base-erp-h219-v8-release-envelope-20260815 is the latest accepted, non-executable v8 release-envelope contract. The local candidate is frozen as release base-erp-public-product-20260815-v8, release fingerprint 606bf4abd676b61decaf5dcb618f32e4c017c4bafaee8874f4d371683b5350d0, and a staged, non-recursive 17-file BOM 41ca71034c5cf71486b760de8a4e2f0623f4d4d4b1332c2ea9b1c63a0a5142dd; the release fingerprint excludes the actual commit, which remains PENDING_OWNER_PUBLIC_COMMIT. It consumes the accepted H218 server-owned projection, preserves release/health/workbench/platform-gates parity and bare/slash workbench compatibility, and remains non-executable pending owner/runtime/publication gates. Independent fresh gpt-5.6-sol/medium review PASSed P0/P1/P2=0/0/0; manifest/artifact/handoff/exchange SHA-256 are 4b524c56a9894ab8159ee2baef1e94381c2c0681e4b9600dd57043c4cac49870 / 123c3ad829c71a3f3d4094f01cc4fd89ede5abb2733f0d7015eca84b950bb2a3 / 12c0e9d530d20ba2d101f70fff9dc898cc30c1d01ec1c63f656a633b93436a62 / 762fbf155d4661e13d95cb8bff1e6c0530b03320d80edb478d08ce9d17c14b13. Queue/cursor are completed=53/active=null/blocked=0; no Build/runtime, wallet, external platform, Obsidian or CIRCLE state changed.
This project ports the CIRCLE Arc-to-ERP V3.2 settlement workbench into a Base-native product. The frozen upstream snapshot is retained under upstream/arc_erp_v3_2/; it is evidence and reusable implementation material, not a Base truth source.
Current local validation (2026-08-15 H219/v8): focused suite 48/48 pass, full suite 260/260 pass, and the deterministic rerun is identical. Fresh independent gpt-5.6-sol/medium review is PASS with P0/P1/P2=0/0/0. The six public surfaces—/release.json, /healthz, /platform-gates.json, /workbench.json, /workbench, and /workbench/—share one fail-closed v8 readiness predicate; stale, missing, placeholder, alternate, or CIRCLE identity returns 503. Local evidence remains L0/L1 and does not substitute for a chain receipt, ERP readback, or complete current public-platform bundle.
The current release candidate is base-erp-public-product-20260815-v8 with release fingerprint 606bf4abd676b61decaf5dcb618f32e4c017c4bafaee8874f4d371683b5350d0 and BOM 41ca71034c5cf71486b760de8a4e2f0623f4d4d4b1332c2ea9b1c63a0a5142dd. The visitor-visible evidence surface remains at /evidence/ and /evidence.json; the responsive operator product is exposed at /workbench/ and /workbench.json, with a deterministic read-only refund ceiling preview at /refund-preview.json. These surfaces bind scenario queues, causal evidence, ERP consequence previews, receipt/finality gates and replay safety without granting a wallet or ERP write. The actual deployment commit is not bound locally and remains PENDING_OWNER_PUBLIC_COMMIT.
Base and CIRCLE are independent release projects. Before any external write, config/base_circle_platform_isolation_matrix_v1.json must be checked against the live target identity. Only the exact Base repository gaysonloser/base-erp-settlement-workbench, Render service base-erp-settlement-workbench, and Base-specific entries may be written. Existing CIRCLE resources, account-level fields, domains, manifests, releases and receipts must not be changed, reused or treated as Base evidence. If a shared profile cannot hold a separate Base entry, the operation stops at an owner/platform gate.
The B08 revalidation adds readCurrentBaseRuntimeBinding as the canonical source of the current 02_Build runtime hash, run id, date and cursor. The release candidate is recorded in runtime/release_candidate_2026-08-10.json; current-release chain, ERP, and eight-platform receipts remain independently gated, so local readiness alone is not a publication unit or daily count.
Current v8 publication state is deliberately zero-credit: all eight required rows—GitHub, Render, Base App, Base Dashboard, Base.dev, Talent, Guild and Basename/base.org—have no current v8 receipt (native_receipt=null, release_receipt=false, credit=0, publication_unit_credit=0). The v7 GitHub/Render/Dashboard evidence remains historical only and must not be relabeled as v8. Base App readiness is separate from release receipt; Dashboard/Base.dev remain one canonical identity. Talent, Guild, Basename/base.org and Base Sepolia remain owner/execution gates, not current v8 receipts. No v8 GitHub release, Render deployment, Dashboard release join, or publication unit is claimed.
Current task capability injection exposes Base Docs 3 tools and Base MCP 0 tools. Base MCP OAuth is pending the owner's final Allow; this README does not claim a 15-tool MCP surface, wallet identity, transaction, approval, or public-write authority.
The product closes a receipt-first operating loop:
Base event -> settlement case -> evidence match -> ERP draft/posting -> ledger/close readback -> ecosystem proof
Base-specific lanes are Smart Wallet receivable/payable/refund, x402 API settlement, B20 inventory/role lifecycle, programmable contract settlement, treasury swap reconciliation, and agentic workflow evidence. A standard transfer proves only a transfer. Invoice, counterparty, refund and accounting meaning require separate business evidence and fail closed when ambiguous.
03_Baseis the product/knowledge owner analogous to CIRCLE14_Arc: maintain scenario truth, Base official-source mapping, product queue, tests, quality review and a typed handoff. It has no wallet-write or external-publication authority.02_Buildis the engineering/execution owner analogous to CIRCLE09_Circle: implement the accepted packet, run ERP/Frappe integration, execute owner-reviewed Smart Wallet actions and publish truthful receipts. Its existing daily runtime remains the only authority for30+10.01_Configowns registry, scope separation, audits and source-snapshot integrity.
The only product exchange is shared/base_erp_exchange_v1.json. Daily chain counts, wallet gates and publication counters never enter this project runtime.
base-erp-h218-platform-gates-public-surface-20260815 is the latest accepted, non-executable public-surface integration contract. It consumes H217 frozen module/readback rather than duplicating evaluators and defines server-owned GET/HEAD /platform-gates.json, shared /workbench.json and /workbench/ projection, and deterministic visitor-safe four-row state for Base Sepolia rehearsal, Talent, Guild and Basename/base.org. Its v7 release join is a historical dependency only; it is not relabeled as a v8 receipt. Current v8 keeps Dashboard/Base.dev as one identity, Base App readiness-only semantics, zero-credit/non-receipt defaults, hidden-identity redaction and fail-closed BASE/CIRCLE isolation. Independent fresh gpt-5.6-sol/medium review PASSed P0/P1/P2=0/0/0; manifest/artifact/handoff/exchange SHA-256 are 08978962a4a0cd3bbbe59d5d095679fc80bd991c8299d63bf2b28b319b706e1f / d77211c599dba80c8e708b5bdd231cdfdaa6424a4b21bfae0aed6cd4707dcb9e / 523e0074d0010b5733d6805f4c29e36292f135f4903f2a4b9dd667002c6db04a / fff9bc97de73872a9f72788fca363f2c1ff79b83befa9b388bfeb0b499f480e9. Exact six Build paths are future-only after 02_Build revalidation; no Build/runtime, wallet, external platform, Obsidian or CIRCLE state changed.
base-erp-h217-remaining-platform-execution-gates-20260815 is the latest accepted, non-executable remaining-platform gate packet. Its independently verified v7 GitHub/Render/Dashboard envelope (5459eaf3b8000b5a85197516d0b72a5cc46e03a5, release fingerprint bfd8e57684b0c43bb92dbc9ac3bcd7426b226dc816541c008c7085b7cc6ae5ae, BOM 3b856d0a18fc996b47e5bb4bb0b4c06a73e28ff2f5a0ce13e08612b27ad3529c, Render deployment dep-da00nk1t0dsc738jpuv0) is historical input only and is not a v8 receipt. H217 keeps four remaining Base Sepolia/Talent/Guild/Basename owner gates, native-domain/readiness semantics, all credits zero, exact future Build paths, fail-closed BASE/CIRCLE isolation and execution_authority=none_until_02_Build_revalidates; no Build/runtime, wallet, deployment, platform/public write or CIRCLE state changed. H217 manifest/artifact/handoff/exchange SHA-256 are dbd6b5257aa5472a8e4621ec1ecd0c9a8ea2270c37b821912d86a9229f82b4a8 / a886f3d35ddff84852448de5ca5832087bf879c7d840b70bc9e6719e7e92acc8 / 853970cc363c22a1d366ea0c6b217f9fe73fd70c01da1e1e4c595f3c0bc32124 / dcbab1831d14ce36bec6a14579c2b8d1d991992435f693b440a12939bab6300e.
base-erp-h214-recurring-settlement-public-surface-integration-20260814 is the latest accepted, non-executable integration increment over H213. It closes the real composition gap by wiring the immutable H213 contract into src/server.mjs, src/base-erp-workbench.mjs and src/operator-workbench-page.mjs: server-owned GET/HEAD /recurring-settlement.json, the same top-level projection in /workbench.json and /workbench/, deterministic visitor status_readback_pending/redaction defaults, adapter/period/no-rollover and allowance readback, structurally separate CDP tx_hash versus manual wallet_sendCalls callsId/status previews, receipt/finality and ERP non-posting gates, and visitor regression tests. It is independently PASSed by /root/review_h214_packet (gpt-5.6-sol/medium, P0/P1/P2 0/0/0) and accepted once in the unique exchange as accepted_for_02_Build_bounded_pending_revalidation_non_executable. The exact six-path Build write set, release/BOM regeneration including the H213 source-module digest, H212 platform alias rules and BASE/CIRCLE stop gates are in the handoff; H213 semantics and all runtime/queue/cursor files remain out of scope.
H214 SHA-256: manifest 372ea725b36f5a02c95571264e686cd9c3aa9f7fa2a6a0e6ad060770368dd634, artifact ba1aa096490b0d2f175451ed1e5044f5f88088d9ffc22c0510c55567baff2006, handoff 15ec3ab42324a9b57f3d57d3e830b4cdd95207f443347ef27e946a9fa515763a, exchange 8dbc06921ecfa3344fcdc0baead6a3d7db66761bafc47d85ca656047a6ae8b8e; fixture 166ee8683defdeddfcb9b8a5abb33ea1d05ff03206098b6ab706e8fb7a405056; execution_authority=none_until_02_Build_revalidates.
base-erp-h213-recurring-spend-permission-settlement-20260814 is the latest Build-ready, non-wallet product increment. It adds the previously missing Base Account Spend Permission/Subscription lifecycle: server-owned permission and release binding, getStatus versus getPermissionStatus adapter gates, period reset/no-rollover, charge-only positive remaining, zero-remaining revoke, CDP tx-hash direct receipt/finality versus manual prepare*→wallet_sendCalls callsId/status branches, H210 finality/ERP readback composition, 25 deterministic vectors, and exact future Build paths. Fresh independent gpt-5.6-sol/medium review passed P0/P1/P2 0/0/0; the exchange handoff is accepted_for_02_Build_bounded_pending_revalidation_non_executable. execution_authority=none_until_02_Build_revalidates; no login, wallet, platform, ERP or CIRCLE action occurred.
H213 final SHA-256: manifest d1fbbcdaf8c4c9ac62db0193d4ced147a414aa97b745f7cfd33b5fd539ba1b6f, artifact f9fbc6c1675463285475882b2a07c67c35ae76a20c1286c5beb1c566d7ef9bc5, handoff ced8beb5552f6ba116fd23a728c0418012bfbe88941bc3452c81a30c55c953db, exchange 492199748e62733a2f34e5e2d4eb0d80c8fa382048103d469dffa51e07ce7d67. Queue/cursor remain completed=49, active=null, blocked=0.
H212 files live under projects/2026-08_Base_Knowledge_System/{source_evidence,artifacts,handoffs}/ with the H212 slug. 03_Base does not create wallet or platform writes; 02_Build must re-read the current official sources and exact owner-visible target before any action. Queue/cursor remain unchanged at completed=49, active=null, blocked=0.
base-erp-h211-cumulative-refund-closure-20260814 is the current Build-ready, non-wallet product increment. It adds a unique-original receipt gate, integer cumulative ceiling, explicit receipt_refund_outgoing versus payment_refund_incoming branches, one owner review or immutable evidence admission, sendCalls v2.0.0/atomic/call-status/receipt/finality dossier, direction-specific non-posting ERP readback, 18 vectors, exact Build write set and wait/recovery stops. Fresh independent gpt-5.6-sol/medium review passed P0/P1/P2 0/0/0; the exchange handoff is accepted_for_02_Build_bounded_pending_revalidation_non_executable. Outgoing from remains unbound until 02_Build owner revalidation; incoming creates no BASE request; no current refund receipt, ERP close, publication unit or Mainnet success is claimed.
Packet files live under projects/2026-08_Base_Knowledge_System/{source_evidence,artifacts,handoffs}/ with the H211 slug. 03_Base does not create wallet or platform writes; 02_Build must re-read official sources and current owner-visible state before any external action. Queue/cursor remain unchanged at completed=49, active=null, blocked=0.
- Upstream manifest:
config/upstream_arc_source_manifest.json - Base product contract:
config/base_erp_product_contract_v1.json - Product runtime:
runtime/current_state.json - Base scenario router:
src/base-erp-scenario-router.mjs - Tests:
test/base-erp-scenario-router.test.mjs - Simulation schema and fixture:
config/simulated_transaction_record_schema.json,fixtures/simulated_transactions.json - Public identity/exposure contract:
config/release_identity_and_exposure_contract_v1.json - Mutable Arc upstream delta contract:
config/arc_upstream_sync_contract_v1.json
The upstream snapshot deliberately excludes .git, node_modules, caches and historical review artifacts. Arc chain/network/wallet claims must be replaced with current Base official facts before promotion. B20 experimentation starts on Base Vibenet; Base Sepolia is used for ordinary testnet product flows; Base Mainnet actions require the existing 02_Build single-review gate.
Local tests and simulation are L0/L1 evidence only. L2 needs a unique successful testnet receipt plus deterministic product readback. L3 needs a unique Base Mainnet Smart Wallet receipt, authoritative ERP readback, same-commit Git/Render proof and the required Base ecosystem receipts. No platform row or simulated ERP record may be promoted into a daily count by prose.
Every simulated transaction is structurally non-countable: it has no transaction hash, is marked not_broadcast, and remains L0. Simulation records support product and ERP construction only; the existing 02_Build runtime owns all real daily counts.
Every truthful public release must expose gaysonloser.base.eth together with the full primary Base Account 0xBa36D092dB2999bb1FaBbaf281AC956A97189C25, the release fingerprint and evidence limitations. Basename resolution, Builder Code attribution, platform verification, transaction success and score movement are independently verified claims; configuration alone cannot prove them.
The Base/CIRCLE isolation protocol is mandatory for GitHub, Render, Base App, Base Dashboard, Base.dev, Talent, Guild, Basename/base.org and Base Sepolia: the exact BASE targets are GitHub gaysonloser/base-erp-settlement-workbench on main, Render service srv-d9t0bsafngtc7387gqo0 at base-erp-settlement-workbench.onrender.com, and Dashboard app 6a7a0717e209a55163497d2d with canonical primary URL https://base-erp-settlement-workbench.onrender.com. The CIRCLE denylist is gaysonloser/arc-payment-receipt, srv-d9cumml8nd3s73c9nehg, arc-payment-receipt.onrender.com, and programme-final-20260810. Read the exact target, assert that no CIRCLE identifier appears, write only the Base-specific resource, then read back a native receipt joined to the current release. Any ambiguity or CIRCLE target is a stop condition, not an invitation to overwrite.
The Arc ERP source remains a moving upstream. BASE never silently recopies its dirty working tree. 03_Base reviews semantic deltas into the single project exchange, and 02_Build implements only accepted, Base-revalidated packets.