LensReading which lens this session carries.

Auditor evidence pack

Expense report at policy check

Administration · Travel & Expense · line AD3A · Trip Request to Booking. This pack names every action taken on this unit, who or what took it, the authority that permitted it, and the model, prompt and policy versions in force at that moment.

Chain verified

Every record links to the one before it and hashes to its stored value. 2 records were re-hashed on this page load, in order, starting from the genesis value. Nothing was read from a cached verdict.

hash = sha256(prevHash + "|" + JSON{seq, unitRef, actor, action, outcome, occurredAt})

Records
2
Append-only, sequenced
Agent actions
2
Taken by software
Human actions
0
Taken by a named person
Refusals
0
Blocked by the authority register
Corrections
0
Later record supersedes an earlier one
Legal hold
Held
HOLD-004

The unit

What the work was, and where it sits

Reference
AD3A-1014
Subject
Zara Voss
Requested by
Daniel Novak
Value
$81k
Materiality
medium
Currently held by
S2P spine (gbs)
Sub-function owner
Director, Travel & Expense
Orchestrator
Travel & Expense Orchestrator

Every action, in order

Actor, authority, versions in force, and the hash link to the record before it

1
Policy Check AgentpolicyCleared

Cleared request

2026-08-18 07:51:00ZAuthority AD3-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A2Retention OPS-3YLegal hold HOLD-004
Prompt
gate-approval@p8
Policy
materiality-bands@v9
Tools
read-only-lookup@t12
in 2bb3f6aa...8c3b45out c79a6b48...8271ccartifact ART-AD3A-1002-1 genesis 55336275...d45a0d
2
Traveler Duty-of-Care AgentgbsIn progress

Holding at policy check

2026-08-18 08:25:00ZAuthority AD3-AUTH-A1 · cap $250,000Jurisdiction SGAutonomy A4Retention OPS-3YLegal hold HOLD-004
Prompt
task-execution@p21
Policy
materiality-bands@v9
Tools
ledger-write@t7, document-fetch@t9
in 96b6fdab...433649out 5ae72009...ee1767artifact ART-AD3A-1002-2 55336275...d45a0d fb1c5e95...a250d5

Authority relied on

Who was allowed to do this, up to what value, in which jurisdictions

AD3-AUTH-A1ActiveTravel & Expense Orchestrator

Any unit on a travel & expense line where every intake check passed, the policy in force is current, and the value sits inside the cap below.

Cap $250,000US · UK · DE · SG · AU · FR · BRDelegated from Director, Travel & ExpenseExpires 2026-09-30

Versions in force

Exactly what was running when these actions were taken

KindIdentifierVersionStatusOwner
modelreasoner-core5.4currentPlatform model council
modelextract-lite2.9currentPlatform model council
policymateriality-bandsv9currentGroup controller
promptgate-approvalp8currentGovernance office
prompttask-executionp21currentShared service engineering
toolsetledger-writet7currentFinance systems
toolsetread-only-lookupt12currentPlatform engineering
toolsetdocument-fetcht9currentShared service engineering

Gates on this line

The control points this unit had to clear

Approve
Held for a named human when the unit exceeds the expense report decision envelope, when confidence falls below the floor, or when a policy clause is engaged.
Approver: Director, Travel & Expense · not reached

Records schedule and holds

How long this evidence must be kept, and whether it is frozen

OPS-3Y3 years
Operational routing and execution
Internal operating requirement. No statutory driver, so the shortest defensible period is used deliberately.
Deleted at three years. This is the only class where the estate deletes rather than retains by default.
HOLD-004active
Internal investigation — expense approvals
A pattern of approvals just under a materiality threshold was flagged by the observe layer and is being examined. The hold covers the approving authority records as well as the transactions.
Custodian Head of Internal Investigations · requested by Audit committee

What this pack proves, and what it does not

Read this before you rely on it

It does prove
  • Every action carries a named actor, an actor kind, and a timestamp.
  • Every action names the authority grant that permitted it and the cap that grant carries.
  • Every action stamps the model, prompt, policy and tool versions in force at that moment.
  • Corrections are additive. A later record supersedes an earlier one and says why; the earlier record is never edited or deleted.
  • The chain is re-hashed live on this page, so a single altered field is detected immediately.
It does not prove
  • It is not tamper-proof against an attacker with write access to the store, who could rewrite the whole chain from genesis. Making that impossible requires publishing chain tips to a store this application cannot write to. That anchor is not built, and this page does not claim it.
  • The evidence in this demonstration is modeled from a simulated estate, not captured from production systems.
  • Identity here is the actor name recorded on the action. Cryptographic agent identity and signed attestation are a separate piece of work.