Growth Control Completion Specification v1.1

Master Engineering Completion Plan — August 20, 2026

Operationalizes MIZOKI_3.5_WHITEPAPER_r3.5.1_AUG2026.md, MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md, and amendment MIZOKI_3.5_WHITEPAPER_r3.5.2_AMENDMENT_AUG2026.md. Advances Frontiers F1, F2, F4, and F5 into active in-scope builds alongside core governance, telemetry, and decision-tracing workstreams. The live Cell Registry remains ground truth; where this document and the registry disagree, the registry wins.


Workstream 0 — Governance, Canon, and Vocabulary Consolidation

Vocabulary alignment. Ratified product terminology — Decision Control Plane, Decision Eligibility Layer (DEL Score), Growth Decision Graph, Intent Engine v2, ValidationPassport, High-Value Decision Jobs (J-01 through J-06) — is standard canon on every surface: engineering code, external copy, product docs, and operator-facing UI. RATIFIED_VOCABULARY in scripts/mizoki_canon.py is the machine copy. Ratification never upgrades a claim: capability statements still carry their honest LIVE / PARTIAL / IN BUILD / PROPOSED labels.

Live Canon Status API. GET /api/v1/status/canon programmatically compares declared capability status against live Cloud Run service registries, feature flags, and serving revisions. Prevents documentation-reality drift — the endpoint answers "is what the whitepaper says still true?" with measured evidence, not inference. [IN BUILD]

Workstream A — Intent Engine v2 Hardening and Ephemeral Lifecycle Purges

Privacy enforcement (O-1 PRIVACY LOCK). Schema-level locks block invasive telemetry at ingest validation — not as operator-toggle settings. Enforced by tests/test_o1_privacy_lock.py and the validation-orchestrator schema gate.

Signal prohibitions (schema-enforced): - No audio or microphone-derived signals. Ever. - No keystroke dynamics — permanently prohibited (owner ruling O-1). No raw keyboard events, typing speed, flight times, text-input analysis, or fingerprints. - No gaze tracking; no fine-grained geolocation beyond existing coarse, consent-scoped region. - Sensitive-category deny-list — health, sexuality, religion, financial distress, minors — never predicted, stored, surfaced, or composed into inferences.

Strict ephemeral retention (code-enforced, not policy prose):

Module Retention Bound Purge Mechanism
I-01 PassiveAttentionSequence Session end Raw sequence buffers purged on session termination
I-02 SessionOutcomeForecast Active session Bounded strictly to session duration
I-03 CreativeSemanticProfile Creative asset lifecycle Retained only while the creative asset is active
I-04 IntentHypothesis Strict TTL Graph bridges expire and are swept on TTL schedule
I-05 ValidationPassport Ledger retention Immutable decision trace; audit-grade retention

Session-end purge jobs and retention-bound tests are part of the build, not the documentation.

Workstream B — ValidationPassport Packaging (Decision Job J-05 Product)

Immutable decision trace. The ValidationPassport assembles a complete execution history from the immutable learning ledger into a cryptographically hashed envelope — the single artifact that makes every decision defensible under audit.

Trace envelope contents: 1. Decision ID and tenant context 2. Input signal references (canonical event envelope IDs) 3. Ranked causal hypotheses from the Reason phase 4. Evaluated counterfactual plans (including mandatory no-action baseline) 5. DEL Score and individual gate evaluation results (identity/signature, policy alignment, context sufficiency, hard constraints) 6. Assigned autonomy level (L0–L5) and action class 7. Approval records (human or delegated, with timestamp and principal) 8. Dispatched action commands or veto reasons 9. Predicted outcomes at time of decision 10. Backfilled realized outcomes (when observed)

The passport is the J-05 Executive Defensibility product — one auditable trace reconciling conflicting channel reports.

Workstream C — Net Yield Completion

E-commerce contribution compute. Ingests Shopify order and refund telemetry into standard order economics tables. Component-level pricing:

NCM(C) = Σ [R − COGS − F − S − P − E[RL]] − AdSpend(C)

Where: R = line-item revenue, COGS = bundle-decomposed cost of goods, F = fulfillment/pick-pack, S = shipping, P = payment gateway fees, E[RL] = expected return cost (actual-only until one observed cycle per SKU).

Fail-closed writeback rules. NET_YIELD_WRITEBACK=false is enforced by test-level barriers (tests/test_writeback_flags.py) that fail if the flag is flipped. Value writeback to platform bidders activates only after a verified pilot with reconciled margin economics. The metric contract (NCM-v1) is versioned; any change ships as NCM-v2 with migration.

Workstream D — Frontier F3: Supply-Chain and Inventory Synchronization [IN BUILD — observe-only]

Inventory graph nodes. Extends Shopify connectors to model real-time stock levels, holding costs, and fulfillment node capacities within the Growth Decision Graph: - (:SKU)-[:STOCK_STATE] — current inventory level, reorder point, weeks-of-cover - (:FulfillmentNode)-[:CAPACITY_STATE] — processing capacity, backlog, geographic reach

Observe-only recommendation vectors:

Condition Recommendation Mechanism
Stockout detected Throttle bidding on affected SKUs DCP advisory; no adapter dispatch
Overstock flagged Accelerate media spend on clearance items DCP advisory; requires L2+ for action
Regional capacity constraint Geo-shift media spend to serviceable regions DCP advisory; geo-reservation gated

Observe-only first (owner ruling 2026-08-19). Recommendations are logged as passport entries without dispatching to action runner adapters until the frontier climbs the autonomy ladder.

Workstream E — Decision Jobs Registry and 90-Day Pilot Instrumentation

Job standardization (J-01 to J-06):

Job Name Input Signals Eligible Decisions Governing Constraints
J-01 Incrementality Holdout results, CATE estimates Budget shifts between channels Refutation must pass; lift CI excludes zero
J-02 Waste Prevention Cross-stack CPA spikes Pause/redirect flagged campaigns Prohibition on automatic campaign blame
J-03 Margin Control NCM, inventory state (F3) Budget toward high-margin, in-stock SKUs Contribution economics; fulfillment capacity
J-04 Learning Stability Platform learning-phase signals Staged changes with rollback paths Cool-down windows; noise detection
J-05 Executive Defensibility ValidationPassport traces Reconciliation of conflicting reports Cryptographic hash chain; full audit trail
J-06 Team Leverage Assembled evidence packages Human-authorized actions from evidence Authorization gate always retained

Automated pilot state machine. Manages tenant onboarding across the 90-Day Growth Control Pilot lifecycle: - Days 1–30 · Observe: Connect agreed stack, establish baseline data quality, define target Decision Jobs. Zero changes to live execution. - Days 31–60 · Validate: Synthetic-control geo experiments, CATE model calibration, propensity verification, margin reconciliation against the customer's own books. - Days 61–90 · Recommend: Fully contextualized decision proposals with complete audit trails, routed through designated human approval, every prediction graded against outcomes.

State transitions generate pilot reports required to advance execution authority through the Three-Gate Evidence Maturity Framework.

Workstream F — Frontier F4: Continuous Calibration via Automated Micro-Geo Holdouts [IN BUILD]

Geo reservation engine. Selects representative geographic control groups using Synthetic Control Methods (SCM). Candidate geographies drawn from config/f4_geo_candidates.yaml (owner-provided). Selection criteria: population representativeness, media-spend proportionality, historical treatment-effect variance.

Approval-gated execution. Geo-holdouts alter media spend — candidate reservations must pass through L2 Human Approval flows before execution. Spend perturbation caps are owner-declared per-geography. After two clean calibration cycles complete, reservations become eligible for bounded autonomy within declared spend caps.

Bayesian calibration loop. Ground-truth incremental lift estimates from geo-experiments inject as informative priors into Bayesian Marketing Mix Models (MMM). The loop: 1. Reserve geography → schedule perturbation → execute (L2-gated) 2. Estimate realized lift via synthetic control 3. Update Bayesian MMM priors with realized lift 4. Assess prior-posterior divergence; flag and re-test if excessive 5. Repeat continuously — calibration becomes a system property, not a quarterly project

Workstream G — Frontier F1: Creative Component Unbundling [IN BUILD]

Multimodal feature extraction. Extracts semantic features from ad assets via vision-language embeddings: - Copy length and promotional framing (discount %, urgency cues, social proof) - Layout structure (grid position, visual hierarchy, CTA placement) - Imagery classification (product-only, lifestyle, UGC, abstract) - Color and contrast profiles

Lands on the CreativeSemanticProfile lane (I-03) and writes to Decision Memory in the Growth Decision Graph.

Causal effect isolation. Doubly Robust ML (DR-Learner / DML) separates the independent causal effect of individual creative components from overall asset performance. The Clipped-ReLU DEL gate applies identically: authority_c = min(cap_c, max(0, DEL_score − threshold_c)) — creative rotation recommendations below threshold get zero authority.

Effect estimates labeled provisional until pilot-scale creative volume exists. Generated-creative deployment always retains human approval.

Workstream H — Frontier F2: Multi-Quarter LTV Treatment Regimes [IN BUILD]

Retention balancing. Dynamic treatment regimes evaluate multi-period outcome horizons: - Immediate conversion gain: Y_{t+1} - Discounted multi-quarter contribution margin: Y_{t+365} - Net present value of the customer relationship under each treatment regime

The ledger gains an explicit outcome-horizon dimension. Acquisition stops buying customers the P&L later regrets.

Data-gated publishing. Code-level invariant (not policy prose): long-horizon LTV findings are published only after ≥ 2 observed quarters of repeat-purchase data exist for the cohort. Insufficient data emits data_insufficient warnings and blocks publication to decision surfaces.

Workstream I — Frontier F5: Treasury-Gated Spend Governance [IN BUILD]

Capital constraint integration. Enterprise financial constraints become hard gates in VALIDATE and DECIDE: - Liquidity floors (minimum working capital) - Credit line availability - Debt covenant proximity curves

v1 (current build): Consumes owner-declared constraints from config/treasury_constraints.yaml as validated tenant configuration. Missing configuration = no F5 constraint claimed (fail-closed, honest health — the system never invents a floor it wasn't given).

v2 (when Capital division treasury feed lands): Replaces declared values with live treasury positions. Same gate mechanics, live data.

Automated spend tightening via DEL. When cash reserves approach defined liquidity floors: 1. DEL automatically reduces channel spend caps proportionally 2. Budget expansion proposals receive automatic veto 3. The specific treasury constraint is named in the ValidationPassport 4. Human routing on breach — treasury vetoes to human review, never silently overridden


Platform Operational Architecture Summary

Dimension Mechanism Function
State Machine SRPVDAL (7-stage) Every signal traverses Sense→Reason→Plan→Validate→Decide→Act→Learn before execution
Ingress Gateway 15 native connectors Normalizes raw data into 10-dimension Canonical Event Envelopes
Decision Evaluation Four deterministic gates Identity/Signature, Policy Alignment, Context Sufficiency, Hard Constraints
Decision Authority Clipped-ReLU DEL authority_c = min(cap_c, max(0, DEL_score − threshold_c)) — zero below threshold, capped at covenant
Autonomy Control L0–L5 ladder Observe-only → full autonomy; earned per (account × action class); promotion always human
Causal Inference CATE meta-learners S/T/X-Learner, DR-Learner/DML with automated refutation
Triangulation Micro CATE + SCM GeoLift + Bayesian MMM User-level causal ML × geographic experiments × aggregate portfolio models
Measurement iROAS, never platform ROAS The number the bank account reports, not the ad platform
Privacy O-1 PRIVACY LOCK (schema-enforced) Audio, keystroke, gaze, fine-geo, sensitive categories — blocked at validation, not toggled
Audit Immutable learning ledger + ValidationPassport Every decision traceable; prediction never grades itself

Critical Path: Required Owner Inputs for Deployment

To move from code completion to live pilot deployment, the following configuration parameters must be supplied by the enterprise owner:

Input Config Path Purpose Blocks
Pilot tenant selection Operator decision Initial brand account and agreed source connectors All workstreams
Cost structure config/net_yield_costs.yaml COGS, payment fees, pick-pack-ship, baseline return rates per SKU Workstream C (Net Yield)
Treasury constraints config/treasury_constraints.yaml Minimum liquidity floors, credit limits, covenant proximity Workstream I (F5)
Candidate geo pool config/f4_geo_candidates.yaml Permissible regions, spend perturbation caps, excluded markets Workstream F (F4)
Creative asset access Multimodal asset store permissions Training creative component models Workstream G (F1)

Once configured, the system executes the 90-Day Pilot in observe-only mode (Days 1–30), generating verifiable ValidationPassports and lift metrics required to advance through the Three-Gate Evidence Maturity Framework and unlock higher autonomy levels.


Workstream Dependency Graph

WS-0 Governance & Canon ─────┬──→ WS-A Intent Engine v2 ──→ WS-G F1 Creative ←── Owner: Asset Access
                              │                                  (I-03 lane)
                              └──→ WS-B ValidationPassport ──┐
                                                              ├──→ WS-E Decision Jobs & Pilot ←── Owner: Pilot Tenant
Owner: Cost Config ──→ WS-C Net Yield ──┬─────────────────────┘         │
                                        ├──→ WS-D F3 Supply-Chain      │
                                        └──→ WS-H F2 LTV Regimes ←────┤←── WS-F (2 cycles)
                                                                       │
                              Owner: Geo Pool ──→ WS-F F4 Geo Cal ←───┘
                              Owner: Treasury ──→ WS-I F5 Treasury (parallel)

Build sequencing logic: - Foundation first: WS-0 and WS-B are prerequisites — every downstream workstream writes passports and uses ratified vocabulary. - Prove-and-price before predict-and-expand: WS-C must price conversions before WS-D can compute inventory-adjusted recommendations and before WS-H can evaluate multi-quarter contribution margins. - Calibrate before autonomy: WS-F must complete ≥ 2 clean cycles before WS-H publishes long-horizon findings. - Owner inputs gate frontiers, not each other: WS-I and WS-G have no inter-workstream dependencies — they gate on owner-provided configuration and can build in parallel. - Every frontier enters at observe or recommend: Nothing spend-affecting promotes past calibration gates (Brier ≤ 0.20, AUC ≥ 0.72, ≥ 2 purchase cycles). - Every phase ships a sellable artifact: Pilot report, calibration certificate, decision-job SLA, margin reconciliation.


The 90-Day Growth Control Pilot — Standard Commercial Onboarding

Adopted as standard by owner ruling 2026-08-19. The pilot is both the sales motion and the proof motion.

Phase Days Activity Deliverable Autonomy
Observe 1–30 Connect agreed stack. Baseline data quality. Define target Decision Jobs. Zero live changes. Baseline data-quality report; connected-stack inventory L0
Validate 31–60 Synthetic-control geo experiments. CATE calibration. Propensity verification. Margin reconciliation vs customer books. Calibrated model card; first verified lift findings; margin reconciliation L0–L1
Recommend 61–90 Decision proposals with complete audit trails. Human-approved. Every prediction graded against outcomes. Decision proposals with ValidationPassports; pilot completion report L1–L2

Three-Gate Evidence Maturity Framework

The pilot that closes a customer is the same machine that produces the verified numbers that flip the public Preview labels.

Packaging Ladder

Tier Entry Deliverables Gate
Signal Factory Free public demo Live SRPVDAL walkthrough; truth-delta preview Gate 1
90-Day Growth Control Pilot Paid Calibrated models, first lift findings, margin reconciliation, passports Gate 2
Signal Operations Annual J-01–J-06 under chosen autonomy tier; standing F4 recalibration Gate 2+
Enterprise Growth Control Annual + F2 LTV, F3 supply-chain, F5 treasury; Capital/Counsel/Risk interlock Gate 3

Growth Control Completion Specification v1.1 · August 20, 2026 Companion to: Whitepaper r3.5.1 + Amendment r3.5.2 + Growth Control r2.0/r2.1 Ground truth: docs/architecture/CELL_REGISTRY.md (cells), production/service-registry.yaml (services), src/shared/virtuoso_models/WIRING.md (wiring)

← All docsView source on GitHub →