# visibility.cloud — Five dimensions. No performer.

> Your record says what happened. It cannot say who performed it. EPCIS 2.0 — the standard your whole traceability programme is built on — records what, when, where, why and how. Its Who is a company: a GLN, the legal entity — never the performer. visibility.cloud is the record with the performer in it: every event carries an attested observer — a person, an agent, or a robot — and capturedBy, the account that stands behind the capture, stamped at the door and impossible to un-write. And it is built to hold up whether or not the other side of the handoff joined anything.

**Verified 2 August 2026.** Three doors of the spine answer over HTTPS today — POST https://epcis.dev/translate, /validate and /hash — against sha256-pinned official GS1 artefacts, and 925/925 spine tests pass. Every open gap is a named entry in the open P0 ledger at /p0-ledger; the dated summary is at /what-ships-today.

## The one fact to check before you believe anything else

Go check us. It takes ten minutes and doesn’t involve us.
EPCIS 2.0 §7.2.2 defines five event dimensions: what, when, where, why, how. No performer is among them. The party fields are organisation-grain — EPCIS §7.3.6.4, CBV §7.4.3, CBV §8.7.1 (PGLN). The conformant path to a performer today is a namespaced user-extension field (EPCIS §6.3 / §9.1 / §10.1.3). So the standard can say a company did a process — its Who is the company, a GLN. It cannot say which person or which device observed the event at 06:12: no field names the performer. The specs are public. Don’t take our word for it.

## The spine's laws

1. **Conforms to EPCIS 2.0 and CBV 2.0.** Implemented against GS1's official OpenAPI description, pinned by digest.
2. **Validated on every capture.** Each event is machine-checked against the official GS1 EPCIS 2.0 JSON schema before it is accepted. A capture that does not validate is refused, in RFC 7807 problem+json, carrying the standard's own exception types — not a vendor error string.
3. **Stamped by the gateway, not by the sender.** recordTime, who captured it, and the grade of that attestation are applied at the door. Whatever you sent in those fields is stripped. The scriber is not the part being scribed.
4. **Identified by the standard's own hash.** The standardized EPCIS event hash from CBV 2.0 §8.9, with GS1 Digital Link normalisation, so the same event captured twice is the same event, and a changed event is a different one.
5. **Append-only, by construction.** No service identity anywhere in the system holds an UPDATE or a DELETE grant. You can add a mark. You cannot un-draw one.
6. **Minimally scoped on read.** You see your own scope. What is outside it is absent, not greyed out and not redacted — there is no shape left behind to argue about.
7. **Ten years of vendor XML, translated.** EPCIS 1.1, 1.2 and 2.0 XML in, EPCIS 2.0 JSON-LD out, with a round-trip fidelity report per job so the translation is reviewable rather than trusted.
8. **A door for agents as well as people.** The same interface, the same key, over MCP — so a partner's logistics agent can capture and query without a human copying values between two systems.

What the laws add up to: Everyone in this market has built a network that is authoritative because you joined it. This platform makes a record that is verifiable whether or not you joined anything — and it carries, in the record itself, an attested answer to who observed the event, including when the observer was an agent.

## Capture is free. It stays free.

Recording an event will never cost you money — policy, stated ahead of published terms: the gate never lands on capture; terms post here the day they are set. Revenue attaches to answers — traces, custody evidence, exception review, partner grants, seats, retention. Prices post as numbers, on a page, without a call, when they are set.

## What ships today (condensed)

Live and verified:
- POST epcis.dev/translate — EPCIS 1.1 / 1.2 / 2.0 XML → 2.0 JSON-LD, with a per-job fidelity report. Live; curl it
- POST epcis.dev/validate — verdict against the sha256-pinned official GS1 EPCIS 2.0.1 schema, per-path errors. Live; curl it
- POST epcis.dev/hash — the CBV 2.0 §8.9 event hash, GS1 Digital Link normalised, gated on OpenEPCIS reference vectors. Live; curl it
- 925/925 spine tests pass; GS1's normative artefacts vendored and pinned by sha256 digest, re-checked in CI

In the open P0 ledger (/p0-ledger):
- Hosted capture, query and MCP at api.epcis.dev — R2 + pipeline provisioning and deploy, [OWNER]
- npm: npx epcis.dev — registry publish, [OWNER]
- The public repository and its clone URL — [OWNER]
- Published prices — they post here as numbers when set

The ledger in full, dated: /what-ships-today

## The answers (each names its open entries in the P0 ledger)

- **The trace: where is it, and who touched it.** One lot, one EPC, one question — the full event chain in seconds, and at every hop not just a company doing a process but the attested observer: which person, which agent, which device, at the moment of the scan. Today's record shows a case arrived at a DC; it never shows who received it. This answer shows both.
- **Chain-of-custody evidence: the record that holds up in the room.** A custody chain you can hand to a regulator, an auditor, or the other side of a chargeback dispute — every event content-hashed per CBV 2.0 §8.9, append-only with corrections as declared events, carrying the attested observer — verifiable whether or not the counterparty joined anything.
- **Exception views: the handoffs that went silent.** The standing view of every handoff where the record went quiet — received with no performer, shipped with no custody closure, a franchise or co-manufacturer boundary crossed with nothing attested on the far side — triaged before the auditor or the claim finds it first.
- **SharingGrants: scoped sharing that compiles, and revokes, cleanly.** Share exactly these goods, these event kinds, this window, at this attribution grain — with a customer, a shipper, or a regulator — as a grant that compiles to a spine-native scope, is enforced identically on every door, and revokes without rewriting history. Answer the traceability clause with a grant, not a paragraph.
- **Recall & audit readiness: FSMA 204 without the war room.** When the call comes, the trace-back that took days across the co-manufacturer or franchise boundary becomes a query: covered-food KDEs and CTEs, custody closed at every hop, exportable in the shape the auditor asks for — so the 2028 enforcement floor is a de-risking deadline you beat early, not a gun to your head.
- **The Sunrise 2027 decision read: the executive gift.** Exactly what Sunrise 2027 requires of you — GTIN owner, converter, or retailer; which symbology and which URI form is genuinely your decision; what the lane must extract versus what nothing obliges you to encode — and the one structural fact you can verify without us: EPCIS 2.0 §7.2.2 defines five dimensions and no performer — the Who it carries is a company, a GLN. Ten minutes, the specs are public, don't take our word for it.
- **Seats & deputization: the mandate your agent works under.** A human seat provisions an agent seat with a written mandate — scope named, ceiling named — so the agent that works your exception queue or answers your customer's verifier acts under authority you granted and can be shown to have acted under it. provisionAgentSeat is a ceremony with a human audience, not a route; identity resolves through id.org.ai — Agent. Human. Thing.

## The family (built in the open)

Three developer doors under this surface; every answer here is a view over the record they write and read. Their mastheads carry "· by visibility.cloud".
- epcis.dev — the event engine: an EPCIS 2.0 capture gateway; translate, validate and hash answer on that origin today
- transactions.dev — the paperwork layer: purchase orders, ASNs and invoices compiled onto the same event record in the standard's own vocabulary
- barcoding.dev — the barcode layer: every barcode read, verified and generated, with the source and license named on every answer
- id.org.ai — the identity layer: Agent. Human. Thing. Who an observer is resolves there; this surface only names it.

## Doors

- /get-started — the branching interview (machine twin: /flow.json)
- /first-trace — a worked illustrative trace + the segment waitlist
- /trace — the same chain, interactive: seven worked custody chains, one per segment, with
  a switch that adds or removes the performer
- /answers — the offer surface
- /what-ships-today — the dated ledger
- /llms.txt · /icp.json · /agent-classes.json — the machine face

We answer in writing. We take at most five conversations a month, only when you ask for one, and only after you already have the written read.
