Review manager
Review manager is the fixed-source surface for Business, Driver, Customer, Professional, and Product feedback. It includes private reads, bounded CSV-export source paths, and a Business-review moderation write; none was exercised.
The fixed route /intelligence/reviews allows level 0. The sidebar item requires Pro or Enterprise for level 0; its Business-owner expression can additionally consult configured Reports membership, but that does not widen the route. API authorization remains separate.
Source-defined categories
The UI source renders Business, Drivers, Customers, Professionals, and Products tabs, plus search and pagination. Product review navigation first selects a Business; query state can retain tab, pagination, and selected entities. These controls identify source paths, not a safe workflow or deployed result.
The retained screenshot is controls-only and contains no review record. It does not establish deployed access or current response fields.
Read, export, and filter boundaries
Fixed source reads Business, user, and product review listings/details. Returned fields can include names, email addresses, images, addresses, order numbers, timestamps, ratings, comments, products, and enabled state.
Contrary to the previous statement that no CSV was identified, current source renders a download flow for the Business and Drivers tabs. It builds date filters using created_at from start-of-day through end-of-day. Business CSV can include a selected Business ID; Driver CSV can load level-4 users, filter by a selected driver ID, and adds review type=1. The fixed paths are business/business_reviews.csv and users/user_reviews.csv.
Those authenticated GET downloads are export actions and are not safe by verb. No review list, driver filter, CSV response, Blob, filename, or production value was accessed or created.
Moderation write boundary
Business review detail source exposes an enabled-state update. The other inspected review-category details do not establish the same switch. No moderation request was sent, and source code cannot prove a deployed write, authorization result, persistence, or success notification.
Maintenance boundary
Revalidate route/menu/plan gates, tabs, query keys, Business and driver filters, date construction, CSV paths, fields, moderation control, and API authorization on source drift. Runtime or positive export/moderation claims require synthetic review data, blocked writes/downloads, immutable serving receipts, and independent admission.
Related guides: Reports overview · Business reports