Forge template
Verified business desk
A mock credential desk. Evidence stays off the ledger. The verifier sees status, not the file.
Start from a reviewed template, not a random repository.
Adapters in this template
- Organisation tenancy
Running in a demo
The verified-business desk holds several synthetic organisations side by side. They are labels, not tenants in a database.
- Organisation profile
Running in a demo
A synthetic organisation has a subject id and a lifecycle status. Nothing is a real company check.
- Ownership note
Running in a demo
A restricted field names synthetic controllers. The verifier does not see it.
- Evidence redaction
Running in a demo
Evidence is a label on the application. The mock ledger does not store it, and the verifier cannot read it.
- Credential issue
Running in a demo
An analyst can issue a mock credential after review. Issuance is a status change in the browser.
- Credential status
Running in a demo
A verifier checks status only: issued, flagged, or revoked.
- Issuance pause
Running in a demo
An admin pause stops new mock credentials and flags ones already issued.
- Case review
Running in a demo
The analyst accepts, rejects, or sends the synthetic application back for evidence.
- Role access
Running in a demo
Each desk has named roles. A restricted field is hidden from the role that should not see it.
- Audit log
Running in a demo
Each transition appends an event the auditor can read. The digest is a label, not a cryptographic hash.
- State machine
Running in a demo
A record only moves along the transitions defined for its desk.
- Synthetic records
Running in a demo
Every desk starts from invented organisations, invoices, and assets. Reset restores that seed.
- Demo fence
Running in a demo
Every running desk states that it is synthetic, local, and not for production.
- Consent record
Specified only
A later contract for noting that a synthetic subject allowed a check. The desk does not store a consent document.
- Entity resolution
Specified only
A later contract for comparing two synthetic names. No external registry is queried.
Not in the box
- Private repository
- Push or pull request to an upstream project
- GitHub Codespaces
- Dev Container
- Docker Compose file
- Ephemeral preview URL
- SBOM
- Pinned commit
- OpenSSF score
- Secret scan
- Vulnerability scan
- Source-derived code pack
