PortfolioCommandCenter
Trust receipt for PortfolioCommandCenter: Fixture-backed public demo proof is supported, with explicit limits. Includes checks, evidence, exclusions, freshness, and limitations.
Trust Receipt
trust receipt partial proof with gaps
Portfolio Command Center can be demonstrated from fixture-backed GitHub Repo Auditor artifacts without private local operating data.
Verdict
mixed Fixture-backed public demo proof is supported, with explicit limits.
Freshness
static_fixture 2026-04-12T12:00:00+00:00
Checks
8 7 passed, 0 failed, 1 not checked, 0 inconclusive
Receipt ID
tr_public-fixture-portfolio-command-center-demo 2026-06-27T00:00:00Z
Boundary
This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.
Not Checked
Known proof gap not checked
The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.
no direct evidence reference
Passed
The public demo source is a committed fixture file, not the private live portfolio output. passed
The public demo source is a committed fixture file, not the private live portfolio output.
fixture-report
The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo. passed
The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo.
demo-make-target, demo-build-script, demo-report, demo-workbook, demo-dashboard, demo-control-center-json, demo-control-center-markdown, demo-portfolio-truth, demo-weekly-digest, demo-security-burndown, demo-history-previous, demo-history-current, demo-proposals, demo-warehouse
The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape. passed
The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape.
demo-portfolio-truth, demo-weekly-digest, demo-security-burndown
The public recording checklist requires fixture output and blocks private local data exposure. passed
The public recording checklist requires fixture output and blocks private local data exposure.
recording-checklist
Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces. passed
Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces.
summary, verification-notes, screenshot-ops-shell, screenshot-portfolio, screenshot-risk-security, screenshot-burndown, screenshot-trends, screenshot-weekly-digest
manifest references fixture input and generated output paths passed
manifest references fixture input and generated output paths
no direct evidence reference
visual capture from Portfolio Command Center passed
visual capture from Portfolio Command Center
no direct evidence reference
Evidence
Evidence entries are public-safe references and digests, not raw private reports.
| ID | Title | Kind | Reference | Digest |
|---|---|---|---|---|
| summary | Human-readable public fixture demo summary. | summary | GithubRepoAuditor/docs/demo-proof/public-fixture/SUMMARY.md | 15aefab56a22b667... |
| recording-checklist | Public-safe recording checklist and redaction guard. | checklist | GithubRepoAuditor/docs/demo-proof/public-fixture/RECORDING-CHECKLIST.md | 6f7aea433679edd1... |
| fixture-report | Committed fixture report used as the public demo source. | fixture | GithubRepoAuditor/fixtures/demo/sample-report.json | be4ea286a11b1aac... |
| demo-make-target | Make target that runs the fixture demo generator. | repo-doc | GithubRepoAuditor/Makefile | 0f70132ce7641631... |
| demo-build-script | Fixture artifact generator for output/demo. | script | GithubRepoAuditor/scripts/build_demo_artifacts.py | d16e9ce5c38aa7e9... |
| demo-report | Generated demo report. | json | GithubRepoAuditor/output/demo/demo-report.json | 12e43eb80263cbd8... |
| demo-workbook | Generated demo workbook. | workbook | GithubRepoAuditor/output/demo/demo-workbook.xlsx | 6fb1423325b96534... |
| demo-dashboard | Generated demo HTML dashboard. | html | GithubRepoAuditor/output/demo/dashboard-sample-user-2026-04-12.html | dccb0be243e01f07... |
| demo-control-center-json | Generated demo operator control-center JSON. | json | GithubRepoAuditor/output/demo/operator-control-center-demo.json | 8d38e5d131e8eb7a... |
| demo-control-center-markdown | Generated demo operator control-center Markdown. | markdown | GithubRepoAuditor/output/demo/operator-control-center-demo.md | 19e7ada449155201... |
| demo-portfolio-truth | Generated demo portfolio truth snapshot. | json | GithubRepoAuditor/output/demo/portfolio-truth-latest.json | c66a09a1d3882f80... |
| demo-weekly-digest | Generated demo weekly command-center digest. | json | GithubRepoAuditor/output/demo/weekly-command-center-sample-user-2026-04-12.json | df085a9acbb9ef56... |
| demo-security-burndown | Generated demo security burndown report. | json | GithubRepoAuditor/output/demo/security-burndown-sample-user-2026-04-12.json | 7a37d3e331b23e26... |
| demo-history-previous | Generated previous demo truth snapshot for trends. | json | GithubRepoAuditor/output/demo/portfolio-truth-2026-04-05T120000Z.json | 4037ce360c8804d3... |
| demo-history-current | Generated current demo truth snapshot for trends. | json | GithubRepoAuditor/output/demo/portfolio-truth-2026-04-12T120000Z.json | c66a09a1d3882f80... |
| demo-proposals | Generated empty automation proposal queue. | json | GithubRepoAuditor/output/demo/pending-proposals.json | 0bba03f7a1f663c2... |
| demo-warehouse | Generated demo warehouse snapshot. | sqlite | GithubRepoAuditor/output/demo/portfolio-warehouse.db | 4bd737e4d69490be... |
| verification-notes | Commands run, capture method, and public-safety review notes. | verification-notes | GithubRepoAuditor/docs/demo-proof/public-fixture/VERIFICATION-NOTES.md | 4b11f4cd33890cef... |
| website-content | Website-ready Operator OS demo content block and what-stays-private copy. | website-copy | GithubRepoAuditor/docs/demo-proof/public-fixture/WEBSITE-CONTENT.md | f10cac882dced787... |
| screenshot-ops-shell | Tauri desktop shell pointed at fixture output. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/00-ops-tauri-window.png | cfb321ed1a647acb... |
| screenshot-portfolio | Portfolio tab rendered from fixture truth. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/01-portfolio.png | 72670e0db8c6c504... |
| screenshot-risk-security | Risk and Security tab rendered from fixture truth. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/02-risk-security.png | 2e072158f210f5a8... |
| screenshot-burndown | Burndown tab rendered from fixture security burndown. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/03-burndown.png | 8e5c2d79e55e3835... |
| screenshot-trends | Trends tab rendered from fixture truth history. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/04-trends.png | 91be6db49e08179b... |
| screenshot-weekly-digest | Weekly Digest tab rendered from fixture digest. | screenshot | GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/05-weekly-digest.png | 35b300e7044896b5... |
Intentionally Excluded
Private local portfolio stateThe receipt is generated from the committed public fixture proof package, not live workstation output.
Secrets and credential valuesThe receipt records proof metadata and digests only. It does not include tokens, secret values, or credential-bearing configs.
Private services and session transcriptsThe demo proof explicitly requires no private services and does not rely on local agent transcripts.
Private source dataThe source package states that private data is not required for this proof.
Limitations
This receipt summarizes evidence from a fixture proof package. It is not a live production security certification.
Passing checks mean the named fixture claims are supported by listed evidence, not that every adjacent workflow was tested.
Artifact digests prove local file identity at generation time, not long-term availability at a public URL.
Known gap: The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.
Reproduce Or Inspect
Start from the public fixture proof package.Receipt source: GithubRepoAuditor/docs/demo-proof/public-fixture/proof-package.json
Run source project command.make demo
Run source project command.python scripts/validate_proof_package.py docs/demo-proof/public-fixture/proof-package.json
Run source project command.pnpm demo:desktop:fixture
Validate the generated receipt.trust-receipt validate --receipt samples/ghra-public-fixture-receipt.json
Payload SHA-256: 51e1631b9370137fabda065eced3b9a81931319e62509e0d88c2f181d7ed0d78
Generated by trust-receipt-generator 0.1.0
payload sha-256 · 51e1631b9370137fabda065eced3b9a81931319e62509e0d88c2f181d7ed0d78