Trust Receipt trust receiptpartial proof with gaps

PortfolioCommandCenter

Portfolio Command Center can be demonstrated from fixture-backed GitHub Repo Auditor artifacts without private local operating data.

Verdict
mixed
Fixture-backed public demo proof is supported, with explicit limits.
Freshness
static_fixture
2026-04-12T12:00:00+00:00
Checks
8
7 passed, 0 failed, 1 not checked, 0 inconclusive
Receipt ID
tr_public-fixture-portfolio-command-center-demo
2026-06-27T00:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Not Checked

Known proof gap
not checked
The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.
no direct evidence reference

Passed

The public demo source is a committed fixture file, not the private live portfolio output.
passed
The public demo source is a committed fixture file, not the private live portfolio output.
fixture-report
The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo.
passed
The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo.
demo-make-target, demo-build-script, demo-report, demo-workbook, demo-dashboard, demo-control-center-json, demo-control-center-markdown, demo-portfolio-truth, demo-weekly-digest, demo-security-burndown, demo-history-previous, demo-history-current, demo-proposals, demo-warehouse
The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape.
passed
The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape.
demo-portfolio-truth, demo-weekly-digest, demo-security-burndown
The public recording checklist requires fixture output and blocks private local data exposure.
passed
The public recording checklist requires fixture output and blocks private local data exposure.
recording-checklist
Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces.
passed
Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces.
summary, verification-notes, screenshot-ops-shell, screenshot-portfolio, screenshot-risk-security, screenshot-burndown, screenshot-trends, screenshot-weekly-digest
manifest references fixture input and generated output paths
passed
manifest references fixture input and generated output paths
no direct evidence reference
visual capture from Portfolio Command Center
passed
visual capture from Portfolio Command Center
no direct evidence reference

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

IDTitleKindReferenceDigest
summaryHuman-readable public fixture demo summary.summaryGithubRepoAuditor/docs/demo-proof/public-fixture/SUMMARY.md15aefab56a22b667...
recording-checklistPublic-safe recording checklist and redaction guard.checklistGithubRepoAuditor/docs/demo-proof/public-fixture/RECORDING-CHECKLIST.md6f7aea433679edd1...
fixture-reportCommitted fixture report used as the public demo source.fixtureGithubRepoAuditor/fixtures/demo/sample-report.jsonbe4ea286a11b1aac...
demo-make-targetMake target that runs the fixture demo generator.repo-docGithubRepoAuditor/Makefile0f70132ce7641631...
demo-build-scriptFixture artifact generator for output/demo.scriptGithubRepoAuditor/scripts/build_demo_artifacts.pyd16e9ce5c38aa7e9...
demo-reportGenerated demo report.jsonGithubRepoAuditor/output/demo/demo-report.json12e43eb80263cbd8...
demo-workbookGenerated demo workbook.workbookGithubRepoAuditor/output/demo/demo-workbook.xlsx6fb1423325b96534...
demo-dashboardGenerated demo HTML dashboard.htmlGithubRepoAuditor/output/demo/dashboard-sample-user-2026-04-12.htmldccb0be243e01f07...
demo-control-center-jsonGenerated demo operator control-center JSON.jsonGithubRepoAuditor/output/demo/operator-control-center-demo.json8d38e5d131e8eb7a...
demo-control-center-markdownGenerated demo operator control-center Markdown.markdownGithubRepoAuditor/output/demo/operator-control-center-demo.md19e7ada449155201...
demo-portfolio-truthGenerated demo portfolio truth snapshot.jsonGithubRepoAuditor/output/demo/portfolio-truth-latest.jsonc66a09a1d3882f80...
demo-weekly-digestGenerated demo weekly command-center digest.jsonGithubRepoAuditor/output/demo/weekly-command-center-sample-user-2026-04-12.jsondf085a9acbb9ef56...
demo-security-burndownGenerated demo security burndown report.jsonGithubRepoAuditor/output/demo/security-burndown-sample-user-2026-04-12.json7a37d3e331b23e26...
demo-history-previousGenerated previous demo truth snapshot for trends.jsonGithubRepoAuditor/output/demo/portfolio-truth-2026-04-05T120000Z.json4037ce360c8804d3...
demo-history-currentGenerated current demo truth snapshot for trends.jsonGithubRepoAuditor/output/demo/portfolio-truth-2026-04-12T120000Z.jsonc66a09a1d3882f80...
demo-proposalsGenerated empty automation proposal queue.jsonGithubRepoAuditor/output/demo/pending-proposals.json0bba03f7a1f663c2...
demo-warehouseGenerated demo warehouse snapshot.sqliteGithubRepoAuditor/output/demo/portfolio-warehouse.db4bd737e4d69490be...
verification-notesCommands run, capture method, and public-safety review notes.verification-notesGithubRepoAuditor/docs/demo-proof/public-fixture/VERIFICATION-NOTES.md4b11f4cd33890cef...
website-contentWebsite-ready Operator OS demo content block and what-stays-private copy.website-copyGithubRepoAuditor/docs/demo-proof/public-fixture/WEBSITE-CONTENT.mdf10cac882dced787...
screenshot-ops-shellTauri desktop shell pointed at fixture output.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/00-ops-tauri-window.pngcfb321ed1a647acb...
screenshot-portfolioPortfolio tab rendered from fixture truth.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/01-portfolio.png72670e0db8c6c504...
screenshot-risk-securityRisk and Security tab rendered from fixture truth.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/02-risk-security.png2e072158f210f5a8...
screenshot-burndownBurndown tab rendered from fixture security burndown.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/03-burndown.png8e5c2d79e55e3835...
screenshot-trendsTrends tab rendered from fixture truth history.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/04-trends.png91be6db49e08179b...
screenshot-weekly-digestWeekly Digest tab rendered from fixture digest.screenshotGithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/05-weekly-digest.png35b300e7044896b5...

Intentionally Excluded

Private local portfolio state
The receipt is generated from the committed public fixture proof package, not live workstation output.
Secrets and credential values
The receipt records proof metadata and digests only. It does not include tokens, secret values, or credential-bearing configs.
Private services and session transcripts
The demo proof explicitly requires no private services and does not rely on local agent transcripts.
Private source data
The source package states that private data is not required for this proof.

Limitations

This receipt summarizes evidence from a fixture proof package. It is not a live production security certification.
Passing checks mean the named fixture claims are supported by listed evidence, not that every adjacent workflow was tested.
Artifact digests prove local file identity at generation time, not long-term availability at a public URL.
Known gap: The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.

Reproduce Or Inspect

Start from the public fixture proof package.
Receipt source: GithubRepoAuditor/docs/demo-proof/public-fixture/proof-package.json
Run source project command.
make demo
Run source project command.
python scripts/validate_proof_package.py docs/demo-proof/public-fixture/proof-package.json
Run source project command.
pnpm demo:desktop:fixture
Validate the generated receipt.
trust-receipt validate --receipt samples/ghra-public-fixture-receipt.json