Coming Soon

Authorization Receipts

The next evolution of Runtime Authority's evidence: not a database record you have to trust our systems to keep serving correctly, but a self-contained artifact you can verify on your own.

This page describes direction, not a shipped capability. Runtime Authority's decision engine and the Evidence Portal are live today; Authorization Receipts are how that evidence evolves. For the planned receipt shapes and lifecycle, see Authorization Receipts in the Developers section.

A signed database row is not a portable proof

Today, every Runtime Authority decision produces signed evidence inside the Evidence Portal. That proves a record wasn't altered after you were shown it. It doesn't, by itself, prove you were shown the complete and honest history -- verifying it still means trusting that PayReality's systems remain available, unchanged, and cooperative, indefinitely.

That's a reasonable trust model while an integration is live and the relationship is operational. It's a weaker one than a five-year-later regulatory review, an insurer underwriting risk without system access, or an enterprise proving compliance to its own auditors actually needs.

What we're designing toward

Portable by construction

A receipt is a self-contained artifact, not a database row. Verifying one won't require querying PayReality's live systems.

Cryptographic integrity

Every receipt is signed. Tampering with any field after issuance is detectable without trusting the platform that issued it.

Independent verification

The goal is a verifier who never has an operational relationship with PayReality -- an auditor, an insurer, a regulator -- being able to confirm a decision happened, honestly, on their own.

Minimal disclosure

A receipt should prove a decision was made correctly without necessarily exposing its sensitive content to every party who might one day need to confirm it happened.

Verification without an operational relationship

Regulators

Examining a decision years after the fact, without depending on PayReality remaining operational, unchanged, or cooperative.

Insurers

Assessing AI-operational risk from a portable artifact, without requiring operational access to a customer's PayReality tenant.

Enterprise customers

Proving to their own auditors and boards that a specific AI-initiated action was authorized under their governance -- without PayReality as a required intermediary.

What a receipt won't claim

An Authorization Receipt will prove that an action was authorized. It won't, and shouldn't, be read as proof that the action was actually carried out downstream -- that's a distinct problem from authorization, and this page won't pretend otherwise.

Building toward this and want early input?

If independent verification of AI authorization decisions matters to your compliance or risk function, we want to hear what "verified" needs to mean for you.