Architecture

One uncertain boundary. One deterministic core.

The model narrows semantic ambiguity; it never owns the replay result. Invalid or unapproved proposals stop before deterministic execution.

From source rows to evidence

  1. Committed source rows Untrusted input
  2. Schema mapper Fixture proposal
  3. Mapping approval Person · exact proposal hash
  4. Canonical event set Code · re-derived from approved mapping
  5. Dataset profile Code · bounded facts
  6. Bounded case proposer Planned · authored manifests today
  7. Case approval Person · exact scope hash
  8. Replay engine Code · five rule gates
  9. Finding source trace Code · original rows
  10. Evidence Bundle assembly Planned

A refused request carries a review state and no result hash.

01

L1 · Interpret

A constrained mapper proposes targets, transforms, confidence and evidence. Today's provider is a deterministic fixture; live model adapters are planned. It cannot edit rows or decide results.

02

L2 · Approve

A person approves the exact mapping and authored case proposal by hash. Flagged fields require a justified override. Approval cannot edit a computed result.

03

L3 · Decide

Versioned code owns ordering, deduplication, calculation, evaluation, and hashes.

04

L4 · Evidence

The server resolves findings to canonical eventId, rawRowHash, artifact coordinates and unchanged raw values. Unresolvable lineage is refused. INCONCLUSIVE has no finding evidence.

What the canonical hash covers

canonicalReplayResultHash hashes the engine version, semantic event projection and evaluation when present. Volatile run metadata is excluded.

Complete approval records, all mapping and manifest fields, and source trace are not protected by this result hash. A future bundle hash and independent bundle assembly and verification remain planned.

The browser's guide progress is presentation state. Each API replay creates a request-local workflow; durable audit history is not implemented.

Walk through a case