Approve packaging before it is printed, shipped, sold, or changed.
A missing Arabic label block stops your container at the port. A missing allergen is a recall. Both are decided at artwork stage — in an email thread, against a spreadsheet nobody version-controls.
PackAuth catches them before the plates are cut. Then it holds the approval, the evidence and the release certificate that prove why the pack was cleared.
API, agent and widget first · usage-based · every decision replayable
The same error, caught at four stages. PackAuth operates at the leftmost bar — the only one where a fix is a file change.
24lifecycle states, concept to archive
12policy rails gating every consequential action
128deterministic rules — no model guesses a verdict
11approval types, each scoped to real authority
The problem
Packaging approval is the last unowned process in the supply chain
Formulation has a PLM. Production has an ERP. Quality has a QMS. Packaging approval has email, PDF markup, and whoever has been there longest — and it is the decision that legally commits your brand to a claim in a market.
The container that does not clear
Artwork ships to a Gulf market without a complete Arabic label block, or without a registered importer on pack. Goods are produced, palletised, shipped — and stopped. The cost is the freight, the demurrage, the re-label and the retail window you just missed.
The allergen that moved
A supplier reformulates. The spec is updated. The artwork is not — or it is, and the emphasis rule for the destination market is missed. This is the failure mode that ends in a recall notice, and it is a data-reconciliation problem wearing a safety hat.
The claim nobody can substantiate
"Halal", "recyclable", "no added sugar" go on pack because marketing asked and nobody could produce the document that says otherwise. Eighteen months later a regulator asks who approved it, against what evidence — and the certificate expired last spring.
None of these are AI problems. They are authority problems: nobody can say who approved what, against which evidence, for which market, on what date.
Who this is for
Four kinds of company, one shared problem
You own a pack that goes to more than one market, and somebody has to say it may be printed. That signature is currently defended by an email thread.
Brand owners exporting to 2+ markets
You place the product on the market, so the labelling duty is yours whoever printed it. Every added market multiplies the checks and nothing tracks which pack was cleared for which.
Contract manufacturers and co-packers
You print what the brand approved and carry the consequence when the approval was wrong. You need the approval on file, scoped, dated, and attached to the exact artwork file you ran.
Converters and print houses
A plate change costs a day and a run. You want a release you can act on rather than a PDF and a verbal yes, and a way to check it is still valid on the morning of the run.
Regulatory and quality consultants
You sign off packs for clients who each keep their evidence somewhere different. One record per client, per market, with the clause each finding traces to.
Not for you if you sell one product in one market, or if nobody is asked to approve artwork before it prints. The record only pays for itself where the approval is contested later.
The status quo
What this replaces, and what it does not
Packaging approval is not an empty category. It is a full one where no tool holds the decision — so the decision falls back to email.
Email, spreadsheets and PDF markup
Where most approvals live today. Everything is present and nothing is queryable: who approved which version, for which market, against which evidence, is a reading exercise across four inboxes.
Artwork proofing and pre-press tools
They compare two files and find the differences, precisely. They do not know which markets the pack is going to, what those markets require, or whether the supplier certificate behind a claim is in date.
PLM and packaging specification systems
They hold the specification and the bill of materials. They record that an approval happened; they do not run the check, scope the authority, or refuse a release.
Regulatory content databases
They tell you what the rule says. Reading the rule and applying it to this artwork, in this market, on this print date, is still a person with a checklist.
AI label checkers
A model reads the pack and reports what it thinks it sees. Useful as input. A verdict that varies between runs cannot be the basis of a release you defend a year later.
Where PackAuth sits
After extraction, before the plates. It takes canonicalised artwork as input, applies deterministic rules, and holds the approval and the release. It does not proof files or write regulation.
PackAuth consumes the output of the tools above rather than replacing them. The gap it fills is the decision itself — which is why it currently sits in an inbox.
The solution
An authority layer, not another label checker
PackAuth does not begin at "upload a PDF". It begins at the manifest: what the product is, where it is going, who is responsible, and what evidence that requires. Artwork is one input to that, checked late — not the thing the process is built around.
Every consequential action passes a rail: an ordered set of checks that must all hold before the action is permitted. No approval without a locked evidence snapshot. No print release without a live, in-scope approval. No release at all while a blocking finding is open.
AI proposes. Rules decide. Humans approve. PackAuth records.
What a model may never do here
Approve packaging
Activate a rule
Override a blocking finding
Issue a print release
Mark evidence legally valid
Grant a person authority they do not hold
Models extract, classify, translate and recommend — genuinely useful, and genuinely fallible. The verdict comes from deterministic rules over canonical data; the signature comes from a person who holds the authority to give it.
How it works
Six stages, each one gated
The lifecycle is a state machine: 24 states, 39 legal transitions. An illegal transition is rejected and the attempt is recorded. It is never quietly coerced into a legal one.
Every stage names one rail and runs it to completion before acting. Select a stage for detail.
The lifecycle
Every state, and what moves out of it
This is the spine. A manifest sits in exactly one state. An illegal transition is rejected and the attempt is recorded. Red states block a release. Green states permit one. Select any state for detail.
blocks release release permitted in progressdashed — terminalSelect any state for its transitions.
Staleness is automatic. Eleven change classes demote a live approval back to revalidation required — artwork version, formula or spec, target market, rule pack version, standard version, claim, packaging material, supplier evidence expiry, certification expiry, counterparty suspension, and revocation of the approver's authority. Nobody has to notice.
On the artwork
Every finding points at a place on the pack
A compliance run is not a score. It is a list of places on the pack. Each one names the rule that raised it, and the pack that rule was bought with. Select any marker.
One run, one artwork version, one set of target markets. The markers are numbered in reading order; four raised a finding and five cleared.
blockingmajorno finding
The pack drawing is illustrative. Every message, severity, recommendation and pack attribution beside it is read from the rule registry at build time — the generator refuses to build if a marker names a rule the canon does not contain, so this figure cannot drift away from the engine it depicts.
The product
What your team actually looks at
The market matrix answers your Monday-morning question. Which markets can you print for today, and what exactly is stopping the rest?. It is live at app.packauth.com, and every row it shows is fetched from the same API an integrator calls — the dashboard is a client of the contract, never a second implementation.
The product contains allergens but no allergen emphasis or 'contains' statement was detected.
Emphasise allergenic ingredients within the ingredient list, or add a compliant 'Contains' statement.
allergen_emphasis_present_003 · allergen_pack
blocking
An allergen declared in the formula of record is not declared and emphasised in the artwork ingredient list.
Add the missing allergen to the ingredient list and emphasise it in line with the destination market's emphasis rule.
allergen_formula_to_artwork_001 · allergen_pack · human review
blocking
No minimum cocoa solids percentage declared for a chocolate product.
Declare 'cocoa solids: minimum X%' in the same field of vision as the product name.
choc_cocoa_solids_001 · chocolate_pack
major
The artwork declares an allergen that does not appear in the formula of record.
Confirm whether the formula record is out of date or the artwork over-declares. Reconcile the two before approval.
allergen_artwork_to_formula_002 · allergen_pack · human review
major
One or more ingredient suppliers have no valid allergen declaration on file.
Request an in-date allergen declaration from each ingredient supplier.
allergen_declaration_evidence_005 · allergen_pack
minor
A 'may contain' statement is present without a supporting cross-contact assessment in evidence.
Attach the supplier allergen declaration or cross-contact risk assessment that supports the precautionary statement.
allergen_may_contain_substantiated_004 · allergen_pack · human review
Partial release, immediately
UK and EU print today. Blocked markets stay blocked, and the exclusion is recorded on the approval and carried onto the certificate.
Every finding is actionable
A rule that produces a message without a recommendation fails the build. There is no finding here that leaves a designer guessing.
Uncovered says so
Not a pass, not a fail — where no rules exist, no verdict is offered. That column is the honesty of the whole product in one cell.
Workflow
A food export, end to end, across four parties
The work crosses company boundaries constantly. That is where email loses it. Each lane is a different company. Each handoff is a gate that passes, or names what is missing.
The supplier never sees your manifest
A counterparty gets a scoped portal: the request made of them, what they uploaded, its status. Not the findings, not other suppliers, not your other products.
The consultant gets context, not a PDF
Findings arrive with the rule that produced them, the market it concerns, the zone on the artwork, and the recommendation — not an email saying "can you check this".
The printer gets something checkable
A certificate with the artwork hash on it. They verify their own file against it over a public endpoint, with no PackAuth account.
Jurisdictions
Markets resolve through a hierarchy, and coverage is stated honestly
A target market inherits every duty above it. Pick Saudi Arabia and you get GCC duties and the global baseline, without anyone remembering to add them. Where PackAuth has no rules for a market, it says so. It never reports a pass for a market it did not check.
6
Nothing matches that filter.
European Union
resolves EU → GLOBAL
7 packs12 rules8 blocking
blocking
Manifest has no product bound.core_manifest_resolvable_001 · core_packaging_lifecycle
blocking
Product is not classified to a category, so no sector or product pack can resolve.core_classification_present_002 · core_packaging_lifecycle
blocking
No target market declared, so no jurisdiction decision can be taken.core_target_market_present_003 · core_packaging_lifecycle
blocking
Mandatory particulars are not present in the official language of the destination member state.eu_member_state_language_001 · eu_pack
blocking
No EU-established responsible operator address detected.eu_responsible_operator_002 · eu_pack
blocking
A kosher certification mark is used on the artwork; its licensed use must be confirmed against the certifying body's current certificate.kosher_symbol_licensed_003 · kosher_pack
Manifest has no product bound.core_manifest_resolvable_001 · core_packaging_lifecycle
blocking
Product is not classified to a category, so no sector or product pack can resolve.core_classification_present_002 · core_packaging_lifecycle
blocking
No target market declared, so no jurisdiction decision can be taken.core_target_market_present_003 · core_packaging_lifecycle
blocking
A kosher certification mark is used on the artwork; its licensed use must be confirmed against the certifying body's current certificate.kosher_symbol_licensed_003 · kosher_pack
blocking
A component supplier is not approved for every destination market this release covers.supplier_approved_for_scope_004 · supplier_evidence_pack
blocking
A recycling mark is on the artwork and at least one component is not kerbside recyclable.sustainability_recycling_mark_matches_material_002 · sustainability_claims_pack
every rule they inherit still runs · what is missing is national law on top
12 rules
IrelandIE · inherits EU — the same 12 rules, 8 blocking · no Ireland national rules on top of EU
12 rules
GermanyDE · inherits EU — the same 12 rules, 8 blocking · no Germany national rules on top of EU
12 rules
FranceFR · inherits EU — the same 12 rules, 8 blocking · no France national rules on top of EU
9 rules
United StatesUS · baseline packs only — 9 rules, 6 blocking · no United States national rules
9 rules
CanadaCA · baseline packs only — 9 rules, 6 blocking · no Canada national rules
9 rules
AustraliaAU · baseline packs only — 9 rules, 6 blocking · no Australia national rules
A manifest targeting one of these is checked against everything it inherits, and the result says so. What PackAuth will not do is imply that national requirements beyond the inherited ones have been checked, because they have not been written yet.
Why the honest column matters. A compliance product that reports green for a market it never checked is worse than no product — it converts an unknown risk into a false assurance. Registered markets are classifiable as targets today and produce a clear not covered result, never a pass.
Who signs
Nobody here is simply "an approver"
Every role holds specific authority scopes, and may only sign an approval those scopes satisfy. A consultant with label authority cannot sign a market release. A printer with print authority cannot approve a halal claim. Nobody has to remember this.
Green dashed — evidence flowing in. Solid blue — releases flowing out. Select any party for what they see and what they can do.
An approval is only tested when something goes wrong: a recall, an audit, a rejected container. These are the questions asked then, and where the answer comes from.
The same six questions, asked a year later
The question
Email and spreadsheets
With PackAuth
Who approved this pack?
A name in a thread, if the thread was kept.
A named approver, and the authority scope they held when they signed.
Approved for which markets?
Usually unstated, so it reads as all of them.
Recorded per market, with exclusions carried onto the certificate.
Against which artwork?
The file attached to the reply, if it is still the current one.
One artwork version, content-hashed. A different file fails the check.
On what evidence?
Certificates in a shared drive, expiry unknown.
An evidence snapshot pinned at approval, with validity dates checked.
Under which rule?
Somebody's reading of a regulation, unrecorded.
A rule id and the clause it cites, retrieved from the primary source.
Is it still valid today?
Nobody is watching. It is valid until somebody notices it is not.
11 change classes demote the approval automatically and say why.
Nothing above requires anyone to work differently. The approval still happens; it is recorded as it happens rather than reconstructed afterwards.
What is at stake
The duty sits with whoever places the product on the market
Not with the printer, and not with the agency that drew the artwork. These are the consequences the record exists for.
Allergen and ingredient errors
The most common cause of food recalls. A withdrawal costs the stock, the logistics and the retailer relationship; the labelling duty is on the business whose name is on the pack.
Market entry refusal
A missing Arabic label block, an absent importer address, an organic claim with no control body code. The container arrives, is inspected, and does not clear.
Claims you cannot substantiate
Organic, halal, recyclable and nutrition claims each carry an evidence obligation. The claim is only lawful while the certificate behind it is in date for that market.
What an auditor asks for
Not whether you have a process. Whether you can produce, for one named pack, who approved it, for which markets, on what evidence, and against which version of which rule.
PackAuth is compliance infrastructure, not regulatory advice. It runs the checks you have bought, records what it checked, and states which markets it does not cover.
Integration
It sits between the systems you already run
PackAuth does not replace your PLM, your ERP or your artwork tooling. It is the approval and evidence layer between them. Every capability is an API endpoint before it is a screen, every state change fires a signed webhook, and there is a sandbox you can drive end to end before you talk to anybody.
Try it before you ask
sandbox.packauth.com mints a tenant on the spot — no sign-up, no email, no call. It is a separate database, so the interesting operations are the ones that change state, and the one that refuses to.
Reference and a request builder
dev.packauth.com lists every operation with the scope it needs and sends the reads for you. Generated from the same registry the API is routed from, so it cannot describe an endpoint that is not there.
Recipes that run
The cookbook is executable, not a page of snippets, and CI runs it. Writing it found five things a reader would otherwise have found the hard way — including one defect in the API.
API first
Every dashboard action maps to a documented endpoint. The screens, widgets, CLI and agent tools are clients of the same contract, never parallel implementations.
Webhooks
Signed with HMAC-SHA256 over timestamp.body. Your systems learn about a blocking finding or an issued release without polling.
Embeddable
Consultants embed the flows into their own client portals. A retailer can validate a supplier's packaging approval before a listing goes live.
The business case
The arithmetic is stage-of-catch, not licence cost
PackAuth does not claim to make compliance cheaper in the abstract. It moves the point of catch earlier. What a packaging error costs is driven by how late you find it, not by how serious it is.
Caught at artwork
A file change
The designer moves a block, the consultant re-approves, the run proceeds on schedule.
Caught at print
Plates + substrate
Origination is re-cut and the material already run is scrapped. Schedule slips into the next slot.
Caught in transit
Freight + demurrage + relabel
Stock is held at the border. Relabelling is manual, in-market, at someone else's rate — and the retail window closes.
Caught on shelf
Withdrawal + remediation
Product comes back. The cost is the stock, the logistics, the customer relationship, and the regulatory record that follows the brand.
Where the time goes back
Evidence chasing — counterparties are asked for exactly what their type and risk require, and expiry is monitored rather than discovered
Re-checking after a change — a material change stales the affected approvals automatically and re-runs only the affected packs
Audit preparation — the answer to "who approved this, on what basis" is stored state, not an archaeology project
Market-by-market re-work — partial approval lets ready markets print while a blocked one is resolved
What it does not do
Replace your regulatory adviser — it routes work to them with the context attached
Guarantee compliance in a market it carries no rules for — it reports that market as not covered
Decide whether a product is halal, or whether a claim is true — it establishes whether the claim is evidenced and by whom
Approve anything on its own — every signature belongs to a person holding the authority
Evidence and replay
An approval is only as good as what it was taken against
Every approval locks an immutable evidence snapshot: the exact documents, their versions, hashed. Asked in eighteen months why a pack was cleared for a market, PackAuth answers with what was true then — not with whatever is on file today.
Artwork content hash, pinned
Formula and specification version
Rule pack and dictionary versions in force
Extraction provider and version
Approver, role, and the authority scope exercised
Audit rows and evidence snapshots are append-only at the database level. Continuous integration attempts an update and a delete on every run and fails the build if either succeeds — a trigger that exists but never fires reads as assurance while providing none.
Why was this package approved for Saudi Arabia on 28 June 2026?
The question the whole architecture exists to answer — with evidence, rules, versions and approver scope, not a recollection.
A pack carries executable rules and a price. That is what makes gcc_pack a product rather than a button. Buy the market you are entering; the checks appear on the next run.
9
Nothing matches that filter.
Core Packaging Lifecycle PackManifest integrity, artwork versioning, evidence snapshot, approval, print release, change control and audit rules. Every manifest resolves this pack.
enforced12 rules
GB CLP PackGB chemical label duties from assimilated Regulation (EC) No 1272/2008. Every rule cites its Article: supplier identity, product identifier, signal word, hazard statements, precautionary statements, pictograms and nominal quantity. It also requires the classification itself on file, because an unasked question is not a negative answer. PackAuth does not classify.
enforced8 rules
UK Cosmetics PackUK cosmetic label duties from assimilated Regulation (EC) No 1223/2009. Every rule cites its Article: responsible person, nominal content, durability or period after opening, precautions, batch number and ingredient list. It also requires the three documents a UK release depends on — safety report, product information file and notification. The US regime is cosmetics_pack.
enforced9 rules
UK PackUK label duties: English language, UK responsible business address, date marking format, allergen emphasis.
enforced4 rules
EU PackEU label duties: member-state language, EU responsible operator, nutrition declaration format, minimum font size.
enforced5 rules
GCC PackGCC label duties: mandatory Arabic label block, production and expiry date marking, importer identification, country of origin.
enforced5 rules
US PackUS food label duties from 21 CFR Part 101. Every rule cites its section: identity, ingredients, responsible business, net quantity, nutrition, English, and claims. Four duties are declared out of scope rather than guessed at.
enforced9 rules
Canada PackCanadian bilingual label duties. Catalogued, not yet rule-packed.
planned
Food Labelling PackMandatory food label elements: legal name, ingredient list, net quantity, date marking, storage, business name and address, country of origin, nutrition declaration.
enforced10 rules
Allergen PackAllergen cross-check between the formula of record and the artwork ingredient list, including emphasis and 'may contain' handling.
enforced5 rules
Cosmetics PackUS cosmetic label duties from 21 CFR Parts 701 and 740. Every rule cites its section: identity, ingredients, net quantity, responsible business, and the safety-substantiation warning. Does not cover the EU regime.
enforced5 rules
Chemical / Hazard PackWorkplace hazard communication (GHS) label duties. Not yet rule-packed. The consumer regime and the transport regime are covered by their own packs, each cited section by section.
planned
Medical Device Labelling PackGreat Britain medical device duties from the Medical Devices Regulations 2002. Every rule cites its regulation: GB establishment, MHRA registration, the UK Responsible Person a non-UK manufacturer must appoint, the declaration of conformity, and the UK marking. The Annex I label duties are not enforced, because that Annex is incorporated by reference and PackAuth has not read it.
Supplements PackUS dietary supplement duties. Every rule cites its section: the Supplement Facts panel required by 21 CFR 101.36, the analysis behind it, and the 101.93 disclaimer that must accompany a structure/function statement. It also requires the 21 CFR 111.127 label-release procedure on file. Supplement Facts is not Nutrition Facts, and nothing checked the panel on a supplement before this pack.
enforced4 rules
Pharmaceutical PackUS drug label duties from 21 CFR Part 201. Every rule cites its section: identity, responsible business, ingredients, the OTC Drug Facts panel, English, and expiry dating. It checks that required statements are present. It does not judge whether directions for use are adequate — that is a clinical question.
enforced6 rules
Hazardous Substances PackUS consumer hazardous-substance duties from 16 CFR Part 1500. PackAuth does not decide whether a product is hazardous. It requires the hazard determination to be on file, and blocks when nobody has made one.
enforced2 rules
Hazardous Materials (Transport) PackUS transport marking and labelling from 49 CFR Part 172. PackAuth does not assign a UN number or hazard class. It checks the shipping description exists and the package carries the markings it requires.
enforced3 rules
Chocolate and Cocoa PackCocoa solids declaration, reserved product naming, vegetable-fat statement and milk-solids duties for chocolate products.
enforced4 rules
Claims PackDetects claims on artwork and requires each to resolve to approved substantiation evidence permitted in every target market.
enforced4 rules
Sustainability Claims PackRecyclable, compostable, carbon-neutral and recycled-content substantiation. Catalogued, not yet rule-packed.
enforced3 rules
Halal PackHalal certificate validity, certification-body recognition in the destination market, halal-risk ingredient screen, and mandatory human halal review where risk terms are present.
enforced7 rules
Kosher PackKosher certificate validity and certifying-agency recognition. Catalogued, not yet rule-packed.
enforced3 rules
Organic PackOrganic certification, control-body code and ingredient-percentage duties. Catalogued, not yet rule-packed.
enforced5 rules
Packaging Material PackFood-contact suitability, migration evidence, ink and adhesive declarations, and recyclability marking consistency for every declared component.
enforced5 rules
Amazon Marketplace PackMarketplace listing-image and e-label requirements. Catalogued, not yet rule-packed.
planned
Supplier Evidence PackCounterparty document chase, expiry monitoring and scope validation. Catalogued, not yet rule-packed.
enforced5 rules
Packs with no rules yet are listed as planned and never resolve onto a manifest. A pack that is applicable but unpurchased is reported — the run is never reported clean because a check was unpaid.
Start with the market that is blocking you
PackAuth is opening with food and confectionery exporters shipping into the UK, EU and Gulf. That is where a late catch costs a container, not a comment. If your packaging approvals live in a spreadsheet and an email thread, we would like to talk.
Selecting a Gulf destination resolves the GCC pack on top of the global baseline.
Arabic label block — the full mandatory particulars in Arabic. This is the single most common export blocker and the reason the pack exists.
Importer identification — the in-market registered importer must appear on pack.
Country of origin — mandatory, in both English and Arabic.
Production and expiry dates — Gulf markets expect both; a single durability date raises a finding.
Importer registration on file — an in-date registration for each Gulf destination.
Saudi Arabia and the UAE inherit all of these automatically by resolving upward to GCC.
The allergen cross-check
The highest-consequence rule PackAuth runs, and deliberately asymmetric.
In the formula, missing from artwork → blocking. Under-declaration is a safety failure. The release stops.
On the artwork, missing from the formula → major, human review. Over-declaration is a commercial problem and may mean the spec is stale. A person reconciles it.
Emphasis duty — where the destination flags a term as a major allergen, an emphasis or "contains" statement must be present.
"May contain" — a precautionary statement with no supporting cross-contact assessment raises a finding.
Canonical allergens are matched through their aliases: whey, casein, lactose all canonicalise to milk; spelt, semolina, malt to gluten cereals. Matching is diacritic-insensitive and word-boundary anchored, so an alias never matches inside a longer word.
Claim substantiation
Every claim detected on artwork or declared on the product must resolve to evidence that is approved, in date, and permitted in every target market.
Unsubstantiated → blocking. PackAuth will not release a claim it cannot evidence.
Market recognition — a halal certificate valid for the UAE does not automatically satisfy Saudi Arabia. The gap is raised per market, not waved through.
High-risk claims route to a reviewer holding legal claim authority.
Detected but not declared — a claim on artwork that is not on the product record is surfaced, because it cannot otherwise be substantiated or approved.
European Union — enforced
EU-wide packaging and labelling baseline. Member-state language duties are resolved at country level.
Resolves EU → GLOBAL
Mandatory particulars are not present in the official language of the destination member state. eu_pack
No EU-established responsible operator address detected. eu_pack
EU allergen emphasis duty not satisfied for one or more declared allergens. eu_pack
No nutrition declaration detected for an EU destination. eu_pack
Gulf Cooperation Council — enforced
GCC standardisation baseline; Arabic is mandatory across member states.
Resolves GCC → GLOBAL · required language(s): ar
Arabic label block not detected for a Gulf target market. gcc_pack
A halal claim or Gulf destination is in play but no valid halal certificate is on file. halal_pack
No in-market importer identified on the artwork. gcc_pack
The halal certificate has expired or expires before the intended print date. halal_pack
Country of origin is mandatory for Gulf markets and was not detected. gcc_pack
The certifying body on the halal certificate is not evidenced as recognised by every Gulf destination market. halal_pack
Gulf markets expect both production and expiry dates; a single durability date was detected. gcc_pack
An alcohol-class ingredient or carrier is present alongside a halal claim. halal_pack
United Kingdom — enforced
Great Britain and Northern Ireland packaging and labelling requirements.
Resolves UK → GLOBAL · required language(s): en
No MHRA device registration on file for this device. medical_device_pack
No classification on file, so whether this product is hazardous under GB CLP has never been established. uk_clp_pack
No responsible person name and address detected on the container or packaging. uk_cosmetics_pack
Mandatory particulars must be in English for the UK market. uk_pack
No UK Responsible Person appointment on file. medical_device_pack
No supplier name and address detected on the label. uk_clp_pack
No nominal content detected on the container or packaging. uk_cosmetics_pack
No UK or Northern Ireland responsible business address detected. uk_pack
Saudi Arabia — enforced
Saudi market; Arabic label block mandatory, importer details mandatory.
Resolves SA → GCC → GLOBAL · required language(s): ar
Arabic label block not detected for a Gulf target market. gcc_pack
A halal claim or Gulf destination is in play but no valid halal certificate is on file. halal_pack
No in-market importer identified on the artwork. gcc_pack
The halal certificate has expired or expires before the intended print date. halal_pack
Country of origin is mandatory for Gulf markets and was not detected. gcc_pack
The certifying body on the halal certificate is not evidenced as recognised by every Gulf destination market. halal_pack
Gulf markets expect both production and expiry dates; a single durability date was detected. gcc_pack
An alcohol-class ingredient or carrier is present alongside a halal claim. halal_pack
United Arab Emirates — enforced
UAE market; Arabic label block mandatory.
Resolves AE → GCC → GLOBAL · required language(s): ar
Arabic label block not detected for a Gulf target market. gcc_pack
A halal claim or Gulf destination is in play but no valid halal certificate is on file. halal_pack
No in-market importer identified on the artwork. gcc_pack
The halal certificate has expired or expires before the intended print date. halal_pack
Country of origin is mandatory for Gulf markets and was not detected. gcc_pack
The certifying body on the halal certificate is not evidenced as recognised by every Gulf destination market. halal_pack
Gulf markets expect both production and expiry dates; a single durability date was detected. gcc_pack
An alcohol-class ingredient or carrier is present alongside a halal claim. halal_pack
The 11 authority scopes
An authority scope is the unit of delegated approval power. A person may only sign an approval their scopes satisfy.
Marketing claim approval — Sign off on non-regulated promotional claims.
Legal claim approval — Sign off on claims carrying legal exposure or substantiation duty.
Regulatory label approval — Sign off on mandatory label elements for a declared jurisdiction.
Formula / spec approval — Sign off on the product formulation or technical specification of record.
Packaging material approval — Sign off on material suitability, food-contact status and migration evidence.
Translation approval — Sign off on the accuracy of a required-language label block.
Certification mark approval — Sign off on the use of a certification mark or logo under a valid certificate.
Print technical approval — Sign off on print-technical readiness (colour, dieline, resolution, bleed).
Market release approval — Sign off on releasing stock to a declared market and channel.
Supplier evidence approval — Sign off that counterparty evidence is sufficient for the declared scope.
Retailer private-label approval — Sign off on a retailer's private-label packaging requirements.
High-risk scopes may never be self-approved.
Suppliers — material and ingredient
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Packaging supplier — default risk medium; owes food contact declaration, material specification, migration test report, quality certificate
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Testing laboratories
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Certification bodies
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Certification body — default risk medium; owes accreditation certificate, scope of accreditation
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Printer
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Distributor / importer
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Distributor — default risk low; owes distribution agreement
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Retailer
Counterparties see a scoped portal: the request made of them, what they uploaded against it, and its status. Never your manifest, your findings, or each other.
Required evidence is derived from type and risk level, never hand-maintained per counterparty. Risk drives the revalidation clock: low 24m · medium 12m · high 6m · critical 3m.
Approvers
The people whose signature the whole system exists to make meaningful.
No legal product name detected — a brand name alone is not a legal name.
In this run — the element was detected, so the rule ran and produced no finding. A rule that could not run at all would block instead.
What resolves it — Add the name under which the food is legally sold, distinct from the brand.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — A required element must be present on the artwork.
This check ships with food_label_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
The artwork carries a claim that is not declared on the product record.
In this run — raised against this artwork version.
What resolves it — Declare the claim on the product so it can be substantiated and approved, or remove it from the artwork.
Severity major — Blocks release but may be dispositioned by an authorised approver with a recorded justification. It blocks the print release until it is resolved.
How it is checked — Two sources must agree — e.g. formula allergens against the artwork ingredient list. A person confirms the outcome; the engine never closes this one on its own.
This check ships with claims_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
Net quantity
food_net_quantity_003 · Food Labelling Pack · format check
No net quantity in a legal metric unit detected.
In this run — the element was detected, so the rule ran and produced no finding. A rule that could not run at all would block instead.
What resolves it — Declare net quantity in g, kg, ml or l in the principal field of vision.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — A present element must match a declared pattern (date format, net quantity, batch code).
This check ships with food_label_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
GTIN barcode
core_barcode_present_010 · Core Packaging Lifecycle Pack · format check
No scannable GTIN detected on the artwork.
In this run — the element was detected, so the rule ran and produced no finding. A rule that could not run at all would block instead.
What resolves it — Add the barcode and confirm it matches the GTIN recorded on the product variant.
Severity major — Blocks release but may be dispositioned by an authorised approver with a recorded justification. It blocks the print release until it is resolved.
How it is checked — A present element must match a declared pattern (date format, net quantity, batch code).
This check ships with core_packaging_lifecycle. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
An allergen declared in the formula of record is not declared and emphasised in the artwork ingredient list.
In this run — raised against this artwork version.
What resolves it — Add the missing allergen to the ingredient list and emphasise it in line with the destination market's emphasis rule.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — Two sources must agree — e.g. formula allergens against the artwork ingredient list. A person confirms the outcome; the engine never closes this one on its own.
This check ships with allergen_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
In this run — the element was detected, so the rule ran and produced no finding. A rule that could not run at all would block instead.
What resolves it — Add a tabular nutrition declaration per 100 g or 100 ml, unless a documented exemption applies.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — A required element must be present on the artwork.
This check ships with food_label_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
Arabic label block
gcc_arabic_label_001 · GCC Pack · language check
Arabic label block not detected for a Gulf target market.
In this run — raised against this artwork version.
What resolves it — Add the Arabic product name, ingredients, allergens, net quantity, origin, manufacturer/importer details and date marking.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — Every mandatory language for the target market must be present in the required label block. A person confirms the outcome; the engine never closes this one on its own.
This check ships with gcc_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
Date marking
gcc_production_and_expiry_004 · GCC Pack · format check
Gulf markets expect both production and expiry dates; a single durability date was detected.
In this run — raised against this artwork version.
What resolves it — Declare production date and expiry date, in Arabic as well as English.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — A present element must match a declared pattern (date format, net quantity, batch code). A person confirms the outcome; the engine never closes this one on its own.
This check ships with gcc_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
No responsible business name and address detected.
In this run — the element was detected, so the rule ran and produced no finding. A rule that could not run at all would block instead.
What resolves it — Add the name and address of the food business operator responsible in the destination market.
Severity blocking — Must be resolved before any release. Cannot be waived by the platform. It blocks the print release until it is resolved.
How it is checked — A required element must be present on the artwork.
This check ships with food_label_pack. Without that pack the rule never resolves onto the manifest, and the run reports the check as unpurchased rather than passed.
Regulator / auditor
The party who arrives eighteen months later and asks the question the architecture was built for.
The replay context — manifest version, artwork hash, spec version, evidence snapshot, pack versions, dictionary versions, extraction provider and version.
Immutable — audit rows and evidence snapshots are append-only at the database level, and CI attempts an update and a delete on every run to prove the triggers fire.
What was true then — the snapshot answers with the evidence as it stood at approval, not whatever is on file today.
Honest scope — for a market with no rules the record shows "not covered", never a manufactured pass.