The first pilot for SAP: ApeiroRA's audit-logging signal — their Go SDK, their collector, their wire format, unchanged — into a NEO audit sink that keeps every company's records in that company's own book and answers each on the wire with a receipt. Once a minute each book seals into one 32-byte commitment that leaves for a door; nothing else leaves. 10,008 companies, 58.6 million records, none failed — and the sinks were stopped mid-work and came back without a record lost.
What this is. A provider here is one company of the consortium — a cloud, infrastructure or service provider in the 8ra sense — emitting its own audit records (who did what, to which resource, with what outcome) as ApeiroRA's audit-logging signal describes them. No company trades with another in this demonstration; no message passes between them. 150 companies is the consortium's size today; 10,008 is the network it describes. The marketplaces demonstration further down is the other case — two companies, one deal, two books.
What was built. ApeiroRA's audit-logging signal is OpenTelemetry: their Go SDK emits audit records, their collector forwards them, on their wire format. We put a NEO audit sink behind that wire. Every record lands verbatim in its company's own book and is answered with a receipt on the wire (record id, integrity hash, sink time); once a minute each book seals into one 32-byte commitment that leaves for a door. What the door sees is 10,008 objects a minute — whatever the record rate. Nothing else leaves a company: no record, no content, no counterparty.
How it was reached. First the small test that is the consortium's shape today: 150 companies × 0.5 audit records/s each × 3 minutes → 13,535 records, 0 failed, 74 requests/s, p50 1.7 ms; 2,249 seals admitted at the door, every one of them cross-checked against the door's journal and its kit verified (ALL OK, 2,249 periods — fleet150-3min.json · cross-check). Then the ladder at 10,008 companies with one disk sync per record: 3,577 / 4,235 / 4,719 requests/s at 0.5 / 1 / 1.5 records per company per second, 0 failed at every step (run 9). Then the sink's group commit — one disk sync per window of records, every request still answered only after the sync that covers it — and the two-hour run above at 8,140 requests/s (SUMMARY.json · completeness.json · crosscheck-summary.json).
And it survives its sink. Right after the run the twelve sink processes were stopped in the middle of their work — 26,793,445 records answered 200 but not yet in their books — and restarted. The sink's intake log replayed 26,628,445 records into the books, every company sealed and every seal was admitted — 10,008 → 10,008, 0 unadmitted — within 31 minutes of the stop, no operator in the loop (state-after-drain.json). A receipt a company holds is valid before, during and after. Three minutes at the same rate on the restarted sinks: 6,648 requests/s, 0 failed, 36,853 seals admitted (after-restart-smoke-SUMMARY.json).
Bounded on purpose: the twelve doors on this box are test doors with their own journals — the leg from those doors to the production ledger was not part of this run. Verified here means: the record is in its company's book, under a commitment the door admitted, with a kit that recomputes record → snapshot → commitment; it does not mean the record's business content is true, and a record never sent cannot be missed by any bookkeeper. Their SDK and collector were used as published; one box (16 vCPU, 62 GB) carried all of it.