What the reader sees
The Shared Record, screen by screen: the code, the first sentence, the entries, the seal, and the controls the other side can use. Nothing on it edits the record.
A Shared Record is the page the other side opens from the link you send. It is the same page for a customer, an auditor, a regulator, or another company's engineer, and it needs no account. This page walks it top to bottom, in the order a reader meets it, so you know what your customer will see before you send the link.
The code
The link opens on one screen: the record's name, your organization, and a field. "Enter the code that came with this link to open this record." Nothing of the record is served until the code is entered, and the check does not run until then. Five wrong tries lock the field for fifteen minutes; the record does not change. The code is six characters and you send it by a separate channel from the link.
The first sentence
The record opens and the check runs at once, in the reader's browser, over the history PacSpace served. While it runs the page says "Checking this record in your browser." When it finishes, the first sentence is the count: how many entries the record has, how many match what was committed, and when the last one was committed. When one does not match, the sentence names it: "This record has 3 entries. 2 match what was committed. Entry 2 does not match."
Under it, three lines every reader gets: "Checked in this browser just now." The boundary: "The check shows the record is unchanged since it was committed. It does not show that what was recorded was true." And what the check is: "Your browser compares this record's fingerprints with the ones committed on infrastructure no party controls, and confirms the entries run from the first to the last with none missing."
If PacSpace cannot be reached when the page opens, the sentence says nothing was fetched and nothing was checked. If the check cannot finish, it says so and confirms nothing. The page never says "checked" unless the check ran.
The record
Three figures: entries committed, days with entries, and the alignment, "N of N match the committed record". A bar for every day with entries, linked to a calendar; hovering a bar lights its day and reads "14 September · 7 entries". Opening a day shows its entries as a table, the title first, with the entry's kind and actor under it, its number, its state, and its time in UTC. A day with no entries opens too, and says what the entries on either side put it between: "Entry 90 happened on 13 September at 09:41 UTC, and entry 91 on 14 September at 09:41. The record holds nothing between them, and it doesn't say why." A gap in the record is as telling as a change.
Opening an entry shows the sealed record as it was committed: the title, the time, who acted, and the fingerprints of the files it names. Under it the seal, 64 characters, and one of two sentences: "The sealed record reproduces this seal." or "The sealed record does not reproduce this seal." Then "Committed under" and the reference it was committed under, and the writer and the actor as two separate facts: "Written by Northwind Robotics, CI key" and "ci-runner-7 is who acted. It does not hold this key."
When an entry amends an earlier one, both are shown, each marked, with "Open it" between them and the line "An amendment is a new entry. This one stays as it was written."
Change one character
Three controls under the entries: "Change one character", "Check again", and, once a character has been changed, "Restore". They change the reader's copy in their browser and nothing else. Change one character, and the page says "You changed one character of your copy. The committed record did not change." Check again, and the check catches it: "The change shows." Restore, and the original is back and the check passes again. This is how a skeptical reader satisfies themselves that the check is real, on the page, without trusting anyone's word for it.
Check a file you hold
A drop target: "Drop the file here. It is fingerprinted in this browser and never uploaded." The reader drops a file they were given, the browser fingerprints it, and the page says "This file matches an entry in the record." or "This file is not in the record." The file never leaves their machine.
Record that you checked this
Optional. "It writes a record of its own that says you checked these entries today. This record does not change, and the acknowledgment is never required to check it." A reader who presses it writes an acknowledgment, under the name you gave the link when you shared it, that they checked entry N on that day and whether it matched. It appears beneath the record for you and for anyone who holds a link: "Acknowledged through the link issued to Acme, 14 September. Entry 3 was checked and it matched." It is offered only after a check has finished, and an acknowledgment of a failed check says so.
Print a statement
A link to the printable statement, once a daily statement covers every entry of the record. Until then the page says when it will be printable. See The statement and the check without PacSpace.
Show details
A disclosure at the foot of the page with the counted sentence as PacSpace holds it, for a reader who wants the server's count beside the browser's.
What it never shows
The record page shows the reader what you wrote and what was committed. It shows no file, no storage location, and no key. It shows no other record of yours. And it edits nothing: every control on the page acts on the reader's copy in their browser, and the committed record cannot be changed from this page or any other, by you, by the reader, or by PacSpace.