Skip to content
Compliance, finance & operations

Compliance, finance & operations

Domain analyses and remediation routing. ComplianceService, FinanceService and OperationsService each ask the sovereign model plane to assess one domain, and all three return the same status, violations and audit-trail shape. ComplianceService also holds the operator-owned half of a remediation: who an order is addressed to, whether it was approved, and the standing routing table by finding category.

This page also defines the evidence-document types (citations, facts, findings, deadlines and seals) that remediation orders and twin action cards share.

Summary

ServiceRPCKindPurpose
ComplianceServiceAnalyzeComplianceUnaryCompliance status, violations and audit trail
ComplianceServiceAssignRemediationUnaryAddress one remediation order
ComplianceServiceDecideRemediationUnaryRecord the human decision on one order
ComplianceServiceListRemediationRoutesUnaryList the routing table
ComplianceServiceSetRemediationRouteUnaryRoute a finding category to a department
ComplianceServiceDeleteRemediationRouteUnaryRemove a category’s route
FinanceServiceAnalyzeFinanceUnaryFinancial posture findings
OperationsServiceAnalyzeOperationsUnaryOperational health and risk findings

What an analysis reads

None of the three analyses reads a live data source. FACE has no mapping from a domain to one of the tenant’s connections and tables. The verdict rests only on the system_context you send and on the instance’s own configuration. Every response from the current server says so in live_data_note. To ground an analysis, put the relevant facts in system_context.

A model failure is not reported as a pass. When the model returns nothing usable, the status is Unable to Assess, with a spoken_response that says it is not a finding of compliance.

ComplianceService

Full name semantics.v1.ComplianceService.

AnalyzeCompliance

rpc AnalyzeCompliance(AnalyzeComplianceRequest) returns (AnalyzeComplianceResponse);
  • Kind: Unary.
  • Auth: Bearer session.
  • Errors: UNKNOWN if the compliance agent’s template cannot be loaded. Model problems are not errors: when the model plane is not configured, times out, or returns an empty or unparseable answer, the response has compliance_status: "Unable to Assess" and no violations.

The compliance agent is given the instance’s environment, the observed audit-logging behaviour, operator-declared settings (labelled as declarations, not evidence), and system_context. The model call has a time budget, 15 seconds by default.

Request: AnalyzeComplianceRequest

Shared by all three analysis RPCs.

FieldTypeDescription
system_contextstringAdditional context for the analysis, appended to the system state. This is the only caller-supplied evidence the analysis sees.

Response: AnalyzeComplianceResponse

Shared by all three analysis RPCs.

FieldTypeDescription
compliance_statusstringPass, Warning, Fail, or Unable to Assess when no assessment was produced. Other values come verbatim from the model.
violationsrepeated ComplianceViolationFindings, each in one sentence.
audit_trailrepeated ComplianceAuditTrailSystems checked and their status.
spoken_responsestringA spoken-style summary. On Unable to Assess it says why.
ordersrepeated RemediationOrderThe dispatchable form of the findings, one per violation. The current server derives no orders, so this list is empty.
live_data_notestringThe server’s sentence about which live data the analysis read. Currently it always says that none was read. Empty only from an older server.

AssignRemediation

rpc AssignRemediation(AssignRemediationRequest) returns (AssignRemediationResponse);
  • Kind: Unary.
  • Auth: Bearer session. The author is the verified session subject.
  • Errors: INVALID_ARGUMENT if order_id or assignment is missing, or the assignment names no department, service provider or contact. UNAUTHENTICATED if the session has no subject. FAILED_PRECONDITION if no remediation order has ever been derived on this instance. NOT_FOUND if the order id is unknown. INTERNAL if the assignment cannot be stored.

Addresses one order. Assignments are stored separately from the analysis, so they survive the next derivation. The author fields in the request are ignored and set by the server. Because the current server derives no orders, this RPC returns FAILED_PRECONDITION until orders exist.

Request: AssignRemediationRequest

FieldTypeDescription
order_idstringRequired. RemediationOrder.id.
assignmentRemediationAssignmentRequired. department, service_provider and contact are read. At least one must be set. Author fields are ignored.

Response: AssignRemediationResponse

FieldTypeDescription
assignmentRemediationAssignmentThe stored assignment, with the server’s author and timestamp. Display this, not your draft.

DecideRemediation

rpc DecideRemediation(DecideRemediationRequest) returns (DecideRemediationResponse);
  • Kind: Unary.
  • Auth: Bearer session. The decider is the verified session subject.
  • Errors: INVALID_ARGUMENT if order_id or dispatch is missing, or dispatch.state is empty or not one of DRAFT, APPROVED, REJECTED, SENT. UNAUTHENTICATED, FAILED_PRECONDITION, NOT_FOUND and INTERNAL as for AssignRemediation.

Records the human decision on one order. FACE sends nothing itself. SENT records that a person dispatched the order outside the platform.

Request: DecideRemediationRequest

FieldTypeDescription
order_idstringRequired. RemediationOrder.id.
dispatchRemediationDispatchRequired. state is required. note and channel are stored. Author fields are ignored.

Response: DecideRemediationResponse

FieldTypeDescription
dispatchRemediationDispatchThe stored decision, with the server’s author and timestamp.

ListRemediationRoutes

rpc ListRemediationRoutes(ListRemediationRoutesRequest) returns (ListRemediationRoutesResponse);
  • Kind: Unary.
  • Auth: Bearer session.
  • Errors: INTERNAL if the stored routing table is unreadable. While it is unreadable, every category reads as unrouted and new routes are refused.

Request: ListRemediationRoutesRequest

No fields.

Response: ListRemediationRoutesResponse

FieldTypeDescription
routesrepeated RemediationRouteEvery route, by category, ascending.

SetRemediationRoute

rpc SetRemediationRoute(SetRemediationRouteRequest) returns (SetRemediationRouteResponse);
  • Kind: Unary.
  • Auth: Bearer session. The author is the verified session subject.
  • Errors: INVALID_ARGUMENT if route is missing, route.category is empty, or the route names neither a department nor a contact. UNAUTHENTICATED if the session has no subject. INTERNAL if the route cannot be stored.

Creates or replaces the route for one category. The category is matched exactly against a finding’s category. It is not a prefix or a pattern. Orders addressed through a route carry assignment.basis = OPERATOR_ROUTING_RULE, which is distinct from an order someone assigned individually.

Request: SetRemediationRouteRequest

FieldTypeDescription
routeRemediationRouteRequired. category plus a department or contact. Author fields are ignored.

Response: SetRemediationRouteResponse

FieldTypeDescription
routeRemediationRouteAs stored, with the server’s author and time.

DeleteRemediationRoute

rpc DeleteRemediationRoute(DeleteRemediationRouteRequest) returns (DeleteRemediationRouteResponse);
  • Kind: Unary.
  • Auth: Bearer session.
  • Errors: INVALID_ARGUMENT if category is empty. UNAUTHENTICATED if the session has no subject. INTERNAL if the route cannot be removed.

Deleting a category that has no route is not an error.

Request: DeleteRemediationRouteRequest

FieldTypeDescription
categorystringRequired. The category whose route to remove.

Response: DeleteRemediationRouteResponse

FieldTypeDescription
deletedboolWhether a route for that category existed.

FinanceService

Full name semantics.v1.FinanceService.

AnalyzeFinance

rpc AnalyzeFinance(AnalyzeComplianceRequest) returns (AnalyzeComplianceResponse);
  • Kind: Unary.
  • Auth: Bearer session.
  • Errors: FAILED_PRECONDITION if no model plane is configured on the instance. UNAVAILABLE if the model plane does not answer. An empty, unparseable or empty-but-parseable answer returns compliance_status: "Unable to Assess".

Assesses the financial posture of the system state and system_context. Uses AnalyzeComplianceRequest and AnalyzeComplianceResponse. Findings arrive as violations.

OperationsService

Full name semantics.v1.OperationsService.

AnalyzeOperations

rpc AnalyzeOperations(AnalyzeComplianceRequest) returns (AnalyzeComplianceResponse);

Assesses operational health and risk. The request and response are the same as for AnalyzeFinance.

Messages

ComplianceViolation

FieldTypeDescription
categorystringArea of the finding. Remediation routes match on this exactly.
severitystringSeverity, as the finding states it.
descriptionstringThe finding in one sentence.
related_rule_idstringThe rule the finding relates to, if any.
remediationstringSuggested remediation.

ComplianceAuditTrail

FieldTypeDescription
system_namestringSystem checked.
statusstringIts status.
last_checkedstringWhen it was checked, as reported.

RemediationOrder

A dispatchable remediation: what to do, to what specification, by whom, and the record behind every figure. Every value in a step’s specification is cited, and a step that would need an unmeasured figure is not emitted. A deadline appears only when a contract clause, SLA or statute in the data supplies it.

FieldTypeDescription
idstringStable within an analysis: the rule id plus the subject, so assignments and decisions survive the next derivation.
related_rule_idstringThe rule behind the finding.
categorystringThe finding’s category.
severitystringCRITICAL, HIGH, MEDIUM or LOW, as the finding stated.
subject_idstringWhat the order is about: a carrier, a column, a PO.
summarystringThe violation’s own sentence, unchanged.
assignmentRemediationAssignmentWho it is addressed to.
stepsrepeated RemediationStepThe procedure, in order.
specificationsrepeated DocumentFactWhat the records say.
citationsrepeated CitationWhere every figure came from.
deadlinesrepeated DocumentDeadlineDeadlines with a cited authority.
determinationsrepeated DocumentFindingFindings as codes.
narrativeDocumentNarrativeProse over the frozen fields.
dispatchRemediationDispatchThe operator’s decision. Unset means nobody has decided. That is not a rejection, so display it as neither approved nor refused.
sealDocumentSealSet at approval, never at derivation.

RemediationStep

FieldTypeDescription
ordinalint321-based position.
instructionstringWhat to do, in the imperative, naming values.
performed_bystringThe role that performs it, when a record says so. Otherwise empty, never a guess.
citation_idsrepeated stringCitations for any figure the step names.
specificationmap<string, string>The specification to carry the step out to. Keys are stable codes, values are as read.
verificationstringHow to check that it worked, against the same source.

RemediationAssignment

FieldTypeDescription
departmentstringA department in your organisation. Only an operator sets it: FACE has no org chart.
service_providerstringAn external provider, such as the carrier the finding is about. May be derived from a record.
contactstringEmail or desk, only when an operator supplied one.
basisstringDERIVED_FROM_RECORD, OPERATOR_ASSIGNED, OPERATOR_ROUTING_RULE or NOT_ROUTED. NOT_ROUTED is the default. Display it as unrouted rather than hiding the block.
assigned_bystringThe verified subject, when operator-assigned. Server-set.
assigned_at_unixint64When it was assigned. Server-set.
citation_idsrepeated stringCitations for a provider derived from a record.

RemediationDispatch

FieldTypeDescription
statestringDRAFT, APPROVED, REJECTED or SENT. An empty string means no decision, which is a fourth state and not a synonym for DRAFT.
decided_bystringThe verified subject. Server-set.
decided_at_unixint64When it was decided. Server-set.
notestringWhy, in the decider’s words.
channelstringHow a SENT order left. Empty means the sending was not recorded.

RemediationRoute

FieldTypeDescription
categorystringA finding category, matched exactly.
departmentstringDepartment the category is routed to.
contactstringContact for the category.
set_bystringThe verified subject. Server-set.
set_at_unixint64When it was set. Server-set.

Evidence-document types

Remediation orders and twin action cards share these types. The platform’s rule is that everything except a narrative is determination: fixed arithmetic over cited records, never a model. A model may write only the narrative, and only from fields that are already frozen.

EvidenceDocument

A document a third party acts on, such as an adjuster, a carrier’s claims desk or a court. It assembles the file, shows what was read and proposes a next step. It does not underwrite, bind, settle or satisfy an obligation on anyone’s behalf.

FieldTypeDescription
kindEvidenceDocumentKindDocument kind.
subject_idstringYour own identifier for the subject: a shipment, claim or customs entry. Also the chain key for the seal.
referencestringThe document’s own reference, where one exists.
counterpartystringWho it is addressed to, or who owes.
factsrepeated DocumentFactWhat the records say.
findingsrepeated DocumentFindingWhat was determined, as codes.
citationsrepeated CitationWhere each figure came from.
deadlinesrepeated DocumentDeadlineComputed deadlines.
claimed_amountoptional doubleWhat the document asks for. Absent means not determined. See absent.
exposure_amountoptional doubleValue at risk, not yet lost.
units_shortoptional int32Units short.
units_damagedoptional int32Units damaged.
absentrepeated AbsentFigureWhy a figure is absent, when it is.
narrativeDocumentNarrativeExpression over the frozen fields.
sealDocumentSealSet at approval. Unset on a pending card is correct.

Citation

FieldTypeDescription
idstringCitation id, for example C1, referenced by facts, findings and narrative.
source_kindstringRecord kind, for example bol, invoice, po or reefer_reading.
source_idstringThe record’s id in your own system.
fieldstringWhich field of the record.
valuestringThe value as read, verbatim.
connection_idstringConnection it was read through.
lineage_record_idstringThe lineage record of the extraction that read it, so the citation can be audited.
observed_atint64When it was observed, from the lineage record.
perceptionPerceptionSet only when a model read the value off a scanned document. Absent means a structured record.

Perception

FieldTypeDescription
outcomePerceptionOutcomeHow the reading went.
confidencedoubleThe model’s own confidence. Never used as a truth threshold.
modelstringThe model that read it.
page_refstringWhere on the document.

DocumentFact

FieldTypeDescription
label_codestringStable label code, for example FACT_BOL_QUANTITY. The client composes the label.
valuestringAs read, or as computed.
citation_idsrepeated stringNever empty.

DocumentFinding

FieldTypeDescription
codestringStable code, for example OSD_SHORT, OSD_DAMAGED, RATECON_ACCESSORIAL_UNSUPPORTED or SLA_BREACH_CONFIRMED. Render nothing for an unknown code, never the raw token.
severitystringCRITICAL, MAJOR, MINOR or INFO.
citation_idsrepeated stringNever empty.
operandsmap<string, string>The numbers the code declares.

DocumentDeadline

A date computed from a record date by a named rule. It is an input for a person entitled to act, not advice. There is no “days remaining” field: compute it from due_unix when you render.

FieldTypeDescription
rulestringFor example CARMACK_NOTICE_9M, CARMACK_SUIT_2Y1D, COGSA_SUIT_1Y or CONTRACT_<clause>.
authoritystringThe cited authority, for example 49 U.S.C. § 14706(e).
basisstringdelivery, should-have-been-delivered or disallowance.
from_unixint64Start date.
from_citation_idstringThe record that supplied the start date.
due_unixint64Due date.

AbsentFigure

FieldTypeDescription
figurestringThe figure’s field name, for example claimed_amount.
reasonstringNO_BACKING_RECORD, NOT_STATED_ON_DOCUMENT, ILLEGIBLE, EXTRACTION_FAILED or NOT_YET_DETERMINABLE.

DocumentNarrative

FieldTypeDescription
bodystringThe prose.
authored_bystringdeterministic-template, or the model id.
figure_idsrepeated stringCitation ids of every figure the body mentions.

DocumentSeal

FieldTypeDescription
algorithmstringFor example sha256-chain-v1.
content_hashstringHash over the document’s canonical content.
prev_hashstringThe previous seal for the same subject_id.
sealed_atint64When it was sealed.
signaturestringDetached signature, when a signing key is configured.
key_idstringSigning key id.

Enums

EvidenceDocumentKind

ValueMeaning
EVIDENCE_DOCUMENT_KIND_UNSPECIFIEDNot set.
EVIDENCE_DOCUMENT_KIND_STATEMENT_OF_POSITIONParalegal and claims recovery.
EVIDENCE_DOCUMENT_KIND_OSD_REPORTOver, short and damaged report.
EVIDENCE_DOCUMENT_KIND_NOTICE_OF_INTENT_TO_CLAIMNotice of intent to claim.
EVIDENCE_DOCUMENT_KIND_SUBROGATION_DEMANDSubrogation demand.
EVIDENCE_DOCUMENT_KIND_FNOLFirst notice of loss (cargo insurance).
EVIDENCE_DOCUMENT_KIND_CARGO_LOSS_SURVEYCargo loss survey.
EVIDENCE_DOCUMENT_KIND_WARRANTY_COMPLIANCE_AUDITWarranty compliance audit.
EVIDENCE_DOCUMENT_KIND_PRE_DEPARTURE_RISK_BINDINGNot built. Pricing risk needs a rating basis, loss history and appetite that the platform does not hold. Never emitted.
EVIDENCE_DOCUMENT_KIND_CLAUSED_EBOLNot built. No source carries the driver or receiver remarks that make up the clausing. Never emitted.
EVIDENCE_DOCUMENT_KIND_RATE_CON_ACCESSORIAL_AUDITRate confirmation accessorial audit.
EVIDENCE_DOCUMENT_KIND_MSA_SLA_COMPLIANCE_AUDITMSA / SLA compliance audit.
EVIDENCE_DOCUMENT_KIND_TEMPERATURE_EXCURSIONCold-chain temperature excursion.
EVIDENCE_DOCUMENT_KIND_CHAIN_OF_CUSTODY_AUDITChain-of-custody audit.
EVIDENCE_DOCUMENT_KIND_CUSTOMS_MANIFEST_EXCEPTIONCustoms manifest exception.
EVIDENCE_DOCUMENT_KIND_PROCEDURE_DEVIATION_LOGNot built. A deviation log needs the customer’s written procedures, which no source carries. Never emitted.
EVIDENCE_DOCUMENT_KIND_RETURN_DISPOSITIONDisposition of a returned unit. Never invents a return identifier.
EVIDENCE_DOCUMENT_KIND_SERVICE_DISRUPTIONA service disruption stated by your own records, with the dwell counted from them.
EVIDENCE_DOCUMENT_KIND_EQUIPMENT_LIMIT_APPROACHA channel trending towards a limit the feed itself states. A linear trend, not a prediction.

A client that meets an unknown kind should render the generic document shell, never the raw token.

PerceptionOutcome

ValueMeaning
PERCEPTION_OUTCOME_UNSPECIFIEDNot set.
PERCEPTION_OUTCOME_READThe value was read.
PERCEPTION_OUTCOME_NOT_PRESENT_ON_DOCUMENTThe document does not carry the value.
PERCEPTION_OUTCOME_ILLEGIBLEThe value is present but illegible.
PERCEPTION_OUTCOME_EXTRACTION_FAILEDExtraction failed.