Source-of-Truth Whitepaper

MIZ OKI 3.5 Intelligence Compendium

Every deployed intelligence capability — media acquisition, customer retention, media management, commerce — catalogued, status-labeled, and grounded in the live cell registry.
r4.1 Final August 20, 2026 39 Registered Cells 10 Governance Services
Other tools optimize the number your ad platform reports. Mizoki optimizes the number your bank account reports.

MIZ OKI 3.5 is the Operating Knowledge Intelligence platform — a governed decision-infrastructure layer for enterprises that must move beyond dashboards, fragmented AI, and unsafe automation. It connects to business systems, converts signals into canonical evidence, organizes that evidence into a temporal-causal knowledge base, and governs every recommendation and action through the SRPVDAL operating loop. The commercial narrative is three words: Prove. Profit. Anticipate.

The Governing Loop: SRPVDAL

Every intelligence workflow in the platform moves through seven mandatory phases. No phase may be skipped. Legacy five-phase "SRDAL" naming is permanently superseded.

Sense→
Reason→
Plan→
Validate→
Decide→
Act→
Learn

Platform at a Glance

39
Registered Cells
10
Governance Services
15
Platform Services
7
SRPVDAL Phases

The production fleet comprises 32 numbered cells (Cells 1–32), the ORACLE latent-intent family (Cells 33–36), the Data Injector & External Intelligence Gateway (Cell 37), and CRE Prospecting (Cells 38–39) — all deployed on Google Cloud Run in us-central1. Ten horizontal governance services enforce the SRPVDAL loop across every domain. The cell registry at docs/architecture/CELL_REGISTRY.md is the number authority; external copy references services by name, never by number.

I. Media Acquisition Intelligence

The most mature domain. Media acquisition intelligence spans the full pipeline from signal capture through causal measurement to governed budget execution — proving what ad spend actually caused, pricing every conversion at what it truly nets, and refusing to act outside the evidence.

Causal Proof Engine Partial

Causal Credit Ledger Cells 26–27, 36 · measurement-rails

Every conversion classified caused or anticipated under the Rubin potential-outcomes framework. CATE estimation via the meta-learner family (S/T/X-Learner, DR-Learner/DML), hardened by automated refutation (placebo-treatment collapse, random-confounder invariance, subset stability), and triangulated against Bayesian MMM and geo experiments. Estimates that fail refutation are flagged, never shipped. The credit rule: a conversion is incremental only if experiment lift excludes zero AND the model had not already scored the customer in-market at exposure.

Uplift & Heterogeneous Treatment Effects Cell 26 (cell26-causal-uplift) Live

X-Learner heterogeneous treatment-effect estimation for uplift-quadrant targeting — budget on persuadables, first-class suppression of sure-things and sleeping dogs. Live-verified: run 31495398264, serving revision cell26-causal-uplift-00001-672, BigQuery connected.

Experiment Infrastructure measurement-rails · Cell 36

Holdout registry (randomized, ghost-bid, matched-geo), deterministic arm assignment, lift with Wilson/bootstrap confidence intervals. Ghost bids log the counterfactual auction without spending on placebo ads (Johnson, Lewis & Nubbemeyer, JMR 2017). Geo experiments use Meridian-GeoX-class synthetic control — publisher-agnostic because platform lift studies are the platform grading itself.

Threshold & Budget Intelligence Live

Threshold Intelligence Signal division

Structured discovery of activation points in platform delivery algorithms. Spend concentration strategies validated against causal measurement — not platform-reported metrics.

Budget Intelligence & Cross-Channel Reallocation service-decision-control-plane

Rectified-linear uplift gate (uplift > 5%, confidence > 0.70 — the Signal ReLU gate) driven by iROAS from the credit ledger. Per action class: authority_c = min(cap_c, max(0, DEL_score − threshold_c)). Flat zero below threshold = deterministic denial. Covenant cap = saturation. Platform sets floor thresholds; customers may raise but never lower.

Creative Intelligence Partial

Creative Fatigue & Rotation Cell 26 (Creative Suite)

Statistical decline forecasting + rotation strategies. Frequency-adjusted response decay detection; intent-stage → message-archetype fit. Winners determined by causal NCM lift, not CTR. Creative generation out of GA scope (brand-safety liability); formal revisit trigger post-Phase 3.

F1: Creative Component Unbundling In Build

Multimodal feature extraction — copy length, promotional framing, layout structure, imagery class, CTA placement — via vision-language embeddings. Doubly Robust ML (DR-Learner / DML) isolates the independent causal effect of each creative component from overall asset performance. The Clipped-ReLU DEL gate applies: component-rotation recommendations below threshold get zero authority. Lands on the CreativeSemanticProfile lane (I-03) and writes to Decision Memory. Effect estimates labeled provisional until pilot-scale creative volume exists; generated-creative deployment retains human approval.

Audience Intelligence Partial

Uplift-Quadrant Targeting Cell 26

X-Learner heterogeneous effects identify persuadables. Predictive audiences upgrade lookalikes — expansion candidates carry calibrated intent, not demographic resemblance. Measurement live; activation partial.

Measurement Foundations Live

Server-Side Measurement Rails service-marketing-connectors · intent-shopify-extender

Enhanced Conversions (Google), Meta CAPI with shared event-ID 48-hour dedup, GA4 Measurement Protocol, offline conversions, house attribution-window recompute, drift monitoring at 20% divergence over three consecutive days. Value writeback to platform bidders behind hard-off flags, dry-run by default.

Google Ads GAQL Intelligence Cell Live

Flagship SRPVDAL Proof Cell 31 · src/cells/google_ads_gaql

SearchStream extraction, GoogleAdsFieldService validation with caching, MCC traversal, canonical normalization, Firestore/BigQuery persistence, full-funnel mapping. Plans generated only after reasoning over evidence; mutate actions only under approval and eligibility. Default autonomy: observe/recommend.

OpenRTB Bidstream Intelligence Partial

Programmatic Intelligence Cell infrastructure

Senses bid requests, win/loss notices, buyer/seat metadata, device signals, price floors, currency, and consent. Reasons about inventory quality, auction duplication, floor effects, win-rate changes, fraud indicators, exchange performance, and supply-path optimization.

II. Customer Retention & Lifecycle Intelligence

Retention intelligence extends the same governed loop into lifecycle marketing, email, CRM integration, and the discipline of proving which retention actions actually keep customers versus merely applauding conversions that were coming anyway.

ESP / Email Intelligence Cell Partial

Email Lifecycle Governance ESP cell

Normalizes sends, opens, clicks, bounces, unsubscribes, complaints, conversions, suppression, segments, and campaign metadata. Reasons about deliverability, fatigue, segment quality, creative performance, send-time effects, revenue contribution, suppression risk, and cross-channel attribution. Actions tightly gated because email affects trust, compliance, and deliverability. SendGrid mapper live; Klaviyo proposed.

ORACLE Latent Intent Engine Partial

The anticipation layer that powers both acquisition and retention — calibrated predictions of who is entering market, what they'll want next, and when. Never "mind-reading," never audio, always with an explanation path.

Cell 33 — Micro-Signal Ingestion intent-signal-ingest Partial

Validates and consent-gates behavioral micro-signals: dwell, scroll velocity, viewport deceleration, partial-watch depth, tab-focus transitions. Consent check runs before persistence and fails closed; deny-listed categories discarded at ingest, not stored. Hard prohibitions: no audio, no keystroke dynamics (owner ruling O-1), no gaze, no fine-grained geolocation. IAM-locked, dispatch-only deploy.

Cell 34 — Intent Scoring API intent-scoring-api Partial

Sub-100ms intent scores with calibrated probabilities (Brier-scored), intent stages (awareness → consideration → in-market → purchase-imminent), purchase-timing windows, and explanation paths — no score delivered without its reasoning. Hourly single-writer batch scoring. Two-tower embeddings for candidate generation; session-sequence transformer serving behind default-off flag. Shadow since 2026-07-31; model quality gate open (fv2 model: 0.6967 AUC / 0.1845 Brier mean — blocked on real forward labels).

Cell 35 — Intent Graph intent-graph Partial

Durable intent subgraph on Firestore with boot rebuild, DSAR/erasure leg (live-verified 2026-08-10). Customer/Household/Topic/Product/Campaign nodes; SHOWED_INTEREST edges with decay, PRECEDES sequence edges with lift/support/confidence. Household links labeled deterministic vs. probabilistic; probabilistic edges excluded from all causal math. 321 tests at merge.

Cell 36 — Causal Credit intent-causal Live

The caused-vs-anticipated ledger. Refutation battery operational. Live-verified 2026-08-11: run 31494599562, fail-closed smoke passing, serving intent-causal-00012-j27. The one rule that keeps the crystal ball honest: prediction never grades itself.

Intent Engine v2 Perception Modules In Build

Five Modules with Data-Retention Contracts

I-01 PassiveAttentionSequence — viewport deceleration and scroll dynamics against session baselines. Ephemeral: raw sequence buffers purged on session termination.
I-02 SessionOutcomeForecast — ordered event streams to conversion probability with drift metadata. Retention: active session only.
I-03 CreativeSemanticProfile — asset embeddings mapped to session context. Retention: bounded to creative asset lifecycle.
I-04 IntentHypothesis — temporary graph bridges linking session evidence to causal hypotheses. Retention: strict TTL expiry; swept on schedule.
I-05 ValidationPassport — per-decision governance trace; ledger retention. The J-05 Executive Defensibility product.

Session-end purge jobs and retention-bound tests are part of the build, not documentation. O-1 PRIVACY LOCK is absolute and schema-enforced at both ingest and hypothesis creation.

Net Contribution Yield In Build

Order Economics & True Profit net-yield

Every order priced at what it truly nets: component COGS (bundle-decomposed), pick-and-pack, shipping, payment fees, expected return cost (actual-only until one observed cycle per SKU). Cohort net-margin computation. Value writeback hard-off until verified pilot. The bidding signal fed back to platforms is net contribution, not checkout revenue. The metric contract (NCM-v1) is versioned; any change ships as NCM-v2 with migration. IAM-locked, dispatch-only. Serving revision net-yield-00007-snj.

F2: Multi-Quarter LTV Treatment Regimes In Build

Long-Horizon Retention Economics

Dynamic treatment regimes evaluate multi-period outcome horizons: immediate conversion gain (Yt+1) balanced against discounted multi-quarter contribution margin (Yt+365) and the net present value of the customer relationship under each regime — so acquisition stops buying customers the P&L later regrets. The ledger gains an explicit outcome-horizon dimension. Code-level invariant: long-horizon findings publish only after ≥ 2 observed quarters of repeat-purchase data per cohort; insufficient data emits data_insufficient and blocks publication to decision surfaces.

III. Media Management & Deployment Intelligence

The operational infrastructure that manages connectors, executes governed actions, enforces policy, and maintains the knowledge base that every domain intelligence cell draws from.

Governance Services — The Horizontal Layer

ServicePhaseFunctionStatus
service-canonical-ingestionSenseThe one door in — publishes to Pub/Sub; hosts KG projection hook for kg_nodes/kg_relationshipsLive
service-validation-orchestratorValidateFull domain battery; caller-selected subsets rejected (422)Live
service-policy-enginePlanDeclarative policy.yaml, hash-versioned; treasury gate (F5), constraint veto, policy+treasury reloadLive
service-decision-control-planeDecideThe ONLY path to an authorized action; holds DCP_SIGNING_KEY; treasury vetoes to human reviewLive
service-approval-routingDecideTenant-scoped pending approvals queueLive
service-action-runnerActTwo-key + adapter enforcement; 13 installed adapters (Meta CAPI, Meta Ads, Google Ads, LinkedIn); execution fail-closed — all switches offLive
service-audit-replayLearnValidationPassport assembly, job status, canon status, treasury breach reviews, pilot state machineLive
service-model-registryReasonBaseline-or-nothing; every routed model registers a named baselineLive
service-media-incrementalityValidateIncrementality validation serviceLive
service-data-manager-connectorActData Manager API connector — never executed against live APILive

Action Runner Adapters — Installed Actuators

13 adapters + 1 legacy alias installed on the action runner. Every adapter has its own kill switch; all switches are off — execution is fail-closed and the tenant allowlist is empty (empty denies all).

ProviderAdapterCapability
Meta (CAPI)meta_capiUpload & restatement (measurement, separate from meta_ads)
Meta (Ads)meta_adsCampaign budget & status, adset bid & audience
Google Adsgoogle_adsCampaign budget & status, ad-group bid, keyword bid & status
LinkedInlinkedinStatus & daily budget

Platform Services

API Gateway api-gateway Live

The one intentionally public ingress. All other services are IAM-locked (unauth /health returning 403 is healthy posture).

Boss Agent (ADK) boss-agent-adk Live

Operator-facing orchestrator: six-domain runtime, 10 sixdomain MCP tools, eight intent tools. Mixture-of-Agents / Mixture-of-Experts / REWOO / Coding MOA. Does not bypass eligibility.

Command Center UI miz-oki-command-center-ui Live

Next.js/React/TypeScript command center (not a dashboard): live knowledge graph, SRPVDAL loop monitor, decision queue, simulation console, channel intelligence pages, audit ledger. Flag-off posture; mock content labeled.

Virtuoso Models Service virtuoso-models-service Live

Multi-vendor LLM routing layer: role-based dispatch, governed global fallback (claude-opus-5), alert on backup-path serving. No hardcoded model strings outside the registry. IAM+locked.

Gemini KG Pipeline gemini-kg-pipeline Live

Knowledge graph projection and GraphRAG serving from the Firestore-backed store. IAM-locked; callers: Boss OIDC, Cloud Scheduler OIDC, UI with buildAuthHeaders.

MOA Controller & MOE Router miz-oki-moa-controller · miz-oki-moe-router Live

Mixture-of-Agents consensus (POST /moa/consensus) and Mixture-of-Experts routing. IAM-locked. The Boss serves the MOE route in-process.

Connector Gateway Live

Marketing Connectors service-marketing-connectors

THE public webhook boundary for all marketing/commerce integrations. Mounted adapters: Meta/Facebook Ads, Google Ads, GA4, LinkedIn Ads, Amazon Ads, The Trade Desk, Google Merchant Center, approved public Google Shopping feeds, and Shopify (HMAC-signed webhooks + Admin GraphQL + OAuth install). One governed ingress — every accepted record forwards to service-canonical-ingestion. No direct connector-to-KG side doors.

External Intelligence Gateway Partial

Cell 37 — Data Injector & Market Intelligence market-signal-ingest

Dual role: (a) governed injection of non-streaming data — backfills, bulk loads, partner feeds, synthetic training data; (b) processing of external search/market sources — Google SERP/KG, Amazon Creators API, Meta platform signals, Wikidata (CC0 identity anchor), Schema.org structured data, SERP feeds. MarketSignal envelope + serp_provider / amazon_sp / shopify_inventory mappers built. External signals as corroboration only — never independently causal. Deployed 2026-08-11; SERP provider awaiting valid API key. Generic injection door: not started.

Knowledge Base & Graph Layer

Firestore-Backed Temporal-Causal Knowledge Base Live

Entities, relationships, sequence, causality, evidence, uncertainty, policy, and outcomes. Relationship types: semantic, temporal, causal, financial, policy, identity, learning, and (new) interest, sequence, creative-resonance, and hypothesis-status edges. Tenant-isolated. Neo4j retired by owner decision 2026-08-09. BigQuery mizoki-prod.unified is the analytical backbone. Vector search and document retrieval as projection options.

Growth Control Frontiers

F3: Supply-Chain & Inventory Yield Sync In Build

Inventory and fulfillment telemetry joins the Growth Decision Graph as typed nodes: (:SKU)-[:STOCK_STATE] (current level, reorder point, weeks-of-cover) and (:FulfillmentNode)-[:CAPACITY_STATE] (processing capacity, backlog, geographic reach). Three recommendation vectors — throttle bidding on stockouts, accelerate on overstock clearance, geo-shift on regional capacity constraints — are logged as ValidationPassport entries without dispatching to action runner adapters until the frontier climbs the autonomy ladder. Observe-only first (owner ruling 2026-08-19). Prevents the oldest waste in commerce advertising — paying to send customers to products you cannot ship.

F4: Continuous Bayesian Calibration via Micro-Geo Holdouts In Build

Geo reservation engine selects representative control groups using Synthetic Control Methods (SCM) from owner-provided candidate pool (config/f4_geo_candidates.yaml). Schedules spend perturbations within declared caps, estimates realized lift, and injects ground-truth incremental lift as informative priors into Bayesian MMM — calibration becomes a system property, not a quarterly project. Because geo-holdouts alter media spend, candidate reservations must pass through L2 Human Approval flows. After two clean calibration cycles, reservations become eligible for bounded autonomy within declared spend caps.

F5: Treasury-Gated Spend Governance In Build

Liquidity floors, credit availability, and debt covenants as hard constraints in VALIDATE and DECIDE. When cash reserves approach defined floors, DEL automatically reduces channel spend caps and vetoes budget expansions — naming the specific treasury constraint in the ValidationPassport. Treasury vetoes route to human review, never silently overridden. v1 (current): owner-declared constraints from config/treasury_constraints.yaml; v2: live treasury positions from the Capital division. Missing config = no constraint claimed (fail-closed, honest health). The enterprise sentence: your marketing system cannot spend money your treasury says you don't have.

IV. The Complete Cell Registry

Cells 1–32 — Production Fleet

CellFunctionPhase
1Discovery & IngestionSense
2Stream ProcessingSense
3Data Validation / KG Brain (GraphRAG serving, Firestore-backed)Sense
4Feature EngineeringSense
5Storage & PersistenceSense
6MOE RouterReason
7Causal EngineReason
8Graph AnalysisReason
9Prediction EngineReason
10Knowledge SynthesisReason
11Decision EngineReason
12Optimization EngineReason
13Risk AnalysisDecide
14Strategy PlanningDecide
15Validation & TestingDecide
16KD Autotuner & Customer SegmentationDecide
17Supply Chain OptimizationDecide
18MoE Router & CLV PredictionDecide
19System MonitoringAct
20Dynamic Pricing & Feedback/RLAIFAct
21Advanced MLAct
22NLP EngineAct
23Computer VisionLearn
24Observability HubLearn
25Security & ComplianceLearn
26Creative Suite / Causal Uplift Estimator (dual-service)Meta / Learn
27DR-Learner & DoWhy RefutationMeta
28A/B Testing (legacy — NOT an intent cell)Meta
29Meta Pixel Event ExtractionMeta
30Time Series AnalysisMeta
31Recommendation Engine / Google Ads GAQLMeta
32ROI DashboardMeta

Cells 33–37 — ORACLE & Gateway

CellServiceFunctionStatus
33intent-signal-ingestMicro-signal ingestion with consent gatePartial
34intent-scoring-apiIntent scoring, calibrated probabilities, explanation pathsPartial
35intent-graphDurable intent subgraph, DSAR/erasure, household labelsPartial
36intent-causalCaused-vs-anticipated ledger, refutation batteryLive
37market-signal-ingestData Injector & External Intelligence GatewayPartial

Cells 38–39 — CRE Prospecting

CellServiceFunctionStatus
38cre-prospecting-coreSense→Reason: roster/flyer intake, geocoding, entity resolution, scoring, matching, submarket intelligenceLive
39cre-outreach-enginePlan→Act→Learn: email authoring via Virtuoso, validation passport, DCP authorization, CRM sync, holdout/lift measurementLive

V. MIZOKI Signal for Shopify

The first commercial instance of the Media Acquisition cell — a separate offering built on the full platform base. Positioning: the merchant-market instance of a certifiable autonomous media control system.

Thesis

Independent Shopify merchants lose money to two structural failures: ad platforms grade their own homework (self-attribution inflates ROAS), and every tool optimizes revenue while merchants live on margin. Signal closes both: it measures what ad spend actually causes and optimizes Net Contribution Margin — what an order actually nets after everything it costs — under governance a founder can watch working.

Merchant Tiers — Honest Capability Floors

TierProfileDeliverableAutonomy
T1 Emerging< 300 orders/moValue feeds, feed enrichment, cold-start seeding, pooled priors — no merchant-level incrementality claimsL0–L1
T2 Growth300–3K orders/mo+ ghost-bid & cohort holdouts, always-on rotating holdout, NCM reallocationL2–L3
T3 Mid-market3K+ orders/mo+ geo-lift, lift-calibrated mini-MMM, cross-channel, covenant autonomyL4–L5 per class

The Four Levers (Black-Box Era, Lever-Native)

Modern merchants run Advantage+ / Performance Max — granular control is gone. Signal owns the levers that remain:

  1. Value Signal — E[NCM] per conversion via Meta CAPI + Google Enhanced Conversions / Conversion Value Rules. Send margin/pLTV to the bidder, not raw revenue — the bidder then hunts keepers, not discount-hunters.
  2. Exclusions — existing customers, high-return cohorts, owned-channel converters. Never pay for what the flow already wins.
  3. Creative Supply — fatigue detection (frequency-adjusted response decay), intent-stage → message fit, holdout-judged winners (NCM lift, not CTR). Generation out of scope.
  4. Budget & Guardrails — covenant caps + working-capital-aware pacing. Spend paced against weeks-of-inventory-cover and a merchant cash floor. Shop Campaigns and Klaviyo in the same causal audit.

Commerce Integration Stack

Shopify Webhook Receiver service-marketing-connectors Live

OAuth app (MIZ OKI Commerce Link), HMAC-signed webhooks (orders/*, refunds/*, inventory_levels/*, fulfillments/*), bulk-operation backfill, Admin GraphQL sync. Pub/Sub delivery path provisioned (topic + DLQ + push subscription). OAuth OFF pending operator secrets. Single governed ingress — fans out to canonical ingestion, intent extender, and net-yield. ORACLE pixel collector edge (POST /pixel/collect) flag-off by default.

Intent Shopify Extender intent-shopify-extender Live

Downstream consumer: Cell 33 intent signals + outcomes. IAM-locked; former public webhook receiver retired 2026-08-12 (the single-ingress collapse). ORACLE /pixel/events door flag-off (Stage A capture). CI deploy path established.

Net Yield Service net-yield Live

NCM computation: NCM(C) = Σ [R - COGS - F - S - P - E[RL]] - AdSpend(C). Bundle-decomposed COGS, 3PL surcharges, gateway fees, expected return cost. Writeback OFF. Rows carry hashed customer keys only. Dispatch-only deploy.

Go-to-Market

Signal Intelligence Public Surface Live

mizoki3.com/signal

Live production surface: causal-credit positioning, proof engine, field-note scenarios (composites, labeled), capability dossiers, dual roadmap previews, and the Signal Factory demo — raw connector events travel all seven SRPVDAL stages including one deliberate guardrail block. ORACLE pre-conversion perception page serving at /signal. Content QA gates enforced in CI.

VI. Additional Domain Intelligence

CRE Prospecting Live

Cell 38 — Prospecting Core (Sense → Reason) cre-prospecting-core

Roster/flyer intake, geocoding, entity resolution, scoring, matching, submarket intelligence. Composes with the existing mizoki_cre underwriting module. Never touches a recipient. IAM-locked; operator remainder: Google Maps API key. Deployed 2026-08-17.

Cell 39 — Outreach Engine (Plan → Act → Learn) cre-outreach-engine

Email authoring via Virtuoso, validation passport, DCP authorization gate, draft deployment (auto_send: false permanent), CRM sync, follow-up scheduling, holdout/lift measurement. Split at the DECIDE boundary — never computes a match. IAM-locked; operator remainder: provider transports (Graph/Gmail/Pipedrive), scheduler SA.

Legal & Policy Intelligence Partial

Counsel Room

Converts contracts, regulations, and internal rules into machine-checkable decision constraints. Mixture-of-Legal-Experts with IRAC reasoning. Demo engine only (fixtures, never production tenant data). Legal conclusions remain advisory-only.

Financial Intelligence Partial

Predictive Financial Cell

Reasons over revenue, margin, cost, cash flow, CAC, LTV, iROAS, payback, and forecasts. Financial validation sits inside Validate — an action that lifts platform-reported ROAS but destroys margin is not auto-approved. Advisory-only; built, pre-benchmark.

Document & Research Knowledge Live

Horizontal Knowledge Service

Transforms uploaded files, reports, notes, research, competitive intelligence, and strategy documents into structured evidence, relationships, and reusable decision memory. Ownership of resulting decisions remains with the relevant operating domain.

Future Domains Proposed

Capital, Risk, and Estate divisions are proposed — no code exists in the fleet. CRE underwriting and asset-risk reasoning (Simulation Passport, mandatory baselines) are built and advisory-only. Binding valuation, engineering, environmental, and credit decisions remain with licensed human authorities.

VII. Governance & Privacy Architecture

Hard Signal Prohibitions (Schema-Enforced, with Tests)

Autonomy Ladder (L0–L5)

LevelAuthorityPromotion Gate
L0 ObserveRead-only recommendations + reasoning pathsInstall default
L1 SignalValue feeds, audience syncs, feed enrichment; no spend changes14 days clean reconciliation
L2 HousekeepPause low-inventory/high-return SKU ads; rotate creative; exclusions1 purchase cycle at L1, zero violations
L3 ReallocateIntra-platform budget, ±20%/day cumulativeCalibrated forecasts over 2 cycles; ≥ 1 holdout
L4 Cross-channelCross-platform reallocation; bid-strategy changes≥ 2 experiments; clean DEL history
L5 AutonomousFull class authority within signed covenantT3 volume + sustained miNCM accuracy + covenant

Levels held per action class — L4 on budget while L2 on bids is normal. Every level: one-tap kill switch, immutable journal, weekly plain-language digest. Demotion is mechanical, never discretionary. Clamp widening is never autonomous; the promotion decision is always human.

ValidationPassport — The Immutable Decision Trace

Cryptographically Hashed Decision Envelope service-audit-replay Live

Every governed decision produces a ValidationPassport — a complete, hashed execution trace assembled from the immutable learning ledger. Contents: (1) decision ID and tenant context, (2) input signal references (canonical event envelope IDs), (3) ranked causal hypotheses from Reason, (4) evaluated counterfactual plans including the mandatory no-action baseline, (5) DEL Score and individual gate results (identity/signature, policy alignment, context sufficiency, hard constraints), (6) assigned autonomy level and action class, (7) approval records with timestamp and principal, (8) dispatched action commands or veto reasons, (9) predicted outcomes at time of decision, (10) backfilled realized outcomes when observed. This is the J-05 Executive Defensibility product — one auditable trace reconciling conflicting channel reports.

Canon Status API In Build

Live Canon Verification GET /api/v1/status/canon

Programmatically compares declared capability status (this whitepaper, the OFFERING_MAP, the cell registry) against live Cloud Run service registries, feature flags, and serving revisions. Prevents documentation-reality drift — the endpoint answers "is what the whitepaper says still true?" with measured evidence, not inference.

Claim Discipline

VIII. Production Roadmap

IX. High-Value Decision Jobs

Six defined product surfaces — each a job with input telemetry, eligible decisions, constraints, required evidence, and a targeted outcome.

JobNameCore Function
J-01IncrementalityHoldout-before-budget-shift; CATE + refutation evidence
J-02Waste PreventionCross-stack CPA-spike diagnosis; prohibition on automatic campaign blame
J-03Margin ControlBudget toward high-margin, in-stock, fulfillable SKUs; contribution economics
J-04Learning StabilityProtect platform learning phases from noisy feedback; staged changes with rollback
J-05Executive DefensibilityOne auditable decision trace reconciling conflicting channel reports
J-06Team LeverageAutomated evidence assembly with the human authorization gate retained

X. Platform Operational Architecture

DimensionMechanismFunction
State MachineSRPVDAL (7-stage)Every signal traverses Sense→Reason→Plan→Validate→Decide→Act→Learn before execution
Ingress Gateway15 native connectorsNormalizes raw data into 10-dimension Canonical Event Envelopes
Decision EvaluationFour deterministic gatesIdentity/Signature, Policy Alignment, Context Sufficiency, Hard Constraints
Decision AuthorityClipped-ReLU DELauthority_c = min(cap_c, max(0, DEL_score − threshold_c))
Autonomy ControlL0–L5 ladderObserve-only → full autonomy; earned per (account × action class); promotion always human
Causal InferenceCATE meta-learnersS/T/X-Learner, DR-Learner/DML with automated refutation
TriangulationMicro CATE + SCM GeoLift + Bayesian MMMUser-level causal ML × geographic experiments × aggregate portfolio models
MeasurementiROAS, never platform ROASThe number the bank account reports, not the ad platform
PrivacyO-1 PRIVACY LOCK (schema-enforced)Audio, keystroke, gaze, fine-geo, sensitive categories — blocked at validation, not toggled
AuditImmutable ledger + ValidationPassportEvery decision traceable; prediction never grades itself

XI. Critical Path: Required Owner Inputs

To move from code completion to live pilot deployment, the following configuration parameters must be supplied by the enterprise owner. Once configured, the system executes the 90-Day Pilot in observe-only mode, generating verifiable ValidationPassports and lift metrics required to advance through the Three-Gate Evidence Maturity Framework.

InputConfig PathPurposeBlocks
Pilot tenant selectionOperator decisionInitial brand account and agreed source connectors (Google Ads, Meta, Shopify, GA4, BigQuery)All workstreams
Cost structureconfig/net_yield_costs.yamlCOGS, payment fees, pick-pack-ship, baseline return rates per SKUNet Yield (NCM)
Treasury constraintsconfig/treasury_constraints.yamlMinimum liquidity floors, credit limits, covenant proximity curvesF5 Treasury Gating
Candidate geo poolconfig/f4_geo_candidates.yamlPermissible regions, spend perturbation caps, excluded control marketsF4 Geo Calibration
Creative asset accessMultimodal asset store permissionsTraining creative component models (vision-language embeddings)F1 Creative Unbundling

XII. Completion Workstream Architecture

Ten engineering workstreams operationalize the whitepaper, amendment, and Growth Control unified system into active builds. Each workstream maps to specific cells, services, and frontiers — with explicit dependency chains and build gates.

WSNameScopeDepends OnStatus
0Governance & CanonVocabulary ratification, Canon Status API, OFFERING_MAP v2.3 alignment—Partial
AIntent Engine v2 HardeningO-1 PRIVACY LOCK enforcement, ephemeral lifecycle purges (I-01–I-04), retention-bound testsWS-0In Build
BValidationPassport PackagingImmutable decision trace envelope (10 fields), J-05 product surfaceWS-0Live
CNet Yield CompletionOrder economics tables, NCM compute, writeback fail-closed gatesOwner: cost configIn Build
DF3 Supply-Chain SyncInventory graph nodes, 3 recommendation vectors, observe-only dispatchWS-CIn Build
EDecision Jobs & 90-Day PilotJ-01–J-06 registry, pilot state machine (Observe→Validate→Recommend)WS-B, WS-CPartial
FF4 Geo CalibrationGeo reservation engine, SCM lift estimation, Bayesian MMM prior loopOwner: geo pool; WS-EIn Build
GF1 Creative UnbundlingMultimodal extraction, DR-Learner component isolation, DEL-gated rotationOwner: asset access; WS-A (I-03)In Build
HF2 LTV RegimesDynamic treatment regimes, outcome-horizon ledger, ≥2-quarter publish gateWS-C, WS-F (2 cycles)In Build
IF5 Treasury GatingCapital constraint integration, DEL spend tightening, breach routingOwner: treasury configIn Build

Dependency Graph

graph TD
    WS0["WS-0 Governance & Canon"]
    WSA["WS-A Intent Engine v2"]
    WSB["WS-B ValidationPassport"]
    WSC["WS-C Net Yield"]
    WSD["WS-D F3 Supply-Chain"]
    WSE["WS-E Decision Jobs & Pilot"]
    WSF["WS-F F4 Geo Calibration"]
    WSG["WS-G F1 Creative Unbundling"]
    WSH["WS-H F2 LTV Regimes"]
    WSI["WS-I F5 Treasury Gating"]

    OC["Owner: Cost Config"]
    OG["Owner: Geo Pool"]
    OA["Owner: Asset Access"]
    OT["Owner: Treasury Config"]
    OP["Owner: Pilot Tenant"]

    WS0 --> WSA
    WS0 --> WSB
    OC --> WSC
    WSC --> WSD
    WSB --> WSE
    WSC --> WSE
    WSE --> WSF
    OG --> WSF
    WSA --> WSG
    OA --> WSG
    WSC --> WSH
    WSF --> WSH
    OT --> WSI
    OP --> WSE

    style WS0 fill:#e8f4f8,stroke:#1A7FB5,color:#0B1A2E
    style WSA fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSB fill:#e6f7ed,stroke:#1B8A50,color:#0B1A2E
    style WSC fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSD fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSE fill:#fef3e2,stroke:#B87A14,color:#0B1A2E
    style WSF fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSG fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSH fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style WSI fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
    style OC fill:#fff8f0,stroke:#C4814A,color:#2C3038
    style OG fill:#fff8f0,stroke:#C4814A,color:#2C3038
    style OA fill:#fff8f0,stroke:#C4814A,color:#2C3038
    style OT fill:#fff8f0,stroke:#C4814A,color:#2C3038
    style OP fill:#fff8f0,stroke:#C4814A,color:#2C3038

Build Sequencing Logic

The 90-Day Growth Control Pilot — Standard Commercial Onboarding

The pilot is both the sales motion and the proof motion — the machine that closes a customer is the same machine that produces the verified numbers. Adopted as standard by owner ruling 2026-08-19.

PhaseDaysActivityDeliverableAutonomy
Observe1–30Connect agreed stack (Google Ads, Meta, Shopify, GA4, BigQuery). Establish baseline data quality. Define target Decision Jobs. Zero changes to live execution.Baseline data-quality report; connected-stack inventoryL0
Validate31–60Synthetic-control geo experiments. CATE model calibration. Propensity verification. Margin reconciliation against customer's own books.Calibrated model card; first verified lift findings; margin reconciliationL0–L1
Recommend61–90Fully contextualized decision proposals with complete audit trails. Routed through designated human approval. Every prediction graded against outcomes.Decision proposals with ValidationPassports; pilot completion reportL1–L2

Three-Gate Evidence Maturity Framework

The alignment that makes the machine self-reinforcing: the pilot that closes a customer is the same machine that produces the verified numbers that flip the public Preview labels. The sales motion and the proof motion are one motion.

Packaging Ladder

TierEntryDeliverablesGate
Signal FactoryFree public demoLive SRPVDAL walkthrough; truth-delta preview; system logic proofGate 1
90-Day Growth Control PilotPaidCalibrated models, first verified lift findings, margin reconciliation, decision proposals with passportsGate 2
Signal OperationsAnnualDecision Jobs J-01–J-06 under chosen autonomy tier; standing F4 recalibration; weekly plain-language digestGate 2+
Enterprise Growth ControlAnnual+ F2 LTV regimes, F3 supply-chain sync, F5 treasury gating; Capital/Counsel/Risk division interlockGate 3