Static snapshot. A frozen copy of the operator dashboard, safe to open anywhere. The buttons below are drawn but inert — recording a verification and being refused the release is a state change, so it runs on the live app: python src/demo.py --serve.

BaseDrift

payout pout_0060
Inbox · ← All decisions
Released
Routine payment — nothing was being changed
R2a_no_change_confirmed
Semantic layer read this as a payment follow-up, and the payout destination is confirmed unchanged against the vendor master. 540341470860 (payout fund account) is a known account for this vendor

Verification — what would release this

Ask the supplier to send Rs 1 from this account, and no other:
540341470860
chosen because 540341470860: 67 settled payout(s), added 2024-04-13 via onboarding, verified by onboarding_kyc
Two people, not one. Whoever records the verification outcome must not be whoever releases the payment. A compromised or complicit AP clerk who can do both approves their own request, and the control is theatre. This is enforced when the button is pressed, not only drawn on the screen.

What was checked

Supplier
VEND0055
Destination account
540341470860
Destination came from
The payout itself — the payout's own fund account, never the email [razorpay_fund_account]
Fund account
fa_0060
Amount
Rs 82,000.00
Change request
doc_6c7b32f851917472
Correlated by
Named on the payout [explicit_note]
Evidence source
Replayed perfect extraction [replayed_perfect_extraction]
Semantic reading
PAYMENT_FOLLOWUP / NONE / NONE

Accounts on file for this supplier

AccountAddedVerifiedSettled
540341470860
HDFC0598886 · active
At onboarding
2024-04-13
Verified at onboarding (KYC)67
payouts
This paymentPrimary
929860270863
HDFC0650870 · active
Added because of an email request
2024-10-03
Verified by a callback4
payouts
962845950622
ICIC0632523 · active
Added because of an email request
2026-05-16
Never verified outside email0
payouts
Never established
An account is established once something outside email has confirmed it — onboarding checks, a rupee from the account, a callback — or once it has actually carried a payout. Being on file is not the same thing: an account can be on file because one email asked for it and nobody checked. The engine treats those as unconfirmed rather than as wrong, so they hold rather than reject.

Identity checks — against your supplier records

result
check
finding
OK
Destination account
account_continuity
540341470860 (payout fund account) is a known account for this vendor
from Payout, against our records

What this maps to at RazorpayX

POST /v1/payouts/pout_0060/approve
payout released from pending

Action plans. Nothing in this repository calls Razorpay.