ZoikoDigital
Evidence Ledger

Keep every workforce-record change connected to its evidence.

One record, every material change — source event, deterministic classification, worker correction, authorized review, approval, release, acknowledgment, and reconciliation, connected and attributable from end to end.

Record REC-88214-A

v4 · Approved

Source status

Verified

Policy / version

Break & Rest v3.2

Current use

Payroll reference

Source event captured

Aug 4, 2026 · 07:02 PDT

Classified against policy v3.2

Aug 4, 2026 · 07:02 PDT

Correction submitted by worker

Aug 5, 2026 · 09:14 PDT

Approved by reviewer

Aug 6, 2026 · 14:40 PDT

Release & receipt pending

Awaiting downstream acknowledgment

2 evidence available1 restricted
Attributable history, not a raw activity feedHuman review stays humanVersion continuity, never silent overwriteGoverned export, not a log dump
Ledger vs. Activity Log

Material history, not a raw telemetry feed.

An activity log records everything that happened. The Evidence Ledger records what changed, why, and what it connects to — and says plainly what it can't show.

Raw activity log

  • Every raw signal, regardless of materiality
  • Flat, chronological, disconnected entries
  • No linkage to evidence or policy context
  • Corrections often overwrite silently

Evidence Ledger

  • Material lifecycle transitions only
  • Object linkage across record, version, evidence, decision
  • Evidence context and availability shown explicitly
  • Corrections create linked history, never overwrite
RecordVersionEvidenceDecisionPackageReconciliation

Persistent limitation

The ledger explains what changed and why it's connected — it is not a completeness guarantee, a legal-admissibility claim, or proof of correctness. This applies everywhere in the product, not just here.

Evidence-Continuity Lifecycle

One record, eight connected stages.

Late events, conflicts, and withdrawn evidence are shown as part of the record — not smoothed into a falsely clean timeline.

1

Source

Material event

Clock-in captured

Actor

Time capture service

2

Validate & Contextualize

Material event

Location & device confirmed

State

Contextualized

3

Classify

Material event

Matched to policy v3.2

Next action

Await review if flagged

4

Review & Correct

Material event

Worker correction submitted

Owner

Assigned reviewer

5

Approve & Resolve

Material event

Reviewer decision recorded

State

Approved · v4

6

Release

Material event

Sent to downstream system

State

Queued for delivery

7

Acknowledge & Reconcile

Material event

Destination receipt matched

Next action

Resolve if mismatched

8

Retain / Restrict / Redact / Archive

Material event

Retention policy applied

Owner

Privacy & lifecycle admin

Late-arriving event — shown, not hiddenConflicting evidence — flagged for reviewWithdrawn evidence — record kept, evidence markedReopened case — new linked history, not a reset
Ledger Event Anatomy

Every material event, fully explained.

No event is a bare line item — each one expands into identity, timing, reason, evidence, and what happens next.

EVT-30456 · type: correction_approved · v4

Resulting state: Approved

Affected object

REC-88214-A

Actor / service

J. Alvarez — Compliance Reviewer

Role / scope

Reviewer · Team 12 scope

Canonical timestamp

2026-08-06T14:40:11Z

Local timestamp

Aug 6, 2026 · 7:40 AM PDT (UTC-7)

Action / reason

Approved worker correction — break duration

Before → after

25 min → 30 min

Source / policy context

Break & Rest Policy v3.2

Evidence references

2 available, 1 restricted

Relationships

Supersedes EVT-30401

Retention state

Standard retention · not restricted

Owner / recovery

Compliance Reviewer team

Record Lineage

Version comparison, not silent overwrite.

Every correction, reclassification, or reopening creates a new linked version — the prior version stays visible, not deleted.

v1

Source

v2

Normalized

v3

Corrected

v4

Approved

Break duration25 minchanged to30 min
ClassificationShort break — flaggedchanged toCompliant
ReasonWorker correction — supervisor confirmed actual break end time
Evidence change+1 supervisor confirmation added
Downstream impactPayroll reference updated on release

Comparing v3 (Corrected) against v4 (Approved). Select a version above to change the comparison.

Worker Visibility & Correction

Your record, explained in plain language.

Workers see their own history, why something changed, who acted, and how to request a correction — not a black box.

ChangeBreak duration corrected
ReasonSupervisor confirmed actual time
Actor roleCompliance Reviewer
Evidence categorySupervisor confirmation
StatusResolved

Worker rights, always

  • Full access to your own record history
  • The right to request a correction
  • The right to escalate an unresolved request
  • Never required to waive correction, privacy, appeal, grievance, legal, or contractual rights — under any tier or configuration
SubmittedAssignedInformation RequestedUnder ReviewResolvedEscalatedClosedReopened
Human Review & Approval

The ledger records context. It does not decide.

Accountable people make the call — the system's job is to make sure they have what they need to make it well.

Reviewer roleCompliance Reviewer
ScopeTeam 12 · Break & Rest corrections
Inputs reviewedOriginal record, correction request, evidence
ActionApproved
ConditionNone — approved as submitted

Approval, correction outcomes, payroll effects, discipline, legal conclusions, and other external decisions are kept separate from ledger state. The ledger shows that a decision was made, by whom, and why — those decisions themselves belong to authorized people and processes outside the ledger.

Evidence Availability

Ten explicit states. No universal "complete."

Each state carries text and an icon — never color alone — and a clear recovery path. There's no completeness percentage here; evidence availability is stated per item, not summarized into a score.

Available

Accessible to authorized viewers now.

Restricted

Exists, access is scoped by role or purpose.

Missing

Expected but was never captured.

Stale

Available, but past its expected refresh.

Withdrawn

Removed by an authorized source action.

Superseded

Replaced by a newer linked version.

Redacted

Present, with content masked by policy.

Unavailable

Cannot currently be retrieved or shown.

Conflicting

Multiple sources disagree — flagged for review.

Unknown

State could not be determined.

Access, Privacy & Retention

A governance layer, not an open shelf.

Access is scoped by role and purpose — nothing here implies every administrator sees every event.

Role & purpose-based access

Every view is scoped to a role and a stated purpose — not open by default.

Field-level masking

Sensitive fields can be masked independently of whether the record itself is visible.

Attributable redaction

A redaction is itself a logged, attributable action — not an invisible edit.

Policy-controlled retention

Retention follows configured policy, not a single universal duration across every org.

Preservation & restriction

Records can be held or restricted, without implying automatic legal-hold coverage.

Access review

Who accessed what, and why, is itself reviewable — access isn't a one-time grant and forget.

Governed Evidence Export

Export is a controlled workflow, not a download button.

Every package states its purpose and limitations up front — it is never presented as an unrestricted log dump or a legal-proof package.

1

Define Purpose

2

Select Content

3

Apply Access / Redaction

4

Review Limitations

5

Approve

6

Generate Package

7

Deliver

8

Record History

Package ID / versionPKG-2201 · v1
PurposeInternal payroll reconciliation
ScopeTeam 12 · Aug 1–7, 2026
Included / excludedApproved records included; open corrections excluded
Evidence categoriesClassification logs, supervisor confirmations
Redaction summary2 fields masked per access policy
LimitationsNot a legal-proof or completeness guarantee
DestinationPayroll system — secure delivery
Receipt / expiryDelivered Aug 8 · expires Sep 8, 2026
Product UI

See the product, not a mockup of a promise.

Synthetic organizations, IDs, and evidence throughout — no real names, photos, or confidential content.

1,204

Records with material events this week

18

Open review items

96%

Evidence available (this org, this period)

3

Reconciliation items needing review

Overview shell: left navigation (Records, Events, Evidence, Review & Corrections, Exports, Reconciliation) with scope and date controls at top. Counts and results are server-authorized per viewer.

System Boundaries

What the Evidence Ledger is not.

The Evidence Ledger is never presented as:

  • Blockchain-based or immutable
  • Tamper-proof
  • Legally admissible evidence
  • Regulator-ready or statutory audit evidence
  • Universally complete
  • A guarantee of correctness or compliance
  • A surveillance dashboard or raw telemetry store
  • An employee-monitoring timeline

It also does not make consequential decisions.

Payroll outcomes, discipline, misconduct findings, legal status, and other external decisions remain with authorized people and processes — the ledger provides context for those decisions, not the decisions themselves.

Enterprise Readiness

Evaluate it the way your team actually evaluates software.

Real product UI, a Trust Center, and a demo with your questions — not a fear-based compliance pitch.

Record scope & identity

What's captured, from which sources, tied to which identity and access model.

Evidence lifecycle

How evidence moves from capture through availability states to retention or redaction.

Change integrity

How corrections, reclassification, and reopening create linked history.

Exports & integrations

How governed packages are built, delivered, and reconciled downstream.

Worker rights

How correction, escalation, and access work from the worker's side.

Privacy & legal governance

How access, redaction, and retention are configured and reviewed.

Evidence, Connected

Traceable history. Accountable review. Worker rights, intact.

Start free and connect your first record, or bring your enterprise evaluation questions to a live demo.