Period: 2026-07-17T14:01:31 → 2026-08-16T14:01:31 (UTC) · Station: unregistered · Generated: 2026-08-16T14:01:36Z
Generated locally by the station that performed these actions. Free during early access — evidence packs may become a paid feature later; your receipts and raw export remain free forever.
1005 governed actions in the period, 1002 of them Ed25519-signed. Total external spend: $100.00.
96% of workflow execution units in this period ran as local compute without consulting a model (27 of 28 units, from the sealed routing verdicts in the receipts themselves).
| COMPLETED | 524 |
| REFUSED | 114 |
| ROLLED_BACK | 60 |
| SENT | 10 |
| approved_not_executed | 46 |
| blocked_by_policy | 1 |
| credential_present_untested | 3 |
| executed | 84 |
| failed_safely | 8 |
| failed_with_receipt | 6 |
| not_configured | 1 |
| pending_approval | 109 |
| unknown | 39 |
| cli | 1 |
| mcp | 1 |
| mcp_tools_call | 1 |
| scheduler | 665 |
| session | 6 |
| studio | 23 |
| studio_mcp_gate | 6 |
| terminal_confirm | 26 |
| ui_click | 66 |
| unknown | 205 |
| vscode_chat | 3 |
| vscode_hud | 2 |
| capability_scope | 1 |
| disk_space | 1 |
| live_policy | 2 |
| plan_pin_changed | 1 |
| policy_block | 1 |
| require_human_unattended | 108 |
The station re-audited its ENTIRE receipt corpus from canonical disk bytes at generation time:
| UNSIGNED | 0 |
| UNTRUSTED_KEY | 0 |
| VERIFIED | 265 |
| VERIFIED_MOCK | 5 |
3 receipt(s) FAILED re-audit — named in manifest.json under verification.failed; a failure is reported, never hidden.
An auditor can independently re-verify any receipt at
railcall.ai/verify (runs entirely in the browser — no RailCall
server involved) or with the offline CLI verifier. The station's public key
and fingerprint are in manifest.json.
{
"apply": {
"live_workflows_enabled": false
},
"dag": {
"live_workflow_ids": [
"singleops_backlog_to_discord",
"singleops_backlog_to_google_sheet",
"single_ops_to_sheet"
],
"live_workflows_enabled": true
},
"mcp": {
"live_workflow_ids": [],
"live_workflows_enabled": true,
"module_reads_enabled": true,
"lazy_tools_enabled": true
},
"mcp_expose": {
"workflow_ids": []
},
"routing": {
"local_only": false,
"sensitive_stays_local": false
},
"guards": {
"min_free_disk_mb": 500
}
}Every change to this policy is a signed audit event; the full change history is in the station's hash-chained audit log (Studio -> Settings -> Audit chain -> Raw JSON).
| HIPAA §164.312(a)(1) Access control | Studio session tokens (0600, loopback-only), per-channel authentication (session / cli / scheduler / mcp), RBAC roles on team stations. |
| HIPAA §164.312(b) Audit controls | Every action seals an Ed25519-signed receipt; refusals are receipts too; hash-chained audit log with off-box witness anchoring. |
| HIPAA §164.312(c)(1) Integrity | Receipt integrity hashes recompute from canonical bytes; tampering with any sealed field breaks the signature (verified in this pack). |
| HIPAA §164.312(d) Person or entity authentication | Approvals bind the exact payload hash; station identity is issuer-signed; team approvals are member-key co-signed. |
| HIPAA §164.312(e)(1) Transmission security | Credentials never leave the local vault; egress passes policy + redaction gates; MCP responses are attestation-only by default. |
| SOC 2 CC6/CC7 (change & ops monitoring) | Execution-policy changes are signed events; plan pins stop drifted workflows; spend caps and freeze provide preventive controls. |
The raw receipts for this period are included under
receipts/ — the same data available through the free export on
every tier. manifest.json lists each file's sha256 and carries
the pack's own integrity hash + signature.