From the offline HRIS to a banking core
RheoServ Waumpaum came from the offline HRIS experiment. That experiment put CRDT SQLite in one HTML file. The experiment was a temporary change from the work on plastron. The HRIS showed that the difficult parts operate correctly:
- an in-memory cr-sqlite engine, inlined as WASM
- portable dumps, encrypted with AES-256-GCM
- a merge for many operators, in the browser
- a strict
connect-src 'none'policy, thus no data can go out of the page
RheoServ Waumpaum uses all these parts again. It applies them to a much larger domain: credit-union core banking.
Familiar, but not a copy
Enterprise core banking is the reference. It is a person-centered core. You search for a person. Then you go to the accounts of that person, and then to the real-time transactions. RheoServ Waumpaum uses the same structure:
-
the table names and the column names (
Pers,Acct,Rtxn,AcctHold,AcctRole) - the screen titles (Person Search, Account Inquiry, Real-Time Transaction Post)
-
the labels with spaced abbreviations that an experienced operator expects (
Acct Nbr,Rtxn Typ Cd,Cur Bal,Avail Bal)
RheoServ Waumpaum is deliberately not a copy of a product. It does not integrate with a product. It is a new, offline, open design of the same model, and it is familiar to an operator.
What a waumpaum is
A waumpaum is not a parallel ledger, and it is not a table. It is a slice of the
Rtxn table: one or more transactions that have flags. The flags are
WaumpaumInd = 1, WaumpaumBeltId, and WaumpaumPeerInstCd.
The flags set the transactions apart for exchange with a different institution.
The name comes from wampum, with respect, as a design metaphor. Wampum belts recorded agreements between nations. In this system, a waumpaum is a signed record that attests a ledger state. Thus two credit unions can settle, and they do not show their encrypted ledgers to each other. (The name is a metaphor, not a claim of Indigenous ownership.)
Three audiences
The remaining sections of this post give instructions for three audiences:
- The teller operates in one credit union.
- The credit union merges one day of offline changes.
- The payment provider settles between institutions.
Each story has a short video from the live app. The videos come from the same Playwright tests that the repo includes. The written instructions are in USER-MANUAL.md.
- Open the built app.
- Select Demo data.
- Set a passphrase of your choice.
- Select an operator.
Part 1 — The teller
Start a session US-1
Load the data for the day with a passphrase. Then select your operator identity. (Your role sets your screens.)
- Open the file. The app shows a locked gate screen first.
- Keep Demo data selected.
- Type a passphrase.
- Click Start session.
- Select an operator. The Dashboard shows the members, the balances, the holds, and the unsettled waumpaums.
Person Search → Account Inquiry US-2
Start with the person. Find a member, go to the accounts of that member, and open one account.
- In Person Search, type a name (for example, Broadwater).
- Click the member. The app shows the accounts of the member through
AcctRole. - Open one account.
The Account Inquiry header shows Cur Bal and Avail Bal. The tabs are History, Holds, and Roles.
Real-Time Transaction Post US-3
Post a deposit, a withdrawal, a transfer, or a fee. The ledger changes in real time.
- Select an
Acct Nbr. - Set Rtxn Typ Cd (for example,
WD). - Set Post Amt.
- Post the transaction.
If a debit is more than the available balance, the app refuses the debit with
Insufficient Funds. If not, the Rtxn posts and the balance decreases. Each post
writes a change_event that identifies the operator.
Hold Inquiry — place and release a card hold US-4
A card authorization decreases the available balance. It does not change the ledger.
-
Click Place Hold. The app creates an
AcctHoldand an AUTHRtxn. Avail Bal decreases, and Cur Bal does not change. -
Click Release Hold. The available balance increases again. The hold changes to
RLSD, and the AUTH changes toRVSD.
If a hold is more than the available balance, the app refuses the hold with
Hold Amt Exceeds Avail Bal.
Lock the session US-6
Erase the decrypted data from memory when you go away from the computer.
- Export your changes first. By design, you lose the changes that you did not export.
- Click Lock session. The app goes back to the gate screen. It erases the database, the key, the passphrase, and the identity.
Part 2 — The credit union merges one day of changes
Several tellers start with the same morning truth. Each teller makes changes offline. cr-sqlite is a CRDT, thus the changes of all tellers converge with no server. No last-writer-wins rule overwrites the changes of a teller. The coordinator merges the encrypted changes of all tellers in the browser.
Export changes and merge (no Node) US-5
The coordinator makes the offline edits of all operators converge in the same HTML file.
- Operator: click Export my changes. The app makes an encrypted
.waumpaumchangesfile. - Coordinator: open Data & Security → Merge Operator Changes.
- Coordinator: select the changes files of the operators.
- Coordinator: click Export merged truth for tomorrow.
cr-sqlite makes the divergent edits converge for each column.
The merge keeps the attribution US-12
See the operator that made each change. The audit data goes with each changeset.
- Open Audit. It shows the change log (operator, entity, action) and the session events.
change_event and session_log are CRRs. They merge into the truth together with
all the other data.
Part 3 — Payment providers and the Waumpaum Exchange
The CRDT merge makes edits converge in one credit union. Between credit unions, a separate
Waumpaum Exchange nets the obligations. The Exchange is on a network. A waumpaum is a signed
slice of Rtxn. It is the record that goes from one institution to the other. Figure 2 shows the
three steps of the settlement.
Issue a waumpaum US-7
Flag a transaction for exchange. Then export its signed attestation.
- Open the Waumpaum Desk.
- Select a recent
Rtxn. - Click Issue a Waumpaum.
- Select the counterparty (
WaumpaumPeerInstCd).
The app sets the flag WaumpaumInd = 1 on the row. (The row goes into
v_WaumpaumRtxn.) The app exports a signed .waumpaumproof. This file is the atomic
negotiable record for the Exchange.
The Exchange makes a belt CLI
Netting with a single writer collects the proofs into a settlement belt. (The netting runs outside the offline core.)
cd exchange node net-belt.mjs --proofs ./proofs --belt-id 2026-07-07T18:00Z --out ../fixtures/woven.clearbelt
The script adds the settlement amounts of the proofs for each (AcctNbr, counterparty) pair. Then
it writes a .clearbelt that the credit union can read.
Read the Belt US-10
Import the settlement belt of the Exchange back into the ledger.
- Open Read the Belt.
- Load the
.clearbelt. - Preview each settlement string.
-
Post the settlement strings. Each string becomes a
Rtxn(RtxnTypCd='CLR') that has the belt id. The post updates the balances.
The app does not post a string for an unknown account. It reports the unknown accounts, and it never invents an account.
Post to the longhouse (deferred). This feature sends the signal "a new belt is ready" through a public image feed. It uses ChaosEdgeSteg steganography. The feature has a design, but the app does not include it. The feature makes the CSP less strict. Thus it belongs in a separate build variant, and never in the teller core.
The other roles
Loan officer — Loan Payment Post US-8
Examine the loan book and apply a payment.
- Open Loan Pipeline.
- Open Loan Inquiry. The screens show the balances, the next payment due, the rate, and the payment history.
-
Use Loan Payment Post to apply a payment. A
DPRtxnmoves the balance nearer to zero and recordsAcctPmtHist.
Planner — Reports → encrypted CSV US-9
Run the predefined reports. The app exports encrypted files only.
- Open Member 360. It is the book of business (the deposits and the loans for each member).
- Open Reports.
- Run a report.
-
Click Export CSV. The app makes a
.csv.encfile only. It never makes a plain CSV file.
References
- rheophile10/rheoServ-waumpaum — the source code and the build
- USER-MANUAL.md — the full written instructions
- the built app — one self-contained file
- Offline HRIS — the project that RheoServ Waumpaum came from
- cr-sqlite — convergent replicated SQLite
- Wampum (the source of the metaphor, with respect): Onondaga Nation, Oneida
- CSE ITSP.40.111 — approved algorithms (AES-GCM, PBKDF2)