One chronological proof
Every value below comes from the deterministic fictional fixture.
1. A concrete blocker
A public reward exists, but its currency, payout rail, timing, tax/identity categories, and current written terms are incomplete. An autonomous worker should not start blindly.
Fixture sources: example.org/reward · example.org/contact — reserved example-domain placeholders
2. One bounded inquiry
The destination is displayed only as +12****0147. The fixture uses the NANP-reserved 202-555-0147 range.
- Payout currency
- Payout rail
- Payout timing
- Identity or tax step categories
- Written terms location
3. Deterministic custody
The same owner-reviewed packet always produces the same control identifiers.
packet_hash bade77a79b653473…f9747f7b idempotency payoutproof-bade77a79b653473c3a01bd2 approval_id approve-bade77a79b653473 max_calls 1 recurrence false
4. Live starts fail closed
The evaluator attempts a start without live enablement. The production gate stops before the CALL-E runner or any network side effect.
Unauthorized start: live calls disabled; set PAYOUTPROOF_ENABLE_LIVE=1 only after exact authorization CALL-E runner invoked: false
5. A smaller result
A clearly labeled synthetic result passes through the production normalizer. Raw transcript, provider summary, and full phone are discarded.
{
"status": "COMPLETED",
"terminal": true,
"masked_phone": "+12****0147",
"written_source_required": true,
"contractual_verification": false
}6. Why the boundary matters
Impact: avoid work with unusable payout logistics. Idea: turn one narrow phone interaction into a permissioned evidence checkpoint. Implementation: strict validation, hashes, idempotency, dual live gate, and allowlisted output. Experience: one path from incomplete terms to a written-source-required verdict.
Verification you can reproduce
No account or secret is needed for the local judge path.
npm cinpm run judge