An agent saying “done” is not proof.
A Receipt preserves one governed action. Connector-executed actions bind approval, write, destination read-back and verification result. A Recovery Record carries the complete commercial result and all of its Receipts. The Value Ledger records what that result is worth.
Effective and last reviewed: 16 July 2026
Every action stays inspectable. Every connector change gets checked.
Every governed action keeps its evidence references, authority, owner and completion state. Connector-executed actions also bind the external write, destination-system read-back and verification result. Human work keeps the accountable owner, reported completion and supporting record without being presented as a verified system change.
What a Receipt captures
Approved action
The exact target, payload and result the action was authorized to pursue.
Evidence
Which records, artifacts, and provenance labels supported the decision.
Authority
The permissions, policy, responsible role and exact approval behind the action.
Action
What an agent executed or what an accountable person was assigned and reported complete.
System state
For connector execution: the before state, destination-system response, read-back and verification result.
Verification result
For connector execution: whether the observed destination state matched the exact approved action.
Receipt anatomy
| Field | Meaning |
|---|---|
| Receipt ID / Work Object ID | Stable references for the proof record and governed unit of work. |
| Intent and human owner | What was requested and who remains accountable. |
| Charter and policy version | The authority and control rules applied to the action. |
| Source scope and evidence references | What SupraOS was permitted to use and which evidence supported the run. |
| Approval event | Who approved the reviewed action, when, and under which context. |
| Actor and execution context | Human, agent, system, connector, model, tool, or runtime context relevant to the action. |
| Before state and executed action | The intended change and the state known before execution. |
| Destination-system response and read-back | For connector execution, the destination response and resulting state read back after the write. |
| Completion or verification status | Connector-verified, partially verified, failed, pending, human-completed or held. |
| Recovery Record link | The commercial result this action advanced and the other Receipts attached to it. |
| Timestamp and integrity metadata | When the event occurred and the metadata used to detect later alteration. |
Verification statuses
Verified
A connector read-back shows that the destination state matches the intended, approved result.
Partially verified
Some required result can be confirmed, but the complete target state is not yet proven.
Failed or mismatched
The connector, destination state, or verification check did not confirm the intended result.
Pending
Execution or verification is incomplete.
Human-completed
A responsible person reports the required step complete and attaches the supporting record. This is recorded human completion, not a connector-verified system change.
Held
SupraOS holds the action until the required authority, evidence and policy conditions are complete.
Share the proof. Keep source data protected.
Receipts surface the proof each reviewer needs while sensitive source data remains inside customer controls.