receipt · PortfolioCommandCenter

reading room · 992 words · 4 min

PortfolioCommandCenter

Trust receipt for PortfolioCommandCenter: Fixture-backed public demo proof is supported, with explicit limits. Includes checks, evidence, exclusions, freshness, and limitations.

Trust Receipt

trust receipt partial proof with gaps

Portfolio Command Center can be demonstrated from fixture-backed GitHub Repo Auditor artifacts without private local operating data.

Verdict

mixed Fixture-backed public demo proof is supported, with explicit limits.

Freshness

static_fixture 2026-04-12T12:00:00+00:00

Checks

8 7 passed, 0 failed, 1 not checked, 0 inconclusive

Receipt ID

tr_public-fixture-portfolio-command-center-demo 2026-06-27T00:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Not Checked

  • Known proof gap not checked

  • The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.

  • no direct evidence reference

Passed

  • The public demo source is a committed fixture file, not the private live portfolio output. passed

  • The public demo source is a committed fixture file, not the private live portfolio output.

  • fixture-report

  • The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo. passed

  • The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo.

  • demo-make-target, demo-build-script, demo-report, demo-workbook, demo-dashboard, demo-control-center-json, demo-control-center-markdown, demo-portfolio-truth, demo-weekly-digest, demo-security-burndown, demo-history-previous, demo-history-current, demo-proposals, demo-warehouse

  • The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape. passed

  • The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape.

  • demo-portfolio-truth, demo-weekly-digest, demo-security-burndown

  • The public recording checklist requires fixture output and blocks private local data exposure. passed

  • The public recording checklist requires fixture output and blocks private local data exposure.

  • recording-checklist

  • Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces. passed

  • Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces.

  • summary, verification-notes, screenshot-ops-shell, screenshot-portfolio, screenshot-risk-security, screenshot-burndown, screenshot-trends, screenshot-weekly-digest

  • manifest references fixture input and generated output paths passed

  • manifest references fixture input and generated output paths

  • no direct evidence reference

  • visual capture from Portfolio Command Center passed

  • visual capture from Portfolio Command Center

  • no direct evidence reference

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

ID Title Kind Reference Digest
summary Human-readable public fixture demo summary. summary GithubRepoAuditor/docs/demo-proof/public-fixture/SUMMARY.md 15aefab56a22b667...
recording-checklist Public-safe recording checklist and redaction guard. checklist GithubRepoAuditor/docs/demo-proof/public-fixture/RECORDING-CHECKLIST.md 6f7aea433679edd1...
fixture-report Committed fixture report used as the public demo source. fixture GithubRepoAuditor/fixtures/demo/sample-report.json be4ea286a11b1aac...
demo-make-target Make target that runs the fixture demo generator. repo-doc GithubRepoAuditor/Makefile 0f70132ce7641631...
demo-build-script Fixture artifact generator for output/demo. script GithubRepoAuditor/scripts/build_demo_artifacts.py d16e9ce5c38aa7e9...
demo-report Generated demo report. json GithubRepoAuditor/output/demo/demo-report.json 12e43eb80263cbd8...
demo-workbook Generated demo workbook. workbook GithubRepoAuditor/output/demo/demo-workbook.xlsx 6fb1423325b96534...
demo-dashboard Generated demo HTML dashboard. html GithubRepoAuditor/output/demo/dashboard-sample-user-2026-04-12.html dccb0be243e01f07...
demo-control-center-json Generated demo operator control-center JSON. json GithubRepoAuditor/output/demo/operator-control-center-demo.json 8d38e5d131e8eb7a...
demo-control-center-markdown Generated demo operator control-center Markdown. markdown GithubRepoAuditor/output/demo/operator-control-center-demo.md 19e7ada449155201...
demo-portfolio-truth Generated demo portfolio truth snapshot. json GithubRepoAuditor/output/demo/portfolio-truth-latest.json c66a09a1d3882f80...
demo-weekly-digest Generated demo weekly command-center digest. json GithubRepoAuditor/output/demo/weekly-command-center-sample-user-2026-04-12.json df085a9acbb9ef56...
demo-security-burndown Generated demo security burndown report. json GithubRepoAuditor/output/demo/security-burndown-sample-user-2026-04-12.json 7a37d3e331b23e26...
demo-history-previous Generated previous demo truth snapshot for trends. json GithubRepoAuditor/output/demo/portfolio-truth-2026-04-05T120000Z.json 4037ce360c8804d3...
demo-history-current Generated current demo truth snapshot for trends. json GithubRepoAuditor/output/demo/portfolio-truth-2026-04-12T120000Z.json c66a09a1d3882f80...
demo-proposals Generated empty automation proposal queue. json GithubRepoAuditor/output/demo/pending-proposals.json 0bba03f7a1f663c2...
demo-warehouse Generated demo warehouse snapshot. sqlite GithubRepoAuditor/output/demo/portfolio-warehouse.db 4bd737e4d69490be...
verification-notes Commands run, capture method, and public-safety review notes. verification-notes GithubRepoAuditor/docs/demo-proof/public-fixture/VERIFICATION-NOTES.md 4b11f4cd33890cef...
website-content Website-ready Operator OS demo content block and what-stays-private copy. website-copy GithubRepoAuditor/docs/demo-proof/public-fixture/WEBSITE-CONTENT.md f10cac882dced787...
screenshot-ops-shell Tauri desktop shell pointed at fixture output. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/00-ops-tauri-window.png cfb321ed1a647acb...
screenshot-portfolio Portfolio tab rendered from fixture truth. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/01-portfolio.png 72670e0db8c6c504...
screenshot-risk-security Risk and Security tab rendered from fixture truth. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/02-risk-security.png 2e072158f210f5a8...
screenshot-burndown Burndown tab rendered from fixture security burndown. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/03-burndown.png 8e5c2d79e55e3835...
screenshot-trends Trends tab rendered from fixture truth history. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/04-trends.png 91be6db49e08179b...
screenshot-weekly-digest Weekly Digest tab rendered from fixture digest. screenshot GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/05-weekly-digest.png 35b300e7044896b5...

Intentionally Excluded

Private local portfolio stateThe receipt is generated from the committed public fixture proof package, not live workstation output.

Secrets and credential valuesThe receipt records proof metadata and digests only. It does not include tokens, secret values, or credential-bearing configs.

Private services and session transcriptsThe demo proof explicitly requires no private services and does not rely on local agent transcripts.

Private source dataThe source package states that private data is not required for this proof.

Limitations

This receipt summarizes evidence from a fixture proof package. It is not a live production security certification.

Passing checks mean the named fixture claims are supported by listed evidence, not that every adjacent workflow was tested.

Artifact digests prove local file identity at generation time, not long-term availability at a public URL.

Known gap: The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.

Reproduce Or Inspect

Start from the public fixture proof package.Receipt source: GithubRepoAuditor/docs/demo-proof/public-fixture/proof-package.json

Run source project command.make demo

Run source project command.python scripts/validate_proof_package.py docs/demo-proof/public-fixture/proof-package.json

Run source project command.pnpm demo:desktop:fixture

Validate the generated receipt.trust-receipt validate --receipt samples/ghra-public-fixture-receipt.json

Payload SHA-256: 51e1631b9370137fabda065eced3b9a81931319e62509e0d88c2f181d7ed0d78

Generated by trust-receipt-generator 0.1.0

payload sha-256 · 51e1631b9370137fabda065eced3b9a81931319e62509e0d88c2f181d7ed0d78