Legal businessAster Retail Pvt LtdGSTIN29AABCU9603R1ZJBranch / locationIndiranagar · Retail floorWorkspace roleBusiness owner

Counter manager · connected fictional workspace

Offline & devices

Local event queue, sync, conflict, counter, hub, bridge, printer, scanner, and resilience truth.

Coverage environment · Offline & devices is enabled by a server-shaped access snapshot (permission version 6, assurance AAL2). The production API independently rejects missing, cross-domain, and out-of-scope access; this fictional preview creates no credential.

Edge command · Counter 04

Local truth → cloud truth

ConnectionCloud online
Offline leaseValid · policy v4 · 5h 42m
Authoritative sync09:42:18 · cursor 2,841
Durable local queue0 events · lag 0s
01Local commitSQLCipher / IndexedDBSequence 0182 · signed
02Branch edgeHub reachableCounter can still finalise
03Cloud acceptanceAcknowledged through 0181Duplicate-safe · gap-aware
04Business effectsEffect receipts uniqueInvoice · stock · books · loyalty

This screen uses deterministic fictional data and UI controls. The PWA cache, signed protocol, encrypted SQLite and PostgreSQL paths are implemented and tested, but this preview does not contact real devices, a live branch hub or production cloud.

Professional edge · Bridge C04

Certificate → allowlist → durable queue → physical result

CertificateSHA-256 7e41…c09aTenant / Branch 01 / Counter 04 bound
Local API9 typed commandsNo shell · path · arbitrary URL
SQLCipher queue0 waitingRestart-safe · bounded retry
Bridge stateHealthy · v2.1.0Loopback only
Barcode scannerKeyboard wedge
ready
80 mm thermalESC/POS · cut · drawer · status
ready
A4 printerServer PDF · system spool
ready
Label printerZPL · PDF fallback
ready
Cash drawerESC p pulse · reason required
ready
Weighing scaleSerial stable-weight read
ready
Customer display2-line local update
ready
Biometric terminalMapped punch events only
ready
Label protocol
Formal archiveA4 · GST-A4 v4 · PDF SHA-256 c84d…3f10Data + tax + template + generation time frozen

Deterministic simulator only: the Rust bridge, signed command checks, encrypted queue, protocol encoders, revocation, update verification, and archive hashes are implemented and tested. No physical device, production certificate, installer signature, or live branch hub was contacted.

Queue · immutable journal

Event 0182 survives restart

Already processedEVT-C04-0182 · estimate.savedIdempotency offline-idem-…0182 · payload v2
Device / counter
POS-C04 / Counter 04
Local / server time
09:59:58.6 / +1.4s skew
Dependencies
None · sequence gap 0
Acknowledgement
Existing ACK restored

A retry carries the same local ID, sequence, payload hash and idempotency key. A partial batch resumes from the first unresolved event; acknowledged events cannot post twice.

Conflict inbox · 5 policies

Preserve the commercial truth

Stock shortage · auto-reconcile
Local intentFinal invoice INV/26-27/001842 · customer served
Server truthFloor stock is −5 PCS after cloud acceptance
Controlled outcomeInvoice preserved · negative ledger · alert + transfer suggestion

Resolution appends actor, reason and evidence. It never deletes or rewrites the accepted event.

Two offline levels

Cache only what the counter needs

PWA · lighter counterService worker shell · AES-GCM IndexedDB · basic sale / estimate
POS Companion · long-durationTauri 2 / Rust · per-device SQLCipher · WAL + full sync journal

No unrelated tenant, full payroll, bank credential, platform secret or document archive is cached.

Branch Local Hub

Useful, never a single point of failure

Coordination
3 authorised counters
Shared deltas
Stock · credit · loyalty · series
Hub unavailable
Independent durable mode
Cloud authority
PostgreSQL after sync

Upgrade + recovery

No event stranded between versions

  • Client2.3 · 2.4
  • APIv1 · v2
  • Sync1 · 2
  • Device runtime2.0 · 2.1

Restart reopens the encrypted journal. Device loss revokes identity, restores known acknowledgements and opens unsynced reconciliation; accepted evidence remains in cloud history.