Business Cases that need your attention or have a recent outcome.
Workspace locked.Unlock this browser tab to load Business Cases.
Business Cases could not be loaded.
Open
0
Blocked
0
Critical
0
Decision ready
0
Loading Business Cases
Needs Your Attention
0
Work in progress
0
Scheduled Monitoring
0
Recent Outcomes
0
No Business Cases
Create a case to begin supervised analysis. No mock cases are shown here.
Data connections
Control access to approved analytics sources.
Connections could not be loaded.
Connection
Provider
Status
Last tested
Actions
No data connections
Connect an approved warehouse to start governed analysis.
Governed model access
AI providers
Register credentials, verify a safe probe, approve the registry binding, then activate that binding. The current runtime route is not changed here.
Registry only. Current runtime route unchanged.Activating or revoking a provider binding changes registry metadata only; it does not switch, start, or stop model execution. Per-execution external-model approval remains separate.
AI provider settings could not be loaded.
Registered providers
0 providers
No AI providersSave a provider binding to begin verification.
Bounded AI responsibilities
Model roles
Save registry candidates per role. Activating a role binding records server-gated eligibility; it does not reconfigure the current runtime route.
Registry role bindings only. Current runtime route unchanged.The browser cannot declare a model eligible. Benchmark disposition and registry activation eligibility come only from the server. Per-execution external-model approval remains separate.
Model role assignments could not be loaded.
AI role portfolio
Author and critic roles should use independently evaluated model bindings.
Source discovery
Inspect approved source metadata and prepare a portable semantic draft.
Workspace locked.Unlock this browser tab to load approved connections.
No discovery run
Select a connection and scope to inspect its source metadata.
Inspecting source metadata
Building bounded profiles and evidence.
Discovery unavailable
Approval required
Discovery result
Request
Thread
Evidence
Bounded scan summary
Control plane
Event timeline
Inventory
Discovered sources
Source
Type
Layer
Columns
Reusable BI
Decision
No source objects matched this scope.
Validation
Issues and caveats
No validation issues were reported.
Portable contract
Semantic draft
No semantic draft was generated for this run.
Contracts and releases
Promote validated semantic drafts through immutable approval-bound releases.
Workspace locked.Unlock this browser tab to manage semantic releases.
No release selected
Create or select a semantic release to inspect its immutable snapshot.
Loading release
Release unavailable
Semantic release
Release
Digest
Immutable snapshot
Release metadata
Human gate
Approval decision
Released artifacts
Export generators
Approval required
Generated JSON
Released output
Source of truth
Semantic contract snapshot
Audit trail
Inspect bounded control-plane events and sanitized execution metadata.
Workspace locked.Unlock this browser tab to inspect audit events.
Recent events
Event log
Loading audit events
No audit events match this filter.
Event type
Status
Time
No event selected
Select an audit event to inspect its sanitized payload.
Audit event
Event
Request
Thread
Product guide
Documentation Center
Step-by-step product instructions, setup guides, governance boundaries, and troubleshooting.
Docs 0.12.14
Capability labels are part of the instructions.Implemented, local-only, planned, enabled, held, disabled, and unavailable states are never interchangeable.Operator, Administrator, and Developer are documentation journeys, not permission roles. This build uses an administrator credential plus an optional read-only judge credential; it does not implement RBAC or individual identity.
7 topicsRelease-bound guidance for the selected documentation journey.
Quick Start
Run your first supervised analysis
Implemented
Use this path when a business question needs a reproducible investigation rather than an informal answer.
Unlock the workspace.Enter an administrator or read-only judge token for this browser tab. The token is held in session storage and is cleared when the tab closes.
Open Business Cases.Select an existing case or create one with a concrete question, owner, affected metrics, source scope, and severity.
Ask the AI Curator for a bounded Investigation.Open the AI Curator tab and enter: “Investigate this Business Case and propose a bounded Investigation.” The deterministic responder recognizes “Investigate” and returns a typed proposal when the case context supports it.
Review and confirm the proposal.Check the exact investigation question and source scope, enter a rationale, and confirm. Confirmation creates a planned Investigation and draft Evidence Packet; it runs no query.
Open the Investigation tab.Select the confirmed Investigation and review its analytical question, evidence state, and current blockers.
Complete the Analytical Workplan.Confirm the method, time window, grain, dimensions, evidence requirements, and expected output before validation.
Validate before any effect.Source, semantic, SQL, cost, evidence, and approval checks must pass in order. A model proposal is never execution authority.
Review the result state.Collected evidence, pending human review, Decision Brief preparation, and publication are separate states. Stop when the UI reports a blocker or missing approval.
Expected outcomeThe case shows what is known, what is blocked, which proof exists, and the exact next operator action.
Operator workflow
Business Case Board
Implemented
The board is the product home. It is an attention queue, not a KPI dashboard or task tracker.
Create a case.Choose Create Business Case and record one business condition or question. Use the summary for business context, not a proposed answer.
Set only operator-owned states.You may triage, investigate, block, escalate, dismiss, or reopen within the allowed transitions. Evidence-ready, approved, published, and resolved states require governed artifacts.
Explain blockers.Blocked, escalated, dismissed, and reopened states require a reason. Missing-data blockers must name the unavailable source or field.
Inspect the detail rail.Verify owner, affected metrics and entities, source scope, evidence state, approval need, and next action before continuing.
Operator workflow
Investigation and Analytical Workplan
Implemented
Create through a governed proposal.Use the exact Curator action request shown in Quick Start, review its question and source scope, then confirm it with a rationale. Free-form conversation cannot create an Investigation.
Select the confirmed Investigation.Each Investigation is a bounded analysis inside one Business Case. Do not combine unrelated questions into one Investigation.
Resolve the scope.Confirm metrics, dimensions, filters, comparison, time window, grain, and relevant source objects. Mark unresolved assumptions instead of guessing.
Choose only a supported method.Metric reconciliation is the current implemented method path. Trend, segmentation, cohort/funnel, anomaly, data-quality, and root-cause labels remain planning vocabulary until their own governed implementations pass.
Validate the plan.The deterministic receipt binds the current Business Case, Investigation, source versions, and Semantic Contract release. Any later scope change requires validation again.
Review SQL progressively.The generated SQL Candidate remains a proposal. Static safety validation runs before an administrator-authenticated dry-run; a typed Approval is created only for the later bounded execution effect.
Operator workflow
Bounded evidence collection
ImplementedChecking release gate
The controlled read-only path is implemented, but release authorization is separate from technical readiness. Runtime Effect Authority is a persisted default-deny gate with a global emergency stop. Inspection and reconciliation may remain available; a held effect cannot receive a new Approval or start.
Confirm current authority.The Investigation, Workplan receipt, connection, source version, Semantic Contract release, SQL Candidate, cost receipt, Evidence Packet head, and effect-specific Approval must all match.
Review the exact Approval scope.The dialog loads a server-derived read-only preview of the target, estimate and scan cap, row/result-byte limits, validity, timeout, Packet binding, and any separate model-egress route and guard columns.
Collect only when enabled and approved.The path is read-only and bounded. Raw rows and full result sets are not persisted; an idempotent replay must not create a second warehouse job.
Interpret the state literally.Collected or validating evidence is not Human Evidence Review. Ready, reviewed, Decision Brief, business Decision, and publication remain distinct.
Preview is not ApprovalPreviewing creates no Approval or audit event, persists nothing, and calls neither the warehouse nor the model. Confirmation must reuse the displayed scope digest or fail closed.
Stop conditionIf authority changed, cost exceeded policy, evidence is empty, schema differs, or the Packet revision moved, resolve the blocker and validate again.
Before evidence collection
Can this source support the claim?
Local onlyPlanning only
A healthy connector or registry-approved table is not automatically authoritative for the business claim you are investigating.
Name the exact claim.State the metric, legal entity or business unit, period, timezone, currency, and decision the evidence must support.
Check the source role.Confirm whether the source is authoritative, supporting, diagnostic, or unsuitable for that exact claim. GA4 attribution, for example, is not financial revenue truth.
Match approved versions.The selected Source Registry version and Semantic Contract release must match the Investigation references. Similar names are not enough.
Stop on conflict.If sources disagree, authority is missing, or period/currency/grain differs, record the blocker. Do not choose the most convenient number.
Current boundaryThis build can plan authority and reconciliation deterministically, but it does not yet execute multi-source proof or resolve discrepancies.
Operator workflow
AI Curator conversation
ImplementedDeterministic mode
Ask for context.Use the Curator inside the selected Business Case to explain blockers, summarize governed context, or propose a bounded next step.
Inspect citations and limitations.A response without authoritative references is conversation context, not evidence or semantic truth.
Review typed proposals.Confirm or reject the structured target fields and rationale. Free-form chat cannot directly mutate a Business Case or Investigation.
Expect deterministic fallback.No provider-backed Curator is currently configured. The available responder does not imply autonomous LLM analysis.
Before you rely on an output
Current product limits
Implemented
Human Evidence Review and Decision Brief currentness are composed locally as read-only supervision state; creation and operator actions remain inactive.
Business Decision and Monitoring currentness are local read-only contracts; recording, scheduling, and external effects remain inactive.
Materialization and BI network writes are disabled.
Postgres analytical-source support, immutable spreadsheet snapshots, GA4 reporting, and live cross-source reconciliation are not yet claimed.
No model has passed the frozen evidence-interpretation benchmark; role selection is not proof of quality or permission to send data.
Administrator Quick Start
Configure without granting hidden authority
Implemented
Unlock only your browser tab.Treat the shared administrator token as a shared administrative credential boundary. It proves possession of one credential, not one-person identity, RBAC, or production-grade attribution.
Register connections.Save write-only credentials, test metadata access, and keep inactive connections unavailable to discovery.
Discover and review source metadata.Discovery is bounded and metadata-only. Approve or reject the exact source version separately.
Release semantic truth.Create an immutable Semantic Contract release and record an independent approval decision before governed use.
Configure AI providers separately.Verification, administrative approval, registry activation, role eligibility, and per-execution egress Approval are different gates.
Inspect Audit.Use sanitized event metadata to verify lifecycle and effect history. Never copy secrets into rationale or troubleshooting notes.
Settings
Data connections
ImplementedRegistry only
Open Settings → Connections.Choose Add connection and select BigQuery, Postgres, or REST API. A registered connection is not automatically a governed Source.
Enter an explicit identity.Use a recognizable name and environment. BigQuery requires project and location; Postgres requires host/port/database; REST requires HTTPS base URL, allowed hosts, and allowed path prefixes.
Provide credentials once.Credential fields are write-only, encrypted at rest, and scrubbed from the browser form. They are never returned by the API.
Test the connection.The status must visibly change to connected, warning, or error. Correct the displayed safe error rather than repeatedly rotating credentials.
Activate deliberately.Inactive connections cannot support discovery. Activation still grants no SQL execution, source authority, materialization, or BI-write permission.
REST boundaryThe current connector discovers OpenAPI metadata only. Row ingestion, pagination, cursors, retries, and quarantine are not implemented.
Sources
Discover and govern source metadata
ImplementedMetadata only
Select an active connection.Set strict maximum object and column counts before starting discovery.
Run bounded discovery.The workflow collects metadata without distinct counts or value samples. It must not display private rows.
Inspect inventory and timeline.Review object references, columns, types, grain clues, warnings, and the generated semantic draft.
Record the Source Registry decision.Approve or reject the exact version with a rationale. A later metadata change creates a new version rather than rewriting the approved one.
Do not infer authority.Registry approval establishes an eligible technical object only. Business-claim authority requires the separate Source Fabric governance path.
Source governance
Review source authority
Local onlyPlanning only
Review authority independently from connection health and Source Registry approval. This procedure records governance metadata; it does not read data or create evidence.
Verify the request scope.Require one claim type, metric, legal entity or business unit, period, timezone, currency, extraction or revision, and semantic context.
Verify immutable support.Bind the exact approved Source Registry version, exact approved Semantic Contract release, and bounded supporting artifact references.
Keep duties separate.The requester and decision maker must be different stable subjects. Record the decision once; do not rewrite an earlier immutable decision.
Record the stop condition.Reject or hold when authority, mapping, version, or business scope is incomplete. A technical connection status cannot override the result.
Contracts
Semantic Contract releases
ImplementedOffline outputs
Select the generated draft.Source discovery supplies the semantic draft name, source draft reference, and immutable contract content. Check that you selected the intended draft.
Create a release candidate.Enter Created by and create the immutable snapshot. Initial creation does not ask for an approval rationale.
Review metric truth.Check expressions, grain, dimensions, joins, denominator behavior, access policy, caveats, and provenance before deciding.
Approve or reject independently.Enter the evidence-based rationale in the separate Approval decision. Only an approved release can produce deterministic downstream specifications.
Generate offline artifacts.Superset, Metabase, dbt, Dataform, Looker Studio, Power BI, and LLM-context outputs are specifications only. No target API is called and nothing is published.
Settings
AI providers and model roles
Local onlyRegistry candidate
Choose a provider type.OpenModel, OpenRouter, direct OpenAI-compatible, and explicitly self-hosted profiles are supported by the local registry candidate.
Save the write-only secret.Specify endpoint, protocol, model reference, and local-only binding where applicable. OpenModel catalog entries select their required Messages or Responses protocol; Grok 4.5 remains an unassessed registry candidate. Never paste a key into documentation, rationale, logs, or chat.
Advance one lifecycle gate at a time.Saved unverified → Verified → Approved → Active. Verification proves bounded transport metadata; it does not prove model quality.
Assign a candidate to one role.Roles are Curator dialogue, case intake and planning, SQL author, SQL critic, semantic metric critic, evidence interpretation, and Decision Brief.
Check benchmark eligibility.A role binding may activate only when the exact provider, model, protocol, and task contract have eligible benchmark evidence. Current evidence-interpretation candidates are FAIL or HOLD.
Keep egress approval separate.Registry activation does not start runtime execution and never grants permission to send a Business Case payload to an external model.
Governance
Audit, security, and troubleshooting
Implemented
Filter Audit by exact event type.Select an event to inspect bounded identifiers, status, timestamp, and sanitized JSON.
Follow the object chain.Correlate Business Case, Investigation, Packet revision, approval, execution, and artifact references rather than relying on message text.
When locked, unlock again.A 401 clears the tab token. A 403 preserves valid read-only judge access while refusing the administrative action. Never store a token in localStorage or a screenshot.
When validation blocks, fix scope.Refresh stale metadata, use the current release and Packet head, correct semantic or SQL issues, and request a new exact Approval instead of bypassing the gate.
When an external outcome is unknown, stop.Use reconciliation and idempotent replay. Never submit a second job merely because the first response timed out.
Developer orientation
Preserve the authority boundary
ImplementedDoctrine frozen
Model proposesLangGraph validatesWarehouse provesHuman approvesBI consumesAudit remembers
Business Situation is the internal aggregate root; the customer-facing name is Business Case.
Analytics Case is presented as Investigation and remains bounded inside one Business Case.
Evidence Packet is proof; Approval permits one scoped effect; Decision records the accountable business choice.
CrewAI and LangChain remain optional, replaceable plumbing. They never own routing, truth, approval, or side effects.
BI artifacts are downstream specifications. The portable Semantic Contract remains the metric authority.
Source Fabric
Source authority and reconciliation planning
Local only
This path is deterministic governance metadata. It does not read a source, create evidence, resolve a discrepancy, or grant execution authority.
Resolve the canonical basis.Use one exact approved Source Registry version, one exact approved Semantic Contract release, and time-bounded canonical principal artifacts.
Submit an authority request.Bind claim type, metric, legal entity, period, currency, extraction/revision, semantic context, and immutable support references.
Record an independent decision.The requester and decider must be different stable subjects. A later decision cannot reverse the immutable original.
Approve join mappings separately.Every member binds exact registry/release digests, source-local dimension definition digest, type, and separate submitter/approver subjects. Matching names are never enough.
Assemble the reconciliation plan.Require selected-dimension grain and pairing safety, distinct physical sources, legal entity/timezone/currency agreement, discrepancy preservation, and measurable settlement counter-evidence.
Stop before proof.Immutable file snapshots, durable source-authority persistence, extraction snapshots, claim evaluation, and live multi-source execution remain future milestones.
Release truth
Capability matrix
0.12.14
Capability
State
Meaning
Business Cases, Investigations, Workplans
Implemented
Active product objects and local UI/API path.
Source Registry metadata and Semantic releases
Implemented
Versioned metadata and immutable decisions; not automatic business-claim authority.
Bounded query execution code path
Checking runtime
Technical readiness does not grant release authorization or create an Approval.
Fresh BigQuery effects
Checking release gate
Persisted Runtime Effect Authority is independent from technical readiness and effect-specific Approval.
External-model effects
Checking release gate
No provider egress is authorized by model configuration or technical readiness.
Source authority and cross-source planning
Local only
Reference-only deterministic contracts; no connector or evidence runtime.
Human Evidence Review and Decision Brief
Local only
Read-only currentness is composed locally; Review and Brief creation remain inactive.
Business Decision and Monitoring
Local only
Read-only authority is projected for supervision; recording, scheduling, and actions remain inactive.
Materialization apply
Checking runtime
Risk-bearing warehouse writes must remain disabled without a separate approved milestone.
BI network writes
Checking runtime
Current exporters create offline specifications only.
Excel/CSV snapshots, GA4, analytical Postgres
Planned
No support claim until each governed read-only path has its own proof.
Engineering
Local validation checklist
Implemented
Keep the worktree explainable.Do not commit credentials, environment files, runtime state, private samples, generated evidence, or unrelated edits.
Run deterministic tests.Execute pytest, Ruff checks and format verification, compileall, JavaScript syntax validation, the distribution build, and git diff checks.
Verify the real surface.For UI changes, test desktop and mobile rendering, keyboard controls, UA/EN, Light/Dark/System, console health, and the absence of fake controls.
Reconcile doctrine and gaps.Update product-doctrine and remaining-gaps in the same coherent commit whenever capability truth or sequencing changes.
Keep external effects explicit.Local PASS never authorizes a provider call, warehouse execution, deployment, materialization, BI write, or production support claim.
No documentation matches
Try a product object, setting name, error state, or a shorter phrase.