Payment Collection & Security
The accounts guests may use to pay. Each digital account can carry its own payment address and QR code. The first account is the primary payment destination: guests see it, with its username button and phone check.
| Control | What it means | Status |
|---|---|---|
| Privileged payment role | Only authorized users can modify payment destinations. | Authentication required |
| Fresh sign-in | Payment settings change only within 10 minutes of a GUIDON sign-in, checked by the database. Deleting guest data and permanently deleting an event need the same. | Active |
| Authenticator-app code (MFA) | A second factor for these changes, on top of the fresh sign-in. | Planned |
| Immutable audit trail | Every payment settings change is recorded with the old and new values, who, and when. Entries can't be changed or deleted from GUIDON, and each Ball's history is hash-linked, so a change made to an earlier entry outside GUIDON shows up. | Active |
| Public portal is read-only | Guest-facing code can display payment information but cannot modify it. | Architecture rule |