enteredEntered
One external business reference, opaque subject reference, declared purpose, and raw address intent are recorded.
Normalize a declared service address, capture purpose-bound device evidence, apply an explainable versioned policy, require human review where evidence is weak, and retire precise data without erasing accountability.
A state is not a UI label. It determines which actor may act, what evidence exists, what may be retried, and how recovery proceeds.
enteredOne external business reference, opaque subject reference, declared purpose, and raw address intent are recorded.
normalizedThe declared address maps to a provider-backed Mappls Pin, coordinate, components, confidence, and provenance.
capture_authorizedA specific subject granted one purpose-bound, expiring, accuracy- and retention-governed evidence capture.
evidence_capturedImmutable source identity, event and receipt time, coordinate, accuracy, provider context, and integrity hash are committed.
comparedA versioned policy records distance, effective uncertainty, thresholds, and its verify, reject, or review recommendation.
review_requiredWeak, conflicting, or policy-sensitive evidence is assigned to an attributable human decision.
verifiedterminalA policy or human decision accepted the declared address for the exact recorded purpose.
rejectedterminalEvidence did not establish the declared address, with reason, recommendation, actor, and appeal path retained.
cancelledterminalConsent was withdrawn before evidence capture and no precise observation may be accepted.
Commands express intent. The aggregate validates current state and invariants, commits one new version, and emits a fact in the same transaction.
enter_verificationApplication useraddress_verification.enteredUse the external application or case reference as durable business identity.
normalize_addressPolicy serviceenteredaddress_verification.normalizedBind normalized provider response to address-input hash and request identity.
authorize_captureApplication usernormalizedaddress_verification.capture_authorizedConsent identity, text version, subject, purpose, expiry, and retention policy form one grant.
revoke_consentApplication usercapture_authorizedaddress_verification.consent_revokedCommit withdrawal once and reject all later evidence under that grant.
capture_evidenceEvidence capture applicationcapture_authorizedaddress_verification.evidence_capturedUse a device-generated source-event identity created before transmission.
comparePolicy serviceevidence_capturedaddress_verification.comparedEvidence hash, normalized-place version, and policy version identify the exact comparison.
verifyPolicy servicecomparedaddress_verification.verifiedBind the terminal decision to comparison and aggregate version.
rejectPolicy servicecomparedaddress_verification.rejectedBind the terminal decision to comparison and aggregate version.
deferPolicy servicecomparedaddress_verification.review_requiredCreate one review case per comparison version.
review_verifyHuman reviewerreview_requiredaddress_verification.verifiedReviewer decision records reason, independent evidence, and any override under one identity.
review_rejectHuman reviewerreview_requiredaddress_verification.rejectedReviewer decision records reason, independent evidence, and any override under one identity.
Keep provider responses, business identity, state, events, and side-effect delivery distinct so each can be reconciled safely.
Business identity, purpose, lifecycle, selected evidence, comparison, decision, and version.
verificationIdexternalReferencesubjectReferencepurposestateversionProvider-backed place identity and address interpretation.
mapplsPincoordinateformattedAddresscomponentsconfidenceprovenanceAttributable authority and privacy bounds for precise capture.
consentIdsubjectpurposetextVersiongrantedAtexpiresAtretentionUntilstatusImmutable device observation with quality, timing, provenance, and integrity identity.
evidenceIdsourceEventIdeventTimereceivedAtcoordinateaccuracycontentHashExplainable recommendation, human disposition, override, and appeal context.
policyVersionthresholdsrecommendationoutcomeactorreasonOne external business reference maps to one verification aggregate.
Precise evidence is accepted only under active consent for the exact declared purpose and time window.
Provider normalization and application policy are identified separately.
An automated actor cannot override its own policy recommendation.
Every terminal outcome retains evidence hash, policy version, actor, and attributable reason.
Precise evidence can be redacted without erasing the audit trail or claiming that retained hashes can reconstruct it.
Recovery changes durable truth only through the same rules as normal operation. A timeout is an unknown outcome, not evidence that nothing happened.
Receipt or evidence event falls outside the committed grant window or grant status is revoked.
Reject it without retaining precise payload and require a fresh consent for another attempt.
Source-event identity or content hash already belongs to an accepted evidence envelope.
Return the original result for an idempotent retry or reject conflicting reuse as a security event.
Provider confidence, device accuracy, separation, or policy combination enters the review band.
Request clarification or independent review; do not transform uncertainty into a definitive match.
Precise evidence remains present beyond purpose, tenant, or jurisdiction policy.
Redact coordinate and place payloads, retain the minimum decision and integrity record, and audit completion.
Measure state age, event health, retries, reconciliation, and sensitive-data access alongside latency and error rate.
Only explicitly indexed evidence is linked. Empty sections are not backfilled with invented endpoints or package names.
8 labs · 5 hostile scenarios/api/places/search/json/{REST_KEY}/rev_geocodemappls-rest-apis8 verified tests