MIZ OKI 3.5 — Offering Map, Signals Intelligence Engine & External Knowledge Enrichment

Complete Canonical Edition v2.3 FINAL — with Implementation Plan

Version: 2.3 (2026-08-19) — Growth Control ratification edition (owner rulings 2026-08-19-A/-B) Changelog: - v2.3 correction (2026-09-13, owner-delegated ruling; register row 27): §B.6 F4 row IN BUILD → LIVE — pilot armed 2026-08-24; every reservation L2-approval-gated; bounded autonomy earned only after 2 clean cycles (0 complete). Machine copy contracts/mizoki_contracts/canon_status.py and generated docs/CANON_STATUS.md trued in the same commit. Tree-truth alignment only; no architectural direction changed. - v2.3 (2026-08-19, growth-control-completion run): register rows 22–24 — product vocabulary RATIFIED as official on every surface (Decision Control Plane, Decision Eligibility Layer/DEL Score, Growth Decision Graph, Intent Engine v2, ValidationPassport, High-Value Decision Jobs — supersedes row 3's external-copy restriction; canon rule V5 retired), Growth Frontiers advanced per amendment r3.5.2 (F3 IN BUILD observe-only; F1/F2/F4/F5 IN BUILD with per-frontier gates; Phases 8–9 collapsed into one build program), High-Value Decision Jobs J-01…J-06 + the 90-Day Growth Control Pilot adopted as the commercial standard. New Part B.6 carries the Growth Control layer with the amended §6 status table. Plans of record committed to docs/ (r3.5.1 whitepaper + Growth Control r2.0 + amendment r3.5.2 — the amendment governs where they differ; whitepaper now docs/MIZOKI_3.5_WHITEPAPER_r3.6_SEP2026.md (r3.6 SEP2026 folds r3.5.1 + r3.5.2, 2026-09-02)). Cell 37 identity restated per the registry (Data Injector & External Intelligence Gateway; generic injection door [IN BUILD — not started]). - v2.2.1 (2026-08-19, owner-directed override in-session): corrections register rows 18–21 applied in place — Firestore-backed KG language (Neo4j retired 2026-08-09; register row 15's WIRING condition satisfied affirmatively), deploy-note and hosted-environment staleness corrected, B.1 fleet line advanced to 39 registered cells (owner rulings 2026-08-11/2026-08-16), Phase-0 LII-merge item marked complete. Tree-truth alignment only; no architectural direction changed. - v2.2: Integrated the Signal Intelligence Division marketing capabilities documentation as new PART F (full product descriptions, ORACLE flagship, causal measurement, playbooks, glossary, staged rollout) — corrected before integration: cell numbering realigned to shipped reality (34/35/36; Cell 28 legacy untouched); "Decision Control Plane" removed as a product construct; TigerGraph/Firestore removed from the stack pending WIRING.md verification; LIVE/PARTIAL/PROPOSED labels applied (two-tower real-time path behind LII_REALTIME; DR-Learner, churn/expansion, CRM/offline/CTV as PROPOSED); vendor quotes paraphrased as market context. Corrections register rows 14–16 added. - v2.1: Merged addendum patches P1–P9 (third-party blueprint validation): D.0 per-action-class L5 certification model; D.6 L5 prerequisite systems; "negotiation proposes / deterministic policy authorizes"; ZK scope correction; Creators API supersedes PA-API in Strategy 2; Google Trends alpha strategy; Freebase/MID lineage note; horizon framing. Final-review fixes: plan aligned to build prompt v1.1 (Cell 37, KG-writer-only rule, EKG person-table prohibition, extraction path, orchestration, monitoring); erasure-cascade scope extended to new person-touching ingestion; inventory_level in the MarketSignal enum; PA-API grep added to standing rules. - v2.0: Truth-discipline corrections register (12 items); LIVE/PARTIAL/PROPOSED labeling throughout; external-KG strategies re-architected to available sources; L5/distillation vectors triaged to RESEARCH; five-phase plan.

Status: Canonical. Supersedes both original draft documents and the standalone v2.1 addendum. Repo placement: docs/OFFERING_MAP.md (optionally split Parts A–B / C–D into docs/EXTERNAL_KG_ENRICHMENT.md at merge — either form is acceptable). Deploy note (corrected 2026-08-19, register row 19): the marketing site deploys ONLY via human workflow_dispatch of deploy-homepage.yml with the typed APPROVED token + passing canon check (its push trigger was removed 2026-07-30; bot merges cannot ship it). Doc merges to main do dispatch the Deploy Router for matching service paths (src/shared/**, services/<x>/**) — every merge is a deploy decision for the paths it touches, but never the site. Ground truth: WIRING.md, miz-oki-platform-expert skill v3.0 (2026-07-31), ontology-kg-virtuoso skill. Companion artifact: CLAUDE_CODE_BUILD_PROMPT_EXTERNAL_KG_v1.1_FINAL.md (+ supplemental addendum-A instructions) — the execution vehicle for Phases 0–3.


PART A — TRUTH-DISCIPLINE CORRECTIONS REGISTER

The source drafts were directionally right but contained the recurring error class: plan-vintage vocabulary presented as shipped, unavailable data sources presented as ingestible, and proposed capabilities presented as current state. Corrections, in order of severity:

# Draft claim Correction Label
1 "Amazon Product Knowledge Graph (Amazon X / Catalog Graph)" with "co-purchase relationship graphs" as an ingestible public source No public Amazon product KG exists. Legitimate surfaces: SP-API Catalog Items (ASINs, browse-node taxonomy, classifications, variation relationships, sales ranks) and Product Type Definitions (JSON schemas) — seller/vendor-authorized per tenant, ToS-bound. Co-purchase ("frequently bought together") graphs are not extractable without scraping (ToS violation) — permanently out of scope; only stale academic datasets exist (license review required, Step 5 of intake contract). Corrected → Part C, Strategy 2
2 "Map public Google Knowledge Graph MID identifiers directly into Neo4j" Legacy KG Search API is deprecated. Supported path is Google Cloud Enterprise Knowledge Graph: the Entity Reconciliation API reads source BigQuery tables and writes stable MID columns back to BigQuery (legacy /m MIDs retained for backward compat; new Cloud MIDs c- prefixed; resultScore removed; name-field licensing property applies). A stronger fit than the draft proposed — it runs natively against mizoki-prod.unified. Corrected → Part C, Strategy 1
3 "Decision Control Plane" as a named product component checking autonomy tiers The enforcement reality is the VALIDATE + DECIDE gates on the autonomy ladder L0–L5, with promotion gates fixed at Brier ≤ 0.20, AUC ≥ 0.72, stable lift across ≥2 purchase cycles. "DCP" survives only as internal shorthand for the uplift_export_cohort gated activation path — never customer-facing, never a separate subsystem. Corrected throughout
4 Connector list "Google Ads, Meta, The Trade Desk, Klaviyo, Shopify" in SENSE Live mappers per Skill 17: Meta, Google Ads, SendGrid, OpenRTB (the draft omitted two of the four that exist). Shopify = PROPOSED → scheduled to PARTIAL in the current build. Klaviyo, TTD = PROPOSED. Corrected → Part B
5 "Counsel, Capital, Risk, Estate: interconnected decision cells running on the same governed loop" Counsel exists as the Counsel Room demo engine (demo_counsel.py, Mixture-of-Legal-Experts, IRAC) — demo fixtures, never production tenant data. Capital / Risk / Estate cells do not exist in the fleet. PARTIAL (Counsel demo) / PROPOSED (rest)
6 World models, Nash/Pareto consensus, federated ZK, self-evolving guardrails, CID/CoLE/ICD distillation presented as capabilities All are RESEARCH vectors. None built. Several conflicted with hard governance; reframed in Part D. RESEARCH
7 "Self-Evolving Guardrail Synthesis — dynamically contract or expand execution clamps" Expansion of clamps can never be autonomous. The governance deny-list, no-audio rule, and consent gate are schema-level hard gates — not tunable. Autonomy promotion gates are fixed policy requiring human approval. Reframed: autonomous contraction (defensive tightening) is permitted; any widening is a human-approval-tier proposal. "VIX_ad" is an invented metric — internal use only, labeled illustrative until validated. Corrected → Part D.4
8 "Triples exceeding confidence threshold are written to Neo4j Causal Memory" No side doors into Neo4j or BigQuery. External triples pass the full 20-step semantic intake contract; the entropy threshold is a quarantine-exit criterion only. External triples are imported/inferred assertions — never causal edges. Causal edges are minted exclusively by the Cell 36 → Cell 26 (X-Learner) → Cell 27 (DoWhy refutation) chain. Corrected → Part C, Strategy 4
9 Federated ZK cross-client learning as a near-term feature Intersects consent scopes, DPAs, and competitive confidentiality. RESEARCH only, gated behind formal privacy/legal review. Customer-facing mention requires preview framing. RESEARCH → Part D.3
10 Cell numbering ambiguity ("Cells 28/33/34" for ORACLE) Shipped reality (measured 2026-07-31): Cell 33 = intent-signal-ingest, Cell 34 = intent-scoring-api, Cell 35 = intent-graph, Cell 36 = intent-causal — all four live, IAM-locked (unauth /health 403), deploys dispatch-only. Cell 28 remains legacy, NOT repurposed. Shipped MCP surface is the eight intent_* tools; lii_* names are plan-vintage aliases never built. Corrected throughout
11 Global fallback claude-opus-4-8 Advanced to claude-opus-5 (Boss directive 2026-08-04). All LLM calls via virtuoso_call; fallback fires only after primary failure; alert on served_by != "primary". Corrected
12 "Anticipatory intent" phrasing drift Codified: "anticipatory intent with proof of causal lift" — never "mind-reading." Every score ships with confidence + explanation path, never a bare number. Standard
13 Third-party blueprint presents Capital/Risk/Estate as part of a "complete offering map" and treats research vectors as designed subsystems Labels unchanged: Counsel PARTIAL (Counsel Room demo), Capital/Risk/Estate PROPOSED; Part D items remain RESEARCH until built and benchmarked. Validated blueprint corrections adopted in Parts C–D (see changelog). Standard
14 Signal Intelligence marketing doc maps "Cell 28 = Intent Scoring API, Cell 34 = intent graph, Cell 35 = incrementality" Plan-vintage numbering. Shipped reality per row 10: Cell 33 = intent-signal-ingest, Cell 34 = intent-scoring-api, Cell 35 = intent-graph, Cell 36 = intent-causal; Cell 28 remains legacy, never repurposed. All Part F references realigned. Corrected → Part F
15 Signal Intelligence doc lists Firestore and "Neo4j / TigerGraph" in the stack Canonical stack: BigQuery unified, Neo4j, Cloud Run (us-central1), FastAPI, React/TypeScript/MUI (D3/Cytoscape for graph viz). TigerGraph is not in ground truth and is removed; Firestore removed pending verification against WIRING.md — reinstate only if WIRING.md confirms. Corrected → Part F
16 Signal Intelligence doc presents two-tower/Vertex real-time retrieval, DR-Learner, churn/expansion propensity, and CRM/offline/CTV ingestion as current capabilities Labels applied: two-tower + Vertex Vector Search real-time path is PARTIAL (behind feature flag LII_REALTIME); DR-Learner PROPOSED (Cell 26 ships X-Learner; Cell 27 ships DoWhy refutation); churn/expansion propensity PROPOSED; CRM, offline, and CTV ingestion PROPOSED (live mappers: Meta, Google Ads, SendGrid, OpenRTB; Shopify building to PARTIAL). External vendor figures (branded-search iROAS ~0.27x, reported-vs-measured ROAS gaps ~1.5–3x, buyer-journey supplier-meeting share ~17%) are vendor-sourced market context, never Mizoki results. Corrected → Part F
17 Part C agent-enhancement 1 registers the brand-search holdout via "the Cell 36 experiment registry (POST /api/v1/causal/holdout)" That route was never built (measured 2026-08-11; re-confirmed 2026-08-18). The live design registry is measurement-rails POST /v1/rails/designs — registration; Cell 36's real surface is holdouts:assign (assignment, not registration). experiments/brand_search_cannibalization/register.py targets the real route and refuses without --mde, out-of-band holdout, or post-impression registration. Body text corrected in place 2026-08-18. Corrected → Part C
18 v2.2 stack/graph lines say "Neo4j" (B.1 diagram, B.4, B.5 cascade wording, Part C diagram, F.2 stack) The tree retired Neo4j on 2026-08-09 (owner decision; the neo4j-uri host is NXDOMAIN by choice); the knowledge and intent graphs serve from the Firestore-backed store (cell03 repository factory; cell35 durable store). Row 15's "Firestore — reinstate only if WIRING.md confirms" is satisfied affirmatively. Body corrected in place 2026-08-19 (owner-directed override). Corrected → B/C/F
19 "Any push to main triggers deploy-homepage.yml" (header note, Part E standing rules, end-note); "repo unreachable from hosted environments" Stale since 2026-07-30: the site ships only via human dispatch + typed APPROVED + canon check (GOVERNANCE 2.1); bot merges cannot ship it. Cloud sessions operate the repo daily through the auto-merge lanes. Corrected in place 2026-08-19. Corrected → header/Part E
20 B.1 fleet line: "32-cell fleet … plus Cell 37 (scheduled in the current build)" 39 registered cells (owner rulings 2026-08-11/2026-08-16; docs/architecture/CELL_REGISTRY.md is the number authority): Cell 37 deployed 2026-08-11 (partially operational; operator remainder open) and Cells 38–39 CRE Prospecting deployed-ci 2026-08-17. Corrected in place 2026-08-19. Corrected → B.1
21 Part E Phase 0 item 2: "Complete the pending LII merge first" Long complete (LII branches merged ~2026-08-10; DSAR live-verified). Marked done in place 2026-08-19. Corrected → Part E
22 Row 3 removed "Decision Control Plane" as a product construct; canon rule V5 restricted it in external copy SUPERSEDED by owner ruling 2026-08-19-A (Growth Control r2.0 §7.1): Decision Control Plane, Decision Eligibility Layer/DEL Score, Growth Decision Graph, Intent Engine v2, ValidationPassport, and High-Value Decision Jobs are RATIFIED official vocabulary on every surface. Canon rule V5 retired (scripts/mizoki_canon.py, RATIFIED_VOCABULARY added); rule-03 clause updated. Ratification never upgrades a claim — capability labels and TRUTH.md figure labels still govern. Row 3's enforcement-reality description (VALIDATE+DECIDE gates on the L0–L5 ladder) remains architecturally true; only the naming restriction is lifted. Ratified → B.6
23 v2.2 carried no Growth Frontier lanes; F-family capabilities existed only in board drafts Growth Control r2.0 + amendment r3.5.2 committed as plans of record (r3.6 SEP2026 folds r3.5.1 + r3.5.2, 2026-09-02). F3 IN BUILD observe-only (ruling 2026-08-19-A); F1/F2/F4/F5 IN BUILD (ruling 2026-08-19-B) with per-frontier gates — F4 reservations L2-approval-gated until 2 clean cycles; F1 estimates provisional until pilot creative volume; F2 findings gated on ≥2 observed quarters (code guard); F5 v1 config-declared floors, fail-closed absent config. Machinery ships; authority and findings are earned. Adopted → B.6
24 High-Value Decision Jobs and the 90-Day Pilot were unregistered product surfaces J-01…J-06 registered (config/decision_jobs.yaml + registry module + internal GET /api/v1/jobs); the 90-Day Growth Control Pilot (Observe→Validate→Recommend, Three-Gate Evidence Maturity Framework approved through Gate 3) is the standard commercial onboarding (docs/pilot/PLAYBOOK.md, r2.0 §4.2 verbatim). The pilot that closes a customer is the machine that produces the verified numbers that flip Preview labels. Adopted → B.6
25 Intent-family footnote called Cell 37 "(in build)" bare, contradicting B.1's deployed row Tree-truth alignment in place 2026-08-21 (owner final-override wave, STATE_RESUME follow-on): the footnote now reads "deployed 2026-08-11, partially operational; the external-intelligence covariate-supply scope stays [IN BUILD]" — matching B.1 and the v2.3 header restatement. No architectural direction changed. Corrected → intent-family footnote
26 v2.3 header and the registry note said Cell 37's "generic injection door [IN BUILD — not started]" Tree-truth 2026-08-21 (RUN PACK v2.1, Cell-37 completion under OWNER_APPROVALS_2026-08-20): the door is BUILT — market-scope intake /inject/batch+/inject/gcs+/inject/synthetic landed 2026-08-19 (synthetic quarantined to the training plane; reprocess now carries an explicit plane filter), and the canonical half /inject/canonical/batch+/inject/canonical/gcs landed 2026-08-21: backfill/partner-file events forward with provenance labels to service-canonical-ingestion's single governed gate (no second gate), synthetic categorically refused, person-identifier payloads refused without retention (Cell 33 keeps the person plane), caller-supplied available_to_model_at refused (bitemporal law). DARK by default — 503 until the operator sets CANONICAL_INGESTION_URL + grants the caller-SA allowlist. Pins: tests/market_signal/test_injection_door.py. docs/architecture/CELL_REGISTRY.md's note trued in the same commit; the v2.3 changelog text stands as dated history. Corrected → CELL_REGISTRY note
27 §B.6 (v2.3, 2026-08-19) and its machine copy still read "F4 auto micro-geo calibration — IN BUILD" after the 2026-08-24 go-live, while AGENTS.md Article 9.1, rule 05 A.10 (owner-approved 2026-09-01), README, the Feature Catalog and the marketing whitepaper r2.0 all said LIVE Owner-delegated ruling 2026-09-13, decided on precedence and tree truth: AGENTS.md (constitution set) outranks this map, and the tree ships F4_CALIBRATION=true (deploy-growth-scheduler.yml:145), the first cycle ran (growth-scheduler-first-cycle-v762t, status=scheduled, F4_GO_LIVE_2026-08-24.md) and its reservation sits in the owner's L2 queue (OPEN_ITEMS.md P-1). LIVE labels the machinery; authority is earned — per-action L2 approval, bounded autonomy only after 2 clean cycles (0 complete), actuator deliberately unregistered (P-2), unconfigured tenant vault = lane dark. PARTIAL was considered and rejected (the engine acts — it minted a governed reservation — and the machine canon spec says LIVE); IN BUILD rejected (contradicts the constitution set, reads an armed lane as undeployed, and hides the owner's pending L2 decision). Whitepaper r3.6 Appendix A keeps the 2026-08-19-B text verbatim as the dated ruling of record; this table carries the amended status. Corrected in place 2026-09-13. Corrected → B.6
28 F.4 (and Part F throughout) names the flagship "ORACLE" with no rule for which name customer-facing copy carries; the site landing says "Causal Growth Control" and the ratified vocabulary says "Intent Engine v2" — three names, one capability Owner ruling 2026-09-22 (OPEN_ITEMS OR-3, Option 1 — three tiers): Causal Growth Control = the offer a customer buys; Intent Engine v2 = the capability's name on every surface, engineering and external (already ratified, ruling 2026-08-19-A); ORACLE = the internal program/lane codename, retained in this map, the registry, reports and history, never introduced in new customer copy. Decision material: docs/reports/ORACLE_DOC_PUSH_2026-09-15.md §12.2. Customer-facing reconciliation (/signal copy at the next owner-dispatched homepage build, with the served-site content gate widened first) stays owed on the OR-3 row; rule 03 line owed with it Ruled — engineering record kept; external copy reconciliation pending (labels unchanged: IN BUILD / PARTIAL)

PART B — THE OFFERING MAP

B.1 Positioning

"Other tools optimize the number your ad platform reports. Mizoki optimizes the number your bank account reports."

MIZ OKI 3.5 is an autonomous, governed AI decision system for enterprise performance marketing and media acquisition. It replaces correlation-based dashboard analytics with a seven-phase governed control loop (SRPVDAL) that measures true causal incrementality — classifying every conversion as caused or merely anticipated — and drives budget with iROAS, not platform ROAS. Long-horizon positioning: a certifiable autonomous media control system reaching bounded L5 authority progressively, action class by action class (Part D.0) — this positioning carries preview framing until the first class is certified ≥L2 in production.

┌─────────────────────────────────────────────────────────────────────────┐
│                          MIZ OKI 3.5 PLATFORM                           │
├─────────────────────────────────────────────────────────────────────────┤
│  DOMAINS                                                                │
│   Signal (Causal Acquisition)  LIVE      Marketing (Media Buying) LIVE  │
│   Counsel (Legal MoE)          PARTIAL — demo engine                    │
│   Capital · Risk · Estate      PROPOSED                                 │
├─────────────────────────────────────────────────────────────────────────┤
│  CAPABILITY DISCIPLINES                                                 │
│   Threshold · Budget · Creative · Audience Intelligence                 │
│   Measurement Foundations (identity, envelopes, ledger)                 │
├─────────────────────────────────────────────────────────────────────────┤
│  SHARED CAUSAL KNOWLEDGE GRAPH                                          │
│   BigQuery `mizoki-prod.unified` ── Firestore-backed knowledge+intent KG │
│   Canonical JourneyEvent + MarketSignal envelopes                       │
│   unified.causal_credit_ledger (immutable)                              │
├─────────────────────────────────────────────────────────────────────────┤
│  GOVERNED SEVEN-PHASE SRPVDAL LOOP                                      │
│   Sense → Reason → Plan → Validate → Decide → Act → Learn               │
│   Autonomy ladder L0–L5 · Signal ships at L0/L1                         │
│   L5 = certified per (account × action class), never a global switch    │
└─────────────────────────────────────────────────────────────────────────┘

Fleet: 39 registered cells (owner rulings 2026-08-11/2026-08-16; docs/architecture/CELL_REGISTRY.md is the number authority): the 32-cell production fleet (Cells 1–32 + 3-1 KG-viz bridge) of independent FastAPI services on Cloud Run (us-central1), plus the ORACLE/intent family Cells 33–36 (LIVE, IAM-locked), plus Cell 37 market-signal-ingest (deployed 2026-08-11, partially operational — operator remainder open), plus Cells 38–39 CRE Prospecting (cre-prospecting-core / cre-outreach-engine, deployed-ci 2026-08-17). Critical-path cells (3, 24, 28) hold min-instances ≥ 1. Performance targets: p50 < 50 ms, p95 < 100 ms, 99.9% availability, 1000+ RPS peak.

B.2 Capability disciplines

Discipline Core function Mechanism Status
Threshold Intelligence Find activation points in platform delivery algorithms Structured discovery + spend concentration LIVE (Signal)
Budget Intelligence Cross-channel/region reallocation Rectified-linear uplift gate (uplift > 5%, confidence > 0.70 — the Signal ReLU gate) driven by iROAS from the credit ledger LIVE (recommend, L0/L1)
Creative Intelligence Prevent fatigue decay Statistical decline forecasting + rotation strategies PARTIAL
Audience Intelligence Uplift-quadrant targeting: budget on persuadables; first-class suppression of sure-things and sleeping dogs X-Learner heterogeneous effects (Cell 26) LIVE (measurement) / PARTIAL (activation)
Measurement Foundations Unified identity + single audit trail Server-side ingestion gates, unified time windows, immutable ledger LIVE

B.3 The SRPVDAL loop (canonical seven phases — never shortened)

  1. Sense — Raw payloads from live connectors (Meta, Google Ads, SendGrid, OpenRTB — LIVE; Shopify — building to PARTIAL; Klaviyo, TTD — PROPOSED) normalize through MAPPERS[source](raw) → schema-valid, provenance-stamped JourneyEvents (schemas/journey-event.json), upserted via ingest_gate (MERGE on event_id, CAS on source_payload_hash; duplicates are success). Market-level context (SERP, trends, sales ranks, inventory) rides the sibling MarketSignal envelope (Part C, Strategy 4) through its own gate into unified.market_signals — never mixed into JourneyEvents. Cell 33 micro-signals (dwell, scroll velocity, partial watch) carry a behavioral_signal block + consent_scope behind a hard consent gate — no consent, no persistence; audio signal types rejected at Pydantic validation.
  2. Reason — Cause-and-effect evaluation over the temporal-causal graph (e.g., creative fatigue vs. site-latency spikes vs. pixel drops).
  3. Plan — Intervention candidates: bid adjustments, budget reallocations, pauses, experiment designs. (Research direction: world-model candidate pre-screening and Pareto proposal generation live here — Part D.1/D.2 — as proposal generators only.)
  4. Validate — Statistical/causal/policy/creepiness gates: guardrail clamps (budget ±20%, bid ±30% — the Signal guardrail set), automated refutations (placebo, random-common-cause, data-subset via DoWhy in Cell 27), consent-scope verification, sensitive-topic deny-list (health, sexuality, religion, financial distress, minors — schema-level, never predicted/stored/surfaced). Authorization is exclusively deterministic policy — no negotiated or model-generated consensus ever self-authorizes.
  5. Decide — Execution-authority check against the autonomy ladder L0 (Observe) → L5 (Autonomous), evaluated per action class (D.0). Signal ships at L0/L1. Promotion only at Brier ≤ 0.20, AUC ≥ 0.72, stable lift across ≥2 purchase cycles on that class's decision stream; spend authority earned over ≥2 purchase cycles; promotion decision human.
  6. Act — Authorized adjustments against destination APIs; ACT cells consult GET /api/v1/causal/assignment before serving (holdout arms honored at serve time). Execution reliability contract (D.6): idempotent operations, retry with backoff, post-write reconciliation.
  7. Learn — Verified outcomes to unified.causal_credit_ledger; predictions closed via realized/realized_at in unified.intent_predictions; model health (Brier/AUC/PSI) monitored; auto-demotion to observe-only at Brier > 0.20.

B.4 The knowledge graph as shared causal memory

BigQuery unified is the analytical backbone; the knowledge graph and the intent graph (Cell 35) are Firestore-backed (Neo4j retired 2026-08-09 — register row 18). Canonical intent-graph schema (notation):

(:Customer)-[:SHOWED_INTEREST {weight, last_ts, decay}]->(:Topic)
(:Topic)-[:PRECEDES {lift, support, confidence}]->(:Topic)     // co-occurrence crystal ball
(:Customer)-[:MEMBER_OF {match_type: deterministic|probabilistic, confidence}]->(:Household)

Why the KG is load-bearing:

Two structural rules (non-negotiable): 1. Graph relationships never establish causality by existing. A PRECEDES or any imported edge is evidence topology; causal status is conferred only by the registered-holdout → X-Learner → DoWhy chain, recorded in the ledger. 2. Deterministic identity for all causal measurement. Probabilistic household edges are recall-only and excluded from all causal math (tested).

All graph writes route through the KG writer path (Cell 3 writes / Cell 24 updates). No pipeline, cell, or script writes the canonical graph directly.

B.5 The competitive moat (prominent in all documentation)

The governance and privacy layer is the strongest differentiator vs. platform self-attribution and correlation-only intent vendors (Bombora/6sense):

  1. Consent gate — architectural, precedes persistence.
  2. No-audio rule — enforced at schema validation, not operator settings.
  3. Creepiness deny-list — health, sexuality, religion, financial distress, minors: never predicted, stored, or surfaced.
  4. GDPR erasure cascade — GET/DELETE /api/v1/intent/subject/{id} cascades BigQuery + the graph store + vector index. Scope rule: every new ingestion path carrying person-level data (e.g., the Shopify connector's JourneyEvents) is added to the cascade's coverage map before it ships; market-level tables (unified.market_signals) are asserted person-data-free at validation and therefore outside cascade scope by construction.
  5. Data minimization at the boundary — person-level or customer data is never sent to third-party enrichment or reconciliation services (Enterprise KG included); entity-spine scope is organizations, brands, products, campaigns only.
  6. Proof of causal lift — holdout-before-activation is mandatory and non-negotiable; refutation failure means the estimate is flagged, never shipped; CIs always, point estimates never.

B.6 Growth Control layer — ratified vocabulary, Decision Jobs, frontier gating (v2.3)

Plans of record: docs/MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md + docs/MIZOKI_3.5_WHITEPAPER_r3.6_SEP2026.md (r3.6 SEP2026 folds r3.5.1 + r3.5.2, 2026-09-02) — the r3.5.2 ruling, Amendment 2 and consistency notes are carried verbatim in its Appendix A and govern the Growth Control document §5/§6 where they differ; the r3.5.x files are preserved byte-verbatim under docs/whitepapers/archive/. The live Cell Registry remains ground truth over both.

Ratified vocabulary (owner ruling 2026-08-19-A — official on every surface): Decision Control Plane (service-decision-control-plane) · Decision Eligibility Layer / DEL Score (the policy-engine evaluation: DEL vs the 80.0 platform floor) · Growth Decision Graph (the tenant-scoped decision substrate over the Firestore-backed KG: Campaign→LandingPage→SKU→Margin→Policy→Action→Incremental Outcome, plus evidence/operating context and Decision Memory) · Intent Engine v2 (modules I-01 PassiveAttentionSequence · I-02 SessionOutcomeForecast · I-03 CreativeSemanticProfile · I-04 IntentHypothesis · I-05 ValidationPassport — the code homes are the shipped ORACLE pre-conversion lanes; retention bounds are code, not prose) · ValidationPassport (as product vocabulary: the assembled per-decision governance trace packaging the eight decision objects; as a contract object: mizoki_contracts.ValidationPassport, object #4 — the package is a read-model, never a ninth object) · High-Value Decision Jobs (J-01…J-06). Ratification never upgrades a claim.

High-Value Decision Jobs (the product surfaces; registry config/decision_jobs.yaml): J-01 Incrementality · J-02 Waste Prevention (the SIG-042 narrative — composite/illustrative) · J-03 Margin Control (contribution economics + F3 triggers) · J-04 Learning Stability · J-05 Executive Defensibility (the ValidationPassport package) · J-06 Team Leverage. Each row carries input signal, eligible decisions, governing constraints, required evidence class, outcome metric, dossier URL, and current status.

The 90-Day Growth Control Pilot (commercial standard, ruling 2026-08-19-A): Days 1–30 Observe → 31–60 Validate → 61–90 Recommend, riding the Three-Gate Evidence Maturity Framework (approved through Gate 3). Playbook: docs/pilot/PLAYBOOK.md (r2.0 §4.2 verbatim). The pilot report is the artifact that produces verified numbers; Preview labels flip only on those.

Deployment state (amended §6 — single status source; contradicting it anywhere is a defect):

Capability Status
SRPVDAL state machine, Decision Control Plane, DEL scoring, autonomy ladder, audit ledger LIVE
Connector gateway & canonical envelope LIVE
Signal public surface, capability dossiers, Signal Factory demo (Gate 1) LIVE
Causal proof core (meta-learners, refutation, triangulation) PARTIAL — serving lanes per registry
ORACLE intent cells 33–36; Growth Decision Graph intent edges PARTIAL — observe-only / shadow
Intent Engine v2 modules I-01…I-05 IN BUILD — shadow, flags off, retention bounds as code
Net Yield lane (order economics, cohorts, writeback dry-run) IN BUILD — writeback off until verified pilot
Measurement rails writeback PARTIAL — machinery in production code; MEASUREMENT_WRITEBACK stays OFF (ast-pinned fail-if-flipped)
F3 supply-chain / inventory sync IN BUILD — observe-only (ruling 2026-08-19-A)
F4 auto micro-geo calibration LIVE — pilot armed 2026-08-24 (mycocoons); every reservation L2-approval-gated; bounded autonomy only after 2 clean cycles (0 complete — first reservation awaits owner L2, OPEN_ITEMS P-1; actuator deliberately unregistered, P-2); unconfigured tenant vault = lane dark; ruling 2026-09-13 (owner-delegated) supersedes the 2026-08-19-B IN BUILD label
F1 creative unbundling IN BUILD — estimates provisional until pilot creative volume (ruling 2026-08-19-B)
F2 multi-quarter LTV regimes IN BUILD — findings gated on ≥ 2 observed quarters, guard in code (ruling 2026-08-19-B)
F5 treasury-gated spend governance IN BUILD — v1 config-declared floors, fail-closed; v2 on live treasury feed (ruling 2026-08-19-B)
90-Day Pilot & packaging ladder ADOPTED — commercial standard (ruling 2026-08-19-A)

Frontier gating notes (machinery ships; authority and findings are earned): F4 is spend-affecting by nature and therefore CANNOT be observe-only — its gate is per-action human approval through the L2 flow, with bounded-autonomy eligibility only after two clean calibration cycles, and the eligibility flip itself is a logged owner-approved config change. F1's generated-creative deployment retains human approval always. F2 emits data_insufficient — never an extrapolated finding — below two observed quarters per cohort. F5 claims NO constraint when config/treasury_constraints.yaml is absent or invalid (health reports not_configured); breach = veto + human routing, with the constraint named in the passport. Standing constants unchanged: O-1 PRIVACY LOCK; consent fail-closed; sensitive-category deny-list at ingest AND hypothesis creation; probabilistic identities excluded from causal math; prediction never grades itself (activation requires a registered holdout); Preview labels flip only on verified pilot numbers; MEASUREMENT_WRITEBACK and NET_YIELD_WRITEBACK stay OFF, enforced by fail-if-flipped tests. Generated status surface: docs/CANON_STATUS.md + internal GET /api/v1/status/canon (declared status vs code-level flag truth; drift is a CI warning).


PART C — EXTERNAL KNOWLEDGE ENRICHMENT (VALIDATED ARCHITECTURE)

External public knowledge extends SENSE and REASON — but every external source passes the 20-step semantic intake contract (registration → sensitivity/licensing review → profiling → ontology mapping → entity resolution → validation → quarantine → gated ingestion → audit → retrieval evaluation). No side doors. External assertions carry provenance type imported or inferred — never observed, never causal.

              PUBLIC / LICENSED KNOWLEDGE SOURCES
 ┌────────────────────┬─────────────────────┬──────────────────────┐
 │ Google Cloud       │ Amazon SP-API       │ Wikidata / Schema.org│
 │ Enterprise KG      │ Catalog surfaces    │ (CC0 open graph)     │
 │ (BQ-native ER→MID) │ (per-tenant auth)   │                      │
 └─────────┬──────────┴─────────┬───────────┴──────────┬───────────┘
           ▼                    ▼                      ▼
 ┌──────────────────────────────────────────────────────────────────┐
 │        SEMANTIC INTAKE LAYER (20-step contract, ontology/)       │
 │  registration · licensing · profiling · mapping · ER · validate  │
 │  quarantine · ingest gates · provenance(imported|inferred) · audit│
 └──────────────────────────────┬───────────────────────────────────┘
                                ▼
 ┌──────────────────────────────────────────────────────────────────┐
 │   MIZOKI TEMPORAL-CAUSAL GRAPH (Firestore KG + mizoki-prod.unified) │
 │  :ExternalEntity —[:SAME_AS {confidence, source, mid, qid}]→ int.│
 │  Brand entities · Market intent nodes · Product taxonomy         │
 │  (writes via Cell 3/24 writer path; causal edges ONLY from       │
 │   Cells 36→26→27 validation chain)                               │
 └──────────────────────────────────────────────────────────────────┘

Strategy 1 — Google Cloud Enterprise Knowledge Graph — HIGHEST LEVERAGE, BUILD FIRST

The legacy public KG Search API is deprecated. The supported product is Enterprise Knowledge Graph on Google Cloud, whose Entity Reconciliation API is BigQuery-native: it reads up to 10 source BigQuery tables mapped to a common schema, performs knowledge extraction into RDF triples, clusters entities at Google scale, and writes the linking result back to BigQuery as a stable MID column. Legacy /m MIDs remain in entity identifiers for backward compatibility; new Cloud MIDs use a c- prefix; resultScore was removed from lookup responses; the name field carries a license-requirement property that must pass Step 5 (license review) before any UI display.

Historical note for identifier hygiene: legacy /m MIDs are Freebase-era identifiers (Freebase retired 2016; entity data migrated toward Wikidata) preserved in Google's KG for backward compatibility — treat /m and c- MIDs as equivalent join keys, and prefer Wikidata Q-ids as the neutral spine where both exist.

Why this beats hand-mapping a public graph: we run Google's reconciliation engine directly over mizoki-prod.unified candidate tables — organizations, brands, products, campaigns only; person/customer/household tables are forbidden by denylist and tripwire-tested — land MIDs as golden-cluster identifiers, then hydrate selected entities via KG lookup (schema.org-typed JSON-LD) into :ExternalEntity nodes with SAME_AS {confidence, source, external_id, mid?, qid?, valid_from, valid_to} edges, submitted through the Cell 3/24 writer path behind feature flag EXTERNAL_ENTITY_SPINE (default off until OCP approval).

Agent enhancements: - Audience Intelligence groups touchpoints around MID/Q-id-anchored entity topics instead of unstructured keywords (observe-only additive field first). - Entity resolution uplift — MID clusters as an additional ER signal in golden-record construction (survivorship unchanged; merges reversible; never merge on name similarity alone). - B2B account intelligence — organization MIDs join cleanly with Wikidata (Strategy 3).

Status: PROPOSED → target LIVE in Phase 1. Paid Cloud service — budget line approved before enablement; cost guard (--confirm-cost) on the reconciliation job.

Strategy 2 — Amazon commerce surfaces (corrected)

Available, legitimately: - SP-API Catalog Items — ASIN-level attributes, browse-node taxonomy and classifications, variation relationships (variation families), sales ranks per marketplace. Seller/vendor authorization → per-tenant connector, ToS-bound, rate-limited. Primary path — unaffected by the PA-API deprecation. - SP-API Product Type Definitions — JSON-schema definitions of catalog product types → direct input to ontology mapping (Step 9) for the commerce/product ontology. - Amazon Creators API (successor to the deprecated PA-API 5, which now returns 403 to legacy callers; endpoint retired mid-2026) — affiliate/creator catalog surface with eligibility gating (≥10 qualifying referred sales in 30 days; primary-account-owner registration; new LWA/Cognito-versioned auth). Weak fit for Mizoki's seller/vendor model — optional per-tenant surface for clients who are also Amazon Associates. Status: PROPOSED, low priority. Any legacy PA-API reference anywhere in repo/docs is a defect (standing grep, Part E).

Removed from roadmap permanently: co-purchase relationship graphs. Not exposed by any API; extraction implies scraping. Academic datasets are stale and license-restricted — offline RESEARCH benchmarking only, never production claims.

Agent enhancements (rescoped honestly): - Creative Intelligence — ad variations targeting variation-family complements (verified relationships), not assumed co-purchases. PROPOSED. - Threshold Intelligence — sales-rank trajectories per browse node as demand covariates: raise thresholds on rank-accelerating SKUs, pause promotion on inventory-constrained SKUs (inventory via the Shopify connector's inventory_level MarketSignals). PROPOSED, depends on Shopify connector. - Ontology — browse-node taxonomy + product-type schemas imported as a mapped external taxonomy (SKOS-style) via OCP. PROPOSED.

Strategy 3 — Wikidata & Schema.org (genuinely open — CC0)

The strongest open canonical-identity foundation among all proposed sources: CC0 structured data with full programmatic access (SPARQL, dumps). Schema.org types already underpin the Google KG JSON-LD responses (natural join key).

Agent enhancements: - Corporate parentage & brand relationships — resolve B2B accounts/domains to Wikidata entities (P127 owned-by, P749 parent-organization, P355 subsidiaries) → reconstruct ownership structures. Audience Intelligence can suppress non-persuadable subsidiaries or unify related corporate accounts. PROPOSED. - Entity spine — Wikidata Q-id + Google MID + internal golden-record id as a triple-keyed SAME_AS cluster with per-edge confidence, fully provenance-stamped; Q-id preferred as the neutral spine. PROPOSED. - Governance: external ownership edges are imported assertions with bitemporal validity; contradictions between Wikidata and Google KG are preserved, scored, and marked — never silently resolved.

Strategy 4 — Search & market signals (the MarketSignal envelope)

Sourcing rule: SERP features, trend trajectories, and rank data come from licensed API providers or official surfaces only (Step 5 license review). No scraping; scraper-based pseudo-APIs (pytrends-class, archived/unmaintained) are prohibited — ToS exposure plus malformed/zero-filled series would poison invariance training (D.5).

Trends specifics: the official Google Trends API is an application-gated alpha (limited testers). Action: submit the alpha application for mizoki-prod immediately (free to approved testers). Its consistently scaled interest data (1800-day history, daily→yearly aggregation, geo restriction) is materially better than per-request 0–100 indices for trend_index signals — when access clears it becomes the preferred adapter behind the vendor-swappable SerpProviderAdapter. Until then, the licensed provider is the bridge.

Schema (shipped by the current build): market-level signals are not JourneyEvents. The sibling MarketSignal envelope ($id mizoki/schema/market-signal.json; signal_type enum v1: serp_position, serp_feature, trend_index, sales_rank, share_of_voice, inventory_level; versioned SERP-feature enum — upstream features get deprecated, e.g., FAQ rich results in May 2026) lands in unified.market_signals through its own mapper family (MARKET_MAPPERS) and gate, served by Cell 37 market-signal-ingest with quarantine + reprocess, SERP response caching, daily cost caps, and Cloud Scheduler-driven pollers. Validation rejects any payload containing person-level identifiers — consent_scope: "market" is asserted, not assumed. All time fields UTC; all joins use the unified time-window convention.

LLM structured-extraction path: unstructured inputs (SERP text, licensed feed prose) are structured via virtuoso_call(Role.DATA_CAUSAL, ..., response_format=market_signal.gemini_response_format()) — and the model's output is treated as untrusted input: identical deterministic validation before the gate; failures quarantine with reason llm_extraction_invalid; assertion_type: inferred + registry model_version stamped; reasoning summaries persisted to mizoki-prod.mii.reasoning_traces; instructions embedded in fetched content are data, never commands; served_by != "primary" alerts.

Agent enhancements: 1. Brand-search cannibalization measurement — flagship, LIVE-able now. Register a paid-brand-search holdout (geo or ghost-bid) via the live design registry (measurement-rails POST /v1/rails/designs — the plan-vintage POST /api/v1/causal/holdout on Cell 36 was never built, corrections register row 17; experiments/brand_search_cannibalization/register.py targets the real route; holdout 10–20%, MDE declared up front, registered before first impression), with organic SERP position and Knowledge-Panel presence as covariates from market_signals (deterministic identities only; probabilistic household matches excluded by explicit predicate, tested). The credit ledger separates cannibalized organic traffic from net-new incremental conversions. Expect iROAS ≪ platform ROAS on brand search — that's the product working. Status: PARTIAL (experiment machinery LIVE; covariate feed in build). 2. Anticipatory demand — trend trajectories feed predictive interest profiles; Budget Intelligence pre-positions bids before volume peaks — only with a registered holdout validating the predictive action against incremental lift. PROPOSED. 3. Triplet extraction with entropy gating: IE over SERP/web text → S-P-O triples → cross-source Shannon-entropy consensus (1 − H(T) > 0.85 as the quarantine-exit criterion) → then the full intake contract. Triples land as knowledge assertions — never causal edges. PROPOSED.


PART D — L5 AUTONOMY & DISTILLATION VECTORS (GOVERNED RESEARCH TRACK)

Everything in this part is RESEARCH unless noted. Customer-facing mention requires preview framing; scenario numbers require "illustrative"/"composite" labels.

D.0 L5 as a certified operating property (governs all of Part D)

L5 is not a global switch. Autonomy is certified per (account × action class), where an action class is a bounded, typed operation (e.g., "budget reallocation ≤ clamp within campaign group X", "creative rotation", "bid adjustment ≤ clamp", "campaign pause"). Certification requirements per class:

  1. Reversibility — a tested rollback path; irreversible classes (audience deletion, contract-level changes) are permanently capped below L5.
  2. Measurement — the class's decisions are covered by registered holdouts and ledger-classified outcomes.
  3. Calibration — the fixed promotion gates (Brier ≤ 0.20, AUC ≥ 0.72, stable lift across ≥2 purchase cycles) evaluated on that class's decision stream; evidence pack auto-assembled from the ledger; promotion decision human.
  4. Degradation — automatic demotion triggers wired (D.4 contraction): calibration drift, refutation failures, consent-drop spikes, volatility.
  5. Blast radius — per-class spend/exposure caps independent of the guardrail clamps.

Ascent begins with the most reversible, best-measured classes; an account's headline "autonomy level" is the minimum across its active action classes. This is the certification model behind the "certifiable autonomous media control system" positioning — used in copy only with preview framing until the first class is certified ≥L2 in production.

D.1 Counterfactual generative world models (ecosystem digital twin) — RESEARCH, high value

Forward model P(S_{t+1} | S_t, A_t) simulates platform-auction response to candidate actions before capital commits; reverse model recovers the auction state required for a target outcome. Grounding requirement: the simulator is seeded and continuously re-fit from the credit ledger and experiment registry — real measured lift, refutation outcomes, guardrail breaches — not synthetic priors. Simulator outputs are prediction-type assertions; a simulated win is never reported as a result. Deployment path: PLAN-phase candidate pre-screening (rank thousands of budget permutations, forward the top set into VALIDATE's real gates). The simulator augments VALIDATE; it never replaces holdouts. Simulator-vs-realized calibration is tracked as a first-class metric.

D.2 Pareto-consensus multi-agent negotiation — RESEARCH; proposal generator only

Single-objective agents optimizing aggressively is the canonical L5 failure mode. Architecture rule (adopted): negotiation proposes; deterministic policy authorizes. The Pareto/Nash layer is a PLAN/VALIDATE-phase proposal generator whose outputs are candidate actions with objective trade-off metadata (Signal: max lift; Risk: min downside volatility per the D.6 portfolio layer; Counsel: policy/GDPR). Authorization is exclusively the job of deterministic policy services — the VALIDATE gates (clamps, refutation, consent, deny-list) and DECIDE authority checks against the per-class autonomy ladder. No negotiated consensus ever self-authorizes an API call; hard constraints are the feasible region's boundary, not negotiable objectives. Status: RESEARCH; Counsel objective prototyped against Counsel Room fixtures only (never production tenant data).

D.3 Federated / zero-knowledge collective intelligence — RESEARCH, legally gated

Cross-client KGE structure sharing with differential privacy is a genuine long-term moat. Gate: formal privacy/legal review (consent scopes, DPAs, competitive confidentiality) before any design doc; until cleared, absent from all customer documentation. If cleared, the transferable artifact is structure (topic→topic PRECEDES priors, threshold shapes) — never identities or transactions.

Scope correction (adopted): a ZK proof attests that an approved computation ran correctly over committed inputs — it cannot attest that measured lift was genuinely causal. Causal validity is only ever established by the registered-holdout → X-Learner → DoWhy chain inside each tenant. The federated design therefore transfers only ZK-attested computation claims ("this embedding update was produced by the approved pipeline over ledger-verified experiments") plus differentially private structure — never a cross-tenant causal claim. Marketing may never describe ZK as "proving incrementality."

D.4 Adaptive guardrail envelopes — asymmetric by design — RESEARCH

D.5 Distillation frameworks — RESEARCH, benchmark-gated

Goal: compress external-KG + search structure into sub-10 ms edge-executable student embeddings alongside unified.intent_vectors (128-dim). Evidentiary limit (standing): distilled models inherit teacher bias unless interventionally corrected; a distillation benchmark win is an engineering claim, never a causal claim.

Technique What it is Mizoki fit Gate
Interventional distillation (do-calculus during teacher inference) Strip platform-reporting bias (e.g., inflated brand-search self-attribution) so students learn intervention effects, not correlation noise Serves the caused-vs-anticipated moat; teacher signals from the credit ledger Student must reproduce ledger-measured lift directions on held-out experiments
Graph-structure + text co-distillation (CoLE-style; graph transformer ⊗ LLM → RotatE/TransE-class KGE) Fuse KG topology with entity text into compact embeddings Enrich (:Topic) / :ExternalEntity neighborhoods; feeds the Vertex two-tower path (flag LII_REALTIME) GraphRAG retrieval P/R improvement per quality-metrics.yaml — no benchmark, no claim
Invariant-consistency distillation on search signals Invariance penalty + contrastive loss discards phrasing/seasonal noise, retains stable intent nodes Maps churning queries onto durable (:Topic) nodes — stabilizes PRECEDES edges PSI stability of topic assignments across query-drift windows
Triplet extraction + entropy filter See Part C, Strategy 4 Intake-contract-bound Quarantine-exit threshold + post-ingestion graph audit

All teacher/student runs through virtuoso_call (startup guard enforces no hardcoded model strings); traces to mii.reasoning_traces — the MII distillation hook exists for exactly this.

D.6 L5 prerequisite systems (adopted; RESEARCH → BUILD_DEBT until scheduled)

  1. Portfolio risk layer — cross-campaign/cross-account exposure model (correlated drawdown, channel concentration limits); the Risk objective in D.2 reads from it. Without it, per-campaign clamps can sum to portfolio-level over-exposure.
  2. Execution reliability contract — every ACT operation idempotent (idempotency keys per destination API), retried with backoff, reconciled against platform state post-write; unreconciled writes alarm and freeze the action class.
  3. Incident recovery — per-action-class runbooks: freeze class → revert via rollback path → root-cause into the ledger → recertification required before re-promotion.
  4. Metric contracts — every metric feeding VALIDATE/DECIDE (iROAS, Brier, AUC, PSI, consent-drop rate) gets a versioned definition (source tables, window, formula) in repo; a definition change invalidates in-flight certifications for classes consuming it.
  5. Security & threat controls — adversarial-input review for all external-data paths (SERP text is untrusted input — enforced in the extraction path), per-tenant credential isolation (SP-API pattern), model-output injection-resistance tests.

Each lands in docs/BUILD_DEBT.md with the D.0 certification model as the forcing function.


PART E — IMPLEMENTATION PLAN

Standing rules across all phases - Approval gates: APPROVED: MERGE and APPROVED: DEPLOY — explicit, human, per workstream. No exceptions. - Cloud sessions and the Boss's local Terminal both operate the repo (auto-merge lanes per .claude/rules/02-multi-session-coordination.md). The marketing site never ships from a merge — human dispatch of deploy-homepage.yml with the typed APPROVED token + canon check only (GOVERNANCE 2.1; corrected 2026-08-19, register row 19). Doc merges under src/shared/** / services/<x>/** dispatch their deploy workflows via the Deploy Router — treat those merges as deploy decisions. - Drive ↔ repo kept in sync via rsync; uploads verified via md5. - Ontology changes ship as OCPs (ontology/proposals/OCP-YYYYMMDD-<slug>.md); steward/architecture tiers require human approval; the system never approves its own. - Deferred items land in docs/BUILD_DEBT.md. Copy-vs-code gaps resolve by building to the claim, not softening the copy. - Pre-merge hygiene greps: legacy model strings (gemini-2.0-flash|grok-4-1|claude-opus-4-6|gpt-5.2|imagen-4.0) and legacy Amazon references (paapi|product advertising api, case-insensitive) — zero hits required. assert_no_legacy_strings() stays green. - All graph writes via the Cell 3/24 writer path; all ingestion via mapper → gate; person-level data never leaves the platform for third-party enrichment. - Skill + Boss-skillpack parity delta applied the same day any merge lands (drift is a defect). - Execution vehicle for Phases 0–3: CLAUDE_CODE_BUILD_PROMPT_EXTERNAL_KG_v1.1_FINAL.md + addendum-A supplemental instructions (~16–21 working days effort across Workstreams A–F: docs/DEBT/skill-delta; MarketSignal + Cell 37 + extraction + orchestration; entity spine; Shopify + SP-API connectors; brand-search experiment wiring; monitoring/alerting).

Phase 0 — Canonicalization & prerequisites (Week 1)

  1. Merge this document to docs/OFFERING_MAP.md on a feature branch; PR description carries the corrections register. Gate: APPROVED: MERGE.
  2. ~~Complete the pending LII merge first~~ — DONE (register row 21: LII branches merged ~2026-08-10, DSAR live-verified; external-KG work built on the intent graph as planned).
  3. Retire superseded drafts and the standalone addendum in Drive (archive folder, superseded note); upload this v2.1 with md5 verification.
  4. docs/BUILD_DEBT.md entries: Klaviyo/TTD connectors; Capital/Risk/Estate cells; Amazon co-purchase (permanently out of scope, reason noted); Phase 4 distillation (benchmark harness prerequisite); Phase 5 autonomy scaffolding; D.6 items 1–4; L5 certification program per D.0.
  5. Submit the Google Trends API alpha application for mizoki-prod (runbook docs/runbooks/TRENDS_ALPHA_APPLICATION.md).

Exit: docs merged; LII branch merged; Drive in sync; Trends application submitted; no stale claims live anywhere.

Phase 1 — Entity spine: Enterprise KG + Wikidata (Weeks 2–5)

  1. Budget line approved → enable Enterprise KG API in mizoki-prod (Boss executes the runbook; paid service; cost guard on jobs).
  2. Source registration (intake Steps 1–5) for both sources, including the KG name-field license constraint.
  3. Map candidate unified tables (organizations, brands, products, campaigns — person tables denylisted and tripwire-tested) to the reconciliation schema; run Entity Reconciliation; land MIDs in unified.entity_mids.
  4. OCP-1 (:ExternalEntity + SAME_AS) — steward-tier human approval; all graph writes behind EXTERNAL_ENTITY_SPINE (default off) via the Cell 3/24 writer path.
  5. Hydrate top-N entities (KG lookup JSON-LD + Wikidata SPARQL ownership properties) → quarantine → reversible-merge ER → gated writer submission.
  6. MID/Q-id topic anchoring into Audience Intelligence — observe-only additive field.

Exit: ER precision/recall ≥ baseline per quality-metrics.yaml; MID coverage reported; zero side-door writes (audit); GraphRAG retrieval non-regressing. Gates: MERGE → DEPLOY.

Phase 2 — MarketSignal + SERP/trend connector + flagship experiment (Weeks 4–8, overlaps P1)

  1. OCP-2 (architecture-tier): MarketSignal schema, unified.market_signals, MARKET_MAPPERS, versioned SERP-feature enum, Cell 37. Human approval.
  2. License a SERP/trends provider (documented Step 5 review); Trends official API slots in when alpha access clears (adapter swap).
  3. Cell 37 deployed IAM-locked (unauth /health 403, matching 33–36); pollers on Cloud Scheduler; quarantine + reprocess; cost caps; extraction path with untrusted-output validation; monitoring/alerts (fallback serves, quarantine spikes, consent drops, budget warnings).
  4. Flagship: brand-search cannibalization — geo/ghost-bid holdout registered before first impression via Cell 36; SERP covariates joined (unified time windows, deterministic identities only); ≥1 full purchase cycle; lift with Wilson/bootstrap CIs; Cell 26 heterogeneity + Cell 27 refutation before any customer-facing claim.

Exit: first ledger-classified brand-search report (incremental vs anticipated, CIs, refutation pass) — the marquee case study, labeled with real client data or "composite/illustrative," never Airbnb's published figures. Gates: MERGE → DEPLOY.

Phase 3 — Commerce surfaces: Shopify + Amazon SP-API (Weeks 8–14)

  1. Shopify PROPOSED → PARTIAL: official-webhook mapper (orders, checkouts, products, inventory), HMAC + replay protection on the existing SENSE ingress cell (no new cell), unified.consent_registry check before any person-level field passes the gate (redact + consent-drop counter otherwise), erasure-cascade coverage map updated before ship. Whitepaper status labels flip only after tests pass; live-site copy is a separate GATE-2 decision.
  2. Amazon SP-API per-tenant connector (Catalog Items + Product Type Definitions): LWA OAuth per tenant, rate-limit-aware; sales ranks → MarketSignals; variation relationships → gated imported assertions; OCP-3 taxonomy import (SKOS-style, licensing note). Co-purchase tripwire test permanent.
  3. Threshold Intelligence demand covariates (rank velocity × inventory) — observe-only recommendations; any activation behind a registered holdout.
  4. Retail media measurement interop (ROADMAP): Amazon Ads (connector adapter exists, not live-verified) and Walmart Connect (no connector) as MMM spend channels through src/shared/growth_control/mmm_export/ once MMM_EXPORT is armed and the ≥ 2-closed-quarter bar is met; console-attributed sales are reported, never the KPI (docs/product/MEASUREMENT_INTEROP.md). No customer-facing claim until a connector is live-verified.

Exit: one pilot tenant with both connectors live; taxonomy mapping coverage reported; recommendations at L0/L1. Gates: MERGE → DEPLOY per connector.

Phase 4 — Distillation & real-time enrichment (Weeks 12–20, research track)

  1. Benchmark harness first (quality-metrics.yaml + ledger-replay lift-direction test). No benchmark, no claim.
  2. Co-distillation prototype → GraphRAG retrieval delta → if positive, Vertex two-tower behind LII_REALTIME.
  3. Invariant-consistency pass on market_signals query streams → topic-assignment PSI stability report.
  4. Interventional-distillation experiment on ledger-labeled teachers; validate on held-out experiments.

Exit: benchmark deltas published internally; anything customer-facing carries preview framing. Gate: MERGE only (research artifacts need a separate DEPLOY approval to touch prod paths).

Phase 5 — Autonomy certification scaffolding (Weeks 16–24+, research track)

  1. Asymmetric adaptive clamps: autonomous contraction triggers wired to auto-demotion; widening proposals templated as human-approval artifacts.
  2. D.6 prerequisite systems scheduled from BUILD_DEBT: metric contracts first (cheap, unblocks certification), then execution reliability contract, incident runbooks, portfolio risk layer.
  3. World-model v0: offline auction simulator fit from registry + ledger; PLAN-phase candidate ranking only; simulator-vs-realized calibration tracked.
  4. Pareto proposal generator prototyped against Counsel Room fixtures; deterministic authorization untouched.
  5. Federated/ZK: privacy-legal review memo first; design doc only if cleared; ZK scope language per D.3 enforced in all materials.
  6. First L2 certification review for the most reversible, best-measured action class (budget reallocation within clamps is the natural candidate): evidence pack auto-assembled from the ledger (Brier ≤ 0.20, AUC ≥ 0.72, ≥2 stable cycles on the class's stream), decision human. This is the program's first public milestone.

Exit: contraction triggers live in Grafana; metric contracts in repo; simulator calibration report; certification evidence-pack template in repo.

Horizon framing: Phases 0–3 (the v1.1 build prompt, ~16–21 working days effort) are the execution vehicle for the first two quarters. Phases 4–5 plus the D.0 certification program and D.6 prerequisite systems extend across a ~24-month horizon, sequenced so the first L2-certified action class is the first public milestone. All horizon claims carry preview framing.

KPI dashboard

Risk register (top 6)

  1. Enterprise KG cost/licensing — pilot on one table set; cost guard; name-field license reviewed before UI display.
  2. SERP/Trends provider drift (feature deprecations; alpha-access uncertainty) — versioned feature enum; vendor-swappable adapter; licensed bridge until official access clears.
  3. Amazon ToS exposure — per-tenant OAuth only; SP-API primary; Creators API optional and gated; no scraping; co-purchase permanently out (tripwire-tested).
  4. External-triple pollution — quarantine + entropy gate + post-ingestion audit; imported/inferred provenance; causal edges only from the validation chain; writer-path-only graph writes.
  5. Privacy boundary — person-table denylist on all third-party enrichment (tripwire-tested); erasure-cascade coverage map maintained; consent-registry checks on person-touching connectors.
  6. Research-track leakage into marketing copy — claim-labeling standard in every artifact; preview framing mandatory; illustrative labels on all scenario numbers; ZK never described as "proving incrementality."

PART F — SIGNAL INTELLIGENCE DIVISION: PRODUCT & CAPABILITY DESCRIPTIONS

(Marketing-facing layer. Integrated from the Signal Intelligence Division documentation, corrected per register rows 14–16. All claims carry LIVE / PARTIAL / PROPOSED labels; external figures are vendor-sourced market context, never Mizoki results.)

F.1 Division mission & positioning

The Signal Intelligence division turns every fragmented marketing signal — a paid-search click, a bidstream request, an email open, a cart event, a scroll — into governed, causal evidence a marketer can act on with confidence. Where most marketing stacks show what happened, Signal Intelligence tells you what is about to happen and whether your marketing actually caused it.

The discipline in four moves: (1) capture behavioral signals across every channel; (2) resolve them to people and households under consent; (3) infer latent intent — what a person is likely to want next and when; (4) prove, with causal experiments, which marketing dollars produced net-new outcomes versus which merely took credit for conversions that would have happened anyway.

Positioning: "crystal ball plus proof." The flagship, ORACLE (Latent Intent Inference), is an anticipatory intent engine — intent stage, next-best interest, and purchase timing with calibrated probabilities. But ORACLE never ships a prediction without its companion: the causal credit ledger distinguishing conversions we caused from conversions we merely anticipated. We say "anticipatory intent with proof of causal lift." We never say "mind-reading."

Business goals: the three headline targets — 40% CAC reduction, 35% ROAS increase, 67% ROI improvement — are design/benchmark targets, labeled verified / benchmarked / pilot-target / illustrative per deployment evidence, never guaranteed outcomes.

F.2 Platform grounding (corrected)

Signal Intelligence runs on the canonical MIZ OKI 3.5 architecture — no separate stack: FastAPI microservices on Cloud Run (us-central1); BigQuery mizoki-prod.unified as the analytical backbone; the Firestore-backed knowledge + intent graphs (register row 18); BigQuery ML with a Vertex AI Vector Search retrieval path (PARTIAL — behind feature flag LII_REALTIME); React/TypeScript/MUI frontend with D3/Cytoscape graph visualization; served intent scores at sub-100ms (platform targets p50 < 50 ms, p95 < 100 ms).

The ORACLE / intent family (shipped reality — LIVE, IAM-locked): - Cell 33 — intent-signal-ingest: micro-signal ingestion behind the hard consent gate. - Cell 34 — intent-scoring-api: the Intent Scoring API. - Cell 35 — intent-graph: the intent graph (Firestore-backed — register row 18). - Cell 36 — intent-causal: incrementality, the experiment registry, and causal credit. - Cell 28 is a legacy production cell — it is not part of the intent family. - Cells 26–27 provide uplift estimation (X-Learner) and DoWhy refutation; Cell 37 market-signal-ingest (deployed 2026-08-11, partially operational; the external-intelligence covariate-supply scope stays [IN BUILD]) supplies market-level covariates (Part C, Strategy 4).

Functional cell-range groupings used in earlier marketing material (Sense 1–5, Reason 6–12, etc.) are indicative only — reconcile against WIRING.md before use in any published artifact.

The Boss agent exposes the division through MCP (the eight shipped intent_* tools, plus Gmail, Google Calendar, Google Drive, Chrome automation, scheduled tasks): a marketer can ask in natural language, get intent + ledger evidence, and (with approval) schedule activation.

F.3 Omnichannel signal capture

Source What's ingested Status
Paid search — Google Ads (GAQL) Campaigns, ad groups, keywords, search terms, assets, conversions, budgets, audiences, geo, attribution (SearchStream + field validation, MCC traversal) LIVE
Programmatic — OpenRTB bidstream Bid requests, win/loss, buyer/seat IDs, exchange/DSP metadata, device signals, floors, consent signals LIVE
Meta Platform events per live mapper LIVE
Email — SendGrid Sends, opens, clicks, bounces, unsubscribes, complaints, suppressions LIVE
Ecommerce — Shopify Orders, checkouts, products, inventory (inventory → MarketSignal inventory_level) PARTIAL (in build)
Web/app behavioral SDK (Cell 33) Search sessions, dwell, scroll velocity, hover, partial video watches, rewatches, cart events LIVE (consent-gated)
CRM (accounts, contacts, opportunities, revenue/margin) — PROPOSED
Offline / CTV Geo-level measurement through the canonical envelope PROPOSED
Klaviyo, The Trade Desk — PROPOSED

Every signal becomes a canonical JourneyEvent (tenant, source, event type/time, raw payload reference, normalized fields, entity candidates, provenance, governance labels, confidence, audit IDs) via MAPPERS[source] → ingest_gate. Market-level context rides the MarketSignal envelope (Part C) — never mixed into journeys.

Identity resolution — deterministic-first. Exact matches on authenticated identifiers first; probabilistic matching (device/IP/behavioral inference) extends reach only where governance permits — the standard trade-off being near-perfect accuracy with limited reach on deterministic links versus broader reach with statistical uncertainty on probabilistic ones. The intent graph labels every household link deterministic or probabilistic with confidence, and probabilistic links are excluded from all causal math (tested platform rule).

Consent-first. Cell 33's hard consent gate: no consent, no ingestion. Governance lives inside the Sense layer, not bolted on after.

F.4 ORACLE — the anticipatory flagship

Naming (owner ruling 2026-09-22, corrections register row 28 / OPEN_ITEMS OR-3): on customer-facing surfaces this capability is Intent Engine v2 within the Causal Growth Control offer. "ORACLE" is the internal program codename and stays in this map and the engineering record. Ratification never upgrades a claim — the labels in this section are unchanged.

Latent Intent Inference. ORACLE infers intent that hasn't yet expressed itself as a click or form fill, from behavioral micro-signals. The modeling pattern is the two-stage candidate-generation + ranking architecture proven at web scale in recommender systems (the design popularized by Google's 2016 YouTube recommendations work): two-tower embeddings (customer tower ⊗ topic/product tower) trained in BigQuery ML generate candidates, sequence models over the ordered micro-signal stream rank and time them. The real-time ANN retrieval path via Vertex AI Vector Search is PARTIAL (LII_REALTIME flag); batch scoring is LIVE.

The Intent Scoring API (Cell 34) serves, sub-100ms: - Intent vectors (dense embedding of current intent state) - Predicted next interests with calibrated probabilities - Intent-stage classification: awareness / consideration / in-market / purchase-imminent - Confidence + explanation path on every score — the shortest SHOWED_INTEREST → PRECEDES trace through the intent graph. No bare numbers, ever.

Calibration is the product. ORACLE reports both discrimination (AUC — ranks a true converter above a non-converter) and calibration (Brier — a well-calibrated "70%" is right about 70% of the time). This is the direct answer to the standard complaint against opaque intent vendors whose scores can't be validated.

Purchase-timing prediction — mapping customers toward a predicted purchase window so outreach lands at maximum receptivity rather than on a fixed cadence. LIVE per shipped scoring surfaces.

Churn / expansion propensity — the same architecture applied to churn risk and upsell drift. PROPOSED; surfaces only when calibration thresholds are met.

KG-based predictions (Cell 35 graph): PRECEDES co-occurrence reasoning ("interest in X tends to precede interest in Y"), human-readable explanation paths, and household rollups with deterministic/probabilistic labels.

Real-time alerts & subscriptions: "notify when this account enters in-market," "alert when purchase-imminent probability crosses 0.7" — via Pub/Sub and SSE dashboards, triggering Boss-agent workflows.

Autonomy: ORACLE ships observe-only (L0/L1). Promotion follows Part D.0's per-action-class certification: Brier ≤ 0.20, AUC ≥ 0.72, stable lift across ≥ 2 purchase cycles on that class's decision stream; auto-demotion at Brier > 0.20; promotion decision human.

F.5 Causal measurement & incrementality — the "proof" half

Uplift modeling (Cell 26): X-Learner meta-learning estimates heterogeneous treatment effects — who is persuadable, not just who converts — efficient under the unequal treatment/control sizes typical of marketing holdouts. LIVE. DR-Learner (doubly robust pseudo-outcomes for consistency under weaker nuisance-model assumptions): PROPOSED.

Refutation (Cell 27): every estimate is stress-tested with DoWhy refuters before it's trusted — placebo treatment (effect should collapse to zero), random common cause (estimate shouldn't move), data-subset stability. An estimate that fails refutation is flagged, never shipped.

Experiment designs (Cell 36 registry — registered before first impression, MDE declared up front): - Holdouts — withhold media from a randomized control group. - Ghost bids — log the auction instances where a control user would have been served, identifying the counterfactual without spending on placebo ads (the design introduced in the 2017 Journal of Marketing Research "Ghost Ads" methodology; cheaper and more precise than PSA or intent-to-treat tests). Available only where platforms expose the necessary auction logs; geo/holdout is the fallback elsewhere. - Geo experiments — treat statistically matched test markets against control markets; the rigorous method for broadly-targeted, hard-to-address channels (CTV prospecting, social prospecting, paid search).

The caused-vs-anticipated credit ledger (unified.causal_credit_ledger): every conversion classified caused (net-new, proven by experiment) or anticipated (would have happened anyway), each with a confidence interval. This turns intent prediction from a liability ("you're taking credit for existing demand") into an asset ("here is exactly what we caused, and what we'd have gotten for free").

Why this beats the alternatives: - vs. last-click: one touchpoint credited, journey and counterfactual ignored. - vs. platform self-attribution: platforms grade their own homework — reported ROAS credits any post-exposure conversion; iROAS reflects only experiment-proven net-new revenue. Vendor-published market context (not Mizoki results): geo-holdout databases have reported branded-search median iROAS near 0.27x, and public geo-test case studies commonly show platform ROAS overstating measured iROAS by roughly 1.5–3x, widest on brand search and retargeting. Expect iROAS ≪ platform ROAS on brand search — that's the product working (flagship experiment, Part C Strategy 4). - vs. correlation-only intent vendors: surge/topic scores say an account is "researching" — a correlation, usually account-level only. ORACLE gives the calibrated person/household probability and proves by experiment whether the response moved the outcome.

F.6 Acquisition intelligence (toward the 40% CAC target)

  1. Stop paying for anticipated conversions. Ledger-tagged "anticipated" spend is the first budget to cut — lowering CAC without lowering volume.
  2. Reallocate to proven-incremental channels. Budget plans optimize iROAS, not platform ROAS, and pass the VALIDATE gate (financial/statistical/causal/policy) before any spend moves.
  3. Target in-market earlier. Concentrate acquisition spend on in-market and purchase-imminent segments instead of spraying awareness budget cold.
  4. Multi-touch and causal. MTA maps path-to-conversion; experiments calibrate it — the industry-consensus "trifecta" (MTA + MMM + incrementality) with incrementality as the calibration layer.
  5. Predictive audiences. Expand from high-value seeds via embedding nearest-neighbor retrieval — with the upgrade over classic lookalikes that every candidate carries a calibrated intent probability and stage. (Real-time path PARTIAL per LII_REALTIME; activation export via the gated uplift_export_cohort path.)

F.7 Journey intelligence

F.8 Activation & access

F.9 Governance as a marketing advantage

Trust is a feature marketers can sell to their own customers and legal teams — the Part B.5 moat, restated for the field: - Consent-first ingestion (architectural, precedes persistence). No consent, no data. - Profiling rights honored: individuals' rights around solely-automated decisions and profiling (GDPR Art. 22-class protections, human-intervention rights) are exactly why ORACLE defaults observe-only and routes significant actions through human approval. - Creepiness deny-list: health, sexuality, religion, financial distress, minors — never predicted, stored, or surfaced, at schema level. - No audio, ever — the bright-line answer to "is my phone listening to me." - GDPR erasure cascade across BigQuery + the graph store + vector index; coverage map maintained for every person-touching connector. - Governance inside the loop: every prediction/action carries provenance, confidence, explanation path, and eligibility status, written to the immutable ledger.

F.10 Playbooks by marketing function

Function Play Expected outcome (labeled per claim discipline)
Demand Gen Subscribe to in-market alerts → concentrate paid on in-market/purchase-imminent → validate with ghost-bid/geo holdout → cut anticipated-only spend Lower CAC without volume loss; higher iROAS on retained spend
Lifecycle / CRM Predicted next-interest + purchase timing trigger nurtures at receptivity → suppress anticipated-anyway customers Higher conversion per send; lower fatigue/unsubscribe
Growth / Performance Always-on incrementality across the mix → optimize to iROAS → feed proven-incremental audiences into predictive expansion The 35% ROAS-lift target
Brand Geo experiments on brand/CTV → downstream stage progression (awareness → consideration) as leading indicator Defensible causal evidence last-click can't provide
RevOps Intent API + Pub/Sub into CRM to prioritize pipeline by calibrated stage → ledger as the single causal source of truth for sourced vs. influenced Marketing/sales alignment on one causal reality

Regional/segment views: calibrated intent aggregates by region/DMA/segment (heatmaps of in-market demand concentration); the same regional structure powers geo holdouts with matched control markets; X-Learner heterogeneous effects read lift per segment/region — where a channel is genuinely incremental versus wasted.

F.11 Glossary (marketer-facing)

Latent intent — intent inferred from behavior before explicit expression. Intent vector — dense embedding of current intent state. Intent stage — awareness / consideration / in-market / purchase-imminent. Calibrated probability — 70% means right ~70% of the time (Brier-measured). AUC — probability a true converter ranks above a non-converter. Two-tower model — candidate-generation architecture with separate user/item encoders. iROAS — experiment-proven net-new revenue ÷ spend (vs. platform ROAS crediting any post-exposure conversion). Ghost bid — logging would-be impressions to form a free counterfactual control. X-Learner / DR-Learner — meta-learners for who is persuadable. DoWhy refutation — placebo / random-common-cause / subset stress tests. PRECEDES edge — interest in X tends to precede interest in Y. Caused vs. anticipated — the ledger distinction. Dark funnel — the untrackable majority of the buying journey.

F.12 Claim discipline — field language rules

✅ "Anticipatory intent with proof of causal lift." ❌ "Mind-reading," "we know what customers are thinking," "we listen." ✅ "Calibrated probability this account is in-market" (with confidence + explanation path). ❌ "This account will buy." ✅ "Proven-incremental" only after a registered experiment passes refutation. ❌ "Incremental" for correlation-only or platform-reported numbers. Targets (40% CAC / 35% ROAS / 67% ROI) always labeled verified / benchmarked / pilot-target / illustrative. External vendor figures are market context, never Mizoki results. ZK is never described as "proving incrementality" (D.3). No audio. Sensitive topics denied. Consent required. Humans in the loop on significant decisions.

F.13 Staged customer rollout (maps to Part E phases)

Stage 1 — Sense & See (Weeks 0–6). Stand up ingestion for the two highest-spend live channels (typically Google Ads + OpenRTB or Meta) plus SendGrid; Shopify as it reaches PARTIAL. Deterministic-first identity + consent gate on. Advance at: ≥80% attribution/identity coverage and a populated intent graph. ORACLE observe-only.

Stage 2 — Score & Explain (Weeks 6–12). Enable Cell 34 scoring + Intent Scores Grid + Predicted Journey Timeline for one function (Demand Gen or Lifecycle first). Promote past observe-only only at: Brier ≤ 0.20, AUC ≥ 0.72, stable lift ≥ 2 purchase cycles; otherwise advisory + retrain.

Stage 3 — Prove (Weeks 8–16, overlapping). Launch Cell 36 incrementality with a ghost-bid or geo holdout on the single most-questioned channel (usually branded search or retargeting — the Part C flagship). DoWhy refutation must pass before any estimate informs budget. Reallocate at: refutation-passing iROAS whose CI excludes the hurdle rate.

Stage 4 — Act & Compound (Quarter 2+). Move budget on the ledger; wire Pub/Sub + Boss-agent MCP alerting; expand predictive audiences from proven-incremental seeds. Reversal rules: measured iROAS below hurdle two cycles → revert; promoted model's Brier > 0.20 → auto-demote to observe-only.

F.14 Caveats (standing)


End of document. v2.3 COMPLETE (the v2.2 FINAL body carrying the v2.3 in-place ratification register) — supersedes the two original drafts, v2.0, the standalone addendum, v2.1, and the standalone Signal Intelligence division doc. (Historical next-action note retired: v2.2 landed on main 2026-08-18 db2983e0; v2.2.1 tree-truth corrections applied 2026-08-19; v2.3 register/ratification edits applied 2026-08-19; the site does not deploy on push — register row 19.)

← All docsView source on GitHub →