{
  "checks": [
    {
      "evidence_refs": [
        "fixture-report"
      ],
      "id": "claim:fixture-input",
      "status": "passed",
      "summary": "The public demo source is a committed fixture file, not the private live portfolio output.",
      "title": "The public demo source is a committed fixture file, not the private live portfolio output."
    },
    {
      "evidence_refs": [
        "demo-make-target",
        "demo-build-script",
        "demo-report",
        "demo-workbook",
        "demo-dashboard",
        "demo-control-center-json",
        "demo-control-center-markdown",
        "demo-portfolio-truth",
        "demo-weekly-digest",
        "demo-security-burndown",
        "demo-history-previous",
        "demo-history-current",
        "demo-proposals",
        "demo-warehouse"
      ],
      "id": "claim:demo-generation",
      "status": "passed",
      "summary": "The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo.",
      "title": "The fixture demo command generates the JSON, workbook, dashboard, control-center, truth, and warehouse artifacts under output/demo."
    },
    {
      "evidence_refs": [
        "demo-portfolio-truth",
        "demo-weekly-digest",
        "demo-security-burndown"
      ],
      "id": "claim:desktop-compatible-schema",
      "status": "passed",
      "summary": "The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape.",
      "title": "The generated portfolio truth uses the PortfolioCommandCenter projects schema rather than the older lightweight repos demo shape."
    },
    {
      "evidence_refs": [
        "recording-checklist"
      ],
      "id": "claim:public-recording-boundary",
      "status": "passed",
      "summary": "The public recording checklist requires fixture output and blocks private local data exposure.",
      "title": "The public recording checklist requires fixture output and blocks private local data exposure."
    },
    {
      "evidence_refs": [
        "summary",
        "verification-notes",
        "screenshot-ops-shell",
        "screenshot-portfolio",
        "screenshot-risk-security",
        "screenshot-burndown",
        "screenshot-trends",
        "screenshot-weekly-digest"
      ],
      "id": "claim:visual-capture",
      "status": "passed",
      "summary": "Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces.",
      "title": "Public-safe Portfolio Command Center frames were captured from the fixture-backed desktop shell and React tab surfaces."
    },
    {
      "evidence_refs": [],
      "id": "verification:1",
      "status": "passed",
      "summary": "manifest references fixture input and generated output paths",
      "title": "manifest references fixture input and generated output paths"
    },
    {
      "evidence_refs": [],
      "id": "verification:2",
      "status": "passed",
      "summary": "visual capture from Portfolio Command Center",
      "title": "visual capture from Portfolio Command Center"
    },
    {
      "evidence_refs": [],
      "id": "known-gap:1",
      "status": "not_checked",
      "summary": "The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.",
      "title": "Known proof gap"
    }
  ],
  "evidence": [
    {
      "description": "Human-readable public fixture demo summary.",
      "digest_sha256": "15aefab56a22b6676489983470ef1ed0df3bff2b54b7e83cf9e135fb77209308",
      "id": "summary",
      "kind": "summary",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/SUMMARY.md",
      "supports": [
        "visual-capture"
      ],
      "title": "Human-readable public fixture demo summary."
    },
    {
      "description": "Public-safe recording checklist and redaction guard.",
      "digest_sha256": "6f7aea433679edd1b6aa1abb0d4ba7e4b6092d8c30ddaf521033c5316464f109",
      "id": "recording-checklist",
      "kind": "checklist",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/RECORDING-CHECKLIST.md",
      "supports": [
        "public-recording-boundary"
      ],
      "title": "Public-safe recording checklist and redaction guard."
    },
    {
      "description": "Committed fixture report used as the public demo source.",
      "digest_sha256": "be4ea286a11b1aac61b69ac01803bdd4362f48e326b40c3e74bd1b1a81b5c2a7",
      "id": "fixture-report",
      "kind": "fixture",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/fixtures/demo/sample-report.json",
      "supports": [
        "fixture-input"
      ],
      "title": "Committed fixture report used as the public demo source."
    },
    {
      "description": "Make target that runs the fixture demo generator.",
      "digest_sha256": "0f70132ce76416317e6af70dd6e4ceee6e329ac068b323c6cbc435f0a84110a0",
      "id": "demo-make-target",
      "kind": "repo-doc",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/Makefile",
      "supports": [
        "demo-generation"
      ],
      "title": "Make target that runs the fixture demo generator."
    },
    {
      "description": "Fixture artifact generator for output/demo.",
      "digest_sha256": "d16e9ce5c38aa7e90a6812cd57e55a5038365e90be0fb917913366f96783d335",
      "id": "demo-build-script",
      "kind": "script",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/scripts/build_demo_artifacts.py",
      "supports": [
        "demo-generation"
      ],
      "title": "Fixture artifact generator for output/demo."
    },
    {
      "description": "Generated demo report.",
      "digest_sha256": "12e43eb80263cbd821d345f4b43d49066a9e6a66d063490ab227ea650808bc9e",
      "id": "demo-report",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/demo-report.json",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo report."
    },
    {
      "description": "Generated demo workbook.",
      "digest_sha256": "6fb1423325b9653490f8c03e7afb7d40c9dde39400f537a5ca7bc753ab6b4e40",
      "id": "demo-workbook",
      "kind": "workbook",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/demo-workbook.xlsx",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo workbook."
    },
    {
      "description": "Generated demo HTML dashboard.",
      "digest_sha256": "dccb0be243e01f07110eea7f99f90a6e3aca7c0a2d688cae20203c83e0365122",
      "id": "demo-dashboard",
      "kind": "html",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/dashboard-sample-user-2026-04-12.html",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo HTML dashboard."
    },
    {
      "description": "Generated demo operator control-center JSON.",
      "digest_sha256": "8d38e5d131e8eb7a2d902a71594d5f60ef5f28a41d2879cd4f6a475ff725f6fc",
      "id": "demo-control-center-json",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/operator-control-center-demo.json",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo operator control-center JSON."
    },
    {
      "description": "Generated demo operator control-center Markdown.",
      "digest_sha256": "19e7ada4491552018d756e10ea9b130d5b5ea733ec275b67c8908f9ee2429a6f",
      "id": "demo-control-center-markdown",
      "kind": "markdown",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/operator-control-center-demo.md",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo operator control-center Markdown."
    },
    {
      "description": "Generated demo portfolio truth snapshot.",
      "digest_sha256": "c66a09a1d3882f807a5f81ce9cfd05876d266a069f6e8a9ae8c6332ca0d88ec5",
      "id": "demo-portfolio-truth",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/portfolio-truth-latest.json",
      "supports": [
        "demo-generation",
        "desktop-compatible-schema"
      ],
      "title": "Generated demo portfolio truth snapshot."
    },
    {
      "description": "Generated demo weekly command-center digest.",
      "digest_sha256": "df085a9acbb9ef563785e3fa3b605553b137fb8d848cd22001bbd4444f9fa45d",
      "id": "demo-weekly-digest",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/weekly-command-center-sample-user-2026-04-12.json",
      "supports": [
        "demo-generation",
        "desktop-compatible-schema"
      ],
      "title": "Generated demo weekly command-center digest."
    },
    {
      "description": "Generated demo security burndown report.",
      "digest_sha256": "7a37d3e331b23e265c4f303db1b685f04d14409862875f2098e6a535bd221795",
      "id": "demo-security-burndown",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/security-burndown-sample-user-2026-04-12.json",
      "supports": [
        "demo-generation",
        "desktop-compatible-schema"
      ],
      "title": "Generated demo security burndown report."
    },
    {
      "description": "Generated previous demo truth snapshot for trends.",
      "digest_sha256": "4037ce360c8804d3ff033c39c6fb3301dbc1c1de4f4e845db45970f6e224385b",
      "id": "demo-history-previous",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/portfolio-truth-2026-04-05T120000Z.json",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated previous demo truth snapshot for trends."
    },
    {
      "description": "Generated current demo truth snapshot for trends.",
      "digest_sha256": "c66a09a1d3882f807a5f81ce9cfd05876d266a069f6e8a9ae8c6332ca0d88ec5",
      "id": "demo-history-current",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/portfolio-truth-2026-04-12T120000Z.json",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated current demo truth snapshot for trends."
    },
    {
      "description": "Generated empty automation proposal queue.",
      "digest_sha256": "0bba03f7a1f663c2f7c8583d5b29940bea349e0e3197ead42de15cabda70aec0",
      "id": "demo-proposals",
      "kind": "json",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/pending-proposals.json",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated empty automation proposal queue."
    },
    {
      "description": "Generated demo warehouse snapshot.",
      "digest_sha256": "4bd737e4d69490be31210d1f6c472c66b81bcfac63aa4268c225bb84ddcf70a2",
      "id": "demo-warehouse",
      "kind": "sqlite",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/output/demo/portfolio-warehouse.db",
      "supports": [
        "demo-generation"
      ],
      "title": "Generated demo warehouse snapshot."
    },
    {
      "description": "Commands run, capture method, and public-safety review notes.",
      "digest_sha256": "4b11f4cd33890cef899ec30f02f24e5ce88cd7a526981b092163ac85110e5f96",
      "id": "verification-notes",
      "kind": "verification-notes",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/VERIFICATION-NOTES.md",
      "supports": [
        "visual-capture"
      ],
      "title": "Commands run, capture method, and public-safety review notes."
    },
    {
      "description": "Website-ready Operator OS demo content block and what-stays-private copy.",
      "digest_sha256": "f10cac882dced78795ee3bfc9d82177854e0e4526bb44277991fb8e0b15d24a0",
      "id": "website-content",
      "kind": "website-copy",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/WEBSITE-CONTENT.md",
      "supports": [],
      "title": "Website-ready Operator OS demo content block and what-stays-private copy."
    },
    {
      "description": "Tauri desktop shell pointed at fixture output.",
      "digest_sha256": "cfb321ed1a647acbdda54850a3697787590014a6d96b9958743b3d99b962c52c",
      "id": "screenshot-ops-shell",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/00-ops-tauri-window.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Tauri desktop shell pointed at fixture output."
    },
    {
      "description": "Portfolio tab rendered from fixture truth.",
      "digest_sha256": "72670e0db8c6c504a12087516a68ef7890f34606e3c04b73538464c37344b797",
      "id": "screenshot-portfolio",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/01-portfolio.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Portfolio tab rendered from fixture truth."
    },
    {
      "description": "Risk and Security tab rendered from fixture truth.",
      "digest_sha256": "2e072158f210f5a86e8281208458364c49cd7b9ecb977ef8c2cd3041b3dfb9dc",
      "id": "screenshot-risk-security",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/02-risk-security.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Risk and Security tab rendered from fixture truth."
    },
    {
      "description": "Burndown tab rendered from fixture security burndown.",
      "digest_sha256": "8e5c2d79e55e3835bfc4052022f7ee26de23232f7af5a738fb253fdb82305419",
      "id": "screenshot-burndown",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/03-burndown.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Burndown tab rendered from fixture security burndown."
    },
    {
      "description": "Trends tab rendered from fixture truth history.",
      "digest_sha256": "91be6db49e08179b56ac08155d919b0e5ff68806b5be552af232a8ed1f0dc731",
      "id": "screenshot-trends",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/04-trends.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Trends tab rendered from fixture truth history."
    },
    {
      "description": "Weekly Digest tab rendered from fixture digest.",
      "digest_sha256": "35b300e7044896b5b07cac58f0e82b0f8f8af645dfd4f2e9eb6653d4037384a2",
      "id": "screenshot-weekly-digest",
      "kind": "screenshot",
      "public_safe": true,
      "redaction_status": "public_fixture",
      "reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/screenshots/05-weekly-digest.png",
      "supports": [
        "visual-capture"
      ],
      "title": "Weekly Digest tab rendered from fixture digest."
    }
  ],
  "excluded_data": [
    {
      "category": "Private local portfolio state",
      "examples": [
        "raw local audit output",
        "private project names",
        "local absolute paths"
      ],
      "reason": "The receipt is generated from the committed public fixture proof package, not live workstation output."
    },
    {
      "category": "Secrets and credential values",
      "reason": "The receipt records proof metadata and digests only. It does not include tokens, secret values, or credential-bearing configs."
    },
    {
      "category": "Private services and session transcripts",
      "reason": "The demo proof explicitly requires no private services and does not rely on local agent transcripts."
    },
    {
      "category": "Private source data",
      "reason": "The source package states that private data is not required for this proof."
    }
  ],
  "freshness": {
    "age_seconds": 6523200,
    "evidence_collected_at": "2026-04-12T12:00:00+00:00",
    "generated_at": "2026-06-27T00:00:00Z",
    "notes": "Static public fixture evidence is useful for demo proof, not live production health.",
    "status": "static_fixture"
  },
  "integrity": {
    "generator": "trust-receipt-generator 0.1.0",
    "payload_sha256": "51e1631b9370137fabda065eced3b9a81931319e62509e0d88c2f181d7ed0d78",
    "source_digests": [
      {
        "digest_sha256": "15aefab56a22b6676489983470ef1ed0df3bff2b54b7e83cf9e135fb77209308",
        "id": "summary"
      },
      {
        "digest_sha256": "6f7aea433679edd1b6aa1abb0d4ba7e4b6092d8c30ddaf521033c5316464f109",
        "id": "recording-checklist"
      },
      {
        "digest_sha256": "be4ea286a11b1aac61b69ac01803bdd4362f48e326b40c3e74bd1b1a81b5c2a7",
        "id": "fixture-report"
      },
      {
        "digest_sha256": "0f70132ce76416317e6af70dd6e4ceee6e329ac068b323c6cbc435f0a84110a0",
        "id": "demo-make-target"
      },
      {
        "digest_sha256": "d16e9ce5c38aa7e90a6812cd57e55a5038365e90be0fb917913366f96783d335",
        "id": "demo-build-script"
      },
      {
        "digest_sha256": "12e43eb80263cbd821d345f4b43d49066a9e6a66d063490ab227ea650808bc9e",
        "id": "demo-report"
      },
      {
        "digest_sha256": "6fb1423325b9653490f8c03e7afb7d40c9dde39400f537a5ca7bc753ab6b4e40",
        "id": "demo-workbook"
      },
      {
        "digest_sha256": "dccb0be243e01f07110eea7f99f90a6e3aca7c0a2d688cae20203c83e0365122",
        "id": "demo-dashboard"
      },
      {
        "digest_sha256": "8d38e5d131e8eb7a2d902a71594d5f60ef5f28a41d2879cd4f6a475ff725f6fc",
        "id": "demo-control-center-json"
      },
      {
        "digest_sha256": "19e7ada4491552018d756e10ea9b130d5b5ea733ec275b67c8908f9ee2429a6f",
        "id": "demo-control-center-markdown"
      },
      {
        "digest_sha256": "c66a09a1d3882f807a5f81ce9cfd05876d266a069f6e8a9ae8c6332ca0d88ec5",
        "id": "demo-portfolio-truth"
      },
      {
        "digest_sha256": "df085a9acbb9ef563785e3fa3b605553b137fb8d848cd22001bbd4444f9fa45d",
        "id": "demo-weekly-digest"
      },
      {
        "digest_sha256": "7a37d3e331b23e265c4f303db1b685f04d14409862875f2098e6a535bd221795",
        "id": "demo-security-burndown"
      },
      {
        "digest_sha256": "4037ce360c8804d3ff033c39c6fb3301dbc1c1de4f4e845db45970f6e224385b",
        "id": "demo-history-previous"
      },
      {
        "digest_sha256": "c66a09a1d3882f807a5f81ce9cfd05876d266a069f6e8a9ae8c6332ca0d88ec5",
        "id": "demo-history-current"
      },
      {
        "digest_sha256": "0bba03f7a1f663c2f7c8583d5b29940bea349e0e3197ead42de15cabda70aec0",
        "id": "demo-proposals"
      },
      {
        "digest_sha256": "4bd737e4d69490be31210d1f6c472c66b81bcfac63aa4268c225bb84ddcf70a2",
        "id": "demo-warehouse"
      },
      {
        "digest_sha256": "4b11f4cd33890cef899ec30f02f24e5ce88cd7a526981b092163ac85110e5f96",
        "id": "verification-notes"
      },
      {
        "digest_sha256": "f10cac882dced78795ee3bfc9d82177854e0e4526bb44277991fb8e0b15d24a0",
        "id": "website-content"
      },
      {
        "digest_sha256": "cfb321ed1a647acbdda54850a3697787590014a6d96b9958743b3d99b962c52c",
        "id": "screenshot-ops-shell"
      },
      {
        "digest_sha256": "72670e0db8c6c504a12087516a68ef7890f34606e3c04b73538464c37344b797",
        "id": "screenshot-portfolio"
      },
      {
        "digest_sha256": "2e072158f210f5a86e8281208458364c49cd7b9ecb977ef8c2cd3041b3dfb9dc",
        "id": "screenshot-risk-security"
      },
      {
        "digest_sha256": "8e5c2d79e55e3835bfc4052022f7ee26de23232f7af5a738fb253fdb82305419",
        "id": "screenshot-burndown"
      },
      {
        "digest_sha256": "91be6db49e08179b56ac08155d919b0e5ff68806b5be552af232a8ed1f0dc731",
        "id": "screenshot-trends"
      },
      {
        "digest_sha256": "35b300e7044896b5b07cac58f0e82b0f8f8af645dfd4f2e9eb6653d4037384a2",
        "id": "screenshot-weekly-digest"
      }
    ]
  },
  "issued_at": "2026-06-27T00:00:00Z",
  "limitations": [
    "This receipt summarizes evidence from a fixture proof package. It is not a live production security certification.",
    "Passing checks mean the named fixture claims are supported by listed evidence, not that every adjacent workflow was tested.",
    "Artifact digests prove local file identity at generation time, not long-term availability at a public URL.",
    "Known gap: The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date."
  ],
  "producer": {
    "name": "trust-receipt-generator",
    "source_adapter": "ghra-public-proof-package",
    "source_commands": [
      "make demo",
      "python scripts/validate_proof_package.py docs/demo-proof/public-fixture/proof-package.json",
      "pnpm demo:desktop:fixture"
    ],
    "version": "0.1.0"
  },
  "public_safety": {
    "included_data_policy": "Only fixture proof metadata, public-safe paths, checks, digests, and known gaps are included.",
    "review_notes": [
      "source_data_mode=fixture",
      "redaction=fixture-only",
      "live_write_performed=False"
    ],
    "status": "public_safe_fixture"
  },
  "receipt_id": "tr_public-fixture-portfolio-command-center-demo",
  "reproduce": [
    {
      "notes": "Receipt source: GithubRepoAuditor/docs/demo-proof/public-fixture/proof-package.json",
      "step": "Start from the public fixture proof package."
    },
    {
      "command": "make demo",
      "step": "Run source project command."
    },
    {
      "command": "python scripts/validate_proof_package.py docs/demo-proof/public-fixture/proof-package.json",
      "step": "Run source project command."
    },
    {
      "command": "pnpm demo:desktop:fixture",
      "step": "Run source project command."
    },
    {
      "command": "trust-receipt validate --receipt samples/ghra-public-fixture-receipt.json",
      "step": "Validate the generated receipt."
    }
  ],
  "schema_version": "trust-receipt/v0.1",
  "subject": {
    "claim": "Portfolio Command Center can be demonstrated from fixture-backed GitHub Repo Auditor artifacts without private local operating data.",
    "name": "PortfolioCommandCenter",
    "public_reference": "GithubRepoAuditor/docs/demo-proof/public-fixture/proof-package.json",
    "type": "public-fixture-demo"
  },
  "summary": {
    "badge": {
      "color": "#b7791f",
      "label": "trust receipt",
      "message": "partial proof with gaps",
      "style": "flat"
    },
    "failed_count": 0,
    "headline": "Fixture-backed public demo proof is supported, with explicit limits.",
    "inconclusive_count": 0,
    "not_checked_count": 1,
    "passed_count": 7,
    "verdict": "mixed"
  },
  "unverified": [
    {
      "id": "known-gap:1",
      "reason": "The fixture date is intentionally static, so screenshots show the app stale-data banner when viewed after the fixture date.",
      "status": "not_checked",
      "title": "Known proof gap"
    }
  ]
}
