Work / Chitragupt / Wiki / Concepts
upload-only
Conceptcanonicalverified 2026-09-01
CONCEPT.UPLOAD-ONLYUpload-only
Summary
Every fact in chitragupt's ledger originates from a document the user uploaded. There is no manual entry, no typed-in amount, no "trust me" income line.
Why it matters
Liability containment. A manual entry has no source artefact to point back to during an IT scrutiny or DPDP audit; an uploaded document does. Upload-only is what keeps the product a read-only-review platform and not a bookkeeping tool.
Implications
- No "Add expense" button anywhere. Inbox is the only writer.
- Every parsed entry carries its source document ID — broken trace = bug.
- Past-AY reviews are still gated by upload, not retyping.
- Any feature that asks the user to type money is a SPEC violation. Push back, don't build.
- Failure mode UX (failed parse, partial parse) must offer re-upload, not manual fix.
- Narrow exception (Portfolio only): a linked broker API pull counts as a source artefact too, provided the raw response is persisted immutably with provider/account/fetch-time — it's machine-fetched, not typed, so it satisfies "has a source to point back to" the same way a document does. See 2026-09-01-broker-api-sync-as-source. This does not extend to Tax, Expense, or Inbox.
Related
- read-only-review — the parent principle this enforces
- user-identity-entry — the chain every parsed fact travels once uploaded
- identity-buckets — where an uploaded document lands in the Inbox tree
- ledger-entry-types — the strict enum of facts a parser may emit
- money-in-paise — once uploaded, every amount lives as paise integers
- tier-free — uploads are free even before parsing is unlocked
- 2026-09-01-broker-api-sync-as-source — Portfolio-only broker-API source-artefact exception
Sources
- .context/wiki/concepts/* § "Hard constraints (V1) — non-negotiable"
Every project of mine is written down like this.
Read the résumé