Provenanced stock assurance

Inventory assurance

A read-only mirror of ERP stock plus governed adjustments. Balances are rebuilt from immutable movements—never edited counters.

0
Net quantity
₹0
Stock value

Recent movements

The stored movement ledger—not a live ERP call

How to read this module

1
Mirror

ERP responses are hashed in private R2 before canonical records are used.

2
Derive

On hand equals inbound movements minus outbound movements, excluding voided rows.

3
Detect

Negative balances, substitutions, missing purchase evidence and transfer mismatches become unified findings.

4
Govern

Manual adjustments need a reason, note and independent approval.

Items and balances

ERP items are read-only; manual reference items remain editable
ItemCategoryStoreOn handReorderValueSource

Movement history

Voids remain queryable but never change the derived balance
DateItemStoreDirectionReasonQuantityReferenceOrigin

Adjustment queue

Maker–checker decisions and immutable history

Propose an adjustment

Submitting does not change stock. A different administrator must approve it.

Governed stock counts

Blind capture, offline sync, independent recount and immutable decisions

Control boundary

1
Blind by design

Expected quantities are frozen on the server and never sent to the phone.

2
Offline with conflicts

Drafts survive restarts. A changed server revision must be reviewed, never overwritten.

3
Maker–checker

The original counter cannot recount variance lines or decide the count.

4
No silent adjustment

A decision records evidence; inventory changes still use the governed adjustment workflow.

Manual reference item

Add item

For weighed labels, save only the 2–6 digit store prefix. The phone resolves the encoded quantity deterministically.

Preview first

Open a blind count

Opening freezes the server-side expected quantities. The phone payload never contains them.

Independent review

Stock count

This decision does not post an inventory adjustment.