Every scan is a question.
A case, a lot, a single unit — five attested hands, continents apart. visibility.cloud chains every hop into one verifiable record — who asked, who answered, on whose authority.
There is no single version of this problem.
Anonymity is one defect and it sends four different bills. A recall page written for a jeweler is a page about somebody else’s week, so this surface does not write one. Pick the bill that is yours; each read stands on its own evidence and says what that evidence is.
- RecallOne run went bad and you withdrew everything it could have been in. Food CPG and QSR — whoever owns the recall desk.
- AuthenticityA convincing copy carries the same digits as the original. Jewelry, watches and luxury — brand protection, and whoever answers the client.
- ShrinkEvery unit was scanned, and the investigation still ends at “seen here, then not.” Apparel and general merchandise — loss prevention, and the fulfillment side that owns the dock it happens on.
- The discarded scanThe lane reads the serial, the lot and the expiry, and keeps none of them. Retailers and brands on the Sunrise 2027 timeline.
Nothing in your building is broken.
The barcode scans first time. The register rings it. The warehouse books the receipt and the count reconciles at the end of the period. The drill is on the calendar, the read points are where they should be, the artwork went through every stage it was meant to. Nobody skipped anything, and nobody was sold a bad product.
Every one of those four bills is what doing it correctly produces — given a record that was only ever asked one question.
It names a class. That is all.
It is worth being precise about what the limit actually is, because the imprecise version is easy to dismiss and the precise version is not.
The barcode is not unreadable. It is read constantly — more often than any other act in your business. It is not inaccurate; it is one of the most reliable pieces of engineering in commercial history. It is not proprietary, or hidden, or withheld by anybody.
It answers what kind of thing is this with total precision and total reliability, and it has no capacity whatsoever to answer which one.
The gap is always exactly where the dispute is.
Inside your own four walls, you can reconstruct a run. The trouble starts at the door.
The carrier's system says one thing. The 3PL's says another. The four hours between pickup and cross-dock exist properly in neither, because each side recorded its own half and nobody recorded the seam. When the auditor asks who had custody of this lot at 14:20, that seam is what you hand them.
And the fix has a way of going quiet. Visibility programs tend to stop the month the capture bill lands — not because anyone decided the evidence was worthless, but because the line item grew with volume and the answers did not.
One problem, not two.
The barcode that could not say which one, and the record that cannot say who, are the same defect at two different grains.
A record that names a kind of thing, performed by a kind of party. Categories all the way down, in a world where the questions being asked are about individuals.
If you have started nodding, check this before you believe the rest.
Not an argument — a citation, and it is free. Ten minutes with published specs, no account and no call, and it is the reason “a company has no hands” is a structural statement rather than a slogan. The engineer’s version of this ledger — pinned digests, exit codes — is at epcis.dev.
Stamped from outside. Stripped of whatever you sent.
The capture spine underneath visibility.cloud is written, and these are its laws rather than its features. They are the part that cannot be renegotiated later.
-
01
Conforms to EPCIS 2.0 and CBV 2.0.
Implemented against GS1's official OpenAPI description, pinned by digest.
-
02
Validated on every capture.
Each event is machine-checked against the official GS1 EPCIS 2.0 JSON schema before it is accepted. A capture that does not validate is refused, in RFC 7807 problem+json, carrying the standard's own exception types — not a vendor error string.
-
03
Stamped by the gateway, not by the sender.
recordTime, who captured it, and the grade of that attestation are applied at the door. Whatever you sent in those fields is stripped. The scriber is not the part being scribed.
-
04
Identified by the standard's own hash.
The standardized EPCIS event hash from CBV 2.0 §8.9, with GS1 Digital Link normalization, so the same event captured twice is the same event, and a changed event is a different one.
-
05
Append-only, by construction.
No service identity anywhere in the system holds an UPDATE or a DELETE grant. You can add an event. You cannot erase one.
-
06
Minimally scoped on read.
You see your own scope. What is outside it is absent, not grayed out and not redacted — there is no shape left behind to argue about.
-
07
Ten years of vendor XML, translated.
EPCIS 1.1, 1.2 and 2.0 XML in, EPCIS 2.0 JSON-LD out, with a round-trip fidelity report per job so the translation is reviewable rather than trusted.
-
08
A door for agents as well as people.
The same interface, the same key, over MCP — so a partner's logistics agent can capture and query without a human copying values between two systems.
What the laws add up to: Everyone in this market has built a network that is authoritative because you joined it. This platform makes a record that is verifiable whether or not you joined anything — and it carries, in the record itself, an attested answer to who observed the event, including when the observer was an agent.
All of the above is implemented and verified: 1031/1031 spine tests pass against GS1's normative artifacts, and the translate, validate and hash doors are live at epcis.dev today.
Where atoms generate bits, someone is being paid.
Energy and silicon become tokens, and that trade is metered, invoiced, and growing every quarter. A print, a scan and a read are the same trade at the other end of the economy — a physical act, and a record that could come out of it — and your building performs thousands of them a day.
Where they do not, something is being lost, and there is no line for it anywhere.
Both ledgers are rented. Only one has a meter.
You rent reasoning by the token, and every token is billed to a request, a key and an owner. You rent production by the case, and the case is billed to nobody.
The plant that makes your product is a generating station too — raw material in, finished units out, all day. It counts what comes off the line. It cannot tell one unit from another, because nothing about a case distinguishes it from the case behind it, so what the line reports is a total and never a unit. Owning the plant instead of renting it changes what you can do about that, and nothing about the meter.
A unit that was only ever counted in a total cannot be priced apart, insured apart, financed apart, recalled narrowly, or preferred by a machine.
Capture is free. It stays free.
Not a trial. Not a tier. Not a meter you watch.
Recording an event will never cost you money. That is a policy of the platform, not an introductory price, and it holds because the cost structure underneath capture is object storage and a catalog, which is cheap enough to carry permanently. It is not a subsidy paid for by something else, and it will never appear in the interface as a counter. Stated as policy ahead of published terms: terms post here the day they are set, and this sentence carries them.
Revenue attaches to answers, on the business side: traces, custody evidence you can hand to an auditor, exception review, partner grants, seats, retention beyond the free floor. You will pay for what you ask, never for what you record.
Prices for the answers post here when they are set: as numbers, on a page, without a call.
Your record. Their record. Nobody's merged.
The hard problem in this category has never been the run. It is the handoff — and the reason handoffs are hard is that they are between two companies who will not, and should not, pool their records.
So sharing runs on grants, not on a merge. Your 3PL grants you scope on the events they captured; you grant them scope on yours. Two records stay two records. Neither party is principal, whichever one is larger. A grant is narrow, dated, and withdrawable, and withdrawing it rewrites nothing either side already holds — because nothing in this system rewrites.
Every link carries an attested who at a grade — the spine records who captured an event and at what grade. Turning that attestation into a resolved party identity — a GS1 Digital Link answered with a named organization — is not built; it is one of the open lines on What ships today, and it ships behind that line, never ahead of it.
Two clocks. Neither of them is ours.
Sunrise 2027 is the timing. It is GS1's program, not ours: by the end of December 2027, retail point-of-sale is expected to scan and process 2D barcodes as well as the linear ones. That changes who generates supply-chain events. Today it is scanners, on docks, run by staff. After it, the same carton is scannable by a shopper on a sidewalk, by a returns clerk, by a partner's agent — humans and devices, most of them not yours.
FSMA 204 is the return, never the urgency. The largest public RFID rollout in food service — roughly 3,200 restaurants — is attributed to FSMA 204's compliance requirements by the deploying software vendor's own president: a third party carries the causal claim, not us. And the rule's own record is softening, not hardening — the enforcement floor moved to July 2028, and FDA is actively soliciting further flexibilities. Use FSMA 204 for operational ROI and Sunrise 2027 for timing, never the reverse. Anyone selling you the deadline as a gun to your head is one search away from being caught.
For the brand that owns the GTIN, the same square points both ways. The 2D code on your own carton will make every shopper scan and every returns scan an item-level signal attributable to your GTIN and your lot, in a record the retailer does not own and cannot withhold — which is also what turns a full recall into a lot-level withdrawal. Which barcode you print is your decision as GTIN owner — not your co-manufacturer's, and not Sunrise's. Whether shoppers scan at volume is a hypothesis, and we say so: a bet we are asking you to shoot down, not a number we can cite.
A public GS1 Digital Link resolved through id.gs1.org answers what the item is; by policy it will not tell you who touched it — that resolver is anonymous by design (see GS1's own conformant-resolver standard for what a public resolver returns). visibility.cloud is the private, brand-owned counterpart that names who touched each item: for the brand that owns the GTIN, item-level visibility that names the party at every step, not the anonymized trace the public resolver returns. Resolving a party from that record is unbuilt and listed as unbuilt on What ships today; what the spine writes today is the attested observer the resolution will read. You see your own product move, down to the individual item, by serial number, with a who on every link.
Fork the scan.
The retail lane will read the whole symbol and keep a twelfth of it. The other eleven twelfths are yours for the asking, and asking costs nobody a behavior change.
From the end of December 2027, under GS1’s Sunrise program, retail point of sale is expected to scan and process 2D barcodes as well as the linear ones. A 2D symbol on a consumer pack can carry the GTIN, the serial, the batch or lot, and the expiry date, in one scan, at the same counter, on the same hardware. The register needs the GTIN. It has no field for the rest and no reason to keep it.
So the fork is the whole idea, and it is deliberately unambitious: the GTIN goes where it already goes, and the serial, the lot and the expiry go to your record instead of to the floor. Nobody scans differently. Nothing new is bought for the lane. The date is already on somebody’s plan in your company, because the artwork has to change anyway.
The lane-side split is not built, and What ships today says so. What is live today is the read underneath it: the interview at get started ends every business path with the Sunrise decision read for your situation — which symbology and which URI form is genuinely your decision as GTIN owner, and what the lane must extract versus what nothing obliges you to encode.
One place to point your agents.
An agent buying from you has to show whose money it is spending and under what limit. An agent working inside your plant has to show whose authority it holds and which task it was asked to perform. Those are the same question, asked from opposite sides of the same door.
Your agents will reason over anything you hand them. What they get handed is fourteen systems, a credential each, and no two of them describing the same object the same way.
visibility.cloud will onboard those sources as one surface: modern SaaS platforms through their own APIs, Apache Iceberg lakes read and written in both directions, the EDI mailbox that has been running since before anyone there was hired, and the print, scan and read events coming off the floor — landing as one event record with an attested observer on it, at the grain a question is actually asked at.
Then the agents get one secure place to explore it, under a seat with a written mandate: scope named, ceiling named, every read evaluated against the same grants every human read is. The point is not a chat window over a warehouse. It is that the answer comes back actionable — a bounded set of cases, a named handoff, a specific gap — instead of an integration project per source.
Neither the sandbox nor the seat mandate it runs under is built, and What ships today says so. What is live today is the machine face this surface already publishes: /llms.txt, /icp.json, /agent-classes.json, /flow.json and /variants.json, plus the markdown twin of this page on this same route.
What ships today, and what does not.
Live and verified
- POST epcis.dev/translate — EPCIS 1.1 / 1.2 / 2.0 XML → 2.0 JSON-LD, with a per-job fidelity report. Live; curl it
- POST epcis.dev/validate — verdict against the sha256-pinned official GS1 EPCIS 2.0.1 schema, per-path errors. Live; curl it
- POST epcis.dev/hash — the CBV 2.0 §8.9 event hash, GS1 Digital Link normalized, gated on OpenEPCIS reference vectors. Live; curl it
- 1031/1031 spine tests pass; GS1's normative artifacts vendored and pinned by sha256 digest, re-checked in CI
In What ships today — the open entries
- Issued capture keys — the hosted door answers a key today; issuing one to you waits on a verified sending address and a named human sender
- The Iceberg write path (Pipelines → R2 Data Catalog) — the hosted spine writes the same rows, on the same daily partitions, straight to R2 today; the Pipelines stream that would carry them is refused by the account quota (code 1017, 20 of 20 streams used), so the cutover is a backfill behind a limit increase
- The public repository and its clone URL — the engine is MIT-licensed and published on npm; opening the repository itself is a decision we have not taken
- Published prices — they post here as numbers when set
Four lines from each column. The ledger in full, dated, is a page of its own.
Why trust this page.
Not because of who wrote it — because of what you can check. The standard is implemented as written, against GS1's own normative artifacts, vendored and pinned by sha256 digest and re-verified in continuous integration; validation errors carry the standard's own exception types; the event hash is the standard's own, gated against someone else's reference vectors, not ours. Where we have made a choice the standard leaves open, we say so.
GS1 has not reviewed, certified or approved this platform, and nothing here should be read as a GS1 position. The whole site is checked against a dated ledger — What ships today, which lists what answers over HTTPS now and what does not — and a claim anywhere on this origin that outruns that list is a defect you should report the way a defect is reported.
visibility.cloud is stewarded under The Org.AI Foundation.
What you will buy here: answers.
Capture is free. Revenue attaches to answers, on the business side — and every answer is a view over the same record the developer surface queries, so there is nothing to audit because there is nothing separate. Each answer is a view over a spine primitive that already passes its tests — 1031/1031 — and each states, in its own words, which part of it is not built; the dated list of those is What ships today.
- The traceWhere is it, and who touched it — the full event chain, with the attested observer at every hop.
- Custody evidenceThe record that holds up in the room — hashed, append-only, verifiable without joining.
- Exception viewsThe handoffs that went silent — received with no performer, custody never closed.
- SharingGrantsShare exactly these goods, this window, this grain — and revoke without rewriting history.
- Recall & audit readinessFSMA 204 without the war room: the trace-back as a query, exportable.
- The Sunrise 2027 readWhat December 2027 requires of you — deliverable today, because it is documents.
- Seats & deputizationThe mandate your agent works under: scope named, ceiling named.
Built in the open. Three engines under this page.
visibility.cloud is the commerce layer of a family that builds in the open. Underneath this surface are three developer-facing sites — each one public, readable, and an engine you can run, before you believe a sentence here. Every answer sold on this page is a view over the record they write and read; there is nothing separate to audit. Their mastheads carry “· by visibility.cloud”; this fold is the acknowledgment in the other direction — what each one is, in one line.
- epcis.devThe event engine — an EPCIS 2.0 capture gateway: every event validated against GS1's pinned official schema, stamped at the door, hashed by the standard's own hash, append-only. Its translate, validate and hash doors answer on that origin today.
- transactions.devThe paperwork layer — purchase orders, ASNs and invoices, X12, EDIFACT or API-native, compiled onto the same event record in the standard's own vocabulary. The paperwork rides the record; it never becomes a second one.
- barcoding.devThe barcode layer — every barcode read, verified and generated, GS1 to VIN to ISBN, with the source and license named on every answer. Reading a barcode is free there, and it stays free.
- worklists.devThe work layer — a task will be the causal parent of the events that satisfy it, so the record reads “this was scanned because this task said to.” Closing one will mean presenting an attested capture rather than ticking a box, so the record of work done and the evidence it happened are the same object.
The who at every hop resolves via id.org.ai — Agent. Human. Thing. — the family's identity layer; naming it is all this page does with it. The argument for one family over one record is written down on each of them: From stripes to grids here, Observability and traceability are one at the event engine, The paperwork is a projection at the paperwork layer, The meaning behind the stripes at the barcode layer.
Give one of them a name.
Your capture workspace is provisioned from the list. We write when your seat is ready, and follow up about it from there.