JPS Desk v0.7.0 introduces a critical hand-over flow designed to decouple decision history verification from the operatorβs control. By exporting checkpoints and reporting coverage limits, the update allows external reviewers to retain independent references for comparing supplier decisions. This addresses a fundamental trust gap in procurement workflows where the entity managing the data also controls the interface for viewing it.
The Mechanics of Independent Verification
The new feature, located under Admin β Project β Decision record, requires operators to register a holder and download checkpoint lines. Crucially, the system preserves the checkpoint bytes produced by Runtime and compares digests upon confirmation to prevent stale updates. A download alone does not move the holderβs cursor; only the explicit confirmation action updates the position, ensuring a precise audit trail of when data was actually validated by the external party.
Testing Coverage and Edge Cases
The integration test TestHandOverWithTheRuntime demonstrates the systemβs ability to track witnessed versus unwitnessed records. When a fourth decision record is created, the report shifts to three witnessed and one unwitnessed, only updating to four witnessed after the next checkpoint is confirmed. The tests also cover data integrity failures, such as truncating stored files or removing newlines, ensuring that damaged checkpoints are excluded from verification inputs and the affected holder is identified.
Limitations and Current Status
While PR #241 reports passing tests with Runtime 0.27.1, the author clarifies these are repository assertions, not fresh live runs. The tool explicitly states that confirmation records what the operator says happened, not proof of physical delivery or long-term retention. Additionally, the release notes list specific limitations, including issues with two Desk processes sharing a project and undefined behavior on macOS and Windows, warning users not to assume cross-platform validation.
Key Takeaways
- JPS Desk v0.7.0 enables external holders to retain independent checkpoint copies for procurement reviews.
- The system uses digest comparisons to reject stale confirmations, ensuring data integrity during hand-overs.
- Integration tests verify coverage reporting but do not yet validate cross-platform behavior on macOS and Windows.
- Confirmation logs operator intent, not physical delivery, meaning independent custody relies on the holderβs retention practices.
The Bottom Line
This update is a necessary step toward auditability, but it remains a trust-based mechanism rather than a cryptographic guarantee. Until external retention policies are enforced, the integrity of the hand-over still depends on the holderβs discipline, not just the toolβs code.