HUMANITY COLLECTIVEGaza, today ← Back to the collective
About

One engine, two faces

Humanity Collective and Humanity Ledger are two names for the same system. Collective is what families and the public see. Ledger is what operators use underneath. Both read from the same recorded events.

The two faces
Same database. Different surfaces. No duplicate truth.

Humanity Collective is the public face. Families register a need, receive a private link, and see their place held in view. Visitors can explore Gaza by place, follow help in progress, and join in solidarity — without seeing private contact details.

Humanity Ledger is the operator spine. Coordinators, validators, and implementing partners move each need across a visible lifecycle: who holds it, what is blocking it, what happens next. The workbench is for signed-in operators — not a public browsing surface.

The public surface only shows what the ledger actually recorded. It does not invent outcomes the engine has not stored.

What you see on Collective
Aggregates and proof — never private contact fields.
  • Places held in view — sub-areas across Gaza, with counts drawn from registered cases.
  • Help in progress — tracks (one per sector) moving through the public five-stage funnel: Registration, Verification, Routing, Delivery, Family confirmation.
  • Solidarity — public voices of people who joined in solidarity with a place or with Gaza. Names and countries may appear; email does not.
  • Private family pages — each registered family gets a token-gated link (/h/<token>). Only people with the link can open it.
  • Activity feed — recent ledger events shown in plain language, with timestamps. Wording follows what was recorded — not what we wish had happened.
In this demo

The numbers on Collective come from a seeded demo database, not live operations. In the current reviewer seed:

2 families (cases) · 2 tracks (one per sector) · 0 tracks pending confirmation · 0 families with a recorded receipt confirmation · 0 ledger events

Family-sourced confirmations: 0. Source provenance was not recorded for these legacy confirmations, so they are not counted as family-sourced.

Treat every figure as illustrative unless you are running against a live deployment.

What Ledger holds underneath
Operator-facing detail the public surface does not expose.

Ledger stores the full coordination record: case intake, track state per sector, partner routing, funding allocation, implementer delivery claims, family feedback, and an append-only event log. Operators work in queues, tracks, reports, and the ledger itself.

The public surface never shows phone numbers, full contact names, or internal operator notes. Signed-in operators open the workbench; visitors without credentials are not dropped into operator screens.

If you are reviewing the product, the guided walkthrough at /demo (operator sign-in required in non-demo mode) shows one household’s journey end to end. This about page is the public explanation.

Demo mode
Read this before you treat anything as live.

This deployment is a demo. Records are seeded or illustrative. Registrations submitted here are for testing and are not yet acted on by real partners. No real aid delivery results from anything in this demo.

The demo banner at the top of every public page repeats the same warning. Contact email on /contact may not be monitored in demo mode.

In this demo, the operator workbench is open for inspection without sign-in. In a real deployment it requires operator credentials.

Delivery and family confirmation
Four terms. One rule: never claim receipt before the family confirms.

When help reaches delivery, the public story uses exactly these words:

Delivery recorded

The implementer or system recorded that delivery happened. This is a deliverer’s claim — not proof the family received help.

Pending confirmation

Delivery was recorded; the family has not confirmed receipt yet. The track waits at this stage until feedback exists.

Family confirmation

The family’s own feedback is recorded in the ledger. Only when that feedback confirms that assistance arrived, in full or in part, may the public story speak of confirmed receipt.

Ledger

The event was stored append-only — proof of what was recorded, and when. The ledger does not judge truth beyond the record.

Every step is recorded. Not every recorded step is family-confirmed. Pending confirmation must never read as receipt.
How to verify
For reviewers cloning the repository.

Product canon — spine definition, locked vocabulary, Arabic status lines, and the never-change list — lives in BOARD.md at the repository root. Read it before proposing changes.

Automated proof checks live in tools/proof_test.py. A passing run confirms public registration, solidarity signup, privacy boundaries, and workspace gating behave as documented. The script uses a temporary database — it does not modify the frozen reviewer seed.

Run instructions and the full route inventory are in README.md. This page is the on-site explainer; the README remains the handover document for repository reviewers.

Questions
Reach the team.

Whether you want to deploy Collective in your area, partner on coordination, or ask a product question — use the contact page.

Get in touch →

Implementing partners can also apply via Join as implementer (/join/implementer).