initialising
TUNNELING TECHNOLOGIES000
TUNNELING EXECUTION SYSTEMS / ENACTIVE REALITY
Request a diagnostic
Singapore · Hong Kong · Redwood City Execution systems · Verified autonomy · Enactive Reality

We compile intent into verified work.

Tunneling builds closed-domain execution systems: asynchronous graphs of a hundred or more specialised agents that operate on an institution's own ontology, drive the professional tools the work actually runs on, verify every result against a domain checker, and halt at a human gate before anything irreversible happens.

Quantum tunnelling — a particle crossing a barrier
classical mechanics says it cannot cross

The name is the thesis. Most enterprise AI stops at the barrier between what a model can articulate and what an institution can be held responsible for. We build what gets through it.

Scroll
0Nodes in the largest closed-domain graph now in production
0Pipeline stages under one deterministic scheduler
0Reality gates between an agent and an irreversible action
0Working days to a written register you can act on without us · the pilot that follows runs four to eight weeks

Every institution runs on one process that three people understand, that cannot be paused, and that nobody has written down. That is where this work begins.



01The platform

An execution layer,
not a chat surface

A language model produces text. An institution needs a completed task: a filing that reconciles, a drawing that can be manufactured, an allocation that survives audit. Between the two sits everything that is hard — the domain's objects and rules, the professional software the work actually runs in, the checkers that decide whether a result is correct, and the authority to act.

The Tunneling stack is six layers that close that distance. Value rises as you move down it. So does the engineering cost of being wrong. We build downward only as far as an institution is prepared to be accountable.

Value ↓ increases Execution ↓ hardens
L1 · Ontology

The institution, made computable

An ontology is not a database schema. It is the set of objects an organisation argues about, the relations that constrain them, and the permissions that decide who may change what.

A contract, a lot, a work order, a counterparty, a tolerance band, a shipment, a learner. Each carries state, version history, provenance and an access class. Agents never see raw tables; they operate on typed objects with declared side effects, which is what makes their behaviour reviewable after the fact.

Entity model

Objects, attributes, lifecycle states and the events that move between them.

Relation graph

Supply, ownership, substitution, dependency, causality — traversable by agents, constrained by rules.

Permission classes

Read, propose, execute. Most agents never hold more than propose.

Provenance

Every value carries a source, a timestamp and a confidence. Unsourced values cannot enter a claim.

Cross-cutCut by what the system has to be right about — where ground truth lives, and what it costs to check it. Not by industry name, not by company size, not by geography.

Where ground truth lives decides which layer carries the load — a disputed claim is settled by sourcing and critics (L1, L4), a machine state is settled by the plant's own systems and a signature (L2, L5) — and the cut is imperfect: a fab's export-control filings behave like Binding procedure, not Physical state of record, so a single client can sit in two clusters and should be scoped that way.

Layer / cluster A · Evidence under disputeReconciling sources that disagree
IND-01 Capital markets · IND-02 Banking, insurance & credit risk · IND-03 Legal, audit & tax
B · Physical state of recordMachine and material state against the records
IND-04 Semiconductor · IND-05 Supply chain & trade · IND-06 Plants, utilities & grid · IND-07 Discrete engineering
C · Binding procedureConformance to an enforceable rule
IND-08 Pharma, medtech & clinical · IND-09 Healthcare delivery & payers · IND-10 Public sector & infrastructure
D · Capability in a personSkill transfer, measured after exit
IND-11 Education & workforce capability · IND-12 Interactive media & simulation
L1Domain OntologyIssuers, instruments, events and sources; every claim typed to who said it and when.Lines, tools, lots, SKUs and sites keyed to the IDs the MES and WMS already carry.Clauses, obligations, filings and deadlines, each bound to the citation it came from.Skills, prerequisites, roles and evidence of mastery — not courses or lesson lists.
L2Reality CompilerDrives the terminal, data room and CMS; every write is a typed action with a diff.Writes into MES, WMS and CMMS through their APIs, not by scraping operator screens.Drafts inside the firm's own document and matter systems, versioned, never in a chat box.Runs the professional tool the person is graded in — CAD, IDE, trading sim, edit bay.
L3Asynchronous Node Graph7 parallel evidence branches, then normaliser, conflict resolver, coverage reviewer.A branch per line, tool or lane; fan-in waits for the slowest sensor feed to land.One branch per obligation; the graph runs narrow and deep rather than wide.A branch per learner or scene; the graph runs at session pace, not overnight batch.
L4Verification Lattice12 critic nodes check figure, quote, date, source tier and cross-product consistency.Checkers on units, mass balance, tolerance and schedule feasibility before any release.Every sentence must resolve to a cited clause; uncited text is blocked, not flagged.Rubric and rule checkers score the artefact; the person's judgement stays unscored.
L5Reality GatesTerminal publication gate AI-116 fails closed; nothing reaches a reader unapproved.Any change to a setpoint, recipe or shipment halts at a named engineer's signature.The signing professional approves before filing; the gate records who approved, and when.Lightest of the four: certification, and any live-system or real-money step, stay gated.
L6Trajectory CorpusClaim map, source map and call-trace archive replay any published item end to end.Each run keeps the fault-detection trace: the ordered checks that located the fault.Builds the firm's precedent file — matter, rule version, reasoning, outcome on file.Stores what the person did, not what they watched; scored on transfer after exit.

We are deliberately small. There is no platform licence to defend, no seat count to grow and no reference architecture we need you to adopt. An engagement begins with one workflow, a named owner and an acceptance test — and ends when that test passes or we tell you it will not.


02Reference architecture

155 nodes,
eleven stages,
one audit trail

A real graph, running in production: 114 reasoning nodes and 41 deterministic workers across eleven stages. It ingests one event and returns four independently verified publishable products plus a complete evidence ledger, with no human touching the middle of it.

Scale is the whole engineering problem. Almost anyone can wire five agents together. It changes character at fifty, where concurrency, partial failure, cross-product consistency and per-claim attribution stop being incidental and become the design itself. Who runs this one, how many people use it and what it replaced are in section 07.

Domain

Closed. Bounded vocabulary, bounded sources, bounded output formats. Closure is what makes verification tractable.

Execution

Asynchronous. Stages fan out concurrently; barriers appear only where a decision needs the full set.

Failure

Local. A failed node drops its branch and is repaired in place. It does not take the run with it.

Output

Gated. Nothing reaches a reader until node AI-116 has cleared the claim map and the evidence ledger.

CLOSED-DOMAIN EXECUTION GRAPH — MARKET EVENT → VERIFIED PRODUCTS NODES 155 REASONING 114 STAGES 11 BRANCHES 7 CRITICS 12

System Entry

Loading stage map…

This graph is one instance, not the firm's whole capability. A hundred-node asynchronous graph is the right shape when the work fans out into many independent artefacts under one deadline. Most of the engagements in section 04 do not need one: a reconciliation pilot runs at 20 to 40 nodes and a healthcare packet graph is smaller still. Section 03 lists what the stack does; this section shows what it looks like at the top of its range.

What breaks at scale

Contradiction between products. The poster says one thing, the article another, the video a third. Stage 09 exists only to catch that, and it is the stage clients underestimate most.

What we refuse to skip

Stage 10. Every claim in every artefact is mapped back to a source, a dataset and a rendering job. If a number cannot be reproduced from the ledger, the product does not publish.

What this transfers to

The topology is domain-independent. Substitute the ontology, the branch interpreters and the checkers, and the same eleven-stage shape covers research, engineering release, and regulatory reporting.

AGENT TRACE — STAGE 04 · SINGLE-EVENT RESEARCH ROUTE illustrative

03Capability taxonomy

Eight things
the system does

Sector names are a poor way to scope this work. Two banks can want opposite things and a bank and a fab can want the same thing. So the catalogue below is cut by the unit of output — what the system has to hand back before anyone will call the run finished — because that is what decides which checker has to exist and how long it takes to build.

Each entry states its input, its checker, its gate and the earliest point at which you could accept or reject it. The sector practices in section 04 are these eight capabilities, recombined and given a vocabulary.

If the answer is a number

Your systems disagree with each other, or with the physical world. That is C-01 and C-03. Ground truth already exists somewhere in your estate; the work is locating it and proving the match.

If the answer is a document

Somebody has to sign it and could be asked to defend it. That is C-02 and C-04. Ground truth is a source or a rule, and the checker is a lookup you can run on any sentence.

If the answer is a file or a person

The work happens inside professional software, or inside someone's head. That is C-05, C-07 and C-08, and it is the expensive end.

C-01H0 · 10 DAYS

Reconciliation

Unit of outputA matched record set, plus a discrepancy register naming the field, both values, and the document that governs which one wins.

Input
Two or more record populations that are supposed to agree and do not.
Checker
Field-level match, arithmetic re-run on every line, date and term feasibility, governing-clause lookup.
Gate
Propose only. No payment release, no journal posting, no credit note without a named approver.
Layers
Load sits on L1 and L4. L2 is light — most of this is read.
Instances we have scoped or built
  • Supplier invoice against purchase order and goods receipt — freight, duty and tax lines included, which is where three-way matching usually fails
  • Custody statement against the internal position ledger — per account, per day, with the break aged
  • Bill of materials against the released drawing revision — per part number, per revision
  • Five trade documents, one consignment — commercial invoice, packing list, bill of lading, certificate of origin, letter of credit
  • Claim submission against the policy schedule and the treaty wording
  • Payroll run against employment contracts and the collective agreement
C-02H0 · 10 DAYS

Attribution

Unit of outputA claim map: one row per assertion, carrying the document, the date, the page, and the check that confirmed it.

Input
A question, a body of documents, and a written rule for what counts as a source.
Checker
Numeric recomputation against the underlying series, citation re-located at page level, coverage audit, contradiction register.
Gate
The publication gate fails closed. Uncited text is removed rather than flagged.
Layers
L1 for the source hierarchy, L3 for parallel evidence branches, L4 for the critics.
Instances we have scoped or built
  • Sell-side note with a disclosure appendix — and a stated basis behind every figure in it
  • Investment committee memo — each input carrying its licence and redistribution terms
  • Regulatory submission — every statement mapped to the clause it answers and the version in force
  • Literature review for a safety or clinical file — with the search strategy recorded, not reconstructed later
  • Due-diligence report — a data-room document number standing behind each finding
  • Client enquiry answered with its source list attached
C-03H1 · 6 WEEKS

Cause ranking

Unit of outputAn ordered list of candidate causes, each with the evidence that supports it and the one test that would settle it.

Input
An anomaly with a timestamp, and read access to the histories that could explain it.
Checker
Replay against cases your team already solved, unit and dimensional validation, a precedent applicability test.
Gate
Read-only against the systems of record. No setpoint, recipe or configuration writes, ever.
Layers
L1 for the asset and event model, L2 in read mode, L4 for the replay harness.
Instances we have scoped or built
  • Yield excursion on a 300mm line — fault-detection traces, defect maps, recipe edits, maintenance records, incoming material
  • Unplanned downtime on a rotating asset — vibration history, work orders, lubrication records, load profile
  • A grid constraint that keeps recurring at the same hour — telemetry, outage records, weather, market schedule
  • Cost variance on a capital project — against the baseline and the change register
  • Freight exceptions clustering on one lane — carrier events, customs holds, terminal congestion
  • A conversion metric that dropped — traced to a release, a segment or a supplier rather than guessed at
C-04H1 · 6 WEEKS

Rule-bound drafting

Unit of outputA draft, plus a clause trace tying every paragraph to the obligation, standard or precedent it satisfies.

Input
The enforceable text — statute, standard, contract, protocol — and the facts of the matter.
Checker
Each sentence must resolve to a cited clause. Deadline arithmetic and version currency are checked separately.
Gate
The named professional signs. No filing and no client transmission without a recorded sign-off.
Layers
L1 for the obligation model, L4 for the clause checker, L5 for the signature.
Instances we have scoped or built
  • Regulatory filing — each section naming the rule and the rule version it answers
  • Clinical study document set — against ICH guidance and the protocol version actually in force
  • Contract review against the firm's own playbook — deviations listed with the fallback position
  • Instructions for use and labelling — against the applicable device standard, in every market language
  • Public procurement documentation — against the tendering rules of one jurisdiction
  • Tax position paper — against the statute, the ruling and the group's own prior filings
C-05H1 · 8 WEEKS

Professional tool operation

Unit of outputA working artefact in the tool's own native format, with the operation log that produced it and the check that it passed.

Input
An intent, the tool itself, and the acceptance rule the artefact has to satisfy.
Checker
Re-open, re-measure, re-execute. Constraint trees, watertight geometry, formula audit, a test run that has to pass.
Gate
Writes land in a working branch or a scratch document. Release into the controlled vault takes a signature.
Layers
L2 carries almost all of it. Typed tool calls, never synthetic mouse coordinates.
Instances we have scoped or built
  • CAD — a parametric model rebuilt from a specification, exported, and re-measured against the tolerance table
  • Spreadsheet models — rebuilt with a formula audit and every output recomputed from the inputs
  • EDA and layout — a rule-deck run, violations split into fixable and needs-a-person
  • BI and SQL — a report built against the semantic layer, with the query and the row counts attached
  • Document and slide production — driven by your template, versioned in your own store rather than a chat window
  • Image and video production — every rendered frame re-opened and inspected before it counts as delivered
C-06H0 · 15 DAYS

Exception triage

Unit of outputA routed decision: the exception, the recommended action, the evidence behind it, and the person who owns it.

Input
A stream of exceptions that currently arrives in a shared mailbox or a spreadsheet.
Checker
Policy conformance, entitlement, precedent match, and a confidence floor below which an item goes to a person untouched.
Gate
Nothing auto-resolves at first. Acceptance rates are measured for weeks before any auto-clear band is agreed in writing.
Layers
L1 for the exception taxonomy, L3 for throughput, L5 for routing authority.
Instances we have scoped or built
  • Customs holds and classification queries — scoped to one trade lane and one jurisdiction
  • Alarm floods on a plant board — deduplicated and ordered by consequence rather than by arrival time
  • Insurance claims intake — complete, incomplete, or needs an adjuster, with the missing item named
  • Payment exceptions and screening hits — routed by reason code to the desk that can clear them
  • Service tickets — classified against the entitlement and the contractual response clock
  • Quality deviations — sorted by criticality against the site's own classification rules, not a generic severity scale
C-07H2 · 1 QUARTER

Multi-artefact production

Unit of outputSeveral products built from one evidence pack, plus the consistency report proving they do not contradict each other.

Input
One event or one body of evidence, and a format specification for each output.
Checker
Per-format critics first, then a cross-product consistency stage, then a claim map covering every output at once.
Gate
The publication gate holds all outputs together. One unresolved objection blocks the entire set, not just the artefact that failed.
Layers
L3 and L4 both heavy. This is the capability that forces a graph rather than a pipeline.
Instances we have scoped or built
  • The 155-node system in section 02 — one market event becomes four verified products and one evidence ledger
  • Product launch pack — spec sheet, training deck, sales note and support article from one release record
  • Regulatory change cascade — internal briefing, procedure amendment and client notice from a single rule change
  • Course build — lesson, worked examples, assessment items and marking scheme from one syllabus objective
  • Multilingual publication — translations checked against the source claim map rather than against each other
  • Investor communications — deck, release and prepared remarks reconciled before any of them goes out
C-08H2 · 1 QUARTER

Capability transfer

Unit of outputMeasured transfer after exit: the person performs an unassisted task afterwards and somebody marks it.

Input
A skill definition, a checker for the artefact the learner produces, and an environment worth rehearsing in.
Checker
Symbolic and rubric checkers score the artefact. The person's judgement is not scored by a model.
Gate
No grade of record without the named examiner. No live system, no real money and no real patient inside a rehearsal.
Layers
L1, L2 and L6. This is where the trajectory corpus is worth the most and takes longest to accumulate.
Instances we have scoped or built
  • Zhihu MathHub — the misconception found in the working, three lines above the wrong answer
  • StudyHub — a question becomes a path whose state survives the session
  • Trading floor rehearsal on a market replay — P&L attributed to the decision that caused it
  • Field-engineer rehearsal on a plant model — permit and isolation steps enforced rather than narrated
  • Onboarding into an internal system — the trainee's actions checked against the real procedure, in a copy of it
  • Future Film Lab — persistent characters, and a world that remembers what the person did in it
No checker yet

Two claim classes we have tried and failed to build a checker for, and therefore decline to take on. Whether a specific piece of information is material and non-public: the test is legal and contextual, and our attempts produced confident answers with no way to verify them. And whether a photograph depicts what its caption says it depicts: image-to-claim verification held up on staged tests and fell apart on real archive material. Both stay out of scope until somebody builds the checker, and that includes us.

The cut is imperfect and worth arguing with. Reconciliation and cause ranking overlap wherever the disagreement is between a record and a machine — a lot mismatch is both. When a workflow sits across two entries we scope it as two, with separate acceptance tests, rather than pretending it is one thing.


04Sector practices

Twelve practices,
one execution stack

The six layers are shared and the eight capabilities in section 03 are shared. The ontology, the branch interpreters, the checkers and the gates are rebuilt per sector, because that is where the difficulty sits and none of it generalises for free.

Each practice states the same six things in the same order: the work as it stands and what it costs, the instrumented workflows with the measure attached to each, where we think the sector is going and where we disagree with it, how the node graph is re-cut, what decides correctness and what we refuse, and which capability gets you a result fastest. Twelve is not the limit of what the stack covers — it is the list where we have either built something or scoped one closely enough to publish numbers.

A · Evidence under disputeGround truth is a source. The work is reconciling records and authorities that disagree.
B · Physical state of recordGround truth is a machine, a material or a shipment, and the records disagree with it.
C · Binding procedureGround truth is an enforceable rule, and someone signs to say the work conforms to it.
D · Capability in a personGround truth is what someone can do afterwards, and it is measured after they leave.

The cluster cut is by where ground truth lives, not by industry name, and it is imperfect in a way worth knowing about: a semiconductor firm's export-control filings behave like Binding procedure rather than Physical state of record, so one client can sit in two clusters and should be scoped as two engagements with separate acceptance tests. Cost figures throughout are observed ranges from operations of the stated size. They are not benchmarks and none of them come from a named client.

IND-01 · Capital markets, brokerage and research

A first-take note takes 90 minutes to write and three hours to make defensible.

The 155-node reference system — 114 reasoning nodes and 41 deterministic workers across 11 stages — was built for a financial-information client and still runs there. We install the same graph against your own instrument and issuer names: seven parallel evidence branches gather the record, twelve critic nodes attack what they produce, and the terminal publication gate AI-116 fails closed, refusing to release any product in which a claim cannot be resolved to a source document, a date and a page. The sector suits verified execution because the acceptance test already exists in writing — your compliance manual and your research policy are the checker specification. One limit stated up front: the graph holds state across sessions at persistence level L2, and level L3, where a system acts directly on live books and records, is gated and only partially built.

The barrier

The expensive part of research is not the prose. It is the disclosure appendix, the stated basis for the price target, the restricted-list check and the page reference standing behind every figure — work that lands on an associate at 06:00 and on a supervisory analyst who must sign the note under FINRA Rule 2241 and Reg AC before it can be distributed. Add one more covered name, one more language, or one more client entitlement class, and that tail of work grows while the writing time stays flat.

Ontology objects
IssuerInstrumentEventSource documentHouse estimateClaimPublished productEntitlement classMandate constraintHolding
01 · EconomicsWhat the work costs as it stands
01 · The work as it standsObserved shape and observed cost · ranges from operations of this size, not any named client
How it runs todayAn issuer reports at 07:00 London. The covering analyst and one associate pull the release, the results presentation and the call transcript, update the model in Excel, and draft a first-take note in the BlueMatrix or Word house template. The associate rebuilds the disclosure appendix by hand — ownership thresholds, banking relationships, the twelve-month price-target history, the Reg AC certification — and puts the name past the control room's restricted and watch lists. A supervisory analyst then reads for price-target basis and risk language before the note can leave the building, while the same note is read out at the 07:15 morning meeting whether or not that review has finished. Consensus is a separate job on a separate morning: someone opens Visible Alpha, IBES on Refinitiv or Bloomberg BEst, exports estimates into a spreadsheet, and works out by eye which houses moved, in which direction, and on what evidence. Buy-side desks run the mirror of this — a portfolio manager and a compliance officer checking a proposed position against the investment policy statement, concentration limits and the restricted list, usually in a shared workbook that nobody owns.
Cost todayThese are typical ranges observed where desks measure themselves; they are not a benchmark and they are not drawn from any named client. A first-take note runs 60–90 minutes of analyst writing and 2–4 hours of associate work across the model, the appendix and the citation pass. A supervisory analyst clears 8–15 notes a day at 15–30 minutes each, and that queue is the binding constraint in the first hour after an open. On a desk of roughly 40 analysts and 20 associates publishing about 250 notes a month, the arithmetic is: 250 × 3–5 hours of model, appendix and citation work = 750–1,250 hours; plus 250 × 15–30 minutes of supervisory review = 60–125 hours; plus 60–80 hours a month keeping the consensus spreadsheet current. Post-publication corrections — a wrong prior-year figure, a stale disclosure, a mislabelled chart — run at 2–6 per hundred notes on desks that count them, so 5–15 corrections a month at 1–3 hours each across analyst, editor and compliance, each one requiring a re-send to the distribution list.
What the pilot takesA pilot runs six to eight weeks against one sector team, one product type and one entitlement boundary — typically 20–30 covered names and the first-take note only. From your side it needs a research operations lead for about four hours a week; one analyst and one associate for two hours a week each as the acceptance panel; a supervisory analyst for two sessions of ninety minutes to define in writing what a passing note looks like; and read access to the research archive, the disclosure register and the restricted list. Weeks 1–2 build the ontology against your own object names, because a generic one fails on the first house-specific segment definition. Weeks 3–5 run the graph in shadow alongside the live desk, publishing nothing to clients. Weeks 6–8 produce 60–100 notes both ways and have your supervisory analyst judge them blind to which is which. No production system is connected to your distribution platform during the pilot.
What changesThe measurable is the share of published claims that resolve to a named source document, a date and a page, counted across every claim rather than sampled, and the count of unattributed numbers reaching a reader, where the target is zero and the actual number is reported weekly. Reported beside it: associate hours per published note, supervisory analyst minutes per note, and corrections per hundred notes — each of these measured for four weeks before the pilot begins, so there is a baseline rather than a recollection to compare against. Because AI-116 fails closed, a note whose provenance is incomplete does not publish late; it does not publish, and the gap shows up as a gate rejection with a reason attached, which is itself a measurement of where your evidence chain is thin.
Stays manualThe investment view stays with the analyst. The system assembles evidence, recomputes every numeric claim against the underlying series, and flags where two houses read the same datum in opposite directions; it does not set the rating, the price target or the recommendation, and we would advise against buying any system that says it does. Supervisory sign-off stays manual because the liability is personal and regulatory — a named individual certifies the note, and a graph cannot hold that certification. Order routing and transmission to clients sit outside the gate by design and will not be automated. One admitted limit: our consensus normalisation is dependable on headline lines — revenue, EBIT, EPS, dividend — and unreliable below them, because segment definitions differ house to house in ways that no critic node we have written can reconcile safely. On the reference system that reconciliation is still done by a person, and sub-headline dispersion is presented raw, unnormalised, and labelled as such on the face of the output.
02 · Instrumented workflowsCut by Cut by the unit of work that enters the graph: one market event, one body of existing house views, one mandate document, one licensed input, one inbound client question, one already-published record. Each workflow starts from a different object, so no two share an entry point or a failure mode.
CM01
Single event to published product chain

A central bank statement, an earnings release or a sanctions listing enters at stage 02 and fans out across the seven parallel evidence branches at stage 04, then into the 27-node poster pipeline at stage 05 and the long-form stage 06. On the financial-information deployment, the pattern it replaced was two analysts and one editor spending roughly three hours per macro print; what remains manual is the editor's review of a completed dossier, typically 25 to 40 minutes. Stage 07, the video route, stays switched off for most desks because voice and likeness approval takes longer than the news cycle the item serves.

Event dossier: a dated draft note, the poster set, and a claim map listing every factual sentence with its source URL, publication timestamp and retrieval hash, plus the AI-116 gate record showing pass or fail with reasons.
CM02
House view consensus and dispersion map

Forty sell-side notes on one issuer typically carry a dozen distinct claims about it, and a house frequently disagrees with itself between its credit desk and its equity desk without anyone recording that fact. The normaliser and conflict resolver at stage 04 place each numeric forecast against its source page, then the coverage reviewer marks which disagreements are evidential and which are definitional, such as two desks using different adjusted-earnings definitions. Conflicts the resolver cannot settle are printed as open conflicts rather than averaged away.

Dispersion register: a dated table of every distinct claim on the issuer, the holder of each claim, the quoted evidence with page-level citation, and a separate section of residual conflicts left unresolved.
CM03
Mandate and exposure screening

An investment management agreement is read clause by clause into the domain ontology at layer L1, and current holdings are tested against those clauses together with sanctions listings, exclusion policies and concentration limits, including look-through into pooled funds where the holdings file supports it. Every flag cites the clause number and the holding record that triggered it, so a compliance officer can dismiss a false positive in well under a minute. The screen advises; it never places, cancels or amends an order, and the graph has no execution connection at all.

Exposure screening memo per mandate: the clause-by-clause reading, the holdings tested, each flag with its clause reference and holding identifier, and a named list of clauses the system could not test and why.
CM04
Entitlement-aware derivative content

Exchange feeds, index licences and third-party estimate sets each carry redistribution terms that differ by channel, and a summary derived from a licensed input inherits those terms. Each input is tagged with its licence reference at ingestion, and a deterministic worker among the 41 refuses to emit derived content into a channel the licence does not cover, including social posts and unentitled client tiers. Where a licence is ambiguous the worker fails closed and routes to the vendor relationship owner rather than guessing.

Entitlement manifest attached to each published asset: every input, its licence reference and clause, the permitted channels, and the deterministic worker's decision record with timestamp.
CM05
Bespoke client enquiry with sources

A sales desk or an institutional client asks a question that has no published answer, such as which of the firm's covered issuers changed guidance language on freight costs in the last two quarters. The question is answered from the firm's own corpus and its entitled data only, and every sentence in the answer resolves to a document the client is permitted to see. Questions the system cannot answer within those bounds are returned as declined, with the reason stated.

Enquiry response pack: the answer, a source map naming each document consulted with its access date, and an explicit list of sub-questions declined with the reason for each.
CM06
Supervision and record reconstruction

Two years after publication, a supervisor needs to show why a specific sentence in a specific note was published and what was checked before it went out. Stage 10 writes the claim map, source map, data reproducibility record, asset manifest and call-trace archive for every item at the moment of publication, so reconstruction is retrieval rather than investigation. The archive is written once and cannot be edited by any node in the graph.

Reconstruction file for any published item: claim map, source map, asset manifest, call-trace archive, the outputs of the 12 critic nodes, and the AI-116 gate record with the identity of the human who cleared it.
CM01 · measure

On 30 consecutive events, median minutes from wire item to drafted dossier with a complete claim map, and the count of those 30 that reached the gate carrying zero unattributed factual sentences. The client picks the 30, not us.

CM02 · measure

Given 40 notes on one issuer, every target price, earnings estimate and spread forecast in the register must carry a page-level citation. The client audits 20 citations at random; any that does not resolve to the stated page counts as a failure.

CM03 · measure

Run against a back-file of breaches the compliance team already found over twelve months; the screen must reproduce at least 95 per cent of them, and every false positive must carry a clause citation. Missed breaches are counted individually, not as a rate we choose.

03 · Where this sector goesHorizon 18-36 months · our view, stated to be argued with
P01
Buyers will pay for attribution quality rather than draft quality.

Draft generation is now available from several open-weight models at low marginal cost, so it stops being a differentiator. What remains expensive is proving, per sentence, which document and timestamp a claim came from, and keeping that proof retrievable years later.

Score vendors on a failed-citation rate measured on your own corpus, not on writing samples. Ask for the number before the demo, and ask what it was on the first week of the last deployment.
P02
A major manager publicly blames a client-facing error on an unsourced model claim.

Summarisation tools are being placed in front of clients faster than publication controls are being rebuilt behind them, and a fabricated number in a client note is visible in a way an internal error is not. We call this likely rather than certain; it depends on disclosure practice as much as on failure rate.

Put a gate that fails closed in front of anything client-facing now, and keep a record of what it blocked. The blocked list is the evidence you were controlling the risk before an incident, not after.
P03
Market-data and estimate licences add explicit model-output clauses at renewal.

Vendors can see derived content circulating in channels their current terms did not contemplate, and renewal is the only moment they can reprice it. Tagging inputs at ingestion is much cheaper to build before a renewal negotiation than during one.

Inventory which licensed inputs already feed model-derived output, and by which channel, before your next renewal date. Bring that inventory to the negotiation rather than letting the vendor construct it.
P04
Disagreement maps across house views will price above summaries of the same notes.

A summary of forty notes is available to every competitor holding the same forty notes. Where the notes disagree, on what evidence, and which disagreements are definitional rather than substantive is work almost nobody does, and it survives commoditisation longer.

Before commissioning another summarisation pilot, test whether your own desks can already state where they disagree with each other on your five largest covered names. If they cannot, that is the higher-value build.
Where we disagree with the sector

The common expectation is that generative tooling cuts research headcount by 30 to 50 per cent within three years. We think net analyst headcount in sell-side and buy-side research moves very little over 18 to 36 months, and that the cost line shifts rather than shrinks: from drafting and formatting towards evidence supervision, entitlement management and record reconstruction, which are all salaried human roles today. Firms that cut analyst seats first and build the attribution layer second will re-hire within two years, at a higher cost per seat, because the people who can adjudicate a contested claim are the same people they released. We hold this view with moderate confidence. If regulators accept machine-generated attribution records without a named human signatory, the headcount argument changes and we would be wrong.

04 · Node graph, re-cut for this sectorAgainst the eleven-stage reference
Driving axisEvidence branch breadth and the cost of attributing every claim. Cost here is not model inference; it is the fan-out at stage 04, where seven evidence branches each retrieve, normalise and cite independently, and then the per-sentence attribution burden that follows. Risk is concentrated in a single event: publishing a sentence with no resolvable source, or with a source the recipient is not entitled to see. The graph is therefore shaped to make attribution cheap to produce and expensive to skip.

Stage 04 is the expanded stage in this sector: all seven evidence branches stay live, each with its own retrieval, normaliser feed and critic, because a capital markets claim usually needs a primary filing, a market-data record and a third-party view before it can be published. Those seven branches run fully concurrent; there is no ordering between them and no shared state. A synchronising barrier is mandatory at the conflict resolver, which must not start until all seven branches have landed or been recorded as failed, otherwise a slow branch is silently treated as an absent view and dispersion is understated. Stage 05, the 27-node poster pipeline, collapses to zero for buy-side internal work with no published product, and stage 07 video collapses for most desks. Stage 09, cross-product consistency, expands whenever one event feeds a note, a poster and a terminal alert, since the same number appearing with two different values across products is the most common visible failure. Stage 10 must complete before stage 11 begins, and AI-116 at stage 11 fails closed: no gate record, no publication. Six reality gates remain in place across the run; none of them is configurable by the desk.

Seven branches, one barrier

The seven evidence branches at stage 04 run concurrently and independently, but the conflict resolver waits for all of them. A branch that times out is recorded as failed rather than dropped, so the dispersion register shows a gap instead of a false consensus.

Poster pipeline is optional

The 27 nodes of stage 05 exist for published product. Buy-side desks producing internal memoranda switch the whole stage off, which removes roughly a fifth of the graph's runtime cost and none of its verification.

Attribution cost per sentence

Attribution, not drafting, dominates the compute and review budget on this sector's graphs. A note of 40 factual sentences carries 40 claim-map rows, each with a retrieval hash, and that is the line item to model when sizing a pilot.

Gate AI-116 fails closed

The terminal publication gate blocks on any unresolved critic objection or missing entitlement record. It cannot be overridden inside the graph; a human with a named role clears it, and the clearance is written to the archive.

05 · Correctness and authorityWhat decides, and what we refuse
Checkers

Numeric market claims, meaning any price, yield, spread, index level or volume, are checked by the market-data reconciler against the entitled data record for the exact timestamp stated in the claim. A numeric market claim carrying no timestamp fails on that ground alone and is never rounded into an approximation. Corporate facts, meaning issuance, guidance, dividend, filing and governance events, are checked by the filing matcher against the regulatory filing or exchange announcement, using the filing identifier and its publication time; a press summary is not accepted where the filing exists. Third-party opinions and forecasts are checked by the attribution resolver, which requires a named author, a named document and a page or paragraph reference; anything that resolves only to a house name is demoted to unattributed and blocked from client-facing output. Every input, at ingestion, is checked by the entitlement classifier, a deterministic worker that maps the input to its licence clause and the permitted channels for the intended asset. Text we write ourselves that looks forward is checked by the recommendation-language screen: no price target may appear without the model that produced it attached, and no performance figure may appear without its calculation method and period stated in the same sentence. Any passage naming a living individual in connection with a transaction is routed by the sensitive-surface checker to a human before it can reach stage 11.

Gate policy

The graph will not place, amend, cancel or route an order, and holds no execution credentials of any kind. It will not transmit client holdings, mandate documents or portfolio identifiers to any endpoint outside the client's own boundary. It will not publish anything without a passing AI-116 record, and no node can override, suppress or edit a critic objection; an objection is closed by a named human or it stays open. It will not distribute research to a recipient outside the entitlement list attached to that asset, including internal recipients. It will not produce a personalised investment recommendation for an identified individual. It will not amend or delete an archived record from stage 10. These refusals are compiled into the graph, not exposed as settings, and no configuration file we ship can turn them off.

Acceptance

Take 100 sentences at random from the first month of output. At least 98 must resolve to their cited source within two clicks, and zero of the 100 may be a numeric market claim published without both a timestamp and an entitled data source. Separately, name 20 items published during the pilot; each reconstruction file must be produced within one working day. Fail either test and the pilot fee is not payable.

Will not automate

We cannot determine whether a given piece of information is material non-public information, because that depends on facts outside any document set: who knew it, when, and under what duty. No checker we have can establish those facts, so the graph makes no MNPI judgement at all; it routes the passage to a named compliance officer and stops, which means a desk with no such officer available will see items sit unpublished. A second limit in the same family: we do not accept a number read out of a chart image as a source. Extraction from plotted axes is not reliable enough to attribute, so a claim that exists only inside a chart is marked unsourced and blocked, even where the number is almost certainly correct.

06 · Where this sector entersCross-reference to the capability catalogue in section 03 and the horizons in section 05
Fastest entry · H0

C-02 attribution replayed against 30 items you already published. Ten working days, read-only, and the deliverable is a failed-citation rate on your own output.

Pilot · H1

C-02 with C-07 on one sector team, one product type and one entitlement boundary. Six to eight weeks to an acceptance test your supervisory analyst signs.

The long part · H2 to H3

The four-product pipeline running off one evidence pack, plus the ledger that makes a two-year-old note reconstructable. Quarters, and it is the part that compounds.

If your sector is not here, the question is the same one: which workflow is bounded enough to verify, painful enough to fund, and owned by someone who can accept or reject the result. Where a sector has no answer to that, we say so rather than sell into it. Name the workflow and we will tell you within two working days whether we think it is one →



05Delivery horizons

Ten working days,
then quarters

Buyers ask how fast this can be real, and the honest answer has four parts rather than one. The cut below is by time to a result you can accept or reject — not time to a demonstration, and not time to a signed contract. Each horizon has a different thing at the end of it, needs a different thing from you, and fails in a different way.

The first horizon is genuinely two weeks and genuinely useful, and it is the one we give away. The fourth is measured in years and is where the value actually accumulates. Anyone who tells you the fourth arrives on the first horizon's timetable is selling a demonstration.

H0 · INSTRUMENTATIONUNPAID
10 working days

Measure the work, do not change it

Read-only, against a copy of your own history. Nothing is integrated, nothing is written, and no system of record is touched. The deliverable is a document plus one agent you can watch run.

What exists at the end
An opportunity register with a row per step in the workflow: what it costs today in hours, whether an acceptance test can be written for it, and who would own it. Plus one read-only agent replaying your back-file, so the numbers come from your data rather than from a slide.
What we need from you
Half a day on site or two hours remote, a named owner, and a back-file of 200 to 800 completed items from the last two years. Read access under an NDA, provisioned to named individuals on our side.
What it does not include
No integration, no write access, no production deployment, and no model fine-tuned on your data. If a workflow needs a system connection to be assessed, it moves to H1 and we say so rather than approximating it.
What goes wrong here

Getting the back-file. Legal review of an NDA and the provisioning of read access routinely take longer than the ten days of work they enable, and that is the schedule risk on this horizon, not the analysis.

H1 · ONE VERIFIED WORKFLOWFIXED PRICE
4–8 weeks

One workflow, one acceptance test

A graph of 20 to 40 nodes covering a single named workflow, with its checkers, its gate and an acceptance test written before we start. It runs in propose-only mode against real inputs.

What exists at the end
A working system your team runs on live inputs without our involvement, producing a proposal a named person accepts or rejects. Per-node evaluation sets, the checker suite, the gate policy in writing, and the acceptance test result whether or not it passes.
What we need from you
A named owner with authority to sign the acceptance test, roughly two to four hours a week of a domain expert's time, read access to the systems in scope, and the back-file from H0 if we did not already have it.
What it does not include
No write-back to a system of record, no auto-clear band, no second workflow, and no scale testing beyond the pilot volume. Adding a second workflow is a second pilot, not a scope change.
What goes wrong here

The acceptance test turns out to be unwritable, usually because the work is judged rather than checked. When that happens we say so in week two and stop, and it has happened. The other common failure is that the domain expert's four hours a week do not materialise.

H2 · PRODUCTION GRAPHSCOPED PHASES
1–2 quarters

Write-back, behind gates, under audit

The graph grows to 40 to 150 nodes across several workflows, begins writing into systems of record through their APIs behind approval gates, and carries an audit ledger that reproduces any run from stored inputs.

What exists at the end
Multiple workflows on one ontology, typed write-back with rollback, an approval routing model naming who signs what, the evidence ledger, monitoring, and a per-node regression suite built from accepted runs. Auto-clear bands only where months of measured acceptance justify them.
What we need from you
Integration engineering time from your side, a security review, a decision on deployment topology, and named approvers for each gated action. Change management, because this is the horizon where the work of the people around it actually changes.
What it does not include
No autonomous irreversible action, at any node, in any configuration. Payments, releases, filings, equipment commands and identity changes stay behind a human gate permanently and are not on the roadmap.
What goes wrong here

Cross-workflow contradiction. Two workflows that were each correct alone produce outputs that disagree, and the stage that catches it is the one clients most often want to cut for schedule. We will not cut it, and that argument usually happens around week nine.

H3 · ONTOLOGY AND CORPUSSTANDING
12+ months

The part that compounds, and it is slow

One ontology across the estate rather than per workflow, and a trajectory corpus of verified runs — including the instructive failures — that makes each subsequent build cheaper than the last.

What exists at the end
Consolidated objects, relations and permission classes spanning several functions. A corpus of trajectories with their failure paths and repairs, owned by you. Where authorised and where a checker exists, selected connections into real processes at persistence level L3, which is gated and partial by design.
What we need from you
A standing owner rather than a project sponsor, a budget that survives a reorganisation, and the willingness to fix identifier and relation problems in your own systems, which is where most of the calendar goes.
What it does not include
Anything we have no checker for. Section 03 lists two claim classes we tried and abandoned, and section 04 lists what each sector's practice refuses. The refusals do not shrink as the engagement grows.
What goes wrong here

Sponsorship. Twelve-month programmes outlive the person who commissioned them, and the ontology work that pays in year two is the easiest thing to defer in month seven. We have had this happen and the mitigation is unglamorous: ship something usable every quarter.

01 · What actually ships in ten working daysRead-only, against your own back-file · these are the H0 deliverables, named
Q01 · C-01
Three-way match replay

Invoice against purchase order against goods receipt, replayed over 500 historical documents including freight, duty and tax lines. Output is an exception list, not a percentage.

Deliverable: exception register + measured baseline
Q02 · C-02
Failed-citation rate on your own output

Thirty items you already published, re-checked claim by claim. Every figure re-located to a document, a date and a page, or listed as unsourceable.

Deliverable: claim map + failed-citation rate
Q03 · C-03
Top-three recall on solved excursions

Fifty anomalies your engineers already diagnosed, replayed blind against the archive. We report how often the true cause was in the top three, and how often it was not in the list at all.

Deliverable: recall measurement on your own history
Q04 · C-01
Baseline drift measurement

The approved baseline against the document everyone actually works from, with every applied and unapplied change traced to its approval reference. Run on a closed programme first.

Deliverable: drift register with approval trace
Q05 · C-06
Exception queue shadow run

One month of exceptions replayed in shadow. Every item gets a proposed classification and owner, compared against what your team actually did, in both directions.

Deliverable: agreement matrix + routing proposal
Q06 · C-01
Line-level remittance or rate reconciliation

One month of payments reconciled against the contract terms and the schedule version in force, with each difference classified by cause rather than aggregated.

Deliverable: variance register with cause classes
Q07 · C-04
Clearance-evidence gap

A closed review re-run to answer a question the file usually cannot: not what was found, but what was checked and cleared, and whether any reason was recorded.

Deliverable: clearance register + evidenced share
Q08 · C-08
Continuity audit on a live product

Two hundred long sessions replayed against declared world state by an automated harness. Contradictions per hour, counted rather than sampled.

Deliverable: contradictions-per-hour figure + repair list
02 · What cannot be compressedFour constraints that set the calendar, none of which are engineering
Legal and access

NDA execution and read-access provisioning to named individuals. Frequently two to six weeks, and on public-sector and regulated work it is longer than every other item combined. Start it before you decide anything else.

Validated environments

Where your environment is qualified — pharma, medical device, parts of finance — validation is your process and it sets the schedule. We design so the validatable boundary is the deterministic wrapper rather than the model, which helps, and it does not make validation fast.

Identifier and relation repair

The same object carries different identifiers in five systems and the relation you need has never been declared. This is the single most under-estimated item on every engagement, and it is work in your estate, not in ours.

Expert attention

Two to four hours a week from the person who actually knows the work. When that does not materialise the pilot does not slip — it produces a system that is confidently wrong in ways nobody caught, which is worse.

03 · Earliest horizon per capabilityAgainst the eight capabilities in section 03 · what sets the floor in each case
Capability Earliest useful resultRead-only, on your back-file Pilot with an acceptance testPropose-only, live inputs What sets the floorThe binding constraint, not the model
C-01Reconciliation10 working days4 to 6 weeksGetting the back-file, and the state of your identifier mapping between the two populations.
C-02Attribution10 working days6 to 8 weeksWhether your source hierarchy is written down. Where it is not, defining it is the first fortnight.
C-03Cause ranking10 working days, scored only6 weeksDepth and continuity of the history. Two years of clean trace data is worth more than any model choice.
C-04Rule-bound drafting15 working days6 to 8 weeksReading the enforceable text into typed obligations. Ambiguity in your own playbook surfaces here and has to be resolved by you.
C-05Tool operationNot available at H08 weeksLicensing, environment and the tool's own API surface. A tool without a scriptable interface is a different and longer conversation.
C-06Exception triage15 working days4 to 8 weeksWhether the exception taxonomy exists. Most queues are classified by habit rather than by a written rule.
C-07Multi-artefact productionNot available at H0One quarterCross-product consistency. This capability is a graph rather than a pipeline and does not have a two-week version.
C-08Capability transfer10 working days, audit only6 to 10 weeksHaving a measurement of transfer at all. Most clients do not, and building it is the first fortnight of the pilot.

H0 is free and it is the whole of what is free. We do not recover its cost later in a build fee, and roughly one in three of the H0 engagements we have run ended with us recommending that the client not proceed — usually because the workflow could not be given an acceptance test, occasionally because an existing tool already covered it. The register is yours either way, and you can take it to another supplier.

Apply for the ten-day diagnostic → · the form composes the brief in your browser and transmits nothing until you send it.

06Research programme

Enactive
Reality

Every engagement we run is also an experiment in one question: under what conditions does a digital experience leave a durable change in the person who had it? We call the answer Enactive Reality, and it is the reason this firm exists rather than a consultancy that happens to use models.

The term is borrowed deliberately. Enactivism holds that cognition arises through action in an environment, not through representation of one. The engineering consequence is specific: an environment that cannot be acted on, and cannot answer with consequences, cannot teach anything.

Formal definition

Enactive Reality is a medium in which a person enters an AI-driven world, takes a role, acts under rules that answer back, and returns with knowledge, capability, relationships or results that persist outside it.

Virtual reality asks

How does a person enter a digital space? The product unit is immersive display. The experience usually ends with the device.

The metaverse asks

Where is a person persistently online? The product unit is presence and assets. Most of the value stays inside the platform.

Enactive Reality asks

What did a person do, and who are they once they leave? The product unit is a transferable episode. Success is measured after exit.

BoundaryFive concepts that are routinely conflated
ConceptThe question it answersCore product unitAfter the session endsPosition in the stack
VRHow does a person enter a digital space?Immersive display and interactionThe experience typically stops with the hardwareA carrier
MetaverseWhere is a person persistently online?Space, identity, social graph, assetsValue largely remains on the platformA social narrative and product form
Generative RealityHow does AI continuously produce and revise a world?World state, simulation, generation, executionTechnically continuous, but agnostic to the personThe underlying technical paradigm
Enactive RealityWhat did the person do, and who are they afterwards?One transferable episodeKnowledge, capability, relationships or results are carried outThe human experience paradigm — where value is judged
Reality CompilerHow does intent become trustworthy software and real action?Tasks, typed tool calls, verification, rollbackReal-world state feeds back into the next stepThe execution infrastructure beneath all of it

The relation is simple to state and hard to build. Generative Reality produces the world. Enactive Reality changes the person. The Reality Compiler connects both to consequences that hold outside the session. We are not building a larger game; we are building the execution layer between human intent, professional tools, simulated worlds and real services.

LayersProgramme layers ER-01 to ER-06 — a separate set from the platform stack in section 01
ER-01

Experience

A person enters, takes a role, acts, and bears the consequences. Entry is a design problem; it is not the achievement.

ER-02

World model

Objects, characters, rules, time, space, causality, state and an event log. Feedback must come from readable rules, never from improvisation.

ER-03

Agent

Planning, role, dialogue, intent parsing, tool proposal, conflict and collaboration between multiple acting entities.

ER-04

Professional tools

HTML and Canvas, Python and symbolic mathematics, Blender, Unreal, CAD, business APIs. The world's credibility is borrowed from software people already trust.

ER-05

Reality

Courses, appointments, stores, manufacturing, payment, and the humans who approve and respond. The boundary where consequences become real.

ER-06

Carryover

Knowledge, capability, emotion, relationships, documents, orders and decisions that go back with the person. Without this layer the other five are entertainment.

Entry

Role, space, task, story. Necessary, and routinely mistaken for the achievement.

Consequence ↓

Each layer down adds transferable value and demands more structured state, permission and verification. Most projects stop at ER-02 and call it a product.

StateFour levels of world persistence
L0 · STATIC

Fixed content

Video, articles, fixed levels. Value is concentrated in a single act of consumption.

Commercial unit · impressions
L1 · REACTIVE

Immediate response

Characters answer, scenes react, and the state returns to zero shortly after the session ends.

Commercial unit · engagement
L2 · PERSISTENT

Durable world state

Relationships, resources, tasks and consequences are remembered. The world keeps evolving; a person returns to something that moved without them.

Where our production systems operate today
L3 · REALITY

Connected consequence

Appointments, orders, coursework, manufacturing and services cross safely into real processes, behind authorisation and human confirmation.

Gated · partial deployment
The unit of value changes

From what I watched to what I changed. People pay for continuity of state, credible consequence and transfer back into their own life or work.

The retention mechanism changes

From waiting for the next episode to returning because the world left something unresolved. Relationships, resources and commitments create the reason.

The defensibility changes

From volume of model calls to the state graph and the verified trajectory record. Reusable world rules and real outcomes become long-lived assets.

The measure of an Enactive Reality system is not how long someone stayed. It is what they took out with them, and whether it held.

StudyHub and Future Film Lab are the running instances; what they are and who uses them is in section 07. Three stop lines govern the programme. If people only watch and never act, we rebuild the interaction rather than add more content. If the model cannot hold facts and state, we shrink the world and the tool freedom until it can. If a connection to reality cannot be verified safely, it stays in simulation behind human approval — we do not ship it because the roadmap said so.

07Deployments

Systems that
survived contact

Client systems and our own products are shown separately, because they answer different questions. Client work proves the stack holds under someone else's data, permissions, exceptions and deadlines. Our own products give us an environment we control end to end, where we can push the research further than a client would reasonably fund.

None of these are demonstrations. Each one has users who notice when it is wrong. They are also not the full picture: they are the deployments we are permitted to name. Several of the workflows described in section 04 are scoped or in build under agreements that do not allow us to say whose they are, and we would rather leave a gap on this page than describe a client obliquely enough to be identified.

Jin10 Data Jin10 Data 24/7 global financial information and research platform
Client system · the graph in section 02, deployed

Who relies on it, what it replaced, and what it got wrong

Jin10 had the raw material problem every information business has: reports and newswire fragmented across topics and formats, research views that could not be retrieved as views, institutional disagreement that could not be compared, sources that could not be located, and long research sessions that broke halfway and had to be restarted.

The system we built ingests commodity, industry, macro, company and asset-class research — native text and scanned files alike — and organises views, facts, figures and industrial relationships into research products. It does not only answer what a report said. It compares consensus and dispersion across reports, tracks how a view moved over time, connects supply-chain context, and produces investor-education material with page-level source locations. Full originals stay inside Jin10's existing membership, purchase and institutional entitlement system; the derivative layer never leaks the thing it was derived from.

A single research request became a process that can be resumed rather than restarted. And when evidence is insufficient, the system says so instead of writing a confident conclusion — which is the hardest behaviour to engineer and the only one that matters to a professional reader.

Who relies on it. Research staff, editors, the investor-education team and institutional users read the same content assets through different entitlement classes. The system does not decide who may see what; the client's existing membership, purchase and institutional permission model does, and the derivative layer inherits it rather than re-implementing it.

What it replaced. A research request used to be a person, a search box and a folder of PDFs, restarted from the beginning whenever a long session broke. It is now a process that resumes. The measurable that mattered to the client was not speed: it was the share of published claims that resolve to a source, a date and a page.

What it got wrong. The first version had no cross-product consistency stage. Four artefacts generated from one evidence pack could each be internally correct and disagree with one another, and they did. Stage 09 exists because of that, and it was added after launch, not designed in. The second correction was the snapshot rule: early nodes were allowed to re-fetch, which cost us the ability to replay a conclusion. Both fixes cost more than building the stage correctly the first time would have.

155 nodes114 reasoning nodes and 41 deterministic workers: classifiers, judges, planners, interpreters, architects, writers, renderers, critics, gate judges
7 branchesNative source, public search, official filings, AKShare, Yahoo Finance, institutional terminals, private knowledge base
12 criticsDensity, visual quality, structure, data logic, subtitle timing, cross-product consistency
1 ledgerEvery published claim resolvable to source, date, page and a reproducible dataset
Education
Zhihu Zhihu MathHubLearning product inside a knowledge community

Diagnosis, task planning, interactive explanation, grading and learner state existed as five disconnected features. We joined them into one loop, so a learner moves between explanation, figure, video, practice and feedback without the system losing track of what they are actually struggling with. Mathematical claims are checked symbolically before they reach a student.

Financial information
Jin10 Data Jin10 Research InsightResearch retrieval and entitlement-aware derivative content

Reports, newswire and public data turned into searchable, comparable answers with page-level source location — and a controlled derivative layer for the content team that respects the entitlement boundaries of the material it was built from.

Own productsWhat we run ourselves · the research claim is in section 06
StudyHub

A question becomes a path that keeps moving

StudyHub organises questions, materials, courses and knowledge into a continuous learning experience. A learner starts a task, enters guided study, works through dynamic lessons and generated video, and completes interactive exercises that are graded by domain checkers rather than string comparison.

The product is not built to get one answer right. It tracks what is being studied, where the difficulty actually sits, what hint comes next, and how to move between explanation, practice, feedback and review without a reset.

StudyHub interface showing a learning task and AI interaction
Learning tasks · Dynamic lessons · Checked assessment01
Future Film Lab

Persistent characters, and the world that remembers them

Future Film Lab works on generative image and video, character agents, interactive narrative and virtual worlds. With original IP and short-form work it tests identity consistency across frames and sessions, AI-directed production, and interactive story workflows that hold together over repeated contact.

The long-run problems — persistent characters, story agents, durable environments — are the same problems the world runtime solves for industrial rehearsal, approached from the side of narrative. It is cheaper to discover a continuity failure in a short film than in a training simulator a regulator has approved.

Identity latent — consistency across frames02

08The firm

Small by design,
deep by necessity

Tunneling Technologies is a research-led engineering firm in Singapore, founded by doctoral researchers trained in China and the United States, working across trustworthy AI, causal identification, operations research, control theory, multimodal inference and the learning sciences.

We stay small on purpose. The work we do well requires the people who designed a system to be the people who sit with the client while it fails. That does not survive being staffed out, so we do not staff it out. It also means we take on a limited number of engagements and say no to most of the rest.

Method

How an
engagement
actually runs

STEP 01 / 04
01 Diagnostic

Observe the work before deciding what should be automated

We observe the work before specifying anything, then return an opportunity register naming what can be verified and what cannot. This is the free diagnostic; its full terms, duration and deliverable are set out once, in section 09, rather than restated here.

02 Pilot

One scenario, four to six weeks, a result you can reject

No large first contract. One workflow, with scope, acceptance criteria, data boundary and price fixed in advance. If it passes, we extend. If it fails, the failure is contained inside the pilot and you owe nothing further. We would rather lose a contract than defend a system that does not work.

03 Deployment

Connect to what exists rather than replacing it

The stack meets your systems of record where they are — ERP, CRM, MES, PLM, LIMS, DMS, spreadsheets, the shared mailbox — on-premises, in your cloud tenancy, or air-gapped. Data residency, model routing and retention are configured per deployment, not per vendor default.

04 Operation

Run it, measure it, and hand it over

Hosting, monitoring, per-node evaluation and change management as the business moves. The trajectory record that accumulates belongs to you. So does the source, on terms agreed before the first line is written — including the terms under which you take the whole thing in-house.

AssuranceWhat we commit to in writing
Deployment topology

On-premises, private cloud tenancy, or air-gapped. Model routing, data residency and retention set per deployment and stated in the contract.

Ownership

Data use, ownership, source code and derivative rights are fixed before work begins. The trajectory record is yours, including the failure traces.

Auditability

Every run produces an immutable ledger of inputs, model calls, checks, approvals and outputs. Reproducible on demand, including by your auditor.

Exit

A defined handover: architecture, node specifications, evaluation suites and operating runbook. No component of the system is hostage to our continued involvement.

BenchCut in two passes. The first pass is by decision rights: three people accountable inside the firm for what ships, then eight advisers who are not. The advisory bench is then cut by function — learning product, AI and infrastructure, growth and community — so that no person appears in two groups and no function is left without a named owner.

Eleven people design and build these systems: three who hold decision rights inside the firm, and eight advisers each retained against a named practice. Closed-domain work is specified by whoever has to answer for the result, so the people listed here are the people on the engagement rather than a sales layer in front of a delivery team. The shape is deliberate, and it has a price attached.

The cost is capacity. Eleven senior people cannot run many production builds at the same time, so we take a limited number of engagements and a start date is quoted as a slot rather than as an immediate yes. If a project needs to be scaled up mid-flight with additional staff, we will delay it or decline it instead of handing the work to people you have not met, and buyers who need elastic headcount should choose a larger firm.

01 · MANAGEMENTManagement

Crison

Head of Learning Product

Owns demand mining and product architecture for StudyHub

M.S. National University of Singapore; former asset allocation and quant researcher at CICC Wealth and CSC.

Writes on education and memory science for 9,000+ followers on Zhihu, and converts that reader evidence into the StudyHub requirement set rather than into a feature wish list. Her research years at CICC Wealth and China Securities are why a learning product here is specified with a stated hypothesis and a measurable before-number, the way an investment mandate is.

Febian

Head of AI & Infrastructure

Owns the core LLM tracks inside the node graph

M.S. NTU; PhD candidate at CUHK-Shenzhen; assistant researcher at the Asian Institute of Digital Finance.

Built the core LLM tracks the node graph runs on, and publishes deep learning work at ACM conferences, so the model choices are ones he has had to defend in review. His quantitative finance background sets where a model is allowed to reason and where a deterministic worker takes the result instead.

Yijing Li

Head of Growth & Community

Owns go-to-market and the client engagement pipeline

Founder and CEO of Siren AI; ex-Boston Consulting Group and Kearney; M.S. Management, Boston University.

Took an LLM-based MVP from concept to launch at Siren AI, and before that ran a 28-person sales team as a real estate VP, raising conversion 30%. Her consulting work at Boston Consulting Group and Kearney sets how an engagement is scoped: a written problem statement and a current cost in hours or headcount, or the pilot does not start.

02 · LEARNING PRODUCTStrategic advisers — Learning Product

He Jiadi

Adviser — North American market

Owns North American market entry and admissions practice

Ed.M. Harvard; Executive Director at NCSD; founder of Panda Education; Harvard and Georgetown interviewer.

Runs North American programmes at NCSD and founded Panda Education, so US-facing requirements come from someone who has placed students, not only sold to them. As an alumni interviewer for Harvard and Georgetown he sets what counts as credible evidence inside a learner record.

Liu Boyan

Adviser — academic research

Owns method review for research and effect claims

Direct-entry PhD student, School of Public Policy and Management, Tsinghua University; multiple CSSCI papers.

Reviews the research behind any learning claim the products make, and says plainly when the published evidence does not carry the weight being put on it. His CSSCI-indexed public policy work is why an effect is stated with a sample size and a method rather than as a percentage on its own.

Jin Lingxi

Senior adviser — EdTech

Owns audience testing and EdTech channel relationships

Leading mathematics and physics writer on Zhihu, 200,000+ followers; long-standing educational author.

Writes mathematics and physics for more than 200,000 Zhihu followers, which gives a live read on which explanations land and which quietly fail. His EdTech industry relationships are how new material is tested with real readers before it is built into a product.

03 · AI & INFRASTRUCTUREStrategic advisers — AI & Infrastructure

Tiange Xiang

Senior adviser — AI research

Owns the vision and spatial reasoning research direction

CS PhD student at Stanford; visiting scholar at MIT with Kaiming He; Spatial Intelligence Rising Star, CVPR 2026.

Works on spatial intelligence at Stanford and at MIT with Kaiming He, and rules on which perception methods are stable enough to put in front of a client and which are still papers. He was named a Spatial Intelligence Rising Star at CVPR 2026.

Sam

Adviser — core development

Owns inference acceleration for multimodal models

PhD, Nanyang Technological University; inference acceleration for multimodal large language models.

Works on making multimodal large language models cheaper to run, which is what decides whether a 155-node graph is affordable per document rather than only correct. He advises on where latency is bought back in the runtime instead of by removing checks.

Xiamiao Zhao

Adviser — algorithm architecture

Owns scheduling and optimisation across the node graph

PhD candidate in mathematics (operations research and cybernetics), Tsinghua University.

Operations research is the branch of mathematics that decides how work is ordered under constraints, and that is what he brings to the scheduling of an asynchronous graph. He advises on where parallel evidence branches earn their cost and where they only add it.

04 · GROWTH & COMMUNITYStrategic advisers — Growth & Community

Leonie Xu

Adviser — AI product & growth

Owns overseas market entry and the CEO network

Global Head of Market & Strategy at Wiz.AI; former head of ByteDance's overseas OKR consulting division.

Ran ByteDance's overseas OKR consulting division across roughly 100 global companies, so she reviews how an engagement will be measured before it is agreed. She co-founded the China Overseas CEO Community, 5,000+ CEOs, and the ByteDance alumni community.

Ethan Yu

Adviser — strategy & growth

Owns pricing, unit economics and pilot scoping

ML quant PM at MindQuant; formerly a risk analyst at a sovereign fund; M.S. Economics, NTU.

Builds machine-learning quant products at MindQuant and previously assessed downside as a risk analyst at a sovereign fund, which is the habit he applies to pricing. He checks that a pilot has a stated cost today in hours, headcount or error rate before any number is quoted against it.

Academic and researchAffiliations represented on the bench
NATIONAL UNIVERSITY OF SINGAPORE NANYANG TECHNOLOGICAL UNIVERSITY CUHK-SHENZHEN ASIAN INSTITUTE OF DIGITAL FINANCE TSINGHUA UNIVERSITY HARVARD UNIVERSITY GEORGETOWN UNIVERSITY STANFORD UNIVERSITY MIT BOSTON UNIVERSITY SOUTHWESTERN UNIVERSITY OF FINANCE AND ECONOMICS
IndustryAffiliations represented on the bench
CICC WEALTH CHINA SECURITIES (CSC) BOSTON CONSULTING GROUP KEARNEY BYTEDANCE WIZ.AI MINDQUANT NCSD PANDA EDUCATION SIREN AI
OfficesThree, and what each is for
APAC · ENGINEERING

Singapore

107 N Bridge Rd,
Singapore 179105

Where the systems are built and run: the 155-node financial-information graph was assembled here, and this is the deployment region for clients whose data may not leave APAC.

Asia/Singapore · UTC+8
HK · CAPITAL MARKETS

Hong Kong

33 Hysan Avenue,
46/F Lee Garden One,
Causeway Bay,
Hong Kong

The institutional client surface: pilot scoping, evidence reviews, and the reality-gate sign-offs a regulated buyer wants done in person, inside market hours.

Asia/Hong_Kong · UTC+8
US · RESEARCH

Redwood City

631 True Wind Way,
Unit 210,
Redwood City,
CA 94063

The research and partnership surface: Enactive Reality work, model and tooling partnerships, and the L3 reality-connected experiments that remain gated and partial.

America/Los_Angeles · UTC−8 (UTC−7 DST)

We publish our reasoning rather than our roadmap. If you want to test whether we understand your domain, the fastest route is not a capability deck — it is forty-five minutes on one of your workflows, where the failure modes we name either match your experience or they do not.


09Engagement

Two ways in.
Both start with
one workflow.

One is unpaid fieldwork that ends in a written register. The other is a paid standing relationship with a named principal. They are not tiers of the same thing, and the table below separates them on five axes so nobody has to guess which one applies.

Whichever you pick, the form composes the brief in your browser and transmits nothing until you send it. Copy it, take it to your own team, and argue with it before it reaches us.

Two ways to begin, and they are not variants of each other. The cut is where the decision currently sits. The free diagnostic is for an organisation that has already chosen one workflow and wants to know which parts of it can be automated to a testable standard, and which parts should be left with the people doing them. The one-to-one advisory is for a single executive who has not chosen yet, or who has a programme already running and needs a senior outside read on whether it will hold. Neither offer produces working software. And the two do not cover the whole space: if you already know what you want built and want a price for building it, that is an implementation contract, it is not described on this page, and you should write to us so it can be scoped separately. The five axes below separate the two offers; where they look similar on the surface, the axes are what tell them apart.

OFFER A

Free diagnostic

Unpaid. We examine one workflow you name and return an opportunity register that puts a labour cost and an explicit acceptance test on every line, including the lines where we recommend against automation.

OFFER B

One-to-one advisory

A paid retainer that puts one named principal alongside one executive, on a standing basis, either to decide what to build or to get a truthful read on a programme already in flight.

Who it is forcut by whether you have already chosen the workflow to change
An organisation that can name one workflow and the one person who owns it. Typical applicants are a finance director carrying a monthly reconciliation or reporting cycle, a plant manager carrying a quality or maintenance workflow, or a head of research carrying a publication and review process. You do not need a budget or an in-house technical team. You do need one process with a defined start and end, a named owner, and the willingness to let us read the materials the work actually runs on rather than a cleaned demonstration set.
One executive with the authority to change direction, in an organisation in one of two positions. Either you are not ready to build and need to decide what to build, in which case the sessions are about where the verifiable work actually is in your business. Or you have a programme already running — internal, vendor-led, or both — and need someone senior from outside to tell you whether it will reach the standard it was funded against. It is bought by the person accountable for the decision, not delegated down to the person managing the workstream.
What you put incut by whether the input is your materials or your own calendar time
One workflow, described in writing, with its named owner. Read access to the real materials behind it — the spreadsheets, the source files, the tickets, the reports as they exist internally. Half a day of on-site access with the people who do the work, or two hours of remote screen-sharing with the same people. An NDA executed before any material moves: we sign yours if you have one, ours if you do not. No purchase order, no budget commitment, and no introduction to your procurement function.
The executive's own calendar time, held as a standing slot rather than booked when something goes wrong; continuity is where the value is, and a principal who sees you once a quarter cannot tell you anything you could not read elsewhere. Access to the documents behind the decision: vendor proposals, internal build plans, programme status reports as they are written internally rather than as they are presented upwards, and the budget envelope. A tolerance for a negative answer, since a substantial part of what the retainer buys is being told that a programme already announced will not meet the standard it was announced against.
What you get outcut by whether the output is a finished document or a standing counterparty
One document, the opportunity register, with a row for each step in the workflow. Every row carries: the current state described in the operator's own words; the labour cost today, stated as people × hours per cycle and cycles per month; the verifiable portion, meaning the part of that step whose output a machine can check against a source document or a rule deck (the written set of domain rules a checker applies); the unverifiable portion, meaning the part that rests on judgement no checker can settle; and an acceptance test — the exact condition, written before any build exists, under which you would accept an automated version of that step as correct. The register also carries a written recommendation against automating specific rows, with the reason given row by row. We walk you through it in a 60-minute session and leave you the file. Nothing in it obliges you to work with us afterwards.
A named principal — the same person for the term, named in the contract before you sign, not a bench that rotates. Standing sessions with that person at an agreed cadence. After each session, a written position of about one page setting out the question you put, our answer, what evidence would change that answer, and what we do not know. On request within the retainer, a written review of a specific vendor proposal or internal build plan, assessed against the same acceptance-test standard used in the diagnostic and against the six-layer stack our own systems are built on. What you do not receive is someone who joins your stand-ups, manages your suppliers, or writes code. The honest limit: we assess what you show us and what we can ask about. Where a vendor's system cannot be instrumented or trialled, our read on it is an informed judgement on documents and answers, and we will label it as such rather than presenting it as a verified finding.
How long it takescut by whether the engagement has a fixed end date
Fixed and short. Half a day on site, or two hours remote, then five working days of our analysis. From application to register in your hands is typically four to six weeks; almost all of that gap is NDA and access turnaround inside your organisation, not analysis inside ours. The engagement ends when the register is delivered and walked through. There is no second phase unless you ask for one.
Open-ended and reviewed rather than fixed. A three-month minimum initial term, then rolling monthly, with a written review at the end of every quarter at which either side can end the arrangement without penalty and without explanation. Sessions run at a cadence set at the start and held in the diary. Advisory relationships that work tend to run past a year; the ones that do not usually end at the first quarterly review, which is what that review exists for.
What it costscut by whether money changes hands, and how the figure is set
Free. No fee, no expenses recharged, and no cost quietly recovered later in a build contract. It costs us roughly five to six person-days of senior time, which is why applications are screened against the three criteria below rather than all accepted. Two consequences follow, and you should know both before applying. We decline diagnostics that fail the criteria, in writing, naming the criterion. And the register contains no price for building anything — it gives you labour cost, acceptance tests and a recommendation; producing a build quote requires a separate, paid scoping engagement.
A paid monthly retainer. We do not publish a figure, because it is set per engagement from two inputs: the seniority of the named principal, and the hours committed to you each month, including preparation and the written work between sessions. The number is fixed in writing before the first session and does not move with usage — no hourly overage, no success fee, and no fee contingent on anything being built afterwards. If the advisory leads to a build, that is a separate contract, separately priced, and the retainer is not credited against it. For budgeting, treat a senior-principal retainer as a fraction of the monthly cost of a senior hire rather than as a contractor day rate.
Not for
Do not apply if you cannot name a single workflow and a single owner. A diagnostic spread across four departments produces a slide rather than a register, and we will not run one. Do not apply if you want a vendor comparison; we examine your process, not our competitors' products. Do not apply if the system you want is already specified and you are looking for a bid, because that is procurement and the register would tell you nothing you have not already settled. Do not apply if read access is likely to be refused once it is actually requested — we have ended diagnostics at the access stage, and both sides lost the weeks.
Do not apply if what you want is an extra pair of hands. This is not staff augmentation: the principal does not take tickets, does not manage your vendors, and does not sit inside your delivery organisation. Do not apply if you want us to build the thing, because an adviser who expects to win the implementation cannot give you an honest read on whether to implement it, and we would rather keep the read clean than hold both. Do not apply if the decision has already been taken and what is needed is an outside name on a document supporting it; we have declined that request before and will decline it again. And if the executive in the sessions cannot change the programme's direction, the retainer will produce well-written positions and no change to the outcome.
How we decideThree tests, applied in order
Bounded enough to verify

The work must produce an output that a named person can mark right or wrong against something outside the model — a source document, a rule deck, a reconciliation, a physical measurement — and we must be able to write that acceptance test in plain sentences before any build begins, because a test written after the system exists is written to the system rather than to the work.

Painful enough to fund

Somebody inside your organisation must be able to state what the work costs today as people × hours per cycle, as an error or rework rate, or as elapsed days against a deadline that matters; where no one can produce that number, the pain has never been measured, and unmeasured pain does not survive a budget round however real it feels day to day.

Owned by someone who can accept or reject

One named person, not a committee, must hold the authority to sign the acceptance test at the start and to reject the delivered result at the end; where that ownership is split across two functions, the first thing an automated system does is expose the split, and it is cheaper for you to resolve it before the engagement than in the middle of one.

What happens after you applyIncluding the step where we may decline
01 · Day 0 to day 2
1. Application, and a written reply

You send the workflow, the named owner, one paragraph on what it costs today in hours or headcount, and which of the two offers you are applying for. A principal reads it. Within two working days you receive a written reply that either accepts you to a screening call, declines with the reason stated, or comes back with two or three specific questions we need answered before we can decide.

You, then a principal on the intake rota — not an account manager
02 · Within five working days of that reply
2. Screening call, 30 minutes

We test the three criteria out loud. We ask what the work costs today, what an acceptable result would look like, and who signs it off. You should use the same half hour to ask what we have not built and where our own claims are thin — the reality-connected persistence level of our platform is gated and only partly proven, and we will say so on the call rather than after the contract.

The named principal and the workflow owner or the executive; no wider audience
03 · Within two working days of the call
3. Decision, including the point at which we say no

We decide in writing. If we decline, we name the criterion that failed and what would have to change for a later application to succeed. This is the step where most declines happen, and the two most common reasons are that no single person can accept or reject the result, and that the workflow's output is something nobody can mark right or wrong. Declining costs you a half-hour call; accepting an engagement that fails these tests would cost you a quarter.

Two principals, one of whom was not on the call
04 · Three to ten working days, driven almost entirely by your legal function
4. NDA, access and scheduling

The NDA is executed, read access is provisioned to named individuals on our side only and revoked at the end, and dates are fixed — the half-day on site or the two-hour remote session for the diagnostic, or the first standing session and the ongoing cadence for the advisory. This step, not our analysis, is what turns a two-week start into a five-week one. If your NDA turnaround is slow, say so at step one and we will send ours on the first day.

Your legal or procurement function and the named owner; our operations lead
05 · Diagnostic: register delivered five working days after the session, walked through within a further three. Advisory: first session within ten working days of signature, first written position within two working days of that session
5. Delivery, and an explicit end

For the diagnostic you receive the opportunity register, we walk you through it in 60 minutes, and the engagement ends there — no automatic next step, no proposal attached to the back of it. For the advisory the relationship begins and runs to the first quarterly review, at which either side can stop without penalty. In both cases the documents are yours to keep, circulate internally, and show to any other supplier you are considering.

The named principal, plus the two analysts who build the register on the diagnostic
LibraryFive teaching films · named-account access, requested below

Each film takes one hard idea, explains the mechanism, and shows the failure it prevents — using real graphs, real traces and real defects, including ours. Films 01 and 02 cover most of what a technical evaluator needs before a first meeting. Tell us which are relevant and we will send those and skip the rest.

FILM 01 · THESIS04:20
01 · The barrier

Why capable models stop at the edge of real work

A model that can pass a professional examination still cannot be handed a professional's responsibilities. The film separates the four things that are actually missing — authority, state, verification and consequence — and shows what each one costs to build.

00:00The tunnelling metaphor, and why we mean it literally 00:55Capability is not the constraint. It stopped being the constraint some time ago. 01:50Four missing layers, demonstrated on one invoice 03:05What an institution is actually buying when it buys autonomy
FILM 02 · ARCHITECTURE08:40
02 · Anatomy of a 155-node graph

A full walkthrough of a production execution graph

Eleven stages, node by node, on the real system. Where it fans out, where it must synchronise, what each critic is looking for, and the three places we got the topology wrong before it worked.

00:00Ingest, resolve, snapshot — why the snapshot comes first 01:40Seven evidence branches and the conflict resolver between them 03:30Four product pipelines running concurrently off one insight pack 05:45Cross-product consistency: the stage everyone underestimates 07:10The publication gate, and what it has refused to pass
FILM 03 · METHOD06:10
03 · Verification

Looking correct and being correct are different problems

Built around four real failures: a chart whose axis was right and whose series was not, a solid that would not print, a citation that pointed at the wrong page, and a sentence that was true in May. Each one shows the checker that now catches it.

00:00Why plausibility is the enemy, not hallucination 01:20State read-back: never trust a self-reported success 03:00One checker per claim class, and how to know you are missing one 04:40Localised repair versus regeneration, on a forty-step task
FILM 04 · VISION07:30
04 · Enactive Reality

The research programme, stated without decoration

What the term means, where it comes from in cognitive science, how it differs from virtual reality and the metaverse, and the six-layer structure required to make an experience leave something behind. Includes the three stop lines we hold ourselves to.

00:00Enactivism in one minute, and why the engineering follows from it 01:30Five concepts that get conflated, separated properly 03:20The six layers, and where most products stop 05:10L2 persistence: what it does to a business model 06:30Three stop lines, and the ones we have actually invoked
FILM 05 · ENGAGEMENT05:00
05 · A diagnostic, end to end

Half a day on site, and the document it produces

Shot during a real diagnostic, with the client's permission and their figures removed. What we watch for, the questions that change the answer, and the opportunity register we hand back — including the two items we recommended against automating.

00:00Observation before specification 01:15Finding the workflow that is bounded enough to verify 02:40Writing an acceptance test the client can fail us on 04:00What we recommended not doing, and why
Application desk · free diagnostic and one-to-one advisoryComposed in your browser · nothing is transmitted until you press send
Who reads it

A principal on the intake rota, not a sales function. There is nobody here whose job is to qualify you. A written reply within two working days, including the reply that says no.

What happens to what you write

The brief below is assembled in your browser. Nothing leaves the page until you send or copy it. We do not run analytics on the form, and the address you give is used to answer you and for nothing else.

What it costs

The diagnostic is unpaid and its cost is not recovered later. Advisory is a monthly retainer set per engagement. Roughly one in three diagnostics ends with us recommending you do not proceed, and you keep the register.

ApplyNine questions · the brief updates as you answer
00What you are applying for
01Sector
02What the finished work has to be — the capability catalogue in section 03
03Where you want to start — the horizons in section 05
04Systems of record it touches — select all
05Data boundary
06Volume through the workflow
07What breaks today
08Where to reply
DIAGNOSTIC SCOPE BRIEF — COMPOSED LOCALLY DRAFT
Send this brief →
ContactOne concrete problem is enough to begin
hello@tunneling.tech

Written to by a person, answered by a person, within two working days. If a message needs a technical answer we would rather be slow and correct, and we will say so on day two rather than go quiet.

Enterprise engagements

Diagnostic → pilot → deployment. Fixed scope, fixed acceptance, fixed price at every stage. Apply in section 09.

Research collaboration

Joint work on execution graphs, verification, world runtimes and the Enactive Reality programme.

Briefing access

Named-account access to the five films, the full narration scripts and the on-screen figures, for technical evaluators.