Loading…
Loading…
Seven-stage execution
Providus turns approved messages into verified real-world payments. You can ask naturally, inspect the exact action, approve it yourself, and follow the evidence across each handoff.
Human approval boundary
A language model may interpret a request, ask a question or explain a recorded state. It does not create an executable transaction, change approved payment fields, authorize a provider mutation, sign a wallet transfer or choose a success state.
Conversational input becomes a structured request without giving the model financial authority.
Deterministic Providus code validates, binds, executes, reconciles and builds the evidence-backed receipt.
Tell the web dashboard what you want to pay in ordinary language. The current conversational path supports Nigerian airtime.
Providus turns supported requests into a typed, validated PaymentIntent and asks for missing or ambiguous fields before any money action.
Freeze the recipient, network, amount, quote, fees, expiry and exact total so you can inspect the terms.
Approve the exact action, then separately sign the exact Celo USDC transfer in your browser wallet. Providus never signs for you.
Deterministic code creates and binds the approved order, then calls the current rails. Paycrest settles NGN; ClubKonnect fulfils current airtime.
Read chain and provider states separately; reconcile unknown outcomes without blind duplicate mutation. A Celo deposit is not Nigerian delivery.
Show an evidence-linked receipt for verified stages and keep unverified outcomes clearly marked.
P6.14 · Trust architecture
The web path stays legible from language to evidence. Providus owns the deterministic handoffs; providers own only their named edge.
A single trust path fans out to separate settlement and fulfilment edges, then joins again only at reconciliation.
The web dashboard is the shipped conversation surface.
Language is interpreted and clarified before it becomes a candidate request.
Deterministic code validates and binds the requested outcome, recipient, quote, fee, expiry and exact total.
The user reviews the frozen terms, approves the action and signs the exact Celo USDC transfer.
Eligibility, durable state, provider calls, fulfilment gating, reconciliation and receipts remain deterministic.
06 · Two separate provider edges
Paycrest owns Celo USDC → NGN settlement, not airtime fulfilment.
ClubKonnect owns airtime fulfilment after Providus’s durable fiat-final gate.
These edges stay separate: Paycrest does not fund ClubKonnect. Providus gates fulfilment, reads each provider independently and reconciles before reporting an outcome.
Chain and provider reads are reconciled; uncertain outcomes are recovered by reference instead of blindly retried.
A stage is final only when its required evidence supports it; Celo, fiat delivery and fulfilment stay separate.
The approved request and its owner-scoped, evidence-backed lifecycle become the human-readable record.
Trust ownership
Language is useful at the front of the path. Money authority begins only after deterministic validation and your approval.
Interpret language without receiving financial authority.
It never becomes an execution, signing or success authority.
You own approval and browser-wallet signing. The system does not move money until both boundaries are explicit.
Review the frozen recipient, amount, quote, fee, expiry and exact total.
Approve the exact action in the conversation or dashboard.
Sign after the server binds the authoritative order; then sign the exact Celo USDC transfer in your browser wallet.
Only then can deterministic Providus code execute and reconcile the provider edges. Providus never signs for you.
Observed states
These public labels describe recorded evidence, not optimistic provider acknowledgements.
Each stage is monotonic in durable transaction state.
Awaiting payment
Order created; the Celo USDC deposit is not yet observed.
Celo deposit confirmed
The USDC transfer is verified on-chain; NGN delivery is still separate.
NGN payout in progress
Paycrest’s liquidity provider is disbursing NGN to the configured fiat recipient.
NGN settlement processing
Paycrest settlement is still progressing; this is not protocol completion.
NGN settlement confirmed
Paycrest fiat delivery is confirmed as durable fiat-final truth; an airtime request has not been sent yet.
Airtime request submitting
The one allowed fulfilment attempt is claimed or in flight.
Airtime processing
ClubKonnect has received the request; acknowledgement is not delivery.
Airtime delivered
ClubKonnect’s documented terminal success status verifies delivery.
Internal lifecycle: pending → settling → settled → processing (airtime) → completed. Cash-out settled is the effective terminal.
Bank cash-out stays a separate, intact path.
NGN is confirmed delivered into the recipient bank account.
Paycrest protocol settlement is complete; this is tracked separately from fiat delivery.
Fiat payout is verified while downstream utility fulfilment is in progress.
The cash-out row is recorded complete; cash-out settled is the effective terminal.
Acknowledgement is never final success; recovery is a real state, not a hidden retry.
Airtime status is unclear. Reconcile the existing RequestID; do not submit another purchase.
An order or completion outcome is unknown and needs durable-reference reconciliation before any new action.
Fiat delivery was confirmed but airtime delivery failed; Providus did not issue an automatic refund.
A documented terminal transaction or payment failure.
A refund is shown only after the return of funds is verified.
The durable validated fact is authoritative fiat delivery and never gets cleared. settling is later protocol progression; settled is protocol completion and also subsumes fiat delivery.
Proof chain
A receipt joins human approval, chain evidence, settlement milestones and fulfilment evidence without collapsing them. Approval is the flow boundary; the persisted receipt covers the resulting payment and provider facts.
The current web path leaves a durable, reviewable record.
Human approval: the user approved exact terms and signed in a browser wallet.
Celo evidence: the on-chain USDC transfer is linked from the receipt.
Settlement evidence: Paycrest delivery is recorded as validated, then protocol settlement as settled.
Fulfilment evidence: ClubKonnect status 200, RequestID and order reference support delivery.
Receipt: the verified outcome keeps each stage and its evidence visible.
One human-gated run, not a guarantee of future delivery.
cktx48b9… · order 6720476887Durable safety
Unknown is a state to reconcile, not permission to repeat a money-moving request.
Neon PostgreSQL + Drizzle stores the transaction facts needed across refreshes and restarts.
Idempotency protects the real-world side effect; reconciliation decides what can be called final.
Review before money moves
Approval is only safe when the action and its limits are visible, not hidden behind provider or protocol language.
Provider names sit at the execution edge; Providus owns the approval, orchestration, reconciliation and proof layer.
A Paycrest quote is an estimate with a capture time, expiry and disclosed fee inputs. Refresh it when stale; do not treat an old quote as a final payout amount.
Current channel and boundary
The web dashboard is the shipped conversation surface. iMessage/Photon, WhatsApp, Telegram, MiniPay, data bundles, electricity and cable are future adapters or categories, not current availability.
Prefer a separate bank cash-out?
Open the dedicated flow to verify a recipient, review a live quote and approve the exact Celo USDC transfer.