cardAuthentication object.
All deliveries share the common envelope (eventId,
eventName, timestamp, programId, sandbox, customerId).
cardAuthentication fields
Only id, customerId and status are guaranteed. Every other field is included only
when known, so absent fields are omitted rather than sent as null.