# Collateral transfers and release

Run `php yii migrate` before using this module. The application must be able to create and write `common/uploads/custody-proofs`; keep this directory outside public web roots. Evidence is downloaded through a branch-scoped controller. PDF, JPG and PNG files up to 10 MB are supported.

From a collateral record, choose **Request transfer or release**. Enter the purpose and, for transfers, an active destination branch. A separate CEO approves the request with a reason. Approval does not change physical custody or post money.

An item must be held and free of submitted/approved applications, active loans and pending repayments. Pending requests reserve custody and prevent new pledges, intake edits and repayment reversals that reopen the associated loan. CEO approval checks the immutable item snapshot again. CEO rejection frees the reservation; an approved request can be cancelled before handover. Actions after a physical handover require a new reviewed workflow; no destructive rollback is provided.

For a transfer, source staff record the departure date, receiving person's name, unique handover reference and signed proof. The item remains assigned to its source branch with **in_transit** status. A different staff member with destination access records the receipt, signed proof, reference and storage location. Only then does custody move to the destination. The client's home branch and historical loan branches stay unchanged. This first implementation transfers unreserved items; moving security on an active loan requires a separate supported exception workflow.

For release, source staff record actual client collection with date, recipient, unique reference and signed proof after CEO approval. The item becomes **released**, retaining its original intake and all history. Released items cannot secure another loan. Existing intake records are preserved as explicitly labelled migration snapshots, rather than invented handover evidence.

Custody requests are visible from the collateral index. The request queue shows stages and is clickable; each detail page shows CEO decisions, physical events and downloadable evidence. Source and destination users can review their shared transfer request even after receipt moves the registry item to the destination.

Loan approval/payout/reloan services enforce custody eligibility; repayment reversals cannot reopen debt against released, transferred or reserved collateral. Amounts and prior repayments are unchanged by custody actions. Recovery sales and surplus refunds are a subsequent module.

Verification scenarios cover active security, duplicate requests/references, stale snapshots, CEO-only approval, self-approval, evidence requirements, two-person transfer, destination scope, cancellation, full settlement and forbidden reversal after release. HTTP checks submit an actual signed proof through the browser-facing form.
