PackAuth

Packaging lifecycle compliance infrastructure

Approve packaging before it is printed, shipped, sold, or changed.

A missing Arabic label block is a container stopped at the port. A missing allergen is a recall. Both are decided at artwork stage — in an email thread, against a spreadsheet nobody version-controls.

PackAuth is the authority layer that catches them before the plates are cut, then holds the approval, the evidence and the release certificate that prove why the pack was cleared.

Cloudflare-first · Stripe-metered · API, agent and widget first

artwork re-run print re-plate shipped re-label on shelf recall cost to fix
The same error, caught at four stages. PackAuth operates at the leftmost bar — the only one where a fix is a file change.
24lifecycle states, concept to archive
12policy rails gating every consequential action
61deterministic rules — no model guesses a verdict
8approval types, each scoped to real authority

The problem

Packaging approval is the last unowned process in the supply chain

Formulation has a PLM. Production has an ERP. Quality has a QMS. Packaging approval — the decision that legally commits a brand to a claim in a market — runs on email, PDF markup and the memory of whoever has been there longest.

The container that does not clear

Artwork ships to a Gulf market without a complete Arabic label block, or without a registered importer on pack. Goods are produced, palletised, shipped — and stopped. The cost is the freight, the demurrage, the re-label and the retail window you just missed.

The allergen that moved

A supplier reformulates. The spec is updated. The artwork is not — or it is, and the emphasis rule for the destination market is missed. This is the failure mode that ends in a recall notice, and it is a data-reconciliation problem wearing a safety hat.

The claim nobody can substantiate

"Halal", "recyclable", "no added sugar" go on pack because marketing asked and nobody could produce the document that says otherwise. Eighteen months later a regulator asks who approved it, against what evidence — and the certificate expired last spring.

None of these are AI problems. They are authority problems: nobody can say who approved what, against which evidence, for which market, on what date.

The solution

An authority layer, not another label checker

PackAuth does not begin at "upload a PDF". It begins at the manifest: what the product is, where it is going, who is responsible, and what evidence that requires. Artwork is one input to that, checked late — not the thing the process is built around.

Every consequential action passes a rail: an ordered set of checks that must all hold before the action is permitted. No approval without a locked evidence snapshot. No print release without a live, in-scope approval. No release at all while a blocking finding is open.

AI proposes. Rules decide. Humans approve. PackAuth records.

What a model may never do here

  • Approve packaging
  • Activate a rule
  • Override a blocking finding
  • Issue a print release
  • Mark evidence legally valid
  • Grant a stakeholder authority

Models extract, classify, translate and recommend — genuinely useful, and genuinely fallible. The verdict comes from deterministic rules over canonical data; the signature comes from a person who holds the authority to give it.

How it works

Six stages, each one gated

The lifecycle is a state machine with 24 states and 39 legal transitions. An illegal transition is rejected with the attempted edge recorded — never quietly coerced into a legal one.

1 2 3 4 5 6 Classifyproduct + markets Resolveapplicable packs Evidencefrom counterparties Checkdeterministic rules Approvescoped authority Releaseverifiable certificate classification rail billing rail evidence rail rule engine approval rail print release rail Stage 1 — Classify and target Stage 2 — Resolve packs Stage 3 — Collect evidence Stage 4 — Check deterministically Stage 5 — Approve with scope Stage 6 — Release and hold
Every stage names one rail and runs it to completion before acting. Select a stage for detail.

The lifecycle

Every state, and what moves out of it

This is the spine. A manifest sits in exactly one state; an illegal transition is rejected with the attempted edge recorded, never coerced into a legal one. Red states block a release, green states permit one. Select any state for detail.

revalidation 24 states 6 block a release · 5 permit one 00 draft 01 classified 02 requirements generated 03 evidence requested 04 evidence pending 05 evidence complete 06 artwork pending 07 artwork uploaded 08 extraction complete 09 compliance running 10 findings open 11 remediation required 12 review required 13 approved for scope 14 approved for print 15 released to print 16 printed 17 market release pending 18 released to market 19 live 20 stale 21 revalidation required 22 superseded 23 archived
blocks release release permitted in progress dashed — terminal Select any state for its transitions.
Staleness is automatic. Eleven change classes demote a live approval back to revalidation required — artwork version, formula or spec, target market, rule pack version, standard version, claim, packaging material, supplier evidence expiry, certification expiry, counterparty suspension, and revocation of the approver's authority. Nobody has to notice.

On the artwork

Every finding points at a place on the pack

A compliance run is not a score. It is a list of locations — this panel, this line, this missing block — each traced to the rule that raised it and the pack that rule was bought with. Select any marker.

Front of pack CHOCO biscuit selection product photography Milk chocolate biscuits VEGAN 120 g ℮ 5 012345 678900 Made in the United Kingdom Back of pack INGREDIENTS Wheat flour, sugar, cocoa butter, cocoa mass, palm oil, whey powder, salt, raising agent, natural vanilla flavouring NUTRITION per 100 g energy · fat · saturates · sugars · salt Arabic panel — not detected BEST BEFORE 12/2027 Choco Foods Ltd, Unit 4, Feeder Road, Bristol BS1 5TT, United Kingdom Store in a cool, dry place. 1 2 3 4 5 6 7 8 9
One run, one artwork version, one set of target markets. The markers are numbered in reading order; four raised a finding and five cleared.

blocking major no finding

The pack drawing is illustrative. Every message, severity, recommendation and pack attribution beside it is read from the rule registry at build time — the generator refuses to build if a marker names a rule the canon does not contain, so this figure cannot drift away from the engine it depicts.

The product

What your team actually looks at

The market matrix answers the only question that matters on a Monday morning: which markets can I print for today, and what exactly is stopping the rest.

Choco Biscuit 120 g — market matrix

run_01HX7Q2V · engine 1.0.0

Manifest man_01HX7Q2T · artwork v4.0 · sha256:9f2c4a1b…

MarketChannelCoverageBlockingReleasable
EURetailEnforced0Yes
GCCRetailEnforced0Yes
UKDistributorEnforced2Blocked
SADistributorEnforced3Blocked
IERetailNo rulesNot claimed

Open findings — 3 blocking, 2 major, 1 minor

packs: allergen · chocolate · claims · core_packaging_lifecycle · eu · food_label
blocking

The product contains allergens but no allergen emphasis or 'contains' statement was detected.

Emphasise allergenic ingredients within the ingredient list, or add a compliant 'Contains' statement.

allergen_emphasis_present_003 · allergen_pack

blocking

An allergen declared in the formula of record is not declared and emphasised in the artwork ingredient list.

Add the missing allergen to the ingredient list and emphasise it in line with the destination market's emphasis rule.

allergen_formula_to_artwork_001 · allergen_pack · human review

blocking

No minimum cocoa solids percentage declared for a chocolate product.

Declare 'cocoa solids: minimum X%' in the same field of vision as the product name.

choc_cocoa_solids_001 · chocolate_pack

major

The artwork declares an allergen that does not appear in the formula of record.

Confirm whether the formula record is out of date or the artwork over-declares. Reconcile the two before approval.

allergen_artwork_to_formula_002 · allergen_pack · human review

major

One or more ingredient suppliers have no valid allergen declaration on file.

Request an in-date allergen declaration from each ingredient supplier.

allergen_declaration_evidence_005 · allergen_pack

minor

A 'may contain' statement is present without a supporting cross-contact assessment in evidence.

Attach the supplier allergen declaration or cross-contact risk assessment that supports the precautionary statement.

allergen_may_contain_substantiated_004 · allergen_pack · human review

Partial release, immediately

UK and EU print today. Blocked markets stay blocked, and the exclusion is recorded on the approval and carried onto the certificate.

Every finding is actionable

A rule that produces a message without a recommendation fails the build. There is no finding here that leaves a designer guessing.

Uncovered says so

Not a pass, not a fail — where no rules exist, no verdict is offered. That column is the honesty of the whole product in one cell.

Workflow

A food export, end to end, across four parties

The work crosses organisational boundaries constantly — and that is exactly where email loses it. Each lane is a different company; each handoff is a gate that either passes or names what is missing.

Brand owner Supplier Consultant Printer Create product Select markets Upload artworkv4.0 Evidencerequest sent UploadDoC + migration 39 blockingrules available Approvescoped Release+ hash

The supplier never sees your manifest

A counterparty gets a scoped portal: the request made of them, what they uploaded, its status. Not the findings, not other suppliers, not your other products.

The consultant gets context, not a PDF

Findings arrive with the rule that produced them, the market it concerns, the zone on the artwork, and the recommendation — not an email saying "can you check this".

The printer gets something checkable

A certificate with the artwork hash on it. They verify their own file against it over a public endpoint, with no PackAuth account.

Jurisdictions

Markets resolve through a hierarchy, and coverage is stated honestly

A target market inherits every duty above it. Selecting Saudi Arabia pulls in GCC duties and the global baseline without anyone remembering to. Where PackAuth has no rules for a market, it says so — it never reports a pass for a market it did not check.

6

European Union

resolves EU → GLOBAL

1 packs 5 rules 4 blocking
  • blocking
    Mandatory particulars are not present in the official language of the destination member state.eu_member_state_language_001 · eu_pack
  • blocking
    No EU-established responsible operator address detected.eu_responsible_operator_002 · eu_pack
  • blocking
    EU allergen emphasis duty not satisfied for one or more declared allergens.eu_allergen_emphasis_003 · eu_pack
  • blocking
    No nutrition declaration detected for an EU destination.eu_nutrition_format_004 · eu_pack

Packs applied: eu_pack

Why the honest column matters. A compliance product that reports green for a market it never checked is worse than no product — it converts an unknown risk into a false assurance. Registered markets are classifiable as targets today and produce a clear not covered result, never a pass.

Stakeholders

Nobody here is simply "an approver"

Every stakeholder type holds specific authority scopes, and may only sign an approval those scopes satisfy. A regulatory consultant holding label authority cannot sign a market release. A printer holding print authority cannot approve a halal claim. The system does not rely on people knowing this.

PackAuth manifest · rules · authority Suppliersmaterial · ingredient Testing labsmigration · analysis Certifiershalal · organic Printercertificate + hash Distributormarket release Retailersupplier check Approvers9 roles hold authority Regulator / auditorasks the replay question
Green dashed — evidence flowing in. Solid blue — releases flowing out. Select any party for what they see and what they can do.

Inside the business

  • Brand ownerMarketing claim approval · Market release approval
  • ManufacturerFormula / spec approval
  • QA managerFormula / spec approval · Packaging material approval
  • Legal reviewerLegal claim approval
  • Export managerMarket release approval

Outside the business

  • PrinterPrint technical approval
  • Regulatory consultantRegulatory label approval · Legal claim approval · Translation approval
  • RetailerRetailer private-label approval
  • Certification bodyCertification mark approval

Evidence providers

  • Co-manufacturerevidence provider — holds no approval authority
  • Packaging supplierevidence provider — holds no approval authority
  • Ingredient supplierevidence provider — holds no approval authority
  • Artwork agencyevidence provider — holds no approval authority
  • Designerevidence provider — holds no approval authority
  • Importerevidence provider — holds no approval authority

23 stakeholder types · 11 authority scopes · 8 approval types.

Integration

It sits between the systems you already run

PackAuth does not replace your PLM, your ERP or your artwork tooling. It is the approval and evidence layer between them — the part none of them own.

PLM / specformula of record Artwork toolingcreative files Supplierscertificates, declarations ERP / QMSSKUs, sites, batches PackAuth — manifest · rules · evidence · approval · release API first · every capability an endpoint before it is a screen Printerrelease certificate + hash Distributormarket release evidence Retailersupplier approval check

API first

Every dashboard action maps to a documented endpoint. The screens, widgets, CLI and agent tools are clients of the same contract, never parallel implementations.

Webhooks

Signed with HMAC-SHA256 over timestamp.body. Your systems learn about a blocking finding or an issued release without polling.

Embeddable

Consultants embed the flows into their own client portals. A retailer can validate a supplier's packaging approval before a listing goes live.

The business case

The arithmetic is stage-of-catch, not licence cost

PackAuth does not claim to make compliance cheaper in the abstract. It moves the point of catch earlier — and the cost of a packaging error is dominated by how late it is found, not by how serious it is.

Caught at artwork

A file change

The designer moves a block, the consultant re-approves, the run proceeds on schedule.

Caught at print

Plates + substrate

Origination is re-cut and the material already run is scrapped. Schedule slips into the next slot.

Caught in transit

Freight + demurrage + relabel

Stock is held at the border. Relabelling is manual, in-market, at someone else's rate — and the retail window closes.

Caught on shelf

Withdrawal + remediation

Product comes back. The cost is the stock, the logistics, the customer relationship, and the regulatory record that follows the brand.

Where the time goes back

  • Evidence chasing — counterparties are asked for exactly what their type and risk require, and expiry is monitored rather than discovered
  • Re-checking after a change — a material change stales the affected approvals automatically and re-runs only the affected packs
  • Audit preparation — the answer to "who approved this, on what basis" is stored state, not an archaeology project
  • Market-by-market re-work — partial approval lets ready markets print while a blocked one is resolved

What it does not do

  • Replace your regulatory adviser — it routes work to them with the context attached
  • Guarantee compliance in a market it carries no rules for — it reports that market as not covered
  • Decide whether a product is halal, or whether a claim is true — it establishes whether the claim is evidenced and by whom
  • Approve anything on its own — every signature belongs to a person holding the authority

Evidence and replay

An approval is only as good as what it was taken against

Every approval locks an immutable evidence snapshot: the exact documents, their versions, hashed. Asked in eighteen months why a pack was cleared for a market, PackAuth answers with what was true then — not with whatever is on file today.

  • Artwork content hash, pinned
  • Formula and specification version
  • Rule pack and dictionary versions in force
  • Extraction provider and version
  • Approver, role, and the authority scope exercised

Audit rows and evidence snapshots are append-only at the database level. Continuous integration attempts an update and a delete on every run and fails the build if either succeeds — a trigger that exists but never fires reads as assurance while providing none.

Why was this package approved for Saudi Arabia on 28 June 2026?
The question the whole architecture exists to answer — with evidence, rules, versions and approver scope, not a recollection.
{
  "approval_id": "app_01HX7Q41",
  "scope": "approved_for_print",
  "jurisdictions": ["EU"],
  "excluded_jurisdictions": ["AE"],
  "artwork_file_hash": "sha256:9f2c4a1b…",
  "evidence_snapshot_id": "evsnap_01HX7Q30",
  "approver": {
    "role": "regulatory_consultant",
    "authority_scope": "regulatory_label_approval"
  },
  "expires_at": "2027-06-28T00:00:00Z"
}

Packs

Content and commerce in one unit

A pack carries executable rules and a price. That is what makes "Add GCC Pack" a product rather than a button. Buy the market you are entering; the checks appear on the next run.

9
  • Core Packaging Lifecycle PackManifest integrity, artwork versioning, evidence snapshot, approval, print release, change control and audit rules. Every manifest resolves this pack.
    enforced12 rules

Packs with no rules yet are listed as planned and never resolve onto a manifest. A pack that is applicable but unpurchased is reported — the run is never reported clean because a check was unpaid.

Start with the market that is blocking you

PackAuth is opening with food and confectionery exporters shipping into the UK, EU and Gulf — the wedge where the cost of a late catch is a container, not a comment. If your packaging approvals currently live in a spreadsheet and an email thread, we would like to talk.

[email protected] Review how it works