ChangeLock

A legitimate change should not preserve stale authority.

ChangeLock freezes the requested material change, requires independent approval, revokes old authority, applies one field, and requests a new ReleaseLock evaluation.

Capability map

How this part of Freight Passport is structured.

Explore the interactive demo →
01

Protected facts

Carrier, driver, tractor, trailer, origin, destination, facilities, windows, risk, policy, seal information, and critical instructions cannot be casually replaced.

  • Initial assignment remains possible
  • Replacement requires ChangeLock
  • Exact old and requested values frozen
02

Independent decision

Requester and approver separation, active scope, strong authentication, versions, and deadlines are rechecked inside the command.

  • No self-approval
  • Distinct approvers
  • Database-clock expiration

The current backend enforces a numeric approval threshold; carrier-security plus customer-security approval domains are not yet guaranteed.

03

Revoke before mutation

Current decisions and unused credentials are revoked before the approved value changes.

  • One protected field per request
  • Immutable action record
  • Durable reevaluation intent
04

Reevaluate before release

Applying a change never creates new authority. A later persisted evaluation must consider the updated shipment state.

  • Old token cannot survive
  • New evaluation linked to change
  • Customer decision remains separate

See it in context

Test the handoff decision yourself.

Use fictional shipment data to explore a valid arrival, a blocked mismatch, a protected change, and a replay attempt.