Growth Control Completion Specification v1.1
Master Engineering Completion Plan — August 20, 2026
Operationalizes MIZOKI_3.5_WHITEPAPER_r3.5.1_AUG2026.md, MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md, and amendment MIZOKI_3.5_WHITEPAPER_r3.5.2_AMENDMENT_AUG2026.md. Advances Frontiers F1, F2, F4, and F5 into active in-scope builds alongside core governance, telemetry, and decision-tracing workstreams. The live Cell Registry remains ground truth; where this document and the registry disagree, the registry wins.
Workstream 0 — Governance, Canon, and Vocabulary Consolidation
Vocabulary alignment. Ratified product terminology — Decision Control Plane, Decision Eligibility Layer (DEL Score), Growth Decision Graph, Intent Engine v2, ValidationPassport, High-Value Decision Jobs (J-01 through J-06) — is standard canon on every surface: engineering code, external copy, product docs, and operator-facing UI. RATIFIED_VOCABULARY in scripts/mizoki_canon.py is the machine copy. Ratification never upgrades a claim: capability statements still carry their honest LIVE / PARTIAL / IN BUILD / PROPOSED labels.
Live Canon Status API. GET /api/v1/status/canon programmatically compares declared capability status against live Cloud Run service registries, feature flags, and serving revisions. Prevents documentation-reality drift — the endpoint answers "is what the whitepaper says still true?" with measured evidence, not inference. [IN BUILD]
Workstream A — Intent Engine v2 Hardening and Ephemeral Lifecycle Purges
Privacy enforcement (O-1 PRIVACY LOCK). Schema-level locks block invasive telemetry at ingest validation — not as operator-toggle settings. Enforced by tests/test_o1_privacy_lock.py and the validation-orchestrator schema gate.
Signal prohibitions (schema-enforced): - No audio or microphone-derived signals. Ever. - No keystroke dynamics — permanently prohibited (owner ruling O-1). No raw keyboard events, typing speed, flight times, text-input analysis, or fingerprints. - No gaze tracking; no fine-grained geolocation beyond existing coarse, consent-scoped region. - Sensitive-category deny-list — health, sexuality, religion, financial distress, minors — never predicted, stored, surfaced, or composed into inferences.
Strict ephemeral retention (code-enforced, not policy prose):
| Module | Retention Bound | Purge Mechanism |
|---|---|---|
| I-01 PassiveAttentionSequence | Session end | Raw sequence buffers purged on session termination |
| I-02 SessionOutcomeForecast | Active session | Bounded strictly to session duration |
| I-03 CreativeSemanticProfile | Creative asset lifecycle | Retained only while the creative asset is active |
| I-04 IntentHypothesis | Strict TTL | Graph bridges expire and are swept on TTL schedule |
| I-05 ValidationPassport | Ledger retention | Immutable decision trace; audit-grade retention |
Session-end purge jobs and retention-bound tests are part of the build, not the documentation.
Workstream B — ValidationPassport Packaging (Decision Job J-05 Product)
Immutable decision trace. The ValidationPassport assembles a complete execution history from the immutable learning ledger into a cryptographically hashed envelope — the single artifact that makes every decision defensible under audit.
Trace envelope contents: 1. Decision ID and tenant context 2. Input signal references (canonical event envelope IDs) 3. Ranked causal hypotheses from the Reason phase 4. Evaluated counterfactual plans (including mandatory no-action baseline) 5. DEL Score and individual gate evaluation results (identity/signature, policy alignment, context sufficiency, hard constraints) 6. Assigned autonomy level (L0–L5) and action class 7. Approval records (human or delegated, with timestamp and principal) 8. Dispatched action commands or veto reasons 9. Predicted outcomes at time of decision 10. Backfilled realized outcomes (when observed)
The passport is the J-05 Executive Defensibility product — one auditable trace reconciling conflicting channel reports.
Workstream C — Net Yield Completion
E-commerce contribution compute. Ingests Shopify order and refund telemetry into standard order economics tables. Component-level pricing:
NCM(C) = Σ [R − COGS − F − S − P − E[RL]] − AdSpend(C)
Where: R = line-item revenue, COGS = bundle-decomposed cost of goods, F = fulfillment/pick-pack, S = shipping, P = payment gateway fees, E[RL] = expected return cost (actual-only until one observed cycle per SKU).
Fail-closed writeback rules. NET_YIELD_WRITEBACK=false is enforced by test-level barriers (tests/test_writeback_flags.py) that fail if the flag is flipped. Value writeback to platform bidders activates only after a verified pilot with reconciled margin economics. The metric contract (NCM-v1) is versioned; any change ships as NCM-v2 with migration.
Workstream D — Frontier F3: Supply-Chain and Inventory Synchronization [IN BUILD — observe-only]
Inventory graph nodes. Extends Shopify connectors to model real-time stock levels, holding costs, and fulfillment node capacities within the Growth Decision Graph:
- (:SKU)-[:STOCK_STATE] — current inventory level, reorder point, weeks-of-cover
- (:FulfillmentNode)-[:CAPACITY_STATE] — processing capacity, backlog, geographic reach
Observe-only recommendation vectors:
| Condition | Recommendation | Mechanism |
|---|---|---|
| Stockout detected | Throttle bidding on affected SKUs | DCP advisory; no adapter dispatch |
| Overstock flagged | Accelerate media spend on clearance items | DCP advisory; requires L2+ for action |
| Regional capacity constraint | Geo-shift media spend to serviceable regions | DCP advisory; geo-reservation gated |
Observe-only first (owner ruling 2026-08-19). Recommendations are logged as passport entries without dispatching to action runner adapters until the frontier climbs the autonomy ladder.
Workstream E — Decision Jobs Registry and 90-Day Pilot Instrumentation
Job standardization (J-01 to J-06):
| Job | Name | Input Signals | Eligible Decisions | Governing Constraints |
|---|---|---|---|---|
| J-01 | Incrementality | Holdout results, CATE estimates | Budget shifts between channels | Refutation must pass; lift CI excludes zero |
| J-02 | Waste Prevention | Cross-stack CPA spikes | Pause/redirect flagged campaigns | Prohibition on automatic campaign blame |
| J-03 | Margin Control | NCM, inventory state (F3) | Budget toward high-margin, in-stock SKUs | Contribution economics; fulfillment capacity |
| J-04 | Learning Stability | Platform learning-phase signals | Staged changes with rollback paths | Cool-down windows; noise detection |
| J-05 | Executive Defensibility | ValidationPassport traces | Reconciliation of conflicting reports | Cryptographic hash chain; full audit trail |
| J-06 | Team Leverage | Assembled evidence packages | Human-authorized actions from evidence | Authorization gate always retained |
Automated pilot state machine. Manages tenant onboarding across the 90-Day Growth Control Pilot lifecycle: - Days 1–30 · Observe: Connect agreed stack, establish baseline data quality, define target Decision Jobs. Zero changes to live execution. - Days 31–60 · Validate: Synthetic-control geo experiments, CATE model calibration, propensity verification, margin reconciliation against the customer's own books. - Days 61–90 · Recommend: Fully contextualized decision proposals with complete audit trails, routed through designated human approval, every prediction graded against outcomes.
State transitions generate pilot reports required to advance execution authority through the Three-Gate Evidence Maturity Framework.
Workstream F — Frontier F4: Continuous Calibration via Automated Micro-Geo Holdouts [IN BUILD]
Geo reservation engine. Selects representative geographic control groups using Synthetic Control Methods (SCM). Candidate geographies drawn from config/f4_geo_candidates.yaml (owner-provided). Selection criteria: population representativeness, media-spend proportionality, historical treatment-effect variance.
Approval-gated execution. Geo-holdouts alter media spend — candidate reservations must pass through L2 Human Approval flows before execution. Spend perturbation caps are owner-declared per-geography. After two clean calibration cycles complete, reservations become eligible for bounded autonomy within declared spend caps.
Bayesian calibration loop. Ground-truth incremental lift estimates from geo-experiments inject as informative priors into Bayesian Marketing Mix Models (MMM). The loop: 1. Reserve geography → schedule perturbation → execute (L2-gated) 2. Estimate realized lift via synthetic control 3. Update Bayesian MMM priors with realized lift 4. Assess prior-posterior divergence; flag and re-test if excessive 5. Repeat continuously — calibration becomes a system property, not a quarterly project
Workstream G — Frontier F1: Creative Component Unbundling [IN BUILD]
Multimodal feature extraction. Extracts semantic features from ad assets via vision-language embeddings: - Copy length and promotional framing (discount %, urgency cues, social proof) - Layout structure (grid position, visual hierarchy, CTA placement) - Imagery classification (product-only, lifestyle, UGC, abstract) - Color and contrast profiles
Lands on the CreativeSemanticProfile lane (I-03) and writes to Decision Memory in the Growth Decision Graph.
Causal effect isolation. Doubly Robust ML (DR-Learner / DML) separates the independent causal effect of individual creative components from overall asset performance. The Clipped-ReLU DEL gate applies identically: authority_c = min(cap_c, max(0, DEL_score − threshold_c)) — creative rotation recommendations below threshold get zero authority.
Effect estimates labeled provisional until pilot-scale creative volume exists. Generated-creative deployment always retains human approval.
Workstream H — Frontier F2: Multi-Quarter LTV Treatment Regimes [IN BUILD]
Retention balancing. Dynamic treatment regimes evaluate multi-period outcome horizons: - Immediate conversion gain: Y_{t+1} - Discounted multi-quarter contribution margin: Y_{t+365} - Net present value of the customer relationship under each treatment regime
The ledger gains an explicit outcome-horizon dimension. Acquisition stops buying customers the P&L later regrets.
Data-gated publishing. Code-level invariant (not policy prose): long-horizon LTV findings are published only after ≥ 2 observed quarters of repeat-purchase data exist for the cohort. Insufficient data emits data_insufficient warnings and blocks publication to decision surfaces.
Workstream I — Frontier F5: Treasury-Gated Spend Governance [IN BUILD]
Capital constraint integration. Enterprise financial constraints become hard gates in VALIDATE and DECIDE: - Liquidity floors (minimum working capital) - Credit line availability - Debt covenant proximity curves
v1 (current build): Consumes owner-declared constraints from config/treasury_constraints.yaml as validated tenant configuration. Missing configuration = no F5 constraint claimed (fail-closed, honest health — the system never invents a floor it wasn't given).
v2 (when Capital division treasury feed lands): Replaces declared values with live treasury positions. Same gate mechanics, live data.
Automated spend tightening via DEL. When cash reserves approach defined liquidity floors: 1. DEL automatically reduces channel spend caps proportionally 2. Budget expansion proposals receive automatic veto 3. The specific treasury constraint is named in the ValidationPassport 4. Human routing on breach — treasury vetoes to human review, never silently overridden
Platform Operational Architecture Summary
| Dimension | Mechanism | Function |
|---|---|---|
| State Machine | SRPVDAL (7-stage) | Every signal traverses Sense→Reason→Plan→Validate→Decide→Act→Learn before execution |
| Ingress Gateway | 15 native connectors | Normalizes raw data into 10-dimension Canonical Event Envelopes |
| Decision Evaluation | Four deterministic gates | Identity/Signature, Policy Alignment, Context Sufficiency, Hard Constraints |
| Decision Authority | Clipped-ReLU DEL | authority_c = min(cap_c, max(0, DEL_score − threshold_c)) — zero below threshold, capped at covenant |
| Autonomy Control | L0–L5 ladder | Observe-only → full autonomy; earned per (account × action class); promotion always human |
| Causal Inference | CATE meta-learners | S/T/X-Learner, DR-Learner/DML with automated refutation |
| Triangulation | Micro CATE + SCM GeoLift + Bayesian MMM | User-level causal ML × geographic experiments × aggregate portfolio models |
| Measurement | iROAS, never platform ROAS | The number the bank account reports, not the ad platform |
| Privacy | O-1 PRIVACY LOCK (schema-enforced) | Audio, keystroke, gaze, fine-geo, sensitive categories — blocked at validation, not toggled |
| Audit | Immutable learning ledger + ValidationPassport | Every decision traceable; prediction never grades itself |
Critical Path: Required Owner Inputs for Deployment
To move from code completion to live pilot deployment, the following configuration parameters must be supplied by the enterprise owner:
| Input | Config Path | Purpose | Blocks |
|---|---|---|---|
| Pilot tenant selection | Operator decision | Initial brand account and agreed source connectors | All workstreams |
| Cost structure | config/net_yield_costs.yaml |
COGS, payment fees, pick-pack-ship, baseline return rates per SKU | Workstream C (Net Yield) |
| Treasury constraints | config/treasury_constraints.yaml |
Minimum liquidity floors, credit limits, covenant proximity | Workstream I (F5) |
| Candidate geo pool | config/f4_geo_candidates.yaml |
Permissible regions, spend perturbation caps, excluded markets | Workstream F (F4) |
| Creative asset access | Multimodal asset store permissions | Training creative component models | Workstream G (F1) |
Once configured, the system executes the 90-Day Pilot in observe-only mode (Days 1–30), generating verifiable ValidationPassports and lift metrics required to advance through the Three-Gate Evidence Maturity Framework and unlock higher autonomy levels.
Workstream Dependency Graph
WS-0 Governance & Canon ─────┬──→ WS-A Intent Engine v2 ──→ WS-G F1 Creative ←── Owner: Asset Access
│ (I-03 lane)
└──→ WS-B ValidationPassport ──┐
├──→ WS-E Decision Jobs & Pilot ←── Owner: Pilot Tenant
Owner: Cost Config ──→ WS-C Net Yield ──┬─────────────────────┘ │
├──→ WS-D F3 Supply-Chain │
└──→ WS-H F2 LTV Regimes ←────┤←── WS-F (2 cycles)
│
Owner: Geo Pool ──→ WS-F F4 Geo Cal ←───┘
Owner: Treasury ──→ WS-I F5 Treasury (parallel)
Build sequencing logic: - Foundation first: WS-0 and WS-B are prerequisites — every downstream workstream writes passports and uses ratified vocabulary. - Prove-and-price before predict-and-expand: WS-C must price conversions before WS-D can compute inventory-adjusted recommendations and before WS-H can evaluate multi-quarter contribution margins. - Calibrate before autonomy: WS-F must complete ≥ 2 clean cycles before WS-H publishes long-horizon findings. - Owner inputs gate frontiers, not each other: WS-I and WS-G have no inter-workstream dependencies — they gate on owner-provided configuration and can build in parallel. - Every frontier enters at observe or recommend: Nothing spend-affecting promotes past calibration gates (Brier ≤ 0.20, AUC ≥ 0.72, ≥ 2 purchase cycles). - Every phase ships a sellable artifact: Pilot report, calibration certificate, decision-job SLA, margin reconciliation.
The 90-Day Growth Control Pilot — Standard Commercial Onboarding
Adopted as standard by owner ruling 2026-08-19. The pilot is both the sales motion and the proof motion.
| Phase | Days | Activity | Deliverable | Autonomy |
|---|---|---|---|---|
| Observe | 1–30 | Connect agreed stack. Baseline data quality. Define target Decision Jobs. Zero live changes. | Baseline data-quality report; connected-stack inventory | L0 |
| Validate | 31–60 | Synthetic-control geo experiments. CATE calibration. Propensity verification. Margin reconciliation vs customer books. | Calibrated model card; first verified lift findings; margin reconciliation | L0–L1 |
| Recommend | 61–90 | Decision proposals with complete audit trails. Human-approved. Every prediction graded against outcomes. | Decision proposals with ValidationPassports; pilot completion report | L1–L2 |
Three-Gate Evidence Maturity Framework
- Gate 1 — Demonstrable Logic: The live public Signal Factory demo. Raw connector events travel all seven SRPVDAL stages including one deliberate guardrail block.
- Gate 2 — Pilot Validation: 90-Day Pilot on live systems with calibrated models and verified margin economics. The pilot report is the Gate 2 artifact.
- Gate 3 — Expansion: L3/L4 execution authority within caps. Criteria: Brier ≤ 0.20, AUC ≥ 0.72, stable incremental lift across ≥ 2 purchase cycles, zero governance violations, margin reconciliation within tolerance.
The pilot that closes a customer is the same machine that produces the verified numbers that flip the public Preview labels.
Packaging Ladder
| Tier | Entry | Deliverables | Gate |
|---|---|---|---|
| Signal Factory | Free public demo | Live SRPVDAL walkthrough; truth-delta preview | Gate 1 |
| 90-Day Growth Control Pilot | Paid | Calibrated models, first lift findings, margin reconciliation, passports | Gate 2 |
| Signal Operations | Annual | J-01–J-06 under chosen autonomy tier; standing F4 recalibration | Gate 2+ |
| Enterprise Growth Control | Annual | + F2 LTV, F3 supply-chain, F5 treasury; Capital/Counsel/Risk interlock | Gate 3 |
Growth Control Completion Specification v1.1 · August 20, 2026
Companion to: Whitepaper r3.5.1 + Amendment r3.5.2 + Growth Control r2.0/r2.1
Ground truth: docs/architecture/CELL_REGISTRY.md (cells), production/service-registry.yaml (services), src/shared/virtuoso_models/WIRING.md (wiring)