Modules

Fourteen modules. Three rings. One registry.

The reviewed machine registry defines fourteen domains across three rings, all currently marked ui. Tenant entitlement, integration maturity and production availability are confirmed separately; registry presence is not GA.

TrustStack Core — Registered core domains with ui/read surfaces. Scope one or more only after capability and integration validation.
GATE · Verify
Make identity context visible before scope changes.
Observed UI/read surface · registry status: ui · not GA

Use GATE to frame who or which party is under review, what was actually recorded and which condition remains open. It does not by itself establish a complete KYC/KYB programme, UBO workflow or generally available onboarding service.

Current surface: hosted KYC and party reads; review is feature-flagged; UBO capture is absent in the reviewed state.

  • Observed hosted KYC and party UI/read surfaces
  • Review path present behind a feature flag, not assumed for every tenant
  • UBO capture is absent in the reviewed state and remains a validation requirement
  • Designed to pass recorded identity context into screening, policy and case workflows
  • Step-up, re-verification and document-evidence behavior require journey-level configuration
Read in the manual
PULSE · Risk
Turn recorded signals into an inspectable decision.
Observed UI/read surface · registry status: ui · not GA

PULSE is intended to connect available risk signals to a decision that can be challenged. In the reviewed state, the honest proposition is an exploratory UI with partial rationale—not complete real-time scoring, universal explanation or proven fraud outcomes.

Current surface: Decision Explorer with partial rationale; the ML indicator is a stub, not an active-model claim.

  • Observed Decision Explorer and partial rationale UI/read surfaces
  • Rules-first decision pattern; any model use is optional and separately validated
  • The current ML indicator is a stub and must not be presented as an active model
  • Designed actions include approve, step-up, review and hold when configured
  • Missing input, threshold or version context stays explicit instead of being inferred
Read in the manual
SWITCH · Payments
Make payment-path choices and limits visible.
Observed UI/read surface · registry status: ui · not GA

SWITCH makes the proposed route, held traffic and available path context inspectable. A scoped exercise can test the control pattern, but live PSP connectivity, routing performance, resilience and service levels must be proven separately.

Current surface: partial routing-configuration and payment path-trail reads; no live provider or automatic failover is inferred.

  • Observed partial routing-configuration UI/read surfaces
  • Observed payment path-trail reads for available fixture data
  • Designed routing factors include provider state, eligibility, geography, cost and risk context
  • Payout, retry and fallback behavior depends on connected providers and validated policy
  • No production traffic, provider redundancy or automatic failover is established by the UI
Read in the manual
LEDGER · Tax & Finance
Put books and tax assumptions on the record.
Observed UI/read surface · registry status: ui · not GA

LEDGER can provide a strong finance anchor when the source, posting state and reconciliation context are available. Tax output remains an input-sensitive calculation: jurisdiction, rate source, basis date and intended report must be validated rather than assumed.

Current surface: books are the strongest observed area; tax rates are static and must be shown with their rate-basis date.

  • Observed books and finance-oriented UI/read surfaces
  • Static tax rates in the reviewed state; always expose the applicable rate-basis date
  • Designed to retain tax inputs, basis and output as a dated decision snapshot
  • Reconciliation, wallet and export behavior remains workflow- and integration-dependent
  • No claim of automatic filing, universal tax correctness or immutable books
Read in the manual
SENTINEL · Policy
Show which policy context governed the decision.
Observed UI/read surface · registry status: ui · not GA

SENTINEL is intended to answer which policy and disposition informed an action. The reviewed surface can demonstrate that control pattern, but not current sanctions-list completeness, universal maker-checker, automated enforcement or regulatory compliance.

Current surface: screening and policy reads use a DEMO screening list; list coverage and live feeds are not established.

  • Observed screening and policy UI/read surfaces
  • Current screening source is a DEMO list and must be labelled as such
  • Designed policy context includes geography, product, age and payment-method conditions
  • Versioning, approval and rollback depend on the configured governance workflow
  • Runtime rule delivery and external screening feeds require integration and validation
Read in the manual
PRISM · Insights
Turn available operating data into a bounded view.
Observed UI/read surface · registry status: ui · not GA

PRISM can help a pilot ask whether the same recorded facts produce a useful operating and evidence view. Reproducibility depends on complete source data, definitions, versions and export logic; the current UI does not prove scheduled production reporting.

Current surface: dashboards and generate-now scorecards; scheduled reporting, contractual service-level monitoring and authority-accepted output are not established.

  • Observed dashboard UI/read surfaces for available operational data
  • Scorecards are generated on demand in the reviewed state, not scheduled automatically
  • Designed comparisons require an agreed baseline, definitions and reporting period
  • Questionnaires and extracts remain purpose-, role- and source-data-dependent
  • No public contractual service-level monitoring, authority-accepted report or customer KPI outcome is claimed
Read in the manual
Optional add-ons — Entitlement-gated extensions for specific obligations — enabled where feasible and licensed.

MoR is a partial ui/read surface in the reviewed snapshot; any delivery depends on jurisdiction, licensing, legal review and contract.

Platform ring — always on — Shared case, evidence, administration and developer fabric in the target architecture. Access and behavior remain role-, entitlement- and deployment-dependent.

Modules compose by contract

The target contracts connect GATE identity context with SENTINEL screening, let PULSE use governed rule packs and raise matters in DOCKET, and route available audit events toward VAULT and reporting data toward PRISM. Exact producers, fields and enforcement are validated per workflow; missing evidence is not inferred.