One definition, every surface

How the platform is put together — read at whichever altitude you need.

Requirements filed
84
Delivered
15
Alpha (prototype)
12
beside Delivered, not in it
In progress
4
Proposals open
42
of 88 with a header
Next gate
M4Persistent Sensing
Q3 2026

Live at v3.12 (2026-09-03). Every figure comes from the catalogue.

The product document makes specific commitments to procurement: human oversight as a design requirement, a triage cycle under four hours, no vendor lock-in at any layer — and an assistant that brings work forward rather than waiting to be asked. This is the machinery that makes those commitments enforceable rather than aspirational — and the one place it is not finished yet.

Two narrated videos accompany this page: the CEO view (Watch the video (PRD v3.12)) and the three PRD levels with where every requirement stands (Watch the video (PRD v3.12)).

Sections are collapsed — the summaries are the overview.
The loop we sell, and the number it turns onThe delay we sell against is not analysis time — it is the hand-offs between systems that do not share a record.
Capture imagery, thermal, gas, process data Analysis surfaces what may be wrong An engineer confirms the judgement is theirs Work planned and tracked today, across disconnected systems: 5–10 days one loop, one record — target: under 4 hours every step recorded against a named person — and it trains the next campaign
The delay we sell against is not analysis time — it is the hand-offs between systems that do not share a record. Removing the hand-offs is an architectural property, not an optimisation, and the same record is what makes each campaign improve the next.
The assistant does not wait to be askedThe platform does not only answer faster — it notices what nobody asked about.
ARRIVING CONTINUOUSLY New campaign Patrol cycle Engineering change Attention debt unreviewed × corroborated × stale confidence gate A digest engineer sets the cadence and the volume budget below the gate — never surfaced at all The engineer decides acted or dismissed — every response logged it surfaces, ranks and asks; it never acts, never files work, never raises an alarm
The platform does not only answer faster — it notices what nobody asked about. This has already happened in practice: a cross-check surfaced an asset carrying more unreviewed evidence and more design-side corroboration than the one under investigation, with no finding ever raised against it. The loop back is the part that keeps it welcome: acceptance rate is how the feature measures whether it is earning attention or spending it.
Why “no vendor lock-in at any layer” holdsHardware- and system-agnosticism is a consequence of the architecture, not a promise on a slide.
A capability built once Their engineers — in the application Their systems — historians, RBI platforms, work management Their automation — on the command line Their partners — integrity firms in the review seat Their AI tools — our connector, inside the assistant they already use
Hardware- and system-agnosticism is a consequence of the architecture, not a promise on a slide. Every boundary is defined once, so a new sensor, historian or downstream system is a connector written against a contract — which is also why a pilot configures rather than integrates.
How “human in the loop” stops being a policy“Observe, reason, recommend” and “human oversight is a design requirement” are commitments we have already put in front of procurement.
THE COMMON SHORTCUT permission boundary An engineer Facility data Assistant its own keys OURS permission boundary An engineer Facility data Assistant acts as the engineer the difference is one arrow: whether the assistant has its own door
“Observe, reason, recommend” and “human oversight is a design requirement” are commitments we have already put in front of procurement. This is what turns them into properties of the system rather than rules people are asked to follow — the assistant has no route to facility data of its own.
What the platform is made ofFive capabilities, each with the requirements delivered over the requirements filed.

Five capabilities, each with the requirements delivered over the requirements filed — and, beside that strict count, how many are on alpha and how many are in progress, so a capability with work under way never reads as untouched. This is the CEO altitude; the CTO tab opens each one into its themes, and the Engineering tab opens each theme into its requirements.

Capability
Owns
Delivered +alpha · +in progress
Evidence Intake
Normalized evidence, QC, provenance, timestamp alignment
2 / 12+0 alpha+0 in progress
World Model
Asset identity, spatial registration, tag reconciliation, engineering context, photorealistic 3D scene (3DGS), AI assistant brain (persistent memory and knowledge)
0 / 11+1 alpha+3 in progress
Evidence Confidence
Cross-source correlation, contradiction, consistency, calibrated confidence
0 / 12+0 alpha+0 in progress
Integrity Analytical Chain
Observed anomaly → damage-mechanism review → risk assessment → inspection-plan reasoning
0 / 6+3 alpha+0 in progress
Operator Handoff
Verification queue, recommendation packets, inspection plan handoff
0 / 10+6 alpha+0 in progress
Commitment by commitmentEach promise the product document makes to a customer, and the thing that keeps it true.

Each promise the product document makes to a customer, and the thing that keeps it true.

What we have committed to What makes it true Status
Human oversight as a design requirement; observe, reason, recommend only The assistant has no path to data of its own. It acts as the signed-in engineer, sees only what they see, and every action is recorded against their name. Built
Triage to work order in under four hours, against five to ten days today One loop and one record end to end, so nothing is re-keyed between systems. The delay we sell against is hand-offs, not analysis time. Built
Hardware-agnostic, system-agnostic, no vendor lock-in at any layer Every boundary is defined once, so a new sensor, historian or downstream system is a connector written against a contract rather than a rebuild. Built
A 90-day pilot rather than a multi-quarter data-modelling effort The same definitions generate the connectors, so a pilot configures what already exists instead of integrating from scratch. Built
Partner integrity firms hold the review seat Partners reach the same capabilities under their own identity and their own permissions — no separate, looser access path to build or audit. Built
AI outputs constrained to defined schemas, with out-of-range values flagged rather than passed on Definitions are enforced by the build, not by review. This is the machinery the hallucination-mitigation story rests on. Built for data and events
An assistant that is proactive and curious — bringing work forward rather than waiting to be asked Ranked by attention debt, filtered by the same confidence gate as a requested answer, delivered into a digest the engineer paces. It surfaces and asks; it never acts. Now four requirements in the catalogue with dates — the digest and the ranking in Q1 2027, coverage prompts in Q2 2027. The fourth, the assistant asking its own question, is filed deliberately undated: it waits on a contract change, not on capacity. Committed
Specialist detection models called on demand as plug-and-play tools — one of the four “why now” enablers The tool definition: one description of a capability, projected to every surface at once. Designed, with the first test written to fail. The gap

What this needs from you

Nothing to approve. One useful input: which route matters commercially next — a partner API, a customer-facing command line, or deeper reach inside the assistants their teams already use.

And one thing to know: the single unfinished piece sits under a capability we already list as a reason the platform is possible now. It is the next thing we close.

What is built, and what is next

Most of the model is running and enforced on every change. This is the honest status.

Written at the 3.10 cut (2026-09-02); the counts on this page are live at 3.12 (2026-09-03). The proactive assistant moved from a design to four dated requirements, and the first half of 2027 stopped being a horizon: it is now two committed milestones — Repeat Visit (Q1 2027) and Continuous Coverage (Q2 2027). Everything below is generated from one source and checked on every change, which is why the release propagated to every derived document without anyone updating them by hand.

By technical boundary object

Object
What it powers
Status
Data
Typed access to every record, generated from reviewed migrations
Built
Access rule
Who can see and change what — enforced in the database itself
Built
Error
A stable code and a stated action, so a caller can respond rather than guess
Built
Operation
The published API, the typed client, the command line, the assistant connector
Built
Agent event
Everything the assistant streams back into the interface
Built
Tool
What the assistant can do, on all four surfaces at once — the one piece still missing
Next
Job
Work that outlives the conversation that asked for it
On demand
Skill
A versioned prompt that composes existing tools to solve one problem — effect and authority derive from the tools it uses
Partial