Trust

The system supports the recall decision. A human owns it.

RecallOps is explicit about proof boundaries: live checks, captured room evidence, deterministic replay, dry runs, gated writes, and optional provider calls are labelled separately.

DETERMINISTICpacket digesta4a2fd3565b7d625...cb02ba893f487c04
GATEDHuman accountability

What this proves

The final action requires a named recall owner and approval reason.

What it does not prove

Agents recommend and prepare. They do not own the legal decision.

DETERMINISTICSource integrity

What this proves

Complaint, shipment, recovery, and receipt data can be recomputed into hashes.

What it does not prove

A digest proves packet integrity, not real-world product removal by itself.

GATEDSystem boundaries

What this proves

SAP, Oracle, regulator, provider, and identity paths disclose their current state.

What it does not prove

Customer tenant writes and real submissions remain authorization-gated.

Status language

Six labels keep the demo honest.

These labels prevent dry-runs, captures, and deterministic replay from being confused with production writes.

LIVE

Created against the currently deployed external service.

CAPTURED

Recorded from an earlier real external interaction.

DETERMINISTIC

Reproduced locally from sealed demo data.

DRY RUN

Payload generated but not written to a tenant.

GATED

Action requires authenticated human or admin authorization.

SIMULATED

Demonstration-only behavior.

Audit path

Start with the proof packet, then inspect raw controls only if needed.

The Trust Center explains the boundaries. The proof packet contains the digest, receipts, room references, and raw data.