SUPERSEDED by docs/marketing/MIZOKI_MARKETING_AUTOMATION_WHITEPAPER_r2.0_SEP2026.md

MIZ OKI 3.5 — Marketing Automation Architecture

Techniques, Processes, and the Governance That Bounds Them

Version: r1.2 · August 2026 Changelog r1.2: added the Clipped-ReLU DEL Authorization Function (§8.1) — the evidence-to-authorization mapping is a named platform process, canonical in architecture/DEL_AUTHORIZATION_FUNCTION.md; corrected §4.1, which had mislabeled ReLU as generic-only; Frontiers F1–F5 updated to PARTIAL (built flag-off in the 2026-08-19 completion run, activation gated on pilot configuration); summary table refreshed accordingly. Changelog r1.1: ghost bids corrected from "technique in use" to PROPOSED (implementation plan only, not claimed on any customer-facing surface); per-module retention bounds added to §3.1; MEASUREMENT_WRITEBACK and NET_YIELD_WRITEBACK flag status added to §7. Reconciled against the gated live surface at mizoki3.com/marketing. Companion documents: MIZOKI_3.5_WHITEPAPER_r3.5.1_AUG2026.md · MIZOKI_SIGNAL_GROWTH_CONTROL_UNIFIED_SYSTEM_r2.0.md · amendment r3.5.2 Amendments: MIZOKI_MARKETING_AUTOMATION_WHITEPAPER_r1.3_AMENDMENT_AUG2026.md (§13, extended capabilities U1–U9) · MIZOKI_MARKETING_AUTOMATION_WHITEPAPER_r1.4_AMENDMENT_AUG2026.md (§14, cross-domain integration) — base stands; amendments add sections and never override this document's labels. Status vocabulary used throughout: LIVE (deployed and measured) · PARTIAL (shipped, incomplete surface) · IN BUILD (active development, not serving) · PROPOSED (designed, unapproved)


1. The Problem This Architecture Solves

Marketing automation has a measurement problem that no amount of automation fixes: the systems that spend the money also grade the results. Every ad platform reports conversions it believes it caused. Those reports overlap, double-count, and systematically flatter the reporting platform. Automating decisions on top of self-graded numbers automates the error.

MIZ OKI's position is narrow and specific:

Other tools optimize the number your ad platform reports. MIZ OKI optimizes the number your bank account reports.

Everything below serves that sentence. The automation techniques are conventional in places — the discipline around what those techniques are permitted to conclude is not.


2. SRPVDAL — The Seven-Phase Loop [LIVE]

Every decision the platform makes traverses seven phases. The phase is recorded in JourneyEvent provenance, so any output can be traced back through the reasoning that produced it.

Phase Function
Sense Ingest signals — journey events, platform telemetry, first-party commerce data
Reason Infer state: intent, stage, segment, latent hypothesis
Plan Generate candidate interventions
Validate Apply statistical, causal, policy, and creepiness gates
Decide Select or withhold — withholding is a first-class outcome
Act Execute through channel adapters, or request execution authority
Learn Write realized outcomes back; recalibrate

The critical structural choice is PLAN and VALIDATE sitting between REASON and DECIDE. A system that reasons then decides will act on any confident inference. A system that must plan candidates and pass them through gates can produce a confident inference and still decline to act on it. Most of this document is about that gap.

Note on legacy naming: older documents reference a five-phase "SRDAL" loop. SRPVDAL is authoritative — it is encoded in the JourneyEvent provenance Phase enum. Legacy references map forward by inserting PLAN and VALIDATE.


3. Signal Acquisition [LIVE — cells 33–36]

Four dedicated cells carry the intent pipeline, deployed and IAM-locked:

Cell Service Function
33 intent-signal-ingest Micro-signal capture and validation
34 intent-scoring-api Intent scoring and session sequence modeling
35 intent-graph Firestore-backed intent graph, latent bridges
36 intent-causal Incrementality and causal credit

Cell 37 (Data Injector) is existing brownfield infrastructure carrying external market signal as corroboration only.

Cell 28 is a legacy cell and was not repurposed. Intent scoring lives in Cell 34. Any document binding intent capability to Cell 28 is stale.

3.1 What is captured [PARTIAL]

Content-free behavioral signal: viewport deceleration, dwell duration, scroll velocity relative to user baseline, swipe vectors, partial watch depth, inline expansion pauses, tab blur/return, and form lifecycle events (form_started, field_focused, form_completed, form_abandoned) with coarse allowlisted field classes.

Signals are ordered into sequences with ULID sequence identifiers, batched client-side (25 events / 5s / pagehide, sendBeacon fallback) through the existing Shopify Web Pixel — extended, never duplicated by a second collector.

Retention is bounded per module, not by a global policy:

No persistent psychological dossier is created. The system recognizes a sequence within a session; it does not accumulate a profile across sessions.

3.2 What is permanently refused [LIVE — owner ruling O-1]

Rejected at the collector and again at ingestion, tagged DISALLOWED_KEYSTROKE_DYNAMICS:

These are discarded at ingest, not stored-and-unsurfaced. Tests prove both directions: permitted lifecycle events validate, every rejected class fails with an explicit tag. This is a permanent owner ruling, not a configuration default — it cannot be flipped by a flag.

The reason is strategic as much as ethical. A capability you can be pressured into enabling is a liability on every enterprise security review. A capability the schema refuses is an asset.


4. Inference: Intent Engine v2 [IN BUILD]

Five modules convert signal into bounded inference.

Module Function
I-01 PassiveAttentionSequence Ordered micro-behavior stream within an active session
I-02 SessionOutcomeForecast Probability of stage transition within a bounded horizon
I-03 CreativeSemanticProfile Multimodal creative embeddings mapped to interaction history
I-04 IntentHypothesis Latent bridges between non-obvious entity clusters
I-05 ValidationPassport Evidence packet accompanying every decision

4.1 The session sequence model [IN BUILD]

Cell 34 runs a compact causal transformer encoder — four layers, 128 dimensions, four attention heads — over tokenized behavior. Tokens are (signal_type, element_class, VDI bucket, dwell bucket, Δt bucket). No raw text or URLs enter the token stream.

Three heads: stage-transition-within-horizon, calibrated next-interest, and hesitation.

On architecture internals: the encoder's feedforward blocks use standard ReLU-family activations — ordinary neural network machinery. Separately, and not to be confused with it, ReLU has a platform-specific role in authorization: the Decision Eligibility Layer's authorization function takes a clipped-ReLU form (see §8 and architecture/DEL_AUTHORIZATION_FUNCTION.md, which governs). The model is CPU-sized to hold a p95 latency budget under 200ms, with a benchmark test enforcing it.

Labels come from the existing realized-outcome loop. Attention summaries join the explanation payload — an intent score is never served as a bare number. If the system cannot explain the inference, it does not surface the inference.

4.2 Creative-aesthetic alignment [IN BUILD]

Multimodal encoders vectorize creative variants into unified.creative_vectors, with per-customer decayed aesthetic-affinity vectors and RESONATED_WITH edges in the intent graph. Ranking sits behind its own flag, with automatic revert to default rotation implemented — not deferred as a TODO.

4.3 Latent bridges [IN BUILD — hypothesis-only]

The graph builds temporary bridge nodes linking disconnected behaviors into inferred states — B2B hiring research plus CRM pricing visits suggests an organizational scaling phase rather than two unrelated keyword triggers.

Bridges carry support, confidence, 30-day TTL, provenance, and status. hypothesis is the only writable status. Promotion to targetable requires separate owner approval. Deny-list screening runs at bridge creation, with tests proving sensitive composites (gym attendance plus meal-replacement purchase, for instance) are rejected at write time rather than filtered at read time.


5. Causal Measurement — The PROVE Loop [PARTIAL]

This is the layer that distinguishes the platform from optimization tooling.

5.1 Attribution is not causation

Last-click, first-click, linear, time-decay, and data-driven attribution all answer "which touchpoints preceded conversion?" None answers "which spend caused conversion that would not otherwise have occurred?" The second question is the only one with budget implications.

5.2 Techniques in use

Qualified holdouts — registered before activation, with power analysis, contamination checks, and outcome-integrity validation preceding the test window.

Geo holdouts — matched-market designs with owner-configured aggregate geographies, exclusions, donors, and caps.

Ghost bids [PROPOSED] — a design exists (GHOST_BID_HOLDOUT_IMPLEMENTATION_PLAN.md) for entering auctions the platform deliberately declines to win, constructing a counterfactual matched on auction dynamics rather than observable traits. This is an implementation plan, not a shipped technique, and is not claimed on any customer-facing surface.

Intention-to-treat — measured on assignment, not on delivery, so delivery failure cannot masquerade as ineffectiveness.

CATE meta-learners — S-, T-, X-, and DR-learner families estimating conditional average treatment effects, surfacing where lift concentrates rather than reporting a single blended average that describes no actual segment.

Automated refutation — every causal estimate is subjected to DoWhy refutation tests: placebo treatment, random common cause, data subset validation. An estimate that survives no refutation test is not reported as a finding.

5.3 The Causal Credit Ledger [PARTIAL]

Conversions are classified as caused or anticipated. A model that correctly predicts a purchase that would have happened anyway has demonstrated forecasting skill and contributed zero incremental revenue. Two principles are enforced in code:

Anticipation is never credit. Prediction never grades itself.

Holdout registration is mandatory before any activation. Not after, not concurrently.


6. Net Yield — The PROFIT Loop [IN BUILD]

Platform ROAS measures revenue against ad spend. It excludes payment processing, fulfillment, shipping, returns, discount liability, and cost of goods. Campaigns can therefore optimize toward negative-contribution revenue while every dashboard reports success.

Net yield modeling pulls true unit economics from commerce data (net_yield_costs.yaml) and computes contribution after all downstream costs. In v1 this runs NET_YIELD_WRITEBACK=false — recommendation only, with a test that fails the build if the flag is flipped without approval.

Missing required costs leave a row incomplete and excluded. Costs are never invented to complete a calculation.


7. Channel Automation and Execution Rails

Surface Function Status
Measurement rails Server-side conversion transmission — Meta CAPI, Enhanced Conversions, GA4 Measurement Protocol PARTIAL
Google Ads adapter Budget, status, bid management; PMax and Smart Bidding signal shaping PARTIAL
Meta adapter Campaign structure, custom/lookalike audiences, Advantage+ value optimization PARTIAL
Commerce integration Shopify order, margin, and inventory truth PARTIAL
Lifecycle Klaviyo segment and flow coordination PARTIAL
Creative deployment DCO, variant rotation, fatigue detection IN BUILD

Every adapter defaults to observe-only. Execution authority is a separate, explicitly granted permission. The system's normal posture toward a live ad account is to watch, model, and recommend.

Two writeback flags govern whether modeled outputs may leave the platform:

Each requires its own verified pilot and separate approval before it can be enabled. Neither flips as a side effect of any other change.


8. Decision Jobs and the Decision Control Plane [IN BUILD]

Automation is expressed as a registry of High-Value Decision Jobs (J-01 … J-06) — recurring, high-consequence questions the system answers on a cadence: budget reallocation, creative retirement, audience expansion, bid posture, inventory-aware pacing, spend suppression.

Each job runs through the Decision Control Plane, which enforces:

  1. Does a ValidationPassport exist with sufficient evidence?
  2. Does the DEL Score clear threshold?
  3. Is the required authority granted for this action class?
  4. Does any governance gate veto?

A job that fails any check produces a WITHHOLD verdict with reasoning — a documented decision not to act, which is the output the architecture is proudest of.

A DEL score never overrides a failed hard constraint. Missing evidence routes to hold, named veto, or human review. Authority is never inferred from a model score.

8.1 The Clipped-ReLU DEL Authorization Function

The mapping from evidence to authorized action takes the form of a clipped ReLU — and the shape is the policy:

The canonical specification is architecture/DEL_AUTHORIZATION_FUNCTION.md, which governs over this summary. The reason it earns a customer-facing paragraph: most autonomy systems make authority a smooth function of model confidence, which means enough confidence eventually buys any action. The clipped function makes two refusals structural — the refusal to act on thin evidence, and the refusal to exceed granted authority no matter how certain the model is.

8.2 ValidationPassport [IN BUILD]

Every decision carries an evidence packet: signals used, model versions, causal estimate with refutation results, confidence bounds, consent basis, retention window, and governing rulings. An analyst can reconstruct any decision without access to the person who made it.


9. The Five Frontiers [PARTIAL — built flag-off, activation gated]

Machinery for all five frontiers was built in the 2026-08-19 completion run (independently verified; see reports/GC_COMPLETION_BUILD_2026-08-19.md). They are governed implementations, not live capabilities: configuration is intentionally null pending pilot inputs, and every activation path is gated as below.

ID Capability Gating condition
F1 Creative unbundling — isolating which creative element drives lift Estimates labeled provisional until pilot creative volume is reached
F2 LTV regime detection Machinery builds now; findings withheld until ≥2 observed quarters
F3 Supply-chain sync — pacing against real inventory Observe-only; a no-dispatch invariant is enforced by test
F4 Automated micro-geo calibration Per-geo reservation requires explicit approval until 2 clean cycles
F5 Treasury gating — spend against liquidity constraints v1 uses owner-declared config floors; fails closed

F4 sequences before F1. F4 cannot be observe-only by nature — reserving a geography is an action — so per-action approval is its control mechanism.


10. Governance as Architecture

Governance is not a compliance chapter appended to a technical document. It is the load-bearing differentiator.

Consent gate — no consent, no persistence. Analytics-only consent rejects behavioral signal. Enforced by test matrix.

GDPR erasure cascade — deletion propagates through every table, vector, graph edge, and derived artifact. Every new field joins the cascade test suite as a condition of merge.

Creepiness deny-list — screening at inference creation, not at display. Sensitive composites are refused at write time.

Observe-only default — every capability ships flag-off. Flags off produce byte-identical serving behavior, asserted by test.

Shadow deployment — predictions write to shadow tables and are never served; bridges write as hypotheses and are never targeted; creative ranks log and never apply.

Three-level rollback — flag revert without deploy; revision revert with recorded pre-deploy revision IDs; additive-only schema changes so old events still validate.

10.1 Autonomy gates

Automated action requires, without exception:

A model that misses any threshold recommends. It does not act. There is no override path that bypasses these numbers.

10.2 Claim discipline as machinery

Truth discipline is enforced structurally rather than by intention: automated content QA gating in CI, status labels on every capability claim, illustrative scenario numbers labeled as such, and a public claim ledger. Preview labels flip to verified claims only after pilot numbers enter the ledger.

The governing policy is build-to-claim: when copy and capability diverge, the resolution is to build the capability. Never to soften the copy.


11. Onboarding: The 90-Day Growth Control Pilot

Standard onboarding, structured in three gates:

Gate 1 — Observe. Instrumentation, signal validation, baseline establishment. No actions taken. Gate 2 — Prove. First registered holdout. Causal estimates produced and refuted. Recommendations issued; humans execute. Gate 3 — Control. Bounded execution authority granted for action classes that have cleared autonomy gates across at least two purchase cycles.

Most platforms sell Gate 3 on day one. The sequence is the product.


12. Summary

Layer What it does Status
SRPVDAL loop Seven-phase decision pipeline with provenance LIVE
Cells 33–36 Intent ingest, scoring, graph, causal LIVE
Signal capture Content-free behavioral sequences, bounded retention PARTIAL
O-1 prohibitions Schema-level refusal of audio/keystroke/gaze LIVE
Intent Engine v2 Five-module bounded inference IN BUILD
Causal measurement Qualified holdouts, CATE, refutation battery PARTIAL
Causal Credit Ledger Caused vs. anticipated classification PARTIAL
Net yield Contribution after true unit economics IN BUILD
Channel adapters Google, Meta, GA4, Shopify, Klaviyo PARTIAL
Decision Control Plane Passport + clipped-ReLU DEL authorization + authority gating PARTIAL
Frontiers F1–F5 Creative, LTV, supply, geo, treasury PARTIAL (flag-off, config-gated)
Ghost bids Auction-matched counterfactual construction PROPOSED

The through-line: the system is designed to be trusted with authority it does not yet have, by demonstrating restraint with the authority it does.


All capability claims in this document carry status labels. Scenario figures elsewhere in MIZ OKI materials are labeled illustrative and are not production telemetry or customer results. Platform business targets (CAC reduction, ROAS improvement, ROI) are stated goals, not measured outcomes, and will not be presented as results until verified pilot numbers enter the claim ledger.

← All docsView source on GitHub →