ASP.NET Core document approval and audit system
A tested ASP.NET Core engineering system for immutable document versions, controlled review, separate approval, publication, withdrawal, and tamper-evident audit verification.

Project definition
Problem statement
Controlled documents require identifiable versions, distinct reviewers, separation of duties, concurrency protection, and evidence of every accepted action.
The system must reject unauthorised or stale transitions and expose any later alteration of retained audit events.
Project objectives
- Create immutable document versions with SHA-256 content digests.
- Require a configurable threshold of distinct reviewers.
- Enforce role, ownership and separation-of-duties rules.
- Detect stale writes with monotonic revisions.
- Build and verify a canonical hash-linked audit chain.
Project structure
Project components
Workflow engine
Implements Draft, InReview, ChangesRequested, AwaitingApproval, Approved, Published, and Withdrawn states.
Policy guards
Checks actor role, record ownership, reviewer threshold, separation of duties, state, and expected revision.
Version store
Preserves immutable version metadata and content digests while keeping reviews attached to the correct version.
Audit chain
Canonicalises event fields, links every event to the preceding hash, and verifies the retained sequence.
PostgreSQL adapter
Persists documents, versions, reviews, revisions, and audit events with Entity Framework Core constraints.
Evidence console
Provides the project purpose and health endpoint without presenting the system as a commercial SaaS workspace.
Methodology
Project workflow
- 01Create a draft
A synthetic author creates a controlled document and its first immutable version.
- 02Submit with a revision
The API accepts the transition only when the author owns the record and the expected revision is current.
- 03Review or revise
Two distinct reviewers accept the version, or a reviewer returns it so the author can create a replacement version.
- 04Approve and publish
An eligible approver accepts the reviewed version and a separate publisher releases it.
- 05Verify evidence
An auditor recomputes all event hashes and preceding links and reports the first inconsistency.
Demonstration scenario
A synthetic author submits an inspection procedure. A stale repeat is rejected, self-review is rejected, two distinct reviewers accept the version, a separate approver approves it, a publisher releases it, and an auditor verifies all six linked events.
Engineering
Tools and method
- Domain model
- A dependency-free C# workflow core keeps state rules deterministic and separately testable.
- ASP.NET Core API
- Minimal typed endpoints, fixed-time API-key comparison, validated synthetic actors, and consistent domain error mapping.
- Data model
- Entity Framework Core and PostgreSQL store documents, immutable versions, reviewer decisions, revisions, and chained audit events.
- Testing
- xUnit v3 covers transition policy, ownership, separation of duties, concurrency, integrity and tamper detection.
- Reproducibility
- Docker Compose runs the API with PostgreSQL and an integration script executes the complete six-event publication flow.
Testing
Evaluation
Evaluation measures
- 32 of 32 labelled scenarios match their expected result
- 32 of 32 scenarios remain deterministic across 100 repeats
- 3,232 total scenario evaluations
- 46 passing xUnit tests
- 97.34 percent line, 96.00 percent branch, and 95.23 percent method coverage
- PostgreSQL integration verifies authentication, stale-write rejection, self-review rejection, two-reviewer approval, publication, and a valid six-event audit chain
Project boundaries
- All actors and documents are synthetic.
- The audit chain is tamper-evident and is not an external notarisation or qualified signature.
- The laboratory does not include production identity, malware scanning, operational retention, regulatory validation, or availability certification.
- The retained measurements establish reproducibility for the controlled test environment, not production capacity.
Included
- 01Approval API, workflow engine, immutable version store, audit verifier, integration stack, and engineering evidence console
- 02Prepared sample data and demonstration scenarios
- 03Automated tests and measured results
- 04Complete source code in a private GitHub repository
- 05Complete project documentation in PDF and editable Word formats with synopsis, abstract, methodology, architecture diagrams, test results, screenshots, and conclusion
- 06Setup and usage guide
Project record
No information is collected on this page.
- Permanent project ID
- GP-CS-1CR0SWP
- Catalogued
- 21 Aug 2026
- Completed
- 25 Aug 2026
- Verified
- 25 Aug 2026
- Demonstration
- Included in repository
Handover
After purchase
- 01Payment is confirmed
The project is marked unavailable and cannot be purchased again.
- 02Repository access is granted
The buyer's submitted GitHub account receives access to the private repository.
- 03The purchase record is delivered
The certification sheet is prepared from the reviewed buyer details and sent privately by email.