Deterministic engine
Same rules + same revenue = same payout, every time. Money-conservation invariants enforced in SQL.
Contract-to-revenue infrastructure · v1.0.2
RoyaltyOS turns PDF agreements into human-reviewed financial rules, reconciles PayPal revenue, and pays contributors — with every cent traceable to a clause, a rule, and an approval.
Boundary: AI interprets. Deterministic software calculates. Humans authorize. PayPal moves money.
Producer · post-recoupment 20%
Frozen · hashed · compiler-validated
$0.00
Conserved to the cent · ledger balanced
PayPal batch · no duplicates
Approved by finance · step-up verified
How it works
PDF magic-byte, size and page validation, SHA-256 hash, ClamAV scan in production, immutable version in private Supabase Storage.
contract_v3.pdf · sha256 9be2…77aa
OpenAI Responses API with strict JSON schema reads up to 3 prior versions, flags contradictions — ambiguous rules stay review-required until a person approves.
REVIEW_REQUIRED clause 4.2 vs amendment §2
Fixed-precision engine: percentages, recoupment, caps, floors, date gates, largest-remainder allocation. What-if simulations never post.
$12,480.00 → $2,496.00 + $9,984.00 · Σ conserved
Finance re-authenticates, approves, executes idempotent payout batches. Webhooks + polls reconcile every item; only failed items retry, as a new version.
PAYOUT SUCCESS batch 7f3a · key 1ca9…
Guarantees
Same rules + same revenue = same payout, every time. Money-conservation invariants enforced in SQL.
Password step-up + finance role required. Approved lines are immutable.
DB locks + unique payout version + PayPal ids. Retries can't double-pay.
Every state change leaves a tamper-evident row. Integrity RPC on demand.
Immutable versions in a private bucket. Malware scan fails closed.
Official PayPal MCP, restricted to list/get. Mutation prompts rejected pre-call.
Amendment demo
The demo amendment cuts Producer's post-recoupment share from 20% to 15%. RoyaltyOS surfaces it for human review instead of silently activating.
CONSISTENT no conflict with prior versions
Who does what
Creates contracts, uploads PDFs, runs AI analysis, shepherds review → activation.
Reviews settlements, verifies identity, approves, executes and retries payouts.
Sees only their own lines — clause → rule → revenue → payout, end to end.
Reads Insights + Audit: hash chains, ledger balance, CSV exports. No pay buttons.
Start in minutes
Sign in, bootstrap a workspace, upload the demo PDFs, and follow the User Flow to your first reconciled payout.