Follow the authority.
Trace how a customer action becomes a business record, a provider request and a result your teams can explain.
The system in four layers
Web and mobile experiences call application services. Verified identity and current permissions determine the caller’s scope. Domain services own state transitions and durable records. Provider adapters translate approved external contracts without becoming an alternate source of domain truth.
| Layer | Responsibility |
|---|---|
| Experience | Business workspace, hosted journeys and consumer wallet. |
| Authority | Verified sessions, membership, ownership and capability checks. |
| Records | Payment state, journals, receipts, audit and durable work. |
| External execution | Approved provider calls, authenticated outcomes and settlement evidence. |
Durability before delivery
Payment requests and downstream work are recorded transactionally. Leased jobs handle retries and delayed processing. Inbound events are durably accepted and deduplicated before their business effects are applied. A scheduler triggers work; it is not the source of truth for that work.
Production timing, throughput, recovery drills and service commitments require target-environment evidence. The existence of a queue or retry mechanism is not an uptime or latency guarantee.
Software records and financial authority
The synthetic demo ledger is authoritative for its simulations. A real account or payment program must establish the financial provider’s authoritative book and how Peyeli’s operational subledger reconciles to it. A mismatch must be investigated rather than hidden by editing history.