Skip to content
Decision-Evidence Operating System

Evidence Fabric — one record that every regulator’s report is built from · usually read by the Chief Compliance Officer

Four regulators asked about the same week, and four teams reconstructed four different stories from the same records.

None of them was lying. They queried different systems, at different times, with different definitions of what counted, and the artefacts they produced disagree in ways that are hard to explain afterwards — which is exactly the moment the question stops being about the decisions and starts being about your controls.

One thread per decision, and every artefact compiled from it

Governed decision recordSealedlog-or-refuse — no record, no effect
  1. intake.receivedrecorded

    channel, timestamp and a provenance hash — a fingerprint proving origin — for every artefact that arrived with it

  2. convening.tier.assignedsealed

    the routing score, the room, the chair and the autonomy tier — the routing is itself an event

  3. room.openedrecorded

    seats, their assigned evidence slices, and the named human who will rule

  4. evidence.attachedrecorded

    each artefact bound to the seat that used it, with the hash it was read at

  5. seat.dissenteddissent kept

    the adversarial seat’s objection, kept in full rather than averaged into a score

  6. gate.verdictsealed

    the computed agreement predicate — the rule that checks the models agree — its inputs, and both model versions, sealed

  7. chair.ruledsealed

    the named human’s ruling, the reasons, and whether it overrode the room

  8. record.sealedsealedsha256:9c30ea1f…b544 (illustrative)

    the thread closes and becomes replayable by anyone you grant a scoped read-seat — read-only access, limited to this record

Compiled from the same stream

  • EU AI Act Article-12 interaction log

    automatic recording over the system’s lifetime, with oversight and risk fields

  • NAIC model-bulletin pack

    documentation of the AI system’s governance, risk management and use, mapped to the bulletin’s own categories

  • OSFI E-23 pack

    model risk management documentation — inventory, tiering and validation evidence, mapped to the guideline’s own structure

  • Colorado quantitative-testing pack

    quantitative testing evidence for external data and algorithms used in a pricing or underwriting decision, mapped to the regulation’s own testing categories

What exists today is the stream they all read from — one tamper-evident record, where any alteration shows, with everything in it.

Illustrative composition, built from the components the product ships. No customer data appears anywhere on this site; the digest above is a placeholder. The interaction logger and the never-dropped audit emitter are observed at NX/services/nexus-workflows/src/services/governance.ts and NX/services/nexus-workflows/src/services/audit-emitter.ts.

See it in the console

Decision room — in session
Decision room — in sessionSee it in the gallery →

The mechanism, in three lines

One governed event stream compiles into every regulator’s artefact, instead of four teams reconstructing four different stories from the same week.

First

The record is the decision

Nothing writes a log about work that already happened. The event is the thing that makes the effect legitimate, so an unwritable event is a refused effect rather than a missing line.

Then

The emitter does not drop

When the downstream store is unavailable the emitter retries behind a circuit breaker — a guard that paces the retries — instead of failing silently. A gap in an audit trail is indistinguishable from concealment, and it is treated that way.

Finally

Regulators read a projection, not a copy

Each jurisdiction pack is compiled from the one stream rather than maintained beside it, so two packs cannot disagree about the same week.

observed at NX/services/nexus-workflows/src/services/governance.ts

1governed event stream every artefact is compiled from◆
0audit events dropped on a downstream failure — the emitter retries behind a breaker◆
3axes every read of the log is scoped on: tenant, owner, business unit◆

“Zero dropped” is a property of the emitter, not a measured uptime figure: on a downstream failure it retries behind a circuit breaker rather than discarding, observed at NX/services/nexus-workflows/src/services/audit-emitter.ts. The scoping predicate lives in the shared query layer every repository inherits, at ROS/src/middleware/organizationContext.ts and NX/services/nexus-auth/internal/authz/openfga_client.go; a surface that cannot resolve all three axes refuses rather than reading across the tenant boundary.

Work out what this costs

Your numbers, in your own browser. Nothing is sent anywhere.

Get the free assessment