The agent and operator only send instructions. The enclave resolves identity, pays the provider, and sanitises the response — so PII never reaches untrusted hands.
The citizen proves identity by NIK. Issuers sign their true attributes with ed25519 — no uploads, no self-declaration.
Signatures verify instantly — "eligible: Tier G1, Rp 700,000" or "not eligible". Transparent, not yet binding.
The operator sees attested attributes only (✓ income=low · Tax Office) — never the salary or name. One click: approve or reject.
check-eligibility runs in the contract and sets the tier & amount by policy. The operator never types a number.
The enclave resolves the name and pays the provider. The agent gets back only a tx_id and status.
The aid lands. Every decision and payment is sealed to an immutable, PII-free audit trail.
The contract maps attested attributes to a fixed benefit tier. The figure is policy, not discretion.