What this proves
The final action requires a named recall owner and approval reason.
What it does not prove
Agents recommend and prepare. They do not own the legal decision.
Trust
RecallOps is explicit about proof boundaries: live checks, captured room evidence, deterministic replay, dry runs, gated writes, and optional provider calls are labelled separately.
a4a2fd3565b7d625...cb02ba893f487c04The final action requires a named recall owner and approval reason.
Agents recommend and prepare. They do not own the legal decision.
Complaint, shipment, recovery, and receipt data can be recomputed into hashes.
A digest proves packet integrity, not real-world product removal by itself.
SAP, Oracle, regulator, provider, and identity paths disclose their current state.
Customer tenant writes and real submissions remain authorization-gated.
Status language
These labels prevent dry-runs, captures, and deterministic replay from being confused with production writes.
Created against the currently deployed external service.
Recorded from an earlier real external interaction.
Reproduced locally from sealed demo data.
Payload generated but not written to a tenant.
Action requires authenticated human or admin authorization.
Demonstration-only behavior.
Audit path
The Trust Center explains the boundaries. The proof packet contains the digest, receipts, room references, and raw data.