Work / Chitragupt / Wiki / Concepts
read-only-review
Conceptcanonicalverified 2026-09-01
CONCEPT.READ-ONLY-REVIEWRead-only review platform
Summary
Chitragupt reads the user's documents and tells them what they say — it never acts on external systems on the user's behalf.
Why it matters
Every "we'll do it for you" feature is a different compliance surface — a different licence, a different liability model, a different product. Staying read-only is what keeps the V1 scope shippable inside DPDP §8 minimisation and outside RBI Account Aggregator write-rails. Liability containment is the load-bearing reason: there is no merchant we cancelled a subscription with, no broker we placed a trade at, no IT Dept submission we filed. The user takes every last-mile action; we hand them a pre-filled artefact.
Implications
- Every CTA collapses to one of
ingest / organise / review / export / nudge. Anything else (subscription cancellers, trade executors, dispute submitters, e-file orchestrators) belongs to a different product. - No broker API integration that acts — no order placement, no trade execution, nothing that touches a broker's write-rails. Portfolio may read holdings via a linked broker API in addition to uploaded statements, per 2026-09-01-broker-api-sync-as-source — that's still read-only (we fetch, we never place an order), so it doesn't cross the line this concept protects.
- No bank-side dispute orchestration. We emit a pre-filled grievance PDF; the user files it.
- No direct e-Filing with the IT Dept. Filing routes through a CA — Hire-CA or Invite-CA.
- The one regulated exception is the Ask CA File / Audit Defence tier, where the engaged CA may deposit an ITR-V acknowledgement into the client's Inbox as a new document (never as an edit).
- "Forward action" UX is always a downloadable artefact, copyable link, or worksheet — never an in-app executor.
Related
- upload-only — the input-side mirror of this principle
- no-manual-entry — sibling ban that enforces the same liability stance
- scope-discipline — third-party orchestration is permanently out of scope
- ask-ca-stream — the one regulated write affordance lives here
- pillar-expense — anomaly + recurring-sub detection, no cancellation
- pillar-portfolio — reconciles uploads or a linked broker API read, no trade execution
- 2026-09-01-broker-api-sync-as-source — the narrow read-only broker-API exception
Sources
- .context/wiki/concepts/* § "Core principle — read-only review platform"
- .context/wiki/concepts/* § "Hard rules" rule 14
- .context/wiki/concepts/* § "Permanently out of scope" — read-only stance
- .context/wiki/concepts/* § "What Chitragupt is"
Every project of mine is written down like this.
Read the résumé