> ## Documentation Index
> Fetch the complete documentation index at: https://corridor.udokaam.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# ADR 0011: Read-only first

> A customer starts by letting Corridor watch its existing wallets and match its own payout records; moving money is the second step.

## Context

Asking a licensed payment company to route money through new software on day one needs a security review, a custody review and pre-funding before it sees any value. Meanwhile the problem it feels every day is visibility: a payout crosses several providers and chains, and breaks surface when a customer complains.

## Decision

**The first product is read-only.** Watch-only observers (Tempo reader, `SolanaWatcher`, `Erc20Watcher`) need only addresses. `reconcileReadOnly` matches the company's own payout records against what moved, by reference first and by amount and counterparty otherwise, and returns matched, short, over, pending, missing and unexpected, with a CSV export. Moving money through Corridor's sagas is the second step, on the customer's own signer.

## Consequences

* A pilot can start in a day with no keys and no money at risk.
* Heuristic matching is weaker than reference matching; the pilot makes that gap visible, which is the argument for routing through Corridor.
* Base has no memo, so Base movements in read-only mode match by amount and counterparty only.

## Alternatives rejected

* **Integration-first:** slower to start and riskier for the customer.
* **Accounting-style wallet reconciliation:** books wallets, not payouts; it cannot tell whether a beneficiary was paid.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.