Static snapshot. A frozen copy of the operator dashboard, safe to open anywhere. The buttons below are drawn but inert — recording a verification and being refused the release is a state change, so it runs on the live app: python src/demo.py --serve.

BaseDrift

payout pout_0044
Inbox · ← All decisions
Released
Routine payment — nothing was being changed
R2a_no_change_confirmed
Semantic layer read this as a payment follow-up, and the payout destination is confirmed unchanged against the vendor master. 500742637533 (payout fund account) is a known account for this vendor

Verification — what would release this

Ask the supplier to send Rs 1 from this account, and no other:
500742637533
chosen because 500742637533: 60 settled payout(s), added 2023-12-20 via onboarding, verified by onboarding_kyc
Two people, not one. Whoever records the verification outcome must not be whoever releases the payment. A compromised or complicit AP clerk who can do both approves their own request, and the control is theatre. This is enforced when the button is pressed, not only drawn on the screen.

What was checked

Supplier
VEND0048
Destination account
500742637533
Destination came from
The payout itself — the payout's own fund account, never the email [razorpay_fund_account]
Fund account
fa_0044
Amount
Rs 15,000.00
Change request
doc_0bc99c60713dc508
Correlated by
Named on the payout [explicit_note]
Evidence source
Replayed perfect extraction [replayed_perfect_extraction]
Semantic reading
PAYMENT_FOLLOWUP / NONE / NONE

Accounts on file for this supplier

AccountAddedVerifiedSettled
500742637533
KKBK0543441 · active
At onboarding
2023-12-20
Verified at onboarding (KYC)60
payouts
This paymentPrimary
936953022902
UTIB0900352 · active
Added because of an email request
2026-06-02
Never verified outside email0
payouts
Never established
An account is established once something outside email has confirmed it — onboarding checks, a rupee from the account, a callback — or once it has actually carried a payout. Being on file is not the same thing: an account can be on file because one email asked for it and nobody checked. The engine treats those as unconfirmed rather than as wrong, so they hold rather than reject.

Identity checks — against your supplier records

result
check
finding
OK
Destination account
account_continuity
500742637533 (payout fund account) is a known account for this vendor
from Payout, against our records

What this maps to at RazorpayX

POST /v1/payouts/pout_0044/approve
payout released from pending

Action plans. Nothing in this repository calls Razorpay.