Skip to content
ASIRI

Platform · One person, every register

She asked what you hold. This is the honest answer.

Nine systems, eleven registers, one name. Asiri assembles it in seconds — including the two entries that make the answer embarrassing, because leaving those out is the part that turns a late reply into a complaint.

Halima Sani

PER-0117 · customer since Mar 2023 · DSR-2026-0117 open

  • Core banking

    Name, phone, BVN

    Account since March 2023. Read six minutes ago.

  • Support desk

    4 tickets

    Subjects and timestamps only. The bodies are never read.

  • Marketing email

    Still in the audience

    She withdrew consent on 22 June. Nothing removed her.

  • Consent ledger

    Withdrawn 22 Jun

    Taken back from the email footer, against notice v3.

  • Identity checks

    BVN verified

    Verifyme, at sign-up. Nothing rechecked since.

  • Payments

    31 transactions

    References and dates. No amounts are read.

  • Collections spreadsheet

    Possibly held

    Sent by email attachment. Nobody can search it to confirm.

  • Backups

    Present in 4 snapshots

    Inventory only. Contents never read.

  • Requests register

    DSR-2026-0117 open

    An objection, 33 days elapsed, still not answered.

Assembled from 9 systems · 11 registers2 entries make this answer embarrassing

The two entries that matter

She withdrew consent on 22 June and is still in the audience

One system says she opted out. Another says she is on the list. Neither is lying — they simply never spoke to each other, and nothing in a normal stack is responsible for noticing that they disagree.

  1. The consent ledger says

    Withdrawn, 22 June

    Taken back from the footer of an email, recorded against notice version 3, timestamped. This record is unambiguous and correct.

  2. Mailchimp says

    Still in the audience

    And still receiving the lapsed-customer campaign, which is the activity with no lawful basis recorded at all.

  3. What she did next

    She complained

    SNAG-2026-004, on 18 July: “you kept marketing to me after I told you to stop, and nobody answered when I chased it.”

  4. What Asiri did

    Flagged it, 21 July

    Two systems disagreeing is the finding. Neither one could have produced it alone, and no dashboard would have shown it.

Eri noticed on 21 July, which is a month after the withdrawal and three days after she complained about it. Noticing late is better than not noticing — and the trail says exactly how late, because that is the number an auditor will want.

DSR-2026-0117 · 33 days elapsed

Assembling the answer is the fast part

This view builds in seconds. What took thirty-three days was nobody owning the request, then discovering that one of the nine systems could not be searched at all — because the collections agency holds a spreadsheet, not an integration.

You cannot answer in full for data you handed to somebody who cannot look it up. That is a supplier problem wearing a rights-request costume.

  1. 22 June

    She withdraws consent

    One click in an email footer. The consent ledger records it correctly and immediately.

  2. 25 June

    She objects formally

    DSR-2026-0117 arrives through the website form. The clock starts here and nobody is assigned.

  3. 18 July

    She complains

    Not about the marketing any more — about being ignored. A second record, and a second clock.

  4. 21 July

    Eri notices the contradiction

    A month after the withdrawal. Late, and the trail says exactly how late.

  5. Today · day 33

    Still open

    Thirty-three days and nothing has been sent. The collections spreadsheet still cannot be searched to answer in full.

Opening this is itself an event

A view this complete has to be watched more carefully than the systems it reads

Everything about one person in a single place is exactly what a rights request needs and exactly what an insider would want. So it is behind its own permission, every open is logged with the reason, and your auditor’s read of this page appears on your trail alongside everyone else’s.

Amaka from Veritas opened one customer record on 24 July to test whether an access request could be answered in full. It could not — and the test is on your trail, including which record she chose.

Rules on this view

Its own permission
Not granted by default with register access. Most people who need Asiri never need this view at all.
Every open is logged
With who, when and why — including support access from Asiri, under our own name.
Nothing sensitive is copied
Ticket bodies, balances and card numbers are never read, so they cannot appear here even for a legitimate request.
Gaps shown as gaps
The collections spreadsheet says “possibly held, cannot confirm”. A view that quietly omits what it cannot see is worse than no view.