{
    "record_type": "claim_ready_verified_action_receipt",
    "record_title": "Boundary decision receipt",
    "receipt_display_type": "verified_action_receipt",
    "receipt_pack": "ai_action_gateway",
    "generated_at": "2026-08-04T21:52:40+00:00",
    "receipt": {
        "receipt_id": "VAR-GW-20260629033722-0Z8JU9",
        "receipt_type": "verified_action_receipt",
        "status": "pending_approval",
        "hash_algorithm": "sha256",
        "payload_hash": "6008e12aa1712a6150e0e8864bdf0d799c9a548fdfe8cd1f20a278a9f26d12ff",
        "receipt_hash": "18dc06468a21bbd05a12992572a07b0c398898528d4e5d749f3b0a9fc5183c86",
        "previous_receipt_hash": "43f798d7dcb692ff1ff3e5b192cc88b31841fe408f91c6df97e00617d63c1fa1",
        "signed_by": "nehraq-action-gateway",
        "issued_at": "2026-06-29 03:37:22",
        "metadata": {
            "source": "nehraq_ai_action_gateway_39a",
            "receipt_payload": {
                "event_id": "EVT-GW-20260629033722-SZE7BE",
                "external_request_id": "b807677b-0be6-4889-87cb-c69f12f12d21",
                "agent_id": "agt-shuppz-customercare-agent-01-5367",
                "action": "customer_commitment",
                "decision": "escalate",
                "reason": "Customer compensation commitments require human approval before execution.",
                "risk_tier": "high",
                "approval_request_id": "APR-GW-20260629033722-CKCEDL",
                "execution_status": "not_recorded",
                "receipt_id": "VAR-GW-20260629033722-0Z8JU9",
                "receipt_type": "verified_action_receipt",
                "receipt_display_title": "Boundary decision receipt",
                "receipt_display_type": "verified_action_receipt",
                "receipt_pack": "ai_action_gateway",
                "issued_at": "2026-06-29T03:37:22+00:00",
                "policy_control_map": {
                    "map_version": "15B",
                    "map_source": "nehraq_policy_control_map_15b",
                    "policy_status": "approval_required_before_execution",
                    "decision": "escalate",
                    "risk_tier": "high",
                    "policy_tags": [
                        "Internal Company Policy",
                        "SOC 2",
                        "NIST AI RMF",
                        "GDPR",
                        "ISO 27001"
                    ],
                    "mapped_policy_packs": [
                        "INTERNAL_POLICY",
                        "SOC2",
                        "NIST_AI_RMF",
                        "GDPR",
                        "ISO27001"
                    ],
                    "mapped_control_codes": [
                        "INTERNAL-AUTHORITY-BOUNDARY",
                        "SOC2-PI-ACTION-INTEGRITY",
                        "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                        "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                        "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                        "GDPR-PERSONAL-DATA-PROTECTION",
                        "SOC2-PRIV-CUSTOMER-DATA",
                        "ISO27001-ACCESS-CHANGE-CONTROL",
                        "INTERNAL-CUSTOMER-COMMITMENT-REVIEW"
                    ],
                    "mapped_controls": [
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-AUTHORITY-BOUNDARY",
                            "control_name": "Action authority boundary enforced",
                            "control_category": "authority_boundary",
                            "evidence": "Nehraq evaluated whether the agent action stayed within configured authority before execution."
                        },
                        {
                            "pack_code": "SOC2",
                            "pack_name": "SOC 2",
                            "control_code": "SOC2-PI-ACTION-INTEGRITY",
                            "control_name": "Action integrity checked before execution",
                            "control_category": "processing_integrity",
                            "evidence": "Boundary decision generated evidence that the proposed action was evaluated before execution."
                        },
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                            "control_name": "Human approval required before execution",
                            "control_category": "human_review",
                            "evidence": "Action was paused before execution because human review was required."
                        },
                        {
                            "pack_code": "NIST_AI_RMF",
                            "pack_name": "NIST AI RMF",
                            "control_code": "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                            "control_name": "Human oversight checkpoint applied",
                            "control_category": "ai_risk_management",
                            "evidence": "Nehraq created an oversight checkpoint for an action with elevated risk."
                        },
                        {
                            "pack_code": "NIST_AI_RMF",
                            "pack_name": "NIST AI RMF",
                            "control_code": "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                            "control_name": "High-risk AI action mapped and managed",
                            "control_category": "ai_risk_management",
                            "evidence": "The decision identified elevated harm potential and applied a control response."
                        },
                        {
                            "pack_code": "GDPR",
                            "pack_name": "GDPR",
                            "control_code": "GDPR-PERSONAL-DATA-PROTECTION",
                            "control_name": "Personal data protection evidence",
                            "control_category": "privacy",
                            "evidence": "Customer-impacting or data-related action was mapped to privacy review evidence."
                        },
                        {
                            "pack_code": "SOC2",
                            "pack_name": "SOC 2",
                            "control_code": "SOC2-PRIV-CUSTOMER-DATA",
                            "control_name": "Customer data privacy control",
                            "control_category": "privacy",
                            "evidence": "Decision evidence supports review of customer data and privacy-impacting actions."
                        },
                        {
                            "pack_code": "ISO27001",
                            "pack_name": "ISO 27001",
                            "control_code": "ISO27001-ACCESS-CHANGE-CONTROL",
                            "control_name": "Access and change control evidence",
                            "control_category": "access_change_control",
                            "evidence": "Action was evaluated for authority, access, or change-control impact before execution."
                        },
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-CUSTOMER-COMMITMENT-REVIEW",
                            "control_name": "Customer commitment review",
                            "control_category": "customer_commitment",
                            "evidence": "Customer commitment, compensation, billing, or legal-sensitive action was mapped to review evidence."
                        }
                    ],
                    "summary": "Policy-linked boundary decision: ESCALATE / HIGH. 9 mapped control(s) attached for action-level evidence review.",
                    "not_compliance_certification": true,
                    "receipt_persistence_phase": "15C"
                },
                "policy_tags": [
                    "Internal Company Policy",
                    "SOC 2",
                    "NIST AI RMF",
                    "GDPR",
                    "ISO 27001"
                ],
                "mapped_policy_controls": [
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-AUTHORITY-BOUNDARY",
                        "control_name": "Action authority boundary enforced",
                        "control_category": "authority_boundary",
                        "evidence": "Nehraq evaluated whether the agent action stayed within configured authority before execution."
                    },
                    {
                        "pack_code": "SOC2",
                        "pack_name": "SOC 2",
                        "control_code": "SOC2-PI-ACTION-INTEGRITY",
                        "control_name": "Action integrity checked before execution",
                        "control_category": "processing_integrity",
                        "evidence": "Boundary decision generated evidence that the proposed action was evaluated before execution."
                    },
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                        "control_name": "Human approval required before execution",
                        "control_category": "human_review",
                        "evidence": "Action was paused before execution because human review was required."
                    },
                    {
                        "pack_code": "NIST_AI_RMF",
                        "pack_name": "NIST AI RMF",
                        "control_code": "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                        "control_name": "Human oversight checkpoint applied",
                        "control_category": "ai_risk_management",
                        "evidence": "Nehraq created an oversight checkpoint for an action with elevated risk."
                    },
                    {
                        "pack_code": "NIST_AI_RMF",
                        "pack_name": "NIST AI RMF",
                        "control_code": "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                        "control_name": "High-risk AI action mapped and managed",
                        "control_category": "ai_risk_management",
                        "evidence": "The decision identified elevated harm potential and applied a control response."
                    },
                    {
                        "pack_code": "GDPR",
                        "pack_name": "GDPR",
                        "control_code": "GDPR-PERSONAL-DATA-PROTECTION",
                        "control_name": "Personal data protection evidence",
                        "control_category": "privacy",
                        "evidence": "Customer-impacting or data-related action was mapped to privacy review evidence."
                    },
                    {
                        "pack_code": "SOC2",
                        "pack_name": "SOC 2",
                        "control_code": "SOC2-PRIV-CUSTOMER-DATA",
                        "control_name": "Customer data privacy control",
                        "control_category": "privacy",
                        "evidence": "Decision evidence supports review of customer data and privacy-impacting actions."
                    },
                    {
                        "pack_code": "ISO27001",
                        "pack_name": "ISO 27001",
                        "control_code": "ISO27001-ACCESS-CHANGE-CONTROL",
                        "control_name": "Access and change control evidence",
                        "control_category": "access_change_control",
                        "evidence": "Action was evaluated for authority, access, or change-control impact before execution."
                    },
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-CUSTOMER-COMMITMENT-REVIEW",
                        "control_name": "Customer commitment review",
                        "control_category": "customer_commitment",
                        "evidence": "Customer commitment, compensation, billing, or legal-sensitive action was mapped to review evidence."
                    }
                ],
                "mapped_control_codes": [
                    "INTERNAL-AUTHORITY-BOUNDARY",
                    "SOC2-PI-ACTION-INTEGRITY",
                    "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                    "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                    "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                    "GDPR-PERSONAL-DATA-PROTECTION",
                    "SOC2-PRIV-CUSTOMER-DATA",
                    "ISO27001-ACCESS-CHANGE-CONTROL",
                    "INTERNAL-CUSTOMER-COMMITMENT-REVIEW"
                ],
                "mapped_policy_packs": [
                    "INTERNAL_POLICY",
                    "SOC2",
                    "NIST_AI_RMF",
                    "GDPR",
                    "ISO27001"
                ],
                "policy_linked_verified_action_receipt": true
            },
            "signature_algorithm": "hmac-sha256",
            "signature": "068a42d090bc6af3b5c87448ff10909624805ce7ef18335bd497cfd809544654",
            "download_url": "https://nehraq.com/liability-os/action-gateway/receipts/VAR-GW-20260629033722-0Z8JU9?download=1"
        }
    },
    "event": {
        "event_id": "EVT-GW-20260629033722-SZE7BE",
        "event_type": "ai_action_gateway_boundary_check",
        "decision": "escalate",
        "severity": "warning",
        "source": "nehraq_ai_action_gateway_39a",
        "action_name": "customer_commitment",
        "agent_name": "Shuppz-CustomerCare-Agent-01",
        "input_hash": "312b2a180ec9d3d431b0e3d7ae43d9782118d3b9d123897d622ec79e719fb2cb",
        "output_hash": "9435f5001336206b8f4657a823bee4db520cb97f4e4939bc8f7c91235edb3106",
        "occurred_at": "2026-06-29 03:37:22",
        "payload": {
            "event_id": "EVT-GW-20260629033722-SZE7BE",
            "external_request_id": "b807677b-0be6-4889-87cb-c69f12f12d21",
            "agent_id": "agt-shuppz-customercare-agent-01-5367",
            "registered_agent_id": 1,
            "action": "customer_commitment",
            "amount": 500,
            "system": "Local Customer Service Agent / Port 1019",
            "risk_context": "risk_tier=HIGH; customer=Robert Kim; expected_decision=ESCALATE; reason=Customer compensation commitments require human approval.; description=Agent wants to promise the customer $500 in future compensation.",
            "decision": {
                "decision": "escalate",
                "reason": "Customer compensation commitments require human approval before execution.",
                "risk_tier": "high",
                "severity": "warning",
                "approval_role": "Authorized Business Reviewer",
                "policy_status": "approval_required_before_execution",
                "policy_tags": [
                    "Internal Company Policy",
                    "SOC 2",
                    "NIST AI RMF",
                    "GDPR",
                    "ISO 27001"
                ],
                "mapped_policy_controls": [
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-AUTHORITY-BOUNDARY",
                        "control_name": "Action authority boundary enforced",
                        "control_category": "authority_boundary",
                        "evidence": "Nehraq evaluated whether the agent action stayed within configured authority before execution."
                    },
                    {
                        "pack_code": "SOC2",
                        "pack_name": "SOC 2",
                        "control_code": "SOC2-PI-ACTION-INTEGRITY",
                        "control_name": "Action integrity checked before execution",
                        "control_category": "processing_integrity",
                        "evidence": "Boundary decision generated evidence that the proposed action was evaluated before execution."
                    },
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                        "control_name": "Human approval required before execution",
                        "control_category": "human_review",
                        "evidence": "Action was paused before execution because human review was required."
                    },
                    {
                        "pack_code": "NIST_AI_RMF",
                        "pack_name": "NIST AI RMF",
                        "control_code": "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                        "control_name": "Human oversight checkpoint applied",
                        "control_category": "ai_risk_management",
                        "evidence": "Nehraq created an oversight checkpoint for an action with elevated risk."
                    },
                    {
                        "pack_code": "NIST_AI_RMF",
                        "pack_name": "NIST AI RMF",
                        "control_code": "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                        "control_name": "High-risk AI action mapped and managed",
                        "control_category": "ai_risk_management",
                        "evidence": "The decision identified elevated harm potential and applied a control response."
                    },
                    {
                        "pack_code": "GDPR",
                        "pack_name": "GDPR",
                        "control_code": "GDPR-PERSONAL-DATA-PROTECTION",
                        "control_name": "Personal data protection evidence",
                        "control_category": "privacy",
                        "evidence": "Customer-impacting or data-related action was mapped to privacy review evidence."
                    },
                    {
                        "pack_code": "SOC2",
                        "pack_name": "SOC 2",
                        "control_code": "SOC2-PRIV-CUSTOMER-DATA",
                        "control_name": "Customer data privacy control",
                        "control_category": "privacy",
                        "evidence": "Decision evidence supports review of customer data and privacy-impacting actions."
                    },
                    {
                        "pack_code": "ISO27001",
                        "pack_name": "ISO 27001",
                        "control_code": "ISO27001-ACCESS-CHANGE-CONTROL",
                        "control_name": "Access and change control evidence",
                        "control_category": "access_change_control",
                        "evidence": "Action was evaluated for authority, access, or change-control impact before execution."
                    },
                    {
                        "pack_code": "INTERNAL_POLICY",
                        "pack_name": "Internal Company Policy",
                        "control_code": "INTERNAL-CUSTOMER-COMMITMENT-REVIEW",
                        "control_name": "Customer commitment review",
                        "control_category": "customer_commitment",
                        "evidence": "Customer commitment, compensation, billing, or legal-sensitive action was mapped to review evidence."
                    }
                ],
                "mapped_control_codes": [
                    "INTERNAL-AUTHORITY-BOUNDARY",
                    "SOC2-PI-ACTION-INTEGRITY",
                    "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                    "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                    "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                    "GDPR-PERSONAL-DATA-PROTECTION",
                    "SOC2-PRIV-CUSTOMER-DATA",
                    "ISO27001-ACCESS-CHANGE-CONTROL",
                    "INTERNAL-CUSTOMER-COMMITMENT-REVIEW"
                ],
                "mapped_policy_packs": [
                    "INTERNAL_POLICY",
                    "SOC2",
                    "NIST_AI_RMF",
                    "GDPR",
                    "ISO27001"
                ],
                "policy_control_map": {
                    "map_version": "15B",
                    "map_source": "nehraq_policy_control_map_15b",
                    "policy_status": "approval_required_before_execution",
                    "decision": "escalate",
                    "risk_tier": "high",
                    "policy_tags": [
                        "Internal Company Policy",
                        "SOC 2",
                        "NIST AI RMF",
                        "GDPR",
                        "ISO 27001"
                    ],
                    "mapped_policy_packs": [
                        "INTERNAL_POLICY",
                        "SOC2",
                        "NIST_AI_RMF",
                        "GDPR",
                        "ISO27001"
                    ],
                    "mapped_control_codes": [
                        "INTERNAL-AUTHORITY-BOUNDARY",
                        "SOC2-PI-ACTION-INTEGRITY",
                        "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                        "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                        "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                        "GDPR-PERSONAL-DATA-PROTECTION",
                        "SOC2-PRIV-CUSTOMER-DATA",
                        "ISO27001-ACCESS-CHANGE-CONTROL",
                        "INTERNAL-CUSTOMER-COMMITMENT-REVIEW"
                    ],
                    "mapped_controls": [
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-AUTHORITY-BOUNDARY",
                            "control_name": "Action authority boundary enforced",
                            "control_category": "authority_boundary",
                            "evidence": "Nehraq evaluated whether the agent action stayed within configured authority before execution."
                        },
                        {
                            "pack_code": "SOC2",
                            "pack_name": "SOC 2",
                            "control_code": "SOC2-PI-ACTION-INTEGRITY",
                            "control_name": "Action integrity checked before execution",
                            "control_category": "processing_integrity",
                            "evidence": "Boundary decision generated evidence that the proposed action was evaluated before execution."
                        },
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-HUMAN-APPROVAL-REQUIRED",
                            "control_name": "Human approval required before execution",
                            "control_category": "human_review",
                            "evidence": "Action was paused before execution because human review was required."
                        },
                        {
                            "pack_code": "NIST_AI_RMF",
                            "pack_name": "NIST AI RMF",
                            "control_code": "NIST-AI-RMF-MANAGE-HUMAN-OVERSIGHT",
                            "control_name": "Human oversight checkpoint applied",
                            "control_category": "ai_risk_management",
                            "evidence": "Nehraq created an oversight checkpoint for an action with elevated risk."
                        },
                        {
                            "pack_code": "NIST_AI_RMF",
                            "pack_name": "NIST AI RMF",
                            "control_code": "NIST-AI-RMF-MAP-MANAGE-HIGH-RISK-ACTION",
                            "control_name": "High-risk AI action mapped and managed",
                            "control_category": "ai_risk_management",
                            "evidence": "The decision identified elevated harm potential and applied a control response."
                        },
                        {
                            "pack_code": "GDPR",
                            "pack_name": "GDPR",
                            "control_code": "GDPR-PERSONAL-DATA-PROTECTION",
                            "control_name": "Personal data protection evidence",
                            "control_category": "privacy",
                            "evidence": "Customer-impacting or data-related action was mapped to privacy review evidence."
                        },
                        {
                            "pack_code": "SOC2",
                            "pack_name": "SOC 2",
                            "control_code": "SOC2-PRIV-CUSTOMER-DATA",
                            "control_name": "Customer data privacy control",
                            "control_category": "privacy",
                            "evidence": "Decision evidence supports review of customer data and privacy-impacting actions."
                        },
                        {
                            "pack_code": "ISO27001",
                            "pack_name": "ISO 27001",
                            "control_code": "ISO27001-ACCESS-CHANGE-CONTROL",
                            "control_name": "Access and change control evidence",
                            "control_category": "access_change_control",
                            "evidence": "Action was evaluated for authority, access, or change-control impact before execution."
                        },
                        {
                            "pack_code": "INTERNAL_POLICY",
                            "pack_name": "Internal Company Policy",
                            "control_code": "INTERNAL-CUSTOMER-COMMITMENT-REVIEW",
                            "control_name": "Customer commitment review",
                            "control_category": "customer_commitment",
                            "evidence": "Customer commitment, compensation, billing, or legal-sensitive action was mapped to review evidence."
                        }
                    ],
                    "summary": "Policy-linked boundary decision: ESCALATE / HIGH. 9 mapped control(s) attached for action-level evidence review.",
                    "not_compliance_certification": true,
                    "receipt_persistence_phase": "15C"
                },
                "compliance_linkage": "Policy-linked boundary decision: ESCALATE / HIGH. 9 mapped control(s) attached for action-level evidence review."
            },
            "approval_request_id": "APR-GW-20260629033722-CKCEDL",
            "auth_mode": "external_agent_api",
            "received_at": "2026-06-29T03:37:22+00:00"
        }
    },
    "hash_chain": [
        {
            "hash_type": "ai_action_gateway_receipt_chain",
            "algorithm": "sha256",
            "payload_hash": "6008e12aa1712a6150e0e8864bdf0d799c9a548fdfe8cd1f20a278a9f26d12ff",
            "previous_hash": "43f798d7dcb692ff1ff3e5b192cc88b31841fe408f91c6df97e00617d63c1fa1",
            "chain_hash": "5fc02f3024146def69640f78141d4ae0e62fd2bd66707989cd5fc5b12dc18575",
            "sequence_number": 31,
            "anchored_at": "2026-06-29 03:37:22"
        }
    ]
}