Other tools optimize the number your ad platform reports. Mizoki optimizes the number your bank account reports.
MIZ OKI 3.5 is the Operating Knowledge Intelligence platform — a governed decision-infrastructure layer for enterprises that must move beyond dashboards, fragmented AI, and unsafe automation. It connects to business systems, converts signals into canonical evidence, organizes that evidence into a temporal-causal knowledge base, and governs every recommendation and action through the SRPVDAL operating loop. The commercial narrative is three words: Prove. Profit. Anticipate.
Every intelligence workflow in the platform moves through seven mandatory phases. No phase may be skipped. Legacy five-phase "SRDAL" naming is permanently superseded.
virtuoso_call; model strings are registry-controlled.The production fleet comprises 32 numbered cells (Cells 1–32), the ORACLE latent-intent family (Cells 33–36), the Data Injector & External Intelligence Gateway (Cell 37), and CRE Prospecting (Cells 38–39) — all deployed on Google Cloud Run in us-central1. Ten horizontal governance services enforce the SRPVDAL loop across every domain. The cell registry at docs/architecture/CELL_REGISTRY.md is the number authority; external copy references services by name, never by number.
The most mature domain. Media acquisition intelligence spans the full pipeline from signal capture through causal measurement to governed budget execution — proving what ad spend actually caused, pricing every conversion at what it truly nets, and refusing to act outside the evidence.
Every conversion classified caused or anticipated under the Rubin potential-outcomes framework. CATE estimation via the meta-learner family (S/T/X-Learner, DR-Learner/DML), hardened by automated refutation (placebo-treatment collapse, random-confounder invariance, subset stability), and triangulated against Bayesian MMM and geo experiments. Estimates that fail refutation are flagged, never shipped. The credit rule: a conversion is incremental only if experiment lift excludes zero AND the model had not already scored the customer in-market at exposure.
X-Learner heterogeneous treatment-effect estimation for uplift-quadrant targeting — budget on persuadables, first-class suppression of sure-things and sleeping dogs. Live-verified: run 31495398264, serving revision cell26-causal-uplift-00001-672, BigQuery connected.
Holdout registry (randomized, ghost-bid, matched-geo), deterministic arm assignment, lift with Wilson/bootstrap confidence intervals. Ghost bids log the counterfactual auction without spending on placebo ads (Johnson, Lewis & Nubbemeyer, JMR 2017). Geo experiments use Meridian-GeoX-class synthetic control — publisher-agnostic because platform lift studies are the platform grading itself.
Structured discovery of activation points in platform delivery algorithms. Spend concentration strategies validated against causal measurement — not platform-reported metrics.
Rectified-linear uplift gate (uplift > 5%, confidence > 0.70 — the Signal ReLU gate) driven by iROAS from the credit ledger. Per action class: authority_c = min(cap_c, max(0, DEL_score − threshold_c)). Flat zero below threshold = deterministic denial. Covenant cap = saturation. Platform sets floor thresholds; customers may raise but never lower.
Statistical decline forecasting + rotation strategies. Frequency-adjusted response decay detection; intent-stage → message-archetype fit. Winners determined by causal NCM lift, not CTR. Creative generation out of GA scope (brand-safety liability); formal revisit trigger post-Phase 3.
Multimodal feature extraction — copy length, promotional framing, layout structure, imagery class, CTA placement — via vision-language embeddings. Doubly Robust ML (DR-Learner / DML) isolates the independent causal effect of each creative component from overall asset performance. The Clipped-ReLU DEL gate applies: component-rotation recommendations below threshold get zero authority. Lands on the CreativeSemanticProfile lane (I-03) and writes to Decision Memory. Effect estimates labeled provisional until pilot-scale creative volume exists; generated-creative deployment retains human approval.
X-Learner heterogeneous effects identify persuadables. Predictive audiences upgrade lookalikes — expansion candidates carry calibrated intent, not demographic resemblance. Measurement live; activation partial.
Enhanced Conversions (Google), Meta CAPI with shared event-ID 48-hour dedup, GA4 Measurement Protocol, offline conversions, house attribution-window recompute, drift monitoring at 20% divergence over three consecutive days. Value writeback to platform bidders behind hard-off flags, dry-run by default.
SearchStream extraction, GoogleAdsFieldService validation with caching, MCC traversal, canonical normalization, Firestore/BigQuery persistence, full-funnel mapping. Plans generated only after reasoning over evidence; mutate actions only under approval and eligibility. Default autonomy: observe/recommend.
Senses bid requests, win/loss notices, buyer/seat metadata, device signals, price floors, currency, and consent. Reasons about inventory quality, auction duplication, floor effects, win-rate changes, fraud indicators, exchange performance, and supply-path optimization.
Retention intelligence extends the same governed loop into lifecycle marketing, email, CRM integration, and the discipline of proving which retention actions actually keep customers versus merely applauding conversions that were coming anyway.
Normalizes sends, opens, clicks, bounces, unsubscribes, complaints, conversions, suppression, segments, and campaign metadata. Reasons about deliverability, fatigue, segment quality, creative performance, send-time effects, revenue contribution, suppression risk, and cross-channel attribution. Actions tightly gated because email affects trust, compliance, and deliverability. SendGrid mapper live; Klaviyo proposed.
The anticipation layer that powers both acquisition and retention — calibrated predictions of who is entering market, what they'll want next, and when. Never "mind-reading," never audio, always with an explanation path.
Validates and consent-gates behavioral micro-signals: dwell, scroll velocity, viewport deceleration, partial-watch depth, tab-focus transitions. Consent check runs before persistence and fails closed; deny-listed categories discarded at ingest, not stored. Hard prohibitions: no audio, no keystroke dynamics (owner ruling O-1), no gaze, no fine-grained geolocation. IAM-locked, dispatch-only deploy.
Sub-100ms intent scores with calibrated probabilities (Brier-scored), intent stages (awareness → consideration → in-market → purchase-imminent), purchase-timing windows, and explanation paths — no score delivered without its reasoning. Hourly single-writer batch scoring. Two-tower embeddings for candidate generation; session-sequence transformer serving behind default-off flag. Shadow since 2026-07-31; model quality gate open (fv2 model: 0.6967 AUC / 0.1845 Brier mean — blocked on real forward labels).
Durable intent subgraph on Firestore with boot rebuild, DSAR/erasure leg (live-verified 2026-08-10). Customer/Household/Topic/Product/Campaign nodes; SHOWED_INTEREST edges with decay, PRECEDES sequence edges with lift/support/confidence. Household links labeled deterministic vs. probabilistic; probabilistic edges excluded from all causal math. 321 tests at merge.
The caused-vs-anticipated ledger. Refutation battery operational. Live-verified 2026-08-11: run 31494599562, fail-closed smoke passing, serving intent-causal-00012-j27. The one rule that keeps the crystal ball honest: prediction never grades itself.
I-01 PassiveAttentionSequence — viewport deceleration and scroll dynamics against session baselines. Ephemeral: raw sequence buffers purged on session termination.
I-02 SessionOutcomeForecast — ordered event streams to conversion probability with drift metadata. Retention: active session only.
I-03 CreativeSemanticProfile — asset embeddings mapped to session context. Retention: bounded to creative asset lifecycle.
I-04 IntentHypothesis — temporary graph bridges linking session evidence to causal hypotheses. Retention: strict TTL expiry; swept on schedule.
I-05 ValidationPassport — per-decision governance trace; ledger retention. The J-05 Executive Defensibility product.
Session-end purge jobs and retention-bound tests are part of the build, not documentation. O-1 PRIVACY LOCK is absolute and schema-enforced at both ingest and hypothesis creation.
Every order priced at what it truly nets: component COGS (bundle-decomposed), pick-and-pack, shipping, payment fees, expected return cost (actual-only until one observed cycle per SKU). Cohort net-margin computation. Value writeback hard-off until verified pilot. The bidding signal fed back to platforms is net contribution, not checkout revenue. The metric contract (NCM-v1) is versioned; any change ships as NCM-v2 with migration. IAM-locked, dispatch-only. Serving revision net-yield-00007-snj.
Dynamic treatment regimes evaluate multi-period outcome horizons: immediate conversion gain (Yt+1) balanced against discounted multi-quarter contribution margin (Yt+365) and the net present value of the customer relationship under each regime — so acquisition stops buying customers the P&L later regrets. The ledger gains an explicit outcome-horizon dimension. Code-level invariant: long-horizon findings publish only after ≥ 2 observed quarters of repeat-purchase data per cohort; insufficient data emits data_insufficient and blocks publication to decision surfaces.
The operational infrastructure that manages connectors, executes governed actions, enforces policy, and maintains the knowledge base that every domain intelligence cell draws from.
| Service | Phase | Function | Status |
|---|---|---|---|
service-canonical-ingestion | Sense | The one door in — publishes to Pub/Sub; hosts KG projection hook for kg_nodes/kg_relationships | Live |
service-validation-orchestrator | Validate | Full domain battery; caller-selected subsets rejected (422) | Live |
service-policy-engine | Plan | Declarative policy.yaml, hash-versioned; treasury gate (F5), constraint veto, policy+treasury reload | Live |
service-decision-control-plane | Decide | The ONLY path to an authorized action; holds DCP_SIGNING_KEY; treasury vetoes to human review | Live |
service-approval-routing | Decide | Tenant-scoped pending approvals queue | Live |
service-action-runner | Act | Two-key + adapter enforcement; 13 installed adapters (Meta CAPI, Meta Ads, Google Ads, LinkedIn); execution fail-closed — all switches off | Live |
service-audit-replay | Learn | ValidationPassport assembly, job status, canon status, treasury breach reviews, pilot state machine | Live |
service-model-registry | Reason | Baseline-or-nothing; every routed model registers a named baseline | Live |
service-media-incrementality | Validate | Incrementality validation service | Live |
service-data-manager-connector | Act | Data Manager API connector — never executed against live API | Live |
13 adapters + 1 legacy alias installed on the action runner. Every adapter has its own kill switch; all switches are off — execution is fail-closed and the tenant allowlist is empty (empty denies all).
| Provider | Adapter | Capability |
|---|---|---|
| Meta (CAPI) | meta_capi | Upload & restatement (measurement, separate from meta_ads) |
| Meta (Ads) | meta_ads | Campaign budget & status, adset bid & audience |
| Google Ads | google_ads | Campaign budget & status, ad-group bid, keyword bid & status |
| Status & daily budget |
The one intentionally public ingress. All other services are IAM-locked (unauth /health returning 403 is healthy posture).
Operator-facing orchestrator: six-domain runtime, 10 sixdomain MCP tools, eight intent tools. Mixture-of-Agents / Mixture-of-Experts / REWOO / Coding MOA. Does not bypass eligibility.
Next.js/React/TypeScript command center (not a dashboard): live knowledge graph, SRPVDAL loop monitor, decision queue, simulation console, channel intelligence pages, audit ledger. Flag-off posture; mock content labeled.
Multi-vendor LLM routing layer: role-based dispatch, governed global fallback (claude-opus-5), alert on backup-path serving. No hardcoded model strings outside the registry. IAM+locked.
Knowledge graph projection and GraphRAG serving from the Firestore-backed store. IAM-locked; callers: Boss OIDC, Cloud Scheduler OIDC, UI with buildAuthHeaders.
Mixture-of-Agents consensus (POST /moa/consensus) and Mixture-of-Experts routing. IAM-locked. The Boss serves the MOE route in-process.
THE public webhook boundary for all marketing/commerce integrations. Mounted adapters: Meta/Facebook Ads, Google Ads, GA4, LinkedIn Ads, Amazon Ads, The Trade Desk, Google Merchant Center, approved public Google Shopping feeds, and Shopify (HMAC-signed webhooks + Admin GraphQL + OAuth install). One governed ingress — every accepted record forwards to service-canonical-ingestion. No direct connector-to-KG side doors.
Dual role: (a) governed injection of non-streaming data — backfills, bulk loads, partner feeds, synthetic training data; (b) processing of external search/market sources — Google SERP/KG, Amazon Creators API, Meta platform signals, Wikidata (CC0 identity anchor), Schema.org structured data, SERP feeds. MarketSignal envelope + serp_provider / amazon_sp / shopify_inventory mappers built. External signals as corroboration only — never independently causal. Deployed 2026-08-11; SERP provider awaiting valid API key. Generic injection door: not started.
Entities, relationships, sequence, causality, evidence, uncertainty, policy, and outcomes. Relationship types: semantic, temporal, causal, financial, policy, identity, learning, and (new) interest, sequence, creative-resonance, and hypothesis-status edges. Tenant-isolated. Neo4j retired by owner decision 2026-08-09. BigQuery mizoki-prod.unified is the analytical backbone. Vector search and document retrieval as projection options.
Inventory and fulfillment telemetry joins the Growth Decision Graph as typed nodes: (:SKU)-[:STOCK_STATE] (current level, reorder point, weeks-of-cover) and (:FulfillmentNode)-[:CAPACITY_STATE] (processing capacity, backlog, geographic reach). Three recommendation vectors — throttle bidding on stockouts, accelerate on overstock clearance, geo-shift on regional capacity constraints — are logged as ValidationPassport entries without dispatching to action runner adapters until the frontier climbs the autonomy ladder. Observe-only first (owner ruling 2026-08-19). Prevents the oldest waste in commerce advertising — paying to send customers to products you cannot ship.
Geo reservation engine selects representative control groups using Synthetic Control Methods (SCM) from owner-provided candidate pool (config/f4_geo_candidates.yaml). Schedules spend perturbations within declared caps, estimates realized lift, and injects ground-truth incremental lift as informative priors into Bayesian MMM — calibration becomes a system property, not a quarterly project. Because geo-holdouts alter media spend, candidate reservations must pass through L2 Human Approval flows. After two clean calibration cycles, reservations become eligible for bounded autonomy within declared spend caps.
Liquidity floors, credit availability, and debt covenants as hard constraints in VALIDATE and DECIDE. When cash reserves approach defined floors, DEL automatically reduces channel spend caps and vetoes budget expansions — naming the specific treasury constraint in the ValidationPassport. Treasury vetoes route to human review, never silently overridden. v1 (current): owner-declared constraints from config/treasury_constraints.yaml; v2: live treasury positions from the Capital division. Missing config = no constraint claimed (fail-closed, honest health). The enterprise sentence: your marketing system cannot spend money your treasury says you don't have.
| Cell | Function | Phase |
|---|---|---|
| 1 | Discovery & Ingestion | Sense |
| 2 | Stream Processing | Sense |
| 3 | Data Validation / KG Brain (GraphRAG serving, Firestore-backed) | Sense |
| 4 | Feature Engineering | Sense |
| 5 | Storage & Persistence | Sense |
| 6 | MOE Router | Reason |
| 7 | Causal Engine | Reason |
| 8 | Graph Analysis | Reason |
| 9 | Prediction Engine | Reason |
| 10 | Knowledge Synthesis | Reason |
| 11 | Decision Engine | Reason |
| 12 | Optimization Engine | Reason |
| 13 | Risk Analysis | Decide |
| 14 | Strategy Planning | Decide |
| 15 | Validation & Testing | Decide |
| 16 | KD Autotuner & Customer Segmentation | Decide |
| 17 | Supply Chain Optimization | Decide |
| 18 | MoE Router & CLV Prediction | Decide |
| 19 | System Monitoring | Act |
| 20 | Dynamic Pricing & Feedback/RLAIF | Act |
| 21 | Advanced ML | Act |
| 22 | NLP Engine | Act |
| 23 | Computer Vision | Learn |
| 24 | Observability Hub | Learn |
| 25 | Security & Compliance | Learn |
| 26 | Creative Suite / Causal Uplift Estimator (dual-service) | Meta / Learn |
| 27 | DR-Learner & DoWhy Refutation | Meta |
| 28 | A/B Testing (legacy — NOT an intent cell) | Meta |
| 29 | Meta Pixel Event Extraction | Meta |
| 30 | Time Series Analysis | Meta |
| 31 | Recommendation Engine / Google Ads GAQL | Meta |
| 32 | ROI Dashboard | Meta |
| Cell | Service | Function | Status |
|---|---|---|---|
| 33 | intent-signal-ingest | Micro-signal ingestion with consent gate | Partial |
| 34 | intent-scoring-api | Intent scoring, calibrated probabilities, explanation paths | Partial |
| 35 | intent-graph | Durable intent subgraph, DSAR/erasure, household labels | Partial |
| 36 | intent-causal | Caused-vs-anticipated ledger, refutation battery | Live |
| 37 | market-signal-ingest | Data Injector & External Intelligence Gateway | Partial |
| Cell | Service | Function | Status |
|---|---|---|---|
| 38 | cre-prospecting-core | Sense→Reason: roster/flyer intake, geocoding, entity resolution, scoring, matching, submarket intelligence | Live |
| 39 | cre-outreach-engine | Plan→Act→Learn: email authoring via Virtuoso, validation passport, DCP authorization, CRM sync, holdout/lift measurement | Live |
The first commercial instance of the Media Acquisition cell — a separate offering built on the full platform base. Positioning: the merchant-market instance of a certifiable autonomous media control system.
Independent Shopify merchants lose money to two structural failures: ad platforms grade their own homework (self-attribution inflates ROAS), and every tool optimizes revenue while merchants live on margin. Signal closes both: it measures what ad spend actually causes and optimizes Net Contribution Margin — what an order actually nets after everything it costs — under governance a founder can watch working.
| Tier | Profile | Deliverable | Autonomy |
|---|---|---|---|
| T1 Emerging | < 300 orders/mo | Value feeds, feed enrichment, cold-start seeding, pooled priors — no merchant-level incrementality claims | L0–L1 |
| T2 Growth | 300–3K orders/mo | + ghost-bid & cohort holdouts, always-on rotating holdout, NCM reallocation | L2–L3 |
| T3 Mid-market | 3K+ orders/mo | + geo-lift, lift-calibrated mini-MMM, cross-channel, covenant autonomy | L4–L5 per class |
Modern merchants run Advantage+ / Performance Max — granular control is gone. Signal owns the levers that remain:
OAuth app (MIZ OKI Commerce Link), HMAC-signed webhooks (orders/*, refunds/*, inventory_levels/*, fulfillments/*), bulk-operation backfill, Admin GraphQL sync. Pub/Sub delivery path provisioned (topic + DLQ + push subscription). OAuth OFF pending operator secrets. Single governed ingress — fans out to canonical ingestion, intent extender, and net-yield. ORACLE pixel collector edge (POST /pixel/collect) flag-off by default.
Downstream consumer: Cell 33 intent signals + outcomes. IAM-locked; former public webhook receiver retired 2026-08-12 (the single-ingress collapse). ORACLE /pixel/events door flag-off (Stage A capture). CI deploy path established.
NCM computation: NCM(C) = Σ [R - COGS - F - S - P - E[RL]] - AdSpend(C). Bundle-decomposed COGS, 3PL surcharges, gateway fees, expected return cost. Writeback OFF. Rows carry hashed customer keys only. Dispatch-only deploy.
Live production surface: causal-credit positioning, proof engine, field-note scenarios (composites, labeled), capability dossiers, dual roadmap previews, and the Signal Factory demo — raw connector events travel all seven SRPVDAL stages including one deliberate guardrail block. ORACLE pre-conversion perception page serving at /signal. Content QA gates enforced in CI.
Roster/flyer intake, geocoding, entity resolution, scoring, matching, submarket intelligence. Composes with the existing mizoki_cre underwriting module. Never touches a recipient. IAM-locked; operator remainder: Google Maps API key. Deployed 2026-08-17.
Email authoring via Virtuoso, validation passport, DCP authorization gate, draft deployment (auto_send: false permanent), CRM sync, follow-up scheduling, holdout/lift measurement. Split at the DECIDE boundary — never computes a match. IAM-locked; operator remainder: provider transports (Graph/Gmail/Pipedrive), scheduler SA.
Converts contracts, regulations, and internal rules into machine-checkable decision constraints. Mixture-of-Legal-Experts with IRAC reasoning. Demo engine only (fixtures, never production tenant data). Legal conclusions remain advisory-only.
Reasons over revenue, margin, cost, cash flow, CAC, LTV, iROAS, payback, and forecasts. Financial validation sits inside Validate — an action that lifts platform-reported ROAS but destroys margin is not auto-approved. Advisory-only; built, pre-benchmark.
Transforms uploaded files, reports, notes, research, competitive intelligence, and strategy documents into structured evidence, relationships, and reusable decision memory. Ownership of resulting decisions remains with the relevant operating domain.
Capital, Risk, and Estate divisions are proposed — no code exists in the fleet. CRE underwriting and asset-risk reasoning (Simulation Passport, mandatory baselines) are built and advisory-only. Binding valuation, engineering, environmental, and credit decisions remain with licensed human authorities.
| Level | Authority | Promotion Gate |
|---|---|---|
| L0 Observe | Read-only recommendations + reasoning paths | Install default |
| L1 Signal | Value feeds, audience syncs, feed enrichment; no spend changes | 14 days clean reconciliation |
| L2 Housekeep | Pause low-inventory/high-return SKU ads; rotate creative; exclusions | 1 purchase cycle at L1, zero violations |
| L3 Reallocate | Intra-platform budget, ±20%/day cumulative | Calibrated forecasts over 2 cycles; ≥ 1 holdout |
| L4 Cross-channel | Cross-platform reallocation; bid-strategy changes | ≥ 2 experiments; clean DEL history |
| L5 Autonomous | Full class authority within signed covenant | T3 volume + sustained miNCM accuracy + covenant |
Levels held per action class — L4 on budget while L2 on bids is normal. Every level: one-tap kill switch, immutable journal, weekly plain-language digest. Demotion is mechanical, never discretionary. Clamp widening is never autonomous; the promotion decision is always human.
Every governed decision produces a ValidationPassport — a complete, hashed execution trace assembled from the immutable learning ledger. Contents: (1) decision ID and tenant context, (2) input signal references (canonical event envelope IDs), (3) ranked causal hypotheses from Reason, (4) evaluated counterfactual plans including the mandatory no-action baseline, (5) DEL Score and individual gate results (identity/signature, policy alignment, context sufficiency, hard constraints), (6) assigned autonomy level and action class, (7) approval records with timestamp and principal, (8) dispatched action commands or veto reasons, (9) predicted outcomes at time of decision, (10) backfilled realized outcomes when observed. This is the J-05 Executive Defensibility product — one auditable trace reconciling conflicting channel reports.
Programmatically compares declared capability status (this whitepaper, the OFFERING_MAP, the cell registry) against live Cloud Run service registries, feature flags, and serving revisions. Prevents documentation-reality drift — the endpoint answers "is what the whitepaper says still true?" with measured evidence, not inference.
Six defined product surfaces — each a job with input telemetry, eligible decisions, constraints, required evidence, and a targeted outcome.
| Job | Name | Core Function |
|---|---|---|
| J-01 | Incrementality | Holdout-before-budget-shift; CATE + refutation evidence |
| J-02 | Waste Prevention | Cross-stack CPA-spike diagnosis; prohibition on automatic campaign blame |
| J-03 | Margin Control | Budget toward high-margin, in-stock, fulfillable SKUs; contribution economics |
| J-04 | Learning Stability | Protect platform learning phases from noisy feedback; staged changes with rollback |
| J-05 | Executive Defensibility | One auditable decision trace reconciling conflicting channel reports |
| J-06 | Team Leverage | Automated evidence assembly with the human authorization gate retained |
| Dimension | Mechanism | Function |
|---|---|---|
| State Machine | SRPVDAL (7-stage) | Every signal traverses Sense→Reason→Plan→Validate→Decide→Act→Learn before execution |
| Ingress Gateway | 15 native connectors | Normalizes raw data into 10-dimension Canonical Event Envelopes |
| Decision Evaluation | Four deterministic gates | Identity/Signature, Policy Alignment, Context Sufficiency, Hard Constraints |
| Decision Authority | Clipped-ReLU DEL | authority_c = min(cap_c, max(0, DEL_score − threshold_c)) |
| Autonomy Control | L0–L5 ladder | Observe-only → full autonomy; earned per (account × action class); promotion always human |
| Causal Inference | CATE meta-learners | S/T/X-Learner, DR-Learner/DML with automated refutation |
| Triangulation | Micro CATE + SCM GeoLift + Bayesian MMM | User-level causal ML × geographic experiments × aggregate portfolio models |
| Measurement | iROAS, never platform ROAS | The number the bank account reports, not the ad platform |
| Privacy | O-1 PRIVACY LOCK (schema-enforced) | Audio, keystroke, gaze, fine-geo, sensitive categories — blocked at validation, not toggled |
| Audit | Immutable ledger + ValidationPassport | Every decision traceable; prediction never grades itself |
To move from code completion to live pilot deployment, the following configuration parameters must be supplied by the enterprise owner. Once configured, the system executes the 90-Day Pilot in observe-only mode, generating verifiable ValidationPassports and lift metrics required to advance through the Three-Gate Evidence Maturity Framework.
| Input | Config Path | Purpose | Blocks |
|---|---|---|---|
| Pilot tenant selection | Operator decision | Initial brand account and agreed source connectors (Google Ads, Meta, Shopify, GA4, BigQuery) | All workstreams |
| Cost structure | config/net_yield_costs.yaml | COGS, payment fees, pick-pack-ship, baseline return rates per SKU | Net Yield (NCM) |
| Treasury constraints | config/treasury_constraints.yaml | Minimum liquidity floors, credit limits, covenant proximity curves | F5 Treasury Gating |
| Candidate geo pool | config/f4_geo_candidates.yaml | Permissible regions, spend perturbation caps, excluded control markets | F4 Geo Calibration |
| Creative asset access | Multimodal asset store permissions | Training creative component models (vision-language embeddings) | F1 Creative Unbundling |
Ten engineering workstreams operationalize the whitepaper, amendment, and Growth Control unified system into active builds. Each workstream maps to specific cells, services, and frontiers — with explicit dependency chains and build gates.
| WS | Name | Scope | Depends On | Status |
|---|---|---|---|---|
| 0 | Governance & Canon | Vocabulary ratification, Canon Status API, OFFERING_MAP v2.3 alignment | — | Partial |
| A | Intent Engine v2 Hardening | O-1 PRIVACY LOCK enforcement, ephemeral lifecycle purges (I-01–I-04), retention-bound tests | WS-0 | In Build |
| B | ValidationPassport Packaging | Immutable decision trace envelope (10 fields), J-05 product surface | WS-0 | Live |
| C | Net Yield Completion | Order economics tables, NCM compute, writeback fail-closed gates | Owner: cost config | In Build |
| D | F3 Supply-Chain Sync | Inventory graph nodes, 3 recommendation vectors, observe-only dispatch | WS-C | In Build |
| E | Decision Jobs & 90-Day Pilot | J-01–J-06 registry, pilot state machine (Observe→Validate→Recommend) | WS-B, WS-C | Partial |
| F | F4 Geo Calibration | Geo reservation engine, SCM lift estimation, Bayesian MMM prior loop | Owner: geo pool; WS-E | In Build |
| G | F1 Creative Unbundling | Multimodal extraction, DR-Learner component isolation, DEL-gated rotation | Owner: asset access; WS-A (I-03) | In Build |
| H | F2 LTV Regimes | Dynamic treatment regimes, outcome-horizon ledger, ≥2-quarter publish gate | WS-C, WS-F (2 cycles) | In Build |
| I | F5 Treasury Gating | Capital constraint integration, DEL spend tightening, breach routing | Owner: treasury config | In Build |
graph TD
WS0["WS-0 Governance & Canon"]
WSA["WS-A Intent Engine v2"]
WSB["WS-B ValidationPassport"]
WSC["WS-C Net Yield"]
WSD["WS-D F3 Supply-Chain"]
WSE["WS-E Decision Jobs & Pilot"]
WSF["WS-F F4 Geo Calibration"]
WSG["WS-G F1 Creative Unbundling"]
WSH["WS-H F2 LTV Regimes"]
WSI["WS-I F5 Treasury Gating"]
OC["Owner: Cost Config"]
OG["Owner: Geo Pool"]
OA["Owner: Asset Access"]
OT["Owner: Treasury Config"]
OP["Owner: Pilot Tenant"]
WS0 --> WSA
WS0 --> WSB
OC --> WSC
WSC --> WSD
WSB --> WSE
WSC --> WSE
WSE --> WSF
OG --> WSF
WSA --> WSG
OA --> WSG
WSC --> WSH
WSF --> WSH
OT --> WSI
OP --> WSE
style WS0 fill:#e8f4f8,stroke:#1A7FB5,color:#0B1A2E
style WSA fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSB fill:#e6f7ed,stroke:#1B8A50,color:#0B1A2E
style WSC fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSD fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSE fill:#fef3e2,stroke:#B87A14,color:#0B1A2E
style WSF fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSG fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSH fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style WSI fill:#f3e8ff,stroke:#7A5DC7,color:#0B1A2E
style OC fill:#fff8f0,stroke:#C4814A,color:#2C3038
style OG fill:#fff8f0,stroke:#C4814A,color:#2C3038
style OA fill:#fff8f0,stroke:#C4814A,color:#2C3038
style OT fill:#fff8f0,stroke:#C4814A,color:#2C3038
style OP fill:#fff8f0,stroke:#C4814A,color:#2C3038
The pilot is both the sales motion and the proof motion — the machine that closes a customer is the same machine that produces the verified numbers. Adopted as standard by owner ruling 2026-08-19.
| Phase | Days | Activity | Deliverable | Autonomy |
|---|---|---|---|---|
| Observe | 1–30 | Connect agreed stack (Google Ads, Meta, Shopify, GA4, BigQuery). Establish baseline data quality. Define target Decision Jobs. Zero changes to live execution. | Baseline data-quality report; connected-stack inventory | L0 |
| Validate | 31–60 | Synthetic-control geo experiments. CATE model calibration. Propensity verification. Margin reconciliation against customer's own books. | Calibrated model card; first verified lift findings; margin reconciliation | L0–L1 |
| Recommend | 61–90 | Fully contextualized decision proposals with complete audit trails. Routed through designated human approval. Every prediction graded against outcomes. | Decision proposals with ValidationPassports; pilot completion report | L1–L2 |
The alignment that makes the machine self-reinforcing: the pilot that closes a customer is the same machine that produces the verified numbers that flip the public Preview labels. The sales motion and the proof motion are one motion.
| Tier | Entry | Deliverables | Gate |
|---|---|---|---|
| Signal Factory | Free public demo | Live SRPVDAL walkthrough; truth-delta preview; system logic proof | Gate 1 |
| 90-Day Growth Control Pilot | Paid | Calibrated models, first verified lift findings, margin reconciliation, decision proposals with passports | Gate 2 |
| Signal Operations | Annual | Decision Jobs J-01–J-06 under chosen autonomy tier; standing F4 recalibration; weekly plain-language digest | Gate 2+ |
| Enterprise Growth Control | Annual | + F2 LTV regimes, F3 supply-chain sync, F5 treasury gating; Capital/Counsel/Risk division interlock | Gate 3 |