Skip to content
PacSpace
Talk to us

A claims agent and the person who decides

A worked example for a government benefits program: a claims agent recommends a decision, an examiner approves or overturns it before the notice goes out, and the program office and its inspector general each check the record.

A benefits program uses a claims agent to read each claim and recommend a decision. An examiner on the program's staff approves or overturns every recommendation before a notice goes out to the claimant. The team that runs the claims system writes one record per claim. The program office reviews a sample of claims each month, and the program's inspector general audits the program. Each checks the record for itself.

The record

EntryTime (UTC)kind · actorIdTitle
109:02:11input-received · claims-agent-3Claim 2026-88104 read: the application and 14 supporting documents
209:02:12model-version · claims-agent-3Model version 2026.08, with the settings the program approved
309:04:37recommendation-made · claims-agent-3Recommended a denial, reason code 4
411:18:05approval-given · examiner-17Denial reviewed and approved
511:18:40notice-sent · claims-agent-3Decision notice sent to the claimant

The agent and the examiner are two actors on one record. The recommendation stays as the agent wrote it, and the examiner's decision is an entry of its own beside it.

What stays out of the record

The claimant's name, numbers, and documents. Each document is named only by its fingerprint, and the record names the claim by the program's own claim number. Everything under content is sealed and stored by PacSpace to run the service, and a reader sees a field only when the program reveals it. Keep personal details out of titles, descriptions, and notes, so that what the program reveals to a reviewer never carries them.

The code

The claims system holds the key and writes the agent's entries. The examiner's case tool writes the examiner's entry, under the examiner's name.

typescript
import { createReadStream } from 'node:fs';
import { PacSpace, fingerprint, readBlindingFile, writeBlindingFile } from '@pacspace-io/sdk';

const pac = new PacSpace({ apiKey: process.env.PACSPACE_API_KEY! });
const record = 'claim-2026-88104';
const agent = { actorId: 'claims-agent-3', instructedBy: 'claims-intake' };

// Fingerprint a file where the program keeps it, and keep its blinding file beside it.
// A second call for the same file reuses that blinding file, so a retry sends the same fingerprint.
async function refOf(path: string) {
  const kept = await readBlindingFile(`${path}.pacspace.json`).catch(() => undefined);
  const { ref, blinding } = await fingerprint(createReadStream(path), { blinding: kept });
  if (!kept && blinding) await writeBlindingFile(path, blinding);
  return ref;
}

// 1. The agent reads the claim: the application and its 14 documents, each fingerprinted where it is stored.
await pac.records.emit({
  record,
  ...agent,
  title: 'Claim 2026-88104 read: the application and 14 supporting documents',
  kind: 'input-received',
  occurredAt: '2026-09-22T09:02:11Z',
  payloads: await Promise.all(claimFiles.map(refOf)),
  idempotencyKey: `${record}:read`,
});

// 2. The model version and the settings it runs under.
await pac.records.emit({
  record,
  ...agent,
  title: 'Model version 2026.08, with the settings the program approved',
  kind: 'model-version',
  occurredAt: '2026-09-22T09:02:12Z',
  payloads: [await refOf('/etc/claims-agent/settings-2026.08.json')],
  idempotencyKey: `${record}:model`,
});

// 3. The recommendation, as the agent wrote it, with its reasons.
await pac.records.emit({
  record,
  ...agent,
  title: 'Recommended a denial, reason code 4',
  kind: 'recommendation-made',
  occurredAt: '2026-09-22T09:04:37Z',
  payloads: [await refOf('cases/88104/recommendation.json')],
  idempotencyKey: `${record}:recommendation`,
});

// 4. The examiner's case tool writes the decision.
await pac.records.emit({
  record,
  title: 'Denial reviewed and approved',
  kind: 'approval-given',
  occurredAt: '2026-09-22T11:18:05Z',
  actorId: 'examiner-17',
  payloads: [await refOf('cases/88104/review.json')],
  idempotencyKey: `${record}:decision`,
});

// 5. The notice goes out only once the decision is committed, so the decision comes first in the record.
await committed(`${record}:decision`);
await pac.records.emit({
  record,
  ...agent,
  instructedBy: 'examiner-17',
  title: 'Decision notice sent to the claimant',
  kind: 'notice-sent',
  occurredAt: '2026-09-22T11:18:40Z',
  payloads: [await refOf('cases/88104/notice.pdf')],
  idempotencyKey: `${record}:notice`,
});

claimFiles is the list of the claim's files as the program stores them. committed resolves when the record.committed webhook lists that idempotency key in records[].referenceId; What an agent did shows it in a few lines. If the model version has a release record of its own, entry 2 can name its entry in references, as in A model release.

When the examiner overturns it

On claim 2026-88131 the agent recommends a denial under reason code 2, and the examiner finds the documents answer it. The examiner's entry says so, and the note gives the reason:

typescript
await pac.records.emit({
  record: 'claim-2026-88131',
  title: 'Recommendation overturned: claim approved',
  kind: 'recommendation-overturned',
  occurredAt: '2026-09-22T14:40:12Z',
  actorId: 'examiner-17',
  payloads: [await refOf('cases/88131/review.json')],
  note: 'Reason code 2 does not apply: document 9 answers it.',
  idempotencyKey: 'claim-2026-88131:decision',
});
Entrykind · actorIdTitle
3recommendation-made · claims-agent-3Recommended a denial, reason code 2
4recommendation-overturned · examiner-17Recommendation overturned: claim approved
5notice-sent · claims-agent-3Decision notice sent to the claimant

Entry 3 stays as the agent wrote it. A reader sees both the recommendation and the examiner's decision, by two actors, in the order they happened.

The program office and the inspector general check it

The program office reviews a sample of claims each month. The claims team sends each sampled claim's history file, and the program office checks each one with the open-source checker, which reads what was committed from the proof layer and never calls PacSpace or the claims team:

bash
curl -H "x-api-key: $PACSPACE_API_KEY" -H "Accept: application/octet-stream" \
  -o claim-2026-88104.json \
  https://app.pacspace.io/api/v1/records/machine-action-record/claim-2026-88104/history

npx @pacspace-io/check claim-2026-88104.json

A history file carries every field of every entry. For a reviewer who should see only some fields, the claims team builds the file with records.disclose instead, revealing the fields that reviewer may read; the checker reads it the same way.

The inspector general opens claim 2026-88104 from a link, with its code sent separately:

bash
curl -X POST https://app.pacspace.io/api/v1/records/machine-action-record/claim-2026-88104/share \
  -H "x-api-key: $PACSPACE_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{ "sharedWith": "Inspector general", "expiresInDays": 90 }'

That link shows each entry's seal. To show the inspector general the entries' fields, the claims team shares from the dashboard's share card and chooses them there. The check runs in the inspector general's browser when the record opens, and any acknowledgment the inspector general records is written under "Inspector general".

What the record answers

  • What did the agent read, and which model and settings did it run? Entries 1 and 2.
  • What did it recommend? Entry 3, as it wrote it.
  • Who decided, and was the decision on the record before the notice went out? Entry 4, examiner-17, committed before the notice entry was written.
  • Where the examiner overturned the agent, what did each say? The recommendation and the decision, side by side, with the examiner's note.

What it does not answer

Whether the examiner read the file, or whether the decision was right. Those are for the program's own review and for an appeal. PacSpace records and never decides. The check shows the record is unchanged since it was committed. It does not show that what was recorded was true.