What one piece of work leaves behind: purpose, sources, what was released and to which destination, what stayed private, what was committed, and what the source system confirmed.
Updated July 2026
Every completed piece of work leaves a record of what was authorized, what was consulted, what crossed the boundary, what was done, and what the source systems confirmed. It is produced by doing the work rather than assembled afterwards, and it is deliberately incomplete in one respect: it proves what Proxara emitted, not what a third party later retained.
| Question | Recorded |
|---|---|
| Who asked | The employee, application or agent, and the firm |
| Under what authority | The approved kind of work, the purpose, and the authority revision in force |
| What was consulted | Each source capability, and the provider revision read |
| What was connected | Which records were correlated, and which were deliberately kept separate |
| What was worked out locally | Derivations, calculations and classifications made inside the firm |
| What was released | Which claims went to which destination and processor |
| What did not leave | What stayed private, and what was omitted, with the reason |
| What the model proposed | The typed proposal, and whether it was allowed or refused |
| Which targets were bound | The real client, record and recipient resolved inside the firm |
| What intervention occurred | The consequence decision, the approver, and why it was required |
| What was attempted | Each provider call, in order |
| What was observed | The authoritative state read back from each provider |
| What remains | Repairs completed, and anything still unresolved |
| How it ended | The exact terminal state |
It carries counts, categories, states, digests, revisions and references rather than client content or client names. An examiner projection, a partner view, an employee's own history and a cryptographic verifier need different fields, and each receives only its own.
Opening the record does not reveal the work's clear material. That lives in the private workspace, under the same authority as the work itself.
Each thing the work produces is retained as a class with a purpose, an owner, an expiry and a method of erasure.
| Class | Held for | Ended by |
|---|---|---|
| Working copies of source material | The active piece of work and its verification | Deletion on expiry |
| Stand-in mappings | Multi-turn work, target binding, recovery, verification and repair | Cryptographic erasure at expiry |
| Private artifacts and their revisions | Review, revision and repair | Deletion under the firm's retention setting |
| Effect and observation history | Proving and repairing real changes | The firm's records policy |
| Content-minimized evidence | The firm's supervisory and examination needs | The firm's records policy |
Mappings needed for recovery and repair are durably encrypted with explicit expiry and least-privilege access. Volatile memory is a cache, never the authority. A single fixed lifetime applied to every class belongs to a demonstration configuration rather than to the product.
A signature makes the record tamper-evident and independently verifiable. It does not turn a guessed outcome into a verified effect, and it is not compliance.
The record is also honest about its edge. It proves what Proxara sent, to which endpoint, under which policy, and what each provider confirmed afterwards. What an external model retained or inferred beyond that is governed by the contract with that processor, and the record does not claim to observe it.
It exists because the work happened, not as a separate task anyone performs. A firm that has to do extra clerical work to produce evidence has a reporting product rather than a work product.
| To understand | Read |
|---|---|
| What authorized the work in the first place | Approved work |
| How an effect is confirmed | Execution and verification |
| The review path for a security owner | The Connect security review |
| How access ends, on either side | Ending access |