Prime Comex Rights Fabric

Platform

One record of what you hold, one record of what you spend, reconciled continuously.

Most estates keep entitlements in procurement documents and consumption in a dozen consoles. The fabric puts both on the same ledger and keeps them agreeing with each other.

Core services

Each service has a documented interface and can be adopted independently.

01

Pool ledger

The system of record for grants: what was purchased, from whom, under which terms, and how much of it is currently drawn. Every movement is append-only, so you can replay any point in time.

02

Draw broker

Hands out and reclaims seats. Requests are checked against the active rulebook before a seat leaves the pool; unused draws lapse on a configurable idle window rather than lingering indefinitely.

03

Attestation collectors

Small agents for workstations, servers, and CI runners. They report launches and durations, sign what they send, and degrade to local buffering when the fabric is unreachable.

04

Rulebook engine

Agreement terms as declarative, version-controlled documents. Changes go through review, take effect on a stated date, and leave the prior version queryable for historical questions.

05

Forecast views

Consumption trends, expiry calendars, and under-use flags, sliced by team, cost centre, or vendor. Views are read-only projections of the ledger, safe to hand to finance.

06

Bridge connectors

Directory sync for identity, inventory import for hosts, ticket creation for exceptions, and export jobs for the finance system. All optional, all reversible.

How a request flows

1. Ask
A person or a pipeline asks the broker for a right to run a titled piece of software, naming the host and the account.
2. Check
The broker evaluates the active rulebook: is there capacity in the pool, is this identity in scope, does the territory or concurrency term allow it?
3. Draw
On approval the ledger records a draw with an expiry. On refusal the requester gets the specific term that blocked it, not a generic error.
4. Observe
Collectors attest to the actual run. Observations attach to the draw, which is what makes later reporting defensible.
5. Return
Idle draws lapse and capacity returns to the pool. Forecast views pick up the change on the next projection pass.

Operating notes

Footprint

A single instance handles a mid-sized estate on modest hardware. Larger deployments shard the ledger by cost centre and run brokers close to the fleets they serve.

Data held

Grants, draws, and observations. No document contents, no keystrokes, no screen capture. Collector scope is declared in configuration and visible to the people being measured.

Exit path

Everything exports as plain, documented records. Moving from the operated tier to a self-hosted open edition is a restore, not a migration project.

Next step

Reference deployments and rulebook bundles live with the open edition. For a walkthrough against your own vendor list, get in touch via the contact page.