GateSolutionsAssuranceProtocolProofDocsPricingRequest pilot
California public-interest reference

Make the public payment prove its authorization before it moves.

EMILIA Program Integrity Gate binds a provider action, authorization, destination, amount, and named approval into one exact-action record—then permits one bounded execution or refuses it.

Designed to sit beside existing program-integrity analytics and payment systems. It does not replace DHCS, CA-MMIS, or their controls.

Before public funds move
One action.One accountable decision.One execution right.
Wrong fields
Do not execute
Unknown outcome
Do not replay
Outside review
Portable evidence

Synthetic and PHI-free. All names, identifiers, amounts, authorizations, destinations, and outcomes below are deterministic fixtures.

Reference lab · no production effect
Interactive reference lab

What happens at the moment of consequence?

Ready to runDeterministic local fixture
Proposed consequence

Exact authorization

Every material field matches. One bounded release is authorized.

Canonical Action Identifier (CAID)caid:1:health.medi-cal.hospice-claim-payment.1:jcs-sha256:_gaImSfYxk3C1BAqP2t3_bYhoHLb1FbGdvh8uk9jM28

Any material field change produces a different action identifier.

AUTHORIZEDRun to verify
  1. 01
    Bind exact actionCanonicalize every material field into one CAID.
  2. 02
    Verify policyCheck authority, signoff, authorization, and destination.
  3. 03
    Bound capabilityIssue at most one tightly scoped execution right.
  4. 04
    Submit onceCall the existing executor with the bound action.
  5. 05
    Resolve outcomeAuthenticate provider evidence before any next action.
  6. 06
    Seal evidencePreserve a portable packet for outside review.
01 / Exact action

Material fields

Action schema
EP-HEALTH-PROGRAM-INTEGRITY-ACTION-v1
Reliance profile
medi-cal.hospice-integrity.v1
Action type
health.medi-cal.hospice-claim-payment.1
Organization (synthetic)
org:ca-dhcs
Provider NPI (synthetic)
1234567890
Member reference (pseudonymous)
member:sha256:1111…1111
Service period start
2026-07-01
Service period end
2026-07-15
Claim amount
1250.00
Currency
USD
Authorization form digest
sha256:2222…2222
Payment destination commitment
sha256:6666…6666
Named reviewer
reviewer:integrity-17
Reviewer authority proof
sha256:4444…4444
Pinned policy
policy:dhcs-hospice-payment
Policy version
1
Policy body digest
sha256:7777…7777
02 / Policy decision

Evidence checks

Pass
Provider standingSigned enrollment snapshot · active
Pass
Verified authorizationForm digest present and verifier accepted
Pass
Action / authorization bindingReceipt CAID equals proposed-action CAID
Pass
Payment destination bindingAuthorized destination equals executor destination
Pass
Named human signoffProgram integrity reviewer · device-bound
Pass
Service and approval windowWithin policy-valid time bounds
03 / Execution right

Bounded capability

CONSUMEDcap_syn_71B9…C201
Scope
One claim release · exact CAID
Budget
USD 1,250.00 maximum
Usage
1 of 1 consumed
Expiry
2026-07-23 14:36 UTC
Amount, destination, action, use count, and time are all bounded.
Executor outcome control

The timeout is a state—not permission to try again.

AUTHORIZED
Initial executor responseProvider accepted the exact bound action.
No-blind-replay guardREFUSED · capability already consumed
Authenticated reconciliationAuthenticated executor receipt: EXECUTED
Safe terminal handlingThe same capability cannot release a second payment.
Portable evidence packet

The agency does not have to take the operator’s word for it.

The packet carries the exact action, policy decision, bounded capability, executor outcome, and evidence-chain head. An authorized reviewer can preserve it and verify it outside the application.

evidence-packet.json
version
emilia.program-integrity.packet.v1
policy
policy:dhcs-hospice-payment@1
challenge
chlg_syn_20260723_1430_00421
verifier
offline-compatible
fixture
true
phi
false
decision
authorized
action_caid
caid:1:health.medi-cal.hospice-claim-payment.1:jcs-sha256:_gaImSfYxk3C1BAqP2t3_bYhoHLb1FbGdvh8uk9jM28
receipt_digest
sha256:9999999999999…999999999999
capability
cap_syn_71B9…C201
executor_outcome
executed
evidence_head
sha256:aaaaaaaaaaaaa…aaaaaaaaaaaa
Honest boundary

A consequence-control demonstration, not a fraud detector.

This browser fixture does not make eligibility, coverage, medical-necessity, provider-sanction, or payment decisions. It demonstrates how an agency can make existing decisions exact-action bound, single-use, fail-closed, and independently reviewable before a consequential action executes.

Practical next step

Test one protected workflow for 60 days.

Start in observe mode beside the existing program-integrity and payment stack. Exercise valid, missing, mismatched, replayed, revoked, and indeterminate cases, then give the portable packet to a separate authorized reviewer.

Scope an observe-mode pilot
Program Integrity Gate | EMILIA | EMILIA