Conflict inspector

Two authorities claim the same fact · 10 live conflicts across 8 domains · the matrix decides the winner, an operator applies it or escalates, and nobody picks a side by hand · Thu 30 July 2026 09:12 GST

The matrix is the decision, not a reference panel. Each fact has exactly one owner at a given precedence, and the winner is computed at detection time and frozen on the conflict row with its rationale. An operator may apply the binding or escalate. Choosing the losing side is only possible by filing a time-boxed, dual-signed authority exception, which then renders next to the binding it overrides. RFID gate reads are immutable and win physical existence. They can never be outvoted, only exempted.
4 immutable contradictions are open. In each one an RFID gate or handheld read disagrees with a system that does not own physical existence. CNF-0011 is the sharp case: Shopify says the unit is sellable and a gate read says it left the building on the 26th. Applying the binding moves custody. It does not write a sellable number, because sellable is derived. Authority matrix →
Sort
Conflict Domain Systems Subject Field Both claims Winner Why, from the binding Tier AED State Action
CNF-0011 physical_existence rfidvsshopify MST-CRM-42-BLK
EPC …3918 2C41 @ YAS
unit_state rfid: read at floor 28-07 12:04
shopify: sold 26-07 18:22
rfid IMM RFID owns physical existence at precedence 1 and the binding is immutable. A sold flag is a commercial fact and cannot deny that a tag was physically read. T3 1,520 Open
CNF-0010 unit_custody rfidvsops2 MSR31-07
EPC …4021 8F3C
custody rfid: gate G1 exit 29-07 14:36
ops2: no dispatch row absent
rfid IMM Absence of an ops2 dispatch is not a counter-claim. Custody moves to IN_TRANSIT_CUSTOMER on the read; the missing AWB becomes case DRF-0142. T2 892 Investigating
CNF-0009 sellable_qty shopifyvsi3 MIN-CNL-019
@ HQ_319
available i3 ledger: 560 29-07 08:31
shopify: 550 29-07 08:31
shopify Shopify owns storefront sellable, but its may_change array is empty, so winning does not let it write a balance. The conflict routes to drift DRF-0134 for a real event. T2 1,800 Applied
CNF-0008 return_intent csdvsi3 CSD-4821
3 lines, FYN01 first
reserved_qty csd: 1 unit @ HQ_319 27-07 19:58
i3: case has 3 lines derived
csd CSD owns return intent, so its claim wins in principle. But the payload sends only the first SKU at quantity 1 with the location hardcoded, so i3 records a conflict instead of posting a wrong hold. T2 840 Blocked
CNF-0007 dispatch_awb ops2vsi3 DHL 4548827193
LBA01 x2
dispatch_location ops2: HQ_319 29-07 07:48
i3: HQ_325 29-07 07:48
ops2 p1 ops2 owns dispatch and AWB. i3 inferred the wrong site from the order's placement location, which is the shape of the 1,205 cross-location defect. T2 306 Open
CNF-0006 physical_receipt grnvsiwms INF-2319 L4
PP02
qty_received grn: 46 counted 28-07 22:10
iwms: 48 carton sum 28-07 22:14
grn p1 GRN owns receipt at precedence 1, IWMS at 2. The carton sum overstates because opening a carton into picking never decrements the carton, so its contents are counted twice. T2 288 Awaiting approval In queue
CNF-0005 carton_position iwmsvsrfid MC-4471
24 units mixed
current_zone iwms: A3 29-07 14:01
rfid: PICKING 29-07 14:01:38
iwms p1 A 38-second timing race, not a disagreement. IWMS owns carton position; the read arrived mid-move. Replaying the IWMS event in order resolves it with no correction. T1 0 Applied
CNF-0004 accounting_truth netsuitevsi3 period 2026-06
on-hand value
on_hand_value netsuite: AED 9.42M 30-06 close
i3: AED 9.61M 30-06 23:59
netsuite p1 NetSuite is the accounting system of record. Any value i3 publishes is a management figure that must reconcile to it, never replace it. The AED 190K gap is 2.0% and needs a line-by-line bridge. T3 190K Escalated
CNF-0003 physical_existence rfidvsiwms JAE17
EPC …4188 91A0
location rfid: HQ_325 dock 29-07 10:58
iwms: HQ_319 bay C 27-07 16:20
rfid IMM The unit is at HQ_325 whatever the bin record says. Applying the binding writes a paired relocation, never a single row, because a lone row that changes location is what produced 1,205 unrecorded transfers. T2 470 Open
CNF-0002 write_off_approval financevsi3 WO-0588
MIN-CNL-019 x4
approval_state finance: approved verbally 24-07
i3: no signature row expired 29-07
finance p1 Finance owns write-off approval, so their intent wins. But an approval that exists only as a conversation is not a signature, and i3 has no row to point at. The resolution re-requests it, it does not backdate it. T3 720 Investigating
CNF-0001 po_status i3vsops2 PO-2026-118
CIC · 1,180u
status i3: received 17-07 19:58
ops2: in_production stale
i3 p1 i3 owns the supplier pipeline. ops2's copy is a stale mirror with no receipt event, which is missing_in_sibling rather than a dispute. T1 0 Applied
CNF-0012 unit_custody rfidvscsd MIN-MRR-003
EPC …4207 3B18
custody rfid: MCC stockroom 29-07 07:56
csd: in_transit_return 26-07 11:40
rfid IMM The parcel arrived and was shelved without a returns scan. Custody moves out of IN_TRANSIT_RETURN, but to QUARANTINE, not to sellable stock: only a physical inspection moves it further. T1 205 Open
CNF-0013 sellable_qty shopifyvsi3 LBA01
@ MCC
available i3 ledger: 84 29-07 11:04
shopify: 72 29-07 11:06
shopify Shopify was updated from the count sheet before i3 saw the count. The stock answer belongs to DRF-0139; this conflict only records that the storefront moved first. T2 1,840 Applied
CNF-0014 landed_cost netsuitevsi3 PO-2026-118
unit cost
unit_cost i3: AED 180.00 17-07
netsuite: AED 187.40 28-07 freight
netsuite p1 Freight landed after the receipt. The correction moves value with zero quantity, so it posts to cost_ledger and never touches the quantity ledger. T2 7,400 Awaiting approval In queue
14 conflicts · 10 live · 4 applied · every row shows the winner and the rationale copied from the binding, so the page needs no join to explain itself There is no "trust the other one" action anywhere in this table. That is deliberate.

Worked example · CNF-0011

Shopify says the unit is sellable. A gate read says it left the building four days ago. This is the conflict that decides whether the authority matrix means anything.

immutable winner
RFID gate read: EPC …3918 2C41 exited gate G2 at YAS on 26-07 18:04. Immutable. RFID gate read 26-07 18:04 · immutable Shopify claims the variant is available at YAS, quantity 33 including this unit. Shopify: sellable available 33 @ YAS The binding for physical_existence names RFID at precedence 1 with is_immutable = true and may_change = custody, condition. Binding decides physical_existence → rfid p1 may_change = custody, condition Allowed: custody moves from IN_STOCK to IN_TRANSIT_CUSTOMER at YAS. One unit-ledger hop plus one paired quantity posting. Custody moves IN_STOCK → IN_TRANSIT_CUSTOMER Refused: no code path may write a sellable number. Sellable is derived from custody and condition, so it changes by itself. Sellable is not written derived · falls out of the projection refused allowed
Measure for MST-CRM-42-BLK at YASBeforeAfterHow it changed
on_hand3333Unchanged. The unit is still owned, so it is still on hand.
sellable3332Derived. Nobody wrote 32. IN_TRANSIT_CUSTOMER is not a sellable stock type, so the sum changed on its own.
floor_sellable1211Derived, same mechanism, scoped to the shop floor.
committed45Derived. The unit is owed to a customer.
available2927Derived as sellable minus unposted holds. Note it moved by 2, not 1, because a hold expired in the same pass.
owned_qty3333Unchanged. Custody moved, title did not.
unit_state (EPC)IN_STOCKIN_TRANSITOne unit-ledger hop, written in the same transaction as the quantity pair.
One decision, one custody change, six measures moved, zero numbers set by hand.Ledger effect: a movement pair sharing one movement_pair_id, summing to zero.

Why "RFID wins" needs a definition

A gate read establishes exactly one thing: this tag was at this antenna at this time. It does not establish sellability, ownership, condition or intent. So "RFID wins physical existence" cannot mean "RFID sets the stock number".

The binding encodes that limit as may_change = {custody, condition}. Applying it is allowed to move a unit between custody states and condition states. It is structurally incapable of writing a derived measure.

This is the same principle that keeps a carrier status string from crediting stock: a claim moves units to a state that is present, owned and not sellable. It never invents sellable stock, and it never does nothing.

What happens next

CNF-0011 is T3 on immutability

Winner
rfid · precedence 1
Immutable
Yes
May change
custody, condition
Tier
T3 immutable_authority
Signatures
2, from different humans
Reversible
Yes, by a further pair
Downstream
opens a drift case if the sold order has no matching dispatch
Confidence
0.96 · display only

The confidence figure is shown and ignored. It comes from the same matcher that produced the conflict, and letting it choose its own reviewer means an over-confident matcher approves its own errors.

Authority matrix

12 domains · 10 systems · versioned, because the answer changes across phases

2 immutable1 exception active
DomainOwner and precedenceMeasureMay changeRationale, shown verbatim on every conflictEffective
order_existence shopify p1 none existence, status An order exists because Shopify says so. i3 never mints or voids an order. 2026-08-01
sellable_qty shopify p1
i3 p2
sellable nothing Shopify owns what the storefront promises. i3 owns the derivation. Winning this domain does not permit writing a balance, which is why the array is empty and the conflict routes to drift. 2026-08-01
dispatch_awb ops2 p1 none status ops2 owns dispatch, AWB and carrier events. i3 consumes them and never guesses a dispatch site from the order. 2026-08-01
return_intent csd p1 committed custody CSD owns why a customer is sending something back and which case it belongs to. It does not own whether the parcel arrived. 2026-09-01
physical_receipt grn p1
iwms p2
on_hand existence, condition The counted receipt wins over a carton sum, because opening a carton into picking does not decrement the carton and the sum therefore overstates. 2026-10-01
carton_position iwms p1 none status IWMS owns which bin a carton is in. A read that arrives mid-move is a timing race, resolved by replay. 2026-12-01
physical_existence rfid p1 IMM on_hand custody, condition Immutable. A gate read proves a tag was at an antenna at a time. Nothing outvotes it. It also proves nothing else, so it may only move custody or condition, never a derived measure. 2027-01-01
unit_custody rfid p1 IMM
ops2 p2
committed custody Immutable. Whose hands a serial is in is settled by the last read. A carrier status string is evidence at weight 0.60 and can never by itself credit sellable stock. 2027-01-01
po_status i3 p1 incoming status i3 owns the supplier pipeline end to end. A sibling's copy is a mirror, and a stale mirror is missing data rather than a dispute. 2026-10-01
write_off_approval finance p1 owned condition Finance owns whether value may leave the balance sheet. An approval that exists only as a conversation is not a signature and cannot be backdated into one. 2026-08-01
landed_cost netsuite p1
i3 p2
none value Value moves in cost_ledger, a second hash-chained journal, because a cost revision changes value with zero quantity. It may never travel through the quantity ledger.
Exception AUX-0001 active until 12-08: i3 wins for the June close only, while the freight bridge is built.
2026-11-01
accounting_truth netsuite p1 none nothing NetSuite is the accounting system of record. Every valuation i3 publishes is a management figure that must reconcile to it, never replace it. i3 cannot change an accounting fact, only report a difference. 2026-08-01

Two domains have may_change empty. Winning them lets a system be believed and changes nothing in the ledger, which is the correct outcome when the disagreement is about a derived number or about somebody else's book.

Precedence, immutability, the permitted change set and the rationale are all columns, and the rationale is copied onto each conflict at detection time so the queue explains itself without a join.

Decision tiers

Value, quantity, reversibility, immutability

  • T1
    Rule applies itValue at or under AED 150, reversible, no immutable authority on the losing side, and a replay resolves it. The rule signs and the conflict closes with an audit row, never silently.
  • T2
    One humanAED 151 to AED 5,000, reversible. One signature from role >= manager plus the feature flag. The requester may never be the signer.
  • T3
    Two different humansOver AED 5,000, irreversible, an immutable authority on the losing side, an authority exception, or a cross-book disagreement with NetSuite. Finance plus ops_manager, or admin.
v2 tiers on the matcher's own confidence: 90% and above auto-resolves, 50 to 90% one approver, under 50% two. That is circular. i3 keys on value and reversibility and shows confidence as a column.

Authority exceptions

The only way to act against the matrix

RefDomainPrefersScopeExpiresState
AUX-0001landed_costi3 over netsuiteperiod 2026-0612-08Active
AUX-0002dispatch_awbops2 over i33PL_ARAMEX13-08Pending
AUX-0000physical_receiptiwms over grnHQ_325expired 18-07Expired

An exception is scoped to a domain and optionally a SKU or location, always time-boxed, always justified, and always dual-signed. It renders next to the binding it overrides so nobody reads the matrix and gets the wrong answer.

No exception may be filed against an immutable binding for the purpose of denying a gate read. AUX-0002 is permitted because dispatch_awb is not immutable.

Conflicts by domain · 30 days

Which facts two systems keep arguing about. A domain that argues constantly is an integration contract that is not written down.

61 total
sellable_qtyunit_custodyphysical_receiptdispatch_awbphys_existencereturn_intentlanded_costother 5 sellable_qty · 16 conflicts · every one routed to drift, because winning it changes nothing unit_custody · 11 conflicts · 9 resolved in favour of an immutable read physical_receipt · 9 conflicts · carton sum against counted receipt dispatch_awb · 7 conflicts · i3 inferring the site from the order physical_existence · 6 conflicts · all 6 won by RFID return_intent · 5 conflicts · all from the single-SKU reservation payload landed_cost · 3 conflicts · freight landing after receipt order_existence, carton_position, po_status, write_off_approval, accounting_truth · 4 conflicts between them 1611976534
Immutable domainDerived measure, routes to driftPhysical, correctable5 return_intent conflicts, one cause: the reservation payload sends one SKU at quantity 1.

How they resolved · 30 days

61 conflicts by resolution action. Nothing is closed by an operator preferring the losing side.

0 side-picks
apply_binding · 25 of 61 · 41% replay, a timing race with no correction · 18 of 61 · 30% routed to drift, because the winning domain may change nothing · 10 of 61 · 16% void, false positive, detector named and fixed · 5 of 61 · 8% exception filed · 3 of 61 · 5% 61 resolved apply_binding · 25 replay · 18 routed to drift · 10 void, false positive · 5 exception filed · 3 operator picked the loser · 0
The 5 voids each named a detector to retune, which is why the false-positive rate fell from 14% to 8% this month.

Conflict types and what each one means

Six types, because "they disagree" is four different problems with four different fixes

TypeWhat it actually isResolution shapeLive
value_mismatchBoth systems have a value for the same field and they differ. The commonest and the least interesting.Apply the binding, then a correction if the losing side is i34
missing_in_i3A sibling has a fact i3 never received. Usually a lost webhook, occasionally a topic that was never emitted.Replay from events_raw, or open a case if the event is unrecoverable2
missing_in_siblingi3 has a fact the sibling does not. Often a stale mirror rather than a dispute.Fan out through the outbox; no ledger effect0
timing_raceBoth are right, in different instants. The classic false conflict.Replay in event order, no correction, no signature0
authority_overlapTwo systems both believe they own the fact, usually because the contract was never written down.Apply precedence, then fix the contract upstream2
immutable_contradictionA gate or handheld read disagrees with a system that does not own physical existence.Apply the binding. There is no other option short of a scoped exception.2

v2 has four of these six. The two it is missing are the two that carry the most weight: authority_overlap, which is the only type whose real fix is upstream rather than in the data, and immutable_contradiction, which is the type where an operator must not be offered a choice.

18 of 61 conflicts in the last 30 days were timing races. Naming them as a type stops them consuming a human decision each.

The rule this page enforces

The matrix decides. A human applies or escalates. v2 renders an 11-domain authority matrix in the right rail and then puts Trust INV2 and Trust ops2 side by side on every row. If an operator can pick either side per row, the matrix is documentation and the two systems diverge by operator preference.

Winning is bounded. Every binding declares what a win is allowed to change. Two domains may change nothing at all: a derived measure and somebody else's book. Winning those means being believed, not being written.

Immutable means immutable. A gate read cannot be outvoted. The only route around it is a scoped, time-boxed, dual-signed exception, which is visible next to the binding for as long as it lives and then expires by itself.

Tier comes from value and reversibility. Never from the confidence of the component that raised the conflict.

State variants

Six of the eight states this page can render

Pattern library ↗
Loading

The winner column renders last. A conflict shown without its computed winner invites somebody to decide it themselves.

Empty

No system disagrees with any other.

All 12 domains agree across 10 systems. Last cross-check 09:04, 41,200 facts compared, 0 divergent. The matrix is still shown, because knowing who would win matters before anyone needs it.

View matrixSibling health
Error

Couldn't load bindings.

The authority service returned 503. The queue is hidden rather than shown without winners, because a conflict list with an empty winner column is an invitation to guess.

Error id cnf-77b41e · 30-07-2026 09:06:44 GST
Service health
Zero-filter

No conflicts match.

3 filters are hiding all 14.

type: timing_racesystem: grntier: T3
Permission

You can read conflicts but not apply bindings.

Applying a binding posts a ledger effect, so it needs role >= manager plus the conflict_apply feature. Filing an exception needs admin plus a second signature.

apps.i3.role = viewer · features = [read]
Request accessWho can do what
Gate-blocked

Two bindings are not yet effective.

physical_existence and unit_custody become effective on 2027-01-01, when GATE-6 closes. Until then RFID conflicts are detected and shown but cannot be applied, and the winner column reads provisional.

4 immutable contradictions held provisional · GATE-6 in shadow, day 3 of 7
Connected to Drift queue Case detail Correction workbench Approvals Anomaly explorer Gates and feed Unit events 3-way reconcile Sibling events ops2 events CSD events GRN events IWMS events Shopify events Cartons and bins PO detail Cost and price Reports Audit log Settings