Tripbooks design system / lab 21 / the accounting walk

Lab 21 / the module where the data is different

The accounting walk.

The accounting module is the hardest test the design system will ever face: an append-only journal, running balances, two-sided entries, three-way matching, reconciliations that must tie to the cent, dual control, period locks, gapless statutory numbering, multi-currency on every line, and an AI agent posting within a delegation. Lab 18 walked it as part of the whole platform; this lab walks it alone, route by route and data-nature by data-nature, against the platform's own module document, to answer one question: is anything still missing?

The honest answer: no new components are needed. The eight primitives the audit added for this module carry every surface. The walk found two places where a rule needed one more sentence to survive an accountant's scrutiny, both now written in, and two adoption notes that cost nothing today.

36Surfaces walked
9/10Archetypes exercised
0New components
1New law
1Law sharpened
2Adoption notes

01 / coverage

Thirty-six surfaces, every one lands on an archetype.

The whole module, from its own consolidated document, mapped surface by surface. Nine of the ten archetypes are exercised; only the Tool archetype goes unused, which is correct, because accounting has no free-form surface and should not.

SurfaceArchetypeWhat carries it
Overview and TAI
OverviewBoardOne range governs everything, every block a cohort, every figure opens its report. Movement chips carry the deltas; sparklines wait on the parked charts decision.
TAI queueWorklistOrdered by consequence, Accept and Reject decide on the row (two words, facts on the row), evidence as chips, confidence in the tooltip. L15 exactly.
Sales
InvoicesRegisterKPI band as filters, tabs by state, one table, one line per cell, functional figure behind Columns.
Invoice recordWorkspaceSticky header, verbs shown only when they apply (L5 says why when not), facts band, tabs, journal tab on register grammar.
Payments receivedRegisterApplied-to links, unapplied as a fact. TAI's applications sit in the same rows as human ones.
Credit notesRegisterThe approvals table stacks above the register, full width; dual control renders as the hatched permission mark.
Customer balancesRegisterCredit hold and reminder stage are badges; Apply credit is a dialog with its consequence computed live (O2).
Customer statementRegister + statementThe statement component: label rows, mono figures right, heavy rule above totals, grouped by trip container. One currency at a time.
RemindersRegisterThe schedule is an anchored rule, never a stored date: N2 was written for exactly this page.
Bad debtsRegister + statementThe aged matrix is the statement component's named use; write-off approval is the two-signature permission mark.
Purchases
BillsRegisterDifference beyond tolerance is the hue exception family (money moving against you), named in L4. Tolerance as a header badge. Credit lines block stacks below, full width.
Bill recordWorkspaceThe Match tab is one table: Sold, Confirmed, Billed, Difference, Tolerance. Drift component grammar, reason under it in words.
Batch paymentsRegisterState badge carries the trail in a tooltip; Early is the destructive-tone badge with its reason.
New batchComposerFields, previewed lines, one save button carrying the second-approval threshold: the generalised gate, verbatim.
Batch recordWorkspacePayments grouped by supplier with subtotals: the group row component. Documents tab on DocRow grammar with share links.
SuppliersRegisterPayable-today gate as a badge, blocked reason in tooltip, onboarding a dialog on the register.
Supplier recordProfileThe customer profile grammar in full, as ruled 19 Aug: identity band, badge layer, KV grid, DocRow bank accounts with retired rows in the dormant fill, section-edit sheets.
Supplier statementsRegisterOurs, Theirs, Gap, Explained as the KPI band; every difference explained in words on its row. One table, never two panes.
RebatesRegisterPlain register; accrual state as a badge.
Banking
Bank accountsRegisterOne row per account; signed off, ties, off-by as the badge system.
Bank account recordWorkspaceStatement lines as a register tab; Match is a dialog showing the difference before recording (O2); Summary is the statement component; Sign off is the gate: enabled only when it ties, refusal names why.
Cash flowRegister + statementEight weeks of arithmetic, lowest close carries the severity edge. Nothing estimated, so nothing needs a chart to be true.
CurrencyRegisterEvery line is the currency pair component: transaction primary, functional secondary, rate and source in the tooltip.
Digital currencyRegisterPolicy as facts, custody balance, conversions register; Convert is a dialog; masked wallet addresses use the masked number component.
Accounting
JournalRegisterNarrative behind Columns and in a tooltip (L1); Posted by in words: Tripbooks, TAI, or a name (L15); endless set paginates (L16).
Journal postingWorkspaceTwo-sided lines with the currency pair on every line, reversal links both ways, idempotency key in a Technical row. See finding F2 for the empty side.
Chart of accountsRegisterTabs by type, balance with its side as a word, in-use as a badge.
Account ledgerRegisterThe running balance column. The one place the register grammar needed a new sentence: finding F1.
Journal issuesWorklistRefused postings ordered by consequence, the reason on the row, a rule bug made loud.
TaxRegister + statementThe return's boxes are a statement; the documents tab is a register; the rules tab is a table with citations.
Tax documentShareThe viewer component renders the document; the UBL payload sits behind it; the share link is the tokened share archetype.
ReportsAnalysis + statementProfit and loss, balance sheet, both cash flows, trial balance, aged matrices: all the statement component, one report at a time, full width. Comparison columns are mono columns plus the achromatic movement chip.
Period closeWorkspaceThe close is the generalised gate at its largest: segments count the checklist, outstanding items named in words, Sign off records who and when, refusal reasons on the pack. Locked periods wear the LOCK flag.
Assurance and settings
Audit trailRegisterAppend-only log as a register; the SoD matrix is the three-state permission mark; reason-gated views use the refusal component and log the reason.
Controls settingsSettingsWhat it is, what it is set to, who may change it: the settings archetype's third column is exactly what SOC evidence wants.
PlaceholdersheldCommissions and Contracts have no plan phase behind them; the empty state component names what they will become.

02 / the stress list

Where accounting data behaves differently, and what carries it.

Routes are the easy half. The module document names behaviours no other module has. Each one, against the system:

Data natureCarried byHow
Append-only, reverse never editfill rule + refsA reversed posting keeps its solid fill (it happened; it is history, not a draft) and links its reversal both ways as references. Nothing is struck through, nothing is deleted, and the pair reads as two facts, which is what double-entry says they are.
Two-sided entriesL13 + mono columnsDebit and credit are words, allowed only inside journal surfaces. Lines render as two mono amount columns; the unused side is structurally blank. Sharpened in F2.
Running balancenew law L17A balance column is only true in date order over the whole set. The register grammar allowed sorting and filtering that would make it lie. Closed in F1.
Must tie to the centgate + badgeTies is a verdict, not a decoration: the reconciliation's Sign off is the generalised gate, enabled only when book less outstanding plus unreconciled equals bank, refusal stating the difference. Unreconciled is ours (our move), signed off is settled solid.
Multi-currency on every linecurrency pairTransaction amount primary, functional secondary, rate and source stamped in the tooltip, never at equal weight. The component was added in Lab 18 for exactly this line shape.
Match variance and tolerancehue exceptionDifference beyond tolerance is one of the four members of the money-moving-against-you family (L4). Within tolerance it is information, achromatic. Sold-versus-confirmed stays information, never an exception.
Dual control and SoDpermission markSolid may, hatched may with a second signature, empty may not. Write-offs (two names), credit notes above threshold, batch approval, bank-detail changes: all the same three-state mark. The SoD matrix is its register.
Masked details, reason-gatedmasked numberLast four kept, reveal logged with a reason: the component's own definition is the module's bank-detail control, word for word.
Period states and locksbadges + LOCK flagOpen is hatched (in flight), soft and hard close are solid with the state as the word, locked wears the LOCK flag. Posting into a closed period gets the refusal component: names the period, names who can reopen, offers the ask.
Gapless statutory numberingmono refsPREFIX-YEAR-N, entity on the record: every reference is mono, and the register never shows a number a document does not have (a credit note awaiting approval has no number, so the cell is a dash: no answer exists yet, L14).
Negative moneyL13Signed mono minus, never parentheses on screen, never red merely for being negative. The law came out of the Lab 18 audit of this module and holds everywhere in it.
An AI that postsL15TAI is an actor in the same registers as people: Posted by TAI, confidence in the tooltip, evidence as chips, acts within delegation, drafts above it. The queue is a worklist, not a special surface.
Anomaly flagsseverity + notificationsSentences with evidence, never acts: the notification centre's Happened list, severity as the hueless edge, every row naming its record (N3).
Documents that are lawviewer + shareImmutable once issued; the viewer renders, the UBL payload sits behind it, corrections are a credit note plus a new invoice, which the invoice family block already draws.

The three renders that prove the edge cases

The account ledger under L17 · 1100 Accounts receivable · date order, whole set
DateEntryNarrativeDebitCreditBalance
14 Jul 2026JE-2026-1198Booking confirmed, Meridian Capital Group148,220.00402,881.10
15 Jul 2026JE-2026-1201Payment received, BKG-RYH39M4S96,400.00306,481.10
15 Jul 2026JE-2026-1204Credit note CN-2026-22 applied4,150.00302,331.10
17 Jul 2026JE-2026-1211Service charge raised, SRV-2026-841,240.00303,571.10

Filter this ledger by source, and the Balance column leaves with the filter. It returns when the filter clears. The figures that remain are true; a running balance over a filtered set would not be.

The journal posting under F2 · two-sided lines, blank is structural
AccountSideTransactionFunctionalDebitCredit
1100 Accounts receivableDebitAED 36,900.00$10,047.6510,047.65
2110 Deferred revenueCreditAED 35,143.00$9,569.239,569.23
2200 VAT payableCreditAED 1,757.00$478.42478.42
10,047.6510,047.65

The empty cells in the Debit and Credit columns are blank, not dashed and not zero: the side does not exist for that line, which is a different fact from "no answer yet". The totals row proves balance; an entry that cannot show this row equal was refused before it reached a screen.

The reconciliation summary as the statement component · sign off is the gate
Book balance, 31 Jul 2026184,220.40
Less outstanding payments-12,845.00
Plus unreconciled receipts3,120.00
Bank balance, statement174,495.40

Label rows, mono figures right, indent for containment, signed minus, heavy rule above the total: the statement grammar carries the reconciliation artifact unchanged, and Sign off stays dead until the arithmetic holds, with the difference named beside it.

03 / findings

Two sentences were missing. They are written now.

F1 · new law L17A running balance never lies

The account ledger shows a running balance, and the register grammar proudly allows sorting and filtering on every register. Those two facts collide: re-sort a ledger by amount, or filter it by source, and the balance column silently becomes fiction. No component was missing; a law was.

L17, added to the platform laws: a running balance exists only in date order over the whole set. Any sort or filter removes the column rather than letting it lie, and it returns when the view does. The ledger's date sort is fixed; everything else about the register grammar stays.

F2 · L14 sharpenedBlank, dash and zero are three different facts

L14 ruled that a dash is not a zero: zero is measured, a dash means no answer exists. The journal's two-sided lines expose a third state the law never named: the credit cell of a debit line is not "no answer", it is a side that structurally does not exist. Writing a dash there would put four hundred false "no answers" on every journal page.

L14 now carries the third state: a structurally empty cell, like the unused side of a journal line, is blank. Zero is measured as nothing, a dash is no answer yet, blank is not applicable. Three glyphs, three facts, and they sort as three facts.

F3 · adoption noteThe overview's deltas go achromatic

The shipped accounting overview colours its deltas and flips the colour where lower is better, a per-metric judgement someone must maintain. The system's movement chip is achromatic by law: glyph for direction, figure for magnitude, no hue, because up is not always good, which is a lesson this module teaches better than any other (DPO up can be discipline, revenue up can be a tax error).

No work now. Adoption is ruled "Not yet"; when it comes, the flip logic is deleted rather than migrated. Recorded in the adoption map.

F4 · adoption noteSparklines ride the parked charts decision

The overview leans on sparklines over twelve like periods. Charts are parked on your word, and the intelligence layer's trend stroke sketch from Lab 20 is the same instrument by another door: a hairline history under a figure, endpoint emphasized, no axes.

No work now. When the chart library discussion happens, the overview's sparklines and the trend stroke should be settled as one decision, not two.

04 / the module's own next phase

R5 lands on the system without a single new shape.

The module document already queues R5. Walked against the archetypes, every planned item lands on an existing shape, which is the strongest forward evidence the validation can offer:

R5 itemLands onNotes
Reports as a report pickerAnalysis + statementOne report at a time, full width, period and comparison as mono columns, change as the achromatic movement chip, exportable because the statement is what prints.
Period close on workspace grammarWorkspace + gateHeader with the period and Sign off, facts band, tabs Checklist, Evidence, Controls. The gate counts the checklist; refusals are named in words.
TAI as a review registerWorklistKind, target, amount, confidence, gate; Accept and Reject on the row; detail in a dialog. The row-decide principle exactly.
Cash flow, Currency, Digital currencyRegisterKPI strip, one table, pager; the chart slot waits on the parked decision.
Density passes, Tax and AuditRegisterL1 and L16 are the instruments: one line per cell, tooltips for the second fact, pagination everywhere money renders.
Consolidation C1, laterStatementA read across entities with per-entity columns is the statement component with more mono columns; CJ-YEAR-N postings are journal grammar. Parked on both sides, and the shapes already agree.

05 / verdict

The system holds the books.

Thirty-six surfaces, fourteen data natures, and the module's own forward plan, all walked against the system. No new component, archetype or concept is needed: the statement, the currency pair, the generalised gate, the group row, the permission mark, the masked number, the viewer and the fill rule, most of them added by the Lab 18 audit for exactly this module, carry everything the accounting document describes, including the parts that are not built yet.

What the walk earned: one law (L17, the running balance), one sharpened law (L14, blank against dash against zero), and two adoption notes that cost nothing until adoption is ruled. The law count moves to forty-eight, and both changes are already written into the specification and the handbook.

What this does not claim

The walk validates design coverage, not the accounting itself: the tax profiles, allowance rates and thresholds still carry their consultant-confirmation flags in the module document, and adoption of the system by the shipped module remains ruled "Not yet". When adoption comes, this lab is the checklist of what changes: the deltas go achromatic, the ledgers gain L17's behaviour, and everything else is restyling, not rethinking.