Proposal: A ledger record for refused actions (RFP 27, Security Monitoring, Auditability and Evidence)
Development Fund Proposal Submission
Proposal file:
proposals/2026-09-Independent-refusal-evidence-for-canton.md
Applicant
Organization: Individual
Author / Primary Contact: Rume Dominic (O'Rume Dominic Uririe), dominicrume@gmail.com, github.com/dominicrume
Champion: Needs Champion
Proposal Classification
Proposal Type:
- RFP-aligned proposal
- Individual initiative
RFP / Roadmap Area: RFP 27, Security Monitoring, Auditability and Evidence
Label: rfp-27:security-monitoring
Funding & Timeline
Total Funding Request: 300,000 CC
Project Duration: 16 weeks
Maximum Amount: N/A
Maximum Duration: N/A
Checklist
- RFP-aligned proposal
- Champion identified or
Needs Championselected - RFP / roadmap alignment identified, if applicable
- Proposal is within any RFP maximum amount
- Proposal is within any RFP maximum duration
The problem, in one paragraph
Canton keeps no artefact of an action a rule stopped. A failed assertMsg
aborts the transaction, so after a refused action the ledger looks exactly as
it would if the application had never tried. What settled is corroborated by
the ledger. What was refused exists only in the application's own logs, written
by the operator, about the operator. That is the half a supervisor asks about.
RFP 27 asks for audit trails and compliance evidence while preserving Canton's privacy model, with privacy, access controls and selective disclosure handled explicitly. This proposal is all four.
What already exists, before any funding
canton-refusal-record1.0.0, a Daml package with no dependencies beyonddaml-primanddaml-stdlib. A refusal becomes a committed transaction; an auditor named in advance observes it and nobody else does.- A record format with a written specification and 20 conformance vectors, implemented three times independently in Python, JavaScript and Go, all agreeing.
- A disclosure format that hands over the refusals without the accepted transactions, where nothing can be removed from what the reader is shown.
- A browser verifier needing no wallet, no install and no network.
- 111 Daml test scripts and 82 mutations, each of which breaks something real and requires a named test to go red.
Credit
The on-ledger pattern was named RejectedAttempt by Federico_Rodriguez, a
Canton Community Tech Partner, on
forum.canton.network/t/9114. He read the
design, identified that application-written receipts cannot prove completeness,
and specified the fix. It was built the next day and he is credited in the
source.
What it does not do, stated here rather than discovered later
An attempt never submitted leaves nothing behind. This makes a refusal that happened impossible to invent, delete, backdate or reorder. It does not make one that never reached the ledger appear, and no ledger artefact can.