For Florida law firms
Statements frozen when executed: an accounting, or a beneficiary's distribution statement, kept as its exact bytes and hash
both lanes · Deterministic — no model call
Current availability
ShippedConfigured and enabled: anyone who can open the matter reads; a firm's staff (on its matters) or the direct service's trustee executes.
- Where it lives
- The firm's Money tab (/admin/matter/[id]?tab=money) and Receipts & releases · the trustee's Assets & bills · one statement's page (/admin/matter/[id]/statements/[id]/print, /matter/[id]/statements/[id]/print) · the closeout binder · /api/matter/statements · /api/matter/statements/[id]/bytes
- What unlocks it
- a firm's staff execute on the firm's matters; on the direct service, the trustee executes their own; whoever can open the matter reads them
Status is evaluated against this deployment's configuration by the capability-status service at build time; the catalogue's facts were last reviewed on the date shown.
Capabilities
- ShippedExecuting a statement freezes it: the database reads the ledger itself through the period's end (from its start, when one is given) and records the statement's exact bytes — its canonical text — with their SHA-256; the table refuses bytes that are not the statement, or a hash that is not theirs.
- ShippedTwo kinds: an accounting of the whole trust (receipts, disbursements, distributions, gains and losses, net change, principal and income, what was in kind, every entry), and one beneficiary's distribution statement (each distribution, cash and in kind, and the total).
- ShippedAn executed statement never changes: a correction is an amended statement that names the one it corrects and says why; the original stays on the record, marked as amended, and each statement is amended once.
- ShippedEvery screen reads a statement from its stored bytes, never from the live ledger; a statement whose bytes cannot be read whole is never shown in part.
- ShippedThe firm's list and each statement's page say when the ledger has changed since a statement was executed — the frozen figures stand as executed.
- ShippedThe exact bytes download from the statement's page, so anyone can compute the SHA-256 and compare — the check needs nothing from the platform.
- ShippedA receipt and release can acknowledge the beneficiary's distribution statement, bound by the statement's own hash; the signature carries the same hash, and a signed receipt keeps the statement it acknowledged — the database refuses any other.
- ShippedApproval writes no money field: a receipt, a signature and an approval carry the statement's hash, never an amount — the figures live only in the frozen statement.
Limits
- A statement is the ledger's figures at execution: it neither files nor approves a Florida trust accounting (§ 736.08135), and its format is the platform's, not a court form.
- The period ends today or earlier, in the platform's home time zone; an amended statement keeps its kind and beneficiary.
- On a firm's matter the firm executes; the trustee reads the executed statements.
- A distribution statement whose beneficiary record was later removed keeps the name it was executed with; whether the ledger has changed since cannot then be checked, and the page says so.
What EstateDraftFL refuses
| Reason code | HTTP | What it means |
|---|---|---|
| auth_required | 401 | Executing or downloading a statement needs a signed-in person who can open the matter. |
| invalid | 400 | A field could not be read — the kind, the beneficiary (a distribution statement names one; an accounting names none), the period (a real date, today or earlier, its start on or before its end) or the note (an amended statement says what it corrects) — nothing was executed. |
| forbidden | 403 | On a firm's matter the firm executes statements — the trustee reads them. |
| not found | 404 | The matter or the statement was not found, or the caller cannot open it. |
| already-amended | 409 | That statement has already been amended — amend the newer one. |
| matter_archived | 409 | The matter is archived — its records can be read, not added to. |
| integrity | 500 | A statement's stored bytes do not hash to its recorded SHA-256 — they are not served. |
| unavailable | 503 | The matter, the statement or the firm's staff could not be read — or the statement could not be executed — just now; nothing was executed. |
Evidence
- supabase/migrations/20261001030000_phase13_frozen_statements.sql
- src/lib/statements.ts
- src/lib/statement-request.ts
- src/lib/statements-server.ts
- src/app/api/matter/statements/route.ts
- src/app/api/matter/statements/[id]/bytes/route.ts
- src/components/StatementsPanel.tsx
- src/components/FrozenStatement.tsx
- src/components/ReceiptsReleases.tsx
- src/app/matter/[id]/closeout/print/page.tsx
- docs/security/MASTER-PLAN-PHASE13-PART3-2026-10-01.md
Last reviewed 2026-10-01