Product operating system

How I coordinate strategy, agents, evidence, and human judgment.

MIN–MAX became more than a product prototype. It became a practical operating system for turning ambiguous product problems into bounded decisions, independent evidence, controlled releases, and reusable learning.

Specialized AI-assisted and automated workflows support research, implementation, Quality Assurance (QA), governance, and evidence collection. I retain ownership of product strategy, prioritization, risk, validation, and release decisions.

Skip the spatial view and use the accessible operating model
Interactive evidence map · executive progressive-disclosure view

One mission. Bounded roles. Independent evidence.

The Full Map contains 91 public-safe evidence nodes and 174 evidence-labelled relationships. These are canonical roles, workstreams, gates, incidents, lessons and outcomes—not 91 employees or autonomous agents.

View density
Relationship layers
Accessible outline

Failure classification · plain language first

How we classify a failure

Identify the failing layer before choosing a fix. A product, test, evidence harness, integration pipeline and deployed environment answer different questions.

Product defect

The product behaves incorrectly, contradicts its intended decision model, creates a dead end, or presents an unsafe or misleading customer state.

Public-safe example
A page displays “Review work-from-home requirement” even though the environment cannot execute the work-from-home question.
Customer consequence
The visitor reaches a dead end or receives an untrustworthy decision.
Remediation boundary
May require product remediation.
Inspect related evidence: WFH dead-end action

Test defect

The test expectation, fixture, locator, or assertion is incorrect even though the intended product behavior works.

Public-safe example
A diagnostic expected the message field’s accessible name to equal one exact string even though the field was correctly labelled and described.
Customer consequence
Delivery is blocked by faulty evidence rather than faulty product behavior.
Remediation boundary
May require test remediation.
Inspect related evidence: Independent Exact-Head Quality Assurance (QA)

Evidence-harness defect

The mechanism used to create or retain evidence fails before it can validly judge the product.

Public-safe example
An evidence package could not start because its output directory or attestation-output contract was invalid.
Customer consequence
The product remains unadjudicated; no pass or failure may be inferred.
Remediation boundary
Requires valid evidence before judging the product.
Inspect related evidence: Authenticated evidence limitation

Continuous-integration defect

The automated integration pipeline, test runner, or build orchestration changes or destabilizes the evidence environment.

Public-safe example
Automatic Continuous Integration (CI) Git-diff capture changed the checkout to a shallow repository after browser tests, invalidating later source-custody checks.
Customer consequence
Release evidence cannot be trusted until the pipeline behavior is corrected.
Remediation boundary
Requires pipeline or test-runtime remediation.
Inspect related evidence: Source-custody drift

Environment defect

The deployed or test environment is incompatible with the approved source, schema, runtime, access, viewport, or binding contract.

Public-safe example
A QA database lacked required foundational tables, so the customer journey could not be executed end to end.
Customer consequence
Product behavior remains unproven in that environment.
Remediation boundary
Requires environment reconciliation or a new environment.
Inspect related evidence: D1 schema incompatibility
A later green run does not erase retained failed evidence. It shows that the corrected candidate passed its own exact gate.

Programme glossary

QA, CI and agent-simulation codes

Quality Assurance (QA)QA
QA means Quality Assurance. The independent validation activity or role that challenges source and intended product behavior. Quality Engineering is the broader team or function. Quality Assurance is the independent validation activity or role; neither label is a claim of extra staffed headcount.
Open related role or evidence
Continuous Integration (CI)CI
CI means Continuous Integration. Automated source, build, test, security, and evidence checks performed when changes are integrated. CI may block release. CI cannot approve its own exception. A passing CI check does not replace human product ownership or UAT.
Open related role or evidence
Agent Customer-Journey Simulation (M2A)M2A
M2A means Agent Customer-Journey Simulation. A deterministic agent simulation that exercises frozen personas across required product paths. M2A can expose path defects and contradictions, but it cannot establish human understanding.
Open related role or evidence
Agent Customer-Journey Simulation, Round 2 (M2A-R2)M2A-R2
M2A-R2 means Agent Customer-Journey Simulation, Round 2. A deterministic second-round simulation that evaluates frozen personas across required product paths. Official M2A-R2 is not executed and not authorized. It is agent simulation, not human research or human-comprehension evidence.
Open related role or evidence
15nodes in system executive view
Loading the optional spatial layer…
System legendTeam functionAgent / workstreamEvidence gateIncident / learningOutcomeCurrentHistoricalFuture / not authorized
Relationship legendAuthorityHandoffBlockerLearningDependencyIndependent reviewAuthorization
Guided story · 8 chapters

How Ola turns ambiguity into a product operating system

Readiness is not a percentage

Seven independent evidence layers

A pass at one layer cannot authorize another. Current blockers stay visible.

  1. 01Source readypassed
  2. 02Exact deploymentblocked
  3. 03Agent Customer-Journey Simulation — Round 2not authorized
  4. 04M2H Human Comprehension Researchnot started
  5. 05Live AI evidencenot authorized
  6. 06External betanot authorized
  7. 07Productionnot authorized

Accessible operating model

The complete system, without the canvas.

The full 91-node evidence model remains here regardless of visual density. Every role identity, responsibility, handoff, gate, incident, lesson, contingency and outcome is available without WebGL.

Product mission

1
  • MIN–MAX LivingMIN–MAX · MIN–MAX operating system · explicit · currentMIN–MAX Living. operations. Broader team: MIN–MAX operating system. Mission: Help renters make trustworthy apartment decisions. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Help renters make trustworthy apartment decisions.

    Protects

    • Help renters make trustworthy apartment decisions.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Accountable product decision ownership
    • Product source reaches the first evidence layer

    Remaining blockers

    • Environment compatibility
    • Human comprehension
    • Live-AI evidence
    • External beta

Accountable product leadership

1
  • Ola Sobo — Accountable Product OrchestratorOla Sobo · Executive Accountability & Risk · explicit · currentOla Sobo — Accountable Product Orchestrator. accountable-owner. Broader team: Executive Accountability & Risk. Mission: Own product strategy, prioritization, risk, validation and release decisions. Decision boundary: May not convert missing evidence into a pass; Does not claim personal execution of every test or source line.

    Own product strategy, prioritization, risk, validation and release decisions.

    Protects

    • Own product strategy, prioritization, risk, validation and release decisions.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Set strategy and priorities
    • Accept or reject bounded risk
    • Authorize merge, deployment, rollback and expansion separately
    • Cannot: May not convert missing evidence into a pass
    • Cannot: Does not claim personal execution of every test or source line

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Accountable product decision ownership
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights
    • Defines the team boundary and decision rights

Product-company functions

14
  • Product Leadership / Product ManagementPL · Product Leadership / Product Management · evidence-derived · currentProduct Leadership / Product Management. governance. Broader team: Product Leadership / Product Management. Mission: Frames the renter decision, sequence and value boundary. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Frames the renter decision, sequence and value boundary.

    Protects

    • Frames the renter decision, sequence and value boundary.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
  • Product Engineering / EngineeringPE · Product Engineering / Engineering · evidence-derived · currentProduct Engineering / Engineering. execution. Broader team: Product Engineering / Engineering. Mission: Builds bounded, testable product behavior. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Builds bounded, testable product behavior.

    Protects

    • Builds bounded, testable product behavior.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Quality EngineeringQE · Quality Engineering · evidence-derived · currentQuality Engineering. independent-review. Broader team: Quality Engineering. Mission: The broader quality function; Quality Assurance (QA) is its independent validation activity or role. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    The broader quality function; Quality Assurance (QA) is its independent validation activity or role.

    Protects

    • The broader quality function; Quality Assurance (QA) is its independent validation activity or role.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • User Acceptance & Product OperationsUAT · User Acceptance & Product Operations · evidence-derived · currentUser Acceptance & Product Operations. operations. Broader team: User Acceptance & Product Operations. Mission: Tests complete owner journeys in the real environment; unlike Quality Assurance (QA), it validates end-to-end customer acceptance in the exact product context. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Tests complete owner journeys in the real environment; unlike Quality Assurance (QA), it validates end-to-end customer acceptance in the exact product context.

    Protects

    • Tests complete owner journeys in the real environment; unlike Quality Assurance (QA), it validates end-to-end customer acceptance in the exact product context.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
  • User Research & Human ComprehensionUR · User Research & Human Comprehension · evidence-derived · currentUser Research & Human Comprehension. research. Broader team: User Research & Human Comprehension. Mission: Separates Agent Customer-Journey Simulation (M2A) from M2H evidence created with people. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Separates Agent Customer-Journey Simulation (M2A) from M2H evidence created with people.

    Protects

    • Separates Agent Customer-Journey Simulation (M2A) from M2H evidence created with people.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Decision Science and ScoringDS · Decision Science and Scoring · evidence-derived · currentDecision Science and Scoring. execution. Broader team: Decision Science and Scoring. Mission: Protects cost, comparison and scoring integrity. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Protects cost, comparison and scoring integrity.

    Protects

    • Protects cost, comparison and scoring integrity.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Platform & Data OperationsPO · Platform & Data Operations · evidence-derived · currentPlatform & Data Operations. operations. Broader team: Platform & Data Operations. Mission: Protects persistence, runtime and environment compatibility. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Protects persistence, runtime and environment compatibility.

    Protects

    • Protects persistence, runtime and environment compatibility.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Reusable remediation control
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Security & Privacy GovernanceSG · Security & Privacy Governance · evidence-derived · currentSecurity & Privacy Governance. governance. Broader team: Security & Privacy Governance. Mission: Keeps access, evidence and claims bounded. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Keeps access, evidence and claims bounded.

    Protects

    • Keeps access, evidence and claims bounded.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Reusable remediation control
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Release Assurance & Source CustodyRA · Release Assurance & Source Custody · evidence-derived · currentRelease Assurance & Source Custody. governance. Broader team: Release Assurance & Source Custody. Mission: Binds source, tests, deployment and rollback. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Binds source, tests, deployment and rollback.

    Protects

    • Binds source, tests, deployment and rollback.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Reusable remediation control
    • Canonical role mapped from audited workstream evidence
  • Accessibility and Inclusive DesignAX · Accessibility and Inclusive Design · evidence-derived · currentAccessibility and Inclusive Design. governance. Broader team: Accessibility and Inclusive Design. Mission: Makes every decision path usable beyond the canvas. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Makes every decision path usable beyond the canvas.

    Protects

    • Makes every decision path usable beyond the canvas.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Reusable remediation control
    • Canonical role mapped from audited workstream evidence
  • AI Product and Model EvaluationAI · AI Product and Model Evaluation · evidence-derived · currentAI Product and Model Evaluation. governance. Broader team: AI Product and Model Evaluation. Mission: Keeps live model value measurable and gated. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Keeps live model value measurable and gated.

    Protects

    • Keeps live model value measurable and gated.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
  • Legal, Provider Rights & RiskLR · Legal, Provider Rights & Risk · evidence-derived · currentLegal, Provider Rights & Risk. governance. Broader team: Legal, Provider Rights & Risk. Mission: Protects consent, data rights and permitted use. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Protects consent, data rights and permitted use.

    Protects

    • Protects consent, data rights and permitted use.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Beta & Production OperationsBO · Beta & Production Operations · evidence-derived · currentBeta & Production Operations. operations. Broader team: Beta & Production Operations. Mission: Turns readiness evidence into controlled operations. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Turns readiness evidence into controlled operations.

    Protects

    • Turns readiness evidence into controlled operations.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence
    • Canonical role mapped from audited workstream evidence
  • Executive Accountability & RiskER · Executive Accountability & Risk · evidence-derived · currentExecutive Accountability & Risk. governance. Broader team: Executive Accountability & Risk. Mission: Retains accountable human stop, rollback and expansion rights. Decision boundary: A functional cluster is not a claim of staffed headcount or distinct workstream count..

    Retains accountable human stop, rollback and expansion rights.

    Protects

    • Retains accountable human stop, rollback and expansion rights.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: A functional cluster is not a claim of staffed headcount or distinct workstream count.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Defines the team boundary and decision rights
    • Canonical role mapped from audited workstream evidence

Canonical roles mapped from audited workstreams

31
  • Accountable Product OrchestratorOla · Executive Accountability & Risk · explicit · currentAccountable Product Orchestrator. accountable-owner. Broader team: Executive Accountability & Risk. Mission: Owns strategy, priority, risk acceptance and release decisions. Decision boundary: Cannot turn missing evidence into a pass.

    Owns strategy, priority, risk acceptance and release decisions.

    Discovered workstream instances (3)

    • Apartment Truth Engine owner decisionmerged evidence · Delivered or governed the apartment truth engine owner decision workstream through protected review.
    • D1 owner proxyscoped evidence · Carries the bounded d1 owner proxy responsibility in a frozen policy.
    • M1 owner proxyscoped evidence · Carries the bounded m1 owner proxy responsibility in a frozen policy.

    Protects

    • Owns strategy, priority, risk acceptance and release decisions.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Authorize bounded next stages
    • Cannot: Cannot turn missing evidence into a pass

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Customer-facing verdict
    • Current blockers and reopening conditions
    • Separate exact-head owner decision
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Product Strategy and Journey GovernanceJourney · Product Leadership / Product Management · evidence-derived · currentProduct Strategy and Journey Governance. governance. Broader team: Product Leadership / Product Management. Mission: Freezes the coherent renter journey, scenarios and evidence sequence. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Freezes the coherent renter journey, scenarios and evidence sequence.

    Discovered workstream instances (3)

    • MVP product-gap prioritiesmerged evidence · Delivered or governed the mvp product-gap priorities workstream through protected review.
    • MVP owner-subset evidence crosswalkmerged evidence · Delivered or governed the mvp owner-subset evidence crosswalk workstream through protected review.
    • MVP user-journey and scenario governancemerged evidence · Delivered or governed the mvp user-journey and scenario governance workstream through protected review.

    Protects

    • Freezes the coherent renter journey, scenarios and evidence sequence.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Frozen decision and acceptance boundary
    • Contributes bounded evidence
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Builder / Product Engineering AgentBuilder · Product Engineering / Engineering · explicit · currentBuilder / Product Engineering Agent. execution. Broader team: Product Engineering / Engineering. Mission: Turns bounded product decisions into exact-source candidates. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Turns bounded product decisions into exact-source candidates.

    Discovered workstream instances (3)

    • WFH trust foundationmerged evidence · Delivered or governed the wfh trust foundation workstream through protected review.
    • Version 12 owner-MVP product remediationmerged evidence · Delivered or governed the version 12 owner-mvp product remediation workstream through protected review.
    • Final-product UAT defect remediationmerged evidence · Delivered or governed the final-product uat defect remediation workstream through protected review.

    Protects

    • Turns bounded product decisions into exact-source candidates.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Frozen decision and acceptance boundary
    • Reusable remediation control
    • Exact-source candidate
    • Bounded security review
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
  • Decision Workspace / Product Experience AgentWorkspace · Product Engineering / Engineering · evidence-derived · currentDecision Workspace / Product Experience Agent. execution. Broader team: Product Engineering / Engineering. Mission: Keeps status, blockers and next actions truthful across surfaces. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps status, blockers and next actions truthful across surfaces.

    Discovered workstream instances (2)

    • M2A manager-fixture isolationmerged evidence · Delivered or governed the m2a manager-fixture isolation workstream through protected review.
    • Decision-first workspace remediationmerged evidence · Delivered or governed the decision-first workspace remediation workstream through protected review.

    Protects

    • Keeps status, blockers and next actions truthful across surfaces.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Reusable remediation control
    • Reusable remediation control
    • Reusable remediation control
    • Contributes bounded evidence
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
  • Apartment Truth Engine / Data-Provenance AgentTruth · Platform & Data Operations · explicit · currentApartment Truth Engine / Data-Provenance Agent. execution. Broader team: Platform & Data Operations. Mission: Separates property, unit, quote, source, confidence and authority. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Separates property, unit, quote, source, confidence and authority.

    Discovered workstream instances (1)

    • Apartment Truth Engine feasibilitymerged evidence · Delivered or governed the apartment truth engine feasibility workstream through protected review.

    Protects

    • Separates property, unit, quote, source, confidence and authority.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Reusable remediation control
    • Reconciled facts and authority
    • Contributes bounded evidence
  • True Cost and Cost-State AgentCost · Decision Science and Scoring · explicit · currentTrue Cost and Cost-State Agent. execution. Broader team: Decision Science and Scoring. Mission: Calculates deterministic cost states without inventing missing values. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Calculates deterministic cost states without inventing missing values.

    Discovered workstream instances (2)

    • Owner-UAT cost and evidence remediationmerged evidence · Delivered or governed the owner-uat cost and evidence remediation workstream through protected review.
    • Apartment-input integrity and scoring gatesmerged evidence · Delivered or governed the apartment-input integrity and scoring gates workstream through protected review.

    Protects

    • Calculates deterministic cost states without inventing missing values.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Reconciled facts and authority
    • Reusable remediation control
    • Reusable remediation control
    • Cost readiness and blockers
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
  • Comparison and Like-for-Like AgentCompare · Decision Science and Scoring · evidence-derived · currentComparison and Like-for-Like Agent. execution. Broader team: Decision Science and Scoring. Mission: Blocks false leaders until comparison variance is resolved. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Blocks false leaders until comparison variance is resolved.

    Protects

    • Blocks false leaders until comparison variance is resolved.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Cost readiness and blockers
    • Reusable remediation control
    • Valid comparison membership
    • Contributes bounded evidence
  • V3.1 Scoring and Confidence AgentV3.1 · Decision Science and Scoring · evidence-derived · currentV3.1 Scoring and Confidence Agent. execution. Broader team: Decision Science and Scoring. Mission: Keeps Fit, evidence, confidence and readiness distinct. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps Fit, evidence, confidence and readiness distinct.

    Discovered workstream instances (3)

    • Fit-scale comprehension remediationmerged evidence · Delivered or governed the fit-scale comprehension remediation workstream through protected review.
    • Scoring-comprehension remediationmerged evidence · Delivered or governed the scoring-comprehension remediation workstream through protected review.
    • Offline recommendation calibrationmerged evidence · Delivered or governed the offline recommendation calibration workstream through protected review.

    Protects

    • Keeps Fit, evidence, confidence and readiness distinct.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Valid comparison membership
    • Shadow model cannot replace authority
  • V3.2 Shadow Scoring AgentV3.2 · Decision Science and Scoring · explicit · currentV3.2 Shadow Scoring Agent. execution. Broader team: Decision Science and Scoring. Mission: Measures offline drift without changing authoritative scoring. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Measures offline drift without changing authoritative scoring.

    Discovered workstream instances (1)

    • V3.2 shadow scoring engineactive evidence · Advances shadow scoring evidence without changing the authoritative runtime model.

    Protects

    • Measures offline drift without changing authoritative scoring.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Reusable remediation control
    • Shadow model cannot replace authority
    • Contributes bounded evidence
    • Observable capability evidence
  • Product Integrity AgentIntegrity · Quality Engineering · explicit · currentProduct Integrity Agent. independent-review. Broader team: Quality Engineering. Mission: Uses Continuous Integration (CI) to automate source, build, test, security and evidence checks when changes are integrated. Decision boundary: CI cannot approve its own exception; A passing CI check cannot replace human product ownership or UAT. Related comprehension concepts: Continuous Integration (CI). Definition: Automated source, build, test, security, and evidence checks performed when changes are integrated. Decision/evidence boundary: CI may block release. CI cannot approve its own exception. A passing CI check does not replace human product ownership or UAT. Concept — not a role, agent, employee or headcount record.

    Uses Continuous Integration (CI) to automate source, build, test, security and evidence checks when changes are integrated.

    Discovered workstream instances (1)

    • Functional QA and security hardeningmerged evidence · Delivered or governed the functional qa and security hardening workstream through protected review.

    Protects

    • Continuous Integration (CI). Definition: Automated source, build, test, security, and evidence checks performed when changes are integrated. Decision/evidence boundary: CI may block release. CI cannot approve its own exception. A passing CI check does not replace human product ownership or UAT. Concept — not a role, agent, employee or headcount record.
    • Exact source, build, test, security and evidence integrity

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: A Continuous Integration (CI) result bound to the exact candidate

    Decision boundary

    • Block integration when an automated source, build, test, security or evidence gate fails
    • Cannot: CI cannot approve its own exception
    • Cannot: A passing CI check cannot replace human product ownership or UAT

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Exact-source candidate
    • Exact-head evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Security Baseline AgentSecurity · Security & Privacy Governance · explicit · currentSecurity Baseline Agent. independent-review. Broader team: Security & Privacy Governance. Mission: Runs source, dependency, access and secret controls. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Runs source, dependency, access and secret controls.

    Discovered workstream instances (1)

    • External-access safety gatemerged evidence · Delivered or governed the external-access safety gate workstream through protected review.

    Protects

    • Runs source, dependency, access and secret controls.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Bounded security review
    • Independent security result
    • Contributes bounded evidence
  • Independent Exact-Head Quality Assurance (QA)QA · Quality Engineering · explicit · currentIndependent Exact-Head Quality Assurance (QA). independent-review. Broader team: Quality Engineering. Mission: Quality Assurance (QA) independently validates exact source and intended behavior without inheriting Builder conclusions. Decision boundary: Cannot silently repair the candidate and preserve independence; Cannot infer a product defect from a faulty test assertion. Related comprehension concepts: Test defect. Definition: The test expectation, fixture, locator, or assertion is incorrect even though the intended product behavior works. Public-safe example: A diagnostic expected the message field’s accessible name to equal one exact string even though the field was correctly labelled and described. Customer consequence: Delivery is blocked by faulty evidence rather than faulty product behavior. Remediation boundary: May require test remediation. Concept — not a role, agent, employee or headcount record. Quality Assurance (QA). Definition: The independent validation activity or role that challenges source and intended product behavior. Decision/evidence boundary: Quality Engineering is the broader team or function. Quality Assurance is the independent validation activity or role; neither label is a claim of extra staffed headcount. Concept — not a role, agent, employee or headcount record.

    Quality Assurance (QA) independently validates exact source and intended behavior without inheriting Builder conclusions.

    Protects

    • Test defect. Definition: The test expectation, fixture, locator, or assertion is incorrect even though the intended product behavior works. Public-safe example: A diagnostic expected the message field’s accessible name to equal one exact string even though the field was correctly labelled and described. Customer consequence: Delivery is blocked by faulty evidence rather than faulty product behavior. Remediation boundary: May require test remediation. Concept — not a role, agent, employee or headcount record.
    • Quality Assurance (QA). Definition: The independent validation activity or role that challenges source and intended product behavior. Decision/evidence boundary: Quality Engineering is the broader team or function. Quality Assurance is the independent validation activity or role; neither label is a claim of extra staffed headcount. Concept — not a role, agent, employee or headcount record.
    • Independent exact-head Quality Assurance (QA) judgment

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: An independent source-and-behavior verdict with exact evidence custody

    Decision boundary

    • Block advancement when exact source or intended product behavior fails
    • Cannot: Cannot silently repair the candidate and preserve independence
    • Cannot: Cannot infer a product defect from a faulty test assertion

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Exact-head evidence
    • Independent security result
    • Merge-safe candidate for deployed review
    • Finding and customer consequence
    • Finding and customer consequence
    • Contributes bounded evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Customer-Trust Adversarial QA AgentTrust QA · Quality Engineering · evidence-derived · currentCustomer-Trust Adversarial QA Agent. independent-review. Broader team: Quality Engineering. Mission: Finds contradictions, dead ends and cross-surface drift. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Finds contradictions, dead ends and cross-surface drift.

    Discovered workstream instances (2)

    • Version 14 owner-trust remediationmerged evidence · Delivered or governed the version 14 owner-trust remediation workstream through protected review.
    • Version 9 deployed-integrity remediationmerged evidence · Delivered or governed the version 9 deployed-integrity remediation workstream through protected review.

    Protects

    • Finds contradictions, dead ends and cross-surface drift.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Finding and customer consequence
    • Finding and customer consequence
    • Contributes bounded evidence
    • Observable capability evidence
  • User Acceptance & Product Operations AgentUAT · User Acceptance & Product Operations · explicit · currentUser Acceptance & Product Operations Agent. operations. Broader team: User Acceptance & Product Operations. Mission: Exercises complete authenticated owner journeys after independent QA and preserves acceptance and cleanup evidence. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Exercises complete authenticated owner journeys after independent QA and preserves acceptance and cleanup evidence.

    Discovered workstream instances (3)

    • Version 12 blocked-path evidence controlsmerged evidence · Delivered or governed the version 12 blocked-path evidence controls workstream through protected review.
    • Owner-UAT governancemerged evidence · Delivered or governed the owner-uat governance workstream through protected review.
    • Disabled-foundation owner-UAT evidencemerged evidence · Delivered or governed the disabled-foundation owner-uat evidence workstream through protected review.

    Protects

    • Exercises complete authenticated owner journeys after independent QA and preserves acceptance and cleanup evidence.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Merge-safe candidate for deployed review
    • Customer-facing verdict
    • Finding and customer consequence
    • Finding and customer consequence
    • Finding and customer consequence
    • Finding and customer consequence
  • Agent Customer-Journey Simulation — Round 2M2A-R2 · User Research & Human Comprehension · explicit · futureAgent Customer-Journey Simulation — Round 2. research. Broader team: User Research & Human Comprehension. Mission: A deterministic second-round Agent Customer-Journey Simulation (M2A) that evaluates frozen personas across required product paths without claiming human evidence. Decision boundary: Cannot claim human validation, human comprehension or completed user research; Cannot self-authorize official M2A-R2 execution. Related comprehension concepts: Agent Customer-Journey Simulation (M2A). Definition: A deterministic agent simulation that exercises frozen personas across required product paths. Decision/evidence boundary: M2A can expose path defects and contradictions, but it cannot establish human understanding. Concept — not a role, agent, employee or headcount record. Agent Customer-Journey Simulation, Round 2 (M2A-R2). Definition: A deterministic second-round simulation that evaluates frozen personas across required product paths. Decision/evidence boundary: Official M2A-R2 is not executed and not authorized. It is agent simulation, not human research or human-comprehension evidence. Concept — not a role, agent, employee or headcount record.

    A deterministic second-round Agent Customer-Journey Simulation (M2A) that evaluates frozen personas across required product paths without claiming human evidence.

    Discovered workstream instances (2)

    • Version 11 M2A execution packagemerged evidence · Delivered or governed the version 11 m2a execution package workstream through protected review.
    • M2A exact-path evidence harnessmerged evidence · Delivered or governed the m2a exact-path evidence harness workstream through protected review.

    Protects

    • Agent Customer-Journey Simulation (M2A). Definition: A deterministic agent simulation that exercises frozen personas across required product paths. Decision/evidence boundary: M2A can expose path defects and contradictions, but it cannot establish human understanding. Concept — not a role, agent, employee or headcount record.
    • Agent Customer-Journey Simulation, Round 2 (M2A-R2). Definition: A deterministic second-round simulation that evaluates frozen personas across required product paths. Decision/evidence boundary: Official M2A-R2 is not executed and not authorized. It is agent simulation, not human research or human-comprehension evidence. Concept — not a role, agent, employee or headcount record.
    • Deterministic agent-simulation evidence kept separate from human evidence

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: A frozen persona-by-path Agent Customer-Journey Simulation — Round 2 result

    Decision boundary

    • Expose deterministic path defects and contradictions when separately authorized
    • Cannot: Cannot claim human validation, human comprehension or completed user research
    • Cannot: Cannot self-authorize official M2A-R2 execution

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Accepted environment required first
    • Simulation does not replace human evidence
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence

    Remaining blockers

    • Official M2A-R2 is not executed and not authorized
  • M2H Human Comprehension Research / Research OperationsM2H · User Research & Human Comprehension · evidence-derived · futureM2H Human Comprehension Research / Research Operations. research. Broader team: User Research & Human Comprehension. Mission: Owns future human-comprehension study gates and stop decisions that cannot be inferred from simulation. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Owns future human-comprehension study gates and stop decisions that cannot be inferred from simulation.

    Discovered workstream instances (3)

    • M1 and M2H owner-proxy preparationmerged evidence · Delivered or governed the m1 and m2h owner-proxy preparation workstream through protected review.
    • M2H precontact operating packagemerged evidence · Delivered or governed the m2h precontact operating package workstream through protected review.
    • M2H study sponsor and owner proxyscoped evidence · Carries the bounded m2h study sponsor and owner proxy responsibility in a frozen policy.

    Protects

    • Owns future human-comprehension study gates and stop decisions that cannot be inferred from simulation.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Simulation does not replace human evidence
    • Human and live-AI lanes remain separate
    • Contributes bounded evidence
  • Recruitment CoordinatorRecruit · User Research & Human Comprehension · explicit · futureRecruitment Coordinator. research. Broader team: User Research & Human Comprehension. Mission: Keeps future contact records separate from research evidence. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps future contact records separate from research evidence.

    Discovered workstream instances (1)

    • M2H recruitment coordinatorscoped evidence · Carries the bounded m2h recruitment coordinator responsibility in a frozen policy.

    Protects

    • Keeps future contact records separate from research evidence.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
  • Human ModeratorModerator · User Research & Human Comprehension · explicit · futureHuman Moderator. research. Broader team: User Research & Human Comprehension. Mission: Uses a neutral script and records first responses before probing. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Uses a neutral script and records first responses before probing.

    Discovered workstream instances (1)

    • M2H moderatorscoped evidence · Carries the bounded m2h moderator responsibility in a frozen policy.

    Protects

    • Uses a neutral script and records first responses before probing.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Independent Research AnalystAnalyst · User Research & Human Comprehension · explicit · futureIndependent Research Analyst. research. Broader team: User Research & Human Comprehension. Mission: Codes pseudonymous observations without contact-data access. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Codes pseudonymous observations without contact-data access.

    Discovered workstream instances (1)

    • M2H analystscoped evidence · Carries the bounded m2h analyst responsibility in a frozen policy.

    Protects

    • Codes pseudonymous observations without contact-data access.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Independent AdjudicatorAdjudicator · Security & Privacy Governance · explicit · currentIndependent Adjudicator. independent-review. Broader team: Security & Privacy Governance. Mission: Recomputes gates without operating the run being judged. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Recomputes gates without operating the run being judged.

    Discovered workstream instances (2)

    • M1 independent adjudicatorscoped evidence · Carries the bounded m1 independent adjudicator responsibility in a frozen policy.
    • M2H independent adjudicatorscoped evidence · Carries the bounded m2h independent adjudicator responsibility in a frozen policy.

    Protects

    • Recomputes gates without operating the run being judged.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Finding and customer consequence
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
  • X-05 Accessibility and Viewport AgentX-05 · Accessibility and Inclusive Design · explicit · currentX-05 Accessibility and Viewport Agent. governance. Broader team: Accessibility and Inclusive Design. Mission: Keeps emulation, exact-source automation and physical corroboration distinct. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps emulation, exact-source automation and physical corroboration distinct.

    Discovered workstream instances (2)

    • Version 14 X-05 trust governancemerged evidence · Delivered or governed the version 14 x-05 trust governance workstream through protected review.
    • M2H accessibility coordinatorscoped evidence · Carries the bounded m2h accessibility coordinator responsibility in a frozen policy.

    Protects

    • Keeps emulation, exact-source automation and physical corroboration distinct.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Three-layer viewport evidence not executed
    • Finding and customer consequence
    • Observable capability evidence
  • Capability and Risk Governance AgentGovernance · Security & Privacy Governance · explicit · currentCapability and Risk Governance Agent. governance. Broader team: Security & Privacy Governance. Mission: Maintains independent readiness dimensions and reopening conditions. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Maintains independent readiness dimensions and reopening conditions.

    Discovered workstream instances (6)

    • Version 12 non-live preparationmerged evidence · Delivered or governed the version 12 non-live preparation workstream through protected review.
    • Post-harness capability-risk governancemerged evidence · Delivered or governed the post-harness capability-risk governance workstream through protected review.
    • Capability-readiness governancemerged evidence · Delivered or governed the capability-readiness governance workstream through protected review.
    • Planning-governance packagemerged evidence · Delivered or governed the planning-governance package workstream through protected review.
    • Authorized-enrichment governance clarificationmerged evidence · Delivered or governed the authorized-enrichment governance clarification workstream through protected review.
    • Live-provider governance recordmerged evidence · Delivered or governed the live-provider governance record workstream through protected review.

    Protects

    • Maintains independent readiness dimensions and reopening conditions.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Current blockers and reopening conditions
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
  • Source-Custody / Release AgentCustody · Release Assurance & Source Custody · explicit · currentSource-Custody / Release Agent. independent-review. Broader team: Release Assurance & Source Custody. Mission: Binds commit, tree, application, workflows, deployment and rollback. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Binds commit, tree, application, workflows, deployment and rollback.

    Discovered workstream instances (3)

    • Authenticated QA build provenancemerged evidence · Delivered or governed the authenticated qa build provenance workstream through protected review.
    • Main-governance recordmerged evidence · Delivered or governed the main-governance record workstream through protected review.
    • Branch-protection verificationmerged evidence · Delivered or governed the branch-protection verification workstream through protected review.

    Protects

    • Binds commit, tree, application, workflows, deployment and rollback.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Separate exact-head owner decision
    • Protected merge and deployment custody
    • Finding and customer consequence
    • Contributes bounded evidence
    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • D1 Read and Environment-Reconciliation AgentD1 · Platform & Data Operations · explicit · currentD1 Read and Environment-Reconciliation Agent. operations. Broader team: Platform & Data Operations. Mission: Reconciles environment identity and schema using bounded read-only evidence. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Reconciles environment identity and schema using bounded read-only evidence.

    Discovered workstream instances (5)

    • Owner-only D1 inspection routemerged evidence · Delivered or governed the owner-only d1 inspection route workstream through protected review.
    • D1 owner-proxy recoverymerged evidence · Delivered or governed the d1 owner-proxy recovery workstream through protected review.
    • D1 Read runner preparationmerged evidence · Delivered or governed the d1 read runner preparation workstream through protected review.
    • Version 13 D1 and X-05 reconciliationmerged evidence · Delivered or governed the version 13 d1 and x-05 reconciliation workstream through protected review.
    • D1 Read execution operatorscoped evidence · Carries the bounded d1 read execution operator responsibility in a frozen policy.

    Protects

    • Reconciles environment identity and schema using bounded read-only evidence.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Future least-privilege secure input
    • Independent reconciliation review
    • Schema compatibility unresolved
    • Finding and customer consequence
    • Observable capability evidence
    • Observable capability evidence
  • Credential Custodian / Revocation AgentCredential · Security & Privacy Governance · explicit · currentCredential Custodian / Revocation Agent. governance. Broader team: Security & Privacy Governance. Mission: Keeps ephemeral credentials out of evidence and proves revocation. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps ephemeral credentials out of evidence and proves revocation.

    Discovered workstream instances (3)

    • D1 credential and revocation custodianscoped evidence · Carries the bounded d1 credential and revocation custodian responsibility in a frozen policy.
    • M1 credential custodianscoped evidence · Carries the bounded m1 credential custodian responsibility in a frozen policy.
    • M1 kill-switch operatorscoped evidence · Carries the bounded m1 kill-switch operator responsibility in a frozen policy.

    Protects

    • Keeps ephemeral credentials out of evidence and proves revocation.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Future least-privilege secure input
    • Contributes bounded evidence
  • Evidence Reviewer / Custody AgentEvidence · Security & Privacy Governance · evidence-derived · currentEvidence Reviewer / Custody Agent. independent-review. Broader team: Security & Privacy Governance. Mission: Checks provenance, privacy, retention and cleanup independently. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Checks provenance, privacy, retention and cleanup independently.

    Discovered workstream instances (3)

    • Authenticated evidence-recovery decisionmerged evidence · Delivered or governed the authenticated evidence-recovery decision workstream through protected review.
    • Authenticated-UAT bounded owner decisionmerged evidence · Delivered or governed the authenticated-uat bounded owner decision workstream through protected review.
    • D1 independent evidence reviewerscoped evidence · Carries the bounded d1 independent evidence reviewer responsibility in a frozen policy.

    Protects

    • Checks provenance, privacy, retention and cleanup independently.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Independent reconciliation review
    • Finding and customer consequence
    • Contributes bounded evidence
    • Observable capability evidence
  • M1 Live-AI Readiness / Model-Evaluation AgentM1 · AI Product and Model Evaluation · explicit · futureM1 Live-AI Readiness / Model-Evaluation Agent. governance. Broader team: AI Product and Model Evaluation. Mission: Keeps a frozen live-model benchmark disabled until separately authorized. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Keeps a frozen live-model benchmark disabled until separately authorized.

    Discovered workstream instances (6)

    • M1 owner-decision packagemerged evidence · Delivered or governed the m1 owner-decision package workstream through protected review.
    • Deterministic live-candidate test clockmerged evidence · Delivered or governed the deterministic live-candidate test clock workstream through protected review.
    • Live-activation candidate controlsmerged evidence · Delivered or governed the live-activation candidate controls workstream through protected review.
    • Evidence-interpreter preparationmerged evidence · Delivered or governed the evidence-interpreter preparation workstream through protected review.
    • M1 model-candidate reviewerscoped evidence · Carries the bounded m1 model-candidate reviewer responsibility in a frozen policy.
    • M1 future benchmark operatorscoped evidence · Carries the bounded m1 future benchmark operator responsibility in a frozen policy.

    Protects

    • Keeps a frozen live-model benchmark disabled until separately authorized.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Provider-Rights and Data-Enrichment AgentProvider · Legal, Provider Rights & Risk · explicit · currentProvider-Rights and Data-Enrichment Agent. governance. Broader team: Legal, Provider Rights & Risk. Mission: Evaluates source rights, entity scope, accuracy, cost and kill switches. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Evaluates source rights, entity scope, accuracy, cost and kill switches.

    Discovered workstream instances (4)

    • Provider owner-decision packagemerged evidence · Delivered or governed the provider owner-decision package workstream through protected review.
    • Provider stage owner-decision packagemerged evidence · Delivered or governed the provider stage owner-decision package workstream through protected review.
    • Authorized-data-enrichment pilotmerged evidence · Delivered or governed the authorized-data-enrichment pilot workstream through protected review.
    • Live-provider pilot foundationmerged evidence · Delivered or governed the live-provider pilot foundation workstream through protected review.

    Protects

    • Evaluates source rights, entity scope, accuracy, cost and kill switches.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Live provider rights incomplete
    • Observable capability evidence
  • Legal, Privacy and Fair-Housing Review AgentLegal · Legal, Provider Rights & Risk · evidence-derived · currentLegal, Privacy and Fair-Housing Review Agent. governance. Broader team: Legal, Provider Rights & Risk. Mission: Reviews consent, sharing, protected-data proxies and source rights. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Reviews consent, sharing, protected-data proxies and source rights.

    Discovered workstream instances (2)

    • Provider and legal governance recordmerged evidence · Delivered or governed the provider and legal governance record workstream through protected review.
    • M2H privacy and cleanup operatorscoped evidence · Carries the bounded m2h privacy and cleanup operator responsibility in a frozen policy.

    Protects

    • Reviews consent, sharing, protected-data proxies and source rights.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Signed legal and privacy evidence incomplete
    • Contributes bounded evidence
  • External-Beta Readiness AgentBeta · Beta & Production Operations · explicit · futureExternal-Beta Readiness Agent. operations. Broader team: Beta & Production Operations. Mission: Integrates privacy, support, recovery, rights and metric gates. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Integrates privacy, support, recovery, rights and metric gates.

    Discovered workstream instances (1)

    • External-beta metrics planmerged evidence · Delivered or governed the external-beta metrics plan workstream through protected review.

    Protects

    • Integrates privacy, support, recovery, rights and metric gates.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
    • Observable capability evidence
  • Production Operations / Incident AgentProd Ops · Beta & Production Operations · evidence-derived · futureProduction Operations / Incident Agent. operations. Broader team: Beta & Production Operations. Mission: Owns rollback, severity response, support and post-incident learning. Decision boundary: Cannot self-authorize merge, deployment, beta or production.

    Owns rollback, severity response, support and post-incident learning.

    Discovered workstream instances (6)

    • Domain and launch-operations planmerged evidence · Delivered or governed the domain and launch-operations plan workstream through protected review.
    • Separate QA and restricted production environmentsmerged evidence · Delivered or governed the separate qa and restricted production environments workstream through protected review.
    • Storage-escalation recordmerged evidence · Delivered or governed the storage-escalation record workstream through protected review.
    • Staging recoverymerged evidence · Delivered or governed the staging recovery workstream through protected review.
    • M1 incident commanderscoped evidence · Carries the bounded m1 incident commander responsibility in a frozen policy.
    • M2H incident ownerscoped evidence · Carries the bounded m2h incident owner responsibility in a frozen policy.

    Protects

    • Owns rollback, severity response, support and post-incident learning.

    Inputs and outputs

    • Input: Bounded product scope
    • Input: Exact-source or evidence contract
    • Output: Reviewable source, evidence, finding or decision input

    Decision boundary

    • Act only inside the named functional boundary
    • Cannot: Cannot self-authorize merge, deployment, beta or production

    Primary handoffs

    • Hands exact, reviewable output to the next independent role

    Handoffs and relationships

    • Canonical role mapped from audited workstream evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
    • Observable capability evidence

Independent evidence gates

7
  • Source readyMIN–MAX operating system · explicit · currentSource ready. independent-review. Broader team: MIN–MAX operating system. Mission: Protected source integrates current trust remediations. Decision boundary: Cannot inherit a pass from another evidence layer..

    Protected source integrates current trust remediations.

    Protects

    • Protected source integrates current trust remediations.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Product source reaches the first evidence layer
    • A source pass does not prove deployed behavior
  • Exact deploymentMIN–MAX operating system · explicit · currentExact deployment. independent-review. Broader team: MIN–MAX operating system. Mission: Version 13 is deployed but not accepted; environment compatibility remains unresolved. Decision boundary: Cannot inherit a pass from another evidence layer..

    Version 13 is deployed but not accepted; environment compatibility remains unresolved.

    Protects

    • Version 13 is deployed but not accepted; environment compatibility remains unresolved.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Protected merge and deployment custody
    • A source pass does not prove deployed behavior
    • Schema compatibility unresolved
    • Three-layer viewport evidence not executed
    • Accepted deployment precedes official simulation
    • Accepted environment required first

    Remaining blockers

    • Version 13 is deployed but not accepted; environment compatibility remains unresolved.
  • Agent Customer-Journey Simulation — Round 2MIN–MAX operating system · explicit · futureAgent Customer-Journey Simulation — Round 2. independent-review. Broader team: MIN–MAX operating system. Mission: Official M2A-R2 is not executed and not authorized; this agent simulation is not human evidence. Decision boundary: Cannot inherit a pass from another evidence layer..

    Official M2A-R2 is not executed and not authorized; this agent simulation is not human evidence.

    Protects

    • Official M2A-R2 is not executed and not authorized; this agent simulation is not human evidence.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Accepted deployment precedes official simulation
    • Simulation cannot substitute for human evidence

    Remaining blockers

    • Official M2A-R2 is not executed and not authorized; this agent simulation is not human evidence.
  • M2H Human Comprehension ResearchMIN–MAX operating system · explicit · futureM2H Human Comprehension Research. independent-review. Broader team: MIN–MAX operating system. Mission: No participant activity or human verdict exists; this evidence cannot be inferred from M2A. Decision boundary: Cannot inherit a pass from another evidence layer..

    No participant activity or human verdict exists; this evidence cannot be inferred from M2A.

    Protects

    • No participant activity or human verdict exists; this evidence cannot be inferred from M2A.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Simulation cannot substitute for human evidence
    • Human and model evidence remain separate

    Remaining blockers

    • No participant activity or human verdict exists; this evidence cannot be inferred from M2A.
  • Live AI evidenceMIN–MAX operating system · explicit · futureLive AI evidence. independent-review. Broader team: MIN–MAX operating system. Mission: Model, project, billing, credential and live calls remain absent. Decision boundary: Cannot inherit a pass from another evidence layer..

    Model, project, billing, credential and live calls remain absent.

    Protects

    • Model, project, billing, credential and live calls remain absent.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Human and model evidence remain separate
    • Human and live-AI lanes remain separate
    • Bounded live value required

    Remaining blockers

    • Model, project, billing, credential and live calls remain absent.
  • External betaMIN–MAX operating system · explicit · futureExternal beta. independent-review. Broader team: MIN–MAX operating system. Mission: Current decision is NO-GO. Decision boundary: Cannot inherit a pass from another evidence layer..

    Current decision is NO-GO.

    Protects

    • Current decision is NO-GO.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Bounded live value required
    • Live provider rights incomplete
    • Signed legal and privacy evidence incomplete
    • Evidence-authorized expansion

    Remaining blockers

    • Current decision is NO-GO.
  • ProductionMIN–MAX operating system · explicit · futureProduction. independent-review. Broader team: MIN–MAX operating system. Mission: Production remains unchanged and out of scope. Decision boundary: Cannot inherit a pass from another evidence layer..

    Production remains unchanged and out of scope.

    Protects

    • Production remains unchanged and out of scope.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot inherit a pass from another evidence layer.

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Evidence-authorized expansion

    Remaining blockers

    • Production remains unchanged and out of scope.

Incidents, lessons and contingencies

13
  • Unknown presented as zeroMIN–MAX operating system · explicit · historicalUnknown presented as zero. governance. Broader team: MIN–MAX operating system. Mission: A missing fact appeared certain. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    A missing fact appeared certain.

    Protects

    • A missing fact appeared certain.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Unknown/zero regression fixtures. Historical source defect closed; future deployment proof remains.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
  • Stale quote without actionMIN–MAX operating system · explicit · historicalStale quote without action. governance. Broader team: MIN–MAX operating system. Mission: A stale quote had no recovery action. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    A stale quote had no recovery action.

    Protects

    • A stale quote had no recovery action.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Executable freshness control. Closed in targeted evidence; rerun on the next exact deployment.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
  • Like-for-like bypassMIN–MAX operating system · explicit · historicalLike-for-like bypass. governance. Broader team: MIN–MAX operating system. Mission: Unlike homes could produce a leader. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Unlike homes could produce a leader.

    Protects

    • Unlike homes could produce a leader.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Membership-bound variance control. Historical blocker closed in source; deployment rerun required.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
  • Zero-active comparison contradictionMIN–MAX operating system · explicit · historicalZero-active comparison contradiction. governance. Broader team: MIN–MAX operating system. Mission: The interface claimed an active comparison with no active set. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    The interface claimed an active comparison with no active set.

    Protects

    • The interface claimed an active comparison with no active set.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Canonical state plus signed transient feedback. Historical failed deployment preserved; later source corrected.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence
  • Inclusive total treated as fees-onlyMIN–MAX operating system · explicit · historicalInclusive total treated as fees-only. governance. Broader team: MIN–MAX operating system. Mission: A confirmed inclusive price was presented with the wrong basis. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    A confirmed inclusive price was presented with the wrong basis.

    Protects

    • A confirmed inclusive price was presented with the wrong basis.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Fail-closed cost/presentation boundary. Historical failure closed in source; deployment pending.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
  • WFH dead-end actionMIN–MAX operating system · explicit · historicalWFH dead-end action. Product defect. The product behaves incorrectly, contradicts its intended decision model, creates a dead end, or presents an unsafe or misleading customer state. Customer consequence: The visitor reaches a dead end or receives an untrustworthy decision. Remediation boundary: May require product remediation. Related comprehension concepts: Product defect. Definition: The product behaves incorrectly, contradicts its intended decision model, creates a dead end, or presents an unsafe or misleading customer state. Public-safe example: A page displays “Review work-from-home requirement” even though the environment cannot execute the work-from-home question. Customer consequence: The visitor reaches a dead end or receives an untrustworthy decision. Remediation boundary: May require product remediation. Concept — not a role, agent, employee or headcount record.

    The product advertised an unavailable assessment.

    Protects

    • Product defect. Definition: The product behaves incorrectly, contradicts its intended decision model, creates a dead end, or presents an unsafe or misleading customer state. Public-safe example: A page displays “Review work-from-home requirement” even though the environment cannot execute the work-from-home question. Customer consequence: The visitor reaches a dead end or receives an untrustworthy decision. Remediation boundary: May require product remediation. Concept — not a role, agent, employee or headcount record.
    • The product advertised an unavailable assessment.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Action-availability contract. Closed in protected source; exact deployment pending.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence
  • Shared check-count divergenceMIN–MAX operating system · explicit · historicalShared check-count divergence. governance. Broader team: MIN–MAX operating system. Mission: Owner and shared reports could disagree on readiness. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Owner and shared reports could disagree on readiness.

    Protects

    • Owner and shared reports could disagree on readiness.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Legacy counts fail closed. Closed in protected source; exact deployment pending.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence
  • Version 12 product failuresMIN–MAX operating system · explicit · historicalVersion 12 product failures. governance. Broader team: MIN–MAX operating system. Mission: Setup, variance, risk copy and mobile status diverged. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Setup, variance, risk copy and mobile status diverged.

    Protects

    • Setup, variance, risk copy and mobile status diverged.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Immutable failed evidence plus regression suite. Version 12 remains failed; its source lessons were integrated.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence
  • D1 schema incompatibilityMIN–MAX operating system · explicit · currentD1 schema incompatibility. Environment defect. The deployed or test environment is incompatible with the approved source, schema, runtime, access, viewport, or binding contract. Customer consequence: Product behavior remains unproven in that environment. Remediation boundary: Requires environment reconciliation or a new environment. Related comprehension concepts: Environment defect. Definition: The deployed or test environment is incompatible with the approved source, schema, runtime, access, viewport, or binding contract. Public-safe example: A QA database lacked required foundational tables, so the customer journey could not be executed end to end. Customer consequence: Product behavior remains unproven in that environment. Remediation boundary: Requires environment reconciliation or a new environment. Concept — not a role, agent, employee or headcount record.

    Only 50 of 56 expected tables were visible.

    Protects

    • Environment defect. Definition: The deployed or test environment is incompatible with the approved source, schema, runtime, access, viewport, or binding contract. Public-safe example: A QA database lacked required foundational tables, so the customer journey could not be executed end to end. Customer consequence: Product behavior remains unproven in that environment. Remediation boundary: Requires environment reconciliation or a new environment. Concept — not a role, agent, employee or headcount record.
    • Only 50 of 56 expected tables were visible.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Credential-free D1 read runner. Current blocker: root cause remains unresolved.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence

    Remaining blockers

    • Current blocker: root cause remains unresolved.
  • Authenticated evidence limitationMIN–MAX operating system · explicit · currentAuthenticated evidence limitation. Evidence-harness defect. The mechanism used to create or retain evidence fails before it can validly judge the product. Customer consequence: The product remains unadjudicated; no pass or failure may be inferred. Remediation boundary: Requires valid evidence before judging the product. Related comprehension concepts: Evidence-harness defect. Definition: The mechanism used to create or retain evidence fails before it can validly judge the product. Public-safe example: An evidence package could not start because its output directory or attestation-output contract was invalid. Customer consequence: The product remains unadjudicated; no pass or failure may be inferred. Remediation boundary: Requires valid evidence before judging the product. Concept — not a role, agent, employee or headcount record.

    A normal authenticated capture could not be established.

    Protects

    • Evidence-harness defect. Definition: The mechanism used to create or retain evidence fails before it can validly judge the product. Public-safe example: An evidence package could not start because its output directory or attestation-output contract was invalid. Customer consequence: The product remains unadjudicated; no pass or failure may be inferred. Remediation boundary: Requires valid evidence before judging the product. Concept — not a role, agent, employee or headcount record.
    • A normal authenticated capture could not be established.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Authenticated-evidence contract. Current evidence limitation; not a product pass.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control

    Remaining blockers

    • Current evidence limitation; not a product pass.
  • Viewport evidence limitationMIN–MAX operating system · explicit · currentViewport evidence limitation. governance. Broader team: MIN–MAX operating system. Mission: A mobile claim lacked correctly labelled proof. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    A mobile claim lacked correctly labelled proof.

    Protects

    • A mobile claim lacked correctly labelled proof.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Three-layer evidence contract. Method approved; execution has not run.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
    • Observable capability evidence

    Remaining blockers

    • Method approved; execution has not run.
  • Source-custody driftMIN–MAX operating system · explicit · historicalSource-custody drift. Continuous-integration defect. The automated integration pipeline, test runner, or build orchestration changes or destabilizes the evidence environment. Customer consequence: Release evidence cannot be trusted until the pipeline behavior is corrected. Remediation boundary: Requires pipeline or test-runtime remediation. Related comprehension concepts: Continuous-integration defect. Definition: The automated integration pipeline, test runner, or build orchestration changes or destabilizes the evidence environment. Public-safe example: Automatic Continuous Integration (CI) Git-diff capture changed the checkout to a shallow repository after browser tests, invalidating later source-custody checks. Customer consequence: Release evidence cannot be trusted until the pipeline behavior is corrected. Remediation boundary: Requires pipeline or test-runtime remediation. Concept — not a role, agent, employee or headcount record.

    A deployed source relationship was not reproducible.

    Protects

    • Continuous-integration defect. Definition: The automated integration pipeline, test runner, or build orchestration changes or destabilizes the evidence environment. Public-safe example: Automatic Continuous Integration (CI) Git-diff capture changed the checkout to a shallow repository after browser tests, invalidating later source-custody checks. Customer consequence: Release evidence cannot be trusted until the pipeline behavior is corrected. Remediation boundary: Requires pipeline or test-runtime remediation. Concept — not a role, agent, employee or headcount record.
    • A deployed source relationship was not reproducible.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Exact-source provenance gate. Historical incident closed by later custody controls.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control
  • V3.2 threshold missMIN–MAX operating system · explicit · currentV3.2 threshold miss. governance. Broader team: MIN–MAX operating system. Mission: Shadow rankings exceeded selected drift limits. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Shadow rankings exceeded selected drift limits.

    Protects

    • Shadow rankings exceeded selected drift limits.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Learning

    Non-disruptive shadow gate. Current activation blocker, not a production defect.

    Handoffs and relationships

    • Finding and customer consequence
    • Reusable remediation control

    Remaining blockers

    • Current activation blocker, not a production defect.

Ola capability evidence

14
  • Strategic judgmentMIN–MAX operating system · evidence-derived · currentStrategic judgment. governance. Broader team: MIN–MAX operating system. Mission: Sequences customer value, trust and technical dependencies. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Sequences customer value, trust and technical dependencies.

    Protects

    • Sequences customer value, trust and technical dependencies.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • First-principles framingMIN–MAX operating system · evidence-derived · currentFirst-principles framing. governance. Broader team: MIN–MAX operating system. Mission: Starts with the renter decision and consequence, not a requested feature. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Starts with the renter decision and consequence, not a requested feature.

    Protects

    • Starts with the renter decision and consequence, not a requested feature.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Systems thinkingMIN–MAX operating system · evidence-derived · currentSystems thinking. governance. Broader team: MIN–MAX operating system. Mission: Separates states, evidence layers, exceptions and downstream effects. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Separates states, evidence layers, exceptions and downstream effects.

    Protects

    • Separates states, evidence layers, exceptions and downstream effects.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Technical product fluencyMIN–MAX operating system · evidence-derived · currentTechnical product fluency. governance. Broader team: MIN–MAX operating system. Mission: Works across contracts, scoring, persistence, testing and provenance. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Works across contracts, scoring, persistence, testing and provenance.

    Protects

    • Works across contracts, scoring, persistence, testing and provenance.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Cross-functional orchestrationMIN–MAX operating system · evidence-derived · currentCross-functional orchestration. governance. Broader team: MIN–MAX operating system. Mission: Connects product, engineering, QA, research, security and platform. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Connects product, engineering, QA, research, security and platform.

    Protects

    • Connects product, engineering, QA, research, security and platform.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Risk-based prioritizationMIN–MAX operating system · evidence-derived · currentRisk-based prioritization. governance. Broader team: MIN–MAX operating system. Mission: Uses hard stops, bounded deferrals, immutable evidence and rollback. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Uses hard stops, bounded deferrals, immutable evidence and rollback.

    Protects

    • Uses hard stops, bounded deferrals, immutable evidence and rollback.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Decision-right designMIN–MAX operating system · evidence-derived · currentDecision-right design. governance. Broader team: MIN–MAX operating system. Mission: Agents gather and challenge evidence; people retain consequential authority. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Agents gather and challenge evidence; people retain consequential authority.

    Protects

    • Agents gather and challenge evidence; people retain consequential authority.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Research disciplineMIN–MAX operating system · evidence-derived · currentResearch discipline. governance. Broader team: MIN–MAX operating system. Mission: Keeps simulation, human evidence, operation and adjudication distinct. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Keeps simulation, human evidence, operation and adjudication distinct.

    Protects

    • Keeps simulation, human evidence, operation and adjudication distinct.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Accessibility and inclusionMIN–MAX operating system · evidence-derived · currentAccessibility and inclusion. governance. Broader team: MIN–MAX operating system. Mission: Treats keyboard, viewport, comprehension and lower-numeracy contexts as product evidence. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Treats keyboard, viewport, comprehension and lower-numeracy contexts as product evidence.

    Protects

    • Treats keyboard, viewport, comprehension and lower-numeracy contexts as product evidence.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Responsible AI leadershipMIN–MAX operating system · evidence-derived · currentResponsible AI leadership. governance. Broader team: MIN–MAX operating system. Mission: Keeps live AI reachable but disabled until exact evidence exists. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Keeps live AI reachable but disabled until exact evidence exists.

    Protects

    • Keeps live AI reachable but disabled until exact evidence exists.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Measurement disciplineMIN–MAX operating system · evidence-derived · currentMeasurement discipline. governance. Broader team: MIN–MAX operating system. Mission: Rejects composite passes and keeps denominators and hard gates explicit. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Rejects composite passes and keeps denominators and hard gates explicit.

    Protects

    • Rejects composite passes and keeps denominators and hard gates explicit.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Learning-loop designMIN–MAX operating system · evidence-derived · currentLearning-loop design. governance. Broader team: MIN–MAX operating system. Mission: Turns findings into reusable contracts, regressions and controls. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Turns findings into reusable contracts, regressions and controls.

    Protects

    • Turns findings into reusable contracts, regressions and controls.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Executive communicationMIN–MAX operating system · evidence-derived · currentExecutive communication. governance. Broader team: MIN–MAX operating system. Mission: States what changed, what remains blocked and what is not authorized. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    States what changed, what remains blocked and what is not authorized.

    Protects

    • States what changed, what remains blocked and what is not authorized.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence
  • Scalable operating modelsMIN–MAX operating system · evidence-derived · currentScalable operating models. governance. Broader team: MIN–MAX operating system. Mission: Builds repeatable roles, manifests, scenarios and protected handoffs. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Builds repeatable roles, manifests, scenarios and protected handoffs.

    Protects

    • Builds repeatable roles, manifests, scenarios and protected handoffs.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Observable capability evidence
    • Observable capability evidence
    • Observable capability evidence

Customer and business outcomes

10
  • Customer TrustMIN–MAX operating system · evidence-derived · currentCustomer Trust. operations. Broader team: MIN–MAX operating system. Mission: Canonical state, uncertainty, actionability and parity. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Canonical state, uncertainty, actionability and parity.

    Protects

    • Canonical state, uncertainty, actionability and parity.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Decision ClarityMIN–MAX operating system · evidence-derived · currentDecision Clarity. operations. Broader team: MIN–MAX operating system. Mission: A decision-first experience with one executable next action. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    A decision-first experience with one executable next action.

    Protects

    • A decision-first experience with one executable next action.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Financial IntegrityMIN–MAX operating system · evidence-derived · currentFinancial Integrity. operations. Broader team: MIN–MAX operating system. Mission: Unknown-versus-zero and monthly-price-basis protection. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Unknown-versus-zero and monthly-price-basis protection.

    Protects

    • Unknown-versus-zero and monthly-price-basis protection.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Operational SafetyMIN–MAX operating system · evidence-derived · currentOperational Safety. operations. Broader team: MIN–MAX operating system. Mission: Fail-closed gates, bounded credentials and rollback. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Fail-closed gates, bounded credentials and rollback.

    Protects

    • Fail-closed gates, bounded credentials and rollback.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Release ConfidenceMIN–MAX operating system · evidence-derived · currentRelease Confidence. operations. Broader team: MIN–MAX operating system. Mission: Exact source, protected CI and independent review. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Exact source, protected CI and independent review.

    Protects

    • Exact source, protected CI and independent review.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Human UnderstandingMIN–MAX operating system · evidence-derived · futureHuman Understanding. operations. Broader team: MIN–MAX operating system. Mission: An explicit evidence layer that remains unproven. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    An explicit evidence layer that remains unproven.

    Protects

    • An explicit evidence layer that remains unproven.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Learning VelocityMIN–MAX operating system · evidence-derived · currentLearning Velocity. operations. Broader team: MIN–MAX operating system. Mission: Incidents become reusable regressions and controls. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Incidents become reusable regressions and controls.

    Protects

    • Incidents become reusable regressions and controls.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • ScalabilityMIN–MAX operating system · evidence-derived · currentScalability. operations. Broader team: MIN–MAX operating system. Mission: Repeatable roles, scenarios, contracts and handoffs. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Repeatable roles, scenarios, contracts and handoffs.

    Protects

    • Repeatable roles, scenarios, contracts and handoffs.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Responsible AIMIN–MAX operating system · evidence-derived · currentResponsible AI. operations. Broader team: MIN–MAX operating system. Mission: AI assists evidence while deterministic logic and people retain authority. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    AI assists evidence while deterministic logic and people retain authority.

    Protects

    • AI assists evidence while deterministic logic and people retain authority.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence
  • Evidence-Based GrowthMIN–MAX operating system · evidence-derived · futureEvidence-Based Growth. operations. Broader team: MIN–MAX operating system. Mission: Beta and production expand only after bounded proof. Decision boundary: Cannot self-authorize merge, deployment, beta, production, or unsupported claims.

    Beta and production expand only after bounded proof.

    Protects

    • Beta and production expand only after bounded proof.

    Inputs and outputs

    • Input: Public-safe product-program evidence
    • Output: A bounded, reviewable decision input or evidence result

    Decision boundary

    • Act only within the named responsibility boundary
    • Cannot: Cannot self-authorize merge, deployment, beta, production, or unsupported claims

    Primary handoffs

    • Hands exact, reviewable output to the next accountable or independent role

    Handoffs and relationships

    • Contributes bounded evidence
    • Contributes bounded evidence
    • Contributes bounded evidence

Accessible concept outline

Failure layers and programme codes, without the canvas.

This glossary is part of the complete accessible operating model. It does not add people, agents or evidence nodes.

Product defect
The product behaves incorrectly, contradicts its intended decision model, creates a dead end, or presents an unsafe or misleading customer state. Example: A page displays “Review work-from-home requirement” even though the environment cannot execute the work-from-home question. Customer consequence: The visitor reaches a dead end or receives an untrustworthy decision. May require product remediation.
Test defect
The test expectation, fixture, locator, or assertion is incorrect even though the intended product behavior works. Example: A diagnostic expected the message field’s accessible name to equal one exact string even though the field was correctly labelled and described. Customer consequence: Delivery is blocked by faulty evidence rather than faulty product behavior. May require test remediation.
Evidence-harness defect
The mechanism used to create or retain evidence fails before it can validly judge the product. Example: An evidence package could not start because its output directory or attestation-output contract was invalid. Customer consequence: The product remains unadjudicated; no pass or failure may be inferred. Requires valid evidence before judging the product.
Continuous-integration defect
The automated integration pipeline, test runner, or build orchestration changes or destabilizes the evidence environment. Example: Automatic Continuous Integration (CI) Git-diff capture changed the checkout to a shallow repository after browser tests, invalidating later source-custody checks. Customer consequence: Release evidence cannot be trusted until the pipeline behavior is corrected. Requires pipeline or test-runtime remediation.
Environment defect
The deployed or test environment is incompatible with the approved source, schema, runtime, access, viewport, or binding contract. Example: A QA database lacked required foundational tables, so the customer journey could not be executed end to end. Customer consequence: Product behavior remains unproven in that environment. Requires environment reconciliation or a new environment.
Quality Assurance (QA)
The independent validation activity or role that challenges source and intended product behavior. Quality Engineering is the broader team or function. Quality Assurance is the independent validation activity or role; neither label is a claim of extra staffed headcount.
Continuous Integration (CI)
Automated source, build, test, security, and evidence checks performed when changes are integrated. CI may block release. CI cannot approve its own exception. A passing CI check does not replace human product ownership or UAT.
Agent Customer-Journey Simulation (M2A)
A deterministic agent simulation that exercises frozen personas across required product paths. M2A can expose path defects and contradictions, but it cannot establish human understanding.
Agent Customer-Journey Simulation, Round 2 (M2A-R2)
A deterministic second-round simulation that evaluates frozen personas across required product paths. Official M2A-R2 is not executed and not authorized. It is agent simulation, not human research or human-comprehension evidence.

Evidence-history rule: A later green run does not erase retained failed evidence. It shows that the corrected candidate passed its own exact gate.

Executive view ready. Fifteen decision-critical nodes are shown; the Full Map keeps all ninety-one public-safe nodes available.

A product model, not an agent demo

The value is not the number of agents. It is the quality of the operating decisions.

Specialization creates leverage only when roles, authority and evidence are explicit. A Builder can implement; it cannot approve its own release. QA can stop a candidate; it cannot silently repair it and preserve independence. A simulation can expose deterministic path defects; it cannot claim that people understand the product. The operating system makes those boundaries visible before the work starts.

  • Explicit roles
  • Clear decision rights
  • Independent review
  • Evidence requirements
  • Safe handoffs
  • Reversible releases
  • Learning loops

One product · multiple evidence layers

“Built” is not a synonym for “proven.”

Source readiness, deployed behavior, simulation, human understanding, live-AI value, beta and production answer different questions. They do not form one blended percentage, and a pass at one layer cannot be inherited by another.

Source readyis notdeployed and proven

Deployed and provenis notunderstood by customers

Human understandingis notlive-AI value

Live-AI valueis notexternal-beta readiness

First-principles product leadership

Eight questions turn ambiguity into a governed decision.

  1. 01What decision should improve?
  2. 02What evidence makes it trustworthy?
  3. 03What can fail?
  4. 04Which failure must block progress?
  5. 05Who owns the decision?
  6. 06What can be reversed?
  7. 07What must remain human-owned?
  8. 08What proof authorizes the next stage?

Failure becomes product infrastructure

Findings are not footnotes. They are inputs to the next operating model.

These sanitized examples distinguish historical defects that were closed in source from environment and evidence blockers that remain current.

Zero-active contradiction

Observed
A customer-facing state claimed an active comparison when no apartments were active.
Why it mattered
The decision story contradicted itself at the point of action.
Decision stopped
The candidate version did not advance.
What changed
Comparison state moved to one canonical source.
Permanent control
Cross-surface parity and signed transient-state regressions.

WFH dead-end action

Observed
The next action offered an assessment the environment could not execute.
Why it mattered
The user could not resolve the uncertainty named by the product.
Decision stopped
Source merge paused.
What changed
Action display became conditional on real capability availability.
Permanent control
An explicit action-availability contract.

Shared-readiness divergence

Observed
Owner, comparison, shared and print surfaces could produce different unresolved-check counts.
Why it mattered
A recipient could see a false ready state.
Decision stopped
The trust remediation did not merge at its first head.
What changed
All surfaces consume one canonical count; malformed legacy data fails closed.
Permanent control
Same-candidate owner/share/print/accessibility parity tests.

D1 schema incompatibility

Observed
The deployed QA environment exposed 50 of 56 expected tables.
Why it mattered
Persistence and recovery journeys could not be trusted.
Decision stopped
Version 13 was not accepted.
What changed
A credential-free, read-only reconciliation runner was prepared.
Permanent control
Physical identity, schema, migration, integrity and semantic evidence gates; diagnosis remains unresolved.

Viewport evidence limitation

Observed
A mobile claim lacked evidence that distinguished emulation from an actual window or device.
Why it mattered
Responsive usability could be overstated.
Decision stopped
X-05 remained blocked.
What changed
The method now requires three separately labelled layers.
Permanent control
Authenticated emulation, exact-source automation and non-emulated corroboration cannot substitute for one another.

V3.2 threshold miss

Observed
A shadow scoring candidate exceeded selected ranking-drift thresholds.
Why it mattered
Activation could change decisions unexpectedly.
Decision stopped
V3.1 remained authoritative.
What changed
Calibration stayed offline and non-disruptive.
Permanent control
A hard threshold gate with no composite override.

The people and functions represented

Recognizable product-company functions—not a claim about headcount.

Specialized roles map to Product Management, Engineering, Design and Accessibility, Quality, Product Operations, Research, Decision Science, Platform, Security, Legal and Privacy, Release Assurance, AI Product, and Beta and Production Operations. The map consolidates audited workstream evidence into canonical roles while keeping the distinct aggregate count and provenance method explicit.

Agents are roles—not autonomous executives

Bounded specialists accelerate evidence. Ola retains the decision.

Each agent represents a bounded role or workstream with defined inputs, outputs, decision rights, and prohibitions. Agents accelerate research, implementation, QA, and evidence collection. They do not replace accountable product ownership, accept business risk, or authorize their own merge, deployment, beta, or production decision.

Executive & Investor Lens

A presentation lens for value, risk and scale—not another agent.

The lens summarizes customer value, operating leverage, evidence discipline, current gaps, contingencies, the path to scale, and Ola’s accountable decision ownership. It does not add a new team, infer investment authority, or convert an open readiness layer into a pass.

What this demonstrates about Ola

Capabilities are shown through decisions and controls—not unsupported superlatives.

Strategic judgment

Sequences customer value, trust and technical dependencies instead of optimizing one signal.

Systems thinking

Models teams, states, evidence, exceptions and downstream effects as one operating model.

Cross-functional orchestration

Connects product, engineering, QA, research, security, platform, rights and release roles.

Technical fluency

Works with scoring contracts, persistence, source custody, browser testing, security and deployment evidence.

First-principles thinking

Starts with the renter decision and consequence rather than the requested feature.

Risk and contingency design

Uses stop gates, rollback, immutable failure evidence, alternative paths and bounded deferrals.

Learning velocity

Turns incidents into reusable controls and regression coverage.

Responsible AI leadership

Uses AI-assisted workflows to accelerate evidence while keeping model authority and human decisions explicit.

From owner MVP to scale

Expansion is evidence-authorized—not calendar-authorized.

  1. 01
    Deterministic owner MVPSource-integrated; next accepted deployment remains open.
  2. 02
    Agent Customer-Journey Simulation (M2A)Prepared; official Agent Customer-Journey Simulation, Round 2 (M2A-R2) is not executed, not authorized and not human evidence.
  3. 03
    M2H Human Comprehension ResearchNot started; human evidence cannot be inferred from simulation.
  4. 04
    Bounded live-AI benchmarkDisabled; zero live calls.
  5. 05
    External betaNO-GO until every prerequisite closes.
  6. 06
    ProductionUnchanged and not authorized.

Evidence methodology

Public-safe by design.

This visualization consolidates public-safe evidence from the MIN–MAX product program. Specialized agent roles are grouped into product-company functions. Sensitive identifiers, private user data, credentials and internal evidence paths are excluded. “Explicit,” “evidence-derived,” “inferred” and “proposed” labels preserve the difference between source statements and organizational interpretation.

Pinned tree
516 protected-main files
Mapped workstreams
56 merged + 19 scoped + 1 active
Evidence gaps
9 retained, never averaged away
Operating-system data/model calls
0

First principles, sustained

Build quickly. Learn honestly. Scale only when the evidence supports it.

The system is useful because it can say “not yet,” preserve the reason, and turn that reason into a safer next move.