PaymentVerification standalone install · one product

Reports

Every report this suite produces and every administrative act it performs, derived from the modules that perform them. An entry naming a symbol that does not exist fails the build, and — the direction that matters — a report-shaped function no entry claims fails it too. A register that only checks its own entries is a list.

Every report below states WHAT IT DOES NOT COVER, and every act states WHAT IT CANNOT DO. Both are required fields, refused when absent, because a report that omits its limits is read as complete and an act that omits them is read as a way to change a decision.

Reports

Refusal rate, and what each refusal was

WEEKLY report.refusalReport

The strongest criticism a provenance gate attracts is override fatigue: refuse too often and people route around it. This measures that, so the answer is a measurement rather than an instinct to soften the gate.

What this report is, and is not

For
OPERATOR, COMPLIANCE, EXECUTIVE
Derived from
the sealed receipts for the period, and the ledger they commit to
Does NOT cover
It counts REFUSALS, not correctness. A gate refusing the right things at a high rate and one refusing the wrong things at the same rate produce the same number. It also says nothing about what was never submitted, because a lot nobody filed produces no receipt.

What the refusals were worth, on outcomes that actually landed

MONTHLY report.realisedReturn

A refusal has a cost the day it happens and a benefit that arrives later or not at all. This pairs them on outcomes that have been attested, so nobody has to argue from a counterfactual.

What this report is, and is not

For
EXECUTIVE, OPERATOR
Derived from
sealed receipts plus a declared economics artefact naming the loss avoided
Does NOT cover
Only outcomes SOMEBODY ATTESTED. A refusal that prevented a loss nobody recorded is invisible here and is not zero — it is unmeasured, which is a different thing and the report says so rather than netting it out.

How much of this rests on model-authored evidence

MONTHLY report.aiExposure

An authority asking "how much of your evidence base is a model talking about itself" is asking a question the receipt already answers per decision. This aggregates it.

What this report is, and is not

For
COMPLIANCE, AUDITOR, REGULATOR
Derived from
the AI-provenance axis on each admitted record in the period’s receipts
Does NOT cover
It reports a DECLARED identity and does not detect AI content. An organisation running a model and signing as `actor:org:` is not caught here and cannot be. Reading this as an AI-detection figure is the one misreading that would matter.

Plan of action and milestones (NIST OSCAL)

MONTHLY oscal.poamFromReceipts

A regulator that speaks OSCAL should be handed OSCAL. Each open gap becomes a POA&M item keyed to the decision that is bound by it.

What this report is, and is not

For
COMPLIANCE, REGULATOR, AUDITOR
Derived from
the coverage gaps in force across the period’s sealed receipts
Does NOT cover
It emits the gaps THIS ENGINE knows about — the ones a collection template made required. A hazard nobody encoded produces no gap and therefore no milestone, and a clean POA&M is not evidence that a control catalogue is complete.

A role-scoped copy of one sealed decision

PER_DECISION roleview.scopedBody

A sealed receipt is the complete record, and its completeness is exactly why it cannot go to everyone: a customs official has a legitimate demand on the regulatory record and no business seeing what the importer priced the risk at.

What this report is, and is not

For
SUPPLIER, OPERATOR, COMPLIANCE, REGULATOR, EXECUTIVE, AUDITOR
Derived from
one sealed receipt, projected to the fields that role may see
Does NOT cover
A view is a SUBSET and never a summary — it removes fields and rewrites none. It carries its own digest, so a recipient can prove the copy came from the receipt; it cannot prove that the fields removed were unfavourable, and the register of what each role loses is the honest answer to that.

Does this run of receipts hang together

ON_DEMAND report.verifyLedger

Every report above is a function of a set of receipts, so the first question about any of them is whether that set is the set that was sealed.

What this report is, and is not

For
AUDITOR, COMPLIANCE
Derived from
the hash chain over the receipts supplied
Does NOT cover
It checks the CHAIN, not the individual receipts. A run can hang together perfectly and every receipt in it still fail `verify-receipt.js`, which is the separate and stronger test.

Is the service answering, and is anything stale

DAILY health.health

This product derives failure exhaustively and, until an app council graded it C+ for reliability, nothing watched the running service.

What this report is, and is not

For
OPERATOR
Derived from
the running process: registry age, revocation freshness, lease state
Does NOT cover
It reports the SERVICE, never a decision. A perfectly healthy service refusing everything and one admitting everything read identically here.

The refusal report, as a page a person reads

WEEKLY report.renderReport

The report is a data structure; this is the rendering a person is handed. It is a separate entry because it is a separate artefact with a separate reader, and because a rendering is where a true computation most easily acquires a false sentence.

What this report is, and is not

For
OPERATOR, EXECUTIVE
Derived from
the output of `refusalReport`, and nothing else
Does NOT cover
It renders what the report computed and adds nothing. If a figure is absent from the structure it is absent here — the rendering never fills a gap in, which is why a blank in this document is a blank in the evidence and not a formatting fault.

What recurring work ran, and what is overdue

DAILY scheduler.status

One job on this schedule matters more than the rest: re-issuing the signed actor registry. Revocation freshness runs from the registry’s own issue date, so a register that stops being re-issued floors every credential in it — quietly, and everywhere.

What this report is, and is not

For
OPERATOR, AUDITOR
Derived from
the schedule artefact and the last run of each job
Does NOT cover
It reports whether a job RAN, not whether what it produced was right. A registry re-issued on time with the wrong entries is on time.

Administrative acts

These are the things an operator DOES. Each one is a place somebody could reasonably expect to be able to change a decision, and none of them can — which is why every entry states what it cannot do, in terms, as a required field.

Admit an observer, and decide what its word is worth

keyring.signRegistry

A provenance class is granted from an observer identity. Enrolment is where that identity is established, and it is the only place.

Who, what, and what not

Who may
the operator, signing with the trust root
Produces
a new signed actor registry version, and a digest every later receipt names
CANNOT
It cannot raise the class of a record already captured, and it cannot make an organisation independent of a sale it is party to — registration proves identity and never confers independence.

Withdraw a key, and say from when

revocation.signRevocationList

A compromise has a DATE. Records signed before it stand and records signed after it do not, and only a stated effective instant can tell them apart.

Who, what, and what not

Who may
the operator, signing with the trust root
Produces
a signed revocation list carrying a sequence and a next-update-due instant
CANNOT
It cannot retrospectively invalidate a decision already sealed. It changes what is admissible NEXT; the earlier receipt says what was believed then, which is what a receipt is for.

Put a governance artefact in force

governance.loadGovernance

Authority limits, quorum sizes and acceptance windows are operator decisions, and an operator decision that nothing signed is a configuration file.

Who, what, and what not

Who may
the operator, signing with the trust root
Produces
a loaded, validated regime with a digest that every receipt decided under it names
CANNOT
It cannot get beneath a code floor. Quorum minimum, acceptance margin and re-ingest depth are clamped in code AND validated at load — both, since 30 August 2026, when the bundle path was found to skip the validators entirely and a top-tier decision released with zero signatures.

Publish a collection template, and classify what may be priced

template.loadTemplate

Which requirements may be waived is the most consequential thing an operator writes down, and taking it on the word of an unauthenticated author was the largest hole this mechanism has had.

Who, what, and what not

Who may
an author whose registry role the signed governance entitles
Produces
a verified template whose waivability classification decides what an acceptor may price at all
CANNOT
It cannot make a NEVER_WAIVABLE requirement priceable, and its verification cannot be declared — since 30 August 2026 it is membership of a module-private set, because a boolean on a caller-supplied object is the caller’s assertion.

Encode a regulation, with its citation and its source digest

instrument.loadInstrument

A rule an operator typed and a rule an authority published are different things, and only the second carries an authority, a citation and a digest of the document it came from.

Who, what, and what not

Who may
an entrant whose registry role the signed governance entitles
Produces
a signed instrument that composes strictest-wins with every other in force
CANNOT
It cannot RESOLVE a conflict with another authority. Two instruments that disagree are refused, never reconciled — picking one would be a program answering a question that belongs to counsel.

Price a gap that may be priced, and sign for it

acceptance.acceptRisk

A gate with no way to proceed is a gate people disable. This is the way to proceed, and it costs a signature and an authority.

Who, what, and what not

Who may
a person whose registry role carries authority for the exposure
Produces
a signed, expiring acceptance sealed onto the receipt with the gap still named
CANNOT
It cannot move a single measurement. The confidence, the bound claim and the gap are identical with and without it — it changes the disposition and nothing else — and it cannot price a gap the template classifies as never waivable.

Keep the registry fresh, on a schedule

scheduler.registryReissueJob

Revocation freshness runs from the registry’s issue date, so a registry nobody re-issues silently floors every credential in it.

Who, what, and what not

Who may
the operator, through a signing callback it supplies
Produces
a re-issued registry at a cadence, and an alarm when it is overdue
CANNOT
It cannot hold a private key. This codebase holds none; the job takes a callback, and a configuration carrying key material is refused by name rather than ignored.

Send a role-scoped copy when a rule matches

notify.defineRules

"Send compliance a copy when a shipment is refused" is a sentence every operations manager says, and in most systems it produces an email nobody can later prove was sent, containing a document nobody can prove matches the decision.

Who, what, and what not

Who may
the operator
Produces
a matched projection with its own digest, and a record that it was produced
CANNOT
It cannot widen what a role may see. The projection is `roleview`’s, so a notification cannot become a route around the scoping rules.

What this page does not cover

Read this before quoting the register

PaymentVerification · standalone install · one product · built by 27-console/build-console.js from the register, not typed.

This page loads nothing from another origin, makes no request at run time, and touches no browser storage. It works from a file on disk with no server.

Nothing in this console is legal advice.