MIZ OKI Media · Causal Growth Control · executive demo
Other tools optimize the number your ad platform reports.
We optimize the number your bank account reports.
Twenty minutes, five acts, one synthetic brand. Each act answers a question a CFO or CMO actually asks, with a control you can touch. Nothing on this screen is a customer result — it is the demo tenant, watermarked, deterministic, and labeled with what is live today and what is still being built.
Net yield and the ORACLE intent surfaces are Preview · in development. Every figure on every act is illustrative — the synthetic tenant demo-fixtures, never a customer result.
The system is designed to be trusted with authority it does not yet have — by demonstrating restraint with the authority it does.
The arc
20 min · exec cut 5 min- 01The Lie · Is our ROAS real?Net yield
- 02The Signals · What do you see before the click — and refuse to see?ORACLE
- 03The Proof · Which conversions did we cause?Causal
- 04The Profit · Where does the next dollar go?Dosage
- 05The Restraint · What stops it doing something stupid?DCP
- 06The 90 Days · How do we start, and what is real today?Pilot
← → move between acts · N talk track · B boardroom type · 1–6 jump
Act 1 · The Lie · 3 min
Same campaign. 4.2× reported ROAS. Negative contribution after returns.
The systems that spend the money also grade the results. Every platform reports the conversions it believes it caused; none of them subtracts refunds, cost of goods, fees or fulfillment. Automating on top of a self-graded number automates the error.
Net yield is Preview · in development (writeback OFF). Every figure on this stage is illustrative — the synthetic tenant, never a customer result.
Profit-Leak Report · top SKUs
| SKU | Ad spend | Reported ROAS | Returns | Contribution after all costs | Result |
|---|
Method: revenue − refunds/returns (actuals only until one cycle per SKU) − COGS − payment fees − fulfillment − ad spend. A row missing a required cost is excluded and named; a cost is never invented to complete the arithmetic. Source: net_yield + order_economics · demo-fixtures.
Touch it: the hero SKU
SKU-DEMO-7742This month, whole catalog
We don't optimize the number the dashboard reports. We optimize the number the bank account reports — and we show you which SKUs your ads are currently paying to lose money on.
Act 2 · The Signals · 4 min
Anticipatory intent from content-free signal. Never mind-reading.
ORACLE reads how a consented session behaves — viewport deceleration, dwell, tab blur and return, form lifecycle — and forms a calibrated, expiring hypothesis about where that session is heading. It never reads what was typed, said, or looked at. What the system refuses to learn matters as much as what it learns.
Intent Engine v2 is Preview · in development — cells 33–36 are deployed and observe-only; nothing here acts. Every figure on this stage is illustrative.
A consented session, replayed
Analytics-only consent rejects every behavioral signal at the collector. Nothing is persisted, nothing is scored, nothing is "stored and unsurfaced". The consent gate precedes persistence — it is architecture, not a setting.
Session outcome forecast
I-02 · shadowProbability of a stage transition inside the session horizon. Served with its uncertainty and an explanation path — never as a bare number.
- ·Hesitation headhigh attention, no click — surfaces a posture recommendation, not a push—
- ·Matched creative rank“technical proof” variant ranked #1 — logged, not applied (flag off)—
- ·Hypothesis TTLexpires with the session; no cross-session profile is written—
The O-1 moment
Privacy lock · live · owner rulingTry to give the system something it must not have. This payload is what a keystroke-dynamics vendor would send. Press the button on stage.
{ "signal_type": "keystroke_dynamics",
"dwell_ms": [112, 98, 143], "flight_ms": [61, 77],
"cadence_profile": "…", "field": "card_number" }
Bright lines — rejected at the schema, not in a policy PDF
- ✕Keystroke dynamicsraw keyboard, entered text, dwell/flight time, typing profilesrefused
- ✕Audio of any kindrejected at Pydantic validation — no flag can enable itrefused
- ✕Gaze, biometrics, fine-grained locationcoarse consent-scoped region onlyrefused
- ✕Sensitive-topic inferencehealth, sexuality, religion, financial distress, minors — never predicted, stored or surfaceddeny-list
- ✓Content-free lifecycle onlyform_started · field_focused · form_completed · form_abandonedpermitted
A capability you can be pressured into enabling is a liability on every security review. A capability the schema refuses is an asset.
Act 3 · The Proof · 4 min
Anticipation is never credit. Prediction never grades itself.
Attribution answers "which touchpoints preceded the sale?" Only a registered experiment answers "which spend caused a sale that would not otherwise have happened?" — the only question with budget implications. Register the holdout first, estimate second, refute third. An estimate that fails refutation is withheld, not softened.
Every figure on this stage is illustrative — the synthetic tenant demo-fixtures, never a customer result. The causal core is PARTIAL; ghost bids are PROPOSED.
1 · Register the holdout
Causal core · partialRegistered before the first impression — never retroactively. Assignment is a deterministic hash of customer + experiment; ACT cells consult the assignment before serving. Intention-to-treat: measured on assignment, not delivery.
2 · Estimate with uncertainty
X-/DR-learner · CATE3 · Refutation battery
DoWhy- ·Placebo treatmenta fake treatment must show no effect—
- ·Random common causeestimate must survive an added confounder—
- ·Data subsetestimate must hold on random halves—
- ·Deterministic identity onlyprobabilistic household edges excluded from causal math—
Causal Credit Ledger · this campaign, this cycle
unified.causal_credit_ledger · partialAct 4 · The Profit · 4 min
Your profit-maximizing spend is $4,048 a day. Not your budget.
Net yield turns platform revenue into contribution after every downstream cost. The dosage curve then asks the marginal question: at what daily spend does the last dollar of incremental margin equal the last dollar of cost? It answers with confidence intervals — and refuses to extrapolate past the spend it has actually observed.
Net yield is Preview · in development (writeback OFF). Every figure on this stage is illustrative — d* included; the dosage lane is advisory.
Net-yield waterfall · hero campaign, month
Net yield · in build · writeback off- !Discount liabilitynot declared by the tenant — row excluded, named as an onboarding gap; never estimatedexcluded
Dosage curve · cumulative contribution vs daily spend
continuous dosage · partial · advisoryMethod: r_learner_local_marginal_moment_wls_v1 · observed support $1,200–$9,500/day. Outside support the curve returns no estimate. Advisory posture: NET_YIELD_WRITEBACK is off; nothing here bids.
Every other tool spends to the budget. This one spends to the profit-maximizing dollar — and tells you, with intervals, how much of today's budget is past it.
Act 5 · The Restraint · 4 min
A decision the system was proudest not to make.
Every proposed move runs the Decision Control Plane: does a ValidationPassport exist with enough evidence, does the DEL score clear the floor, is authority granted for this action class, does any hard constraint veto? Below the floor the answer is a deterministic WITHHOLD with the constraint named. No confidence buys its way past a hard constraint.
Every dollar figure on this stage is illustrative — the synthetic tenant, never a customer result. The DEL formula and the 80.0 platform floor are the shipped operating defaults, not scenario numbers.
Proposed action
DCP · threshold gate · liveGovernance challenge
floors never loweredTry to drag it below 80. Tenants may raise a floor; the platform floor of DEL ≥ 80 cannot be lowered by anyone — including us.
ValidationPassport
VP-—Shipped score: 100 × (0.5 · passport pass rate + 0.3 · evidence completeness + 0.2 · verification weight), HMAC-signed at the DCP. The clipped-ReLU shape (margin-proportional authority, per-class cap) is PROPOSED CANON — drawn dashed, not claimed.
Pick an action.
Restraint Ledger · this month
WITHHOLD verdicts + passportsDecisions the system declined to make, with the reason. No competitor can show you their refusals.
| When | Proposal | Withheld by | Spend not moved |
|---|
F4 micro-geo reservation · live, halting at approval
F4 · live · armed 2026-08-24The one frontier that cannot be observe-only — reserving a geography is an action — so its control is per-action human approval until two clean cycles. Watch a demo-tenant reservation hit every gate.
- ·flag_gateF4_CALIBRATION is not "true" for the demo tenant — nothing submitted—
- ·approval_gateroutes to the L2 decision queue — human approval required—
- ·two_key_gateactuator not registered — an approved decision still cannot execute—
At deploy, the canon gate corrected our own whitepaper's stale datastore reference before it could publish. Restraint is not a feature we bolted on. It is how the platform is built — including how it builds itself.
Close · The 90 Days · 1 min
Most platforms sell Gate 3 on day one. The sequence is the product.
Autonomy is earned per account and per action class — never a global switch. The pilot's product is evidence about your own decisions; whichever exit you choose, you keep it.
Observe
- Connect scoped media, commerce and site sources
- Validate identities, timestamps, unit economics
- No recommendations, no actions
Validate
- First registered holdout; estimates produced and refuted
- Counterfactuals including no-action
- Humans execute everything
Recommend → bounded control
- Narrow, reversible, human-approved actions
- Predicted vs realized scored openly
- Executive scorecard
Autonomy gates — no override path
A model that misses any threshold recommends. It does not act. Today the AUC gate cannot even be scored: the live tables hold zero admissible forward labels — so the intent cell observes. That gap is on this slide on purpose.
What is real today
OFFERING_MAP v2.3 · §B.6| SRPVDAL loop · Decision Control Plane · DEL scoring · audit ledger | live |
| Connector gateway · canonical envelope · O-1 privacy lock | live |
| F4 micro-geo calibration (pilot armed 2026-08-24 · every reservation L2-approval-gated · bounded autonomy after 2 clean cycles, 0 complete) | live |
| Causal proof core · credit ledger · measurement rails | partial |
| ORACLE cells 33–36 · intent edges (observe-only / shadow) | partial |
| Intent Engine v2 · Net Yield lane · F1 F2 F3 F5 | in build |
| Ghost bids · clipped-ReLU authorization shape · ad control plane | proposed |
IN BUILD rows — Intent Engine v2, the Net Yield lane, F1, F2, F3, F5 — are Preview · in development. Every label here is OFFERING_MAP v2.3 §B.6 on the day this page shipped, never this deck's opinion.
Tell us the decision that costs you the most when it goes ungoverned. We scope the two pilot decision classes around it, start observe-only, and put the first registered holdout in front of you by day 31.