Insurance · Fictional receipt
Misdirected presentation revoked before operational use
A corrected eligibility result may be shown only to the intended coverage reviewer for the named purpose.
- Recipient
- Fictional Clearfield Coverage Review Unit
- Purpose
- Correct one coverage review after revoking a misdirected presentation
- Expires
- 2026-09-02T15:20:00Z
- Human owner
- Fictional Insurance Standing Recovery Officer
- Replay limit
- 1 use
- Original stigma shown?
- No
What authorizes recovery?
Correction lineage
The portable claim is not a free-standing character certificate. It is anchored to the exact contest, remedy, and independent non-recurrence records that precede it.
What may the recipient rely on?
A correction, not an identity.
Bounded recovery claim
A corrected eligibility result may be shown only to the intended coverage reviewer for the named purpose.
Subject reference: pairwise:400f5204ac14bc050bcf2c2f
What this does not establish
- General character
- Future conduct
- Cross-context eligibility
- A permanent innocence or clearance status
Where is use allowed?
Five bindings prevent a correction from becoming a roaming credential.
to
2026-09-02T15:20:00Z
What crosses the boundary?
Selective disclosure
The recipient receives the minimum correction facts necessary for the named decision. The original stigma and unrelated evidence stay out of the presentation.
Disclosed
- The corrected eligibility state
- The first presentation was revoked before use
- A replacement presentation has a new pairwise reference
Withheld
- The original stigma
- Medical narrative
- The unintended recipient identity
- A reusable subject identifier
Can a person decline?
Refusal cannot become evidence against the person.
Accountable owner
Fictional standing-recovery ombudsperson · Purpose-bound human review request
How far did recovery travel?
Federated result: Revoked
Coverage is limited to the explicitly named participants and purpose.
May retain: presentation_receipt_hash, purpose_binding, expiry. Must not retain: original_stigma, cross_context_person_identifier, undisclosed_evidence.
May retain: presentation_receipt_hash, purpose_binding, expiry. Must not retain: original_stigma, cross_context_person_identifier, undisclosed_evidence.
Can presentations be joined into a dossier?
Anti-linkability checks
Required protections
- Pairwise recipient reference
- No stable cross-context identifier
- No global cleared-person registry
- No cross-recipient replay
- No correlation by receipt hash or ID
Checked surfaces
- Visible fields and URLs
- Hashes, timestamps, and filenames
- Accessibility labels and metadata
- Print output and structured data
- CSS classes and HTML attributes
What remains unresolved?
Limits remain part of the receipt.
- Revocation does not prove the first endpoint never cached transport metadata
- The replacement cannot be replayed by the first endpoint
- No cross-recipient correlation key is disclosed
Can the claim be inspected?
Machine-readable record and integrity
These fictional demonstrations expose their contract, state model, presentation rules, predecessor lineage, and deterministic hashes. Technical material is available without dominating the affected person’s reading path.
Integrity hashes
- Input SHA-256
- 52b1df0293bbb3f59ea6a7b6e3a20df963d6ad5e30fd13b0c07f6aa7a58ecc2e
- Output SHA-256
- c7626bb1af62295ab3e8a0c06ebc9c330893bd4dd7c20a0aa1a43f094bc43377
- Receipt SHA-256
- 3ab5f3462958be624145b3718334ecf9813b3173ae1bc3d362a07683cd7b5a6d
Complete fictional receipt
{
"accountability": {
"audit_owner": "Fictional independent portability auditor",
"human_owner": "Fictional Insurance Standing Recovery Officer",
"issuer": "Fictional Antichrist.cx Accountability Laboratory",
"recipient_owner": "Fictional Clearfield Coverage Review Unit human review lead"
},
"anti_linkability": {
"accessibility_labels_contain_subject_identifier": false,
"correlation_by_hash_prohibited": true,
"correlation_by_receipt_id_prohibited": true,
"correlation_by_timestamp_reduced": true,
"css_or_dom_contains_subject_identifier": false,
"global_subject_registry": false,
"pairwise_recipient_reference": true,
"print_output_contains_hidden_subject_identifier": false,
"public_url_contains_subject_identifier": false,
"stable_cross_context_identifier": false,
"structured_data_contains_subject_identifier": false
},
"domain": "insurance",
"federation": {
"coverage_statement": "Coverage is limited to the explicitly named participants and purpose.",
"participants": [
{
"acknowledged_at": "2026-08-30T15:20:00Z",
"may_retain": [
"presentation_receipt_hash",
"purpose_binding",
"expiry"
],
"must_not_retain": [
"original_stigma",
"cross_context_person_identifier",
"undisclosed_evidence"
],
"name": "Misdirected endpoint",
"participant_id": "SRP-R47-005-FED-01",
"state": "revocation_acknowledged"
},
{
"acknowledged_at": "2026-08-30T15:20:00Z",
"may_retain": [
"presentation_receipt_hash",
"purpose_binding",
"expiry"
],
"must_not_retain": [
"original_stigma",
"cross_context_person_identifier",
"undisclosed_evidence"
],
"name": "Clearfield review unit",
"participant_id": "SRP-R47-005-FED-02",
"state": "replacement_accepted"
}
],
"status": "revoked",
"unrepresented_as_complete": false
},
"fictional": true,
"fictional_notice": "Synthetic accountable-design demonstration. No real person, institution, allegation, credential, or event is represented.",
"integrity": {
"input_sha256": "52b1df0293bbb3f59ea6a7b6e3a20df963d6ad5e30fd13b0c07f6aa7a58ecc2e",
"output_sha256": "c7626bb1af62295ab3e8a0c06ebc9c330893bd4dd7c20a0aa1a43f094bc43377",
"receipt_sha256": "3ab5f3462958be624145b3718334ecf9813b3173ae1bc3d362a07683cd7b5a6d"
},
"limits": [
"Revocation does not prove the first endpoint never cached transport metadata",
"The replacement cannot be replayed by the first endpoint",
"No cross-recipient correlation key is disclosed"
],
"lineage": {
"contestability": {
"receipt_id": "CTR-R44-005",
"receipt_sha256": "e79340f03aacd9390247d23f050c7a1d9da4c13ee48712697dd890192d99707e"
},
"lineage_complete": true,
"non_recurrence": {
"receipt_id": "NRV-R46-005",
"receipt_sha256": "b61d1bacdbfb8e629f67265fe0650dc59056b303951e9a7c961c01b9b651def1"
},
"remedy": {
"receipt_id": "RMR-R45-005",
"receipt_sha256": "83c70ff919f62bdc52d3a03776c617f6edf4bfcd605dfe44bf5ce596af390b53"
}
},
"presentation": {
"audience_binding_sha256": "2f43654c1ad865b9182a19e5a37e11c0f49d9db1bcce5fcad9752888342bb550",
"cross_recipient_replay_permitted": false,
"expires_at": "2026-09-02T15:20:00Z",
"issued_at": "2026-08-30T15:20:00Z",
"one_time": true,
"presentation_id": "PRS-8929CE1AB89A3563334C",
"presentation_status": "presentation_revoked",
"purpose": "Correct one coverage review after revoking a misdirected presentation",
"recipient": "Fictional Clearfield Coverage Review Unit",
"replay_limit": 1,
"revocable": true,
"revocation_reference": "/standing-recovery/receipt?id=SRP-R47-005"
},
"receipt_id": "SRP-R47-005",
"recovery_claim": {
"claim_type": "narrow_correction",
"disclosed_facts": [
"The corrected eligibility state",
"The first presentation was revoked before use",
"A replacement presentation has a new pairwise reference"
],
"does_not_establish": [
"General character",
"Future conduct",
"Cross-context eligibility",
"A permanent innocence or clearance status"
],
"plain_language": "A corrected eligibility result may be shown only to the intended coverage reviewer for the named purpose.",
"subject_reference": "pairwise:400f5204ac14bc050bcf2c2f",
"universal_person_identifier": null,
"withheld_facts": [
"The original stigma",
"Medical narrative",
"The unintended recipient identity",
"A reusable subject identifier"
]
},
"refusal_and_non_retaliation": {
"adverse_inference_from_refusal_prohibited": true,
"complaint_channel": "Purpose-bound human review request",
"equivalent_human_review_available": true,
"presentation_voluntary": true,
"refusal_permitted": true,
"retaliation_owner": "Fictional standing-recovery ombudsperson"
},
"release": "R47",
"role_views": {
"affected_person": {
"priority_fields": [
"recovery_claim",
"presentation",
"refusal_and_non_retaliation",
"federation"
],
"question": "What narrow correction can I present, what stays private, and what happens if I decline?"
},
"auditor": {
"priority_fields": [
"anti_linkability",
"refusal_and_non_retaliation",
"federation",
"integrity"
],
"question": "Can recipients correlate presentations, retaliate for refusal, or overstate federation coverage?"
},
"issuer": {
"priority_fields": [
"lineage",
"selective_disclosure",
"anti_linkability",
"accountability"
],
"question": "How do I issue a useful correction without creating a portable identity score?"
},
"recipient": {
"priority_fields": [
"presentation",
"recovery_claim",
"limits",
"revocation"
],
"question": "What may I rely on, for which purpose, until when, and what must I not infer?"
}
},
"schema": "antichrist.cx.standing-recovery-portability-receipt.v1",
"selective_disclosure": {
"disclosed_fields": [
"receipt_id",
"status",
"recovery_claim.plain_language",
"presentation.recipient",
"presentation.purpose",
"presentation.expires_at",
"accountability.human_owner"
],
"minimum_necessary": true,
"original_stigma_disclosed": false,
"private_evidence_disclosed": false,
"withheld_fields": [
"recovery_claim.withheld_facts",
"lineage source payloads",
"private evidence",
"cross-context identifiers"
]
},
"status": "presentation_revoked",
"title": "Misdirected presentation revoked before operational use"
}Public design limits
This interface demonstrates an accountable design boundary. It is not legal advice, an identity system, a production credential, proof that a real institution uses these practices, or evidence that selective disclosure alone resolves every power imbalance.