Bitta Commission guide
Audit and security
How Bitta Commission keeps evidence tamper-evident with append-only ledgers, hashes and audit entries, plus business continuity, integrity sweeps, country policies, privacy handling and sanitized support diagnostics.
status: verified applies-to: 1.1.2.0rev: 1
Commission records are financial evidence, so Bitta Commission is built to keep them tamper-evident, explainable and private. This page explains how the app protects evidence, where auditors find it, how country and privacy rules are recorded, and how support can diagnose a company without seeing personal data.
Business continuity records recovery expectations and the last integrity sweep.
Before you start
- Auditors need the Bitta Commission Auditor permission set. It reads configuration, ledgers and evidence and has no direct write access. Support staff use Bitta Commission Support in the same way. See Roles and permissions.
- Most evidence pages are also filtered by the user's commission scope. Give auditors a Finance (all participants) scope if they must see every participant.
- Business Continuity and Country/Region Policies are maintained by a user with the Bitta Commission Setup Administrator permission set.
How evidence is protected
- Append-only ledgers. Earnings, trace nodes, balance movements, eligibility entries, settlements, statements, dispute entries, approvals and accounting entries are inserted once and never edited or deleted. A correction adds a new entry that references the original.
- Hashes. Each ledger row carries a SHA-256 Entry Hash over its content. Many records also keep hashes of their inputs and definitions, for example the calculation input and plan definition hashes on an earning or the Statement Hash on a statement. Hash chains link related rows so that a removed or altered row is detectable.
- Exact-version actions. Governed actions check the record's current version and hash before they change state. An action taken on a stale copy is refused instead of overwriting newer work.
- Idempotency. Commands carry an idempotency key. Repeating the same command returns the original result, and reusing a key for different input is refused with BAA-IDEM-CONFLICT or an area-specific code.
- Governed changes only. Users change commission data through the app's actions, such as Submit, Approve or Freeze, not by editing tables. Most permission set writes are indirect for this reason.
Audit trail
Every administrative and financial operation writes an audit entry with the area and action, the target record and version, the before and after hashes, the acting user and any delegator, the time, session and client type, a hash of the user's commission permission sets at that moment, the result or error code, and a correlation ID.
To review it, run the Commission Audit Report from the role center. It has a print layout and an Excel layout.
Other evidence you can inspect:
| Page | What it shows |
|---|---|
| Commission Export Evidence | One row per report, page or API export: who requested it, when, row count, control amount, the hash of the filters, parameters and enforced participant scope, and a content hash chained over every emitted row. |
| Commission AI Call Audit | One row per AI call, with capability, provider, consent, redaction count, prompt and response hashes and whether data left Business Central. See AI plan design assistant. |
| Commission Archive Register | Archive manifests for statements and ledgers, and restore verifications. |
| Commission Notification Log | Every notification and its outcome. |
| Commission Approval Work Queue | The approval ledger behind each request, including the request hash. |
Integrity sweep and business continuity
Open Commission Business Continuity to record and test your recovery expectations.
| Group | Fields and actions |
|---|---|
| Backup and Restore Expectations | Backup Expectation, Recovery Point Objective Hours, Recovery Time Objective Hours, Restore Test Interval (for example 3M), Last Restore Test Date, Restore Test Overdue, Restore Test Reference. Choose Acknowledge Expectations after review. |
| Encryption | Verify Encryption checks whether data encryption is enabled and records the result and time. |
| Integrity Sweep | Sweep Sample Size sets how many of the most recent entries per ledger are verified. Run Integrity Sweep recomputes their hashes and logs the result. |
After you restore a database or environment, choose Record Restore Test and enter the evidence reference. The app records the test and runs an integrity sweep over the restored ledgers.
Sweep Log opens the Commission Integrity Sweep Log, one row per sweep with the number of ledgers, entries sampled and mismatches. Ledger Results shows the per-ledger result and the most recent entry that failed verification. The sweep is read-only. It never repairs data.
WARNING
If a sweep reports mismatches, do not try to fix ledger rows. Keep the environment as it is, export the support diagnostics, and contact Bitta Apps support.
Country/Region policies
Commission Country/Region Policies records the rules that apply to participants in each country or region. A blank country code is the company default.
| Field | What it does |
|---|---|
| Calendar Code | The commission calendar for participants in the country. |
| Rounding Precision, Rounding Direction | Amount rounding. Zero precision uses Commission Setup. |
| Statement Language Code | The statement language when the participant has no language code. |
| Date Format Code, Unit System Code | How statements and remittance documents show dates and quantities. |
| Statutory Wage Control, Min. Guaranteed Pay Per Period, Max. Recovery Percent | Minimum pay and recovery limits applied to settlements as controls. |
| Document Retention Years | How long commission documents are retained for the country. |
| Require Signed Agreement | Requires a signed plan agreement before a participant is paid or a plan is published for them. |
| Employee Payout Channel, Contractor Payout Channel | The payout channel per payee type. |
| Legal Review Reference, Legal Review Date | The customer legal review that approved the policy. |
A policy is Enforced only when it is not Blocked and has a legal review reference and a review date on or before today. Bitta Commission records and applies the values you enter. Your finance, payroll and legal owners decide what those values must be. Choose Participant Agreements to see the signed agreements per participant and plan version.
Privacy and data handling
- Commission plans, participants, source facts, calculations, settlements, statements, disputes and audit evidence are stored in your Business Central environment.
- The app sends license activation and refresh requests to Bitta Apps when you activate a license. See License lifecycle.
- Operational telemetry is limited. In Release 1.1 the app emits one telemetry event when a batch calculation run invocation finishes, with the operation, mode, result code, duration and a count band. It carries no customer business content, amounts or participant identifiers.
- Exports go only where your users send them: downloaded files, payroll-ready exports and AP documents.
- AI features are off until an administrator enables them and accepts a consent. Prompts are built from allowlisted fields and redacted before any provider call. In Release 1.1 the only provider runs inside Business Central.
- Free-text notes on dispute submissions and approval decisions are stored as hashes only.
- Posted evidence is corrected through reversal, correction or a successor version rather than rewritten.
In Commission Workflow Setup, Register retention policies registers comments, the notification log and the statement archive with the standard Business Central Retention Policies, so you can apply your own retention periods.
User scopes
Permission sets decide what a user can do. Commission User Scopes decide whose records they can see: their own participant, a manager and descendants, or all participants. Saved scope history cannot be edited. Change access by adding a new dated scope. See Roles and permissions.
Support diagnostics without personal data
Open Commission Support Diagnostics and choose Collect. The page lists sanitized facts in sections such as VERSION, ENVIRONMENT, SETUP, FEATURES, IMPLEMENTATION, POLICY, JOBQUEUE, ERRORS, LICENSE and INTEGRITY, each with a Severity Code when it needs attention. Identifiers such as the company ID are hashed, and counts are shown in bands. Choose Export Package to download the text file. The export is recorded in the audit trail. See Job queues, monitoring, and diagnostics.