A trace starts with an actual record
Activity is built from stored workspace events, with searchable history and links to the related request. A node is a record you can inspect, not an animation that implies work happened. Policy requests retain their terms, submitting connection, and owner review.
Keep evidence classes visible
External tool reports are explicitly agent-reported. An administrator first authorizes the tools and evidence origins. An agent can attach hashes, links, timing, and parent references to its own proposals. These reports do not prove that the external tool ran.
Separate permission from provider outcome
An approved proposal shows an authorization decision. Refund provider observations describe what Stripe test mode reported. Neither an agent's success message nor a policy approval should be presented as settlement.
Know the evidence boundary
Commerce events are append-only in the application database. They are not independently signed or externally anchored receipts. Database administration, backups, retention, and independent assurance remain part of operating the deployment.