Skip to content
CCPEDIAby Unity Nodes
#860Incoming Pull Request300K CC requested

Proposal: A ledger record for refused actions (RFP 27, Security Monitoring, Auditability and Evidence)

dominicrume27-09-2026Last activity 3d ago
regulatory-compliancerfp-11:public-verifiabilityrfp-12:rwa-standardsrfp-22:daml-securityrfp-26:key-management-signingrfp-27:security-monitoring

Development Fund Proposal Submission

Proposal file: proposals/2026-09-Independent-refusal-evidence-for-canton.md

Applicant

Organization: Individual

Author / Primary Contact: Rume Dominic (O'Rume Dominic Uririe), dominicrume@gmail.com, github.com/dominicrume

Champion: Needs Champion


Proposal Classification

Proposal Type:

  • RFP-aligned proposal
  • Individual initiative

RFP / Roadmap Area: RFP 27, Security Monitoring, Auditability and Evidence

Label: rfp-27:security-monitoring


Funding & Timeline

Total Funding Request: 300,000 CC

Project Duration: 16 weeks

Maximum Amount: N/A

Maximum Duration: N/A


Checklist

  • RFP-aligned proposal
  • Champion identified or Needs Champion selected
  • RFP / roadmap alignment identified, if applicable
  • Proposal is within any RFP maximum amount
  • Proposal is within any RFP maximum duration

The problem, in one paragraph

Canton keeps no artefact of an action a rule stopped. A failed assertMsg aborts the transaction, so after a refused action the ledger looks exactly as it would if the application had never tried. What settled is corroborated by the ledger. What was refused exists only in the application's own logs, written by the operator, about the operator. That is the half a supervisor asks about.

RFP 27 asks for audit trails and compliance evidence while preserving Canton's privacy model, with privacy, access controls and selective disclosure handled explicitly. This proposal is all four.

What already exists, before any funding

  • canton-refusal-record 1.0.0, a Daml package with no dependencies beyond daml-prim and daml-stdlib. A refusal becomes a committed transaction; an auditor named in advance observes it and nobody else does.
  • A record format with a written specification and 20 conformance vectors, implemented three times independently in Python, JavaScript and Go, all agreeing.
  • A disclosure format that hands over the refusals without the accepted transactions, where nothing can be removed from what the reader is shown.
  • A browser verifier needing no wallet, no install and no network.
  • 111 Daml test scripts and 82 mutations, each of which breaks something real and requires a named test to go red.

Credit

The on-ledger pattern was named RejectedAttempt by Federico_Rodriguez, a Canton Community Tech Partner, on forum.canton.network/t/9114. He read the design, identified that application-written receipts cannot prove completeness, and specified the fix. It was built the next day and he is credited in the source.

What it does not do, stated here rather than discovered later

An attempt never submitted leaves nothing behind. This makes a refusal that happened impossible to invent, delete, backdate or reorder. It does not make one that never reached the ledger appear, and no ledger artefact can.

← Back to Proposals