The blog  ·  2026-07-31

The Paperwork Is a Projection

Written for all four ED segments at once — the founding document, written to be forwarded — the reader deciding whether this layer is a thesis or a feature.

The founding document of transactions.dev


There is an empty box on the American bill of lading.

The form is the VICS Bill of Lading, stewarded by GS1 US since 2012, the standard bill of lading of American retail freight. It ships in two layouts; the landscape one exists so the shipment's data can travel as a 2D barcode on the page. The form reserves a rectangle for that ride, printed and labeled: SUPPLEMENTAL BAR CODE AREA.

The guideline never defined what goes in the box. It reserved the space and stopped. Carriers filled it ad hoc, and no standard ever told a counterparty how to read the result. So in the only sense that matters — a meaning two parties share — the box stayed empty. It has sat on the form, waiting, for twenty years. Longer than most of the startups now promising to fix freight have existed.

The box is not waiting for a barcode format. It is waiting for a decision about what a document is.

What a purchase order actually is

Ask where a purchase order lives today and you get three answers, all of them copies. It is a PDF in someone's inbox. It is an X12 850 in a VAN mailbox, if both parties paid for one. It is a row in an ERP that the other side will never see. None of these is the purchase order; each is a rendering of it, and every disagreement between renderings becomes a phone call. The reconciliation meeting — two companies comparing their copies of the same fact — exists for one reason: the copies were treated as the thing.

The purchase order was never the paper. A PO, an ASN, an invoice, a bill of lading: each is one canonical transaction, a fact recorded once, append-only, between the parties. Everything you can hold, click, or scan is a projection of that record: derived from it, disposable, and checkable against it. The PDF was always a projection. We just never built the other two.

There are three projections worth building, because there are three ways a document meets the world:

The page you read. The rendering for humans — the page an auditor initials, the layout a dock clerk knows by muscle memory — unchanged, except it now admits what it is.

The URL you resolve. Every transaction has an address, and resolving it is not a lookup that vanishes into a log. It is itself an event with identity, witnessed on the same record the document lives on. Who asked for this bill of lading, and when, becomes part of its history. This projection rides GS1 Digital Link where the document carries GS1 identity — GS1's own grammar for putting the identifier in the code and the data on the web. The identifier half of that design is standardized. The document half is the seat nobody took.

The barcode on the goods. The whole transaction — the canonical bytes, compressed and signed by the issuer's key — inside a QR code on the page or the pallet, verifiable offline by anyone holding the issuer's public keys, with no network and no account. Not a link to the document. The document itself, when it fits the square.

The standard already reserved the seat

The standard anticipated this, then waited.

GS1's Core Business Vocabulary is the layer beneath EPCIS 2.0, the standard supply chains use to record what physically happened. It gives business-transaction types their own names: po, desadv (the ASN), recadv, inv, bol, and the rest (CBV 2.0 §7.3). And every EPCIS event type reserves a bizTransactionList: a field whose purpose is to let a physical event name the paperwork it answers to. The join between documents and physics is not our invention. It is a standing field in a ratified standard that nothing on the paper side ever defined how to fill — the bill of lading's empty box, restated as data.

So the design is not "put documents in barcodes." The design is: one canonical record, three conformant projections, and one digest joining all of them. Every projection proves the same sha256 digest of the canonical bytes. That digest is the record's address in the transaction ledger and the same value that rides the event's bizTransactionList. Scan the barcode, resolve the URL, or open the PDF: all three roads verify against the same record, and every physical event that ever answered to the document is joined to it by that same digest.

This is not a thought experiment

A complete signed record inside a barcode is not speculative. Hundreds of millions of people were issued one. The SMART Health Card put a complete signed vaccination record inside a QR code: minified, compressed, signed, verified offline by a phone that had fetched the issuer's public keys in advance. Nobody called it a database export. It was the record, checkable with no network, printing at 40 millimeters square. If a signed vaccination record fits at 40 millimeters, a purchase order can.

And when a document is too large to fit, the answer is already running. Saudi Arabia's tax authority mandates a QR on its e-invoices carrying the seller, the tax figures and totals, a signature, and the hash of the full invoice. India's GST system returns a signed QR of the invoice's core claims, offline-verifiable. Signed core facts in a square already run at national scale, twice over — and in Saudi Arabia's case, the square also proves the whole document.

So the honest design has three size classes, not one promise. The full document when it fits; the signed core facts plus the digest when it doesn't; a pointer plus the digest when even that won't do. The class is chosen by measured size and stated in the answer, and every class proves the digest, so offline integrity holds even when offline content cannot. We will not promise that every document fits in one square. We will promise that every square tells you what it is and proves what it points at.

The dock with no signal

Picture the delivery this actually changes. A truck backs into a receiving bay: a co-packer's dock, a franchisee's back door, a rural DC with no integration budget and, some days, no connectivity at all. The ASN rides as a barcode on the lead pallet's label. The receiving scan reads it, and the receiving event gets its {desadv, po} references stamped into bizTransactionList from the paper on the goods. Zero EDI connections, zero onboarding, zero favors. Later, shipped-versus-seen is adjudicated line by line from the record: what the ASN declared against what the dock observed. Paper versus physics — and for the first time, the paper participated.

Run it the other direction: a purchase order handed to a supplier who has no EDI system, no VAN mailbox, and no intention of buying either is machine-readable from a photograph. EDI included, never EDI-only. X12, EDIFACT, UBL — the grammar Peppol documents ride on — and plain JSON from an ordering API all land in the same canonical record. The counterparty with nothing installed is a first-class citizen of the transaction, because citizenship rides on the goods, not on the connection.

Paper already lost this fight

The informed reader is already composing the rebuttal: the industry litigated paper, and paper lost. The trucking standards body replaced scan-the-paper with an electronic bill-of-lading API in 2022, no barcode in it. Ocean freight's electronic bill of lading has no barcode track at all. Even the health cards retreated: when records outgrew the square, the QR went back to being a pointer.

Right on every fact. Wrong on what they prove. The API-only rails didn't derive the barcode projection; they deleted it. So they work precisely where both parties bought connectivity, which is not most of any network's long tail. And the barcode's job was never the job those rails do. It is not transfer of title. It is join-at-the-dock for the party with nothing installed — exactly the seat the bizTransactionList field has been holding. We did not choose the barcode over the API. The canonical record is API-native; the barcode is one of its three projections, and the eBOL rail is a connector into the same record, not a refutation of it.

The second thrust — a printed barcode is a stale copy — has the same answer. Of course the print can go stale; every projection can. The square proves what was signed and when, by digest against the ledger. A superseding document is recorded; the old one is never deleted, only superseded. A projection can go stale. A record cannot.

The box, filled

One date remains, and it is not ours. GS1's Sunrise 2027 program expects retail point-of-sale to scan and process 2D barcodes by the end of December 2027 — GS1's expectation, not ours, set for reasons that have nothing to do with us. That clock runs whether or not the paperwork learns to ride it.

This is transactions.dev: the business-transaction layer of the event spine — where the PO, the ASN, the invoice, and the bill of lading live as canonical, append-only records; where each one projects to a page, a URL, and a barcode; and where one digest joins every projection to every physical event that answered it.

The industry drew the box twenty years ago. The standard reserved the field. The paperwork was always a projection. Now it projects all the way to the pallet.


1585 words. The access flow is at /get-access/; the family's event door is epcis.dev.