1. Provenance: every figure links to records
A total is never stored as a typed-in number. It is computed from records: payments, advances, approvals, indicator values and the evidence attached to them. Open any figure and you see the list of records it was built from, and from each record you can reach its documents and its history.
This means a report and the work behind it cannot drift apart. If a payment is corrected, every report that includes it reflects the correction, and the audit trail shows that it changed.
2. Named absence: unknown is not zero
Spreadsheets treat an empty cell as zero when they add it up. That turns "we don't know" into "nothing happened". We use named states instead:
- Not recorded: the item is expected but no one has entered it yet.
- Not tracked: the programme has chosen not to collect this item, so no value is expected.
- Not reported: a unit or partner was due to report and has not.
A total that includes a missing value says so, and shows which parts are missing. It is not presented as complete.
3. Refusal by name
When access rules prevent someone from seeing a record, the product says that access was refused and why, rather than showing an empty screen or a smaller total that looks complete. An implementing unit sees only its own work; a donor viewer can read but not change. Either way, the person knows what they are not seeing.
4. AI that proposes, and a system that checks
The AI assistants can draft text, answer questions about your records and suggest entries. Every answer must cite the records it relies on. If the records do not support an answer, the assistant declines and says what is missing. An AI suggestion becomes a record only when a person accepts it, and the audit trail shows that it began as a suggestion.
5. Audit trail
Every create, change and approval is logged with who did it and when. Approvals are tied to the version that was approved, so a later change is visible as a change.