ROLE_MANUFACTURER_ADMIN and the service provider must belong to the current client. All body fields are optional — the server only applies fields actually provided. Status transitions are validated against a fixed set of allowed status values; invalid values return 400. Detail updates are matched by reference between request and existing order details. When status or trackingData of a detail changes, a configured webhook is triggered.