visibility.cloud

The loss has a number.
It has no address.

A fully instrumented chain tells you where a unit was last read. It cannot tell you who was standing there.

Apparel and general merchandise — loss prevention, and the fulfillment side that owns the dock it happens on.

Verified 6 August 2026. The spine behind this page passes 1031/1031 conformance tests against GS1's normative artifacts, and its translate, validate and hash doors are live at epcis.dev. The dated built-and-tested summary is at What ships today.

There is a claim open on a load that came up short. You have the BOL, the POD, the seal number, the license plate on every pallet and a cycle count that disagrees, and the evidence class that would actually name a person is the one the job posting calls verbal communication: a supervisor’s recollection, a paper sign-in sheet, a camera pointed at the next door over. That is a window, not a record, and it closes as the roster turns over. The hop it closes on is almost always the one you do not staff — an agency shift on the cross-dock, a carrier’s driver, the returns desk. Custody genuinely changed hands there. Nobody logged into anything to do it.

The investigation is not being run badly. The read points work, the count is accurate, the exception fires on time, and whoever is working the claim knows exactly which hop to suspect before they open the file. Add another read point and you will buy a tighter interval — the gap narrows from a shift to an hour — and you will learn nothing new about what happened inside it, because the new read is the same kind of fact as the old one.

What it costs you.

A decade ago every scan in this building was a deliberate human act. Somebody picked up a device, pointed it at a label, waited for the beep and put the device down, and the record that came out the other side had a person behind it whether or not anybody wrote that down. Walk the same building now. A fixed reader fires on a conveyor. A portal reads a pallet as it crosses a line on the floor. An autonomous unit reads a rack at three in the morning. One of those is a witness and the other is a sensor, and your record cannot tell you which one you have.

That is not an instrumentation gap you can close by adding read points. The read record has no field for a performer — and the evidence that could name one, a proof-of-delivery signature, a door camera, a WMS login, sits in a different system with nothing to join on.

So the loss is attributed to a site, a shift or a period, and the case closes as a number in a report. The marginal information left in a fully-scanned chain is not another scan. It is a witness.

Try to write the name down.

Take a receiving event that has just passed GS1’s own published EPCIS 2.0.1 schema. Add one field naming the person who took the load. Post it again to the same validator, which takes no key and no account and returns the schema’s verdict, not ours.

  1. The event as the standard has it — a company, a location, a time:

    $ curl -sX POST https://epcis.dev/validate \ -H 'content-type: application/json' -d @receiving.json "valid": true, "errors": []

  2. The same event, with the name of the person who received it:

    $ curl -sX POST https://epcis.dev/validate \ -H 'content-type: application/json' -d @with-a-name.json "valid": false, 8 errors, among them: { "path": "/epcisBody/eventList/0", "keyword": "propertyNames", "message": "property name must be valid" }

There is a way to make it pass: namespace the field — acme:receivedBy, with your own prefix declared — and the same validator says valid again. That is not a workaround, it is the finding. The standard will let you write the name down, in a place nothing but your own systems will ever read. Which is exactly where the answer sits today, in fourteen of them, with nothing to join on.

the validator door →

What changes.

visibility.cloud will put an attested observer on every read — a person, an agent, or an embodied one; a robot or an autonomous reader on the dock will be attested exactly the way a person is — and will never confuse it with capturedBy, the account that warrants the capture. Those two are already separate where it counts: the capture spine takes the observer from the caller, stamps capturedBy server-side, strips a caller-supplied one and rejects a smuggled one, and every one of those four is held by a named passing test. What remains is the door: that spine answers at api.epcis.dev to a capture key, and issuing those keys is not open yet. When it is, a gap is bounded by two attested events with a named observer on each, and an unattributable number becomes a handoff you can take to somebody.

What this is not. It will not stop a theft and it will not predict one. What it removes is the reason the investigation stops: the last read and the next read will both name who was there, so what is a period today becomes a pair of hands. No shrink figure appears on this page, because we hold none we can show you.

The answer products this read lands on — the trace, the custody evidence pack, the exception view — each carry a named entry in this page, and the answers page names which. What you can exercise today is on this page’s buildline.

Before you take this to a meeting.

4 things a reader who knows this field would stop and correct. Several of them cost us the thing this category is usually sold on, which is why they are on the page and not in a footnote.

  1. 01

    The standard’s party fields are organization-grain on purpose. A GLN or a PGLN names a company doing a process (EPCIS 2.0 §7.2.2, §7.3.6.4; CBV §8.7.1). That is not an oversight anybody left in; it is what the standard was scoped to answer, and it answers it well.

  2. 02

    If your guns log in per person and it is enforced, part of this is already solved inside your four walls. The hops that are not are the ones staffed by people who do not work for you, and that is where this argument lives.

  3. 03

    An attested observer is not a camera and it is not a badge reader. It is a claim made at the moment of capture that somebody stands behind — which is why it has to be distinct from the account that warrants it, and why the two are never collapsed.

  4. 04

    None of this is evidence of a crime. It is a named handoff. What that is worth in a claim, a chargeback or a conversation with a carrier is your call, not ours. GS1 has not reviewed, certified or approved this platform.

One place to point your agents.

An agent buying from you has to show whose money it is spending and under what limit. An agent working inside your plant has to show whose authority it holds and which task it was asked to perform. Those are the same question, asked from opposite sides of the same door.

Your agents will reason over anything you hand them. What they get handed is fourteen systems, a credential each, and no two of them describing the same object the same way.

visibility.cloud will onboard those sources as one surface: modern SaaS platforms through their own APIs, Apache Iceberg lakes read and written in both directions, the EDI mailbox that has been running since before anyone there was hired, and the print, scan and read events coming off the floor — landing as one event record with an attested observer on it, at the grain a question is actually asked at.

Then the agents get one secure place to explore it, under a seat with a written mandate: scope named, ceiling named, every read evaluated against the same grants every human read is. The point is not a chat window over a warehouse. It is that the answer comes back actionable — a bounded set of cases, a named handoff, a specific gap — instead of an integration project per source.

Neither the sandbox nor the seat mandate it runs under is built, and What ships today says so. What is live today is the machine face this surface already publishes: /llms.txt, /icp.json, /agent-classes.json, /flow.json and /variants.json, plus the markdown twin of this page on this same route.

What this read stands on.

No shrink rate, loss figure or recovery number is cited here, because none is held that can be shown. Every claim on this read is a checkable property of a record.

See your first trace.

Capture workspaces for retail and point of sale are provisioned from the seat list — we write when your seat is ready.