{
  "schemaVersion": "victoroff.snapshot-review-pack.v1",
  "classification": "synthetic",
  "status": "SAMPLE_NOT_CUSTOMER_ACCEPTED",
  "paymentId": "PAY-88219",
  "sourcePackage": "PAY-88219.json",
  "sourcePackageSha256": "d7c838785e2ddbc4f287192ce5e67ca5310aadbac5db02f61d22b6e3b73d71aa",
  "findings": [
    {
      "label": "Recorded state",
      "detail": "PAY-88219 is recorded as HOLD as of 2026-09-18T14:04:00Z.",
      "sourceIds": [
        "EVT-102"
      ]
    },
    {
      "label": "Trigger and policy",
      "detail": "Changed bank details triggered the policy's independent verification and human approval requirements.",
      "sourceIds": [
        "EVT-101",
        "POL-009"
      ]
    },
    {
      "label": "Hold authority",
      "detail": "The recorded payment is within the agent's delegated hold action, amount limit and currency.",
      "sourceIds": [
        "EVT-101",
        "AGT-007",
        "AUTH-014"
      ]
    },
    {
      "label": "Release authority",
      "detail": "The agent's delegation excludes release. A tool that can release payments does not grant permission to use it.",
      "sourceIds": [
        "AGT-007",
        "AUTH-014"
      ]
    },
    {
      "label": "Bank evidence",
      "detail": "Independent bank verification is missing or not established for this payment.",
      "sourceIds": [
        "EVD-202",
        "POL-009"
      ]
    },
    {
      "label": "Human approval",
      "detail": "The required Finance Controller approval is not established for this payment.",
      "sourceIds": [
        "APR-031",
        "POL-009"
      ]
    },
    {
      "label": "Invoice evidence",
      "detail": "The invoice matches. That is separate from bank verification and release approval.",
      "sourceIds": [
        "EVD-201",
        "POL-009"
      ]
    }
  ],
  "acceptanceCriteria": [
    {
      "id": "AC-01",
      "requirement": "Scope identifies one outcome, snapshot time and exclusions.",
      "sampleEvidence": "Report sections 01 and 02; snapshot metadata."
    },
    {
      "id": "AC-02",
      "requirement": "Every material finding cites supplied records; unsupported conclusions are labeled.",
      "sampleEvidence": "Source-linked findings in source package and sections 01\u201305."
    },
    {
      "id": "AC-03",
      "requirement": "All seven chain stages are populated or explicitly marked missing.",
      "sampleEvidence": "Report section 03 and result.chain."
    },
    {
      "id": "AC-04",
      "requirement": "Tool capability is separated from delegated authority.",
      "sampleEvidence": "AGT-007 and AUTH-014; release remains DENIED."
    },
    {
      "id": "AC-05",
      "requirement": "Missing evidence is not represented as proof an event never happened.",
      "sampleEvidence": "Scope limitation and evidence-gap register."
    },
    {
      "id": "AC-06",
      "requirement": "Each proposed next step states what evidence would close the gap.",
      "sampleEvidence": "Action register below; owners are proposed, not assigned."
    },
    {
      "id": "AC-07",
      "requirement": "A reviewer can inspect source IDs and reproduce the fixed demo result.",
      "sampleEvidence": "Source JSON plus public deterministic demo."
    },
    {
      "id": "AC-08",
      "requirement": "Delivery review, corrections and acceptance are recorded separately.",
      "sampleEvidence": "Not performed for a customer; synthetic sample only."
    }
  ],
  "actionRegister": [
    {
      "id": "GAP-01",
      "gap": "Independent bank verification not established",
      "sources": [
        "EVD-202",
        "POL-009"
      ],
      "proposedOwner": "Customer-designated bank-verification owner; confirm during scoping",
      "nextStep": "Obtain payment-linked independent verification through the agreed process.",
      "closureEvidence": "Verification record identifying payment, method, reviewer and time.",
      "status": "OPEN_IN_SYNTHETIC_SNAPSHOT"
    },
    {
      "id": "GAP-02",
      "gap": "Controller approval not established",
      "sources": [
        "APR-031",
        "POL-009"
      ],
      "proposedOwner": "Authorized Finance Controller in the synthetic policy",
      "nextStep": "Record the controller decision, including any conditions.",
      "closureEvidence": "Payment-linked decision with approver, time and applicable authority.",
      "status": "OPEN_IN_SYNTHETIC_SNAPSHOT"
    },
    {
      "id": "GAP-03",
      "gap": "Production enforcement behavior not demonstrated",
      "sources": [
        "AGT-007",
        "AUTH-014"
      ],
      "proposedOwner": "Customer-designated system owner; not appointed by this report",
      "nextStep": "Scope a separate authorized test of denied release attempts.",
      "closureEvidence": "Approved test plan and system-side execution evidence.",
      "status": "NOT_TESTED"
    }
  ],
  "customerAcceptance": {
    "status": "NOT_PERFORMED",
    "deliveryOwner": null,
    "reviewer": null,
    "acceptedAt": null
  },
  "limitations": [
    "No real payment system accessed.",
    "No independent authentication of fictional provenance.",
    "No customer completion, production enforcement, certification or financial result established."
  ]
}
