Driver Enrollment Flow
The driver enrollment flow registers a mileage-reimbursement (MR) driver under the verified member and configures payment. It is a prerequisite for MR bookings: assign_driver needs an approved enrollment, and the payee setup governs how the reimbursement is issued.
Tool Sequence
Section titled “Tool Sequence”verify_member— create session withlob_idandmember_idenroll_driver— collect driver PII, address, and license details. Status starts aspending(admin approval required).setup_payee— configuredirect_deposit(ABA + account) orcheck(paper).- (Later, after admin approval)
get_member_drivers→assign_driverduring booking.
graph LR
V["verify_member"] --> E["enroll_driver"]
E --> P["setup_payee"]
P --> W["(admin review)"]
W --> B["get_member_drivers → assign_driver
(during booking)"] style V fill:#48bb78,color:#fff style E fill:#d53f8c,color:#fff style P fill:#d53f8c,color:#fff style W fill:#718096,color:#fff
(during booking)"] style V fill:#48bb78,color:#fff style E fill:#d53f8c,color:#fff style P fill:#d53f8c,color:#fff style W fill:#718096,color:#fff
Enroll Driver (enroll_driver)
Section titled “Enroll Driver (enroll_driver)”Required data:
enrollment_type—self(member drives) orfriend_or_family- Driver name (first + last, middle optional)
- Phone (any format; normalized to E.164)
- DOB — driver must be 18+
- Full address (line 1, city, state, postal code)
- Driver license (number, state, expiration). License must not be expired.
Idempotency: if a prior enrollment matches by (first + last, case-insensitive) OR by normalized phone, the existing enrollment is returned with idempotent=true. No duplicate row is inserted.
Status: new enrollments start pending. An admin must approve before the driver can be assigned to trips.
Setup Payee (setup_payee)
Section titled “Setup Payee (setup_payee)”Two payment methods are supported:
direct_deposit— requiresaccount_type(checking/saving), 9-digit ABArouting_number, and 4-17 digitaccount_number. Routing numbers are validated against the ABA mod-10 checksum. Invalid routing numbers are rejected without retry; the error never echoes the value.check— paper checks are mailed to the payee address on file. No banking fields required.
Idempotency (direct deposit): the account number is fingerprinted. If a matching payee already exists, it is returned with idempotent=true.
Compliance (PCI + HIPAA)
Section titled “Compliance (PCI + HIPAA)”- Account numbers and tax IDs are encrypted with AES-GCM before persistence. Ciphertext and IV live in separate columns; the plaintext is never persisted.
- Only the last 4 digits and a stable fingerprint are kept alongside the ciphertext (display + idempotency).
- The input values for
routing_numberandaccount_numberare cleared from memory immediately after encryption. - Audit entries (
mcp.enroll_driverandmcp.setup_payee) carryaction+ a comma-separated list of FIELD NAMES that were supplied — never values. - Error logs capture
session_idonly; no PII or PCI data.
Error Handling
Section titled “Error Handling”MISSING_PREREQUISITE— returned for underage drivers, missing required address fields, or when direct-deposit account type is missing.INVALID_DATE— returned for unparseable DOB or license expiration, or when the license is already expired.- Validation failures (routing mod-10, account length, email shape) return a validation error before any write.
Related
Section titled “Related”- enroll_driver
- setup_payee
- Used by: Booking Flow (MR variant) via
assign_driver