SUPERSEDED — applied 2026-07-31. This update pack was applied in the v3.0 skill rollout; the live skill is
skills/miz-oki-platform-expert/SKILL.md(parity-governed viascripts/skills_sync.py). Retained for history only. Banner added by the v2.2 compliance sweep, 2026-08-12.
miz-oki-platform-expert — SKILL.md v3.0 Update Pack
How to apply: This pack follows the skill's own per-section update mechanism. Replace the sections named below in the existing SKILL.md; insert the new skill sections (16–19) before the Quick Reference section. Everything not named here carries forward from v2.0 unchanged.
REPLACE: Header block
**Version**: 3.0
**Last Updated**: July 12, 2026
**Platform**: MIZ OKI 3.5 (MIZ Operating Knowledge Intelligence)
**Architecture**: 32-cell microservices + shared horizontal services, SRPVDAL framework
**Changelog**:
- v3.0 (2026-07-12): Aligned to Three-Domain Blueprint v2 — SRDAL→SRPVDAL; three Domain Intelligence Cells; Canonical Event Envelope; Validation Passports; Decision Control Plane; decision-object contracts; claims-labeling rule; measurement hierarchy corrected; Data Manager API connector rule; auth hardening requirements
- v2.0 (2026-03-15): Added Boss agent MCP tool mappings; restructured for single-file drop-in update
- v1.0 (2025-10-25): Initial 15-skill comprehensive guide
REPLACE: Overview
This skill guide enables Claude to support the MIZ OKI 3.5 platform — a governed decision-intelligence platform that turns fragmented evidence into validated, explainable, and authorized decisions. The platform is one shared temporal-causal knowledge graph and one Decision Control Plane serving multiple Domain Intelligence Cells; it is not a set of separate products.
Canonical operating loop (SRPVDAL):
Sense → Reason → Plan → Validate → Decide → Act → Learn
Canonical decision pathway:
Evidence → Canonical Event Envelope → Temporal-Causal KG → Domain ReasoningPath
→ Scenario/Forecast/Counterfactual → Validation Passport → Decision Eligibility
→ Authorized Action or Operator Gate → Outcome Learning
Domain Intelligence Cells (example deployments, not a product ceiling): 1. Predictive Financial Intelligence 2. Media Acquisition Intelligence 3. Commercial Real Estate Underwriting & Asset Risk
Key Platform Facts:
- Cells: 32 FastAPI services on Google Cloud Run, plus shared horizontal services (ingestion, identity resolution, provenance/bitemporal lineage, GraphRAG/CausalRAG, counterfactual simulation, model registry, validation orchestrator, policy engine, decision control plane, approval routing, action runner, audit/replay, learning ledger, observability)
- Data: BigQuery (unified dataset), Neo4j (temporal-causal KG), GCS, Pub/Sub, Firestore, Vertex AI
- Frontend: React + TypeScript command center (/command-center, /knowledge-graph, /loops, /decisions, /simulations, /approvals, /audit, /learning, /channels/{finance|media|cre})
- Positioning rule: the platform metaphor is "nervous system," never "brain"
Claims-labeling rule (mandatory): every performance figure written anywhere — docs, code comments, marketing, emails — carries exactly one label: verified result | benchmark result | pilot result | design target | illustrative scenario.
- Business goals (40% CAC reduction, 35% ROAS increase, 67% ROI improvement, 95%+ attribution accuracy): design targets
- Sub-100ms latency, 99.9% availability: design targets until benchmark citations exist
- ACT-991 ($5.0M blocked at DEL 41, re-routed to $3.2M): illustrative scenario — the canonical demo, never presented as a customer result
REPLACE: In Skill 3 (Causal Inference), the "Causal Framework Overview" block
Measurement Hierarchy (evidence strength, ascending):
1. Platform attribution ← one claim, never ground truth
2. First-party journey evidence
3. Causal MMM (Meridian + Robyn run as complements; report divergence)
4. Geo / holdout / randomized experiment evidence (GeoLift or equivalent)
5. Incremental profit after margin, returns, inventory, and cost
← THE decision objective
Meta-learners (X-Learner Cell 26, DR-Learner Cell 27) are estimation tools
inside this hierarchy, not its apex. No model or platform is an oracle.
Also in Skill 3: the "Business Metrics Translation" block figures are design targets — label them as such wherever quoted.
REPLACE: In Skill 4 (FastAPI Backend), the auth guidance
Authentication requirements (supersedes v2.0 template):
- Never deploy a cell with --allow-unauthenticated except the public API gateway.
- Enforce Cloud Run IAM: each calling service account granted roles/run.invoker on exactly the cells it calls.
- Verify Google-signed ID tokens (audience-checked against the receiving cell URL) — never compare bearer tokens to static strings.
from google.auth.transport import requests as ga_requests
from google.oauth2 import id_token
async def verify_oidc_token(authorization: str = Header(None)):
if not authorization or not authorization.startswith("Bearer "):
raise HTTPException(status_code=401, detail="Missing token")
token = authorization.split(" ", 1)[1]
try:
claims = id_token.verify_oauth2_token(
token, ga_requests.Request(), audience=SELF_URL)
return {"service": claims["email"]}
except ValueError:
raise HTTPException(status_code=403, detail="Invalid token")
REPLACE: In Skill 9 (Marketing Attribution), connector rule
Connector rule: all new offline-conversion and enhanced-conversions-for-leads integrations are built on Google's Data Manager API. Legacy Google Ads API conversion-upload behavior is compatibility-only where still permitted, and must not be used for new work.
NEW — Skill 16: Canonical Event Envelope & Bitemporal Ingestion
Purpose
Every event enters the platform through one envelope with four time axes, enabling point-in-time integrity, provenance, and replay.
Core Capabilities
{
"event_id": "stable_hash",
"tenant_id": "tenant",
"domain": "finance | media | cre",
"entity_ids": [],
"source_system": "system",
"source_document_id": "optional",
"occurred_at": "business_effective_time",
"observed_at": "observation_time",
"available_to_model_at": "point_in_time_availability",
"ingested_at": "system_time",
"schema_version": "version",
"source_payload_hash": "hash",
"confidence": 0.0,
"verification_status": "verified | unverified | disputed",
"materiality": "low | medium | high | critical",
"provenance": {},
"audit_id": "audit_record"
}
Best Practices
- Envelope is additive: wrap
service-canonical-ingestionin front of existing SENSE cells; do not rewrite them. - Historical backfill sets
available_to_model_atconservatively to first-ingest time. source_payload_hashcomputed before any transformation.- No model may train or backtest on events filtered by anything other than
available_to_model_at. verification_status: disputedevents surface in contradiction retrieval; they are never silently dropped.
NEW — Skill 17: Validation Orchestration & Validation Passports
Purpose
No candidate decision reaches Decide without a domain-specific Validation Passport issued by service-validation-orchestrator.
Core Capabilities
- Orchestrator runs registered validators per domain; Cell 27 (DoWhy refutation) is one registered validator, not the validation layer.
- Finance passport: point-in-time integrity, survivorship control, leakage control, trial-count tracking, purged/embargoed CV, walk-forward, regime-stratified results, transaction costs, slippage/capacity, PBO, Deflated Sharpe, data-snooping control, uncertainty interval, causal plausibility, contradicting evidence, policy eligibility.
- Media passport: data quality, dedup, consent, identity confidence, attribution maturity, conversion delay, incrementality, MMM, experiments, margin, inventory, fatigue, saturation, cannibalization, fraud, brand safety, rollback.
- CRE passport: evidence completeness, source reliability, point-in-time integrity, rent-roll↔lease match, lease↔ledger match, ledger↔bank reconciliation, NOI normalization, concentration, title/zoning, engineering/environmental, tax reassessment, insurance, market-regime robustness, DSCR/refi gap, sponsor support, valuation cross-check, Monte Carlo calibration, dependency comparison, reverse stress, human-review requirements.
Best Practices
- Passports are immutable, versioned, and attached to the DecisionProof.
- A failed check never silently downgrades — it changes eligibility state.
- Baselines are always run alongside challengers; passports record both.
- Rejected candidate paths are recorded with their failing checks.
- Passport schemas live in the shared contracts package.
NEW — Skill 18: Decision Control Plane, Decision Objects & Staged Autonomy
Purpose
One governed pathway from validated candidate to authorized action.
Core Capabilities
Shared decision objects (versioned JSON Schemas in contracts/):
EvidenceBundle · ReasoningPath · ForecastOrScenario · ValidationPassport
· DecisionProof · ActionAuthorization · OutcomeRecord · LearningRecord
Eligibility state machine:
eligible | approval-required | experiment-required | advisory-only | blocked
Autonomy staging:
- Stage 3 (default for all actuators): observe → explain → simulate → recommend → route for approval.
- Stage 4 (earned per actuator): bounded, reversible, low-risk actions only, after evaluation, approval, rollback, and monitoring are proven.
- Every actuator registers a rollback/compensating action or declares itself irreversible → permanently approval-gated.
- ACT cells hard-refuse any request lacking a valid ActionAuthorization.
Cross-domain flow:
Media proposes growth spend
→ Finance validates cash, margin, payback
→ CRE validates location/lease/capacity where relevant
→ Decision Control Plane approves, gates, or vetoes
Best Practices
- Policy is declarative (policy-as-code), versioned, and replayable.
- Every DecisionProof records rejected alternatives.
- Approvals are routed, timestamped, and attributable to a human identity.
- Audit/replay must reconstruct any decision from evidence forward.
- No model serves a decision path without a model-registry entry and baseline comparison.
NEW — Skill 19: Domain Intelligence Cells — Status & Proof Obligations
Purpose
Track what is built versus what is proven, per cell. Implementation evidence ≠ validated business performance.
Status Ledger
Media Acquisition Intelligence — most mature; production attribution stack live. Open proof obligations: MMM calibration, geo/holdout experiment readouts, incremental-profit validation after margin/returns/inventory joins.
Predictive Financial Intelligence — services (service-financial-tckg, service-macro-regime, service-tgnn-forecast, service-financial-validation-lab) in buildout. Advisory-only until the finance passport battery passes. All outputs are challengers against transparent baselines.
CRE Underwriting & Asset Risk — implementation documented (integration exists, six tools registered, eight-layer engine, Monte Carlo, t-copula, Boss Agent runtime connection). Unproven and must be labeled as such: field extraction accuracy, lease/rent-roll reconciliation accuracy, NOI forecast accuracy, risk-detection recall, probability calibration, committee usefulness, time savings, loss avoidance, post-close surprise reduction. The Chrome Boss Agent extension is point-of-work capture, not the underwriting source of truth. CRE output supports underwriting; it never replaces appraisal, engineering, environmental, legal, fiduciary, lending, or investment-committee authority.
Best Practices
- Before feature work on CRE, run the Stage 2 benchmark battery: extraction benchmark, historical deal reconstruction, adversarial diligence, shadow underwriting, post-close outcomes.
- Never market cross-domain flows until two cells exchange real DecisionProof objects.
- New domains are added as cells on the shared graph — never as separate platforms.
End of v3.0 update pack. Sections not named above carry forward from v2.0 unchanged.