Open **Inbox** and select the new conversation.
4. Send a reply from Cortexico.
5. Confirm the reply is delivered to the test Facebook account.

### `instagram_business_basic`

**How Cortexico uses this permission**

Cortexico uses `instagram_business_basic` to identify and display the Instagram professional account selected by the authenticated business user and associate it with the correct Cortexico tenant.

**How to test**

1. Open Meta Review Center.
2. Select the Instagram channel.
3. Click **Verify Instagram Connection**.
4. Confirm the Instagram account name and ID.

### `instagram_business_manage_messages`

**How Cortexico uses this permission**

Cortexico uses `instagram_business_manage_messages` to receive and respond to Direct messages sent to the connected Instagram professional account. The shared inbox helps authorized customer-service users handle business conversations.

**How to test**

1. Send a DM to the connected Instagram account from a separate test account.
2. Open **Instagram Inbox** in Cortexico.
3. Open the new conversation and reply.
4. Confirm the reply is visible in the Instagram test account.

### `instagram_manage_comments`

**How Cortexico uses this permission**

Cortexico uses `instagram_manage_comments` to read comments on media owned by the connected Instagram professional account and to let an authorized user send an appropriate public or private response.

**How to test**

1. Add a comment to the supplied test Instagram media from a separate test account.
2. Open the Instagram comment workspace in Cortexico.
3. Display the test comment.
4. Send a reply and confirm the response on Instagram.

> If Meta displays the renamed `instagram_business_manage_comments` permission for this app/use case, use that exact permission name in the submission and configuration. Do not request both aliases unless the product configuration requires both.

### `whatsapp_business_management`

**How Cortexico uses this permission**

Cortexico uses `whatsapp_business_management` during WhatsApp Embedded Signup to discover and validate the WABA and phone number explicitly selected by the business user and to subscribe the application to the selected WABA.

**How to test**

1. Open Meta Review Center.
2. Select the WhatsApp channel.
3. Click **Verify WhatsApp Connection**.
4. Confirm the connected WABA ID and Phone Number ID.

### `whatsapp_business_messaging`

**How Cortexico uses this permission**

Cortexico uses `whatsapp_business_messaging` to receive and send customer-service messages through the business phone number selected during WhatsApp Embedded Signup.

**How to test**

1. Send a WhatsApp message from the supplied test phone to the connected business number.
2. Open **WhatsApp Inbox** in Cortexico.
3. Open the new conversation and reply.
4. Confirm the reply is received on the test phone.

### `business_management`

**How Cortexico uses this permission**

Cortexico uses `business_management` to discover business-owned assets that the authenticated user is authorized to connect, validate asset ownership, and associate the user's selection with the correct tenant. Cortexico does not access unrelated business assets.

**How to test**

1. Start the Meta connection flow from Cortexico.
2. Complete OAuth and select an authorized business asset.
3. Return to Cortexico and display the connected Page, Instagram account, WABA, or ad account.

### `ads_read`

**How Cortexico uses this permission**

Cortexico uses `ads_read` to read the selected Meta ad account's campaigns and performance insights. Authorized users use this data to build dashboards, reports, comparisons, and AI-assisted analysis.

**How to test**

1. Select the Meta Ads account in Meta Review Center.
2. Click **Fetch Campaigns**.
3. Open **Campaign Screen**.
4. Display campaign name, spend, impressions, clicks, leads, and ROAS for the selected period.

### `ads_management`

**How Cortexico uses this permission**

Cortexico uses `ads_management` only to apply a campaign change that an authorized user has explicitly reviewed and approved. Cortexico shows the proposed action first, requires manual approval, and records the outcome in an audit log.

**How to test**

1. Open **Ads Bot Actions**.
2. Select the supplied pending test action.
3. Review the target account, campaign, current value, and proposed value.
4. Click **Approve**.
5. Display the completed/failed result and audit log.

### `pages_manage_ads`

**How Cortexico uses this permission**

Cortexico uses `pages_manage_ads` when an authorized user manages advertising associated with a selected Facebook Page through the controlled Ads workflow. The user selects the Page/ad account and manually approves any change.

**How to test**

1. Open the connected Meta Ads account.
2. Show the Page-associated test campaign.
3. Open a proposed controlled action.
4. Review and manually approve the action.
5. Display the audit result.

### `leads_retrieval`

**How Cortexico uses this permission**

Cortexico uses `leads_retrieval` to import leads submitted through Lead Ads forms belonging to the connected Page. Imported leads are stored only in the current tenant and made available to authorized CRM users for follow-up.

**How to test**

1. Open the connected Page's Lead Forms screen in Cortexico.
2. Select the supplied test form.
3. Create a test lead using Meta's Lead Ads Testing Tool.
4. Click **Fetch Leads**.
5. Display the exact test lead and its tenant-scoped CRM record.

**Submission gate:** Do not submit this permission until the real Lead Form and lead-record screen is implemented. Aggregated campaign lead counts are not sufficient evidence.

### Marketing API Access Tier

**How Cortexico uses this feature**

Cortexico is a multi-tenant business analytics and communication platform. The Marketing API Access Tier is required to connect customer-authorized Meta ad accounts, synchronize campaign and insight data at production scale, generate dashboards and reports, and execute only user-approved management actions.

**How to test**

1. Connect the supplied Meta test ad account.
2. Display the account in Meta Review Center.
3. Fetch and display campaign performance.
4. Open dashboard and reporting screens.
5. Demonstrate one manually approved test action and its audit result.

### `public_profile`

**How Cortexico uses this permission**

Cortexico uses `public_profile` only to identify the authenticating Meta user during OAuth and associate the authorization with the correct authenticated Cortexico user and tenant session.

**How to test**

1. Start Meta OAuth from Cortexico.
2. Complete the consent flow.
3. Confirm successful return to the tenant-scoped asset selection screen.

## 4. Recommended recordings

Create short, readable recordings at 1080p or higher. Do not speed up the video, obscure important UI, expose access tokens, or use edited mock data.

1. Facebook connection and Page selection
2. Facebook webhook subscribe/status/unsubscribe control
3. Facebook posts and user comments
4. Messenger receive and reply
5. Instagram identity, DM, comment, and reply
6. WhatsApp WABA/number and receive/reply
7. Meta Ads account, campaigns, insights, and reports
8. Controlled Ads management action and audit log
9. Lead Forms and test lead retrieval, only after the module exists

At the beginning of each video, briefly show:

- The Cortexico URL
- The authenticated test tenant
- The permission or feature being demonstrated
- The connected test asset

At the end of each video, show the resulting record or provider-side outcome.

## 5. Submission checklist

- App icon, privacy policy, terms, data deletion, and deauthorization URLs are publicly accessible.
- Client OAuth and Web OAuth are enabled.
- Valid redirect URI exactly matches the production callback.
- App Domains contains `cortexico.com`.
- Webhook callback and verify token validate for Page, Instagram, and WhatsApp objects.
- Test user works without OTP or administrator intervention.
- Test user has access to every test asset used in the recordings.
- Every requested permission has a matching description, test procedure, and video evidence.
- Videos use real API data and show both the triggering user action and result.
- No access token, app secret, phone number belonging to a real customer, or unrelated tenant data appears.
- Data handling questionnaire answers match actual storage, retention, encryption, and deletion behavior.
- `leads_retrieval` is removed from this submission if the Lead Forms and lead-record workflow is not completed.
- Permission names in the Login for Business configuration match the permission names shown in the App Review request.

## 6. Final warning

No text or screen design can guarantee approval. Meta decides after reviewing the actual app behavior, business verification, data handling, test access, and policy compliance. This pack is designed to remove avoidable review failures and make each requested permission directly testable.
