Counter manager · connected fictional workspace
Offline & devices
Local event queue, sync, conflict, counter, hub, bridge, printer, scanner, and resilience truth.
Coverage environment · Offline & devices is enabled by a server-shaped access snapshot (permission version 6, assurance AAL2). The production API independently rejects missing, cross-domain, and out-of-scope access; this fictional preview creates no credential.
Edge command · Counter 04
Local truth → cloud truth
This screen uses deterministic fictional data and UI controls. The PWA cache, signed protocol, encrypted SQLite and PostgreSQL paths are implemented and tested, but this preview does not contact real devices, a live branch hub or production cloud.
Professional edge · Bridge C04
Certificate → allowlist → durable queue → physical result
Deterministic simulator only: the Rust bridge, signed command checks, encrypted queue, protocol encoders, revocation, update verification, and archive hashes are implemented and tested. No physical device, production certificate, installer signature, or live branch hub was contacted.
Queue · immutable journal
Event 0182 survives restart
- Device / counter
- POS-C04 / Counter 04
- Local / server time
- 09:59:58.6 / +1.4s skew
- Dependencies
- None · sequence gap 0
- Acknowledgement
- Existing ACK restored
A retry carries the same local ID, sequence, payload hash and idempotency key. A partial batch resumes from the first unresolved event; acknowledged events cannot post twice.
Conflict inbox · 5 policies
Preserve the commercial truth
Resolution appends actor, reason and evidence. It never deletes or rewrites the accepted event.
Two offline levels
Cache only what the counter needs
No unrelated tenant, full payroll, bank credential, platform secret or document archive is cached.
Branch Local Hub
Useful, never a single point of failure
- Coordination
- 3 authorised counters
- Shared deltas
- Stock · credit · loyalty · series
- Hub unavailable
- Independent durable mode
- Cloud authority
- PostgreSQL after sync
Upgrade + recovery
No event stranded between versions
- Client2.3 · 2.4
- APIv1 · v2
- Sync1 · 2
- Device runtime2.0 · 2.1
Restart reopens the encrypted journal. Device loss revokes identity, restores known acknowledgements and opens unsynced reconciliation; accepted evidence remains in cloud history.