Enterprise pilot layer

Controls that make Tasfi usable by serious builders.

Tasfi stays focused on Islamic AI verification. The pilot surface behaves like real infrastructure for Muslim builders: account-owned API keys, monthly quotas, metadata-only usage ledger, account-scoped reliability reports, and quarantine-first source intake.

Accounts

Owned API access

Pilot accounts resolve API keys to account metadata, quotas, plan, and status. Disabled accounts fail closed.

GET /v1/account
Usage

Metadata-only ledger

Usage summaries count routes, statuses, risk flags, citations checked, and escalations without storing submitted religious text.

GET /v1/usage
Reports

Account-scoped evidence

Pilot reports are scoped to the authenticated account and include source bundle identity plus reliability counts.

GET /v1/pilot-report
Sources

Quarantine-first intake

Source candidates require license, provenance, checksum, and source type. Intake cannot approve sources into product bundles.

POST /v1/source-intake

Strategy boundary

Blue ocean research informs the roadmap, not product drift.

Tasfi does not expose standalone finance, halal provenance, zakat, or waqf APIs in this pass. Sanad runs inside Guard for authenticated finance AI reliability checks while Maktaba source governance stays internal.