Open your application
Two things decide what you see: which application you are in, and who you are. Pick both and this shows you exactly what you will land on.
Which application
Five applications, one engine. Each answers a different question, and each is entered separately.
Who is at the keyboard
Your role decides which of an application's pages you are shown, what you may sign for, which copy of a record you receive, and what you are told when an answer changes. It is one choice with four consequences, and they are all derived from the same registers the engine uses.
| Role | What they do | May sign up to | Pages |
|---|---|---|---|
| Line | Receives goods, files what arrived, and acts on the answer. | signs nothing | 6 of 15 |
| Supervisor | Runs the shift, chases what is missing, signs for small exposures. | $10,000 as SUPERVISOR | 6 of 15 |
| Manager | Owns the commercial decision and may author a standard. | $250,000 as MANAGER | 9 of 15 |
| Administrator | Administers one installation: imports or builds the rule set, sets the gating and scoring parameters, and manages users downline in their own chain. | $5,000,000 as DIRECTOR | 13 of 15 |
| Suite administrator | Holds the trust root for the installation. Issues the first credential to each application administrator, who then issues downline. Runs revocation and root rotation. THE CUSTOMER HOLDS THIS ROLE — D-24, decided 31 August 2026. | signs nothing | 15 of 15 |
The suite administrator signs nothing, and that is deliberate. Issuing credentials and approving releases are different powers: one identity holding both is one lost key away from doing both, and the resulting record would look perfectly correct.
What you will see when you go in
Every combination is listed below. Choose an application and a role above and this narrows to one.
Corobate
Stock Risk Receipt
AttestedAssets
PaymentVerification
TellmeTiresias
What this filter is, and what it is not
It chooses what you are shown. It does not stop anyone opening anything.
These pages are files on a web host. A file that has been published can be fetched by anyone who knows its address — that is true of every static site and it is true of this one. We are not going to tell you otherwise.
So what actually protects anything?
Your key does. Looking at a page costs nothing and changes nothing. Every act that matters — accepting a document as evidence, writing the standard, signing off a release that is short of one — needs a signature, and the signature is checked against a register your own organisation signed. Anything else is refused, by name, with the reason on the record.
So somebody who opens a page they were not meant to see can read it, and can do nothing with it. The filter is a convenience — it stops a person on a loading dock being handed a compliance report they did not want. The control is the key.
Where the keys come from
Your organisation holds the root. One person — the suite administrator — issues the first credential to whoever administers each application, and they issue onward down their own chain. We do not hold it, and this software cannot: nothing in it stores a private key, and anything that needs signing asks you.
That is not a policy we could quietly change. It is why the records keep checking out after you stop paying us, and why a counterparty can re-check one without asking either of us.
The applications come from the product register, the roles from the persona map, and the pages each role sees from the console's own page register. Nothing on this page is typed.
This page loads nothing from another origin and makes no request at run time. It works from a file on disk with no server.
Nothing here is legal advice.