The complete trail
A BoomPay paper trail keeps the retained record, its history, the actions taken on it, and its verification details together. It does not hide or erase an older record. A hash, an audit event, or a screen by itself is not the record.
Authoritative records
The authoritative record is the protected document or structured record retained by the service that owns the workflow. Document bytes are kept in the BoomPay document volumes and their identifying records are kept in the BoomPay database. Auditd keeps the action history. BoomPay Sign is the source of an official signed PDF or certificate when signing is required.
Each service keeps its own part of the trail. Garage owns shop records, work orders, quotes, photographs, final invoices, and shop-side authorizations. Boost owns customer identity, customer corrections and authorizations, payment mandates, and customer copies. Partners receives only authorized, minimized, read-only oversight records and does not rewrite Garage or Boost evidence.
What every paper trail must show
- The exact person, organization, vehicle, repair, or account record linked to the document.
- The document title, version, source, effective or expiry date, and creation or completion time.
- The original protected bytes, content type, size, SHA-256, storage reference, actor, and capture time for an uploaded record.
- The BoomPay Sign submission, document, or certificate reference.
- The retained PDF hash and a link to verify the PDF with BoomPay Sign.
- Each replacement, correction, certification, review, reissue, void, or superseding record and the record it follows.
How Garage keeps the trail
Garage stores business-profile changes as revisions. A replacement business document creates a new record linked to the record it supersedes. It preserves the original bytes and per-page details, hashes, type, size, uploader, upload time, expiry, review state, and storage reference. The current usable record is the latest authorized, non-superseded, unexpired revision; older revisions remain history.
Recognition and machine suggestions are advisory. Garage retains recognized text, suggestion keys, provider version, and hashes with the immutable document revision. An owner confirmation or correction creates an append-only certification. Replacing or re-certifying a current record invalidates any prepared onboarding submission that depended on the old evidence.
Before a Garage agreement is submitted for signing, Garage freezes the current certified revisions into an immutable evidence package. The package identifies the source documents and pages, their hashes, the owner certification, and a package hash. Garage then retains the official signed PDF, its SHA-256, BoomPay Sign submission, document and audit references, the evidence-package reference, and the verification URL in actor-scoped agreement history.
For a repair request, Garage retains the exact work order, itemized quote, photographs, revisions, final invoice, shop actor, vehicle and amount facts, and lifecycle events. Changing an exact offer or its evidence supersedes the old authorization and requires a fresh customer review and signature in Boost.
Audit record
Every meaningful authentication, create, correction, review, upload, view, download, verification, signature, export, status change, delivery, and cross-service handoff records an audit event with the source service, actor, time, entity, purpose, legal basis, retention class, and a narrow payload. Audit payloads use identifiers, outcomes, and hashes; they do not contain document bytes, raw OCR text, secrets, raw provider responses, private eligibility limits, or unrelated personal information.
The audit event required for a protected view or download is recorded before record data or document bytes are returned. If auditd is unavailable for a required action, the action stops. Browser telemetry and session replay are operational diagnostics and are not the legal or operational paper trail.
Review and correction
Show the current facts before the signing action. Let the person correct an error. Create and link a successor instead of editing or deleting history. Do not preselect the review statement.
A signing action must state what the person reviewed and what the action authorizes. A vehicle card, document upload, automated suggestion, or BoomPay Sign certificate does not by itself approve a repair, loan, payment, or lien.
Copies and verification
After completion, the authenticated person must be able to view and download the exact retained PDF or record copy that belongs to them. BoomPay records the view or download before it returns the document. If the audit service is unavailable, the document action stops.
BoomPay Sign is the source of the official signed PDF or certificate. A certificate proves document integrity. It is not a substitute for a required customer signature. A retained PDF can be checked with the BoomPay document verifier.
Retention and access
Paper-trail history is append-only. A current-state pointer or status may advance only through an authorized, audited transition that preserves the prior record. Access is limited to the correct customer, garage, partner organization, or authorized BoomPay role. API tokens, raw provider responses, private limits, and unrelated customer records are never part of the displayed trail.
Every record carries an explicit retention class. Routine releases preserve the authoritative database and document volumes. Retention expiry, legal hold, archival, and approved destruction are controlled operations; an application user must not silently delete history.
Minimum release check
- A protected record cannot be viewed, downloaded, changed, signed, exported, or handed off when its required audit event cannot be recorded.
- A correction or replacement leaves the prior record readable to authorized history views and identifies what it supersedes.
- The stored bytes match their recorded size and SHA-256 before they are served or used in an evidence package.
- Agreement history is actor-scoped and retains the official signed PDF and BoomPay Sign references.
- Cross-service views expose only the fields and documents required for that service's authorized purpose.
Legal review
This standard describes evidence handling and product behaviour. It does not decide whether an agreement is enforceable. BoomPay must use the reviewed agreement and authorization flow required for the specific legal purpose.