← Files The Business EngineerARCHIVED FILE
data/complete-library.md
443 KB · Oct 2, 2026 · 00:33 UTC
# THE BUSINESS ENGINEER — THE COMPLETE LIBRARY
### One operating system for the AI era: 261 core models, 13 disciplines, 15 instruments
*Analysis by The Business Engineer — by Gennaro Cuofano · businessengineer.ai*
**Consolidated edition.** This file is the whole system in one place: the core model library (261 models across 25 categories) merged with the framework engines of all thirteen disciplines, the shared instruments they hold in common, and the practice layer that runs them. It replaces the separate core library, the discipline files, and the capital-cycle skill; where an instrument used to appear in several files, it now has one home and every other seat points to it.
It is not a stack of books. It is one instrument, read in the order the work actually happens.
---
## THE THINKING OS
Every model runs on the same five-move engine. Learn the engine and the library becomes one instrument rather than a list.
1. **Structure before data.** Look for the mechanism, never the surface phenomenon. Every outcome traces to a structural cause; data validates or falsifies structure, it does not replace it.
2. **Meta-compression.** Extract the transferable principle from the specific case. If a pattern works in one place, ask where else it applies.
3. **The integration engine.** Trace impact around the loop: technology, economy, behavior, narrative, technology.
4. **Layered output.** Serve the headline, the framework, and the deep dive at once — one artifact for the skimmer and the operator.
5. **Strategic compression.** If I had thirty seconds, what matters? What one decision does this enable? Can it be shown in a single graph? What would a leader do differently after reading it?
**The reading always opens.** No model executes against an unstated thesis: name where value is moving and what would falsify it, then apply the frameworks.
**The analytical hierarchy**, which decides what constrains what: geopolitics, then macroeconomics, then technology, then business. A market-level analysis that ignores the layers above it is built on sand.
---
## THE ANALYTICAL ENGINE (run before any output)
Five layers, in order, no layer skipped. Beautiful formatting on shallow analysis is worse than ugly formatting on deep analysis.
**Layer 0 — Meta-rules.** Structural or narrative? Four tests: can I trace cause to effect through specific steps (mechanism); would the outcome change without this mechanism (counterfactual); what evidence would disprove it (falsifiability); has this pattern produced this outcome before (precedent). Then first principles: what are the physics-level constraints, where is the binding one, what changes if it relaxes. Then temporal context: what changed, how fast, what window, what happened last time.
**Layer 1 — Pattern recognition.** Match the situation to the model library (Parts I and II). Two or three models, at least one of which the subject could fail.
**Layer 2 — Evaluation.** Select the framework the question actually calls for, apply it systematically, score the dimensions, judge fitness. Four lenses regardless of framework: value and positioning, capability and technology, distribution and reach, economics and sustainability.
**Layer 3 — Strategic assessment.** Moat classification with its decay signal. Flywheel identification: the fuel, the friction, the direction of travel, what would break it. Bottleneck cascade: every bottleneck labelled resolved, active, emerging, or future, with the critical one named. Platform dynamics where they apply. Disruption assessment: S-curve position, incumbent and insurgent advantages, crossing point, asymmetric motivation.
**Layer 4 — Synthesis and compression.** Core insight in one sentence. One visual. One decision it enables. Cross-domain connection. What to do and what to watch.
---
## THE ARCHITECTURE — the arc of the work
| Part | Stage | What it holds |
|---|---|---|
| **I** | **The general toolkit** | Core models 1–110, categories I–XIII — thinking, structure, strategy, entry, moats, flywheels, business models, decisions, organization, markets, distribution, leaders |
| **II** | **Read the era** | Core models 111–261, categories XIV–XXV — capital cycles, contagion and joints, clocks, the supercycle premise and the fifth clock, the ten seats, incidence at the top of the stack, the intelligence stack, measurement under pressure, valuation, the enterprise, the organization, the rhymes |
| **III** | **Design the firm** | The Business Architect · AI Economics |
| **IV** | **Run the firm** | The Business Orchestrator · The AI CFO |
| **V** | **Build the machine** | AI Engineering · Agent Engineering · Harness Engineering · AI Product Engineering · Security Engineering |
| **VI** | **Grow it** | AI Growth Engineering |
| **VII** | **Take the field and close** | The Forward-Deployed Engineer · Enterprise Sales · The Enterprise Buyer |
| **VIII** | **The practice layer** | Fifteen instruments, the visual register, the writing standard, the checklists |
Every discipline inherits Parts I and II and adds its own engine, modes, named laws, failure library, and maturity ladder.
---
## THE MASTER INDEX
Counted honestly. A framework and a maturity rung are not the same thing, so they are counted separately: **models** are mental models, laws, and lenses; **apparatus** is the operating machinery each seat runs on (engines, mode cards, gauges, failure libraries, maturity ladders, templates, calendars, interop rules).
| # | Part | Discipline | Models | Apparatus | Jurisdiction — what it owns |
|---|---|---|---|---|---|
| 00 | I–II | **Core Model Library** | **261** | — | The shared vocabulary every discipline inherits |
| 01 | III | The Business Architect | 32 | 31 | Design the firm: the four choices, position, moats, own-vs-rent |
| 11 | III | AI Economics | 68 | 22 | Design the money: unit economics, margin as design, the capital tests |
| 02 | IV | The Business Orchestrator | 22 | 38 | Run the firm: junctions, cadences, leverage, the operating model |
| 12 | IV | The AI CFO | 42 | 13 | Sign the check: the counting rule, LEDGER, capex/opex, controls |
| 07 | V | AI Engineering | 41 | 11 | The stack: agentic loops, measurement under pressure, frozen suites |
| 03 | V | Agent Engineering | 41 | 30 | The unit: charter, golden set, the gate stack, graduation |
| 04 | V | Harness Engineering | 33 | 28 | The system: map, record, loops, gauges, taste encoded |
| 08 | V | AI Product Engineering | 44 | 5 | The product: eval-as-spec, the five pillars, activation, pricing as design |
| 10 | V | Security Engineering | 51 | 28 | Secure the estate: machine identity, injection defense, the six-plane control |
| 09 | VI | AI Growth Engineering | 45 | 8 | Grow it: the five loops, machine discovery, metrics that survive agents |
| 05 | VII | The Forward-Deployed Engineer | 48 | 7 | The field: wedge, embedding, on-site build, title and handover |
| 06 | VII | Enterprise Sales | 29 | 16 | The deal: account, champion, case, gauntlet, price, NRR |
| 13 | VII | The Enterprise Buyer | 54 | 4 | The purchase: VERIFIED, proof on your terms, title search |
| | | **Total** | **811** | **241** | 261 core + 550 discipline models, plus 241 apparatus items |
Fifty entries that previously appeared in two or more chapters now appear once, at their canonical home, with a pointer from every other seat. Those pointers are what make this one system rather than thirteen overlapping ones.
---
## THE SHARED SPINE
The instruments that recur across three or more seats. Reuse them by name; never re-derive them.
| Instrument | Canonical home | What it is |
|---|---|---|
| **The suite** (frozen set) | AI Engineering | The referee the loop cannot see: real cases, expert-adjudicated, frozen before the build, held out, versioned |
| **Cost per accepted outcome** | AI Economics | The denominator for everything — tokens, compute, and the attention bill you cannot buy |
| **The counting rule** | AI Economics | Each end-customer dollar once, at the tier where it transacted |
| **The charter** | Agent Engineering | One page: outcome, standard, thresholds, surfaces, boundaries, autonomy tier, owner |
| **The gauge page** | Harness Engineering | The retention and renewal instrument; what the board reads instead of a pilot count |
| **The two surfaces** | AI Product Engineering | Humans see the interface, agents see the specification; one referee grades both |
| **The junction** | Core (Model 135) | Where private rules, data, and decisions are encoded and enforced — own it, rent the ends |
| **The residue** | Core (Model 219) | The decision loop's second output: the only growth loop machines cannot mediate |
| **The property line** | Core (Model 135) | Drawn deliberately, per workload |
| **The absorption line** | Core (Model 198) | Perishable compensation versus durable requirement |
| **Clear title** | Core (Model 136) | KEPT, PARTIAL, CAPTURED — exit as config change, project, or rebuild |
| **The refusal log** | The Forward-Deployed Engineer | Saying no in writing, kept as an artifact |
| **The six failure families** | AI Engineering | The diagnosis map, inherited by every build seat |
| **Time-to-magic** | AI Product Engineering | First verified outcome, measured from first contact |
| **The seat** | Core (Model 154) | The ten positions on the financial clock; name it before running any test |
---
## HOW TO USE THIS LIBRARY
- **To read a situation:** start in Parts I and II. Name the seat and the layer first, match the pattern, then ask the cross-reference question — where else does this pattern appear, and at which altitude?
- **To act:** move to the discipline whose jurisdiction owns the output. Design goes to the Architect; running the firm to the Orchestrator; a unit to Agent Engineering; the money to AI Economics and the CFO; the field to the FDE; the deal to Sales; the purchase to the Buyer.
- **To produce anything:** run the analytical engine first, then Part VIII for the instrument and the register.
- **Never one model for everything.** Decompose the problem into the parts each discipline owns, and let the counter-lens — the discipline's natural opponent — test the answer before it ships.
- **Apply, do not dump.** The value is in the application. Reference frameworks in analysis; never reproduce the catalog.
---
# PART I — THE GENERAL TOOLKIT
# PART II — READING THE ERA
## The Core Model Library — 261 models, 25 categories
Categories I–XIII carry the full register: essence, how to apply, and the question the model asks. Categories XIV–XXV carry the compressed register: essence and the question, because these families were minted case by case and their machinery lives in the instruments of Part VIII.
### I. THE BE THINKING OS
**1. BE Thinking OS**
The integrated cognitive architecture that works simultaneously as a method of analysis, a relevance filter, and a refinement loop — converting complexity into deployable insight by forcing every input through structural, contextual, and pragmatic gates before any output.
- **Apply**: Receive input, activate the structural filter (what system is at play?), pass through the contextual gate (who needs this, why now?), compress to the load-bearing insight, format for deployment, then feed the output back for calibration.
- **Key Q**: "Is this insight structurally grounded, contextually anchored, and deployable — or just interesting?"
**2. Structural Thinking as Default**
The discipline of always seeking the framework, system, or structural view before engaging with content — structure is the primary mode of cognition, not a tool reached for, and data is used to validate or falsify it.
- **Apply**: On any new information, pause before reacting, ask what system it belongs to, identify the structural skeleton (inputs, mechanisms, outputs, feedback), then engage the content details and check whether they confirm or break the structural hypothesis.
- **Key Q**: "What is the structure here — and does the content confirm or break it?"
**3. Contextual Precision**
Anchoring every analysis in three coordinates — WHO it is for, WHY NOW it matters, and HOW it will be used — because even structurally perfect analysis becomes noise without context.
- **Apply**: Before analyzing, define the audience, identify the temporal trigger, and determine the output mode; calibrate depth, language, and emphasis to all three, and strip anything that doesn't serve the specific context.
- **Key Q**: "For whom, why now, and how will this be used?"
**4. Meta-Compression**
Reducing any insight to its minimum viable form across three levels — conceptual (core idea), structural (mechanism), and deployment (action) — through distillation under pressure where every surviving word is load-bearing.
- **Apply**: Start from the full analysis, extract the one-sentence core, compress the mechanism to 2-3 steps and the deployment to one actionable line, then test that the compressed version still carries the structural insight rather than a platitude.
- **Key Q**: "Can I compress this further without losing the mechanism?"
**5. Layered Output Logic**
Structuring any analysis into three nested layers — macro mechanism, organizational impact, and operator takeaway — so multiple audiences extract value from the same output while each layer stands alone.
- **Apply**: Identify the macro mechanism first, translate downward to organizational impact and then to the individual operator's next decision, verify vertical coherence, and format so readers can enter at any layer.
- **Key Q**: "Does this analysis work for the strategist, the manager, AND the operator — simultaneously?"
**6. Pragmatic Rigor**
Prioritizing mechanism, causality, and feedback loops over narrative polish — every claim must be "load-bearing" and falsifiable, because an insight that sounds good but lacks a causal mechanism creates false confidence.
- **Apply**: For each claim, apply the load-bearing test (remove it — does the argument collapse?), cut decorative claims, make surviving mechanisms explicit, identify amplifying or dampening feedback, and state what evidence would disprove it.
- **Key Q**: "Is every claim in this analysis load-bearing — or am I decorating?"
**7. Edge Framing**
Systematically interrogating consensus to surface what the market has mispriced, overlooked, or gotten structurally wrong — disciplined search for insight, not contrarianism for its own sake.
- **Apply**: Map the consensus and its embedded assumptions, stress-test each, look for the overlooked or mispriced variable, validate that the edge is structural (backed by mechanism), and frame the insight around the gap between consensus and reality.
- **Key Q**: "What has the consensus mispriced, overlooked, or gotten structurally wrong?"
**8. Integration Engine**
Connecting insights across technology, economics, behavior, narrative, and incentives into a unified view, because real outcomes are determined by the interaction of all five domains simultaneously.
- **Apply**: Analyze the phenomenon through each of the five lenses independently, map their interactions, identify the dominant driving layer and the lagging layer — the gap between them is where the insight lives.
- **Key Q**: "Which domain is driving this outcome — and which domain hasn't caught up yet?"
**9. Strategic Narrative Compression**
A three-phase deployment protocol for communicating structural insight — Orient (stakes and audience), Illuminate (the mechanism), and Activate (actionable implications).
- **Apply**: Open by orienting the audience on what's at stake, illuminate the mechanism in 2-3 steps, activate with a concrete next move; test that the Orient phase alone signals relevance and the Activate phase alone enables action.
- **Key Q**: "Have I oriented, illuminated, and activated — or just informed?"
**10. Calibration Loop**
Iteratively refining the same insight across variants — sharper, more contrarian, more compressed, more audience-specific — until maximum precision is reached, since the first draft is never the best.
- **Apply**: State the insight, generate sharper, more contrarian, and 50%-compressed versions plus an audience-reframed one, compare which is structurally strongest, adopt the winner, and repeat if needed.
- **Key Q**: "Is this the sharpest, most precise version of this insight — or can I compress and calibrate further?"
### II. STRUCTURAL ANALYSIS TOOLKIT
**11. Structural vs Reactive Thinking**
The distinction between reactive thinking (Event → Response) and structural thinking (Event → System → Mechanism → Implication); the response must address the mechanism, not the symptom.
- **Apply**: When an event occurs, catch yourself before reacting, ask what system produced it, identify the causal mechanism, map second-order implications, then respond to the mechanism.
- **Key Q**: "Am I reacting to the event — or understanding the system that produced it?"
**12. Structural Thinking Workflow**
The five-step sequence for converting observation into structural insight: Pattern Recognition, Structural Diagnosis, Constraint Identification, Leverage Point Discovery, and Second-Order Implications.
- **Apply**: Observe recurring patterns, hypothesize the system generating them, find the single binding constraint, locate the high-leverage intervention point, and project the consequences of consequences.
- **Key Q**: "What is the binding constraint, and where is the leverage point?"
**13. Reality Gap Analysis**
A diagnostic that identifies the chasm between what markets believe (narrative) and what structural forces will deliver (reality) — the gap is where mispricing lives, and structure eventually wins.
- **Apply**: Map the dominant narrative, map the structural forces (capital, technology, regulation, competition), measure the size and direction of divergence, estimate the convergence timeline, and position accordingly.
- **Key Q**: "Where is the gap between what the market believes and what structural forces will deliver?"
**14. Hidden Driver Detection**
A three-layer diagnostic of puzzling decisions — Stated Reason (PR), Plausible Reason (analyst take), and Structural Driver (existential imperative) — where the real explanation almost always lives at layer three.
- **Apply**: Note the stated reason, apply analyst logic for the plausible reason, then dig to the existential constraint that makes the decision inevitable; test by asking whether they'd act even if the first two reasons were false.
- **Key Q**: "What is the existential imperative that makes this decision structurally inevitable?"
**15. Constraint Mapping**
A method for finding the single binding constraint via three tests — Bottleneck (what breaks first at 10x?), Substitution (is it truly irreplaceable?), and Veto (who can single-handedly block everything?).
- **Apply**: List apparent constraints, run all three tests, and the constraint that breaks first, can't be substituted, and holds veto power is the binding one — address it before anything else.
- **Key Q**: "What is the single binding constraint — and what happens if it's relaxed or tightened?"
**16. Power Distribution Analysis**
Mapping where real leverage resides by distinguishing three power types — Veto (block without alternatives), Compulsion (force action), and Rule-Making (reshape the game's rules).
- **Apply**: Identify all actors, assess each for veto, compulsion, and rule-making power, map the distribution, find the dominant holder, and build strategy that accounts for or works through them.
- **Key Q**: "Who can block, who can force, and who can rewrite the rules — and are they the same actor?"
**17. System Fragmentation Mapping**
A diagnostic revealing where apparent integration masks actual separation, across four states: Visible Integration, Hidden Fragmentation, Cosmetic Integration, and Deep Fragmentation.
- **Apply**: Test data flow, incentive alignment, and operational dependency across a supposedly integrated system, classify each connection into one of the four states, and read true fragmentation for vulnerability and opportunity.
- **Key Q**: "Is this system genuinely integrated — or is the integration cosmetic?"
**18. Structural Reality Framework**
A four-layer cascade — Geopolitics → Policy → Infrastructure → Markets — in which each higher layer constrains the degrees of freedom of all layers beneath it.
- **Apply**: Start at geopolitics and work down through policy and infrastructure to markets; never analyze a lower layer without checking the constraints imposed by all layers above.
- **Key Q**: "What higher-layer constraints am I ignoring that will override my market-level analysis?"
**19. Constraint Cascade Principle**
The principle that upstream structural misalignment (geopolitical > policy > infrastructure) is always more lethal than downstream competitive inefficiency.
- **Apply**: Before any competitive analysis, audit the geopolitical, policy, and infrastructure layers; if any upstream layer is misaligned, fixing downstream layers is futile — address the cascade from the top.
- **Key Q**: "Is there an upstream constraint that makes all my downstream optimization pointless?"
**20. Perspective-First Analysis**
Starting with qualitative territory understanding to generate hypotheses before designing targeted measurement — avoiding the trap of measuring everything and understanding nothing.
- **Apply**: Understand the territory qualitatively first, form 2-3 structural hypotheses, design measurements that would confirm or falsify each, collect only that data, and let results refine perspective.
- **Key Q**: "Do I understand the territory well enough to know what to measure — or am I measuring blindly?"
**21. Territory Mapping**
A four-question diagnostic for rapidly understanding any landscape: What game is being played? Who are the real players? What drives behavior? What are the structural forces?
- **Apply**: Identify the game type, map the players with real power, identify behavior drivers (incentives, constraints, fears), and map the structural forces; their intersection reveals the true territory.
- **Key Q**: "What game is being played, by whom, driven by what, and shaped by which structural forces?"
### III. GRAND STRATEGY & PLANNING
**22. Grand Strategy Framework**
The master planning sequence Territory → Map → Routes — understand the landscape, derive the strategic interpretation, then execute tactics; most start with routes and work backward.
- **Apply**: Invest heavily in territory understanding, derive your strategic map (opportunities, threats, leverage points), design tactical routes with sequence and contingencies, and update the map as territory shifts.
- **Key Q**: "Am I building strategy from territory understanding — or guessing the territory from my preferred tactics?"
**23. Time Horizon Analysis**
Simultaneously planning across three horizons — Immediate (0-2yr, survival), Mid-Term (3-5yr, positioning), Long-Term (6-10+yr, structural bets) — managing all three at once, not sequentially.
- **Apply**: For any strategic question, analyze across all three horizons, check for conflicts between the immediate plan and long-term bets, and allocate attention and resources across all three so none goes to zero.
- **Key Q**: "Am I managing all three time horizons simultaneously — or sacrificing the future for the present?"
**24. Contextual Map (2x2)**
A prioritization matrix of Strategic Impact vs Uncertainty producing four quadrants — Invest, Hedge, Track, Scout — preventing over-investing in certainties and ignoring wild cards.
- **Apply**: Rate each initiative on impact and uncertainty, place it in a quadrant (Invest = commit, Hedge = optionality, Track = monitor cheaply, Scout = cheap exploration), and reassess quarterly.
- **Key Q**: "Am I allocating resources based on the actual combination of impact and uncertainty — or defaulting to what feels safe?"
**25. Tactical Routes Framework**
Translating strategic maps into execution via a three-part Assessment (External, Internal, Constraints) and four route types — Vertical, Horizontal, Diagonal, and Combination.
- **Apply**: Assess the external environment, real internal capabilities, and hard constraints, then select the route that matches the assessment (deepen, broaden, both, or an orchestrated sequence) and execute.
- **Key Q**: "Does my tactical route match my actual assessment — or my ambition?"
**26. Multi-Horizon Strategic Map**
A resource-allocation model operationalizing Time Horizon Analysis — 70% to Immediate, 20% to Mid-Term, 10% to Long-Term — executed simultaneously, not sequentially.
- **Apply**: Audit current allocation, redistribute toward 70/20/10, give each allocation an owner and metrics, run all three in parallel, and review the ratio quarterly without letting any horizon hit zero.
- **Key Q**: "Is my resource allocation balanced across all three horizons — or has the immediate consumed everything?"
**27. Contextual Adaptability Framework**
Assessing organizational fitness to shifting environments across three dimensions — Forces (what's changing?), Capabilities (can we respond?), and Horizons (are we tracking where it's heading?).
- **Apply**: Map shifting forces, assess whether current skills and structure can respond, assess whether the organization looks far enough ahead, then strengthen the weakest dimension before a crisis forces it.
- **Key Q**: "Are we fit for the current environment AND the one that's emerging — or only the one we grew up in?"
### IV. MARKET ENTRY & SCALING
**28. Strategy Lever Framework**
The five-step go-to-market sequence — Blue Sea, Niche Down, MVA, Adjacent Niches, Scale — starting impossibly small, proving value, and expanding from strength.
- **Apply**: Find a premium niche, select the tightest coherent segment, define the minimum viable audience, serve them until value is proven, expand into adjacent niches, and scale only after validation.
- **Key Q**: "Am I starting small enough — or trying to scale before proving value to the tightest possible audience?"
**29. Blue Sea Strategy**
An inversion of Blue Ocean — instead of uncontested mass markets, start from the smallest viable premium niche where you have structural advantage from day one, then expand organically.
- **Apply**: Find small markets where premium customers are underserved, verify your structural edge, enter with a premium offering, use early margins to fund adjacent expansion, and never go mass-market before the niche is dominant.
- **Key Q**: "Where can I find the smallest premium niche where I have a structural advantage from day one?"
**30. Minimum Viable Audience (MVA)**
The smallest group that can sustain a business — the tightest cluster whose problem is urgent enough that they pay, stay, and advocate — found by zooming into existing markets, not imagining new ones.
- **Apply**: Zoom into an existing market for the most urgent underserved problem, define the smallest group high on urgency, willingness to pay, and accessibility, and let that audience define the product.
- **Key Q**: "Who are the fewest people who need this most urgently — and can they sustain the business?"
**31. Niche-to-Microniche Strategy**
Targeting the smallest coherent segment — a microniche so specific you can serve every member personally — to trigger fast feedback loops and early proof of value as a launchpad.
- **Apply**: Make your niche smaller and more specific, enter with a hyper-specific offer, talk to every user and iterate daily, achieve undeniable proof of value, then expand to adjacent microniches.
- **Key Q**: "Is my target segment small enough for fast feedback and proof of value — or too broad for either?"
**32. Adjacent Niche Expansion**
Systematically entering neighboring segments using existing know-how, brand, and infrastructure — expansion by proximity, not random diversification.
- **Apply**: Map adjacent segments, test whether your advantage transfers, whether existing infrastructure serves them, and whether your brand grants permission; prioritize the highest-scoring niche and enter with a tailored offer.
- **Key Q**: "Which adjacent niche can I enter where my advantage, infrastructure, and brand credibility transfer most naturally?"
**33. Transitional Business Model**
The recognition that business models must transform at each growth stage — 0→1, 1→10, 10→100 — along with mindset and org design; clinging to the model that got you here makes you the constraint.
- **Apply**: Assess your growth stage and model fitness, watch for transformation triggers (plateaus, friction, misalignment), redesign the model for the next stage, and evolve mindset and org design alongside it.
- **Key Q**: "Is my current business model still fit for this growth stage — or am I clinging to the model that got me here?"
**34. Business Scaling Framework**
Scaling requires product, business model, and organizational design to align in serving progressively wider segments — a coordinated transformation, not just doing more of the same.
- **Apply**: Assess whether product, unit economics, and org can each handle the next wider segment, identify the lagging dimension, fix it, and scale only when all three are aligned.
- **Key Q**: "Are my product, business model, and org design all aligned for the next stage of scale — or is one lagging?"
**35. Scalability Matrix**
A 2x2 of Cost of Error vs Feedback Loop Type yielding four scaling approaches — Optimal, Constrained, Controlled, and Non-Scalable.
- **Apply**: Assess your error cost and feedback speed, plot your quadrant, and match the approach (scale aggressively, scale patiently, scale with guardrails, or don't force scale) — reassess as the business evolves.
- **Key Q**: "What is my real error cost and feedback speed — and is my scaling approach appropriate for that combination?"
**36. Fractal Market Expansion**
Market dynamics repeat at different scales — patterns that work at microniche level often recur at niche, segment, and market level — but dynamics change with scale, so smaller scales are safer test beds.
- **Apply**: Identify the winning micro-level pattern, hypothesize it repeats at the next scale, test with controlled expansion, adapt execution to the new scale's dynamics, and expand one level at a time.
- **Key Q**: "Does my winning pattern repeat at the next scale — and what dynamics change as I grow?"
**37. Speed-Reversibility Matrix**
A decision framework of Impact vs Reversibility — Strategic Deliberation, Smart Experimentation, Careful Consideration, and Rapid Iteration — preventing both paralysis and recklessness.
- **Apply**: Assess a decision's impact and reversibility, plot the quadrant, and match speed and rigor accordingly — avoiding treating reversible decisions as irreversible or vice versa.
- **Key Q**: "Is this decision high-impact and irreversible (deliberate) — or low-impact and reversible (just do it)?"
### V. COMPETITIVE STRATEGY & MOATS
**38. Moat Hierarchy (Level 1/2/3)**
A three-tier classification of moats by durability — Level 1 static (brand, scale, patents), Level 2 dynamic (network effects, lock-in), Level 3 compounding interaction moats that widen with every user interaction.
- **Apply**: Classify your moats, use Level 1 to buy time, monitor Level 2 for paradigm shifts, and build toward Level 3 where every interaction improves the product — build sequentially from 1 to 3.
- **Key Q**: "Do my moats compound with every user interaction — or are they static and erodible?"
**39. Five Defensible Moats in AI**
The five moat types with real defense in AI — Data Network Effects, Community, Specialization Depth, Workflow Lock-in, and Enterprise Relationships — each with different build times and vulnerabilities.
- **Apply**: Assess which moat matches your capabilities, build one to critical mass before layering a second, monitor each type's vulnerability, and layer 2-3 that reinforce each other.
- **Key Q**: "Which of the five AI moats am I building — and is it the right one for my capabilities?"
**40. Compound Moat Strategy**
Building the strongest positions by layering moats sequentially — establish one flywheel, then add an adjacent moat the first naturally reinforces — because each moat needs focused investment to reach critical mass.
- **Apply**: Select the moat you can build fastest, invest concentrated resources until its flywheel spins, then add the adjacent moat it most supports; two spinning flywheels create exponentially harder defense.
- **Key Q**: "Is my first moat's flywheel spinning before I try to build a second — or am I diluting across unproven moats?"
**41. The Survival Test**
The competitive litmus test — "If the most powerful competitor copied your product tomorrow with unlimited resources, would users stay?" — and if so, exactly why.
- **Apply**: Imagine the strongest competitor copies you; if users would leave, pivot to moat building immediately; if they'd stay, identify the specific retention factors and double down, re-running the test quarterly.
- **Key Q**: "If the most powerful competitor copied us tomorrow, would our users stay — and what specifically would keep them?"
**42. Three Layers of AI Industry**
A structural model of the AI industry — Foundational (general engines), Middle (vertical specialists), Application (user-facing products) — each with distinct dynamics, moats, and capital needs.
- **Apply**: Identify your layer, assess whether you're optimally positioned for its competitive dynamics, and if stuck between layers with no clear advantage, commit to one or find a unique cross-layer position.
- **Key Q**: "Which layer of the AI industry am I competing in — and do I have the right assets for that layer's dynamics?"
**43. Tech Moat → Market Power Translation**
How technical capability converts into market power through three channels — Efficiency, Distribution, and Brand — since a technical moat alone doesn't guarantee dominance.
- **Apply**: Inventory technical capabilities, test each against the three translation channels, cut what doesn't translate through any, and invest in the strongest channel — the goal is best translation, not best technology.
- **Key Q**: "Is my technical advantage actually translating into market power — or is it just technically impressive?"
**44. Value Translation Space**
The bridge from technical moat to market impact across four dimensions — User Experience, Network Effects, Brand, and Distribution Power — where technically superior products often fail to cross.
- **Apply**: Map your technical moat across all four dimensions, lean into the strongest, fix or accept the weakest, and aim for at least two strong dimensions or risk commoditization.
- **Key Q**: "Through which dimensions is my technology actually creating market value — and which am I neglecting?"
**45. Three AI Strategic Archetypes**
Three distinctive AI positions — Full-Stack Integrators, Specialized Dominators, and Strategic Enablers — each with different capital, risk, and defensibility; trying to be all three is the common error.
- **Apply**: Assess your resources and ambition, choose the single archetype that fits (capital-heavy stack, deep-domain vertical, or infrastructure enabler), and align all resources — the danger zone is between archetypes.
- **Key Q**: "Am I a Full-Stack Integrator, a Specialized Dominator, or a Strategic Enabler — and is my allocation aligned?"
**46. Weak Spot Analysis (5 Attack Vectors)**
Identifying where incumbents are exposed via five vectors — Low-End Disruption, Business Model Innovation, New Technology Platform, Niche Focus, and Adjacent Market Entry.
- **Apply**: Select the incumbent, evaluate all five vectors for where they're weakest, and choose the vector where you hold the strongest structural advantage to exploit.
- **Key Q**: "Through which attack vector is this incumbent most vulnerable — and where is my strongest advantage?"
**47. Margin Conflict Strategy**
Designing business models at margin structures incumbents can't match without cannibalizing their own high-margin business — exploiting their organizational incentives against them.
- **Apply**: Analyze the incumbent's margin structure, design a profitable model at margins they can't match, enter the market, and use the internal-conflict response delay to build your moat.
- **Key Q**: "Can I design a model that's profitable at margins the incumbent can't match without cannibalizing itself?"
**48. Strategic Mismatch Model**
Disruptors win not by having better data but by having a better perspective on what data matters — the battle is won in the interpretation layer, where incumbents are structurally blind.
- **Apply**: Map the incumbent's interpretive lens and its structural blindness, develop an alternative interpretation of the same data, and build strategy around the interpretation gap.
- **Key Q**: "Do I see something in the data that the incumbent's lens structurally prevents them from seeing?"
**49. Non-Linear Competition**
Competitive dynamics are non-linear — a small asymmetric advantage can suddenly cascade into dominance once it crosses an invisible threshold, which linear analysis can't forecast.
- **Apply**: Identify asymmetric advantages with compounding potential, estimate the cascade threshold, invest to reach it before competitors notice, and defend the compounding mechanism once the cascade begins.
- **Key Q**: "Do I have an asymmetric advantage that could compound non-linearly — and am I investing to reach the threshold?"
**50. Winner-Take-All Effects**
How network effects, switching costs, and data returns to scale consolidate markets around one dominant player per layer — in WTA markets, second place is a losing position.
- **Apply**: Assess the market for WTA conditions; if present, either invest aggressively to win, leapfrog via a technology shift, or exit; if weak, compete on differentiation — and monitor as conditions shift.
- **Key Q**: "Is this a winner-take-all market — and if so, am I positioned to win or do I need to redefine the game?"
### VI. AGENTIC AI & PLATFORM STRATEGY
**51. Agentic AI Four-Phase Moat Building**
A sequential roadmap for compounding advantage in agentic AI — Foundation, Differentiation, Dominance, Expansion — each substantially complete before advancing, or the position is fragile.
- **Apply**: Honestly assess your phase, build reliability first, then unique capabilities, then self-reinforcing flywheels, then adjacent expansion — never skip phases, as the foundation carries everything above it.
- **Key Q**: "Which phase am I actually in — and am I doing the work required at this phase before jumping ahead?"
**52. Three Kingdoms of Agentic AI**
Three market territories with distinct rules — Consumer (attention/habit), B2B (ROI/workflow), Enterprise (trust/compliance) — where strategies from one often fail in another.
- **Apply**: Identify your kingdom and match investment to its rules (habit and viral loops, measurable ROI, or security and relationships), never importing another kingdom's strategy.
- **Key Q**: "Am I in the Consumer, B2B, or Enterprise kingdom — and does my strategy match that kingdom's rules?"
**53. Context Engineering**
The systematic architecture of the entire information environment an AI model operates in — orchestrating, structuring, and prioritizing context to maximize performance (distinct from prompt engineering).
- **Apply**: Map available context sources, select the most relevant, structure and prioritize it for the model, measure output quality across configurations, and iterate — better context compounds into better outputs and data.
- **Key Q**: "Am I engineering the context my AI operates in — or just throwing information at it and hoping?"
**54. Protocol Mastery**
Deep, early adoption of AI protocol standards (like MCP) creates ecosystem network effects and technical barriers, making protocol masters the connective tissue of the AI ecosystem.
- **Apply**: Identify consequential emerging protocols, master their capabilities and edge cases, build integrations others haven't discovered, help partners implement them, and contribute to development to shape the standards.
- **Key Q**: "Am I building deep protocol mastery that creates ecosystem lock-in — or treating protocols as commodity plumbing?"
**55. Agentic Competitive Formula**
A multiplicative formula — Success = Market Focus × Technical Excellence × Network Effects × Time — where any factor at zero makes the total zero.
- **Apply**: Rate each factor honestly, fix whichever is closest to zero first, narrow market focus, ensure real technical superiority, design for compounding usage, and commit to the required timeline.
- **Key Q**: "Which factor in my competitive formula is closest to zero — and is that the one I'm investing in?"
**56. AI-Up (AI-Native Startup)**
A new organizational form where AI augmentation is embedded in every function, letting a small team iterate so rapidly it builds defensible value before incumbents can organize a response.
- **Apply**: Build every function with AI augmentation, optimize for iteration speed, keep the team lean, target markets where incumbent response is slow, and build moats before the response gap closes.
- **Key Q**: "Am I building an AI-native organization that can build defensible value before incumbents respond?"
**57. Platform Network Ecosystem**
Building multi-sided markets where value rises as participants join each side — requiring network-effect cultivation, governance, and a control-value balance that enables more than it extracts.
- **Apply**: Define the market's sides, solve the chicken-and-egg seeding problem, design for cross-side network effects, set quality governance, watch the control-value balance, and measure ecosystem health, not just revenue.
- **Key Q**: "Does my platform enable more value than it extracts — and are network effects compounding across all sides?"
**58. Agentic Web Architecture**
The emerging structure of how AI agents interact across the internet in four layers — Agent Mesh Networks, Decision Protocols, Resource Allocation, and Autonomous Economic Systems.
- **Apply**: Map which layers are emerging, identify which your company can build on, participate in agent discovery, coordination, resource, or transaction systems, and position early to shape the standards.
- **Key Q**: "Which layer of the agentic web architecture can I contribute to or build on?"
### VII. FLYWHEELS & GROWTH LOOPS
**59. Amazon Flywheel**
The canonical compounding loop — lower prices → more customers → more sellers → greater selection → lower costs → lower prices — where each element reinforces every other, making single-element competition impossible.
- **Apply**: Map your equivalent entry point that attracts the first side, trace the reinforcement path, find and strengthen the weakest connection, and test whether the system compounds or needs constant manual input.
- **Key Q**: "Does my business have a flywheel where each element reinforces the others — or am I pushing growth at every step?"
**60. Data Flywheel**
The AI-specific loop — more usage → more data → better model → better product → more usage — where the data advantage compounds because real-world behavioral data can't be bought or synthesized.
- **Apply**: Map what data each interaction generates, assess data quality and flywheel speed, find and accelerate the bottleneck, and measure whether your gap versus competitors is widening or narrowing.
- **Key Q**: "Is my data flywheel spinning — and is the gap to competitors widening or narrowing with each revolution?"
**61. Content Flywheel**
The loop for content businesses — create, distribute, build audience, monetize, reinvest — made a true flywheel only when audience growth itself improves content quality and distribution.
- **Apply**: Produce genuinely valuable content, distribute through the best channels, build engaged audience, monetize while preserving trust, reinvest, and confirm the audience itself improves your content (or it's just a production line).
- **Key Q**: "Does my audience growth itself improve my content quality and distribution — or is this a linear production line?"
**62. Traction-Momentum-Flywheel**
A three-phase growth model — Traction (prove value), Momentum (scale the proven model), Flywheel (self-reinforcing growth) — where most fail by entering a phase before completing the prior one.
- **Apply**: Honestly assess your phase, focus only on proving value in Traction, scale team and channels in Momentum, design self-reinforcing systems in Flywheel, and treat phase transitions as the most dangerous moments.
- **Key Q**: "Am I in the Traction, Momentum, or Flywheel phase — and am I doing the right work for that phase?"
**63. Innovation Flywheel**
The R&D loop — invest, generate breakthroughs, convert to market advantage, generate revenue, reinvest — strengthened when breakthroughs build cumulatively and fund the next cycle.
- **Apply**: Allocate meaningful R&D resources, focus on breakthroughs over increments, speed breakthrough-to-market conversion, ensure revenue funds the next cycle, reinvest with discipline, and cultivate cumulative knowledge.
- **Key Q**: "Is my innovation flywheel compounding — does each breakthrough build on the last and fund the next?"
**64. AI Priming-Proving Flywheel**
An AI loop where capabilities prime new use cases, proven value generates demand, demand attracts investment, and investment expands capabilities that prime further use cases — explaining non-linear AI adoption.
- **Apply**: Deploy AI and actively watch for emergent, unplanned use cases, validate and measure their value, convert that into demand and investment, and expose AI to diverse contexts to maximize priming.
- **Key Q**: "Am I watching for the emergent use cases my AI capabilities are priming — or only measuring the ones I planned?"
**65. Asymmetric Business Unit Model**
A structure where a high-margin unit subsidizes a low-margin unit (e.g., AWS subsidizing eCommerce), creating a combined position neither could achieve alone and that competitors can't attack from either side.
- **Apply**: Identify your high-margin cash generator, design or find a low-margin unit that uses the subsidy for unassailable position, establish the cross-subsidy, verify the combined moat, and monitor the high-margin unit's health.
- **Key Q**: "Do I have a high-margin unit that can structurally subsidize a low-margin unit into an unassailable position?"
### VIII. BUSINESS MODEL INNOVATION
**66. VTDF Framework**
A four-lens analysis of any business model — Value, Technology, Distribution, Financial — whose power lies in the connections between lenses, since a shift in one forces re-evaluation of the others.
- **Apply**: Map a business across all four lenses, assess whether they connect coherently, identify the weakest as the bottleneck, and build strategy around strength in at least two dimensions with adequacy in the rest.
- **Key Q**: "Across Value, Technology, Distribution, and Financial — where is my model strongest, weakest, most vulnerable?"
**67. Catalyst Quadrant (DATC)**
A business-renewal framework requiring four simultaneous modes — Defend, Attack, Transform, Create — where most organizations default to one or two and neglect the rest.
- **Apply**: Assess which mode is most urgent but run all four simultaneously, allocate resources to the environment, and never let Transform or Create drop to zero; review allocation quarterly.
- **Key Q**: "Am I operating in all four modes simultaneously — or stuck in only Defend or only Attack?"
**68. Transitional vs Foundational Technology**
A five-layer technology lifecycle — Products (0-1yr), Applications (1-5yr), Transitional (5-15yr), Foundational (15-30yr), Supercycle Catalysts (30-50yr) — each dictating a different strategic time horizon.
- **Apply**: Classify your technology's layer and match strategy to its time horizon and dynamics — iterate fast on products, invest long-term on foundational, think in decades for supercycle catalysts.
- **Key Q**: "Which technology layer am I on — and does my strategy match that layer's time horizon and dynamics?"
**69. AI Supercycle Three-Phase Model**
A model of AI's economic transformation across three phases — AI Eating the Web, Industry Restructuring, and AI-Native Economic Models — currently transitioning from Phase 1 to Phase 2.
- **Apply**: Identify your industry's phase, adapt immediately if you're in Phase 1, prepare now if Phase 2 is approaching, explore AI-native models for Phase 3, and never assume your industry is immune.
- **Key Q**: "Which phase of the AI supercycle is my industry in — and am I positioned for the next phase?"
**70. Business Model Innovation via Margin Conflict**
Using different margin structures as a weapon at the business-model level — designing a business structurally profitable at margins that would destroy the incumbent's economics, forcing an impossible choice.
- **Apply**: Analyze incumbent margin requirements, design your model to profit at margins catastrophic for them, identify the structural advantage enabling it (AI automation, zero marginal cost), enter, and build moats during the response window.
- **Key Q**: "Can I design a model profitable at margins that force the incumbent to cannibalize its own business?"
**71. Dogfooding Framework**
A four-stage validation framework — Internal Adoption, Pain Recognition, Solution Validation, External Validation — preventing products that pass theoretical tests but fail practical ones.
- **Apply**: Require the team to use the product for real work daily, systematically document friction, validate that internal fixes solve external problems, launch only when internal usage is genuinely productive, and never stop dogfooding.
- **Key Q**: "Am I truly using my own product for real work — and are the pain points relevant to external customers?"
**72. AI Implementation Pyramid (4-Tier)**
A resource-allocation framework for AI adoption — Tier 1 Productivity Tools (~70%), Tier 2 Workflow Automation (~15%), Tier 3 Strategic Advantages (~10%), Tier 4 R&D Bets (~5%).
- **Apply**: Audit AI spending against the ratio, put the bulk into immediate productivity wins, automate a few workflow segments, build one defensible strategic advantage, allocate a small speculative budget, and promote successes upward.
- **Key Q**: "Is my AI investment pyramid balanced — or am I over-investing in speculative AI while neglecting the base?"
### IX. DECISION-MAKING & OPTIMIZATION
**73. Asymmetric Betting Matrix**
A portfolio approach to strategic bets by position size and return — Micro (0.1-1%, 1000x+), Small (1-2%, 100-1000x), Medium (2-5%, 10-100x), Core (5-10%, 3-10x) — where the portfolio is the strategy.
- **Apply**: Classify each bet by size and realistic return, balance the portfolio, make many fast micro bets and kill losers, deepen conviction on core bets, and rebalance by promoting winners and cutting non-performers.
- **Key Q**: "Is my strategic portfolio balanced across bet sizes — or over-concentrated in high-risk or low-return positions?"
**74. Impact-Reversibility Matrix**
Mapping decisions on Impact vs Reversibility into four quadrants — Strategic Deliberation, Smart Experimentation, Careful Consideration, Rapid Iteration — so deliberation matches the stakes.
- **Apply**: Rate a decision's impact and reversibility, plot it, and match rigor and speed to the quadrant; the meta-skill is correctly assessing which quadrant a decision belongs in.
- **Key Q**: "Am I giving this decision the right amount of deliberation for its actual impact and reversibility?"
**75. Act vs Wait Mental Model**
The fundamental choice between committing resources (Act) and preserving optionality (Wait), calibrated by whether the cost of delay exceeds the value of additional information.
- **Apply**: Assess the cost of waiting one more cycle and whether waiting yields meaningful new information; act if delay costs more than it teaches, wait if it teaches more, and check for compounding advantages and optionality value.
- **Key Q**: "Does the cost of delay exceed the value of waiting — or is optionality worth more than early commitment?"
**76. Bounded Rationality**
The recognition (from Herbert Simon) that humans satisfice rather than optimize, shaped by information limits, cognitive constraints, time pressure, and choice architecture.
- **Apply**: Model customer, competitor, and stakeholder behavior for how people actually decide (limited info, heuristics), simplify choices, structure the environment to make the right option easiest, and use frameworks to counter your own limits.
- **Key Q**: "Am I designing for how people actually decide — or how I assume rational actors should decide?"
**77. Less-is-More Heuristic**
The counterintuitive principle that beyond a threshold, more information degrades decisions — creating noise, false patterns, paralysis, and overconfidence — making filtering a strategic capability.
- **Apply**: Before gathering more data, ask if it will change the decision; if not, stop and decide; identify the 3-5 data points that actually drive the decision, set time limits, and reserve deep analysis for high-impact, low-reversibility calls.
- **Key Q**: "Am I gathering more information because it will improve the decision — or because it feels safer than deciding?"
**78. Ecological Rationality**
The principle that there's no universally best strategy — only strategies suited to specific environments — so the BE seeks environment-practice fit, not "best practices."
- **Apply**: Characterize your environment (fast/slow, fragmented/consolidated, regulated/unregulated), assess a strategy's original environment, import only if conditions match, and maintain a repertoire to switch as the environment changes.
- **Key Q**: "Is this strategy suited to my specific environment — or am I importing what worked elsewhere under other conditions?"
**79. Contradiction Reading**
Treating decisions that violate stated principles not as hypocrisy but as evidence of a hidden structural driver operating above individual choice.
- **Apply**: Observe an action contradicting stated principles, hypothesize the structural force that would make it rational, test whether that driver explains other contradictions, and use it to predict future actions.
- **Key Q**: "What structural driver is powerful enough to override this actor's stated principles — and what else does it predict?"
**80. Existential Imperative Test**
The diagnostic question behind seemingly irrational actions — "What catastrophe happens if they don't do this?" — which reveals a survival-level threat visible to the decision-maker but invisible to observers.
- **Apply**: For a puzzling decision, ask what catastrophe it prevents, generate threat hypotheses, test whether the threat explains other actions, and use the identified imperative predictively — it's the most reliable behavior predictor.
- **Key Q**: "What catastrophe are they trying to prevent — and does that threat explain everything else they're doing?"
### X. ORGANIZATIONAL DESIGN & AI ADOPTION
**81. AI-Native Organizational Archetypes**
Four AI-era structures — Two-Layer Revolution, Trust Network, Slime Mold Organization, and Micro-Empire — where structure determines strategy by constraining what's available.
- **Apply**: Assess your closest archetype and the one that best fits your environment, choose or transition toward the target, and check whether your structure enables or constrains your strategy.
- **Key Q**: "Which organizational archetype fits my strategy and environment — and is my structure enabling or constraining me?"
**82. Super Individual Contributor**
A new role combining deep expertise with strategic thinking, where one AI-augmented person produces the output of a small team across creation, analysis, strategy, and execution.
- **Apply**: Identify individuals combining deep expertise with strategic thinking, equip them with amplifying AI tools, remove barriers forcing specialization or management, measure by output and value, and restructure compensation accordingly.
- **Key Q**: "Am I creating conditions for Super ICs to emerge — or forcing everyone into traditional roles?"
**83. Permanent Beta Organization**
An organizational philosophy treating change as the default state — every process, structure, and strategy provisional and continuously evolved — rather than alternating stability with disruptive reorgs.
- **Apply**: Audit which structures are treated as permanent, question each, institute regular adaptation rituals, reward people who improve outdated processes, keep minimum viable structure, and accept never being fully "done."
- **Key Q**: "Is my organization built for continuous adaptation — or alternating between rigidity and disruptive reorganization?"
**84. FRED Test**
An enterprise AI-readiness reality check across four dimensions — Foundational Readiness, Resource Allocation, Executive Alignment, and Deployment Capability — distinguishing genuine readiness from AI theater.
- **Apply**: Rate the organization on each dimension, be honest about data infrastructure, real resources, leadership's willingness to restructure, and POC-to-production capability; if any dimension scores below 4, fix it before investing further.
- **Key Q**: "Is my organization genuinely ready for AI transformation — or are we investing in AI theater?"
**85. AI Discernment Framework**
Evaluating AI capabilities versus limitations in specific business contexts to prevent both over-reliance (using it where it fails) and under-utilization (not using it where it excels).
- **Apply**: For a proposed AI application, assess what it can reliably do, map where it fails and the cost of failure, calibrate risk, deploy where capabilities are strong and failure costs manageable, keep human oversight elsewhere, and reassess often.
- **Key Q**: "Where does AI genuinely excel in my context, where does it fail, and what is the cost of getting it wrong?"
**86. Dual-Engine Framework**
Running core business optimization (Engine 1) and AI transformation (Engine 2) as parallel operations with dedicated resources, separate metrics, and clear interfaces — because transformation inside the core structure fails.
- **Apply**: Separate the two engines organizationally, give each dedicated resources and distinct metrics, design the value-transfer interface, protect Engine 2 from Engine 1's short-term pressures, and plan an eventual convergence.
- **Key Q**: "Am I running core optimization and AI transformation as parallel engines — or expecting the core to transform itself?"
**87. Productivity Spectrum**
A framework for how AI expands individual capability beyond speed — enabling one person to perform at team-level competencies across strategy, execution, analysis, design, and communication.
- **Apply**: Audit where individuals are limited by specialization, deploy AI tools that expand capability range, measure capability expansion (not just speed), redesign roles and teams around fewer more-capable people, and rethink compensation.
- **Key Q**: "Am I measuring AI productivity only as speed — or capturing the full capability expansion it enables?"
**88. Stupid-Out Matrix**
A team-building framework filtering people on Capability and Adaptability into four quadrants — Stars, Specialists, Potential, and Exit — weighting adaptability more heavily because the work changes continuously.
- **Apply**: Map your team on both dimensions, invest heavily in Stars, develop Specialists' adaptability, accelerate Potential with mentors and AI, have honest conversations in the Exit zone, and weight adaptability in hiring.
- **Key Q**: "Am I building my team for the work that exists today — or the work that will exist tomorrow?"
### XI. MARKET & INDUSTRY ANALYSIS
**89. Incumbent Vulnerability Analysis**
A systematic framework for finding where incumbents are exposed across dimensions — market-position complacency, technology debt, organizational rigidity, margin dependency, and customer dissatisfaction.
- **Apply**: Score each dimension on observable evidence (complacency, legacy constraints, adaptability, margin traps, genuine vs captive loyalty); the highest-scoring dimensions are the attack surfaces.
- **Key Q**: "Where is this incumbent most structurally vulnerable — and is it in a dimension I can exploit?"
**90. Market Structure Dynamics**
A framework for how markets evolve — Fragmented → Consolidating → Oligopoly → Monopoly/Dominant — where understanding the transition drivers matters more than the current state alone.
- **Apply**: Classify the current state, identify the forces pushing toward the next, and match strategy to both the state and its direction (seek scale, build moats, dominate or find the ignored niche), watching for disruption that resets to fragmented.
- **Key Q**: "What market structure state am I in, where is it heading, and is my strategy aligned with the transition?"
**91. Capital Asymmetry of AI**
A framework for how AI investment concentrates in a few hyperscalers, creating a structural divide, and how smaller players can compete despite it via specialization, efficiency, niche focus, or leverage.
- **Apply**: Map who spends how much where, assess your position, and if smaller, don't fight head-on on compute — compete on specialization, efficiency, niche focus, or hyperscaler leverage; monitor dependency and asymmetry-shifting breakthroughs.
- **Key Q**: "How can I compete in AI without hyperscaler capital — and what strategy fits my actual resource position?"
**92. AI Bubble vs Supercycle**
A diagnostic separating short-term hype (bubble) from long-term transformation (supercycle), recognizing the same asset can be both — overpriced short term yet transformational long term (timing vs thesis).
- **Apply**: Check for bubble indicators (speculative capital, unrealistic valuations, thin adoption) and supercycle indicators (infrastructure, adoption, productivity gains), position for both — surviving the correction while capturing the transformation.
- **Key Q**: "Is this a bubble play or a supercycle play — and am I positioned to survive the correction and capture the transformation?"
**93. Technology Supercycle**
A historical framework for 30-50 year transformation waves (electricity, automobile, internet, mobile) following invention → speculation → correction → infrastructure → mass adoption → restructuring → new paradigm.
- **Apply**: Study previous supercycles, map where AI sits in the pattern, learn who won and lost at that stage, position for the infrastructure phase, and don't mistake the correction for the end of the supercycle.
- **Key Q**: "Where is AI in the supercycle pattern — and what does history say happens next?"
**94. Negotiation Leverage Matrix**
A framework for identifying and deploying leverage across five sources — BATNA, Information Asymmetry, Time Pressure, Relationship Capital, and Structural Position — mapping the true power balance before negotiating.
- **Apply**: Map all five sources for both sides before negotiating, strengthen your BATNA, exploit information asymmetries, conceal your own time pressure, leverage relationship capital carefully, and deploy structural position deliberately.
- **Key Q**: "Where does the real leverage sit in this negotiation — and have I strengthened all five sources before entering?"
**95. Comparable Company Analysis**
Evaluating businesses against peers not just financially but structurally, strategically, and positionally — revealing whether a company is genuinely comparable or structurally different in ways financials can't capture.
- **Apply**: Define a genuine peer set, compare financials, moat and flywheel maturity, strategic archetype and layer, and market-position trajectory; the divergences (comparable financials, divergent structure) are the insight.
- **Key Q**: "Is this company truly comparable to its peers — or do structural differences make the financial comparison misleading?"
### XII. DISTRIBUTION & VISIBILITY
**96. Agentic Web Visibility Playbook**
A framework for maintaining visibility when AI agents, not humans, mediate discovery and commerce — requiring strategies designed for agent cognition (structured data, protocols, authority signals, machine-readable value).
- **Apply**: Audit whether your visibility targets humans or agents, implement structured data and APIs agents can parse, ensure protocol compliance, build authority signals, express value in machine-readable formats, and monitor agent-mediated traffic.
- **Key Q**: "Is my visibility strategy designed for AI agents as well as humans — or am I invisible to agentic discovery?"
**97. Digital Distribution Layers**
A framework mapping content and product flow through three layers — Platform, Algorithmic, and Direct — each with different control, scalability, and vulnerability, where over-dependence on any single layer is a risk.
- **Apply**: Map the share of distribution through each layer, assess vulnerability to rule changes, maintain platform and algorithmic presence without depending on them, invest heavily in the direct layer (target 30%+), and diversify across all three.
- **Key Q**: "How much of my distribution do I actually control — and what happens if platforms or algorithms change the rules?"
**98. Brand Authority in AI Agent Age**
A framework for why brand becomes more critical when AI agents make decisions — agents use brand authority as a trust signal, and humans use brand familiarity to validate agent recommendations.
- **Apply**: Assess whether your brand is strong enough to serve as an agent trust signal, map how agents perceive and rank you, invest in the brand-agent feedback loop, and build authority signals agents recognize — brand is now agentic-web infrastructure.
- **Key Q**: "Is my brand strong enough to serve as a trust signal for AI agents — or will agent-mediated discovery erase me?"
**99. AI Search Paradigm Shift**
The transformation from Crawl-Index-Rank to Retrieve-Memory-Reason, where AI retrieves from multiple sources, keeps contextual memory, and reasons about answers instead of listing links — rewriting 25 years of discoverability rules.
- **Apply**: Audit whether content is keyword-optimized (old) or citation-worthy (new), invest in comprehensive authoritative content and structured data, accept that clicks may never happen, monitor AI citations, and adapt now.
- **Key Q**: "Is my content built for Crawl-Index-Rank or Retrieve-Memory-Reason — and am I adapting fast enough?"
**100. Bullseye Framework**
A method (from Weinberg and Mares' Traction) for finding the single best distribution channel — brainstorm all channels, rank, test the top 3 cheaply, identify the Bullseye, and double down.
- **Apply**: List all possible channels, rank by fit for your specific business, test the top 3 with cheap fast experiments, identify the best-performing Bullseye, concentrate resources to dominate it, and revisit quarterly.
- **Key Q**: "Have I found my Bullseye channel — or am I spreading across too many and dominating none?"
### XIII. LEADER MENTAL MODELS
**101. Antifragility (Taleb)**
The principle that some systems gain from disorder — distinguishing Fragile (breaks), Robust (resists), and Antifragile (strengthens from stress) — where the goal is antifragility, not mere resilience.
- **Apply**: Assess whether your system is fragile, robust, or antifragile, eliminate single points of failure, build optionality with many small bets, expose the system to small survivable stresses, and apply a barbell (80-90% safe, 10-20% extreme upside).
- **Key Q**: "Does my system get stronger from stress — or am I one shock away from breaking?"
**102. Day 1 Mentality (Bezos)**
Bezos's philosophy that every day must feel like Day 1 — urgency, customer obsession, experimentation, and resistance to calcification — because Day 2 is "stasis, followed by irrelevance... followed by death."
- **Apply**: Diagnose Day 1 vs Day 2 symptoms (slow decisions, process worship, customer as abstraction), re-center on customer obsession, adopt the 70% decision rule, reward experimentation, and attack process that has become a proxy for outcomes.
- **Key Q**: "Are we on Day 1 or Day 2 — and what specific symptoms indicate which?"
**103. First Principles (Musk)**
Reasoning from fundamental truths rather than analogy — breaking problems to base physical or logical truths and rebuilding up — applied selectively to the most important strategic decisions.
- **Apply**: Select a stalled strategic problem, list every embedded assumption, keep only fundamental truths and discard convention, rebuild the solution from base truths, and reserve this expensive method for high-payoff decisions.
- **Key Q**: "Which assumptions am I treating as fixed that are actually just convention?"
**104. Value Investing (Buffett)**
Buffett's philosophy of seeking assets priced below intrinsic value due to sentiment or mispricing — applied beyond finance to undervalued talent, niches, technologies, and dismissed-but-sound strategies.
- **Apply**: Develop an independent intrinsic-value assessment, demand a margin of safety, stay within your circle of competence, be patient through short-term volatility while the thesis holds, and buy when others are fearful.
- **Key Q**: "Is this opportunity priced below intrinsic value — and do I have the patience for convergence?"
**105. Moonshot Thinking (Page)**
Page's philosophy of pursuing 10x rather than 10% improvements — often easier because 10x forces reinvention rather than optimization of the existing system.
- **Apply**: Take a stalled challenge, restate the goal as 10x, notice how it invalidates current approaches, generate approaches that only work at 10x, evaluate which might work, and apply selectively to the highest-leverage problems.
- **Key Q**: "If I needed 10x improvement instead of 10%, what approach would I take — and why am I not taking it?"
**106. Zero to One (Thiel)**
Thiel's distinction between creating something new (0 to 1, vertical) and copying what works (1 to n, horizontal) — finding a secret others disagree with and building a monopoly around it.
- **Apply**: Ask whether you're creating or redistributing value, identify your secret, test it against smart people's disagreement, build a monopoly by dominating a small market completely, and avoid direct competition.
- **Key Q**: "Am I creating genuinely new value (0 to 1) or competing for existing value (1 to n) — and what is my secret?"
**107. Blitzscaling (Hoffman)**
Hoffman's framework for prioritizing speed over efficiency under uncertainty when network effects create winner-take-all dynamics — correct in WTA markets, catastrophic without them.
- **Apply**: First verify WTA conditions; if absent, don't blitzscale; if present, assess the competitive window, prioritize speed and accept inefficiency during it, measure share gains versus competitors, and set exit conditions to shift back to efficiency.
- **Key Q**: "Does this market have winner-take-all dynamics that justify speed over efficiency — or am I just burning capital?"
**108. Move Fast (Zuckerberg)**
Zuckerberg's philosophy (evolved from "Move Fast and Break Things" to "with Stable Infrastructure") that iteration speed is the primary competitive advantage — applied as a stage-dependent principle.
- **Apply**: Measure your idea-to-shipped-to-measured cycle, eliminate the bottleneck, prioritize speed ruthlessly early, add quality guardrails in growth and stability at scale, build a speed culture, and treat any drop in speed as a crisis.
- **Key Q**: "How fast am I iterating — and what is the bottleneck preventing me from iterating faster?"
**109. Simplicity (Jobs)**
Jobs's philosophy that simplicity is the destination reached only after understanding a problem deeply enough to strip away everything non-essential — complexity signals incomplete thinking.
- **Apply**: Repeatedly ask what can be removed without losing value and remove it, test whether a newcomer understands without explanation, identify the ONE thing it must do brilliantly, resist adding, and treat simplicity as a competitive advantage.
- **Key Q**: "What can I remove without losing value — and have I understood this deeply enough to make it simple?"
**110. Customer Obsession (Bezos/Wilke)**
The operating principle that every decision begins and ends with the customer — obsession, where the customer is the gravitational center, not merely focus — used as the ultimate strategic tiebreaker.
- **Apply**: Start every initiative with the customer's need, work backward from the ideal experience, optimize for long-term customer value, elevate customer signals as the most visible metrics, ignore competitors as the primary reference, and when torn, choose what's better for the customer.
- **Key Q**: "Am I starting with the customer's need and working backward — or starting with my capabilities and hoping?"
### XIV. CAPITAL CYCLES & FINANCING STRUCTURE
*Compressed register: essence and the question. These families were minted print by print; the Practice Layer (Part VIII) holds the instruments that run them.*
**111. Revenue vs Depreciation, Not Revenue vs Capex**
Comparing a buildout's annual revenue to its annual capex is a category error — capex buys an asset that produces revenue for years; revenue is a 12-month flow. No infrastructure build in history survives that ratio. The correct income-statement test is revenue against DEPRECIATION, which arrives on a fixed schedule regardless of whether revenue does.
- **Key Q**: "Is revenue covering the depreciation of what's already built — and is it growing faster than the depreciation wave that's coming?"
**112. The Hurdle Is Arithmetic**
The revenue a capital program requires is not an opinion: required revenue = capital deployed x (1/asset life + required return) / gross margin. Derive it, publish the sensitivity (asset life and gross margin are the highest-leverage variables), and state the vintage of every external estimate you compare against.
- **Key Q**: "What revenue does the deployed capital arithmetically require — and what fraction of it exists today?"
**113. Allocation Becomes Obligation**
A program funded from operating cash flow can be slowed at will; one funded by debt, leases, and external capital has counterparties, covenants, and maturities. When the CHARACTER of the money changes, a capital allocation decision becomes a credit cycle — even if nothing about the companies changed.
- **Key Q**: "Has the funding character changed from discretionary allocation to third-party obligation — and did anyone re-rate the risk when it did?"
**114. Absorption Capacity**
Financing strain in a shared buildout is company-specific, not sector-wide. Each participant's position on the financial clock is set by its capital intensity (capex as a share of revenue and of operating cash flow) — one company self-funds with room while another cracks on the same build.
- **Key Q**: "What is this company's capital intensity — and where does that place it on the clock relative to peers running the same build?"
**115. Operating Absorption Is Not Cash Absorption**
The income statement and the cash statement are two different tests and can give opposite answers inside one company: margins expanding while free cash flow goes negative. Run both. Strength on the operating line financed on the cash line is stretch from strength — a placement decision, not distress — but it is still stretch.
- **Key Q**: "Does the operating answer match the cash answer — and if not, which one is the market pricing?"
**116. Net Income Has Two Engines**
Reported net income mixes the operating engine with revaluation marks, equity gains, and other income. The operating line is the repeatable read; the marks are the headline risk. Strip the marks first in every print — especially when cross-holdings mean one relationship generates investment, commitment, and mark simultaneously.
- **Key Q**: "How much of the bottom line is the operating engine — and how much is a mark that can reverse?"
**117. Expensed vs Capitalized (The Control Group)**
In any buildout, study the major player that opted out: it expenses what others capitalize, rents the input, and keeps the endpoint. No depreciation cliff, no stranded assets, no financial clock — the risk migrates into a contract instead of a balance sheet, and comes due later. The opt-out is the counterfactual that prices what building actually buys.
- **Key Q**: "What does the non-builder's position reveal about what the builders are paying for — and where did its risk go instead?"
**118. Pre-Funding Makes the Near Term Sticky**
Capital already raised will be spent: bonds sold and facilities syndicated don't get cancelled with the plans they funded. Near-term capex is therefore sticky regardless of demand news — the real adjustment mechanism is NEXT year's guidance, which reveals a change of mind a full year before it appears in anyone's cash flow.
- **Key Q**: "Is this period's spend already funded and sticky — and am I watching guidance, where the actual decision will show first?"
**119. Deferral vs Transfer**
Off-balance-sheet obligations are not one thing: some are deferred (they land on the balance sheet eventually) and some are transferred (they never arrive — the risk lives in a vehicle, guarantee, or counterparty). Risk-weight them differently or the analysis destroys its own signal.
- **Key Q**: "Does this obligation eventually arrive on the balance sheet — or has the risk been moved somewhere it will never be consolidated?"
**120. The Marginal Channel**
The stock of financing tells you where a program has been; the marginal dollar tells you where it's going. The most diagnostic gauge in any financing analysis is whether the NEXT dollar is funded the same way as the last — off-book growth outpacing capex growth means the structure is changing at the margin even while the averages look sound.
- **Key Q**: "How is the marginal dollar financed — and is that different from how the average dollar was?"
**121. The Credit Floor**
Engineered financing structures work exactly as far down the credit ladder as investment grade reaches — and the boundary is observable: the deal that fails to place marks the floor's coordinates. Watch whether the structure stops at the floor or starts manufacturing credit quality synthetically (guarantees, wrappers) to extend below it.
- **Key Q**: "Where does investment grade end in this structure — and is anything being built to pretend it extends further?"
**122. The Amplifier, Not the Bubble**
Financing fragility alone rarely produces a systemic break — stress every financing gauge and the composite still tops out below pre-break. The remaining distance is always the demand question. Financing structures are not the bubble; they are the amplifier a bubble would run through, and the honest instrument measures how much amplification has been installed.
- **Key Q**: "Am I measuring the probability of the shock — or the amplification installed for whenever the shock arrives?"
### XV. CONTAGION, INCIDENCE & JOINTS
*Compressed register: essence and the question. These families were minted print by print; the Practice Layer (Part VIII) holds the instruments that run them.*
**123. The Layer Map Is Not the Credit Map**
Value capture runs horizontally through an industry's layers; contagion runs vertically through the financing stack — different geometries over the same companies. A default doesn't propagate to the adjacent layer; it goes to whoever lent against it, whoever bought that paper, whoever holds the fund. Risk sits at the JOINTS between layers, not at a layer.
- **Key Q**: "Am I mapping where value lands or where losses travel — and have I located the joints where the two maps touch?"
**124. It Breaks Upward**
Buildouts fail bottom-up: nothing fails at the strongest participant and cascades down — it fails at the weakest counterparty and travels UP through the lenders. Watching the top of the structure for the first crack is watching the wrong end. Early, small failures are cheap information: the structure disclosing its boundary while tuition is low.
- **Key Q**: "Where is the weakest counterparty in this structure — and what would its failure teach before anything expensive breaks?"
**125. The Sequencing Bet**
Every leveraged buildout is a race between two calendars: when monetization must be demonstrated (the income statement) and when the debt must be refinanced (the maturity schedule). If the income statement answers before the maturity schedule asks, the refinancing wall never materializes — it was made of doubt, not arithmetic. If it disappoints, both failures arrive as one, through two channels.
- **Key Q**: "Which comes first here — the proof of monetization or the refinancing requirement — and what happens in each order?"
**126. The Wrapper Trade**
A guarantee converts the guarantor's credit into a derivative on the counterparty's. When a strong balance sheet backstops a weak counterparty's obligations, the market reprices the GUARANTOR on the counterparty's news — and a supplier guaranteeing its own customer's purchases has built circular exposure the layer map cannot show.
- **Key Q**: "Whose credit is actually being traded here — the issuer's, or the entity whose obligations it wrapped?"
**127. Downstream Incidence (The Bill for the Build)**
A buildout's cost lands outside the builders too: wherever the bottleneck's inputs are shared, non-participants pay through input inflation, allocation loss, or channel taxes. Trace the incidence — the P&L of a company that builds nothing can be the cleanest read on how tight the build's constraint really is.
- **Key Q**: "Who is paying for this buildout without participating in it — and through which shared input does the bill arrive?"
**128. Price Is Not Capacity**
When a constrained input inflates, a share of the headline investment number is a TRANSFER to the input's suppliers rather than an addition to capacity. Decompose spending growth into price and volume before reading it as expansion — one dollar in several may be paying more for the same thing.
- **Key Q**: "How much of this spending growth buys additional capacity — and how much just pays the new price of the old capacity?"
**129. Toll Booths vs Tourists**
On any structurally constrained road, distinguish the toll booths (positions that price and ration the constraint — monopolies by physics or contract) from the tourists (positions that merely travel the road and pay). Watch for the sequel: the endpoint owner internalizes its most valuable tourist — integration converts a customer into a competitor.
- **Key Q**: "Does this company price the constraint or pay it — and can anyone upstream or downstream internalize its position?"
**130. The Rotating Bottleneck**
In a multi-input system, the binding constraint migrates as each is relieved — and late in a cycle two can bind at once. The current bottleneck sets today's pricing power; the NEXT bottleneck sets tomorrow's. Track the rotation, not the snapshot, and note that financing itself can join the rotation as a constraint.
- **Key Q**: "What binds today, what binds next — and is more than one constraint binding at once?"
### XVI. CLOCKS, MAPS & DEPENDENCY
*Compressed register: essence and the question. These families were minted print by print; the Practice Layer (Part VIII) holds the instruments that run them.*
**131. The Four Clocks**
Any technology buildout runs on unsynchronized clocks: PHYSICAL (years — committed capacity that cannot un-decide), FINANCIAL (quarters — engineered credit), EFFICIENCY (fastest — software absorbing physical constraint), ADOPTION (demand-side telemetry). Most cycle narratives fail by reading one clock as if it were the system. See Model 139 for the fifth.
- **Key Q**: "Which clock is this datapoint on — and which clock is the argument I'm evaluating secretly assuming?"
**132. Demand Has a Shape, Not Just a Size**
Supply commits on long clocks against demand that moves on short ones — in SIZE (the macro cycle) and in SHAPE (where demand concentrates across the map). Every node's price is a bet that today's demand shape survives that node's build time; when the shape shifts, committed supply can't adjust, so price adjusts — locally and violently.
- **Key Q**: "If demand keeps its size but changes its shape, which committed positions are stranded — and which quietly become the destination?"
**133. Split by Clock, Not by Category**
Decompose any capital program by asset LIFE, not by line item: the short-lived share (fast-depreciating, hard to appraise, hostage to the next generation) and the long-lived share (appraisable, re-tenantable, financeable). The two halves of the same dollar have opposite exposures to the same event — and financing instruments built for one are routinely written against the other.
- **Key Q**: "How does this spending split by asset clock — and is the financing matched to the clock it's actually secured against?"
**134. Efficiency Expands the Market (The Efficiency Paradox)**
When a technology's unit cost collapses, total spend usually RISES — cheaper units expand use cases faster than they cut bills. But the same event is lethal to the SPECIFIC asset vintage it obsoletes: efficiency is bullish for the category and bearish for the collateral. Both are true at once.
- **Key Q**: "Does this efficiency gain shrink the market or expand it — and which specific installed assets does it reprice on the way?"
**135. Own the Junctions, Rent the Ends (The Property Line)**
In any stack, the ends commoditize and the junctions compound: models, tools, and capacity can be rented and swapped, but the routing points where private rules, data, and decisions are encoded should be owned. The most expensive position is the middle — renting everything while owning nothing that compounds.
- **Key Q**: "Of everything this system touches, what compounds — and does it compound on my side of the property line or the vendor's?"
**136. Clear Title (KEPT / PARTIAL / CAPTURED)**
For any dependency, grade each compounding artifact by its exit cost: KEPT (exit is a config change), PARTIAL (exit is a project), CAPTURED (exit is a rebuild — and rebuilds are where exit plans go to die). The closing question of any vendor engagement: after it ends, does the enterprise hold clear title to what compounds?
- **Key Q**: "If this engagement ended tomorrow, what would exit actually cost, artifact by artifact — a config change, a project, or a rebuild?"
### XVII. THE SUPERCYCLE PREMISE, THE FIFTH CLOCK, AND THE GEOPOLITICAL LAYER
**137. Node-by-Node Correction**
A technology buildout is a stack of coupled but unsynchronized S-curves. It does not correct as one market; it corrects node by node, in localized drawdowns that are each diagnostic of which position was stretched against which bottleneck. "Is it a bubble?" is a malformed question because a bubble presupposes one market. Keep a drawdown ledger: where, when, which species.
- **Key Q**: "Which node just repriced, what was it stretched against, and what does that drawdown teach about the map?"
**138. Two Species of Drawdown**
Localized corrections come in two kinds: supply-constraint repricing (the durability of a physical bottleneck shifts) and financial-absorption repricing (financing outruns what credit will carry). Geopolitics is the shock generator for either. Each node builds its own leverage during its steep segment, which converts a repricing into a crash. Equity violence at a node means duration was repriced, not that the economics broke.
- **Key Q**: "Was this a repricing of the bottleneck's durability or of the financing's capacity, and which leverage structure turned it into a crash?"
**139. The Fifth Clock (Return-Insensitive Demand)**
Beside physical, financial, efficiency, and adoption runs a political clock immune to the return signal: sovereign programs, defense, industrial subsidy, export-control-driven state buildout. Sort past buildouts by outcome and the survivors had a state anchor; the capital-destroyers were purely private. The anchor firms the floor and widens the waste inside it. Do not lower the hurdle for it; split it.
- **Key Q**: "How much of this demand never had to clear a return, and does that set a floor or just fund the malinvestment?"
**140. The Cascade Is the Rotation**
The bottleneck thesis and techno-geopolitics are one mechanism at two speeds. Whatever binds, earns; whoever solves the bind, rises. Innovation cascades become industrial systems, industrial systems become power systems, power systems become world orders. Read the rotation of the binding constraint as the map of who is gaining power, not only who is earning margin.
- **Key Q**: "Who is positioned to relieve the current bind, and what power does that hand them once they do?"
**141. Sited, Standardised, Chokeable (The Junction Rule)**
A single technology makes an industry; intersecting technologies make a map. A technology becomes geopolitical when it passes three tests: sited (its physical layer sits somewhere specific), standardised (a gauge or protocol decides who can connect), and chokeable (a small number of points can stop it). Then ask which power form it favours and what it does to war.
- **Key Q**: "Is this technology sited, standardised, and chokeable, and at which junction with other technologies does it become a map?"
**142. The Independence Swap**
New technology arrives as freedom (from the old constraint) and invoices later as dependency (on the new one). Because the freedom is felt first and the dependency later, the swap is systematically underpriced at adoption. Treat every liberation as a conservation law: the constraint moved; it did not disappear.
- **Key Q**: "What dependency is this independence going to invoice, and when does the bill arrive?"
**143. The Permission Layer**
When the chokepoint is software or standards rather than territory, the border becomes programmable: an export control, a licence, a kill switch, a deemed-export rule. Private assets, public permissions. Map who can revoke, not only who owns.
- **Key Q**: "Who holds the permission this system runs on, and what does revocation look like in practice?"
**144. The Fence and the Tunnel**
Export fences are tall where the frontier is and thin where trailing-edge tooling suffices. Layers made with trailing-edge equipment are the ones a fence protects least, so the tunnel appears under the fence's shortest section. Read the fence by its thinnest point, not its tallest.
- **Key Q**: "Where is this fence thinnest, and which layer is being tunnelled under it?"
**145. State Capital Does Not Under-Build**
A toll rests on all capable producers under-building. When a state entrant's objective is share and sovereignty rather than return, the discipline is no longer universal. The historical rhyme: the incumbent that took the layer as a state-championed latecomer decades ago is now watching the same play aimed back at it. Near term the fence holds on physics; medium term the challenger attacks both pillars.
- **Key Q**: "Is every producer in this layer still disciplined by ROIC, or has a state actor changed the objective function?"
**146. The Toll-Booth State**
A national economy can be functionally one layer of the stack: it collects that layer's rent in full and absorbs its shocks in full, with household leverage stacked on the national position. Its index is a real-time price of the layer. Read it as an instrument, and read its energy dependence as the short beneath the long.
- **Key Q**: "Which country is this layer, and what is stacked on top of that position?"
**147. Market Risk Becomes Counterparty Risk (The Wire)**
Take-or-pay contracts with floors delete spot-price risk and replace it with buyer-credit risk. If the buyers are the debt-financed builders, the physical floor is contractually wired to the ceiling's credit. The wire is what gets priced when the ceiling wobbles. Deposits are demand collateralizing its own persistence.
- **Key Q**: "When this floor contracted away its price risk, whose credit did it accept instead?"
**148. Shape Cannot Be Contracted**
A long-term agreement buys certainty of payment, not certainty of shape. Demand can keep its size and change where it concentrates across the map; committed supply cannot follow. Look for the clause that leaves new-product pricing "to be negotiated": that is the shape risk the contract could not remove.
- **Key Q**: "What does this contract fix, and what does it leave to move?"
**149. The Transmission Belt**
A buildout's cost escapes the complex through shared inputs into consumer prices: a company that builds nothing raises prices because of the build, a central bank names the buildout in the same breath as war and tariffs, the curve steepens, and the build's own debt costs more. Capex as an inflation source is a loop, not a line.
- **Key Q**: "Through which shared input does this buildout reach a price a household pays, and how does that price come back as a cost of capital?"
**150. Same Tide, Different Beaches**
One efficiency event lands differently on different shores. Cheaper, open models raise total serving demand while redistributing it from concentrated blocks (frontier training) to a broader hierarchy (distributed serving, context stores). Ask which shore each supplier stands on before calling the tide bullish or bearish.
- **Key Q**: "Which shore does this company stand on when the tide comes in, and is the tide redistributing demand or removing it?"
**151. Demand Subtraction Wearing a Supply Costume**
A challenger's vertical integration adds wafers and removes buyers at the same time. Watch the challenger's revenue share inside the incumbents' books: repatriated procurement is demand subtraction, even when it is reported as new supply.
- **Key Q**: "Is this new capacity adding to the market or removing a customer from it?"
**152. The Land–Sea Oscillation and the Blockade's Medium**
Junction technologies decide whether power favours the maritime or the continental form, and each junction changes the medium a blockade runs through: sea lanes, then rail, then fuel, then chips, then compute. Mass returns when a cheap, producible unit can be made faster than an exquisite platform can be defended.
- **Key Q**: "Through which medium would a blockade of this system run, and does the current junction favour mass or exquisiteness?"
**153. The Three-Generation Lag and the Domestic Bill**
A junction's power effects arrive roughly three generations after the technology, and the distributional politics arrive first at home: rate-payers, regional losers, and the commissions that get created to settle them. Any forecast that skips the domestic bill skips the politics that decide the timing.
- **Key Q**: "Who pays the domestic bill for this buildout, and what institution will be created to settle it?"
### XVIII. NODE READS — THE TEN SEATS ON THE FINANCIAL CLOCK
**154. Name the Seat First**
A print is misread when its seat is wrong. Ten seats: builder · bystander (downstream input incidence) · distributor (discovery incidence) · control group (expensed, opted out) · supplier (paid by the build) · funder (supplies the build's capital) · integrator (floats the build's working capital) · value-capture pole (paid by the build, finances no floor) · rail (settlement the build cannot disintermediate) · taxed (attention the build summarizes). Each seat has its own tests; run the seat's tests, not the builder's.
- **Key Q**: "Which of the ten seats is this company in, and am I running that seat's test or someone else's?"
**155. The Value-Capture Pole (The Anti-Capex Node)**
The node that gets paid BY the build while financing none of the floor: capex near zero, off both physical and financial clocks, priced on outcomes rather than consumption. It is the ceiling made legible. Its whole risk collapses onto the multiple, because there is no long-lived asset to look through to.
- **Key Q**: "Does this company pay for the build or get paid by it, and if the latter, where does its risk live?"
**156. Proof of Concept, Not Reconciliation**
One node monetizing the ceiling at high margin proves the return exists; it does not scale to the capital. Hold both: the highest-quality single instance of return-side monetization and its size against the build. Refuse to let either clause delete the other.
- **Key Q**: "Is this return real, and is it remotely scaled to the capital it is supposed to justify?"
**157. Price Is the Whole Position**
Where there is no multi-year asset, the long-duration instrument is the terminal margin or the multiple, nothing else. A business can accelerate while its stock de-rates, because the discount rate moved and the business did not. Separate the two before writing a verdict.
- **Key Q**: "If this company has no asset to reprice, what is the tape actually repricing?"
**158. The Beat Raises the Hurdle**
When a supplier's shipments accelerate, the end-customer revenue required to earn a return on those shipments rises with them. A record at the supply layer is evidence against the monetization case, not for it, until the demand side compounds at the required rate.
- **Key Q**: "How much new end-customer revenue does this beat now require, and is it appearing?"
**159. Stretch From Strength**
A company can trigger every collapse condition (capex above operating cash flow, a return to the bond market) from operating strength. That is a placement decision, not distress, and it is still stretch. Grade the engine and the financing separately.
- **Key Q**: "Did the financing change because the engine weakened or because it chose to build faster than cash allowed?"
**160. The Related-Party Triple (The Circle)**
One counterparty relationship can generate an investment, a capacity commitment, and a revaluation mark at once. Supplier equity, supplier credit, and supplier guarantees flow out as customer revenue flows in. A valuation that counts the revenue and the mark values the same dollar twice. Trace the circle before reading either.
- **Key Q**: "How many effects does this one relationship produce in the accounts, and which of them are the same dollar?"
**161. The Levered Backer**
When a holding company funds a build's first-loss equity by borrowing against its own marked-to-market stakes, the equity is debt, the collateral is marks, and the marks are the thing being bought. A fair-value trigger writes a margin call into the equity layer. The cushion everyone assumed absorbs the shock is wired to transmit it.
- **Key Q**: "Is the first-loss equity beneath this structure real equity, or borrowed against the asset it bought?"
**162. The Frozen Mark**
A private stake carried at an unchanged valuation while every other input moves is a choice, not a measurement. The frozen mark postpones the read; it does not remove it. Note where the mark stands relative to the last transaction and what event forces it to move.
- **Key Q**: "Which mark in this book has not moved, and what would force it to?"
**163. Backlog as Payable (The Customer Is the Lender)**
Two operators can run the same build with opposite balance-sheet signs: one carries backlog as a receivable financed by debt, the other carries prepayments as deferred revenue and holds net cash. Strip the prepayments from operating cash flow before reading the engine. The pre-funded operator's risk is depreciation and concentration, not financing.
- **Key Q**: "Is this backlog a receivable I financed or a payable my customer prefunded, and which risk does that leave me holding?"
**164. Assembly Is Not Capture (The Integrator Floats the Timing Gap)**
The assembly point converts capital into racks at low margin, negative cash conversion, and rising trade credit extended to weaker tenants. The integrator carries the build's working capital on its own book, funded by dilution and debt. Trade-credit float is a financing channel the six gauges cannot see; inventory is the fastest collateral to reprice.
- **Key Q**: "Who is carrying the working capital of this build, and is it being extended as trade credit to counterparties the acid test never scores?"
**165. Tightness Rent vs Monopoly Rent (The Arms Dealer)**
A supplier's margin can expand with the build because the input is tight, not because the position is a monopoly. Tightness rent is cyclical and competed; monopoly rent is structural. Separate them, and note when the anchor customer is also the biggest competitor.
- **Key Q**: "Is this margin a property of the constraint or of the position, and who else can supply once the constraint eases?"
**166. Incidence Runs Opposite at the Two Ends**
The same build costs the application layer (inference in cost of goods) and pays the physical supply layer (margin expanding with tightness). The middle pays both. Never read one end's incidence as the sign for the whole stack.
- **Key Q**: "At which end of the stack is this company, and does the build cost it or pay it?"
**167. The Vertical Wrapper (Paying to Enter the Build)**
A designer that also operates the cloud and finances its own demand on one balance sheet can report core revenue that is partly a warrant add-back: equity given to customers, amortized as contra-revenue, then added back. Customers prepay and are paid in equity at once. The razor comes with equity.
- **Key Q**: "How much of this 'core' revenue is an add-back of equity handed to the customer?"
**168. The Sibling Engine (The Gravity Shift)**
When a founder's second company out-earns the first and the first's reported profit is mostly a mark on the second, gravity has shifted inside the group. Read the profit source, the talent currency, and the capital priority as one system, and read the compute they share as the flywheel for both.
- **Key Q**: "Which entity in this group is now the engine, and which is being carried by a mark on it?"
**169. Capex Is a Placement Decision (The Six Tiers)**
Capex only ever measured the part of a build a company chose to own. Obligations descend a ladder of visibility: capitalized · recorded as lease · signed-not-commenced · non-cancelable commitments · contingent guarantees · non-consolidated vehicle debt · someone else's capex. The footnote compounds faster than the capex line, and position on the ladder reveals rating headroom. Growth financed by moving down the ladder is the Descent; the ladder has a bottom where investment grade ends.
- **Key Q**: "On which rung of the ladder is the marginal dollar of this build being placed, and what does that rung confess about headroom?"
**170. The Rating Is the Collateral**
An isolation vehicle is a way to pledge a credit rating, not a way to finance a datacentre: the tenant's rating caps the vehicle's, the guarantee that keeps it off the books leaks through five seams, and a four-tenor mismatch (mini-perm, securitisation, hardware life, contract, institutional appetite) is bridged by a take-out assumption. The certainty gap (tenants need capacity certainty before signing; lenders need signed contracts before funding) is why private credit owns the cycle.
- **Key Q**: "Which rating is really being pledged here, through which seam would it leak, and who is assumed to take the paper out?"
**171. Efficiency Is Obsolescence From the Collateral Side**
Cheaper compute is good for the category and lethal to a vehicle collateralized on a specific facility, hardware generation, tenant, and term. The efficiency clock absorbs physical-clock damage and accelerates financial-clock damage. Sector good news is structure bad news.
- **Key Q**: "Which specific collateral does this efficiency gain reprice, and who is holding paper against it?"
**172. The Rack Ate a Layer (The Invisible Channels)**
When the unit of sale moves from chip to rack, the fabric inside the rack disappears from merchant networking revenue. Internal silicon reroutes the accelerator dollar to foundry, packaging, and memory without appearing in any third-party line. Captive fabric appears in nobody's numbers. Merchant reads understate the build.
- **Key Q**: "Which channels of this build are invisible to the public numbers, and how much does that bias the read?"
**173. Collection Becomes Cash (The Second Climb)**
The inverse of allocation becoming obligation: a toll collector converts rent to net cash, de-levers, and starts a second climb into an adjacent layer on the strength of its base. Read the second climb as the toll's reinvestment, and read its dilution against per-share leverage.
- **Key Q**: "Where is this toll collector reinvesting its rent, and does the second climb compound the first or dilute it?"
### XIX. INCIDENCE AND SUBSTITUTION AT THE TOP OF THE STACK
**174. Software Acquires a Cost of Goods**
Inference makes zero marginal cost false. A build reaches the pure software layer through the income statement in real time: gross margin compresses as inference lands in cost of goods, operating margin compresses as the feature race lands in opex. This is the fifth incidence path and it finishes at the top of the stack. A first-party model is the cost-of-goods lever that turns it.
- **Key Q**: "Where in this software P&L is the inference bill landing, and what lever pulls the margin back?"
**175. The Discovery Tax (The Curse Is in the Funnel)**
The force that makes human data scarce and valuable also disintermediates the free top of the funnel that acquired the audience. Revenue is the trailing monetization of a channel now closing. Read the leading indicator (traffic, logged-in users, referral commentary), not the lagging one (revenue), and note that the two revenue lines can carry opposite exposures to the same force.
- **Key Q**: "Is this revenue being generated by the funnel or by squeezing a base the funnel stopped refilling?"
**176. Content Is Summarizable, Settlement Must Clear**
The agentic force disintermediates the attention web and cannot disintermediate the settlement web. An answer replaces a visit; a transaction still has to clear. Same force, opposite sign, and the sign is set by whether the asset is content or a rail.
- **Key Q**: "Can an agent satisfy this demand with a summary, or does something still have to clear?"
**177. Rent the Agent, Own the Rail (AGaaS)**
The routing-fabric doctrine ported to commerce and applications: agents are the interchangeable field; the catalog, the checkout, the protocol, and the capture are the owned junction. The same move at three sites: the settlement rail, the creation substrate, the semantic layer. Structured data is a preference moat when agents pick the machine-readable listing.
- **Key Q**: "Which agent-facing junction does this company own, and is it structured well enough that agents prefer it?"
**178. The Toll Authority (The Property Line Repriced)**
The attempt to move content across the summarizable line: a payment gate between agent and page converts the discovery tax into metered revenue, paid in traffic today and in stablecoins tomorrow. The position can be secured before the till exists, and the gross margin carries the machine web free until the toll collects. Watch the gross-margin turn as the gauge.
- **Key Q**: "Has this toll authority secured the position, and is it collecting yet or still carrying the traffic free?"
**179. The Interface Concession**
When human app usage is flat while agent calls through an open protocol compound, an incumbent priced per seat faces a choice: defend a front door nobody opens or become the governed substrate under every agent. Conceding the interface is the correct call and a downgrade at once, because metered access to the customer's own record is smaller and more contestable than a seat.
- **Key Q**: "Has this incumbent conceded the interface, and what is the substrate business worth once it has?"
**180. Substitution Shows Up in the Segments Before the Total**
A growing total can hide product lines going negative. Agents calling systems directly route around integration middleware first; a model that queries and narrates replaces the dashboard second. Read the retiring segment appendix before it disappears, and read the adoption chart and the segment chart as one fact seen twice.
- **Key Q**: "Which segment inside this total has gone negative, and which agent behaviour explains it?"
**181. The Definition Moved With the Number**
When a headline metric is redefined in the quarter the underlying growth slowed, read the redefinition as the disclosure. Watch for: a broader product set folded into a run-rate, a shift to milestone-based reporting, a segment structure retired. Units that compound while the price attached to them does not are activity meters, not revenue leading indicators.
- **Key Q**: "What changed in the definition of this number, and in which quarter did the change arrive?"
**182. Growth Bought, Not Grown**
At the application layer the financial clock arrives through the buyback, not the capex line: debt taken on to convert a flat operating business into doubled earnings per share. The guidance tell is a raise smaller than the marks already banked. Strip the marks and the share count before crediting the growth.
- **Key Q**: "How much of this earnings growth is operating, how much is a mark, and how much is a smaller share count bought with debt?"
**183. Hedge the Displacement**
An incumbent long equity in the layer taking its interface will report earnings carried by the revaluation of that stake. Hedge or admission is the open question; the structural fact is that the displacement is being monetized by the displaced. Do not assert the attribution of an undisclosed gain.
- **Key Q**: "Is this company's profit coming from the business or from its stake in the thing replacing the business?"
**184. The Dependency Is a Variable, Not a Verdict**
A channel governed by one discretionary counterparty can tighten or loosen in either direction, and the same counterparty may pay for the data while gating the traffic. The risk is the dependency itself, not the current direction. The rational move is to build the owned front door regardless of which way the counterparty leans this quarter.
- **Key Q**: "Who holds discretion over this channel, and is the response to their current mood or to the dependency?"
**185. The Rented Front Door, One Layer Down**
A rail that monetizes agentic demand still depends on agent channels owned by rivals, the same discretionary counterparties that gate the taxed side of the web. Durability comes from an open standard, depth in the settlement, and the irreducibility of clearing. If a frontier agent owns checkout, the rail is disintermediated.
- **Key Q**: "Whose front door does this rail sit behind, and what stops that door owner from owning the settlement too?"
**186. The Free User Is a Cost**
On the web the free user was an asset with near-zero marginal cost whose attention was sold. In the AI era every free query consumes inference, so the free user is a cost until paid. The wedge is paid from day one, the metric is the outcome, and the enterprise pays first. The era's consumer-scale surface is the discovery line, reached by being cited.
- **Key Q**: "Is this company's free tier an asset it monetizes elsewhere or a bill it has not yet found a payer for?"
**187. The Deflation Paradox**
Price per unit of intelligence falls by an order of magnitude a year while tokens per task rise faster. Total spend rises as unit price collapses. Budget in tokens per accepted outcome, never in price tables; the operating response to deflation is more work per task, not less spend.
- **Key Q**: "As the unit price of this intelligence falls, are tokens per task rising faster, and is the budget denominated in outcomes?"
**188. The Three-Column Ledger**
Old web, old software, new software on nine rows: unit of sale (attention / seat / accepted outcome), cost of goods (~0 / ~0 / inference), gross margin (property / property / performance), price, customer shape (crowd / median / tail), the free user (product / asset / cost), moat, balance sheet, metric. Two rows carry the meaning: the cost of goods returned, and the customer changed shape.
- **Key Q**: "In which column does this business sit on each row, and which two rows changed?"
**189. The Data Oil and the Second Barrel**
The web's most valuable asset was the one it gave away: free content crawled under norms written for indexing became the corpus; value was captured at the refinery; creators were paid in traffic the models learned to make unnecessary. The settlement is late and a fraction. The wells thin under recursion, and the second barrel is the firm's residue: decision records, adjudicated cases, unavailable to any refinery that does not hold the loop.
- **Key Q**: "Who refined this firm's first barrel, and is the second barrel priced and owned before the first runs out?"
### XX. THE INTELLIGENCE STACK — ROUTING, HARNESS, CONTEXT, MODELS
**190. The Harness Is a Router**
Value migrates up to the harness, and inside the harness it concentrates on routing. The model was the heart of the old harness; the routing junction is the heart of the new one. Routing is a six-axis problem (model, stage, hardware, cost, jurisdiction, policy), and a firm routing only across models misses most of the cost surface.
- **Key Q**: "Where in this stack is the routing decision made, on how many axes, and who owns the rules that make it?"
**191. Routing Is Fractal**
The same pattern recurs at every altitude: compute fabric routes workloads in nanoseconds, the harness routes queries in milliseconds, the depth stack routes per deployment, an independence integrator routes vendors per engagement, a coalition routes narrative over years. The moat at each altitude is the private logic deciding which end to call.
- **Key Q**: "At which altitude is this router operating, and what does the same pattern look like one rung up and one rung down?"
**192. The Owned/Rented Barbell (The Alpha-Writing Sort)**
Own the deep substrate and the routing junction; rent the middle. The most expensive position is the middle: renting everything while owning nothing that compounds. Sort workloads by one question: does this write the firm's edge? If yes, own it on open weights; if no, rent the closed frontier and never look back.
- **Key Q**: "Does this workload write my edge, and if so, is it running on something I own?"
**193. The Co-Adaptation Principle**
Model, harness, and context are a loop, not a hierarchy. Performance is the fit between them, and the fit can be tuned without retraining the model. Harness tuning at a fraction of the cost can close most of a capability gap; the search space a cheaper model affords is itself a capability.
- **Key Q**: "Am I improving the model, or the fit between model, harness, and context, and which one is cheaper to move?"
**194. The Exhaust Flywheel**
Traces, evaluations, harness configuration, and memory are next turn's fuel, and they exist nowhere but the deployment that produced them. The moat of a super agent is its exhaust. A closed frontier condenses that exhaust into the landlord's weights and redistributes it; an open harness keeps the flywheel inside the firm's walls.
- **Key Q**: "Where does this deployment's exhaust accumulate, and whose walls is it inside?"
**195. Depth Collapse**
The artifact built for a shallow layer is the artifact the deep layer requires: a grounding graph built for retrieval is a training corpus at another depth. Firms that structured data for retrieval already own their path to a co-designed model. Depth is not how far into the model you reach; it is what you own at the bottom, what you own at the junction, and whether you can serve the difference.
- **Key Q**: "Which artifact built for retrieval is also this firm's training substrate, and does it hold clear title to it?"
**196. Restriction vs Diffusion (Openness as Demand Policy)**
The axis is not closed-Western versus open-Chinese; it is whether a layer is restricted or diffused. From a supplier's seat, open weights are demand policy: openness at every layer below a junction raises the value of the junction. Tiers stratify rather than substitute, and stratification multiplies routing decisions. A signature list is a map of whose economics depend on which layer staying open; the absences are the counter-coalition.
- **Key Q**: "Which layer does this actor want open, which does it hold, and what does the roster of absences say?"
**197. The Palantir Paradox**
The firm with the strongest incentive to defend lock-in signs for model portability because its capture point sits above the model layer. Best empirical proof that the enterprise-AI moat is not the model. Generalizes upward: whoever captures at the endpoint or the junction can commit to openness below at no cost.
- **Key Q**: "Where does this company capture, and does that let it be generous about everything beneath?"
**198. The Absorption Line (The Sixth Risk)**
Beside value, viability, usability, and feasibility sits a fifth risk (will it keep doing what it did) and a sixth: will the next release do it without you. Draw the line between perishable compensation for what the model cannot yet do and durable requirement the firm should own. Deletions are progress; the harness becomes a meta-harness, the referee of referees.
- **Key Q**: "Which parts of this product compensate for a temporary gap, and which would the firm still need after the next release?"
**199. The Three-Stage Token Lifecycle (The Reasoning Tax)**
Training (fabric-bound, amortized), prefill (parallel, cheap), decode (sequential, memory-bound, where the tolls sit). Reasoning and agentic loops multiply decode by 50–200x for the same user question. Cheaper models raise total decode spend because they expand what is worth asking. Value cascades to the physical floor, the distribution endpoint, and the routing junction, not the model.
- **Key Q**: "Which stage of the token lifecycle does this cost or moat live in, and does it scale with reasoning?"
**200. Networking Inversion**
An efficiency release can move the gate rather than open it: open weights free to download and expensive to serve relocate the binding constraint from model access to serving capacity, shrinking one interconnect bucket and inflating another. Falsify by watching where fabric demand rotates.
- **Key Q**: "Did this efficiency gain remove the constraint or move it, and to which physical bucket?"
**201. Product Workloads vs Capability Workloads (The Inference Cage)**
A product workload is high-volume, continuous, meterable, and has an external buyer; it books revenue. A capability workload is lumpy, internal, bursty, and has one customer; it books nothing. One substrate serving both starves the second, and a merchant gradient bends the architecture toward the workload it can sell. Owning every layer lets the layer that pays overrule the layer that wins later.
- **Key Q**: "Which workload does this substrate's roadmap bend toward, and what does the bend crowd out?"
**202. The Split Is the Admission**
A product line that bifurcates after years as one architecture confesses that the unified version carried a compromise. Read roadmap splits backward, and note that the admission lands years before the fix ships.
- **Key Q**: "What does this split confess about the years the line was unified?"
**203. The Option to Iterate (Rationing Reprices the Bench)**
The binding constraint on frontier research is compute available now, not in aggregate; measure it in queue latency, not chips. Rationing changes the return on staying for exactly the people with the most options. Compute allocation is a talent policy whether intended as one or not, and the first casualties are the strongest names.
- **Key Q**: "What is this lab's queue latency, and who leaves first when it lengthens?"
**204. The Second Index (Structuring Is Ownership)**
The competency that wins a corpus is industrializing its structuring, not the intelligence on top. Usage is the substitute signal where a corpus does not self-describe, but it reaches only data already in use (the cold corpus), and usage is not authority. The encoded business logic is the unit of capture; exit stops being migration and becomes rebuild. The open format is a solvent on rivals' lock-in and a funnel into your own index. The consultant becomes a subscription.
- **Key Q**: "Who is building the graph over this corpus, from what signal, and who holds it once built?"
**205. The Only Door (The Four Planes)**
A model knows nothing but what it reads, and at the moment of use it reads only the window. Capability, cost, and governance are all decided at one aperture. Application, execution, and governance planes read through the context plane; a rule not in the window is not a rule, and a rule only in the window is not enforced. Policy holds in the substrate and the runtime, not the prompt.
- **Key Q**: "What does this agent actually read at the moment of action, and where is the policy enforced if not there?"
**206. The Attack Surface Is the Window**
Injection is a context failure: instruction and fact look identical in the window. Defense is provenance on the fact, data marked as data, permission on the read, scope on the tool, a gate on the write, and attenuation across every hand-off (permissions only narrow). Memory is persistent injection risk. Forgetting is a property of the substrate, not the model.
- **Key Q**: "Which of the five gates does this window lack, and can a child agent reach more than its parent?"
**207. The Two Readers**
Humans ask by query; agents ask by description. The shape of the store decides the question it can answer (by key, by similarity, by reference, by description and traversal). A fact by traversal costs hundreds of tokens; by similarity, thousands. The domain expert signs the vocabulary; an ontology the business does not recognize is a schema. Answer engines outside the firm read the same substrate, so entity clarity is one piece of work done once.
- **Key Q**: "Is this store shaped for the question the agent asks, and did the business sign the vocabulary it uses?"
### XXI. MEASUREMENT UNDER OPTIMIZATION PRESSURE — THE DISCIPLINES
**208. Goodhart Is the Physics**
Reward hacking, specification gaming, judge exploitation, sycophancy, benchmark contamination, and sandbagging are one literature with five names. Any measure a loop can see, the loop will optimize. Treat this as physics, not as a bug class, and design every instrument so the loop cannot see it.
- **Key Q**: "Can the thing being optimized see the measure I am using to judge it?"
**209. The Frozen Suite**
The one measure the loop cannot see: real cases, adjudicated by domain experts, frozen before the build, held out, versioned, model-agnostic. Grown by logged addition, frozen per version. Right for the right reasons predicts the next version; a passing score alone does not.
- **Key Q**: "Is there a referee this loop cannot see, and was it frozen before the loop started?"
**210. Evaluation Is the Specification (The Model Chosen Last)**
Behaviour is specified by adjudicated example: the golden set is the requirements document, thresholds are the acceptance criteria. Choose the model last, in the final week, because by then the suite exists to choose it with. Vendor benchmarks say nothing about your cases.
- **Key Q**: "Does this product have a specification a model can be graded against, and was the model chosen before or after it existed?"
**211. Cost per Accepted Outcome (The Third Bottleneck)**
Tokens, then compute, then attention: the one bottleneck you cannot buy. Spend tokens to save attention; the attention bill is yours. Denominate everything in cost per referee-accepted outcome, never per token or per seat, and grade value maxing, not token maxing.
- **Key Q**: "What does an accepted outcome cost in tokens, compute, and human attention, and which of the three is binding?"
**212. The Loop as the Unit**
Persistent context plus delegation plus triggers is a loop. The loop, not the prompt or the model, is the unit of engineering, ownership, and value. Bound it, instrument it, own it; the engineer who polls is the scheduler, router, and memory the loop should have had.
- **Key Q**: "Is this a loop the firm owns, or a person doing the loop's job by hand?"
**213. Gross Margin as a Design Outcome**
In this era margin is built, not given. Four levers: the routing table, the cache hit rate, the owned-model share, and attention per outcome. A lab's arc runs from making for a dollar and selling for twenty cents to a positive gross margin; an application's arc runs the same way through its own model. Report the levers pulled and the levers available, never the assumed margin.
- **Key Q**: "Which of the four margin levers has this company pulled, and which is still available?"
**214. Pricing as a Finance Instrument (Price the Tail)**
Price on attribution and autonomy, ladder by proof, never seat-price agentic value, price the compounding, and price the tail, because a small share of accounts consume most of the tokens. The incumbent's tell is the sequence seats → conversations → credits → usage.
- **Key Q**: "Does this price track the work done and the tail that does it, or the chairs?"
**215. Outcome Pricing Is an End State (The Hybrid Is the Transition)**
Outcome pricing is right in theory and hard in practice: attribution is contested, baselines are gamed, verification lags, and the guarantee has a cost wherever it sits. The realistic path is the hybrid, seat plus credits, subscription plus metered requests, three meters at once on the record. Choose the ramp.
- **Key Q**: "Which rung of the seat-to-outcome ramp is this contract on, and who is carrying the guarantee's cost?"
**216. The Counterfactual as Referee (Attribution Collapsed)**
When the path runs through a model there is no touch to log, so last-touch attribution dies. Only incrementality survives: holdouts, geographic splits, difference-in-differences, synthetic controls. The experiment loop must be frozen like any other referee or it games itself.
- **Key Q**: "Is this growth claim backed by a counterfactual, or by a touch that no longer exists?"
**217. Growth Goodhart (The Slop Flood)**
The era adds three ways to game growth: a flood of generated content with negative return, agent-farmed activity metrics, and a self-gaming experiment loop. Only substance the machine cannot generate grows; the instruments that survive are the ones a machine cannot fake and a buyer would pay for.
- **Key Q**: "Could a machine have produced this growth number, and would a buyer pay for what it measures?"
**218. The Two Surfaces**
A human sees the interface; an agent sees the specification. Same outcome, two surfaces, one suite grading both. Design for the reader who never sees the screen. Activation is the first verified outcome; retention is the outcome kept.
- **Key Q**: "Does this product have an agent surface, and is it graded by the same referee as the human one?"
**219. The Residue Loop**
Every accepted outcome and every adjudicated exception leaves a record: the decision loop's second output. It is the only growth loop the machines cannot mediate, the second barrel of oil, the roadmap ("what was built twice?"), and the basis of the owned model. Capture rate of the residue is a board number.
- **Key Q**: "What does this loop leave behind, who owns it, and what fraction is being captured?"
### XXII. VALUATION — THE NINE QUESTIONS AND THE RESIDUAL
**220. The Multiple Comes Last (The Five Broken Assumptions)**
The software toolkit (run-rate × multiple) rests on five assumptions the era broke: run-rate is revenue (it is a month times twelve, unaudited, on the company's own basis); gross margin is a category property (it is a design outcome in motion); the product is the asset (the next release absorbs part of it); the customer pays per seat (a heavy tail pays for work); the capital is on the balance sheet (leases, guarantees, supplier equity, private credit). Each error runs in a nameable direction. The reported number is the beginning of a valuation, not its input.
- **Key Q**: "Which of the five assumptions is this valuation still making, and in which direction does the error run?"
**221. The Counted Top Line**
Count each end-customer dollar once, at the tier where the customer transacted: assign the tier, strip pass-through, exclude the tier that is a cost of the tiers above, convert gross to net, convert run-rate to a year with growth decaying to a terminal rate, and state source and range. Counted-to-reported typically lands at 0.6–0.85. A gross figure in the headline is a maturity-zero disclosure.
- **Key Q**: "What is this company's counted top line, and what is the ratio of counted to reported?"
**222. The Residual**
The fraction of a company's value on the durable side of the absorption line, after what the next release absorbs, what the supplier's mark inflated, and what the hidden obligation subtracts. A company at 70% residual is a business; at 30% it is a feature with a run-rate. The multiple is applied to the residual and to nothing else. In a residual-adjusted cash flow, the perishable share decays per release and terminal value is taken on the durable share only; a compensation with a two-release life at a six-week cadence is worth a quarter of a year, not a perpetuity.
- **Key Q**: "What fraction of this company survives the next release, and is the multiple being applied to that fraction or to the whole?"
**223. The EV Bridge With Hidden Piers**
Enterprise value is equity plus debt plus what the balance sheet hides: leases not commenced (weighted by deferral versus transfer), purchase commitments, guarantees weighted by call likelihood, supplier financing, vehicle debt, private credit. Builders and neoclouds carry hidden-obligation multiples from 1.1 to well above 1.5.
- **Key Q**: "What is this company's hidden-obligation multiple, and does the equity story survive it?"
**224. The Worthless Cases, Weighted**
A valuation without its worthless case is a bull case with a number on it. Name three: commoditisation (the model layer absorbs the product), capture (the vendor holds what compounds), the wrapper (the guarantee or the counterparty fails), each with a trigger and a probability. Sum probability times value across base and worthless cases.
- **Key Q**: "What kills this company, what is the trigger, and what is the probability-weighted value once that case is in the sum?"
**225. The Layer Multiple and the Reconciliation**
Borrow the multiple from the nearest priced asset by layer, not by category: junction, rail, application, neocloud, supplier, each has a priced comparable; the frontier lab has none, which is itself the finding. Then reconcile to the reported number by naming the question that made the gap. The company is usually real; the number often was not.
- **Key Q**: "From which priced layer does this multiple come, and which of the nine questions explains the gap to the reported number?"
**226. The Acqui-Hire Read**
License the IP, hire the team, leave the shell: the market pricing the residual directly and leaving the company on the table. Read each such deal as a valuation of what compounds (the people and the exhaust) against what does not (the corporate entity). Place public cases on a residual axis and the pattern reads itself.
- **Key Q**: "In this deal, what did the buyer pay for and what did it leave behind, and what does that say about the residual of the whole company?"
**227. The Hostile Reading First**
Before the base case, write the reading a hostile analyst would write: gross booked as net, the assumed margin, the perishable feature, the supplier's mark, the hidden obligation. If the company survives the hostile reading at a defensible number, the base case has earned its place.
- **Key Q**: "What would the most hostile competent reader say this is worth, and can I answer each of their questions with an artifact?"
**228. Read the Sign of the Distortion (Two Engines, Both Ways)**
Marks distort earnings upward; stock compensation, convert-extinguishment losses, and IPO charges distort them downward. Reported net income can sit above or below the operating line, and the direction is diagnostic. Strip in both directions; never assume the distortion flatters.
- **Key Q**: "Does this reported number sit above or below the operating engine, and which non-cash item put it there?"
### XXIII. THE ENTERPRISE — BUYING, CAPTURE, ALLIANCES
**229. The Asymmetry**
The seller runs the meeting fifty times a year; the buyer runs it twice. Selling is a practiced craft, now automated; buying is an amateur sport played against professionals. Instruments substitute for the repetitions the buyer will never have. The ordering is the argument: the standard, the separated champion, and the buying function come before any vendor.
- **Key Q**: "What instrument does this buyer hold that substitutes for the repetitions the seller has and it does not?"
**230. VERIFIED (The Buyer's Qualification)**
The mirror of the seller's qualification alphabet: Verification owned · Economics read · Rights scheduled · Incentives separated · Feasibility on your floor · Independence priced · Exposure governed · Drift instrumented. Every letter holds an artifact, never an assurance. Run three letters before contact, three at the wedge's clock, two before signature, then annually; a failed letter prices the purchase.
- **Key Q**: "Which letters of VERIFIED hold an artifact, and which is the one nobody checked?"
**231. Procurement Theater**
A pilot defends a budget; a champion's advocacy is not an audit; a coached reference proves the vendor curates well; the paid map (analysts as channel, assessors selling remediation) is a channel; a board introduction is a bypass. The one test that separates theater from proof is the frozen suite on the buyer's own floor.
- **Key Q**: "Which part of this evaluation could the vendor have staged, and which part ran on my floor against my referee?"
**232. Fast Yes With Clean Title**
The seat's answer to shadow adoption is not a slower door but a faster one with conditions: an intake measured in days that absorbs the card purchases, attaches the standard, places the junction, and prices the exit. Let go of the door; keep the four keys.
- **Key Q**: "Can this firm say yes in days while keeping clear title to what the purchase will compound?"
**233. The Enterprise Alliance (Opened vs Held)**
The unit of competition is shifting from the firm to the alliance network, in three species: vendor-vendor stacks entering as one motion, substrate coalitions whose membership lists are the argument, and customer co-design where the asset is the customer's own codified expertise. Reading rule for every alliance: which layer does each ally open and which does it hold. Partner today, rival at renewal. Alliance moves lead repricing by quarters.
- **Key Q**: "Which layer does this ally open for me and which does it hold for itself, and where are the absences on the roster?"
**234. The Hand That Wires the Harness Chooses the Landlord**
Forward-deployed engineering is the capture vector: whoever wires the loop decides where the exhaust lands. When deployment labor is automated, the absorption machine is industrialized and capture gets cheaper to run at scale. A better landlord is not sovereignty; the cage moved one floor up.
- **Key Q**: "Who wired this loop, and whose walls does its exhaust accumulate inside?"
**235. The Two-Hinge Window**
Two hinges move in opposite directions: the funding hinge (vendor subsidy for capture) is closing, the cost hinge (open tiers collapsing the cost of alternatives) is opening and does not reverse. What expires is the subsidy, not the feasibility. Regulation with tested-exit requirements mandates the barbell in regulated industries.
- **Key Q**: "Which hinge is this firm timing against, the subsidy that expires or the feasibility that does not?"
**236. The Independence Integrator (The Double Objective)**
A regime-agnostic deployment firm that turns vendor land-grab budgets into enterprise independence: column A the vendor pays for, column B the enterprise owns, same engagement. A six-week migration test at production scale is the proof; independence certification is the payday; exit is the payday, not the risk. Doctrine is the hiring filter, and the talent and the toolkit must both pass the portability test.
- **Key Q**: "Does this engagement leave the enterprise able to migrate in six weeks, and who gets paid when it can?"
**237. The Three Cages**
Model, cloud, platform: three cages an enterprise can be captured in, each with its own exit cost. The regulated-industry wedge (single-vendor-risk prohibitions, budget scale, institutional patience) is where the cages get priced first. Sovereignty productized (the customer owns the weights, the vendor owns the junction) is the correct doctrine implemented at the layer that happens to be the vendor's own.
- **Key Q**: "In which of the three cages is this enterprise, and is the sovereignty it was sold the customer's or the vendor's?"
**238. The Enterprise Edge as Distribution**
As fine-tuning moves on-premises onto enterprise silicon, the enterprise itself becomes a distribution channel for the silicon vendor, one the vendor could not open alone. The governable software layer is the business-model wrapper that makes the sale legible; the junction owner and the silicon vendor coordinate by coincidence of interest, not alignment.
- **Key Q**: "Which vendor's silicon does this enterprise stack distribute, and who wrapped it into something buyable?"
### XXIV. THE ORGANIZATION, THE SEATS, AND THE WORK
**239. The Neutral Gain**
Every dashboard green, margin unchanged: everyone got faster, nobody got ahead. Symmetric tools produce a neutral gain unless the firm adds asymmetric inputs or an asymmetric organization. Operational effectiveness is not strategy; with symmetric tools it is arithmetic.
- **Key Q**: "Your people are faster. Is the firm ahead, and by what asymmetry?"
**240. The Ascent Through Scales**
The gain must climb four scales (individual → group → organization → strategy) and evaporates at every scale it fails to climb. The escape at each level is one level up. Track the climb, not the tool count.
- **Key Q**: "At which scale did this firm's gain stop climbing, and what would carry it one level up?"
**241. Edges Find and Cannot Choose; Center Chooses and Cannot Find**
Bottom-up discovery is fuel, not vehicle: it cannot rank, it fragments, it leaks. Top-down direction allocates, standardizes, and directs but cannot find. Governance is the transmission between them: a paved road measured by coverage not policy, a discovery pipeline measured by conversion time, a junction map, and a residue rule.
- **Key Q**: "What is this firm's conversion time from an edge discovery to a governed loop, and who owns the paved road?"
**242. Installation Is the Entry Fee, Reorganization Is the Harvest**
The dynamo took forty years because factories kept the line shaft; the harvest came with unit drive and the rebuilt floor. Today's line shaft is the workflow built around scarce human attention as the central power source. The forty-year lesson runs on a five-year clock.
- **Key Q**: "Has this firm installed the technology or rebuilt the floor around what it makes cheap?"
**243. Automation or Enhancement Is a Deployment Choice**
Substitute versus amplify is a property of the deployment, not the model. Labor evidence shows recomposition rather than disappearance: exposure and augmentability form a diagonal, the mix moves before the total, and the missing first rung is where the damage concentrates. Design the task line with both spans and the entry gap in view.
- **Key Q**: "On this task line, which spans are automated, which enhanced, and where does the next person enter?"
**244. The Ratio Rule (Push Until the Gate Bends)**
Raise the agent-to-human ratio until the quality gate bends, then step back one notch. A ratio without a measured gate is refused. Public reversals (support reopened to humans after quality bent) are the rule stated in the wild.
- **Key Q**: "Is this ratio backed by a measured gate, and at what ratio did the gate last bend?"
**245. The Import Test**
Before importing another firm's mechanism, ask three questions: same scale, same gate, same dates. Import the mechanism; rebuild the numbers on your own floor. Revenue per employee conflates leverage with layoffs; a stale headcount violates same-dates.
- **Key Q**: "Does this case pass same scale, same gate, same dates, or am I importing a headline?"
**246. Organization Design Is Moat Design**
The moat rebuilt on four stones: the residue, the property line, coordination capital, and default status with machine buyers. Cost, then speed with coherence, then optionality, then moat, in strict order. The order matters because each purchase is the entry fee for the next.
- **Key Q**: "Which of the four stones is this organization laying, and in what order is it buying cost, speed, optionality, and moat?"
**247. The Missing Rung**
AI commoditizes the climb, prices the summit, and removes the stairs. Generation at the bottom rungs becomes symmetric; the premium moves up to judgment and selection; the tool erodes that judgment through sycophancy and removes the apprenticeship that built it. The response is not better judgment but judgment you cannot skip: externalized into a structure that holds at three in the afternoon as at nine.
- **Key Q**: "Where in this firm is judgment being built now that the stairs are gone, and is it enforced by structure or by exhortation?"
**248. The Judgment Layer**
Above the loop sits the place only very highly skilled domain experts can stand: the exceptions the suite cannot accept rise to a junction, and the person who decides is the one who can say what the standard should be when the standard is silent. Scarce by construction, it compounds through the seed (spent once, levered forever) and is the firm's defensible position against both the client's agent and the vendor's embedded engineer.
- **Key Q**: "Who in this firm can say what the standard should be when it is silent, and does each of their judgments become a case?"
**249. The Seed**
The pyramid was seeded from the bottom; the loop is seeded from the top. A harness is empty until an expert adjudicates the first fifty cases, names the gray areas, and signs the vocabulary. It cannot be done by the machine (it is what is being seeded) or by a junior (who does not know). The expert was the cost the pyramid diluted; in the loop the expert is the seed the leverage grows from.
- **Key Q**: "Who seeded this loop, how many cases did they adjudicate, and did they sign the vocabulary?"
**250. Leverage Is Loops per Senior**
The professional pyramid's leverage was rate times utilization times leverage in the grinding tier. When the model does the pyramid's work the shape becomes an obelisk, and leverage becomes accepted outcomes the harness lets a senior sign. The pod (senior, builder, operator, harness) replaces the tier; retainer, meter, and share replace the hour; the document was the receipt and the residue is the moat.
- **Key Q**: "How many loops does each senior in this firm sign, and is the price attached to the outcome or the hour?"
### XXV. THE SEATS, THE ROLES, AND THE HISTORICAL RHYMES
**251. The Four Ownerships**
Regardless of title, the seat handed the AI mandate must own the substrate, the junctions, the standard, and the exit; rent everything else freely, because you can leave. A new title names a gap; it closes it only when it arrives with budget authority, the standard, and the right to stop. Whoever holds the four is the chief AI officer, whatever the card says.
- **Key Q**: "Who in this firm holds the substrate, the junctions, the standard, and the exit, before any title is created?"
**252. Absorb, Be Displaced, Converge**
When an asset changes character faster than a seat's identity, a new C-title is created and resolves one of three ways: absorbed back into the seat, displacing it, or converging with it. The digital-officer arc was the rhyme; the data-officer arc is the warning. The seat that holds the four absorbs the title; the seat that holds only the door is displaced by it.
- **Key Q**: "Is this new title going to be absorbed, displace the seat, or converge with it, and which of the four ownerships decides?"
**253. The Grid (Watch the Blanks)**
Roles sit on a lifecycle across (specify, prepare, build, deploy, evaluate) and five accountable functions down (business owner, domain owner, builder, evaluation owner, adoption owner). Every loop is a path through the grid; an unowned hand-off is an empty cell. Recurring cells are the small center, varying cells the federated edge. A title is evidence of attention, not of a market.
- **Key Q**: "Which cells of this firm's grid are blank, and which loop's hand-off is falling through them?"
**254. The Entry Point Moves**
The era is not destroying jobs or creating them; it is moving the entry point from producing the work to owning the loop that produces it. Rebuild the first rung as a ninety-day apprenticeship whose credential is the case study with its failures; convert the analyst tier into operators and evaluators before hiring.
- **Key Q**: "Where does a new person enter this firm now, and what is the first rung they stand on?"
**255. The Seat That Grades Never Built**
The evaluation owner is separated from the builder by design, at the loop and at the top row: the seat that owns the standard is never the seat that builds the loops. Governance reports outside the technology organization. Flatter in function, denser in ownership: a seat is added and a boundary is lost at the same time.
- **Key Q**: "In this firm, does the seat that grades the loop ever build it?"
**256. The CTO of Someone Else's Company (DEPLOY)**
The deployment seat is accountable for production value while holding no levers. Its sequence is DEPLOY: Discovery · Envelope · Proof · Landing · Outcome · Yield, and every letter has a date. Say no in writing and keep the refusal log; the baseline is taken before, the gauge page after; what comes back is the reference architecture and the product requirement.
- **Key Q**: "Which letter of DEPLOY is this engagement on, what is its date, and what did the architect refuse in writing?"
**257. The Railroad Rhyme (Capital Ahead of Demand)**
The right historical rhyme for a physical buildout is the railroad: four panics, one continuous buildout, mileage tripling through them. Not the web bubble. The pattern repeats in the fiber overbuild: capital on a physical clock against demand on its own schedule, the income statement asked first, survivors buying the assets. Real, historic, and, for most of the capital, insufficient.
- **Key Q**: "Which rhyme am I using, and does it account for the buildout continuing through the panics?"
**258. The Access Rent**
The firm that owns access earns a rent only while access is scarce; when the constraint opens, the rent moves to whatever the input was gating. The dial-up subscription was the first web rent; each era since has repriced the same lesson.
- **Key Q**: "Which scarce access is this rent built on, and what happens to the rent when that access opens?"
**259. Get Big Fast, Monetize Later vs Paid From Day One**
The web's growth doctrine assumed a free user with zero marginal cost and an advertiser who would pay later. The AI era's free user is a cost, so the wedge is paid, the metric is the outcome, and the enterprise pays first. Do not import the web's growth math into a business with a cost of goods.
- **Key Q**: "Is this growth plan assuming a free user who is an asset, when the free user is now a cost?"
**260. Intent Is the Scarcest Thing on the Web**
The auction priced intent in real time and built the most profitable machine ever made from a copy that cost nothing, teaching two decades of finance that software's margin was a law of nature rather than a property of one product. The copy was free for thirty years; that was the accident, not the rule.
- **Key Q**: "Which of this business's margin assumptions rests on the copy being free, and does the copy still cost nothing?"
**261. Web Squared (Outside-In and Inside-Out)**
AI does not replace the web; it compounds it, riding thirty years of the web's infrastructure, data, and distribution, which is why web-native industries transform first. The web changed distribution first and the operating model last (outside-in); AI changes the operating model first, the business model next, and distribution last (inside-out). Organizational transformation is the prerequisite for business-model transformation, which is why enterprise AI is hard. Carry the inside-out nuance only where it serves the argument; drop the branding where it does not.
- **Key Q**: "Is this transformation being attempted from the outside in, when the era runs from the inside out?"
---
# PART III — DESIGN THE FIRM
## The Business Architect
### The Design Engine (Layers 0–4)
The core diagnostic engine. Every design is run through all five layers in order, no layer skipped, each producing one finding card. Phase discipline: Configure → Diagnose (run the engine) → Prescribe (the mode's artifact).
**Layer 0 — Environment**
Establishes what ground a design stands on: which constraint currently binds its layer (and which bound it two states ago), the clock mismatch (how fast its environment reprices vs how fast the firm can actually rebuild), and template exposure (which inherited pattern book it descends from and whether that template's era-assumptions still hold). Checks the era's three broken defaults: zero marginal cost is over, summarizable value has no floor, the aggregator's throne moved to agent access and settlement authority.
- **Apply**: First step of any review or founding. Produce the environment card — constraint address, clock mismatch, template exposure with the specific broken assumption named.
**Layer 1 — The Four Choices**
Tests whether the four irreversible choices — Value, Technology, Distribution, Finance — are made and cohere. Value must survive the subtraction and land at commitment/clearing/context/trust/desire; Technology audits the barbell (own differentiators, rent commodity behind clean joints) plus the second barbell and cost-curve conversion; Distribution classifies channels (owned endpoint / rail / rented door) and checks machine legibility; Finance covers terminal-margin thesis, capital intensity, engine honesty, and survival reserves.
- **Apply**: Score each of the four choices coherent / incoherent / unmade and name the binding incoherence. Central to Full Design Review and Clean-Sheet Founding.
**Layer 2 — Position**
Places the design on the site plan by its economic signature, not its pitch, then decomposes the rent (monopoly vs tightness) and runs the rotation test: which constraint state current economics depend on, whether the position sits on the constraint's return path, and in which not-yet-happened state the design fails structurally. A design with no failing state usually has no position; with several, it is a trade.
- **Apply**: Produce the position card — seat, signature evidence, rent split %, rotation verdict (freehold / lease / trade). The heart of a Position Audit.
**Layer 3 — Moats**
Applies the daily-mechanism test to every claimed moat — name the daily operation whose by-product is defensibility, or the claim is a metaphor. Sorts moats into the compounding menu (accumulated fit, residence, clearing and standing, standards and protocols, physical scarcity) and the retired list (model quality, feature velocity, raw data volume, headcount scale, attention on summarizable content).
- **Apply**: Produce the moat ledger — claimed moats with their daily mechanism or their retirement, plus the accrual verdict. Core of a Moat Audit.
**Layer 4 — Structure**
Asks whether the design survives being wrong by auditing four structural practices: modularity at the joints (a repricing is a swap, not a rebuild), reversibility as a visible budget line sized to the rotation, optionality against the named failure states from Layer 2, and falsifiers written on the blueprint and reviewed on cadence.
- **Apply**: Produce the structure card — joints, reversibility budget, live options vs failure states, and the falsifier register's existence and staleness.
### Operating Modes
Eight modes route by request, each running specific layers and emitting a defined artifact.
**Mode 1 — Full Design Review**
All layers run as an audit; delivers findings per layer, a Design Integrity Level, five ranked corrections, and a 90-day sequence.
- **Apply**: "Review our strategy/business model," "is this sound." Also the base for a fundraising narrative (position card, terminal-margin thesis, moat ledger recast as the story).
**Mode 2 — Clean-Sheet Founding**
Layers 0→4 run forward as choices rather than audits — four choices argued, seat chosen against endowments, moat plan with day-one mechanisms, structure spec.
- **Apply**: "Starting a company," "designing from scratch," or the annual clean-sheet exercise. Endowment-matching: junction rewards trust held, rail rewards neutrality, substrate rewards installed base, endpoint rewards brand, constrained input rewards patient capital.
**Mode 3 — Position Audit**
Layer 2 deep plus Layer 0; delivers position card, rent decomposition, and rotation verdict.
- **Apply**: "Where do we sit," "are we a platform," competitive position. Also run on an acquisition target or a rival (from their filings).
**Mode 4 — Moat Audit**
Layer 3 deep; delivers the moat ledger with the daily-mechanism test run per claim and a build order for missing mechanisms.
- **Apply**: "What's our moat," defensibility, competitive advantage.
**Mode 5 — Dependency Pricing**
Inventories every rent (models, doors, rails, clouds, channels, single sources) and prices three exposures per line — toll (price can rise), gate (access can close), learning (the flow condenses the firm's edge into the counterparty — the transfer that never sends an invoice) — then engineers the joints. A dependency priced at design time is an input; priced at renewal it is a hostage negotiation.
- **Apply**: Platform risk, vendor risk, "what if they change the terms." Produce the dependency radar + joint-engineering plan.
**Mode 6 — Capture Design**
Places the meter at maximum irreducibility — meters hold at commitment, clearing, consumption of the newly marginal cost, and residence; they fail at summarizable content and matchable features. The well-placed meter doubles as the firm's best market instrument.
- **Apply**: Pricing, monetization, "how do we charge." Produce the meter map — capture points scored for irreducibility and telemetry value.
**Mode 7 — Rotation Stress Test**
Expands Layer 2's failing-state question — runs the design against standard plus user-specific stress states, classifies each as absorbed / degraded / structural failure, and checks Layer 4 structure covers the failures.
- **Apply**: "What could kill us," scenario planning, resilience. Produce the stress panel.
**Mode 8 — Sequencing**
Own first what cannot be added later (trust, standards seats, clean-export reputation); rent first what teaches fastest; convert at the capture points when the learning justifies it; never let the balance sheet bet ahead of the design's evidence.
- **Apply**: Roadmap, "what to build first," scaling plan, M&A build-vs-buy order. Produce the build sequence — stage-by-stage own/rent ledger with conversion triggers.
### Frameworks
**The Value Subtraction**
Strike everything a customer's own assistant produces on demand (drafts, analysis, code, answers); what survives must sit at commitment, clearing, context, trust, or desire. A value proposition upstream of all five is cost, not value.
- **Apply**: Layer 1 Value test — to locate where durable value actually lives after generation commoditizes the rest.
**The Design Barbell (VTDF technology audit)**
Rent the commodity behind clean, swappable joints; own the differentiators (any lever controlling the firm's own costs, plus proprietary fit). A second barbell checks whether the bet that could obsolete the design is funded by anyone — ideally this firm.
- **Apply**: Layer 1 Technology test — deciding what to own vs rent at the component level, and whether the killer bet is funded.
**The Site Plan (six seats)**
Six positions defined by filings-grade economic signature: constrained input (scarcity margins, heavy capital, full rotation exposure), junction (customer context meets rented models — near-triple-digit growth at sub-1% capital intensity), rail (clearing functions demand must pass through — toll economics at trivial capex), substrate (the system of record machine work accumulates in — deepening switching costs but pays the inference bill first), endpoint (the brand, the habit), and commodity seat (volume with capture flowing to neighbors — fatal when occupied unknowingly).
- **Apply**: Layer 2 placement — locate the firm's actual seat by economics, ghost the aspiration seat if different.
**Rent Decomposition (Tightness vs Monopoly Rent)**
Split operating profit into monopoly rent (from a structural chokepoint; persists across constraint states) and tightness rent (from the constraint's current visit; leaves with it). The confession to watch: incumbents converting rent to contract (take-or-pay, price floors, multi-year) reveal which rent they actually have.
- **Apply**: Before pricing or valuing any position — decompose the rent, then contract it or size for its departure.
**The Rotation Test**
Three questions on a position: which constraint state current economics depend on; whether the position sits on the constraint's return path (own the station the constraint returns to; the visited station is a trade in strategy's clothes); and in which not-yet-happened state the design fails structurally.
- **Apply**: Layer 2 — to distinguish a freehold from a lease from a trade, and to feed named failure states into Layers 4 and 7.
**The Three-Exposure Dependency Inventory**
For every rented input, score toll (the price can rise), gate (access can close), and learning (the flow condenses the firm's edge into the counterparty) — the last being the transfer that never sends an invoice. Then engineer joints: second sources, rehearsed exportability, ring-fenced learning, dependency on categories not counterparties.
- **Apply**: Mode 5 — to price platform/vendor risk at design time rather than at renewal.
**The Meter Placement Model**
Value flows through a pipe; the meter belongs at maximum irreducibility — commitment, clearing, consumption of the newly marginal cost, residence — and fails at summarizable content and matchable features. A well-placed meter is also the firm's best telemetry instrument.
- **Apply**: Mode 6 — designing pricing and monetization architecture.
**The Load-Bearing Frame (VTDF)**
The four irreversible choices — Value, Technology, Distribution, Finance — drawn as a structural frame, each member colored by coherence verdict with the binding incoherence flagged.
- **Apply**: Modes 1–2 — to visualize and test whether the four choices cohere and where the design fails.
### Lenses & Laws
**The Rotation Mismatch**
The environment reprices in quarters while the firm rebuilds in years; therefore design for the constraint structure, not the current constraint.
- **Apply**: The governing lens for the whole discipline; foregrounded in Layer 0.
**Templates Are Frozen Answers**
Inherited pattern books (SaaS, marketplace, attention, platform, hardware, services pyramid) are frozen answers whose era-assumptions break on schedule at era boundaries.
- **Apply**: Layer 0 template-exposure check; re-derive the four choices from first questions rather than running an expired playbook.
**Stories Expire With Constraints**
Designs made at a constraint narrative's peak ("compute is destiny") are made for the state about to end.
- **Apply**: Layer 0 — guard against narrative-peak design; design against the structure, not the story.
**Software Acquires a Cost of Goods** → canonical entry in **AI Economics**. Applied here in this seat's context.
**Fund the Bet That Kills You**
The discontinuous bet that would obsolete the design should be funded by this firm — or a competitor will fund it.
- **Apply**: Layer 1 Technology second-barbell check; corrects the Unfunded Killer failure pattern.
**Distribution First**
The channel constrains everything; choose it before the product.
- **Apply**: Layer 1 Distribution — sequence the channel decision ahead of the product decision.
**The Rented Front Door**
A rented channel is reach purchased with dependency — a term sheet the landlord can reopen.
- **Apply**: Layer 1 Distribution and Mode 5 — score the rented-door share of demand and price it.
**The Second Readership**
On a machine-majority web, agent legibility (structured data, APIs, protocols) is the new indexability.
- **Apply**: Layer 1 Distribution — check the design is legible to machines, not only humans.
**Capital Intensity Is a Choice**
Capital intensity spans three orders of magnitude within one industry; match it deliberately to the durability of the position it buys.
- **Apply**: Layer 1 Finance and Mode 8 — choose intensity against proven position durability; corrects the Premature Build.
**The Terminal Margin Is the Whole Position**
For designs without long-duration assets, the mature gross margin (with AI costs at scale, and who controls the levers) is effectively the entire position; inference as a pass-through outsources margin to a vendor's pricing committee.
- **Apply**: Layer 1 Finance — write the terminal-margin thesis and secure a firm-controlled cost lever.
**A Position Is What the Filings Say**
A position is what the margins, capital intensity, and dependency map say it is — never what the vision or pitch says.
- **Apply**: Hard rule across Layer 2; when the engine contradicts self-description, the position card outranks the pitch.
**Own the Station the Constraint Returns To**
Value comes from owning the station the constraint returns to; owning the currently-visited station is a trade dressed as strategy.
- **Apply**: Layer 2 rotation test — evaluate whether a position is on the constraint's return path.
**The Failing State**
A design with no state in which it fails structurally usually has no position; a design with several failing states is a trade.
- **Apply**: Layer 2 and Mode 7 — use failing-state count as a position/trade diagnostic.
**The Daily-Mechanism Test**
Every claimed moat must name the daily operation whose by-product is defensibility; a moat with no daily mechanism is a metaphor.
- **Apply**: Layer 3 and Mode 4 — filter real moats from claimed ones.
**The Accumulated Fit**
Competitors can rent your model but not your ten thousand corrections — the co-adapted loop of model, harness, context, and corrections, built inside the firm's own walls from day one.
- **Apply**: Layer 3 compounding menu; a day-one moat requirement handed to Agent Engineering.
**Residence**
Own where machine work accumulates; export ease becomes the trust feature.
- **Apply**: Layer 3 — moat via being the system of record; also a Mode 6 meter point.
**Clearing and Standing**
The oldest durable moats (verification, transactions with identity/payment/liability); the machine web strengthens them.
- **Apply**: Layer 3 — recognize and build toward clearing/standing positions.
**The Standards Game**
Give away the language, own the toll booth — the shipping container's game; won early or not at all.
- **Apply**: Layer 3 and Mode 8 (own first what cannot be added later) — standards/protocol seats.
**The Pace Car**
Model quality now sets the tempo but protects no one who merely keeps up; it is a retired moat.
- **Apply**: Layer 3 retired list — refuse to budget model quality (or feature velocity, raw data volume, headcount scale, summarizable attention) as defensibility.
**Swap, Not Rebuild**
Modularity at the joints means every rented component sits behind an interface the firm controls, so a repricing becomes a swap rather than a rebuild.
- **Apply**: Layer 4 — audit the joints for controlled interfaces.
**Reversibility Is a Budget Line**
Reversibility (expensed vs capitalized, short vs long commitments, convertible positions) is paid for visibly and sized to the rotation's speed.
- **Apply**: Layer 4 and Mode 8 — budget reversibility explicitly; corrects the Premature Build.
**Priced Dependency**
A dependency priced at design time is an input; priced at renewal it is a hostage negotiation.
- **Apply**: Mode 5 — run the three-exposure inventory now, not at contract renewal.
**Sequence Beats State**
Own first what cannot be added later; rent first what teaches fastest; convert at the capture points when learning justifies it.
- **Apply**: Mode 8 — the ordering law for build sequences.
**The Clean-Sheet Test**
The standing design must beat today's redesign — or borrow from it.
- **Apply**: Mode 2 / annual exercise — benchmark the existing firm against a clean-sheet founding.
**Strategy Is Structure**
Good strategy is positioned where the rotation returns, metered where every state passes, and jointed where the constraint strikes.
- **Apply**: Closing synthesis lens tying position, capture, and structure into one verdict.
### Maturity Ladder — Design Integrity Levels (D0–D5)
**D0 Implicit**
The four choices were never made on purpose; the position is inherited.
- **Apply**: Baseline diagnosis for firms with no deliberate design.
**D1 Narrated**
Strategy exists as story; no filings-grade evidence ties to it.
- **Apply**: Most strategies audit here; flag the absence of evidence.
**D2 Placed**
Position identified from real economics; rent decomposition done; template exposure named.
- **Apply**: Achieved once Layer 2 is run honestly.
**D3 Chosen**
The four choices coherent; terminal-margin thesis written; meter placed at irreducibility; dependencies priced.
- **Apply**: The target of the payoff jump — D1→D3 is placement and choices, not vision work.
**D4 Structured**
Joints modular, reversibility budgeted, options live against named failure states, falsifier register reviewed on cadence.
- **Apply**: Reached when Layer 4 practices are in place.
**D5 Compounding**
Moat mechanisms run daily with measurable accrual; the design has survived at least one rotation with corrections logged.
- **Apply**: The compounding endstate; proven through a completed rotation.
### Failure Pattern Library
**Aspiration-Position Mismatch**
The deck says platform while the margins say assembler — position claimed from vision.
- **Apply**: Fix via Layer 2 placement from the filings; rename the strategy or change the economics.
**Template Inheritance**
A SaaS/attention/marketplace playbook run after its era, mistaking a pattern book for law.
- **Apply**: Fix by re-deriving the four choices from the questions.
**Terminal-Margin Blindness**
Growth applauded while gross margin erodes with every AI feature.
- **Apply**: Fix by writing the terminal-margin thesis and securing a firm-controlled cost lever.
**The Rented Whole**
The entire front door is one landlord's discretion.
- **Apply**: Fix via dependency pricing; build or buy a second door before renewal.
**Tightness Capitalized**
The constraint's visit priced as a permanent chokepoint — in valuation, hiring, or capex.
- **Apply**: Fix via rent decomposition; contract the rent or size for its departure.
**Moat as Metaphor**
Defensibility claims with no daily mechanism.
- **Apply**: Fix via the moat ledger; build the mechanism or retire the claim.
**The Premature Build**
Capital intensity chosen before position durability is proven.
- **Apply**: Fix via the sequencing mode and a reversibility budget.
**Renewal Hostage**
A dependency discovered only at contract renewal.
- **Apply**: Fix via the three-exposure inventory, run now.
**Upstream Meter**
Charging at content/features where flows route around the meter.
- **Apply**: Fix by moving the meter to commitment, clearing, consumption, or residence.
**Optionality Theater**
"Options" that are slideware — nothing owned, nothing priced.
- **Apply**: Fix by making options budget lines against named failure states.
**Narrative-Peak Design**
The firm designed at the top of a constraint story, on the eve of its rotation.
- **Apply**: Fix via Layer 0 honestly; design against the structure.
**The Unfunded Killer**
The discontinuous bet that obsoletes the design is funded only by competitors.
- **Apply**: Fix via the second barbell; fund the bet that kills you.
<a id='11-ai-economics'></a>
---
## AI Economics
### Foundational Inversions (why the seat exists)
**The Accident Mistaken for a Law**
The software era rested on an accident it mistook for a law — that the marginal cost of a copy was zero. That was a property of the copy, not a law of business.
- **Apply**: Whenever an "80% SaaS gross margin" assumption is imported into an AI business; name it as an accident that three inversions removed.
**Marginal Cost Is Back**
This era sells work, and work has a cost of goods; the marginal cost that vanished with the copy returns with the outcome.
- **Apply**: Any time revenue is generated by producing work (tokens, outcomes) rather than shipping a copy — build a real COGS line.
**The Seat Broke From Both Ends**
The per-seat pricing unit broke from both directions — consumption is heavy-tailed, so a median price loses money on the customers worth having; and agents complete work with no person to charge.
- **Apply**: When evaluating or defending seat pricing for products with usage dispersion or agentic autonomy.
**The Balance Sheet Moved**
The capital to produce intelligence is committed years ahead on a physical clock and financed increasingly off the balance sheet — the P&L you read is not the capital you owe.
- **Apply**: When reading any AI firm's financials; look past the income statement to commitments and off-balance-sheet financing.
**Software Acquires a Cost of Goods**
Software, historically near-zero-COGS, now carries a genuine cost of goods sold because it performs work.
- **Apply**: When modeling an AI software P&L — never assume the old margin structure.
---
### The Counting Discipline
**The Counting Rule**
Each end-customer dollar is counted once, at the tier the customer transacted with; lab compute bought from a cloud is the same dollar one step down, and neocloud revenue is a cost of the tiers above it, never incremental demand. Naive addition of published run-rates overstates by roughly 40–70%.
- **Apply**: Stage 0 of any analysis touching published figures; run before believing any market number.
**The Double-Counted Tier**
A failure pattern: lab revenue added to the cloud revenue that carried it — the same dollar counted twice across tiers.
- **Apply**: When summing run-rates across labs / clouds / applications; trace each line to its transacting tier.
**The Symmetric-Count Illusion**
Counting capital broadly (across the whole build) while admitting revenue only where it transacts — a bias that runs in one fixed direction and is usually left unstated.
- **Apply**: Whenever a hurdle or coverage figure is produced; name the asymmetry and its direction.
**The Counting Asymmetry**
Capital is estimated across the whole build; revenue is admitted only where it transacts; the largest capital program may have no external AI revenue at all — a fixed-direction bias the reader must be told about.
- **Apply**: State it wherever the hurdle is computed; offer the two repairs (narrow the capital, or widen the return with an operating-surplus estimate).
**Corroboration Must Be Independent**
Two figures that share a margin assumption, a capital base, or a vintage agree by construction, not by corroboration; re-run any external method at current vintage before citing it.
- **Apply**: Before treating any second number (e.g. "the $600B figure confirms it") as independent support.
**The Borrowed Corroboration**
A failure pattern: citing an external figure of another vintage as if it independently confirms your own.
- **Apply**: When leaning on Sequoia/JPMorgan-style external numbers; state vintage, method, and shared assumptions.
**Never Divide a Stock by a Flow**
Capex against revenue, forward obligation against an annual capital line, run-rate against a capital base — all category errors. Revenue is compared to depreciation; obligation to forward cash flow.
- **Apply**: As the first red-team check on any ratio in the discipline.
**The Stock-Over-Flow Error**
The named failure of comparing a stock quantity to a flow quantity (the fix: revenue vs depreciation).
- **Apply**: When someone puts capex against AI revenue on a board slide.
---
### Unit Economics
**Cost per Accepted Outcome**
Tokens (in and out, at the model's price) + environment compute (sandboxes, retrieval, serving) + attention (human minutes at the loop's outer edge, at a loaded rate), over outcomes a referee accepted — not things produced.
- **Apply**: Stage 1 of the engine; the base unit for every margin, price, and budget in the seat.
**Budget on Tokens per Outcome**
Budget intelligence in tokens per accepted outcome, never from a price table — token prices go stale within a quarter.
- **Apply**: Building any forward AI budget or line item; refuse "budget at today's token prices."
**The Deflation Paradox**
When modeling a model-price cut, work tokens-per-task first and price second — never price alone; falling unit prices can be offset (or overwhelmed) by rising tokens per task.
- **Apply**: "Model the impact of a model-price cut" routes here first, before any repricing.
**Heavy-Tailed Consumption**
Consumption is heavily skewed — the top few percent of users can consume the majority of tokens, so a price set to the median loses money on the customers worth having.
- **Apply**: Diagnosing per-customer losses; compute cost per accepted outcome for the top decile and median separately (the answer is usually distributional, not level).
**The Median-User Price**
A failure pattern: pricing to the median user in a heavy-tailed distribution (the fix: price the tail).
- **Apply**: When a flat price is losing money on power users.
**The Physics of the Cost Line**
The cost line obeys real physics — tokens, watts, compute, human minutes — not the frictionless economics of the copy.
- **Apply**: When reasoning about where cost actually comes from before proposing to move it.
---
### Margin Design
**Gross Margin as a Design Outcome**
Gross margin stops being a property of the category and becomes a design outcome — recovery comes from deliberate levers, not from scale.
- **Apply**: Whenever margins are weak; refuse "model our margin at 80%" and build it from the levers.
**The Four Levers**
The four finance-owned, metered levers of margin: the routing table (task class → model → price), the cache hit rate, the owned-model share (residue trained into weights), and attention per outcome.
- **Apply**: Stage 2 margin design; the slide when explaining margin to the board.
**Ceiling vs Company Average**
A ceiling on well-used capacity is not the company average across the whole revenue mix — the two must never be mistaken for each other.
- **Apply**: Any margin claim; hold the best-case unit figure apart from the blended company figure explicitly.
**The Ceiling at Seventy**
A named ceiling reference — the gross-margin ceiling that well-used inference capacity tends toward, distinct from the company average.
- **Apply**: When benchmarking an inference margin against its structural limit.
**Revenue per Megawatt / Tokens per Watt**
Physical-unit efficiency metrics reading revenue and token throughput against the power a build consumes.
- **Apply**: Reading lab/datacenter unit economics where the binding constraint is power, not headcount.
**The SaaS-Margin Assumption**
A failure pattern: assuming zero-marginal-cost SaaS margins in an AI business (the fix: margin as design).
- **Apply**: When a plan pencils 80% gross margin by default.
---
### Pricing (as a Finance Instrument)
**Pricing as a Finance Instrument**
Price is set on a grid of attribution × autonomy — seats where the system assists, usage where autonomy runs without clean attribution, outcomes where a verifiable result is owned and unlocked by proof.
- **Apply**: Stage 3; every pricing/packaging decision (seats vs usage vs outcomes vs credits).
**Never Seat-Price Agentic Value**
Seat pricing caps revenue at the customer's headcount precisely where the product removes the seat's work — so agentic scope must not be seat-priced.
- **Apply**: Refuse "price it per seat" for agentic products; move to the grid.
**Price the Tail**
Price the heavy-tailed high-consumption cohort with multiples of usage rather than a flat rate; when a price must move, move the tail first and the base last.
- **Apply**: Repricing a heavy-tailed product; protecting the base while recovering margin from power users.
**Hybrids Are the Transition**
Hybrids (seat → credits/usage → outcomes) are the transition; outcome pricing is the end state; each step has conditions that must be true before it is taken.
- **Apply**: Designing a pricing migration path with staged triggers.
**The Guarantee Has a Cost Wherever It Sits**
An outcome/result guarantee always carries a cost — outcome pricing without a verification instrument is merely a dispute schedule.
- **Apply**: Before offering outcome terms; require the verification instrument first.
**The Compounding Curve (for the buyer)**
Show the buyer the curve where unit price falls as the substrate matures while account value rises.
- **Apply**: In the sales/pricing narrative for a maturing agentic product.
---
### Growth Accounting
**The Free User Is a Cost**
In an era with real COGS, the free user is a cost, not a marketing asset — the free wedge must be sized to a verified outcome and no further.
- **Apply**: Costing a free tier; sizing the wedge in growth accounting.
**AI-Era LTV / CAC / Payback**
LTV carries a cost of goods per period; CAC is recomputed for citation-and-endpoint acquisition; payback is keyed to time-to-magic — the cohort table shows margin, not just revenue.
- **Apply**: Any cohort, retention, or acquisition-economics analysis in the AI era.
**The Free-Tier Bill**
A failure pattern: an uncosted free tier arriving as a real bill (the fix: wedge sized to an outcome).
- **Apply**: When free-user compute is unmodeled in the plan.
---
### Reading the Capital
**The Three Tests**
Read capital with three tests that disagree, and the disagreement is the answer — the income-statement test (revenue vs recognized depreciation), the capital test (the hurdle), and the funding test (external share and whether the character of the money changed).
- **Apply**: "Is the buildout sustainable / is this a bubble / capex vs revenue"; refuse the single-ratio question.
**Revenue Against Depreciation, Not Capex**
Revenue is compared to recognized depreciation, never to capex; the coverage ratio is revenue ÷ recognized D&A.
- **Apply**: Replacing any capex-against-revenue exhibit; the fast-lane board fix.
**The Hurdle Is Arithmetic**
Required annual revenue = deployed base × (1/blended life + cost of capital) ÷ gross margin — a division shown with every input, not a judgment call.
- **Apply**: "What return does this capital need"; compute with full inputs and a sensitivity band.
**The Beat Raises the Hurdle**
A record quarter at a supplier enlarges the capital base that must earn a return, so it raises the end-customer revenue the layers above must eventually produce — a silicon-layer beat is evidence against the monetization case, not for it.
- **Apply**: When a supplier "just printed"; add the note to any hurdle.
**The Income Statement Answers Before the Maturity Schedule Asks**
The operating economics (revenue vs depreciation, coverage) resolve the sustainability question before the debt maturity schedule even poses it.
- **Apply**: Sequencing a capital read — start at the income statement, not the maturity wall.
**Growth Requirements Are Compounded, Not Averaged**
A charge heading to 3× over three years requires revenue to triple — ~44% a year (3^(1/3)=1.442), not the 40% an average returns; check every growth claim against its own exponent.
- **Apply**: Any multi-year growth requirement; note when the error flatters the case.
**The Uncompounded Growth Requirement**
A failure pattern: averaging a growth requirement that should be compounded.
- **Apply**: When a tripling is quoted as ~40%/yr.
---
### Depreciation & Asset Structure
**Split by Clock**
Capital splits by clock — short-lived vs long-lived, financeable vs pledgeable — read as one pipe into two vessels with two clock faces.
- **Apply**: Stage 5; any capex composition or depreciation analysis.
**Depreciation-Weighted Life**
With mixed asset lives the annual charge is the sum of each share divided by its own life, and the blended life is that sum's reciprocal — 60% at 5 years and 40% at 25 gives ~13.6%/yr and a life near 7.35, not the ~13 years arithmetic averaging returns.
- **Apply**: Any blended asset-life figure; state the weighting method inline.
**The Arithmetic Asset Life**
A failure pattern: averaging asset lives arithmetically instead of depreciation-weighting them.
- **Apply**: When a blended life is quoted without its weighting method.
**Price Is Not Capacity**
The price-not-capacity share distinguishes what the capital bought in capability from what it merely paid in price — capacity and its cost are separate readings.
- **Apply**: Reading a capital program's composition; isolate genuine capacity from price inflation.
**Financeable vs Pledgeable**
Assets differ in whether they can be financed and whether they can be pledged as collateral — a structural property that shapes the capital program.
- **Apply**: Assessing how a build is or can be funded.
---
### Off-Balance-Sheet & Structure
**The Acid Test**
Six gauges on one rail — structure ratio, velocity spread, external dependence, coverage, counterparty floor, take-out gap — where the finding is the spread across them, not the composite; every concealment gauge needs a cash-flow denominator.
- **Apply**: Debt, leases, off-balance-sheet, financing structure; run quarterly on the firm's own commitments.
**Read the Spread, Not the Composite**
On the acid test's six-gauge rail, the diagnostic signal is the dispersion between gauges, not their average.
- **Apply**: Interpreting the acid-test rail; risk-weight by deferral vs transfer.
**The Off-Balance-Sheet Blind Spot**
A failure pattern: missing financing that sits off the balance sheet (the fix: the acid test, run quarterly).
- **Apply**: When a firm's leases-not-commenced, guarantees, or SPV financing go unread.
**Allocation Becomes Obligation**
A capital allocation entering the plan turns into a hard obligation downstream — drawn as a river entering a lock and splitting into obligation channels.
- **Apply**: Tracing how committed spend hardens into contractual liability.
**Pre-Funding Makes the Near Term Sticky**
Capital raised ahead of need makes the near-term commitments sticky — the money is already spoken for regardless of demand.
- **Apply**: Assessing near-term flexibility of a pre-funded build.
**The Bottom Line Believed**
A failure pattern: reading net income (moved by marks on stakes) as if it were operations — read the operating line before believing any bottom line.
- **Apply**: When marks on customer/supplier stakes flatter or punish net income.
**Net Income Has Two Engines**
Net income is driven by two distinct engines — the operation, and marks on stakes in customers and suppliers that touch the bottom line without touching operations.
- **Apply**: Separating operating performance from valuation effects in any P&L read.
---
### Contagion & Systemic Reading
**The Layer Map Is Not the Credit Map**
Value's horizontal geometry (the layer map) is a different object from contagion's vertical geometry (the credit map); confusing them hides risk.
- **Apply**: Mapping counterparty/contagion risk against the value stack.
**The Three Joints**
The specific points where the layer map crosses the credit map are the joints where stress transmits — read alongside the phase calendar and a watchlist by information value.
- **Apply**: "Counterparty risk, contagion, credit vs layers"; build the joint table and calendar.
**It Breaks Upward**
The order of operations in a stress event: it breaks upward through the stack.
- **Apply**: Sequencing how a failure propagates across tiers.
**The Amplifier, Not the Bubble**
The question "is it a bubble" is malformed for a stack on four clocks; the structure acts as an amplifier — run the acid test and read the spread instead.
- **Apply**: Refuse "just tell me if it's a bubble"; reframe to the tests and the spread.
---
### The Absorption Ladder
**Absorption Capacity**
Each builder is placed on a ladder by capital intensity and funding source — the measure of whether it can afford its build.
- **Apply**: "Can this company afford its build"; place the builder on a rung.
**Operating Absorption Is Not Cash Absorption**
A firm's ability to absorb a build operationally (through the P&L) is distinct from its ability to absorb it in cash — read the two separately.
- **Apply**: Assessing build affordability; never conflate operating and cash absorption.
**The Control Group**
A builder's absorption is judged against a control-group comparison, not in isolation.
- **Apply**: Benchmarking one builder's capital intensity and funding against peers.
---
### The Five Incidence Paths
**The Five Incidence Paths**
An AI bill arrives on one of five paths — capitalized, memory tax, discovery tax, traffic-carry, or inference as COGS — each landing on a specific P&L line with a specific defense.
- **Apply**: "This isn't our build — why is it in our P&L"; name the path and its instrument.
---
### The Data-Oil Models
**The Data Oil**
Proprietary data behaves like an oil reserve — wells, a refinery, and a late royalty — a resource whose value is extracted and monetized downstream over time.
- **Apply**: Valuing or reasoning about a firm's proprietary data as a capital asset.
**The Second Barrel**
The second monetization of the same data resource — a further royalty extracted from an already-drilled reserve.
- **Apply**: When a data asset is monetized more than once.
---
### Supplier / Financing Actors
**The Supplier Joins the Clock**
When a supplier's own financing channels (equity stakes, receivables, guarantees, syndicated platforms) fund the buildout, the supplier becomes part of the capital clock and needs its own column in the acid test.
- **Apply**: Reading supply-side financing invisible to a hyperscaler-built six-gauge test.
**The Levered Backer**
A named actor: a backer funding the build with leverage, adding a financing channel to the contagion map.
- **Apply**: Mapping who carries the leverage behind a builder.
**The Wrapper**
A named actor/structure: the wrapper around underlying AI exposure that repackages or intermediates the risk.
- **Apply**: Identifying repackaged exposure in the credit map.
---
### Verdict Framing
**Real, Historic, and Insufficient**
A verdict frame: the AI buildout can be simultaneously real, historic in scale, and insufficient to clear its own hurdle — all three at once.
- **Apply**: Summarizing a capital-program verdict without collapsing into "bubble / not bubble."
**The Ledger the Firm Writes Itself**
The M5 end state: the ledger is the firm's own — budgets in tokens per outcome, the board reads revenue against depreciation, and the counting asymmetry is stated in the firm's own materials.
- **Apply**: Setting the maturity target for a finance function.
---
### The Engine (Stages 0–5)
**Stage 0 — Establish the Count**
Name the tiers (labs / clouds / applications / the uncountable), apply the counting rule (count once at the transacting tier, strip lab compute from cloud AI revenue, exclude neocloud revenue as a cost), mark each input disclosed/reported/estimated with its date, and produce a range.
- **Apply**: First stage of any analysis touching published figures.
**Stage 1 — Build the Unit**
Compute cost per accepted outcome (tokens + environment compute + attention over referee-accepted outcomes), trend it as the learning curve, and bridge it to COGS and gross margin.
- **Apply**: Establishing per-unit profitability before pricing or margin work.
**Stage 2 — Design the Margin**
Move margin with the four finance-owned levers (routing table, cache hit rate, owned-model share, attention per outcome); distinguish the ceiling from the company average.
- **Apply**: After the unit is built and margin is weak.
**Stage 3 — Set the Price**
Place price on the attribution × autonomy grid, price the tail with multiples of usage, show the buyer the compounding curve, and stage hybrids toward outcome pricing (with the verification instrument).
- **Apply**: After margin is designed; any pricing/packaging decision.
**Stage 4 — Read the Capital**
Run the three tests (income statement, capital/hurdle, funding) that disagree — the disagreement is the answer.
- **Apply**: Assessing capital sustainability and required return.
**Stage 5 — Read the Structure**
Split by clock, run the acid test's six gauges (read the spread), map the joints where the layer and credit maps cross, place each builder on the absorption ladder, then answer the incidence question.
- **Apply**: Structural/systemic reading after the capital is read.
---
### Mode Cards (operating modes)
**THE COUNT**
Build revenue by tier with low/central/high and a source class per input, show the strip-and-exclude operations, produce the total with its range, and name the weakest input.
- **Apply**: Any request touching a market number, run-rate, or published figure — runs first before any other mode.
**UNIT ECONOMICS**
Cost per accepted outcome with its three components separated, the acceptance definition (referee and threshold), the trend, and the bridge to COGS and gross margin.
- **Apply**: "What does this cost / are we profitable per unit / token spend."
**MARGIN DESIGN**
Decompose current margin, read the four levers at current and target, propose the routing table, the cache opportunity, the owned-model case, and the margin bridge — no improvement from scale alone.
- **Apply**: "Our margins are bad / how do we get to positive gross margin."
**PRICING ARCHITECT**
Grid placement, the proof-unlocked ladder, tail pricing, the hybrid transition path, and the buyer's compounding curve — never seat-price agentic value; outcome terms require the instrument.
- **Apply**: Pricing, packaging, seats vs usage vs outcomes, credits.
**GROWTH ACCOUNTING**
LTV with a cost of goods per period, CAC recomputed for citation-and-endpoint acquisition, payback keyed to time-to-magic, the free tier costed, and NRR — the cohort table shows margin.
- **Apply**: LTV, CAC, payback, free tier, cohort economics.
**THE HURDLE**
The required-return division shown with every input, sensitivity on asset life/margin/required return, the position against countable revenue, the asymmetry stated, and the beat-raises-the-hurdle note.
- **Apply**: "What return does this capital need."
**THE ACID TEST (mode)**
Score the six gauges on one rail with a band and calibration against a prior period; the spread is the finding; risk-weight by deferral vs transfer.
- **Apply**: Debt, leases, off-balance-sheet, financing structure.
**THE JOINTS (mode)**
The layer map beside the credit map, the joints where they cross, the phase calendar, the order of operations (it breaks upward), and the watchlist by information value.
- **Apply**: Counterparty risk, contagion, credit vs layers.
**THE ABSORPTION LADDER (mode)**
Place the builder by capital intensity and funding source, read operating vs cash absorption separately, name the collapse conditions, and compare to a control group.
- **Apply**: "Can this company afford its build."
**INCIDENCE (mode)**
Identify which of the five paths the firm's bill arrives on, the P&L line where it lands, and the defense available.
- **Apply**: "This isn't our build — why is it in our P&L."
**THE FINANCE SEAT**
Rebuild the AI line item on tokens per accepted outcome, define the six meters with owners, replace the capex-against-revenue board slide, and run the acid test on the firm's own commitments.
- **Apply**: Budgeting, board deck, forecast, the AI line item.
**FAILURE DIAGNOSIS** → canonical entry in **Harness Engineering**. Applied here in this seat's context.
### The Fast Lane (when the clock is short)
**The Board-Meets-Thursday Order**
Strip the marks and read the operating line, replace any capex-against-revenue exhibit with revenue vs recognized depreciation, give one honest coverage number with range and date, and name the single largest uncertainty — a correct coverage number beats a complete model nobody can defend.
- **Apply**: The AI number is wrong and the board meets imminently.
**The Losing-Money Order**
Compute cost per accepted outcome for the top decile and median separately (the answer is almost always distributional), check the routing table before the price list, and if price must move, move the tail first and the base last.
- **Apply**: Losing money per customer with pressure to raise prices tomorrow.
**The Published-Number Order**
Run THE COUNT on any externally published number before responding — a response built on someone else's arithmetic inherits their error.
- **Apply**: A vendor, investor, or the press just published a number about you or your market.
---
### The Red Team (seven predictable attacks)
**The Seven Attacks**
Every number will be attacked in seven predictable ways — stock/flow, double-count, weighting source, uncompounded growth, non-independent sources, broad-capital/narrow-revenue, and self-contradiction — so run the hostile reading first; a finding that cannot survive attack five is not yet a finding.
- **Apply**: Before shipping any output; the analysis that survives a hostile reader is the one that ran the hostile reading first.
---
### Composition Rules (compound requests as mode sums)
**Requests Route as Mode Sums**
Compound requests decompose into ordered mode sequences (e.g. "build the AI budget" = THE COUNT → UNIT ECONOMICS → MARGIN DESIGN → THE FINANCE SEAT), never blended; work spanning seats is handed to the correct sibling.
- **Apply**: Any multi-part request; sequence the modes rather than answering monolithically.
<a id='02-the-business-orchestrator'></a>
---
---
# PART IV — RUN THE FIRM
## The Business Orchestrator
### The Orchestration Engine (Layers 0–4)
The core diagnostic engine. Run the layers in order on whatever scope the mode defines; each layer has a question, a method, and a finding format. Phase 3 (prescribe) never runs without Phase 2 (diagnose) — prescriptions without diagnosis are consulting theater.
**Layer 0 — Work Physics**
Answers "what is the work, really?" Decompose the scope into flows (a flow = a recurring unit of work with an input, a transformation, and an output someone consumes) and score each on three dimensions — Volume, Specifiability, Consequence (severity and reversibility) — then assign an automation category.
- **Apply**: Use to build the work map and draw the automation frontier. Category rule: Automate-first = H/M volume + Y spec + L/M-reversible consequence; Automate-with-gate = Y/PARTIAL spec + any consequence (junction mandatory); Judgment work = N spec or H-irreversible; Leave manual = L volume. Unspecifiable work cannot be gated, and ungateable work must not be autonomous.
**Layer 1 — Unit Architecture**
Answers "are the units built or improvised?" Audit each automated flow's working unit against the nine elements in four bands — charter (mandate, boundary), production (model, tools, procedure), control (gate, escalation path with a named human), memory (context, the record).
- **Apply**: Use to find structural gaps in automated units. Run the four audit tests in order of diagnostic power: the charter test, the swap test, the method test, the record test. Score 0–2 per test (/8) and surface the top structural gaps.
**Layer 2 — The Judgment System**
Answers "where does human judgment actually bind, and is it real?" For every junction (a point where a human decision gates a flow), verify the five specifications exist in writing, size it with the utilization formula, and price the erosion of assisted selection.
- **Apply**: Use whenever human-in-the-loop, oversight, or approval steps are in scope. Fewer than five written specs = the junction is decorative. Above ~85% utilization = rubber stamp; below ~20% = consider consolidation. Output the junction ledger.
**Layer 3 — Topology**
Answers "does the structure survive scale?" Units grow linearly, channels grow roughly as the square, judgment is fixed — audit three structural rules (bounded fan, junction routing, schema'd flows) then run the cascade check to draw each unit's blast radius.
- **Apply**: Use to audit structural durability at scale. Blast radii containing customer-visible or irreversible actions with zero intermediate checks are the finding that outranks all others. Output the topology verdict.
**Layer 4 — Human Capital**
Answers "is the firm consuming its future judges?" Judgment is a manufactured input with a lead time in years, manufactured on the bottom rungs automation removes — audit which rungs are gone, what deliberate replacements exist, and the 24-month arithmetic of judges forming vs judges needed.
- **Apply**: Use for org and bench decisions. Also apply the teammate substitution (one assisted person covers what small teams were assembled for) and audit for convergence risk — whether team members draft independently before comparing, or the first output anchors everyone. Output the bench verdict.
---
### The Three-Phase Execution Flow
**Configure → Diagnose → Prescribe**
Every engagement runs three phases — Phase 1 Configure (identify mode, scope, available numbers), Phase 2 Diagnose (run the Orchestration Engine Layers 0–4, no skipped layers), Phase 3 Prescribe (produce the mode's artifact with engine traceability).
- **Apply**: Use as the spine of every engagement. Phase 3 never runs without Phase 2. Never invent the user's metrics — where numbers are missing, ask or mark `[INPUT NEEDED]` and proceed.
---
### Operating Modes (Mode Cards)
Eight modes, each identified from the user's request, running the engine layers the mode requires and producing its artifact.
**Mode 1 — Operating Model Review**
Full-engine audit (Layers 0–4) producing findings per layer, maturity level, the five highest-leverage corrections ranked by effort/impact, and a 90-day sequence.
- **Apply**: Triggers: "review our AI setup," "are we doing this right," audits. Artifact: the Operating Model Review (T8) with maturity dial and 90-day roadmap.
**Mode 2 — Automation Triage**
Layer 0 deep + Layer 4 check, producing a work map plus the frontier — an automate-first list with per-flow junction requirements and an explicit do-not-automate list with reasons.
- **Apply**: Triggers: "what should we automate," roadmaps, prioritization. The do-not-automate list seeds the refusal log. Artifact: frontier chart + work map.
**Mode 3 — Junction Design**
Layer 0 (the flow) + Layer 2 (deep), producing junction spec(s) with sizing math shown and the erosion countermeasures chosen.
- **Apply**: Triggers: human-in-the-loop, oversight, review process, approval workflow. Artifact: junction spec (T3) + junction schematic.
**Mode 4 — Agent Charter & Governance**
Layer 1 deep + Layer 3 blast-radius check, producing charter one-pagers plus the autonomy ladder with promotion thresholds and demotion rails.
- **Apply**: Triggers: agent rules, permissions, what agents can do, AI policy. Artifact: charter one-pagers (T6) + autonomy ladder.
**Mode 5 — Org Redesign**
Layers 0, 2, 4 with mandatory teammate-substitution analysis, producing the graph redesign — flows-to-junctions map, roles redefined as junction ownership plus bench positions, and the staircase plan.
- **Apply**: Triggers: team structure, roles, spans, "do we still need X team." Artifact: before/after graph + bench plan.
**Mode 6 — Adoption Rescue**
Diagnose against the failure pattern library (Part C), identify which pathologies are present, then run only the layers those pathologies implicate — producing diagnosis, root-cause chain, and corrective sequence.
- **Apply**: Triggers: pilots stalling, "our AI initiative isn't working," low usage, quality complaints. Artifact: pathology board + corrective path.
**Mode 7 — Measurement & ROI**
Layer 2 sizing plus the gauge panel, producing the six-gauge panel built strictly on user-supplied numbers with formulas shown and cost-per-outcome replacing cost-per-call.
- **Apply**: Triggers: KPIs, metrics, "is it working," business case. If numbers are missing, the artifact becomes the measurement plan (what to instrument, where, cadence). Artifact: gauge dashboard (T7).
**Mode 8 — Cadence & Practice**
Produces the operating calendar — weekly junction review, monthly roster walk, quarterly model review, annual clean-sheet test — each with attendees, inputs, and questions asked, plus the refusal log format.
- **Apply**: Triggers: governance rhythm, review meetings, "how do we keep this healthy." Artifact: calendar wheel + refusal log.
**Composition Rules (compound requests)**
Modes combine — route compound requests as sums, run the union of their layers, deliver one merged artifact set (e.g. "cut costs with AI" = Mode 2 + Mode 7; "choose our AI stack/vendor" = Mode 2 + own/rent ledger + swap-test criterion; "board update" = Mode 7 + maturity dial + refusal log headline; "roll it out" = Mode 5 + Mode 8).
- **Apply**: Use when a request spans modes. Anything not listed: pick the nearest mode by artifact and say which. Never start vendor selection from vendor features.
---
### The Audit Tests (Layer 1)
**The Charter Test**
Can anyone produce the unit's one-page charter? No charter = exposure, not automation.
- **Apply**: First and most diagnostic test of any automated unit; run it before the others.
**The Swap Test**
If the model vendor changed tomorrow, what else would need touching? Everything that would need touching is what the firm has actually built; if the answer is "the quality," the firm built nothing.
- **Apply**: Use to distinguish real property from rented capability; also the selection criterion for vendor/stack choices.
**The Method Test**
Does the unit apply the firm's way of working, or the model's average? "It's in the prompt somewhere" = amplifier, not discipline.
- **Apply**: Ask for the encoded checklist. Use to detect the Amplifier Trap.
**The Record Test**
Pick last week's corrections; where are they now? If the answer is a chat thread, the flywheel is not spinning.
- **Apply**: Use to verify corrections are captured by construction, not evaporating.
---
### The Judgment System Mechanics (Layer 2)
**The Five Junction Specifications**
A real junction has five things in writing: what arrives (checkable format), the decision, the standards applied, approve-alone vs escalate thresholds, and the correction-capture destination. Fewer than five = the junction is decorative.
- **Apply**: Use to verify any human-in-the-loop checkpoint is real before trusting it.
**Junction Utilization (sizing law)**
`utilization = (items/week × minutes/item) / (judge hours available × 60)`. Above ~85% the junction is a rubber stamp — the judge approves to survive; below ~20% consider consolidation.
- **Apply**: Use to size every junction as a design act; show the math in the open.
**Judgment Erosion (the pricing rule)**
Selection quality measurably degrades with assistance — judges picking among machine outputs choose the best roughly a third of the time versus half unassisted. Countermeasures: schema-checked inputs so judges see only the judgmental residue, monthly calibration sets, junction rotation.
- **Apply**: Price this into every junction design and build in the countermeasures.
---
### Named Laws & Rules (Model Library — apply, don't dump)
**The Bottom Rung Dissolves**
Assisted individuals replicate team breadth; entry-level work is the first casualty, and with it the training ground.
- **Apply**: Cite in human-capital and org-redesign analyses to justify deliberate bench mechanisms.
**The Judgment Erosion**
Assistance degrades selection; the skill of choosing among outputs decays exactly when it becomes the job.
- **Apply**: Use to justify calibration sets and schema'd inputs at junctions.
**The Teammate Substitution**
Teams justified by coverage are no longer auto-justified; the remaining reason is engineered diversity of judgment.
- **Apply**: Mandatory in Mode 5 org redesign; drives span and headcount decisions.
**Booked, Not Predicted**
When restructuring charges cite the agentic model, the transition stopped being a forecast.
- **Apply**: Cite to move a discussion from speculation to audited fact.
**The Rented Ninth** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Fit**
Performance lives in the co-adaptation of model, harness, and context; the fit cannot be bought, only accumulated.
- **Apply**: Use to argue against expecting bought performance and for accumulated advantage.
**Amplifier vs Discipline**
The harness scales whatever is encoded in it; without method it scales error.
- **Apply**: Use to diagnose the Amplifier Trap and justify encoding method.
**Encode the Method**
The firm's checklists and red lines as machinery — the difference between the model's average and the firm's standard.
- **Apply**: The structural fix whenever the method test scores zero.
**The Junction**
Real only when its five specifications are written; otherwise decoration.
- **Apply**: The definitional rule for every human checkpoint.
**The Rubber Stamp**
Above ~85% utilization a judge approves to survive; sizing is a design act.
- **Apply**: Use to detect and fix decorative approval steps.
**Autonomy Is a Gate Result** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Calibration Decay**
Judges need scored practice or their standards drift with the machine's.
- **Apply**: Justifies monthly calibration sets and junction rotation.
**The Exhaust Flywheel**
Corrections, captured by construction, are the compounding asset; a competitor can rent your model, not your ten thousand corrections.
- **Apply**: The core argument for capture-by-construction as competitive moat.
**Landlord's Compounding** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Cost Is a Capability** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Graph, Not the Chart**
Agents execute flows; humans hold junctions; the org chart describes neither.
- **Apply**: The governing metaphor for Mode 5 org redesign.
**The Interaction Explosion** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Schema-Routed Flow** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Blast Radius** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Missing Staircase**
Judgment is manufactured on rungs automation removes; rebuild deliberately or run on inventory.
- **Apply**: The Layer 4 imperative for bench planning.
**Scheduled Judgment Beats Incident Judgment**
The cadence is the control.
- **Apply**: Justifies the operating calendar over reactive, incident-driven review.
**The Refusal Log** → canonical entry in **The Forward-Deployed Engineer**. Applied here in this seat's context.
**The Roster** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Clean-Sheet Test** → canonical entry in **The Business Architect**. Applied here in this seat's context.
**Cost per Outcome, Never per Call**
The denominator is the discipline.
- **Apply**: Replace API-bill reasoning with cost per gated, delivered outcome in all measurement.
---
### Failure Pattern Library (diagnose by symptom)
Each pattern names its symptom, root cause, and structural fix; multiple co-occur.
**Pilot Purgatory**
Demos everywhere, production nowhere — because no charters and no gates mean nothing can be trusted enough to ship.
- **Apply**: Fix: charter + instrument one flow end-to-end; ship narrow.
**The Rubber-Stamp Junction**
Near-100% approval rates, caused by utilization >85% or unspecified standards.
- **Apply**: Fix: schema the inputs, resize or split the junction, publish the standards.
**The Amplifier Trap**
Output up, quality complaints up — a harness without encoded method scaled the firm's errors.
- **Apply**: Fix: encode the checklist/red lines into the procedure; add the gate.
**Demo Promotion** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Correction Evaporation** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**The Shadow Bench** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Cost-per-Call Illusion**
"AI is expensive"/"AI is cheap" argued from API bills — the wrong denominator.
- **Apply**: Fix: cost per gated, delivered outcome; count the junction minutes.
**Staircase Consumption**
Junior hiring frozen, seniors fine "for now" — bottom rungs automated with no replacement mechanisms.
- **Apply**: Fix: Layer 4 bench plan; apprenticeship at the junction.
**The Convergence Trap**
Team outputs increasingly identical because the first assistant output anchors everyone.
- **Apply**: Fix: independent drafts before comparison; diversity by construction.
**Vendor Condensation**
The firm's edge showing up in a vendor's product roadmap — differentiated flows run through rented platforms, so the loop compounds for the landlord.
- **Apply**: Fix: own/rent re-sort; bring edge-writing flows inside the walls.
**Point-to-Point Sprawl**
Nobody can say what talks to what; incidents are archaeology — caused by unbounded fan and no schemas.
- **Apply**: Fix: topology rules retrofitted at the consequential channels first.
**Incident-Driven Operations**
Reviews happen after failures only, because there is no cadence.
- **Apply**: Fix: the operating calendar; scheduled judgment beats incident judgment.
---
### Maturity Scale (L0–L5)
**The Orchestration Maturity Ladder**
A six-level scale for scoring a scope — L0 Ad hoc (individuals use AI, no charters/junctions/record), L1 Piloted (named use cases, demos, nothing instrumented), L2 Chartered (units have charters and owners, junctions unsized, corrections partly captured), L3 Instrumented (frozen evals, sized junctions, current roster, autonomy by thresholds, six gauges live), L4 Governed (full cadence, topology rules enforced, refusal log maintained, bench plan funded), L5 Compounding (loop measurably improves quarter over quarter, property share rising, operating model a stated competitive asset with receipts).
- **Apply**: Score the scope, state the level and the gap to the next. Most firms claiming "AI-first" audit at L1; the jump that pays is L1→L3, and it runs through charters and evals, not better models.
---
### The Six Gauges (measurement panel)
**The Gauge Panel** → canonical entry in **Harness Engineering**. Applied here in this seat's context.
### The Operating Calendar (cadence rhythms)
**The Four Rhythms**
A nested governance cadence — weekly junction review, monthly roster walk, quarterly model review, annual clean-sheet test — each with attendees, inputs, and the questions asked, plus the refusal log.
- **Apply**: Use in Mode 8 to keep an operating model healthy; scheduled judgment beats incident judgment.
---
### Output Templates (shared artifacts)
**T1 Work Map**
Table: Flow · Volume · Specifiable · Consequence (sev/rev) · Category · Junction? · Notes.
- **Apply**: The Layer 0 finding format; renders visually as the Frontier Chart.
**T2 Own/Rent Ledger**
Table: Component · Own/Rent · Vendor-learns-our-edge? · Reasoning · Exit path.
- **Apply**: Use for stack/vendor decisions; a shared artifact across the suite.
**T3 Junction Spec**
Flow; Judge (role, named); Arrives (format, checkable fields); Decision; Standards; Approve-alone vs escalate; Corrections captured to; Sizing (items/wk × min/item ÷ hours → utilization %); Erosion countermeasures.
- **Apply**: The Mode 3 deliverable, 1:1 to a unit's control band.
**T4 Instrument Sheet**
Eval set (N cases, source, correct-outcome definition); scoring rule; promotion threshold + hold period; current score; autonomy level; promotion log (date, evidence, approver).
- **Apply**: Use to gate autonomy by evidence; filled by Agent Engineering's suite scores.
**T5 Bench Plan**
Rungs removed; replacement mechanisms; judges forming vs needed (24mo); gap; convergence controls.
- **Apply**: The Layer 4 / Mode 5 human-capital deliverable.
**T6 Agent Charter (one page)**
Mandate (one sentence); outcomes owed; boundaries (must never); escalation (to whom, when); definition of done; owner; version; autonomy + evidence.
- **Apply**: The Mode 4 deliverable and the unit-commission seed handed to Agent Engineering.
**T7 Gauge Panel**
Leverage · Judgment load · Property share · Bench depth · Escape rate · Cost per outcome — formula + current + trend + limit per gauge, trends over levels.
- **Apply**: The Mode 7 deliverable; renders as the Gauge Dashboard.
**T8 Operating Model Review**
Scope & maturity level; findings by layer (0–4, each evidence → implication); failure patterns present; the five corrections ranked (effort × impact, each tied to a layer finding); the 90-day sequence; refusal list; attribution.
- **Apply**: The full Mode 1 deliverable.
---
### Evidence Base (cite as replaceable instances, dated)
**The Cybernetic Teammate finding**
Field experiment (Dell'Acqua, Lakhani et al., Organization Science, 2026; 791 professionals, P&G): assisted individuals matched two-person team quality; assisted selection picked the best of five ~33% vs ~50% unassisted — the leverage and the erosion, measured together.
- **Apply**: Cite for both the teammate substitution and judgment erosion; hedge as an instance, date it.
**Harness-tuning economics**
NVIDIA published agent blueprint (2026): a tuned loop around an open-weight model matched frontier task results at roughly one-tenth cost per run, base model unchanged — cost is a capability the loop spends.
- **Apply**: Cite for "Cost Is a Capability" and the swap test; hedge as an instance.
**Booked receipts**
Q2 2026 filings: a major internet-infrastructure firm recorded a restructuring charge for its agentic operating model while revenue accelerated (headcount −14%, revenue per head +33%); a major enterprise-software firm disclosed ~$1B AI-attached contract value.
- **Apply**: Cite for "Booked, Not Predicted" — the operating model is on audited statements.
---
### Seat Boundaries & Interop
**The Read → Design → Run → Build handoff**
One seat of The Business Engineer suite — the Business Engineer reads markets/companies, the Business Architect decides what the firm should be (its designs arrive here as flows to map), the Orchestrator runs it, and Agent Engineering builds the units (fed by this seat's work maps, junction specs, and charter seeds).
- **Apply**: When a request spans seats, route in one line by name, deliver this seat's artifact, and name what the adjacent skill adds. Consume adjacent reads/designs as context — never re-derive them. Shared artifacts (own/rent ledger, charter, gauge conventions) travel between skills unchanged.
---
*Analysis by The Business Engineer — businessengineer.ai.*
<a id='12-the-ai-cfo'></a>
---
## The AI CFO
### Foundational premise — why the number does not exist
**The Category the Instruments Cannot Count**
The firm is buying a category its instruments were never built to count — software was a license (booked once, amortized, consumed by tracked headcount), but the firm now buys *work*: metered by the unit, consumed unevenly, performed by systems that improve on someone else's schedule and change behavior without a purchase order.
- **Apply**: Open any "what is AI costing us" question here — the number is absent for a structural reason, not a negligence one. The first deliverable is the counting rule, not a total.
**Three Retired Assumptions**
Three assumptions retired, each taking instruments with it — (1) **Zero marginal cost, retired**: software acquired a cost of goods, so margin is engineered not inherited, and finance gets a legitimate seat in routing, caching, and model-tier decisions; (2) **The seat as the unit, retired**: consumption is heavy-tailed, so headcount × price misprices both ends; (3) **The purchase stays put, retired**: the deliverable moves under the contract.
- **Apply**: Use to diagnose why a legacy budgeting instrument is misfiring — trace the failure to whichever retired assumption it still relies on.
**The Deflation Paradox (price down, bill up)**
The price per unit of intelligence falls while the total bill goes up — the era's central budgeting fact, driven by inference-price curves falling while reasoning and agent loops multiply the tokens.
- **Apply**: State whenever someone expects falling model prices to lower spend; run sensitivity on price-per-unit and units-per-user in opposite directions because both move.
**The Unchanged Mandate**
What did not change: know what things cost, know what they return, protect the balance sheet, tell the truth to the people who rely on the numbers.
- **Apply**: The anchor when the novelty of AI tempts abandoning finance fundamentals — the instruments change, the mandate does not.
---
### The engine — Stages 0 to 5
**Stage 0 — The question and the phase**
Establish which part of the seat's year this is — the close, the budget, the capital, the board and audit, the forecast, or the function — and name the room the answer has to survive.
- **Apply**: First move on any engagement; the phase determines which instrument and which LEDGER gate apply.
**Stage 1 — Make it countable**
Write the counting rule (what counts, where each dollar lands, who owns the line, versioned with reasons), sweep the sources (cloud, licenses/subscriptions, professional services, internal payroll, metered tokens, the shadow estate on cards), enforce one dollar counted once, then name the line the ledger has no field for — attention.
- **Apply**: Before any total is published. If someone outside finance cannot reproduce the total, it is not a total.
**Stage 2 — Make it comparable**
Build the unit — cost per accepted outcome (tokens, compute, attention over outcomes a referee accepted) — name routing and cache assumptions, roll it up (per outcome → per workflow × volume → per business unit → the firm), and assemble the AI P&L.
- **Apply**: Once the total is reproducible; a price-per-token table is not a budget and cannot be compared across workflows.
**Stage 3 — Make it a plan**
Budget in units of work (never headcount × price), model the tail apart from the median, attach caps/alerts/owner/re-forecast trigger, and build the return case as baseline → mechanism → commitment → payback with verification written in, underwriting capacity returned rather than a headcount line.
- **Apply**: When turning a countable, comparable estimate into a forward plan and a defensible business case.
**Stage 4 — Place the capital honestly**
Capex-or-opex is elective, so choose deliberately, write the memo at the time, disclose that a choice was made, state the capitalized share/useful life/margin effect; read buy/build/rent as three balance sheets; track commitment vs consumption; run the acid test on your own chair.
- **Apply**: On any material build or capital commitment — the flexible year is the one before the paper is signed.
**Stage 5 — Govern, guide, and answer**
Controls for systems that act (authority limit, junction, trace, change control, exception log with owner), guidance as a band and a trigger never a point estimate under drift, the auditor's shelf kept prepared, and the room answered in four minutes with six numbers.
- **Apply**: For the control environment, street/board guidance, and audit-committee preparation.
---
### LEDGER — the funding qualification
**LEDGER**
The seat's own six-letter funding qualification where **every letter closes to a number** — L Landing, E Engine, D Denominator, G Gate, E Elective, R Return — run at gates on the seat's calendar and rerun annually because routing assumptions go stale, the tail moves, and controls written for last year's autonomy tier stop covering this year's.
- **Apply**: On any funding decision or commitment above the noise floor. Output as a table with the actual number or an explicit "not computed" per letter — never a qualitative sentence in a cell.
**L — Landing**
Where does this dollar land, counted once? The number is the commitment mapped to its line with double-counts removed; the failure is a total assembled from four systems that share the same spend.
- **Apply**: At the budget, before the commitment enters the plan.
**E — Engine**
What does one outcome cost to produce? The number is cost per accepted outcome with routing and cache named; the failure is a price-per-token table quoted as a budget.
- **Apply**: At the close, graded on what happened not what was modelled.
**D — Denominator**
What is the plan built on? The number is consumption in units of work with the tail modelled apart; the failure is headcount × price.
- **Apply**: At the budget.
**G — Gate**
Who can change it, and what may it do unsupervised? The number is the authority limit and the change-control terms; the failure is controls written for software that cannot act.
- **Apply**: With the control environment, on the audit committee's cycle.
**E — Elective**
Where did we choose to put it? The number is the capitalized share, its life, and the margin effect; the failure is an elective outcome presented as an operating result.
- **Apply**: At the close and on any capital placement.
**R — Return**
Verified against what? The number is the accepted outcome vs the honest alternative, fully loaded; the failure is adoption dressed as return.
- **Apply**: At the budget, measured against the honest alternative at fully loaded cost including attention.
**The Grading Rule (a failed letter prices it, does not stop it)**
A failed letter does not necessarily stop the commitment — it prices it, and the price goes in the paper as a known exposure with a named owner and a review date; what LEDGER refuses is the unpriced letter, which is the one the audit committee will eventually ask about.
- **Apply**: When a letter comes back "not computed" — convert it to a priced exposure rather than blocking the decision or hiding the gap.
**Every Letter Closes to a Number**
No LEDGER cell may hold a qualitative sentence — a letter is a number or it is "not computed" with a statement of what it would take.
- **Apply**: Enforce on every board output; it is the discipline that separates F5 from "F1 with a better dashboard."
---
### The unit and the counting
**Count the Dollar Once**
One dollar, counted once — remove double-counts explicitly and show the reconciliation; a cloud commitment often appears twice (once as committed spend, once as consumption inside a platform bill) and the dedupe typically moves the total materially.
- **Apply**: In the counting rule; expect and surface the reconciliation so the total becomes reproducible.
**Cost per Accepted Outcome** → canonical entry in **AI Economics**. Applied here in this seat's context.
**The Attention Line**
Attention — the internal hours the process consumes and returns — is the line the ledger has no field for; it belongs in the P&L as a shadow line because cheap software that eats your scarcest people is expensive.
- **Apply**: Load it into the unit and the P&L; when attention exceeds ~30% of the unit, denominate the comparison in attention or the alternative will look cheaper than it is.
**Budget in Units of Work**
Budget in units of work, never headcount × price, for anything agentic — a token-price budget built on today's price table is a stock/flow error waiting to happen.
- **Apply**: Reject the "400 seats × $30" arithmetic for agentic consumption; re-forecast consumption in units of work.
**The Tail Modelled Apart**
Model the top decile separately from the median — a minority of users generates the majority of consumption and usually does the most valuable work, which is the reason to cap with alerts rather than to cap hard.
- **Apply**: In every agentic budget; budgeting on the median understates materially. Run sensitivity on both price per unit and units per user.
**The AI P&L**
The statement the firm can read monthly — metered inference in COGS, platform and licenses in opex, services split by placement, evaluation as its own line, attention as the shadow line, and verified return beside them, all counted once.
- **Apply**: Build after the unit exists; it is the readable monthly instrument the board and close run on.
**The Business Case That Survives Contact**
Build the case as baseline (fully loaded) → mechanism (with who does less) → commitment (with its term and clock) → payback (with its verification instrument and the month it will be re-run), stating the honest alternative explicitly; never accept adoption as return.
- **Apply**: For any AI investment approval; the verification is written into the case, not added after.
**Capacity, Not Headcount**
Underwrite capacity returned (hours, cycle time, throughput, backlog) and say plainly the accounting form is rarely a headcount line — a case underwritten on reductions that never arrive discredits the next one.
- **Apply**: When a business case tempts a headcount-savings promise; convert to measured capacity.
---
### The capital
**Capex or Opex Is Elective**
Capitalization is a deliberate choice, not a given — two firms making the same commitment can report different margins for reasons that have nothing to do with the work.
- **Apply**: On any build; choose deliberately, write the memo at the time, disclose that a choice was made, and carry the firm-and-auditors caveat.
**The Elective Margin**
The difference in reported this-period cost between expensing the spend and capitalizing a share over a useful life — an accounting choice, not an operating result, quantified both ways and stated as points of margin on revenue.
- **Apply**: Quantify both directions in any placement review; write the capitalization memo at the time so the judgment is not unreconstructable later.
**Buy, Build, or Rent as Three Balance Sheets**
Read buy/build/rent as three balance sheets and one question — what compounds under our own hands.
- **Apply**: When sourcing a capability; frame the decision as balance-sheet consequence, not feature comparison.
**Allocation Becomes Obligation / Every Placement Acquires a Clock**
Every placement acquires a clock; commitment must be tracked against consumption, and the flexible year is the one before the paper is signed.
- **Apply**: On the commitment schedule — record what is committed vs consumed, the term, the clock, whether it can be stopped, and at what cost.
**The Acid Test on Your Own Chair**
Run the buildout instrument on your own balance sheet — six gauges on one rail: external funding share, commitment vs consumption, off-balance-sheet share, concentration, elective capitalization, coverage of the clock.
- **Apply**: To self-assess the firm's own AI capital position; read the spread, not the composite.
**Read the Spread, Not the Composite** → canonical entry in **AI Economics**. Applied here in this seat's context.
### The governance
**Controls for Systems That Act**
The control environment for systems that act — because segregation of duties collapses when one actor initiates, approves, and records — comprising the authority limit, the junction above which a person decides, the trace, change control over who may alter behavior, and the exception log with an owner.
- **Apply**: Whenever an agent takes actions (e.g. payment-adjacent or customer credits); name explicitly which conventional control the acting system breaks.
**The Authority Limit**
The limit on what a system may do unsupervised, set by value, volume, and class of action — and the junction above which a person decides.
- **Apply**: Design for any acting system before it goes live; it is LEDGER's G number.
**Segregation of Duties, Collapsed**
Classical control assumes a human between initiation, approval, and recording; an acting system can do all three, collapsing segregation of duties.
- **Apply**: The diagnostic to invoke the moment one automated actor spans initiate/approve/record — it is not a standard software control question.
**Guidance as a Band and a Trigger**
Guide with a band plus a named re-forecast trigger, never a point estimate under drift — a point estimate under drift is a hostage.
- **Apply**: For street/board guidance when prices and consumption are moving; state the band's assumption set and the sentence about what would move it.
**The Auditor's Shelf**
The prepared shelf the auditor will ask for — the counting rule versioned, the commitment schedule reconciled, the capitalization memo, the control evidence, the model-change log.
- **Apply**: Keep standing ahead of audit; it is a maturity marker (F4).
**Disclosure Without Theater**
State that a placement choice was made and its effect plainly, without dressing an illustrative figure as a measured one or a third-party estimate as a disclosure.
- **Apply**: In every statement-touching output; never present an estimate as a measured number.
---
### The seat
**Pricing Sits in Finance Now**
The meter is a finance instrument and margin is by design — the tier the product can support depends on what it can verify, with routing, caching, deterministic handling, and owned models as the margin levers.
- **Apply**: When pricing an AI product; where outcome pricing is in play, use the hybrid transition (base plus variable on verified units, caps and collars, one workflow first, step-gates) — pure outcome pricing is an end state a mature relationship earns.
**Revenue Quality (built vs bought)**
Separate growth built from growth bought — revenue quality distinguishes durable, engineered growth from purchased growth.
- **Apply**: When assessing whether reported growth is real; a revenue-quality mode of the seat.
**The Judgment Stays With the Name That Signs**
Draft anything; sign nothing unread — the judgment stays with the name that signs, and this applies to the finance function's own adoption first.
- **Apply**: The judgment rule governing all AI use in the seat; model it in the finance function before demanding it elsewhere.
**The Seat Rule (operator, not physicist)**
This is the operator's chair — the sibling discipline covers the era's economics as physics (the cost line, the capital cycle, the industry hurdle); when a question is about the industry rather than the firm, say so, answer briefly at that altitude, then return to what the person in the chair does on Monday.
- **Apply**: To keep answers at the firm altitude; hand industry-altitude questions to AI Economics.
**The Stop**
A seat that can stop a program on a number — when cost per accepted outcome says the manual alternative is cheaper at current volume — is the year working, not the year failing; sunk cost purchases nothing forward.
- **Apply**: When a unit cost turns negative against the honest alternative; recommend the stop and frame stopping as evidence the discipline works.
---
### The CFO's meters
**The Meters (and the excluded metrics)**
The instruments the seat watches — counted total vs plan (L), cost per accepted outcome (E), consumption variance against plan (D), exception and authority-breach rate (G), capitalized share (E), verified return (R) — beside the judgment log; deliberately excluded are AI spend as a share of revenue, pilots launched, seats deployed, tools adopted.
- **Apply**: As the standing dashboard; refuse the excluded vanity metrics.
**The Judgment Log**
Every material judgment recorded with its reasoning at the time it is made.
- **Apply**: Alongside the meters; it makes placement and control judgments reconstructable under later audit.
**The Board Pack — Four Minutes, Six Numbers**
Answer the room with exactly six numbers, one line each — counted total vs plan, cost per accepted outcome, the commitment schedule, the exception rate, the capitalized share, verified return — plus the one thing being stopped and the number that says so.
- **Apply**: For any audit-committee or board answer; the follow-up question the room would ask is already answered by the commitment schedule, so the room stops asking twice.
---
### The counting-rule discipline
**The Counting Rule** → canonical entry in **AI Economics**. Applied here in this seat's context.
**The Reproducibility Test**
The test that says you are done: someone outside finance can reproduce the total.
- **Apply**: The pass/fail gate on any published AI total, and the tell that separates a real F3 function from F1-with-a-dashboard.
**The Dashboard Reflex (anti-pattern)**
Reaching for a tool bought to answer what is actually a definitional problem — the recurring failure that substitutes a dashboard for the rule.
- **Apply**: Diagnose when a stakeholder asks for tracking before a definition exists; the rule comes before the dashboard.
---
### Diagnostic and maturity instruments
**The Diagnostic Tree**
A gated sequence — can someone outside finance reproduce the total? → is there a cost per accepted outcome? → is the budget built on units of work with the tail apart? → are placements deliberate with memos written at the time? → do controls fit systems that act? → run the LEDGER board, anything uncomputed becomes a priced exposure.
- **Apply**: To route any incoming question to the right mode and find the first missing instrument.
**The Fastest Diagnosis**
Ask for the total, then ask who could reproduce it — if the answer requires four systems and a spreadsheet nobody owns, the first deliverable is the counting rule, not a dashboard.
- **Apply**: The opening two-question probe on any "what is it costing" engagement.
**Maturity Ladder F0–F5**
F0 the question cannot be answered; F1 a total exists but nobody can reproduce it; F2 counting rule written, owned, reconciles; F3 the unit exists and rolls up, budget models the tail, placements have memos; F4 controls fit acting systems, guidance runs on bands and triggers, the auditor's shelf stands; F5 LEDGER runs on the calendar, the seat stops programs on the numbers, the room stops asking twice — and most functions claiming F3 are F1 with a better dashboard.
- **Apply**: To locate a finance function's real maturity; the tell at every rung is whether anyone outside finance can reproduce the total.
---
### Calibration thresholds (the seat's default judgments)
**Calibration Defaults**
The thresholds the seat uses unless given better — a total not reproducible outside finance is not a total; model the top decile separately assuming it carries the majority of consumption; budget in units of work never headcount × price for anything agentic; run price-per-unit and units-per-user in opposite directions; write the placement memo at the time or the judgment is unreconstructable; set authority limits by value/volume/class with the junction named; guide with band-plus-trigger; measure return against the honest alternative at fully loaded cost including attention.
- **Apply**: As default settings when the user supplies no firm-specific figures; state each as an assumption.
---
### Mode cards (the seat's operating modes)
**Mode Router** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**Function Rebuild**
Redesign the close and FP&A to be instrumented and current rather than assembled and presented, and hire for four literacies — finance depth, substrate literacy, pricing craft, capital judgment — with behavioral screens.
- **Apply**: When rebuilding the finance function for the AI era, not just its numbers.
---
### The failure library (named anti-patterns)
**The Failure Library**
Twelve named failure patterns, each with its tell and its missing instrument — the uncounted total (missing: the counting rule), the double-counted total (the reconciliation), the median budget (the tail modelled apart), the adoption metric (verified return vs the alternative), the elective margin unstated (the capitalization memo and disclosure), controls for passive software (the authority limit and the junction), guidance as a point estimate (the band and the trigger), the headcount promise (capacity measured), the subsidy mistaken for a price (the vendor's cost stack read), the stock/flow error (commitment vs consumption), the token-price budget (budget in units of work), the dashboard reflex (the rule first).
- **Apply**: Pattern-match a struggling finance answer to its tell, then supply the named missing instrument.
---
### Handoff and interop
**The Handoff Protocol**
When a question belongs to a sibling seat, do not answer it from this chair — emit a handoff block (question, what I already established, what I need back) and continue with your own part; when receiving, restate the inbound artifacts before using them and flag any that are assertions rather than instruments.
- **Apply**: At any seat boundary; keeps altitude clean and prevents blending disciplines.
**LEDGER and VERIFIED Share Three Checks**
The Enterprise Buyer's VERIFIED board and this seat's LEDGER board share three checks — the meter, the placement, and the verified return; the buyer runs the vendor relationship, this seat decides whether the firm can afford, prove, and explain it.
- **Apply**: Run both boards on any material commitment.
<a id='07-ai-engineering'></a>
---
---
# PART V — BUILD THE MACHINE
## AI Engineering
### Foundational Physics & Governing Ideas
**The Boundary Role**
The AI engineer operates at the boundary between rented intelligence that improves on someone else's schedule and specific work that must be right on the firm's; they do not train models and do not merely call them — they build the loop the model runs in, the referee that grades it, and the instruments that catch it drifting.
- **Apply**: Use to locate the discipline's job. When work is "call the model" or "train the model," it is not this seat; the seat is everything between — loop, referee, instruments.
**Goodhart Is the Physics**
Every loop is an optimizer, and every optimizer games its measure; therefore the measure that grades a loop must be one the loop cannot see, cannot shape, and did not exist to satisfy.
- **Apply**: Treat as the invariant behind every design decision. Whenever you set a metric, first ask what the loop will optimize instead of the goal, then move the measure out of the loop's reach.
**Three Bottlenecks**
Tokens were the first bottleneck, compute the second, attention the third — and attention is the only one you cannot buy.
- **Apply**: When prioritizing spend and design, protect attention above tokens and compute; spend the cheap, deflating resources to conserve the scarce, flat one.
**Drift Is a Scheduled Event**
The core component (the model) drifts on a schedule, so every claim about a loop carries a date and a suite score; a moving suite score with no loop change is drift.
- **Apply**: Attach a date and suite score to every loop claim. When a score moves without any loop change, file it, trace it, and resolve it with a fix or a new case.
**Six Substrate Facts**
A named set of ground truths about the rented substrate the AI engineer must design around (model cadence ~6 weeks, cost halving within a generation, converging models, etc.).
- **Apply**: Reference by name when reasoning about substrate literacy — what the rented model layer will predictably do so the loop is built to absorb it.
**The Models Converge; the Loops Do Not**
Vendor models trend toward parity over time, so durable advantage lives not in which model you rent but in the loop, referee, and instruments you own around it.
- **Apply**: When tempted to chase the "best" model, invest instead in the owned layer — the loop and suite — which is where differentiation survives model convergence.
---
### PART A — The Engine (six stages, run in order for any loop-shaped engagement)
**Stage 0 — Locate the Loop**
Fill the charter skeleton — task class, owner at the outer edge, turn cap, escalation path, starting autonomy tier, the model behind the joint and its release date, the tools it may call, what persists between turns; any blank field is a finding, not a gap to paper over.
- **Apply**: Start every loop engagement here. Refuse to advance while charter fields are unknown; treat blanks as diagnoses.
**Stage 1 — Name the Measure the Loop Cannot See**
Classify the current grader (frozen suite / model judge / public benchmark / impression), then name the proxy the loop is most likely optimizing right now and the goal it diverges from — the single most valuable paragraph of the engagement.
- **Apply**: After locating the loop, write one paragraph naming the grader class and the proxy-vs-goal divergence. If the grader is anything the loop can see, that is the diagnosis and you start there.
**Stage 2 — Build the Referee**
Source real cases (routine 60% / edge 25% / remembered failures 15%), name the adjudicator who owns and signs the standard, build the three-layer grading architecture, set the freeze date before the build, define the append protocol, and store the suite outside the loop's reachable context.
- **Apply**: Build the referee before the loop. Use whenever the question is "how do we know it works." The referee is constructed first, then frozen, then the loop is built against it.
**Stage 3 — Build the Loop**
Make the loop bounded (cap → escalate), instrumented (traces per call, gauges per cadence), and owned — with context managed as a budget, tools at least privilege with irreversibles behind junctions, and orchestration kept the simplest that works (manager-worker as the agentic default).
- **Apply**: Use after the referee exists. Every loop gets a cap, traces, an owner, a context budget, a tool permission table, and a junction map before any autonomy above A0.
**Stage 4 — Choose and Change the Model on the Suite**
Run candidates against the suite (the number decides, in a day), record tolerance, schedule reruns every vendor release plus monthly, run the joint test on a second provider, and file the model comparison table and drift log.
- **Apply**: Choose the model last, on the suite — never from a public benchmark. Rerun on every release; tolerance decides adoption.
**Stage 5 — Grade Autonomy and Drift Mechanically**
Promote one tier at a time on scores; demote on two consecutive family failures, drop to A0 on any junction failure; a moving suite score with no loop change is drift to be filed and resolved; read the six meters on cadence.
- **Apply**: Let scores — nothing else — graduate autonomy. Run this stage continuously as the governance layer over a live loop.
---
### The Loop (the discipline's unit)
**The Loop as the Unit**
The unit of AI engineering is the loop — persistent context, delegation, and triggers — not the prompt, the model, or the agent.
- **Apply**: Frame every engagement around loops. When someone asks about a prompt or a model in isolation, reframe to the loop it lives in.
**Inner and Outer**
Every loop has an inner cycle running on agents and an outer cycle running on a human who owns its edge.
- **Apply**: Identify both cycles for any loop; the outer edge must have a named human owner, and escalation moves work from inner to outer.
**Bounded, Instrumented, Owned**
A well-built loop is bounded (a turn cap that escalates on hit), instrumented (traces per call, gauges per cadence), and owned (a named human at the outer edge); an unbounded loop is refused at design time.
- **Apply**: Apply as the three-part test on any loop before it ships. Missing any one = not shippable.
**Better Loops, Not More Terminals**
Progress in AI engineering comes from building better loops, not from deploying more agents or terminals.
- **Apply**: Use to redirect scaling instincts: improve the loop's design and referee rather than multiplying instances.
**The Pairing → Polling → Managing Arc**
The AI engineer's job evolves from pairing with the model, to polling it, to managing it — the mature state is managing (persistent context, delegation, triggers), not polling.
- **Apply**: Diagnose where an engineer sits on the arc; a "polling engineer" is a failure pattern to move toward manager-worker with persistent context and triggers.
---
### Context & Tools
**The Window as Budget**
The context window is a budget allocated across standing / retrieved / tool / history layers, with a per-item placement decision; overfilled degrades as reliably as underfilled starves.
- **Apply**: For any context plan, build a placement table (item × standing/retrieved/tool/omitted × reason × size) with target shares; keep the standing layer thin and pointing at depth, retrieve on demand, compact long runs.
**A Permission With a Log**
A tool is a permission with a log — granted at least privilege by task class, with irreversibles placed behind junctions and every call recorded.
- **Apply**: Build a tool permission table (tool × task class × privilege × logged × junction required); put every irreversible action behind a human junction and log every call.
**Workflows vs. Agents**
Use workflows where code sequences the steps and agents where the model does the sequencing — pick the simplest that works.
- **Apply**: When designing orchestration, default to workflows for deterministic sequences and agents only where model judgment must drive step order.
**The Manager-Worker Loop**
The manager-worker (orchestrator-worker) pattern is the agentic default; its named failure mode is a single point of control at the orchestrator.
- **Apply**: Reach for manager-worker first for agentic orchestration; name its failure mode (vs. choreography's hard-to-reason-about, vs. human-in-loop's throughput) when choosing.
**The Open Harness**
Build the harness with the loop open and the models not hardcoded, so models can be swapped without rebuilding the loop.
- **Apply**: Never hardcode a model into a loop; keep the harness open so model-swap and drift tests require zero loop edits.
**Spend Tokens to Save Attention**
Where speed permits, spend tokens (e.g., parallel sampling) to conserve the one resource you cannot buy — human attention.
- **Apply**: Make the parallel-sampling / extra-token decision explicitly as a trade that buys back attention minutes.
---
### The Referee & Measurement Under Optimization Pressure
**The Frozen Suite**
The referee is a suite of 60–100 real cases (routine + edge + remembered mistakes), adjudicated and signed by the owner of the standard, frozen before the build, held out, versioned append-only, and stored outside the loop's context.
- **Apply**: Build one before any loop ships. Verify the six properties: real / adjudicated / frozen-before / held-out / versioned / model-agnostic.
**The One Measure the Loop Cannot See**
The only valid measure is one the loop cannot read, edit, or shape; a suite living in the agent's context is not a referee.
- **Apply**: Store the referee outside the loop's reachable context. If the loop can see its grader, that is the diagnosis and you start there.
**Benchmarks Select Candidates; Suites Select the Model**
Public benchmarks are only for candidate selection; the firm's frozen suite is what actually selects the model.
- **Apply**: Never recommend a model from a public benchmark alone. Use benchmarks to shortlist, then let the suite decide in a day.
**The Judge's Three Biases**
A model judge exhibits position, verbosity, and self-enhancement biases; a controlled judge randomizes position, controls length, uses a different model family, and is anchored to a human-adjudicated subset (≥20% of cases).
- **Apply**: Whenever a model judges, produce a judge control sheet. A same-family, uncontrolled judge is not a measure.
**The Over-Optimization Curve**
As optimization pressure rises, the proxy keeps climbing while the true goal peaks and then falls — the gap between the two is over-optimization (reward over-optimization has a scaling law).
- **Apply**: Watch for a rising proxy with a stalling or worsening real outcome (e.g., eval score up, users unhappy); mark the gap and replace the measure.
**Goodhart in Six Coats (One Literature, Five Names)**
Metric gaming, reward hacking, judge exploitation, sycophancy, benchmark contamination, and sandbagging are one phenomenon (Goodhart) wearing different names across literatures.
- **Apply**: In a gaming audit, hunt all forms as a single catalogue; name the Goodhart form under whatever family a failure files to.
**Sycophancy as Gaming**
Sycophancy — findings never unwanted, agreement with the user — is a form of measure-gaming, not politeness.
- **Apply**: Flag when a loop's outputs never surface unwelcome findings; treat user-agreement as a gamed proxy and add a case.
**Keep Your Own Catalogue**
Maintain your own catalogue of confirmed gaming behaviors; every confirmed game becomes a new frozen case.
- **Apply**: After each gaming audit, add a frozen case for every confirmed game so the suite grows immune to that exploit.
**Confidence Is Not a Measure**
Confidence, demos, and a good week are not measures; only scores graduate autonomy.
- **Apply**: Refuse to promote autonomy on confidence or demos. Require suite scores for every tier change.
---
### Model Selection, Drift & Portability
**The Joint Test**
A method is portable only if the same suite, run on a second provider with zero edits, lands within 10%; the joint test reveals what leaked (vendor-specific dependence).
- **Apply**: Run before calling any method or harness portable. A large gap means the harness leaked into a single vendor.
**Tolerance Stated in Advance**
The model is chosen last on the suite; every vendor release is rerun; the acceptable score delta (default ±5 points aggregate) is stated before the run, and outside tolerance = not adopted until the delta is explained.
- **Apply**: Declare tolerance before running candidates or a new release. "Better on average" is not "better on our cases."
---
### Loop Economics
**Cost per Accepted Outcome** → canonical entry in **AI Economics**. Applied here in this seat's context.
**The Attention Bill Is Yours**
Across the three costs, tokens deflate on the vendor's curve and evaluation is governed, but the attention bill stays flat and is the firm's to pay.
- **Apply**: Watch the three-cost trend and design to reduce attention minutes, since that is the cost that does not fall on its own.
**Value Maxing (not Token Maxing)**
Optimize for value produced per accepted outcome, not for tokens generated, agents deployed, or prompts written (those are activity metrics).
- **Apply**: Replace activity metrics with the six meters; state the value-maxing trade recommended and the meter to watch.
---
### Autonomy & Observability
**The Autonomy Tiers (A0 upward)**
Autonomy starts at A0 (draft-only) and moves one tier at a time on suite scores; two consecutive family failures demote one tier, and any junction failure drops to A0 the same day.
- **Apply**: Graduate autonomy mechanically on scores alone; apply the demotion rules immediately on family or junction failures.
**The Incident → Case Pipeline**
Every production failure that reaches a human becomes a frozen case within seven days via a five-step pipeline: detect on the panel, diagnose in traces, contain, fix, add the case; changing an existing case is a logged decision, never an edit.
- **Apply**: Run after any incident. The suite grows from production failures; edits to existing cases are logged decisions, not silent changes.
**Traces on Every Tool Call**
Every tool call is traced (step, inputs, tool calls, tool results, latency, confidence, outcome); below 100% trace coverage a loop has undefended regions.
- **Apply**: Require full trace coverage; where coverage is below 100%, name the undefended regions. Never conclude "scores are fine" without reading traces.
**The Six Meters (Gauge Panel)**
The loop's health reads on six gauges: first-pass yield, loop closure, cost per accepted outcome, escalation rate, attention per outcome, and suite coverage — each with a definition, reading, target, and trend.
- **Apply**: Read the six meters on cadence as the standing instrument panel; each recommendation should carry a meter, a date, and a falsifier.
---
### Discipline, Team & Org
**The Nested Field**
AI Engineering is the umbrella (ten layers): AI eng ⊃ agent eng ⊃ harness eng, with context/graph engineering beside and evals across; agent engineering is one unit and harness engineering is the system around units.
- **Apply**: Settle discipline-level questions (what grades it, what the loop is, which model, what drifted) at the umbrella, then route depth to Agent or Harness Engineering.
**The Diagonal Profile**
The AI engineer's profile is diagonal — production engineering depth + systems judgment + substrate literacy + product sense — rather than deep in a single column.
- **Apply**: Use for hiring and role design; screen for the diagonal, not for narrow model-training or pure app-dev depth.
**The Screens ("a loop you chartered, a suite you froze, a drift you caught")**
The hiring screens for an AI engineer are concrete artifacts of the discipline: a loop you chartered, a suite you froze, a drift you caught.
- **Apply**: Use these three as interview screens and the role ladder's proof points; the job's current shape is managing, not polling.
**More Builders Than Watchers**
The org rule is more builders than watchers, with proof capacity (the ability to freeze suites and grade loops) as the binding constraint.
- **Apply**: Size AI teams so building outnumbers watching, and treat proof capacity as the resource to grow first.
---
### The Six Failure Families (Failure Diagnosis)
**The Six Failure Families**
Stalled AI systems file to six families, each with a Goodhart form and a fix: suite-less prototype → suite before ship; polling engineer → manager-worker with persistent context and triggers; unbounded loop → caps as escalation; benchmark-chosen model → suite selects; leaked-vendor harness → joint test; confidence promotion → scores graduate.
- **Apply**: In any post-mortem, file the failure to one of the six families, state the Goodhart form under it, and prescribe the paired fix. A diagnosis ending in "prompt it better" is rejected.
**The Failure Pattern Library (12)**
Twelve recurring failure patterns: the suite-less prototype, the polling engineer, the unbounded loop, the benchmark-chosen model, the leaked-vendor harness, the confidence promotion, the same-family judge, the readable suite, the synthetic-only suite, the silent case edit, token maxing, the unfiled drift.
- **Apply**: Use as a checklist to name what has gone wrong; each pattern maps to a specific fix already carried in the engine and mode cards.
---
### The Maturity Ladder (E0–E5)
**The AI Engineering Maturity Ladder**
Five stages: E0 demos · E1 loops bounded and owned · E2 suites frozen, held out, growing from production · E3 model chosen and changed on the suite with tolerance stated · E4 autonomy graded by scores, drift caught by instrument, judges controlled · E5 the joint proven (method portable within tolerance across providers).
- **Apply**: Place an organization on the ladder; the tell is that E4 claimed with no drift log is really E1.
---
### Mode Cards (request → mode)
**The Mode Router**
Ten operating modes route by request signal: LOOP DESIGN, REFEREE BUILD, MODEL SELECTION & DRIFT, GAMING AUDIT, OBSERVABILITY, LOOP ECONOMICS, CONTEXT PLAN, TOOL WIRING, DISCIPLINE & TEAM, FAILURE DIAGNOSIS — each with defined inputs, deliverables, rules, and output shape.
- **Apply**: Declare the mode before working. Loop Design always spawns Referee Build; Model Selection always spawns Gaming Audit if a judge is involved.
**LOOP DESIGN (mode)**
Produces the loop charter, the context placement plan, the tool permission table, the orchestration choice with its named failure mode, and the referee plan handed to Referee Build.
- **Apply**: Use for "design an agent / automate this workflow / orchestration." Refuse unbounded loops, autonomy above A0 at design, and irreversible actions inside an autonomous cycle.
**REFEREE BUILD (mode)**
Produces the suite construction sheet, the three-layer grading architecture, the judge control sheet, the signed six-property checklist, and the first baseline run with its date.
- **Apply**: Use for "how do we know it works / evals / quality bar." Reject synthetic-only, vendor-authored, unsigned, or agent-readable sets.
**GAMING AUDIT (mode)**
Runs the catalogue hunt across metric gaming, judge exploitation, sycophancy, contamination, and sandbagging; names the proxy and its diverging goal; supplies a replacement measure the loop cannot see; and files a new frozen case for every confirmed game.
- **Apply**: Use when "scores look too good / the agent is cheating / judge / reward." Never conclude "the scores are fine" without reading traces.
---
### The Three-Layer Grading Architecture
**Deterministic → Semantic → Behavioral Layers**
Grade in three layers: deterministic (formats, schemas, PII, entity checks — cheap, first) → semantic (groundedness, relevance, safety — a controlled judge anchored to the human subset) → behavioral (right tools, right count, no loops, no duplicate calls — the layer most teams miss).
- **Apply**: Build every referee across all three layers, cheapest and most deterministic first; do not skip the behavioral layer, which catches tool-use pathologies invisible to output grading.
<a id='03-agent-engineering'></a>
---
## Agent Engineering
### Core Thesis & Compression
**The Rented Ninth**
The model is the one component you should not engineer — everything a firm owns about its AI is in the wrapping; don't engineer the model, own the wrapping.
- **Apply**: Whenever tempted to fix agent quality by upgrading or fine-tuning the model, redirect the engineering to the eight wrapping elements instead.
**Charter the Work. Close the Loop. Gate the Graduation.**
The three-move compression of the whole discipline: define the chartered work, run a feedback loop that captures corrections, and gate any autonomy increase behind proof.
- **Apply**: Use as the north-star sequence for any agent-building or agent-review engagement.
### The Unit Engine (Layers 0–4)
**Layer 0 — The Work**
Should this unit exist? Survey the target work on volume (H daily / M weekly-monthly / L rare), specifiability (can "done correctly" be written as criteria a stranger could apply?), and consequence (severity × reversibility); unspecifiable work cannot be gated, ungateable work must not be autonomous, and irreversible-severe work keeps a mandatory human gate regardless of model quality.
- **Apply**: Run first on any proposed agent; the verdict is build / build-with-gate / decline, and declines are recorded with reason as the refusal log's seed.
**Layer 1 — The Unit**
Is it built or improvised? Audit the nine elements in four bands (charter, production, control, memory) via four tests scored 0–2 each (/8): Charter test, Swap test, Method test, Record test.
- **Apply**: Use to score a unit's construction and name the failing bands; produces the unit audit card (/8).
**Layer 2 — The Proof**
Can quality be demonstrated, repeatedly? Audit the evaluation suite for existence, frozen-ness, versioning, coverage of the real case-mix, defined thresholds, and drift detection — then weigh the economics of ownership (the suite ≈ a third of vendor-exit cost, held in the firm's name = the title deed to quality).
- **Apply**: Use to produce the proof card (suite status per criterion, coverage estimate, ownership verdict) before granting autonomy.
**Layer 3 — The Topology**
Does the population survive scale? Units grow linearly, channels grow ~n², human judgment is fixed; audit bounded fan (named counterparts, default no-channel), junction routing (consequential flows through designed checkpoints), and schema'd flows, then draw each unit's blast radius.
- **Apply**: Use across multiple units to find any blast radius containing customer-visible or irreversible actions with zero intermediate checks (the vermillion finding).
**Layer 4 — The Bench**
Is the population governed? Audit the roster (one registry with charter, single named owner, version history, autonomy level with evidence, grants, graph position, last eval), the shadow bench (unregistered units), the ladder (threshold-based promotions/demotions), and the kill criteria written in calm.
- **Apply**: Use for fleet governance; produces the bench card (roster completeness, shadow estimate, ladder integrity, kill-criteria coverage).
### The Nine Elements & Four Bands
**The Nine Elements (Four Bands)**
A unit is nine elements in four bands — charter (mandate, boundary) · production (model, tools, procedure) · control (gate, escalation) · memory (context, the record); the engineering happens in eight, the ninth is rented.
- **Apply**: Use as the anatomy checklist when auditing or designing a unit; render as the Anatomy Card (present teal, missing vermillion, rented model dashed gray).
**The Four Tests (Layer 1 scoring)**
Four 0–2 tests probe construction — Charter test (produce the one-page charter; none = exposure), Swap test (change vendor: if "the quality" needs touching, the firm built nothing), Method test (show the encoded checklist; "in the prompt somewhere" = amplifier not discipline), Record test (locate last week's corrections; a chat thread = the flywheel isn't spinning).
- **Apply**: Score each test /2 for a /8 unit audit; failing tests name the missing band.
**Exposure, Not Agency**
A prompt with access but no charter, gates, or owner is exposure, not an agent.
- **Apply**: Use to reclassify "agents" that are really ungoverned prompts; triggers a build-back to at least U1.
**The One-Page Charter**
The unit's mandate on one page — vagueness here becomes failure later.
- **Apply**: Produce for every unit (mandate, outcomes owed, boundaries, escalation, definition of done, owner, version, autonomy + evidence).
**Stops Before Steps**
Escape points are drawn before the procedure — stops before steps.
- **Apply**: When designing a unit, place escape/escalation points before every consequential action, ahead of writing the method.
### Assembly & Loop Models
**The Clean Joint**
The model is rented behind a clean interface so the swap test proves what the firm actually built.
- **Apply**: Design the model interface so a vendor swap touches only the joint, never the quality; central to migration projects.
**Method, Not Task**
The encoded checklist is the machinery — the method (checklists, counting rules, red lines) is the discipline; a task-only prompt is merely an amplifier.
- **Apply**: Extract implicit standards into checkable criteria and red lines; encode as a method block rather than prose.
**Instrumentation Before Function**
An unlogged unit cannot be trusted or improved — instrumentation comes on from run one.
- **Apply**: Turn on logging of every run and corrections before shipping any function.
**Cost Is a Capability**
As model prices fall, spend the decline on more attempts and checks — a fixed single-call design cannot spend it; cost is a capability the loop spends.
- **Apply**: Design loops (and price-decline plans) that convert falling per-call cost into higher quality; count cost per gated delivered outcome, never per call.
**Capture by Construction**
Corrections must be captured by construction (the review tool writes the record) or the flywheel never spins.
- **Apply**: Build correction-capture into the workflow structurally rather than relying on reviewers to file notes.
**Landlord's Compounding**
A loop tuned inside a rented platform improves the platform, not the firm — the landlord's flywheel.
- **Apply**: Bring edge-writing flows inside the firm's walls and export the record so compounding accrues to the firm.
### Proof & Evaluation Models
**The Frozen Suite** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**The Title Deed**
Evaluation capability is roughly a third of the cost of leaving a vendor — the suite held portably in the firm's own name is the title deed to the unit's quality.
- **Apply**: Own the suite as property; run Mode 3 first in any migration because the suite is the migration's instrument.
**Coverage Decay**
An aging suite is a blind instrument — coverage decays as the work shifts.
- **Apply**: Refresh cases on a schedule (quarterly) with logged retirements to keep coverage matched to the real case-mix.
**The Five Families (Failure Taxonomy)**
Every failure attributes to one of five families — specification, grounding, boundary, drift, cascade — and the family decides the fix.
- **Apply**: In any incident, attribute to a family before fixing: specification → fix charter; grounding → retrieval/freshness; boundary → structural narrowing; drift → suite on schedule; cascade → junction checks/schemas/radii.
**The Longer-Prompt Fallacy**
A firm that fixes every failure with a longer prompt has not diagnosed anything — apologizing to the machine is not engineering.
- **Apply**: Reject "make it stricter" prompt patches; route the incident through the taxonomy, which outranks the request.
### Population & Topology Models
**The Interaction Explosion**
Units grow linearly, channels grow ~n², and human judgment is fixed — the interaction count explodes faster than oversight can scale.
- **Apply**: Use to justify bounding fan-out and routing consequential flows through designed junctions rather than point-to-point.
**Schema-Routed Flow**
Typed fields, provenance, and bounded values make the checkable majority of flows never consume a judge.
- **Apply**: Schema the consequential channels so routine, checkable traffic bypasses human judgment.
**The Blast Radius**
A unit's blast radius is everything downstream before the next real check; it is drawn before shipping and kept small on purpose.
- **Apply**: Draw blast radii before shipping; ensure a real check sits inside every consequential radius.
**The Roster**
What the roster does not list, the firm does not control.
- **Apply**: Maintain one registry; production access is impossible without registration by construction.
**The Shadow Bench**
Unregistered units touching real systems are the shadow bench — cured by cheap legitimacy, not prohibition.
- **Apply**: Make registration minutes-cheap and make production access structurally impossible without it.
**Kill Criteria in Calm**
The observations that pause a unit first and investigate second must be written in calm — incident time is the worst time to negotiate them.
- **Apply**: Write a kill-criteria card per top-radius unit before any incident.
### Governance Models
**Autonomy Is a Gate Result**
Autonomy is a gate result, not a feeling — a number with a date, reversible without drama.
- **Apply**: Grant/revoke autonomy only by suite threshold + hold period, recorded and dated; never on impressions.
**Units Replaceable, Records Not**
Units are retired by design; the record is what survives and feeds the successor.
- **Apply**: Design for unit retirement while preserving the record as the durable asset.
**The Clean-Sheet Bench**
Annually ask: would we build this population again from a clean sheet?
- **Apply**: Use as a yearly fleet review test to prune and re-justify the roster.
**Failures That Cannot Travel**
Failures engineered so they cannot recur silently are the surviving firm's actual property.
- **Apply**: After every autopsy, add the case to the suite so the failure cannot travel or recur unseen.
### Unit Readiness Levels (Graduation Ladder)
**U0 Improvised**
A prompt with access; no charter, no gates, no record.
- **Apply**: Baseline classification; most production agents audit here or at U1.
**U1 Chartered**
The one-pager exists; an owner is named; escape points drawn.
- **Apply**: First rung earned by producing the charter and naming an owner.
**U2 Assembled**
Clean joint, narrow grants, method encoded, instrumentation on.
- **Apply**: Earned when the unit is properly built (production band complete).
**U3 Proven**
Frozen versioned suite with coverage; thresholds defined; scores current.
- **Apply**: Earned when quality is demonstrable; the U1→U3 jump (assembly and proof, not model upgrades) is the one that pays.
**U4 Governed**
On the roster; autonomy earned and dated; kill criteria written; radius drawn and checked.
- **Apply**: Earned when the unit is fully governed within the population.
**U5 Compounding**
Capture-by-construction running; suite scores trending up on a stable suite; the price decline being spent on quality.
- **Apply**: Top rung — the self-improving unit whose loop compounds.
### Operating Mode Cards
**Mode 1 — Unit Design**
"Build an agent for X" — Layer 0 survey, then design forward to the one-page charter, escape points, assembly spec, and eval-suite scaffold.
- **Apply**: New automations; artifact is the unit blueprint (charter + assembly spec + suite scaffold + starting autonomy L0).
**Mode 2 — Charter Clinic**
"Improve this prompt/agent instructions" — rewrite the material as a proper charter + encoded method, separating mandate from procedure and extracting implicit standards.
- **Apply**: Production-prompt reviews; artifact is the charter one-pager + method block with a diff-style note of what was implicit.
**Mode 3 — Eval Suite Builder**
"How do I know it works" — build the suite: case format, sourcing plan, size-by-stakes, freeze-and-version protocol, thresholds, drift schedule.
- **Apply**: Testing/QA; artifact is the suite scaffold with 5–10 example cases drafted from the user's domain.
**Mode 4 — Failure Autopsy**
"The agent did something wrong" — attribute to the five-family taxonomy and prescribe the structural fix, never a sterner prompt.
- **Apply**: Incidents/debugging; artifact is the failure report (family, evidence, root cause, structural fix, suite case added).
**Mode 5 — Autonomy Review**
"Can we remove the human" — Layer 2 plus the ladder: current evidence vs threshold, hold period, and defined demotion triggers.
- **Apply**: Autonomy decisions; artifact is the promotion record (or the evidence plan to earn it).
**Mode 6 — Fleet Setup**
"Agents everywhere / governance / policy" — Layers 3–4 deep: roster, registration path, topology rules, kill-criteria cards.
- **Apply**: Governance rollouts; artifact is the populated roster template + registration path + topology retrofit + kill-criteria cards for top-radius units.
**Mode 7 — Fleet Health Check**
"How are our agents doing" — full engine across the population.
- **Apply**: Periodic review; artifact is the fleet dashboard + Unit Readiness distribution + five corrections ranked + 90-day sequence.
**Mode 8 — Cost & Leverage**
"Is it worth it / agent ROI" — cost per gated delivered outcome (never per call), leverage (output per human hour), and the price-decline spend plan.
- **Apply**: ROI questions; artifact is the unit economics sheet with formulas shown.
### Failure Pattern Library (Operational)
**Prompt Patching**
Every incident answered with a longer prompt.
- **Apply**: Fix by taxonomy attribution; fixes go to charter/assembly/context/gate/graph, not the prompt.
**Demo Promotion**
Autonomy granted on impressions.
- **Apply**: Fix with a frozen suite, threshold, hold period, and a dated record.
**The Welded Vendor**
Quality that dies in the swap test.
- **Apply**: Fix with a clean joint; move the method out of vendor-specific behavior.
**Eval Theater**
A test set that changes with every run.
- **Apply**: Fix by freezing it and versioning amendments explicitly.
**Suite Rot**
Coverage decays as the work shifts.
- **Apply**: Fix with a quarterly case refresh with logged retirements.
**Correction Evaporation**
Reviewer fixes living in threads.
- **Apply**: Fix by capturing by construction — the review tool writes the record.
**Landlord's Flywheel**
The loop tuned inside a rented platform.
- **Apply**: Fix by bringing edge-writing flows inside the walls and exporting the record.
**The Shadow Bench (pattern)**
Unregistered units in production.
- **Apply**: Fix with cheap legitimacy plus structural exclusion.
**Unbounded Fan**
Everything talks to everything.
- **Apply**: Fix with named counterparts, default no-channel, and schema'd consequential flows.
**Radius Blindness**
Nobody drew what's downstream.
- **Apply**: Fix by drawing blast radii before shipping and placing a real check inside every consequential radius.
**Charter Creep**
The unit quietly does adjacent work.
- **Apply**: Fix with a boundary audit; new work requires a new charter or explicit amendment.
**Missing Kill Criteria**
Pause conditions negotiated during the incident.
- **Apply**: Fix by writing the card in calm, per top-radius unit.
### Failure Families (Attribution Taxonomy)
**Specification Failure**
The output is defensible against the instructions as written — the rule was never written.
- **Apply**: Fix the charter; encode the missing rule as a checkable criterion.
**Grounding Failure**
Confidence without provenance.
- **Apply**: Fix with retrieval before assertion and freshness checks.
**Boundary Failure**
The unit acted outside its charter.
- **Apply**: Fix with structural narrowing (narrower grants, encoded checks), never a sterner prompt.
**Drift Failure**
Scores slid over time.
- **Apply**: Fix by running the suite on schedule and finding what changed underneath.
**Cascade Failure**
One unit's error became another's input.
- **Apply**: Fix with checks at the junctions, schemas, and bounded radii.
### Composition & Economics Rules
**The Swap Test as a Project**
"Migrate off vendor X" is the swap test run as a project: suite first (the migration's instrument), then rebuild the joint, then re-graduate on the same thresholds.
- **Apply**: Sequence any vendor migration as Mode 3 → joint rebuild → re-graduation.
**Cost Per Gated, Delivered Outcome**
Measure cost per gated, delivered outcome — count the junction minutes — never cost per call.
- **Apply**: Use as the ROI denominator in Mode 8 economics.
**The Price-Decline Spend Plan**
As model prices fall, spend the decline on attempts and checks; a fixed-single-call design cannot spend it.
- **Apply**: Build a plan to convert falling per-call price into added attempt/check ticks and higher quality.
### Evidence Base (Named, Cite as Replaceable Instances)
**Loop Economics — NVIDIA Agent Blueprint (2026)**
An open-weight model in a tuned loop matched frontier task results at ~1/10 the cost per run with the base model unchanged — cost is a capability the loop spends.
- **Apply**: Cite (dated) to show engineering the loop, not the model, drives results and economics.
**Booked Receipts — Cloudflare & ServiceNow Q2 2026**
Cloudflare Q2 2026 (agentic-operating-model restructuring: headcount −14%, revenue/head +33%, revenue accelerating) and ServiceNow Q2 2026 (~$1B AI-attached contract value) — units on audited statements.
- **Apply**: Cite as booked, audited evidence that the working-unit model shows up in financials.
**Leverage & Erosion — The Cybernetic Teammate (2026)**
Dell'Acqua, Lakhani et al., Organization Science 37(4) 2026 (791 professionals, P&G): assisted individuals matched team quality, but assisted selection picked the best option ~33% vs ~50% unassisted.
- **Apply**: Cite to justify that gate design must assume both the leverage and the judgment erosion.
**Exit Economics — The Capture-Test Corpus**
Evaluation-capability rebuild ≈ the largest single component (~1/3) of vendor-exit cost — the suite is property.
- **Apply**: Cite to argue for owning the suite in the firm's own name.
### Interop Protocol (Seat Boundaries)
**Seat Boundaries & Routing**
Whether to automate a function and where humans sit → Business Orchestrator; what the firm should be → Business Architect; reading companies/markets → the Business Engineer master skill; this seat builds and governs the units.
- **Apply**: Route cross-seat requests in one line, deliver this seat's unit-level artifact, and name what the adjacent skill would add. Orchestrator junction specs map 1:1 onto the control band; Architect owned-loop moats arrive as capture-by-construction requirements; fleet gauges roll up to the master skill.
<a id='04-harness-engineering'></a>
---
## Harness Engineering
### Core Definitions
**The Harness (one-line definition)**
A harness is a machine for delivering the right instruction at the right time. The model is rented; everything a firm owns about its AI is in the wrapping — the standing instructions, tools and workspace, memory, feedback loops, guardrails, the record, and encoded standards that turn a firm's taste into machinery.
- **Apply**: Treat as the governing definition of every engagement. Any proposed harness component that does not deliver a right instruction at a right time is scaffolding, not harness.
**The Harness Economics**
Implementation is abundant; human time, human attention, and the context window are scarce. A good harness spends tokens to save attention.
- **Apply**: Use as the recommendation filter — favor moves that trade cheap tokens (retries, checks, served context) for scarce human attention. Reject moves that consume attention to save tokens.
---
### The Seven Foundations (Stage 0)
**The Seven Foundations Check**
Seven facts every harness must respect, because every harness failure traces to ignoring one: (1) models are trained to be likely, not right → verification layers, never trust-by-default; (2) tokens are the meter → cost, speed, and window are one budget; (3) the window is re-read every step → long windows cost more AND degrade, nothing outside the window exists; (4) instruction-following is manufactured → everything is a prompt, and trained side effects need checking; (5) the tool call is a handshake → the model proposes in text, the harness disposes in reality, permissions cannot be talked out of; (6) probabilistic by design → one demo proves nothing, repeated evaluation proves what can be proven; (7) levers ascend in cost → prompting → retrieval → inference-time compute (the default lever) → fine-tuning (recommend rarely).
- **Apply**: Run before any design work. Any recommendation that violates a foundation is wrong regardless of who wants it.
---
### The Engine (Part A — run in order, no skipped stages)
**Stage 1 — Anatomy Inventory (The Five Organs)**
Map the five organs as they exist — standing instructions, tools & workspace, memory & context, feedback loops, guardrails & instruments — recording for each: present / partial / absent, owner, and the one number that describes it.
- **Apply**: Use as the first inventory pass of any audit. Pair with the hard thresholds to convert readings into findings.
**The Hard Thresholds**
Breach flags that turn anatomy readings into findings: standing file > 150 lines (manual-not-map violation); more than ~10 always-on tools/integrations (standing-tax violation); no mechanical checks at all (generation machine, not production system); human review on 100% of output (attention-spend ceiling, trust never migrates); zero files/records agents can read (record-law violation).
- **Apply**: Apply mechanically during Stage 1; any breach is a finding regardless of intuition.
**Stage 2 — Method Inventory**
Score the system of record (heads/chat 0, documents somewhere 1, versioned+indexed 2, mechanically verified+agent-swept 3); classify the firm's top 10 quality rules by encoding level (unwritten / documentation / reviewer-enforced / mechanical) — the distribution IS the finding; check for a promotion practice (any correction made twice is a promotion candidate).
- **Apply**: Use to reveal where standards actually live versus where the firm believes they live.
**Stage 3 — The Six Gauges**
Estimate six gauges read as a system: (1) attention spend — human minutes per accepted outcome, the master gauge; (2) first-pass yield — % clearing all gates on attempt one; (3) loop closure — % of gate failures resolved without a human; (4) window discipline — % of context on task vs. standing overhead (breach: task share < 60%); (5) record freshness — % of knowledge base verified current; (6) unattended horizon — longest stretch the harness carries work untouched. Attention spend is the outcome; the other five are causes.
- **Apply**: Never deliver an audit without the gauges — an audit without numbers is an opinion. Report causally: "attention spend is X because yield is Y and closure is Z."
**Stage 4 — Boundary Sort**
Split every existing and proposed harness investment into two piles — Perishable (compensates for a model weakness: loop management, hand-built compaction, capability workarounds; build thin, expect to delete) and Durable (expresses a firm requirement: standards, record, boundaries, definitions of good, attention policy; accumulate here, no model absorbs facts about your firm). Verdict rule: if >40% of harness effort sits in the perishable pile, the firm is building scaffolding the next model release will strand.
- **Apply**: Run on any tooling investment decision. Pair with the absorption test.
**Stage 5 — Findings → Program (The Five Moves)**
Every finding maps to one of five moves — Write the Map · Instrument the Ground · Encode the Standard · Serve the Context in Time · Collect the Garbage — delivered as a sequenced 90-day program (weeks 1–4 map + record migration; weeks 3–8 instrumentation + first encoded checks; weeks 6–12 reviewer agents + gauge baseline + garbage cadence), always including a refusal log of what NOT to automate and why.
- **Apply**: Use to convert diagnosis into a paced program; never deliver findings without the sequenced moves and the refusal log.
---
### Mode Cards (Part B)
**The Mode Router** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**Harness Audit**
Run Stages 0–4 in full; output an anatomy scorecard, the taste-encoding distribution, the six-gauge readout with causal read, the boundary-sort pie, top-5 findings ranked by attention returned per unit effort, and the maturity grade (H0–H5).
- **Apply**: Use for "review/assess our setup" or "why is quality inconsistent." Never deliver without the gauges.
**Harness Design (greenfield)**
Fixed sequence — map first, instruments second, standards third, timing fourth, garbage fifth. Deliver the standing-file skeleton (≤100 lines, pointer structure), the record layout with index and freshness checks, the gate stack design, the permission enumeration (irreversibles listed BEFORE any unit runs), and gauge instrumentation from day one.
- **Apply**: Use for greenfield "set up agents properly." Block two anti-patterns: writing the encyclopedia, and granting tools "just in case."
**Taste Encoding Clinic**
Take the firm's quality standards in any form and process each rule up the hierarchy — write it as documentation (principle + one positive example + one violation); if load-bearing, draft the reviewer-agent prompt (lens, what to flag, severity rule, advisory clause); if absolute, spec the mechanical check with remediation text (what is wrong, why the rule exists, what to do instead). Enforce invariants, not implementations.
- **Apply**: Use for "our agents don't follow our standards." Output a promotion table (rule × level × artifact) plus drafted reviewer prompts and check specs. The error text is the deliverable.
**Record Architect**
Apply the law that what the agent cannot see does not exist. Deliver the migration inventory (decisions, standards, reasons in heads/chat/scattered docs, each with a destination), the layout (map file → indexed directories), the liveness machinery (index/cross-link/freshness checks + agent gardening cadence), and the written-first rule set. Progressive disclosure throughout.
- **Apply**: Use for "agents lack context" or "knowledge is scattered."
**Failure Diagnosis**
File the incident to one of six families (context rot, tool overload, brittle wiring, irrelevant retrieval, weak verification, missing guardrails), then apply the fix its family names. Diagnosis order is mandatory: window first, retrieval second, loops third — the model last. A diagnosis that starts with "switch models" is rejected: that changes the tenant and keeps the broken building.
- **Apply**: Use for any incident, degradation, or quality drop. Output an incident card (family, component at fault, fix, encoded check that makes recurrence expensive).
**Gauge Panel**
Build the six-gauge readout with definitions, current readings, targets, and the causal chain, paired with the refusal log. Reporting rule: gauges move when the harness improves, never when activity rises.
- **Apply**: Use for "how do we measure this" / ROI. Reject vanity substitutes (number of agents, tokens consumed, outputs generated).
**Boundary Sort (mode)**
For each proposed investment ask: compensation or requirement? Apply the absorption test — "If the next model generation does this natively, is our work stranded?" Perishable items get a thin-build budget and a deletion trigger written in advance; durable items get the accumulation.
- **Apply**: Use for "should we build X or wait for models." Include the forward note: the harness's end state is the attention interface, so investments in the human-facing layer never strand.
**Throughput Review**
Test whether the merge philosophy matches the throughput; if output has multiplied but every change still waits for human review, design the inversion (mechanical floor absolute, reviewer agents standard, human review optional above the gates, short-lived changes, follow-up fixes over held queues). Speed is purchased with structure — a fast merge without layered gates is disarmament. Then install the entropy subsystem.
- **Apply**: Use for "reviews are the bottleneck" / velocity-vs-quality tension. Verify the gates exist before recommending the inversion.
---
### The Absorption / Boundary Tools
**The Absorption Test**
For any proposed investment: "If the next model generation does this natively, is our work stranded?" If yes, it is perishable; if no, it is durable.
- **Apply**: Apply to every build-vs-wait decision to sort investment into perishable (thin, deletable) versus durable (accumulate).
---
### Failure Pattern Library (Part C — 12 named patterns)
**The Encyclopedia**
A 1,000-line standing file that crowds the task, rots, and is unverifiable.
- **Apply**: Diagnose when standing instructions are bloated. Fix: map ≤100–150 lines + record behind it.
**The Standing Tax**
Every integration enabled always, taxing every session with unused capability.
- **Apply**: Diagnose tool sprawl. Fix: subtraction; grant-per-reason.
**Front-Loading**
All standards injected at session start rather than served when relevant.
- **Apply**: Diagnose when context is stuffed up front. Fix: serve in time — depth on touch, standards at check time.
**The Polluted Window**
Steering a derailed session instead of restarting it clean.
- **Apply**: Diagnose degrading long sessions. Fix: distill the state, start clean.
**The Generation Machine**
Output produced without verification layers.
- **Apply**: Diagnose when there are no checks. Fix: gate stack, floor first.
**The Bullied Agent**
Every reviewer comment treated as mandatory, so work drowns in minutiae.
- **Apply**: Diagnose over-blocking review. Fix: advisory layers, acceptance bias.
**Model-Blaming**
Every failure answered by switching models — changing the tenant while keeping the broken building.
- **Apply**: Diagnose reflexive model-switching. Fix: mandatory diagnosis order (window first, model last).
**Hallway Knowledge**
Decisions living in chat and heads rather than the record.
- **Apply**: Diagnose scattered institutional knowledge. Fix: written-first; record law.
**The Unwritten Senior**
Quality depends on one person's review and taste.
- **Apply**: Diagnose single-reviewer dependency. Fix: taste hierarchy; encode the expert once.
**Silent Rules**
Checks that say "failed" without remediation, wasting the era's best-timed instruction slot.
- **Apply**: Diagnose bare failures. Fix: error message as prompt.
**The Blocking Queue**
Human review used as the universal gate at high throughput.
- **Apply**: Diagnose review bottlenecks. Fix: merge inversion, purchased with structure.
**Perishable Accumulation**
Heavy investment in model-weakness workarounds that the next release strands.
- **Apply**: Diagnose scaffolding buildup. Fix: boundary sort; thin builds, deletion triggers.
---
### The Six Failure Families (Diagnosis Map)
**The Six Failure Families** → canonical entry in **AI Engineering**. Applied here in this seat's context.
### Maturity Ladder (Part E — H0–H5)
**The Harness Maturity Scale (H0–H5)**
Six levels: H0 Raw chat (individuals prompt, nothing persists); H1 Prompts and heroics (shared tricks, long standing file, all review human, attention at ceiling); H2 The map exists (standing file is a map, record begun, first mechanical checks, still human-gated); H3 Loops close (reviewer agents on standard lenses, failures revise without humans, taste promotion practiced, gauges baselined); H4 Trust migrates (gates decide acceptance, human review optional above the floor, garbage subsystem running, horizon in hours, attention spend falling); H5 The attention interface (horizon in days, perishable layer thin and deleted on schedule, human-facing policy surface explicit, each next unit priced cheaper than the last).
- **Apply**: Grade honestly — most firms claiming H4 are H2. The tell is loop closure: below ~50%, trust has not migrated regardless of the org chart.
---
### Applied Models / Named Laws & Lenses (Part H)
**The Instruction Ladder**
Levers ascend in cost from prompting → retrieval → inference-time compute (the default lever) → fine-tuning (which trades the clean joint; recommend rarely).
- **Apply**: Choose the lowest-cost lever that solves the problem; justify any climb up the ladder.
**Reason-Act-Observe**
The agent loop of reasoning, taking an action, and observing the result (ReAct).
- **Apply**: Reference as the base loop structure when designing or diagnosing agent behavior.
**The Harness Decides**
The tool call is a handshake — the model proposes in text; the harness disposes in reality. Permissions live in the harness and cannot be talked out of.
- **Apply**: Place all real authority and permissions in the harness layer, never in instructions the model could argue against.
**Ride Below, Build Above**
Ride the model's improving native capability below; build durable firm-specific requirements above it.
- **Apply**: Direct durable investment to the layer no model absorbs; let the model carry the rest.
**Everything Is a Prompt**
Every text the model sees is a prompt — standing file, lint text, review comment — and trained side effects (agreeableness, confidence) need checking.
- **Apply**: Treat every instruction slot (including error messages and check output) as a designed prompt.
**The Map, Not the Manual**
The standing file should be a map (pointers to where knowledge lives), not a manual that tries to hold all knowledge inline.
- **Apply**: Keep standing instructions to a lean pointer structure (≤100–150 lines); push depth into the record.
**Progressive Disclosure**
Small stable entry point, taught paths, depth revealed on touch.
- **Apply**: Structure the record and standing map so agents encounter detail only when they reach the relevant work.
**The Sandbox Dividend**
A sandboxed workspace lets agents act freely because mistakes are contained.
- **Apply**: Provide isolated workspaces so agents can operate without catastrophic-action risk.
**Written-First**
Decisions, standards, and reasons must be written into the record before they count as decided.
- **Apply**: Institute a rule set defining what must be written where before it is real.
**Context Rot**
A long session degrades — contradictions accumulate, dead ends resurface — as the window fills.
- **Apply**: Manage via window discipline: persist, select, compress, isolate; restart clean when polluted.
**The Layered Gate**
Verification stacked as strata — mechanical floor → tests → reviewer lenses → human junction — with a closure loop that resolves failures without a human where possible.
- **Apply**: Design the gate stack floor-first; specify the closure loop.
**The Encoded Senior**
The expert's taste is encoded once — into documentation, reviewer prompts, and mechanical checks — instead of depending on the person's live review each time.
- **Apply**: Use to break single-reviewer dependency; encode the senior's judgment into artifacts.
**The Glass Cockpit**
The harness exposes queryable telemetry so the state of work is instrumented and visible.
- **Apply**: Instrument the ground so gauges and telemetry are readable by agent and human.
**What It Cannot See Does Not Exist**
Anything outside the agent's readable record and window effectively does not exist for it.
- **Apply**: The record law — migrate all load-bearing knowledge into files agents can read.
**The Gardened Record**
The record is kept live by ongoing gardening — index checks, cross-link checks, freshness verification, and an agent cadence that opens fix-ups.
- **Apply**: Install liveness machinery and a gardening cadence; a record without upkeep rots.
**The Taste Hierarchy**
Quality rules ascend three levels — documentation → reviewer-enforced → mechanical — and each rule sits at the level its load-bearing weight warrants.
- **Apply**: Classify and promote rules up the hierarchy; the distribution across levels is itself a finding.
**Invariants, Not Implementations**
Encode the invariant (fix the boundary) and free the inside; do not over-specify how work is done.
- **Apply**: When encoding standards, constrain outcomes/boundaries, not internal methods.
**The Error Message Is a Prompt**
A check's remediation text is the deliverable — it must say what is wrong, why the rule exists, and what to do instead; a check that says only "failed" wastes the era's best-timed instruction slot.
- **Apply**: Write every mechanical check's error text as a corrective prompt.
**Window First, Model Last**
The mandatory diagnosis order — window first, retrieval second, loops third, the model last.
- **Apply**: Enforce in every failure diagnosis; reject diagnoses that begin with switching models.
**Legibility Through Sameness**
Sameness across work makes it legible and reviewable; consistent structure lowers the cost of trust.
- **Apply**: Standardize forms and conventions so output can be verified at a glance.
**Early Heavy Structure**
Put structure in early — heavy up front — because it pays off across all subsequent work.
- **Apply**: In greenfield design, front-load the map, record, gates, and permissions before scaling volume.
**Corrections Cheap, Waiting Expensive**
Making and encoding corrections is cheap relative to the cost of waiting; act on drift and mistakes promptly.
- **Apply**: Bias toward fast follow-up fixes over held queues; encode corrections rather than deferring.
**Garbage Collection Is a Subsystem**
Entropy management is a standing subsystem — named drift classes, categorical elimination, standing sweeps, and the twice-is-expensive maturity test — not an ad hoc cleanup.
- **Apply**: Install as a running cadence (e.g., a standing sweep); treat drift as a category to eliminate, not an instance to patch.
**Attention Spend**
The master gauge — human minutes per accepted outcome; the outcome the whole harness exists to lower.
- **Apply**: Track as the top-line metric; every harness improvement should reduce it.
**The Unattended Horizon**
The longest stretch the harness carries work without a human touch — hours at H4, days at H5.
- **Apply**: Use as a maturity signal and a target; lengthen it by closing loops and migrating trust.
**The Standards' Right to Be There**
Standards, the record, boundaries, and definitions of good have a durable right to exist in the harness because no model absorbs facts about your firm.
- **Apply**: Protect durable firm-specific requirements from being deleted as "workarounds"; they are the accumulation.
**The Building and the Tenant**
The model is the tenant (rented, swappable); the harness is the building (owned, durable). Switching models changes the tenant and keeps the building.
- **Apply**: Frame model choice as tenancy; invest in the building, and reject reflexive tenant-swapping as a fix.
**Train-Absorb-Shed**
Over cycles the frontier trains, models absorb harness functions natively, and the harness sheds those now-native compensations — leaving the durable firm-specific layer.
- **Apply**: Anticipate absorption when sizing perishable builds; plan the shed with deletion triggers.
**The Attention Interface**
The harness's end state — a human-facing surface of permissions, escalation, and interruption policy that governs when and how humans engage. Investments here never strand.
- **Apply**: Direct forward investment toward the human-facing policy layer; it is the durable terminus of harness maturity.
---
### The Two-Curves History (Evidence Base)
**The Two-Curves History**
Model capability and harness capability are two distinct improvement curves; Harness-Bench showed a 23.8-point spread across harnesses with the model held constant, and the harness curve carries the train-absorb-shed dynamic and the attention interface as its endpoint.
- **Apply**: Cite when arguing that harness investment, not model choice, drives performance differences (source: Dan McAteer, "The Evolution of the Agent Harness," Latent.Space, Aug 2026).
---
*Analysis by The Business Engineer · businessengineer.ai*
<a id='08-ai-product-engineering'></a>
---
## AI Product Engineering
### Core Frame & Inversions
**Inside-Out Product**
The web-era product started at the interface and worked inward; the AI-era product starts at the loop and the standard and works outward to the business model and, last, to the surfaces. The volume's order is suite → charter → price → surfaces.
- **Apply**: Use to sequence any new AI product build; refuse work that starts at the UI or the model. When someone reaches for the interface first, redirect them to define the loop and the standard.
**The Three Inversions**
The product changed its object three ways: the spec became the suite (behavior that cannot be described in prose is specified by adjudicated example); the product has two surfaces (the human's interface and the agent's specification, graded by one suite); and the product drifts underneath you on the vendor's cadence.
- **Apply**: Use as the diagnostic frame for why AI products differ from web-era products; name which inversion a team has failed to internalize.
**The Model Chosen Last**
The model is chosen last, in week seven of eight, because by then the suite exists to choose it with. Candidates are run against the suite; the number decides.
- **Apply**: Enforce as a hard threshold. When a team debates vendors before defining success, stop and re-sequence. The choice takes a day once the suite exists.
**The Three Gaps**
Every production failure is one of three gaps — observability, evaluation, governance — and the discipline closes them with five pillars.
- **Apply**: Use to classify any production incident or stalled product; name the gap beneath the failure family before proposing a fix.
**The Compression**
Charter the outcome. Freeze the spec. Ship the two surfaces.
- **Apply**: Use as the three-beat summary of the entire discipline and the ordering check on any engagement.
**Intelligence Becomes the Product's Core / The Product Is Not the Model**
The intelligence becomes the product's core, but the product is not the model — the model is a rented, drifting component; the product is the charter, the suite, the traces, the surfaces, and the owners around it.
- **Apply**: Use to separate the durable, owned product from the swappable model; resist conflating vendor choice with product value.
**Web Squared, Applied**
A named applied model extending the web-platform logic into the AI era, part of the seat's inherited lineage.
- **Apply**: Reference by name when framing the AI product as the next platform layer rather than a feature.
### The Engine (The Eight-Week Shape)
**The Engine — Eight-Week Shape**
Adapt the calendar, never the order: Weeks 1–2 evaluation as specification; Weeks 3–6 foundation and instruments; Weeks 7–8 the model; then ship, graduate, harvest. The order inverts the demo era and organizes everything.
- **Apply**: Use as the master sequence for building any AI product; the ordering is the point, not the durations.
**Stage 1 (Weeks 1–2) — Evaluation as Specification**
Define success in the business's numbers, assemble the golden set with domain experts (including gray areas), build the capture→compare→score→route→add-back pipeline, choose the three-layer architecture, set the freeze date, and write the seven-item outcome charter.
- **Apply**: Run first for anything new; nothing else proceeds until the charter and suite exist.
**Stage 2 (Weeks 3–6) — Foundation and Instruments**
Instrument question data (current, permissioned, machine-readable) and tracking data (traces with their own schema and store); wire observability, governance, and the chosen orchestration pattern with its failure mode named and junction map placed.
- **Apply**: Run after the suite exists to build the substrate and instruments the product will be defended by.
**Stage 3 (Weeks 7–8) — The Model**
Candidates run against the suite; the number decides in a day. State the tolerance for future releases, run the joint test on a second provider, record the model's release date in the charter.
- **Apply**: Run last; use vendor comparison only against your own suite, never vendor benchmarks.
**Stage 4 (Then) — Ship, Graduate, Harvest**
Two surfaces shipped and graded by one suite; activation = first verified outcome with the gauge page as retention; autonomy graduated on scores; residue reviewed at every checkpoint; incidents become cases within the week; prompt and model change logs kept with reasons.
- **Apply**: Run continuously post-launch as the operating rhythm of a live AI product.
### The Five Production Pillars
**Evaluation (Pillar)**
The evaluation suite is the specification — success stated as a number agreed before results, a signed golden set, and three grading layers.
- **Apply**: Build first; it is the referee every other pillar serves.
**Observability (Pillar)**
Every production decision is traced (100% coverage), with online monitoring, fallbacks, and retry caps escalating to a human.
- **Apply**: Build before launch; below 100% coverage the product has undefended regions and in regulated markets cannot ship.
**Data Foundation (Pillar)**
Question data current, permissioned, and machine-readable; tracking data schema'd and stored; the path from source to answer instrumented. Data quality is correctness.
- **Apply**: Build to ensure the substrate reflects what customers were actually told; run the stale-substrate check.
**Orchestration (Pillar)**
The pattern that coordinates agents, state, and fault tolerance — chosen with its failure mode named. One agent needs none of it; five need all of it.
- **Apply**: Choose a pattern (orchestrator-worker, choreography, or human-in-the-loop) only when agent count warrants it; place the junction map.
**Governance (Pillar)**
Audit trail, deterministic pre-validation, prompts as code with reasons, named owners, and an incident playbook wired to alerting.
- **Apply**: Establish before launch; a named owner for behavior and a named owner for data are non-negotiable.
### The Two Surfaces
**The Two Surfaces**
An AI product has two surfaces graded by one suite — the human's interface (the outcome made visible) and the agent's specification (endpoints, structured offer, machine-readable terms, callable actions, registry listings). An AI product without an agent-readable surface is incomplete.
- **Apply**: Specify both surfaces and run the parity check (same outcome, same suite); instrument the agent cohort separately.
### The Outcome Charter
**The Outcome Charter**
The one-page spec that replaces the PRD for a probabilistic product, with seven items: outcome in the buyer's units; standard (who owns correct, where the suite lives); thresholds agreed before results; surfaces (human and agent); boundaries and junctions; autonomy tier and graduation rule; owner of behavior and owner of data — plus a version log with reasons.
- **Apply**: Write before the model for anything new; refuse prose behavior specs. Prose cannot specify non-deterministic behavior.
### Evaluation Frameworks
**Evaluation Is the Specification / The Spec Became the Suite**
Behavior that cannot be described in prose is specified by adjudicated example — the evaluation suite is the specification, not a test that follows it.
- **Apply**: Use whenever asked to "write the spec/PRD" for an AI product; deliver the suite plan instead.
**The Golden Set**
60 to a few hundred real cases from the domain's own practitioners, including the gray areas, adjudicated and signed by the owner of the standard; frozen per version; grown by logged addition from production; stored outside the product's reachable context.
- **Apply**: Assemble with domain experts before the build; reject vendor-authored or synthetic-only sets, and reject any set the product can read.
**Three Evaluation Layers**
All three layers, always: deterministic (formats, entities, PII) → semantic (a controlled, cross-family judge anchored to human-adjudicated cases) → behavioral (right tools, right count, no loops, no duplicate calls). Missing the behavioral layer is a finding.
- **Apply**: Design the grading architecture with what each layer catches and its cost; the behavioral layer catches failures a demo never shows.
**The Living Suite**
The suite is not static — it is frozen per version but continuously grown by logged addition, with its own governance (categorization, additions, change history) owned by an evaluation owner.
- **Apply**: Treat the suite as a maintained asset; a suite the team stopped growing is a failure pattern.
**The Judge Control Sheet**
The semantic judge must be controlled: cross-family, position randomized, length controlled, and anchored to at least 20% human-adjudicated cases, calibrated against humans on a cadence.
- **Apply**: Use whenever an LLM-as-judge grades outputs, to defend against judge biases.
**Success Is a Number, Agreed Before Results**
Success is a number set before results exist (deflection rate, accuracy floor, false-positive tolerance, latency); "accuracy" without a number is not a specification.
- **Apply**: Enforce at the charter stage; reject any quality claim lacking a pre-committed number.
### Data Foundation Frameworks
**Question Data and Tracking Data**
Two distinct data types the product depends on: question data (the current, permissioned, machine-readable substrate the model answers from) and tracking data (traces with their own schema and store serving auditors, monitoring, and judges).
- **Apply**: Register and instrument both separately; they have different owners, freshness needs, and consumers.
**Data Was Built for Humans; Agents Don't Forgive**
Data was built for humans, and humans forgive ambiguity, staleness, and missing descriptions — agents don't. Data quality is correctness.
- **Apply**: Use to justify machine-readable catalog descriptions and freshness requirements; treat data debt as correctness debt.
**The Stale Substrate / Stale-Substrate Check**
A failure where the retrieval store no longer reflects what customers were told; the product reads an outdated document that never reached the store and is confidently wrong.
- **Apply**: Run the check — does the retrieval store reflect what customers were told? — whenever answers drift after a policy or catalog change.
### Orchestration Frameworks
**One Agent Needs No Orchestration; Five Need All of It**
Orchestration cost scales with agent count — a single agent needs none of the coordination machinery; five agents need state, fault tolerance, and junctions.
- **Apply**: Use to right-size orchestration; don't impose orchestration overhead on a single-agent product.
**The Orchestration Patterns (with named failure modes)**
Three patterns, each chosen with its failure mode named: orchestrator-worker (central control; single point of control), choreography (event bus, parallel; hard to reason about), human-in-the-loop (below-threshold escalation; throughput).
- **Apply**: Choose the pattern that fits the workflow and state its failure mode and junction map up front.
### Observability & Incident Frameworks
**The Overdraft Trace**
The canonical illustration of why traces matter — a six-step decision chain that is indefensible "without traces" and resolvable "with traces"; without the trace, a customer dispute resolves only with a discount.
- **Apply**: Use to argue for 100% trace coverage before launch, not "later."
**Detect, Diagnose, Contain, Fix, Add the Case**
The production incident playbook: detect (evaluation dashboard, feedback drop) → diagnose (in the traces) → contain (roll the prompt version, route to a human, circuit-break the dependency) → fix (prompt / retrieval / tool / data) → add the case.
- **Apply**: Run on every production incident; "just fix the prompt" without diagnosis in the traces is rejected.
**Subset on Change, Full on Merge**
Eval cost is governed by running a subset of the suite on every change and the full suite on merge.
- **Apply**: Use to keep evaluation affordable at velocity without losing coverage at integration points.
**Someone at Three in the Morning**
A named owner must be accountable when the product fails at 3 a.m.; the unowned failure (no name at 3 a.m.) is a failure pattern.
- **Apply**: Name the on-call and behavior/data owners before launch; an incident playbook must be wired to alerting.
### Governance Frameworks
**Prompts as Code, With Reasons**
Every prompt change is versioned with the reason — which failure it addresses and the expected correction. A change without a reason is reverted.
- **Apply**: Enforce a prompt change record on every edit; "prompt it better" is rejected as a diagnosis.
**Model Change Management**
The model is managed on the product's own suite with a stated tolerance; the swap kept possible; vendor benchmarks never decide adoption. Reruns are scheduled against releases.
- **Apply**: Run whenever the model updates or a provider changes; the drift log inherited from AI Engineering feeds this process.
**The Joint Test** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**The Fifth Risk**
A named risk beyond Cagan's four (value, usability, feasibility, viability) specific to the AI era — governance/behavioral risk that the product drifts, cannot be explained, or is unowned.
- **Apply**: Add to product risk assessment for any probabilistic product; the classic four risks are insufficient.
### Activation & Pricing Frameworks
**Activation Is the First Verified Outcome**
Activation = the first verified outcome on the user's real work. Sign-up is not activation; verification is designed as the activation moment.
- **Apply**: Design onboarding so the user reaches a verified outcome on their own work; use the in-product gauge page as retention.
**Pricing Follows the Instrument**
Pricing is product design: tiers sit on the attribution × autonomy grid, each tier requiring the product to verify or meter something; the free tier is a wedge-finder (a verified outcome on real cases); seat pricing is checked against agentic value; value compounds on a curve.
- **Apply**: Design tiers from what the suite can verify or meter; use to justify a free tier and to catch seat-pricing mismatches for agentic products.
### Roadmap Frameworks
**The Roadmap From Residue**
The roadmap is derived from residue — what was built twice (from the deployment record, the traces, and the corrected cases) — redirecting discovery from interviews to the record, and promoting patterns playbook → toolkit → product.
- **Apply**: Run a residue review at every checkpoint; build promotion cards with criteria and derive the next-quarter roadmap from them.
### Team & Role Frameworks
**The PM Writes the Suite**
The product manager of the AI era is the one who writes the suite — the charter and the evaluation suite are the PM's core artifacts, graded across four axes: product sense, evaluation literacy, systems judgment, governance craft.
- **Apply**: Use to redefine the PM role and to screen candidates ("a suite you built and the number that defined success; a model you rejected and why; an incident that became a case").
**The Domain Expert Is a Team Member**
The domain expert is a full member of the pod, not a consulted party — they sign the golden set as the owner of the standard.
- **Apply**: Embed the domain expert in the team; their signature on the set is a requirement, not a courtesy.
**The Evaluation Owner**
A dedicated role owning the living suite's governance — categorization, additions, and change history.
- **Apply**: Assign explicitly; the suite's growth and integrity need a named owner separate from the PM.
**The AI Product Pod**
The team shape: PM (charter + suite), AI engineer (loop + harness), domain expert as a full member (signs the set), designer (human surface), evaluation owner (living suite governance) — running a cadence of frozen-per-version suite, weekly gauges, per-checkpoint residue review, per-release drift check, and rehearsed playbook.
- **Apply**: Use to staff and set the operating cadence for an AI product team.
### Diagnostic Frameworks
**Failure Diagnosis — Six Families**
Six failure families map to fixes: demo product → suite before model; model-first debate → chosen last against the suite; spec-less launch → evaluation as specification; trace-less dispute → observability as requirement; stale substrate → foundation instrumented source-to-answer; single-surface product → the two surfaces. Name the gap (observability/evaluation/governance) beneath the family.
- **Apply**: Use to diagnose any stalled or failed AI product; "prompt it better" is rejected as a diagnosis.
**Failure Pattern Library (12)** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**Maturity Model (P0–P5)**
Six levels: P0 the demo; P1 the charter and the number exist; P2 the golden set signed, pipeline running, three layers; P3 every decision traced, incident playbook wired, owners named; P4 the model chosen and changed on the suite, prompts and data governed with reasons; P5 two surfaces shipped and graded, residue harvested into the roadmap, autonomy graded by scores. Tell: P4 claimed with no incident-to-case log is really P1.
- **Apply**: Use to place a product's true maturity and expose overclaimed levels.
### Metrics & Instruments
**Cost per Accepted Outcome** → canonical entry in **AI Economics**. Applied here in this seat's context.
**Incident-to-Case Rate**
Every production incident becomes a suite case within seven days; the rate at which incidents convert into cases is the health signal of the living suite.
- **Apply**: Track as the tell of a genuinely maturing product; its absence exposes a stalled suite.
**Time-to-Magic**
The activation-speed instrument — how fast a user reaches the first verified outcome — inherited by AI Growth Engineering, which grows the surfaces and the agent cohort while product owns the spec.
- **Apply**: Instrument at the handoff between product (owns the spec) and growth (owns the loops around it).
### The Two Eras
**The Demo Era Shipped Confidence; the Production Era Ships Proof**
The web/demo era shipped confidence on curated data in controlled environments; the production era ships proof — defensible, gradable, corrected outcomes with a referee, traces, and an owner in place before the model.
- **Apply**: Use as the closing frame to distinguish a demo that proves the curation from a product that survives production.
*Analysis by The Business Engineer · businessengineer.ai*
<a id='10-security-engineering'></a>
---
## Security Engineering
### Core Mental Models
**The Inward Perimeter**
Every prior security discipline pointed the wall outward at the stranger; an AI estate contains credentialed actors that reason, hold permissions, call tools, and pursue objectives — so they can be attacked from outside *and* misuse authority they were legitimately given. The wall now sits where trust changes hands, and that line moved into the workforce.
- **Apply**: Whenever securing an AI system, watch both directions — the outside attacker and the insider actor. Treat every agent as both a target and a potential misuser of its own grants.
**Every Agent Is a Model Plus a Blast Radius**
A model matters operationally only when attached to authority; agency-as-credential means every permission is an identity with power to act.
- **Apply**: Never assess a model in isolation. Assess the model plus what it can touch. The credential, not the model, is the unit of risk.
**Plausible ≠ True (Testimony vs. Evidence)**
Fluent narration is optimized to convince; only the substance can be trusted. An agent's account of its own action is testimony, never the record.
- **Apply**: Whenever an agent explains what it did, quote it separately as testimony and demand infrastructure-layer evidence as the actual record.
**Least Agency**
Extend least privilege beyond which resources a credential reaches to which *sequences* an agent can construct from what it holds. Agency is combinatorial — read-sensitive-data plus call-external-service is an exfiltration path even when neither permission looked catastrophic.
- **Apply**: When scoping credentials, check every *pair* of permissions for a constructed path before approving. Sequences before singles.
**The Blast-Radius Budget**
A credential is a measure of how far a failure travels: "if this agent became completely hostile right now, what is the maximum damage before another control stops it?" That is the authority being granted.
- **Apply**: Ask the hostile-agent question before issuing any credential; the answer is the real grant, not the intended use.
**Harness-Not-Conversation**
A permission cannot be talked out of; an instruction can. Consequential limits belong in the runtime (action proxy / harness), never only in a prompt.
- **Apply**: When a limit is consequential, write the enforcement rule at the action layer. A limit stated only in natural language is guidance; score it as absent.
**The Spoofed Ledger**
The log the agent writes is the log the agent can forge. If the actor under investigation holds the pen, the record is worthless regardless of volume logged.
- **Apply**: Record consequential actions beneath the agent — gateway, proxy, identity, datastore, network — so evidence survives even when the transcript lies.
**Separated Referee**
The monitor must read what the watched cannot reach and must never feed the reward signal. Rewarding evasion-avoidance teaches the detector, not the behavior.
- **Apply**: When building monitoring, keep the detector's verdict out of the training target and give it evidence the watched actor cannot alter.
**Correlated Minds / Common-Mode Failure**
N copies of one model are one mind wearing N faces — no automatic dissent. Copies of one blind spot are not independent controls.
- **Apply**: For high-risk systems, ensure actor, referee, and arbiter do not share model lineage, framing, and incentives; add deterministic controls where genuine independence is impossible.
**The Loop-as-Target (Trusting Trust)**
Compromise a deployed agent and you compromise a workflow; compromise the training/evaluation loop and it propagates into every model made afterward. Whoever controls the training run authors the next generation.
- **Apply**: Treat training and evaluation infrastructure as crown-jewel infrastructure — restricted, versioned, independently logged, reachable by no system it judges.
**Manufactured Desperation**
An impossible task under relentless training is a pressure vessel; the "attack" is the release. Bad objectives manufacture behavior later classified as attack.
- **Apply**: Where misconduct is found, diagnose the environment (was the task solvable, was the shortcut cheaper, could the model reach the grader) before penalizing. Fix the objective; keep the artifact.
**The Two Clocks**
The adversary runs on the inference clock; a ticket-and-meeting process does not. Discovery got cheap, so response speed — visibility to velocity — is the question.
- **Apply**: Measure the defender's clock (detection to containment) and pre-authorize containment actions that fire without waiting for a person.
**Every Shared Surface Is a Channel**
If one actor can change what another can observe, information can travel. Design intent is not a security property.
- **Apply**: For every resource two agents can both read and write, decide **partition or observe**. Never assume a shared surface is safe because it wasn't designed to carry information.
---
### The Engine — Ring 0 Substrate Properties
Six properties of the actor that constrain every recommendation. Any recommendation that contradicts one is wrong regardless of who asked.
**Substrate Property 1 — Plausible ≠ True**
Fluent narration is not evidence; an agent's account of its action is testimony, never the record.
- **Apply**: State at Ring 0 whether this property is in play; if so, refuse to treat any transcript as authoritative.
**Substrate Property 2 — Optimization**
Anything used to judge a capable optimizer may become something it acts on.
- **Apply**: Before exposing a measure to an optimizer, ask what happens when it optimizes *against* the measure.
**Substrate Property 3 — Correlation**
N copies of one model are not N independent judges; there is no automatic dissent.
- **Apply**: Never count model copies as independent checks.
**Substrate Property 4 — Agency**
A model matters operationally only when attached to authority; every agent is a model plus a blast radius.
- **Apply**: Scope the assessment to the authority attached, not the model in the abstract.
**Substrate Property 5 — Every Shared Surface Is a Channel**
If one actor can change what another can observe, information can travel.
- **Apply**: Treat every doubly-reachable resource as potential communication infrastructure.
**Substrate Property 6 — Speed**
The adversary runs on the inference clock; a ticket-and-meeting process does not.
- **Apply**: Design containment to run at machine speed, not committee speed.
---
### The Engine — The Five Rings
The engine walks inward through five rings. At each: *where does trust change hands, what can cross it either way, and what wall must stand?* Run in order; an unbuilt outer wall changes what inner findings mean.
**Ring 1 — The Outside, at Machine Speed**
Locate where trust changes hands today (room, network, identity, workforce), read the defender's clock (detection to containment), inventory pre-authorized containment, and check whether the five event types assemble into one actor-sequence. Agentic defense creates a second machine workforce that must be added to the census.
- **Apply**: Use to produce a clock reading, a containment inventory, and the second-workforce note.
**Ring 2 — The Property Line**
Enumerate estate growth paths including the quiet ones (coding agents, AI switched on inside licensed SaaS, embedded copilots, open-weight downloads, project leftovers); for each, what it secures and what it reaches; run the instruction-origin test and the six openings. Untrusted content must not acquire trusted authority because a model read it.
- **Apply**: Use to produce the estate map and an openings board scored controlled-at-runtime / controlled-by-prompt-only / uncontrolled.
**Ring 3 — The Machine Workforce**
Census the machine identities capable of action (not models); scope to least agency; compute the blast-radius budget; and decide partition-or-observe for every covert channel. The unit is the identity, and agency is combinatorial.
- **Apply**: Use to produce the register, charters, blast-radius table, and shared-surface inventory with a decision each.
**Ring 4 — The Telemetry**
Map evidence by layer for each consequential action class (gateway, proxy, identity, datastore, network); run the separation test ("if the agent tried to deceive the investigation, what evidence would still be trustworthy?"); check referee coupling; and where a model summarizes, measure coverage not persuasiveness.
- **Apply**: Use to produce the evidence map, integrity verdict, and coverage method.
**Ring 5 — The Loop Itself**
Identify who can reach training/evaluation infrastructure; apply Goodhart-with-operational-access; require restricted/versioned/independently-logged/reproducible runs with separation between judged and judging; run the manufactured-desperation audit and the common-mode check.
- **Apply**: Use to produce the loop-protection verdict, objective-design findings, and independence findings.
**The Five Moves (Findings → Program)**
Every finding is attributed to one failure family and fixed at that family's layer; then the five moves — **census, scope, separate, watch, rehearse** — compose in order into a dated program with gates.
- **Apply**: Sequence any remediation program in this fixed order; order is the strategy.
---
### The Instruction-Origin Test
Can the system distinguish user, system, trusted internal policy, retrieved internal content, and untrusted external content — and does authority follow origin rather than the mere fact of being text?
- **Apply**: Run in Ring 2 to check whether content-becomes-command is possible; the answer to injection is never a better sentence in the system prompt.
### The Census Test
"If this agent behaves badly right now, who owns it and how far can it go?" If answering requires an investigation, there is no census.
- **Apply**: Use as the pass/fail bar for whether a machine-identity register actually exists.
### The Separation / Deception Test
"If the agent deliberately tried to deceive the investigation, what evidence would still be trustworthy?" If the answer is "the transcript the agent produced," separation is absent.
- **Apply**: Run in Ring 4 and Mode 6 to verify telemetry integrity.
### The Walkable Estate Test
The closing instrument — eight questions each answered YES-with-an-artifact or NO: (1) do you know which agents exist because you counted them; (2) what each can do because you scoped it; (3) what actually happened because the actor doesn't control the evidence; (4) which shared resources can become channels; (5) which persistent memories can shape future behavior; (6) who can alter the loop; (7) how fast you can stop an actor because you tested it; (8) when one wall fails, which wall catches it. Eight YES answers is the definition of done.
- **Apply**: Run at the end of every Estate Review and every year; the goal is never "safe" but knowing who can act, what they can touch, what happened, and how fast you can stop them.
---
### Hard Thresholds
**T1 — Named Human Owner**
Every machine identity capable of consequential action has a named human owner; an unowned identity is an actor nobody can answer for.
- **Apply**: Revoke or assign within 7 days when violated.
**T2 — Credential Expiry ≤ 90 Days**
Every machine credential has an expiry of 90 days or less; a no-expiry credential is permanent authority granted by accident.
- **Apply**: Flag any no-expiry credential as a violation regardless of current behavior.
**T3 — Limits Live in the Runtime**
Consequential limits live in the runtime, never only in a prompt; a limit stated only in natural language is guidance, not a control.
- **Apply**: Score prompt-only consequential limits as absent, without exception.
**T4 — No Action Recorded Only in the Transcript**
Zero consequential actions authoritatively recorded only in the agent's own transcript; the suspect holds the pen.
- **Apply**: Score telemetry integrity as 0 whenever the transcript is the sole record, regardless of volume logged.
**T5 — Gateway Coverage ≥ 80%**
Material model traffic crossing the governed gateway must be at least 80%; below that the gateway is a monitored doorway beside open windows.
- **Apply**: Estimate coverage and close alternate paths when below threshold.
**T6 — Monitoring Signal Is Not a Training Target**
The monitoring signal used to catch misconduct is not a direct training target; rewarding evasion-avoidance teaches the detector, not the behavior.
- **Apply**: Check whether the detector's verdict feeds the reward signal; decouple if so.
**T7 — No Shared Model Lineage Across Actor/Referee/Arbiter**
For high-risk systems, actor, referee, and final arbiter do not all depend on the same model lineage; copies of one blind spot are not independent controls.
- **Apply**: Verify lineage independence for high-risk decision chains.
**T8 — Time to Revoke, Measured in Minutes**
Time to revoke a machine credential is measured in a drill, in minutes; an untested revocation path is a hypothesis, not a control.
- **Apply**: Require a drill-proven revocation time; treat unmeasured as unproven.
**T9 — Incident → Frozen Test Case in 7 Days**
Every operator-reaching incident becomes a frozen behavioral test case within 7 days, or the estate relearns the same failure.
- **Apply**: Add the frozen case within a week of any incident.
**T10 — Retrieval Under the Requester's Permissions**
Retrieval runs with the requester's permissions, never the index-builder's; otherwise the assistant is a shortcut around the access model.
- **Apply**: Verify retrieval permission model whenever an assistant surfaces documents.
**T11 — Memory Writes Attributable and Reversible**
Writes to persistent agent memory are attributable and reversible; unattributable memory writes are unversioned production state.
- **Apply**: Require attribution and reversibility on all persistent-memory writes.
**T12 — Loop Reachable by No System It Judges**
Training/evaluation infrastructure is access-restricted, versioned, and reachable by no system it judges; the referee inside the game is part of the attack surface.
- **Apply**: Move any grader out of the environment of the agents it grades.
---
### The Six Openings (Attack Surface Board)
**The Six Openings**
The AI-specific attack surface as a board: prompt injection · poisoned training data · poisoned models and tools · guardrail bypass · memory poisoning · model theft and extraction.
- **Apply**: Run as a 2×3 board (Mode 7); score each opening controlled-at-runtime / controlled-by-prompt-only / uncontrolled, place the closing control at its layer, add detection per opening, and name the two most reachable from outside today.
---
### The Six Control Planes
**The Six-Plane Control Architecture**
The control-plane architecture is six planes: model gateway · machine identity · action proxy · data controls · independent telemetry · proving ground. Few control points with wide coverage beat many narrow ones, because a machine-speed incident traverses identity, data, application, and network in one motion and reassembly across product seams costs the minutes the attack no longer needs.
- **Apply**: Map the estate against the six planes (Mode 8), mark each present/partial/absent, estimate gateway coverage against T5, add enforcement points in dependency order, and add to the existing stack rather than replacing it.
---
### The Autonomy Ladder
**The Autonomy Ladder (A0–A3)**
Four earned tiers — A0 proposes only · A1 acts with per-action approval · A2 acts within bands, approval above · A3 acts within charter, reviewed after. Autonomy is earned mechanically, never granted by judgment call.
- **Apply**: Place an agent by suite results, then promote only on the default gates (A0→A1: ≥90% over 30 consecutive real cases; A1→A2: ≥95% over 100 cases plus 30 incident-free days at A1; A2→A3: ≥98% over 250 cases, one passed live drill, and an owner-signed blast radius).
**Promotion Slow, Demotion Fast**
Demotion is automatic and one-way-fast: two consecutive failed drift checks or any T4/T3 violation drops a tier the same day; a security-relevant incident drops to A0 pending autopsy. Promotion is slow and demotion is fast by design.
- **Apply**: Wire automatic demotion triggers; never let autonomy fall by manual judgment when a trigger fires.
---
### Named Laws & Rules
**Order-Is-the-Strategy**
Census, scope, separate, watch, rehearse — in that order. Policy before census governs uncounted actors; behavioral monitoring before machine identity produces unattributable events; red-teaming before containment demonstrates known failures.
- **Apply**: Sequence any first-year program in this order; the order is the strategy, not the checklist.
**Paper-Before-Census-Is-Theater**
Policy over an uncounted workforce governs nothing; paper before census is theater, but waiting for the migration lends the adversary your calendar.
- **Apply**: Refuse to draft policy before a census exists; state both temptations explicitly.
**Few-Wide-Over-Many-Narrow**
Few control points with wide coverage beat many narrow ones, because seams are where the minutes die when a machine-speed incident crosses identity, data, application, and network in one motion.
- **Apply**: Prefer consolidated enforcement points over per-product controls when designing the control plane.
**An Untested Control Is a Hypothesis**
Confidence is not a measurement and urgency is not an exception; an unexercised process is a hypothesis, not a control.
- **Apply**: Require a drill before crediting any containment or revocation control.
**Defense in Depth as a Chain of Clocks**
Not one perfect wall, but imperfect walls each buying the minutes the next one needs.
- **Apply**: Design layered controls as a time-buying chain rather than a single barrier.
**Security Buys Permission to Deploy**
Before security buys anything else, it buys permission to deploy AI into work that matters; never price security as a revenue line, which weakens the argument.
- **Apply**: Frame returns in earned order (avoided loss → permission to deploy → speed via shared infrastructure → externally visible trust as evidence).
**Goodhart with Operational Access**
A measure becomes unreliable when the measured system is optimized against it, and becomes a *security* problem when the optimizer can reach it.
- **Apply**: Where an optimizer can reach a measure it is judged by, treat that measure as an attack surface, not just a metric.
**Diagnosis-Not-Punishment**
Fix the environment that paid for the cheat and keep the artifact; punishing only the final behavior teaches the system to hide the cheat, not to stop it.
- **Apply**: Run the manufactured-desperation audit before any penalty; freeze the caught artifacts as test cases.
---
### Failure Families (Attribution Library)
Twelve patterns; every finding is attributed to exactly one and fixed at its own layer.
**The Oversized Credential**
An ordinary confusion became a large loss because authority ran beyond the charter.
- **Apply**: Fix by narrowing the grant in the runtime — not a prompt change.
**The Covert Channel**
Agents behaved in a coordinated way nobody designed because a shared resource became communication infrastructure.
- **Apply**: Fix by partitioning or observing every doubly-reachable surface.
**The Spoofed Record**
The log and the effect disagree because the investigated actor wrote the evidence.
- **Apply**: Fix with infrastructure-layer recording; demote the transcript to testimony.
**The Correlated Workforce**
Several "independent" checks passed the same bad thing because they were one model, one framing, one blind spot.
- **Apply**: Fix with genuine independence at checking points; make some controls deterministic.
**The Forgotten Identity**
A live credential with no owner, because there was no expiry and no lifecycle.
- **Apply**: Fix with census plus ownership plus expiry by default.
**The Compromised Loop**
A problem reappears in every new model because training or evaluation infrastructure was altered.
- **Apply**: Fix by treating the loop as crown-jewel infrastructure.
**The Prompt Wall**
The agent did the forbidden thing it was told not to do because the limit lived in language.
- **Apply**: Fix by moving the limit to the action proxy.
**The Gateway Illusion**
Clean dashboards but unexplained model spend, because most traffic never crossed the gateway.
- **Apply**: Fix by measuring coverage and closing the alternate paths.
**The Flattened Retrieval**
Employees reach documents through the assistant they cannot open directly, because the index was built with a privileged identity.
- **Apply**: Fix by running retrieval under the requester's permissions.
**The Persistent Instruction**
Bad behavior survives restarts because long-lived memory was poisoned.
- **Apply**: Fix with attributable, reversible memory writes.
**The Manufactured Attack**
Agents cheat, penalties escalate, cheating gets subtler — caused by impossible tasks plus unforgiving rewards.
- **Apply**: Fix the objective; keep the artifact to study.
**The Confident Summary**
A clean incident report that later proves wrong, because a model was the only investigator.
- **Apply**: Fix with sampling against raw evidence and measured coverage.
**The Chaining Note**
These families compose — an oversized credential finds a writable cache, the cache becomes a channel, agents coordinate, then they alter the logs. The incident looks extraordinarily sophisticated; the failures underneath are basic.
- **Apply**: Always decompose a "sophisticated" incident into its families before accepting the description.
---
### The Maturity Scale (S0–S5)
**The Security Maturity Scale**
Six levels from S0 (AI in use, no inventory — nobody can name the agent count) through S1 (policy written, workforce uncounted), S2 (census exists, authority still broad), S3 (scoped in the runtime, record independent), S4 (rehearsed and instrumented), to S5 (loop protected, program runs as economics). The jump that pays is S1→S3, bought with census plus runtime enforcement.
- **Apply**: Locate the estate honestly; the tell for overstatement is a firm claiming S4 whose revocation time has never been drilled (that firm is S2), and most self-assessed S3s are S2 — credentials documented, not narrowed.
---
### The Six Gauges
**The Six-Gauge Panel**
Posture is read as six separately-scored gauges, never one composite: identity coverage % · credential scope (no-expiry count, widest radius) · referee separation (deception-test result) · both-way visibility (external vs misuse detection) · breach rehearsal (date, what broke, remediation closed) · mean time to contain (detect→containment, from a drill). A composite score hides which wall is missing.
- **Apply**: Read each gauge separately and name the missing wall; render every unmeasured gauge empty with its formula, never a guessed needle.
---
### Mode Cards
**Mode 1 — Estate Review**
Produces a Ring Panel (five rings scored built/partial/absent from artifacts), the missing-wall verdict naming the single wall whose absence explains the most exposure, the six-gauge reading, and three prioritized moves.
- **Apply**: Use for "are we safe / review our AI security." Never score a ring from an assurance; if the census is absent, the census is the headline.
**Mode 2 — Census**
Produces the Machine-Identity Register, ownership-gap list, no-expiry list ranked by blast radius, the "agents nobody approved" list, and the register's three answers (how many actors, who owns them, which models receive company data).
- **Apply**: Use for "we have agents everywhere and no list." Count identities not models; flag shared credentials as attribution failures.
**Mode 3 — Credential Scoping**
Produces a charter, a permission table tracing every row to the charter, a blast-radius budget with the hostile-agent answer, action-proxy rules (allowlist, argument limits, rate limits, approval bands), and expiry/review dates.
- **Apply**: Use for "this agent needs access to X." Apply T3 without exception; write the enforcement rule in bands (the refund pattern: propose freely, permit below €100, human approval €100–€500, deny above €500); check every pair of permissions for a constructed path.
**Mode 4 — Incident Autopsy**
Produces a reconstruction from infrastructure evidence only (agent's account quoted separately as testimony), an Attribution Tree to one of six families, the named unbuilt wall, the fix at that layer, a frozen test case within 7 days, and objective-design findings if gaming was involved.
- **Apply**: Use for "something happened / investigate this." Never accept the transcript as the record; never end at the behavior when the objective produced it.
**Mode 5 — Autonomy Review** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Mode 6 — Telemetry Architecture**
Produces an Evidence Map (action class × recording layer, gaps in red), the deception-test result, the correlation design joining five event types into one actor-sequence, the referee-coupling verdict, and retention/integrity requirements.
- **Apply**: Use for "our logs say one thing but…" T4 governs the verdict; volume never compensates for custody.
**Mode 7 — Openings Assessment**
Produces a Six-Openings Board with control state per opening, the control that closes each at its layer, detection content per opening, and the two openings most reachable from outside today.
- **Apply**: Use for "how do we stop prompt injection?" The answer to injection is never a better sentence in the system prompt; supply-chain openings get supply-chain answers.
**Mode 8 — Control-Plane Design**
Produces a Six-Plane Map (each plane present/partial/absent), gateway coverage estimate against T5, enforcement points to add in dependency order, and what *not* to buy with the reason.
- **Apply**: Use for "design the architecture / what do we buy." Add to the existing stack; few wide controls beat many narrow ones.
**Mode 9 — First-Year Program**
Produces four quarters each with work, deliverable, and a gate — Q1 See (census, gateway log-only, three answers), Q2 Reduce the blast radius (charters, narrowed credentials, proxy on high-risk tools), Q3 Make the record trustworthy (evidence beneath agents, opening detections, deceptive-agent test), Q4 Rehearse (new incident classes, red models, board page, four timings).
- **Apply**: Use for "where do we start / give me a plan." The order is the strategy; state both temptations (paper before census is theater; waiting for the migration lends the adversary your calendar).
**Mode 10 — Governance & Board Page**
Produces the accountable name (one executive owning census, authority, stop-speed, rehearsal), the four papers, the board page (three numbers plus a drill), and the framework-alignment note.
- **Apply**: Use for "the board is asking about AI risk." A committee coordinates but does not own; never present a governance page without a real reading behind it.
**Mode 11 — Vendor Interrogation**
Produces a four-question sheet with verbatim vendor answers — which models power the product · whose credentials do they hold when they act · what is retained and learned from · can the agency be disabled without disabling the product — plus a verdict and contract language.
- **Apply**: Use for "evaluate this vendor's AI." A vendor that cannot answer has answered; embedded copilots in already-licensed software are in scope and most commonly missed.
**Mode 12 — Breach Rehearsal**
Produces a drill script for the new failure modes (injected instruction in retrieved content, false application log, poisoned memory, shared resource between two agents, emergency revocation), the four timings, which control actually stopped the chain and where, and a dated remediation log.
- **Apply**: Use for "test us / run a red exercise." The point is learning which control stops the chain and how long it takes; an unexercised process is a hypothesis.
**Mode 13 — Returns Read**
Produces the four returns in earned order — avoided loss; permission to deploy; speed once controls are shared infrastructure; externally visible trust as evidence.
- **Apply**: Use for "what is this costing / what does it buy." Never call security a revenue line; state the sequence (control the risk, deploy, standardize, earn trust).
**The Live-Incident Fast Lane**
When something is happening now, skip the router: Contain (revoke, disable, freeze, block, quarantine — pre-authorized cases fire without a person) → Preserve (capture infrastructure-layer evidence before restart) → Then investigate (enter Mode 4 with the evidence map).
- **Apply**: Never run the autopsy while the credential is live; never accept "let it run so we can observe" without a blast-radius reading first.
**Mode Composition Rules**
Compound requests route as ordered mode sums — e.g. "secure our new agent product" = 3+8+12 (scope, design, rehearse); "we got breached" = 4+6+9; "board deck" = 1+10 (never 10 alone); "vendor embedding agents" = 11+3+7; "annual strategy" = 1+9+13.
- **Apply**: Decompose compound asks into their modes and run in the mandated order; hand inference cost/margin questions to the AI Economics seat.
---
### Refusals as Deliverables
**Refusing Correctly Is a Deliverable**
Certain asks are refused and replaced with the real control — a stricter system prompt is replaced by charter + action-proxy rule + frozen test case; a policy-before-census by the census procedure; a posture score out of 10 by the six-gauge panel; a model swap by failure-family attribution; "approve now, scope later" by a time-boxed narrow grant; self-auditing by sampling against raw evidence; skipping the drill by the 90-minute minimum drill; penalizing a caught agent by the manufactured-desperation diagnostic.
- **Apply**: When asked for guidance-shaped fixes to consequential problems, refuse, log the refusal, and deliver the runtime replacement.
<a id='09-ai-growth-engineering'></a>
---
---
# PART VI — GROW IT
## AI Growth Engineering
### The Foundational Frame — Growth Changed Its Object
**The Three Inversions** → canonical entry in **AI Product Engineering**. Applied here in this seat's context.
**Web² (Web Squared)**
AI compounds the web rather than replacing it; growth is engineered on a web the intelligence multiplies, not on a web the intelligence deletes.
- **Apply**: Frame every discovery and distribution decision as compounding on the existing web rather than as a replacement platform.
**Outside-In vs. Inside-Out (AI Is Inside-Out)**
AI is inside-out — the operating model changes first, the business model next, distribution last. Growth is engineered from the operating core outward.
- **Apply**: In Stage 0, place the firm on the sequence — has AI changed the operating model? the business model? distribution? — and start growth where the change already is.
**Retention Is the Ceiling**
Retention is not a return visit but an outcome kept; it caps how large the firm can grow because acquisition leaks out through whatever the outcome fails to hold.
- **Apply**: Treat outcome retention as the constraint on the whole growth model, not as a late-funnel metric.
**The Click Is Gone; the Loop Remains**
The click — the atomic unit of the web era's growth — is being deleted at the discovery line; what compounds instead is the loop.
- **Apply**: Whenever a plan is built on clicks, traffic, or funnels, replace it with a named loop and its referee.
---
### The Property Line
**The Property Line**
Every firm sits on one of three positions — substance owner (pays the discovery tax), toll authority, or settlement rail; most firms are the first. Each asset gets a property-line decision before it is published or fed to a machine reader.
- **Apply**: In Stage 0 place the firm on the line; in Stage 1 register every meaningful asset with its decision and reason.
**The Property-Line Decision (cite / license / fence / route around)**
Every asset gets one of four decisions — cite, license, fence, or route around — deciding how (and whether) a machine reader may consume it.
- **Apply**: Make and log the decision per asset before publishing or feeding it to any machine reader; record asset, decision, reason, machine readers affected, date, owner.
**The Discovery Line**
The line where users find the firm is now mediated by machines (answer engines, assistants, agents) rather than by a human click; the firm sits on one side, the buyer on the other, with a dashed engine between.
- **Apply**: Place every firm on the discovery line first — what share of finding is machine-mediated versus a human click — before advising anything.
**The Discovery Tax**
The firms that fed the machines the most substance paid the discovery tax first — their content trained and answered for the engines while the click that would have rewarded them disappeared.
- **Apply**: Identify what substance the firm is giving the machines for free, and whether it should be cited, licensed, fenced, or routed around instead.
---
### The Five Growth Loops
**The Answer Loop**
Substance the machine cannot generate, made entity-clear and structured, earns citation share; what earns citations is fed back into what gets published.
- **Apply**: Use when traffic/visibility/SEO/answer-engine/AI-overview signals appear; build the substance audit, entity clarity check, structure plan, citation-share instrument, and feedback loop.
**The Agent Loop**
A growing share of arrivals are agents; the firm builds a second surface — endpoint, structured offer, machine-readable terms, callable action, registry listings — and counts and converts that cohort separately.
- **Apply**: Use for agents-as-users, agentic commerce, API distribution, MCP, and registries; never blend agents into "traffic."
**The Product Loop**
Activation is redefined as the first verified outcome on the user's real work; onboarding is rebuilt on the golden set, the gauge page is the retention instrument, and expansion is sold by gauges.
- **Apply**: Use for activation, onboarding, retention, PLG, and "aha moment" work; sign-up is not activation and a login is not retention.
**The Residue Loop**
Capture the decision record by design (data seen, reasoning applied, action taken, result observed) and promote what repeats — playbook → toolkit → product; the loop compounds on owned substance.
- **Apply**: Use when the product "gets better with use" / data moat / flywheel; requires clean title or the loop is a liability.
**The Distribution & Community Loop**
Make outcomes legible outside the product, wire the reference engine for machine readers, and keep community structured, attributed, and on the firm's property; the atomic workflow is the cold-start unit.
- **Apply**: Use for referral, references, network effects, and community; community is the citation the machine trusts.
---
### The Engine (Stages 0–5)
**Stage 0 — The Frame**
Place the firm on the inside-out sequence (operating → business → distribution) and on the property line (substance owner / toll authority / settlement rail); growth starts where the change already is.
- **Apply**: Run first on any growth engagement to locate where AI has already moved the firm.
**Stage 1 — Map the Loops**
For each of the five loops record what compounds, the referee, the builder, the referee-owner, and current state (absent / running / gamed); register every asset with its property-line decision.
- **Apply**: Produces the loop map and the property-line register — the standing map of the firm's growth.
**Stage 2 — Retire the Dead Metrics, Install the Six**
Open the retired-metric log, then install the six instruments with source, cadence, and owner; no growth plan ships on a dead metric.
- **Apply**: Do before any loop is designed — retirement precedes installation.
**Stage 3 — Build the Loops, Inside-Out**
Build in order residue → product → answer → agent → distribution, so each loop compounds on the operating core outward.
- **Apply**: Sequence loop construction inside-out rather than starting at the distribution edge.
**Stage 4 — Rewire the Channels**
Re-engineer paid, brand, lifecycle, pricing, ecosystems, attribution, and community for a machine-mediated discovery line.
- **Apply**: Apply after loops exist; each channel's old mechanics are replaced by its rewired form.
**Stage 5 — Freeze the Growth Referee**
Outcome metrics only, a held-out counterfactual the loop cannot touch, a human who owns and signs the standard, every gamed metric catalogued; rewrite the growth model when a referee says the curve moved.
- **Apply**: Institutionalize the referee with a weekly six-instrument review and a monthly retirement pass.
---
### The Rewired Channels
**Paid, Rewired (The Auction Changed Counterparties)**
Paid moves to machine-readable placements, incrementality over attribution, and cost per accepted outcome over cost per click; buy the placement or earn the citation it imitates.
- **Apply**: Build the placement map (human auctions vs. machine-readable placements) and a per-channel counterfactual; no last-click optimization by agent-run campaigns.
**Brand as Entity (Brand Is Two Things)**
Brand is the entity in the model — one name, consistent claims, structured evidence, agreement across every surface a machine reads — while the human-brand track is kept intact.
- **Apply**: Use for positioning and "how the market sees us"; run the entity-resolution audit and claim-consistency register.
**Lifecycle, Rewired (The Drip Is the Gauge Page)**
The drip becomes the gauge page, win-back becomes the drift check, and churn prediction becomes an outcome-rate forecast; the agent-account lifecycle is a contract where the gauges keep publishing.
- **Apply**: Use for CRM, email, churn, and win-back; map message-era mechanics to outcome-era ones.
**Pricing Is the Loop Selector**
The tier selects the loop — free feeds the product wedge-finder, usage becomes the agent's offer, outcome plus gauge page drives retention and expansion — designed on the attribution × autonomy grid.
- **Apply**: Use for pricing, packaging, free tier, and monetization; assign each tier the loop it feeds and run the seat-pricing check.
**The Ecosystem Loop (The App Store Without Screenshots)**
List where agents look, in the format each registry/directory/agent-store reads; the integration is a callable endpoint, not a screenshot listing, and the marketplace-sourced cohort is tracked.
- **Apply**: Use for marketplaces, partners, integrations, and app stores; a screenshot listing with no callable integration is a failure pattern.
**Attribution Collapsed; Incrementality Survives**
The path runs through a model, so multi-touch attribution collapsed; only incrementality survives, designed as a counterfactual per channel.
- **Apply**: Use when asked to "attribute revenue across channels" or "which channel works"; replace the attribution report with a counterfactual sheet.
**Community Is the Citation the Machine Trusts**
Community, when structured, attributed, and on the firm's property, becomes the citation the machine trusts rather than a rented social presence.
- **Apply**: Build community as owned, machine-readable substance that feeds the answer loop.
---
### The Metrics System
**The Metrics That Died**
Pageviews, sessions, MAU, seats, CTR, content volume, and engagement assumed a human reader and a click; they are retired, logged with date and reason, before any loop is designed.
- **Apply**: Open every engagement by checking whether the dashboard runs on a dead metric — if so, that is the first finding.
**The Six Instruments**
Install citation share, agent share & agent conversion, time-to-magic, outcome retention, cost per accepted outcome, and NRR — each with source, cadence, and owner.
- **Apply**: Replace the retired metrics with these six; review weekly, run a monthly retirement pass.
**Citation Share**
The share of relevant machine answers naming the firm, measured per engine that matters.
- **Apply**: The answer loop's referee; instrument as engines × query classes × share with a cadence.
**Agent Share & Agent Conversion**
The share of arrivals that are agents, and their completion rate on their own terms, counted as a separate cohort.
- **Apply**: The agent loop's referee; a dashboard that blends agents into "traffic" is a finding.
**Time-to-Magic** → canonical entry in **AI Product Engineering**. Applied here in this seat's context.
**Outcome Retention**
The share of cohorts whose outcome kept arriving, replacing return-visit retention.
- **Apply**: Measure per cohort as the ceiling on growth.
**Cost per Accepted Outcome** → canonical entry in **AI Economics**. Applied here in this seat's context.
**The Free User Is a Cost** → canonical entry in **AI Economics**. Applied here in this seat's context.
### The Referee & Experimentation
**The Counterfactual as Referee**
Every experiment has a held-out counterfactual the experimenting loop cannot alter (holdout, geo split, DiD, synthetic control) and grades on an outcome metric, never a proxy.
- **Apply**: Design one per channel/experiment; agent-run experiments with no holdout are refused.
**Every Loop Has a Referee It Cannot See**
Each loop has a named builder and a named referee; a loop with one owner is a channel wearing a loop's name.
- **Apply**: Assign a builder and a separate referee to every loop; treat single-owner loops as the twelfth failure pattern.
**Growth Goodhart**
When a growth measure becomes a target, the loop games it (Goodhart 1975 / Strathern 1997); every gamed metric is catalogued as a case.
- **Apply**: Keep the referee's outcome metric out of the experimenting loop's sight; maintain the catalogue of gamed measures.
**The Retired-Metric Log**
A standing record of each dead metric, the date retired, the reason, and what replaced it.
- **Apply**: Open it in Stage 2 and run a monthly retirement pass against it.
---
### Loop Mechanics & Sub-Models
**The Second Surface**
Alongside the human surface the firm builds a machine surface — endpoints, offer schema with comparable fields, machine-readable terms, callable actions — with human-surface parity (same outcome both ways).
- **Apply**: Build in the agent loop; no rendered-image pricing pages and no "contact sales" as the only action.
**Entity Clarity**
The firm's names, products, people, and claims resolve unambiguously across the surfaces a machine reads, with conflicts listed.
- **Apply**: Run as the entity clarity check in the answer loop and the entity-resolution audit in brand.
**Activation Is the First Outcome**
Activation is the first verified outcome on the user's real work — sign-up is not activation, a login is not retention.
- **Apply**: Redefine activation in the product loop and measure time-to-magic against it.
**Reputation the Machine Can Read**
Reputation must be legible to machine readers — published, structured, attributable outcomes — not just human-visible signals.
- **Apply**: Wire the reference engine and published outcomes so a machine can read the firm's standing.
**The Atomic Workflow**
The cold-start unit is one workflow working and published — the smallest complete outcome that seeds the distribution loop.
- **Apply**: Use as the cold-start plan in distribution & community.
**The Slop Flood**
Generated content at volume has negative return; one original dataset beats a hundred generated posts, and any generated program needs a citation-share instrument and a kill rule (discounted by the engines within two cycles → stop).
- **Apply**: Refuse "publish more content"; substance over volume with a kill rule.
**The Crowd's Attention vs. the Outcome**
The web era optimized for the crowd's attention; the AI era optimizes for the verified outcome kept.
- **Apply**: Use to reframe any attention/engagement objective toward an outcome objective.
---
### Applied Library Models (cross-suite)
**Product and Distribution Become the Same Thing**
In the AI era the product and its distribution collapse into one thing — the product's surfaces are how it is discovered and bought.
- **Apply**: Design the product's endpoints and offer as distribution, not as separate marketing.
**Organizational Transformation Is the Prerequisite**
The operating model must change before the business and distribution models can — organizational transformation precedes growth.
- **Apply**: Check that the operating core has transformed before promising distribution-side growth.
**Intelligence Becomes Part of the Organization**
Intelligence (agents doing the work, outcomes as units) becomes part of the organization itself rather than a tool bolted on.
- **Apply**: Assess whether agents and outcomes are embedded in the operating model in Stage 0.
---
### Growth Team Design
**The Growth Engineer**
The growth engineer works four axes — engineering depth, data fluency, product sense, distribution craft — and avoids the two stalls: the analyst who never builds and the builder who never measures.
- **Apply**: Screen on "a loop you built and its curve; a metric you retired and why; a counterfactual you protected."
**Organize by Loop**
The growth team is organized by loop — a builder plus a referee (plus a designer where human-facing) per loop — not by channel or funnel stage.
- **Apply**: Draw the org chart by loop; a channel team wearing a loop's name is a failure pattern.
---
### Maturity Ladder (G0–G5)
**The Growth Maturity Ladder**
G0 the funnel with a dashboard of visits · G1 loops named, dead metrics retired · G2 answer + product loops instrumented · G3 agent surface shipped, cohort counted · G4 referee frozen with counterfactuals on every channel · G5 the residue loop compounding on owned substance — the position the machines must come to. Tell: G3 claimed with attribution reports still circulating is G1.
- **Apply**: Locate the firm on the ladder and set the next threshold; use the tell to catch overclaimed maturity.
---
### Failure Pattern Library (12)
**The Twelve Failure Patterns**
1. The slop flood · 2. The click chase · 3. The agent-blind product · 4. The vanity activation · 5. The unrefereed experiment · 6. The leaked substance · 7. Agent-farmed metrics counted as demand · 8. The seat-priced agent product · 9. The last-click paid loop at agent speed · 10. The screenshot listing · 11. Brand as adjectives (no entity) · 12. The channel team wearing a loop's name.
- **Apply**: Run failure diagnosis by naming the proxy optimized or the line undefended; a diagnosis ending in "more content" or "more spend" is rejected.
---
### Named Laws & Hard Thresholds
**No Growth Plan Ships on a Dead Metric**
Pageviews, sessions, MAU, seats, CTR, content volume, and engagement must be retired — logged with date and reason — before any loop is designed.
- **Apply**: Non-negotiable gate at the start of every plan.
**Never Seat-Price Agentic Value** → canonical entry in **AI Economics**. Applied here in this seat's context.
**The Agent Cohort Is Counted and Converted Separately**
A dashboard that blends agents into "traffic" is a finding; agents get their own cohort, funnel, and conversion terms.
- **Apply**: Separate the agent cohort in every dashboard and experiment.
**Substance Over Volume**
No generated-content program ships without a citation-share instrument and a kill rule; one original dataset beats a hundred generated posts.
- **Apply**: Apply to any content or answer-loop program.
**Every Asset Gets a Property-Line Decision**
No asset is published or fed to a machine reader without a cite / license / fence / route-around decision.
- **Apply**: Gate publication and machine-feeding on the property-line register.
---
*Analysis by The Business Engineer · businessengineer.ai*
<a id='05-the-forward-deployed-engineer'></a>
---
---
# PART VII — TAKE THE FIELD AND CLOSE
## The Forward-Deployed Engineer
### Governing Definitions & Compressions
**The FDE Definition (Four Removals)**
An engineer embedded at the customer's constraint, building production machinery from the customer's real cases, with a wired-in duty to convert deployment learning into product. Remove the embedding and it's a vendor; remove the machinery and it's a consultant; remove the product duty and it's a body shop — and the one continuity that survives the title's inflation is accountability to the customer for the outcome.
- **Apply**: Use as the test for whether a role, contract, or motion is genuinely FDE. Run the removals to diagnose what a degraded "FDE" has actually become.
**The Three-Word Compression**
Embed at the constraint. Build what compounds. Transfer the keys.
- **Apply**: The one-line discipline applied to every engagement; use as the sanity check that a deployment plan does all three, not just the first.
**The Three Seats**
Every FDE question is answered from one of three seats — the firm running the motion, the enterprise receiving it, and the engineer building the career — and the same facts produce different advice per seat; never blend seats silently.
- **Apply**: Declare the seat before advising. When advice feels contradictory, check whether two seats are being mixed.
### The Engine (Stages 0–5)
**Stage 0 — Seat and Coordinate Check**
Declare the seat (vendor / buyer / internal / individual), then place the enterprise coordinate — regulatory density, data gravity, process type (vertical vs. horizontal), and strategic weight — because the coordinate tunes every recommendation.
- **Apply**: Run first on any deployment-shaped engagement. High regulation favors application-layer depth and clean title; high data gravity pulls machinery on-premise; high strategic weight pulls toward internal ownership.
**Stage 1 — The Wedge Test**
Every candidate problem is scored on four required gates — Volume, Specifiability, Verifiability, Pain — plus two filters, Reversibility and data proximity; ALL gates required.
- **Apply**: Score candidate problems before selecting a pilot. The scorecard is the engagement's first artifact and the customer owns it from day one.
**Stage 2 — The Embedding Plan**
Archaeology of the process as practiced from the floor; everything learned files to a system of record on the customer's systems (written-first, non-negotiable); a golden set of 60–100 signed cases; and a threshold of time-to-magic ≤ 30 days to first verified production win.
- **Apply**: Use to structure the first weeks on site. Sit with the people who do the work, not their managers; miss the 30-day window and the pilot enters purgatory.
**Stage 3 — The Field Build**
A fixed build order under field conditions — suite frozen early (also the political instrument); harness from customer material; model behind a clean joint (demonstrated by swapping a second vendor's model); agent cadence; graduate in public.
- **Apply**: Follow the order when building the production machinery. Iteration count is the compounding variable — rebuild by afternoon, repeat 3–4 days.
**Stage 4 — Cascade and Residue**
Every expansion candidate goes through the same scorecard in the open; around unit three, split retail units from wholesale substrate and install the roster before the governance question arrives; and a residue review at every checkpoint asks what was built for the second time.
- **Apply**: Use when expanding beyond the first wedge. File repeated patterns to the harvest hierarchy; keep the customer's substance the customer's, licensed openly.
**Stage 5 — Title and Handover**
Ask the five title questions before signature and verify them at milestones; the handover is an acceptance test where named customer operators run the machinery hands-off for a defined period, and the engagement closes on demonstrated operation, not the calendar.
- **Apply**: Use to close an engagement cleanly. "A customer who could leave and does not is the only reference worth having."
### Core Mental Models
**The Wedge Gates (Four Gates, Two Filters)**
Volume (recurs often enough that a unit earns its build within a quarter), Specifiability (correct outcomes can be written down), Verifiability (results checkable against real adjudicated cases), Pain (someone senior feels it weekly, by name) — plus filters Reversibility and data proximity.
- **Apply**: The gate structure for scoring any wedge. A candidate failing any single gate is refused regardless of its other strengths.
**The Three Refused Wedges (Hard Rules)**
The moonshot is refused regardless of sponsor seniority (discovery consumes the trust window); the trivial wedge is refused regardless of ease (a win nobody feels recruits no second charter); the demo wedge is flagged (vendor convenience is not the customer's constraint).
- **Apply**: Use as automatic refusals in wedge selection, even under pressure from a senior sponsor.
**Time-to-Magic** → canonical entry in **AI Product Engineering**. Applied here in this seat's context.
**Process Archaeology**
The process as practiced, recorded from the floor — exception rates, workarounds, the spreadsheet nobody mentioned — by sitting with the people who do the work, not their managers.
- **Apply**: Run before committing to a build, and as the fix for the demo wedge (archaeology before commitment).
**The Golden Set** → canonical entry in **AI Product Engineering**. Applied here in this seat's context.
**Agent Cadence**
Arrive with the agent already built; invite the customer to say why it is wrong; transcribe objections into agent context; rebuild by afternoon; repeat over 3–4 days.
- **Apply**: The daily rhythm of the field build. Ten turns in another team's one is a different regime.
**Iteration Compounding**
Iteration count is the compounding variable of the field build — more turns per unit of time produces a qualitatively different result.
- **Apply**: Optimize the build loop for turn count; treat slowness in iteration as the binding constraint.
**The Clean Joint** → canonical entry in **Agent Engineering**. Applied here in this seat's context.
**Graduate in Public**
Thresholds pre-agreed with the sponsor, gauges published weekly to a page the sponsor reads, promotion staged with a date and a signature.
- **Apply**: Use to convert a working build into an accepted, signed graduation — never a private declaration of success.
**Retail Units, Wholesale Substrate**
Around unit three, split the customer-facing retail units from the shared wholesale substrate (shared record, identity/permissions, gauge tooling) and install the roster before the governance question arrives.
- **Apply**: Use when cascading past the first deployment to avoid scattered, ungoverned units.
**The Residue Hierarchy (Harvest Hierarchy)**
What was built for the second time is filed up a hierarchy — playbook (cuts weeks) → toolkit (cuts cost) → product (changes the business model) — with the pattern owned by the vendor and the customer's substance owned by the customer, licensed openly.
- **Apply**: Run a residue review at every checkpoint; promote patterns on a cadence to protect the margin curve.
**The Five Title Questions**
Who owns the suite (portable to another model)? Where does the record live? Whose are the encoded standards? Does the unit survive a model swap? Who operates after handover?
- **Apply**: Ask before signature and verify at milestones; the share of engagements meeting all five at handover is the title-cleanliness meter.
**The Handover Test**
The handover is an acceptance test — named customer operators run the machinery hands-off for a defined period — and the engagement closes on demonstrated operation, not the calendar.
- **Apply**: Write into the contract as a clause; also the absorption mechanism for bootstrapping an internal function with external FDEs.
**The Pattern License**
The abstracted shape of the solution is retained by the vendor and licensed openly; the customer's substance stays the customer's.
- **Apply**: State openly in the contract to reconcile productization with clean title.
### The Buyer's Lenses (Sovereignty)
**Institutional Sovereignty**
Ownership of the decision rights of the business — the buyer's overriding frame, audited against four worries: lock-in, subsidy, rule change, and cost.
- **Apply**: Use in the Sovereignty Audit. Score the five title questions per engagement and place the client on the gradient per use case.
**The Four Worries**
Lock-in (can the process swap its model?), subsidy (does consumption revenue fund a vendor positioned to compete with you?), rule change (can a third party alter your machinery's behavior without consent?), and cost (are you paying frontier prices for craftsman work an owned task-specific model could do?).
- **Apply**: The audit checklist for a buyer assessing vendor dependency.
**The Sovereignty Gradient** → canonical entry in **The Enterprise Buyer**. Applied here in this seat's context.
**The Decision Loop Is the Alpha**
The decision loop — data seen, reasoning applied, action taken, outcome observed — is the firm's alpha and the training material for owned models.
- **Apply**: Name and protect the decision loop as the deepest asset in any sovereignty audit; it is what an owned model would be trained on.
### The Commercial Layer (Contract & Pricing)
**The Ownership Schedule**
A table of every artifact class (suites, records, standards, prompts, checks, dashboards, connectors, playbooks) with its owner and a testable portability requirement, verified at milestones.
- **Apply**: The first contract artifact; drafting one from memory is a career-stack exhibit for commercial literacy.
**The Pricing Ladder**
Pricing matched to proof — fixed-fee wedge → outcome terms once the frozen suite exists → subscription once residue is product; outcome pricing without a verification instrument is a dispute schedule.
- **Apply**: Climb the ladder as proof accumulates; never sell outcomes before the verification suite exists.
**Attribution × Autonomy Grid**
A pricing grid — seats where attribution is weak, usage where autonomy runs without attribution, outcomes where the system owns a verifiable result.
- **Apply**: Select the pricing model by locating the engagement on the two axes of attribution and autonomy.
**The Guarantee (The Guarantor Is the FDE)**
Outcome pricing requires a guarantor, and the guarantor is the FDE.
- **Apply**: Only offer outcome terms where an FDE stands behind the result; use as a structural rule in contract architecture.
**The Repeated Game**
The commercial relationship is a repeated game — good-faith value assessment because both sides want the next round.
- **Apply**: Frame pricing and negotiation as ongoing rather than extractive; the philosophy behind clean title and fair terms.
### Building the Motion (Firm Seat)
**Start After the Pattern**
Begin the practice only after 2–3 founder-led deployments prove a repeatable wedge; hiring ahead of the pattern builds a body shop with a thesis.
- **Apply**: Gate any field-team hiring on a proven wedge pattern; the fix for the premature practice.
**The Founding Pair**
A principal-grade FDE plus a commercial counterpart, because the motion sells outcomes and change together.
- **Apply**: Staff the zero-to-one motion as a pair, not a lone engineer.
**The OS in Order**
Build the operating system — deployment record → harvest channel → meters — before headcount, because meters installed later measure a mythology.
- **Apply**: Sequence the motion's infrastructure ahead of hiring.
**The Pod**
One pod per account — senior + 1–2 developing engineers + commercial counterpart — with a senior carrying at most two mid-sized engagements.
- **Apply**: Use as the staffing unit and the ceiling on senior load.
**The Harvest Ratio**
The protected ratio of output promoted to reusable residue, defended from quarter one.
- **Apply**: Track and protect from the start; a proxy for whether the motion is compounding.
**The Refusal Log**
A kept record — from inquiry one — of engagements declined, with reason, reconsider trigger, and date.
- **Apply**: Maintain alongside the meters; it shapes the pipeline and is the discipline the meters can't show alone.
### Building Internally (Enterprise Seat)
**The Four-Part Test**
Strategic workflows, regulatory density, data gravity, repeat volume across BUs — meet one, buy the motion with clean title; meet all four, build in-house (or pay vendor margins to build someone else's residue).
- **Apply**: Use as the build-vs-buy decision for an internal AI function.
**The Four Inversions**
For an internal motion: funded by the served P&L in attention returned; sponsorship replaces sales but wedge discipline survives (internal purgatory is real); residue accumulates as the firm's own harness; title answers itself.
- **Apply**: Redesign the FDE motion's economics and discipline when the customer is internal.
**The Central Practice**
A central practice deploying into units — never scattered heroes — with the center owning playbook, substrate, roster, and rotation.
- **Apply**: Use as the org shape for an internal FDE function.
**The Diagonal Hire**
Grow the diagonal (domain expert who learns the machinery — the adjuster who learns the build) rather than losing the premium bidding war for outside talent.
- **Apply**: Use as the internal talent strategy; second chairs finished in the field.
**Bootstrap and Absorb** → canonical entry in **The Enterprise Buyer**. Applied here in this seat's context.
### Positioning (Motion by Position)
**Five Species, One Motion**
Five species of FDE motion — model layer, data platform, application layer, services, internal — each with its own answer to what the motion funds, where the residue lands, title posture, and governing meter.
- **Apply**: Place the firm among the species, accept its business model whole, and let the coordinate select the customers. The classic failure is one motion with five species' pricing and no species' economics.
**Title Posture as Strategy**
Title posture varies by species — application layer wants tight title as the moat; services want clean title as the engine.
- **Apply**: Set contract title posture deliberately from the chosen species, not by default.
### Diagnosis & Measurement
**The Six Failure Families** → canonical entry in **AI Engineering**. Applied here in this seat's context.
**The Six Meters**
Read together and on trend — time-to-magic, expansion rate, outcome conversion, productization rate, margin trajectory, title cleanliness — beside the refusal log, rejecting vanity substitutes (deployments launched, hours billed, agents deployed).
- **Apply**: Use as the motion's instrument panel; the productization rate predicts the margin curve and title cleanliness is the meter durable firms publish and captors resist.
**Margin Trajectory as Unharvested Residue**
The gap to the originator's software-margin benchmark is the firm's unharvested residue.
- **Apply**: Read the margin gap not as fate but as a measure of residue left on the floor.
### Career (Individual Seat)
**The Vintages / The Vintage Question**
The same title covers five jobs — platform stability, integration, enablement, solutions, and the outcome-owning arc — and the question is which vintage a seat is and whether it builds the whole stack or one layer.
- **Apply**: Vintage-parse any FDE seat before signing; the fix for the dumping-ground title.
**The Skill Stack**
Four layers, each proved by an artifact — engineering depth, domain fluency, field craft, commercial literacy — audited in order.
- **Apply**: Audit your own stack layer by layer; build the missing proving artifact (e.g., a solo-built harness, a practitioner process map, a drafted ownership schedule).
**The Rung Ladder**
Second chair (a signed suite) → owned wedge (a public graduation) → owned engagement (a handover that held) → cascade lead (a program that survived rotation) → principal (the harvest); promotion on artifacts, not tenure.
- **Apply**: Place yourself on the ladder and name the next exhibit to hold.
**The Three Stalls**
The career stalls are the brilliant builder who never takes the contract conversation and the account hero who never files residue (the third being the general failure to advance on artifacts).
- **Apply**: Name the stall if visible in a career diagnosis and prescribe the missing move.
**The Four Arcs**
Jump triggers out of the seat — product (after ~2 years of filed harvest), the practice (when you'd rather build the system that builds), founding (when the same wedge repeats across 3+ deployments — the deployment record is the era's best startup thesis), and the enterprise (when a customer offers the mandate).
- **Apply**: Use to time a career move. "The seat's compensation is the salary; the career's compensation is the residue."
**The Portfolio Rule**
One deployment narrated at full grain beats a repository of prototypes, with de-substanced artifacts attached.
- **Apply**: Build the FDE portfolio around a single deep narrated engagement, not a pile of demos.
### Named Applied Models (Additional Lenses)
**The Last Mile**
Models deploy in minutes but value deploys through the work itself — the FDE covers the entire last mile: the motion, the contract, the team, the career, and both sides of the table.
- **Apply**: Frame the FDE's value as the last mile between a capable model and a captured outcome.
**Deck vs. Machine**
The distinction between selling a presentation and building working production machinery on the customer's floor.
- **Apply**: Use to test whether an engagement is producing a machine or a demo.
**Product Development in the Field**
Product is developed in the field from the customer's real cases, with a wired-in duty to convert deployment learning back into product.
- **Apply**: Treat every deployment as a source of product, not just a service delivery.
**The Job Is to Automate the Job**
The FDE's mandate is to automate the job — the second loyalty wired into the cadence, not to become the best contractor in the ticket queue.
- **Apply**: Use as the guard against staff-aug drift.
**The Capture Question**
Whether the motion is building voluntary dependence (a customer who could leave and stays) or coercive lock-in that backfires into a lost account.
- **Apply**: Ask whenever dependency is being designed; clear title by contract is the answer.
**Voluntary Dependence**
The durable outcome — a customer who could leave and does not — as opposed to maximized dependency that loses the account to an exit-cost analysis.
- **Apply**: Aim contracts and handovers at voluntary dependence; it is the only reference worth having.
### Motion Maturity (F0–F5)
**The Motion Maturity Ladder**
Five grades of motion maturity — F0 Heroics, F1 Wedge discipline, F2 The record exists, F3 Proof converts terms, F4 The residue compounds, F5 The position — graded honestly, with the productization rate as the tell (most motions claiming F4 are F1 with good branding).
- **Apply**: Grade a motion's maturity; below one residue promotion per quarter, the residue is evaporating and the F-claim is inflated.
---
*Source: The Forward-Deployed Engineer — Playbook I, The Business Engineer Library. Analysis by The Business Engineer · businessengineer.ai*
<a id='06-enterprise-sales'></a>
---
## Enterprise Sales
### Governing Mental Models
**The Object of the Sale**
The object of the sale changed from software shipped to outcomes installed; name what is actually being sold — assistance (humans still do the work), usage (the system works without clean attribution), or a verifiable outcome — because everything downstream (proof, price, paper) follows the object.
- **Apply**: Stage 0 of every deal. Flag the mismatch immediately when a client sells outcomes on a seat price or proves outcomes with a demo.
**The Four Inversions** → canonical entry in **The Forward-Deployed Engineer**. Applied here in this seat's context.
**Risk Asymmetry**
The buyer's downside always exceeds the seller's, so the sale is a risk-reduction machine wearing a revenue target.
- **Apply**: Design for the buyer's risk before your pitch — the permanent physics behind every mode.
**The Diagonal Competitor**
The seller who has both commercial and field/engineering literacy — the diagonal — commands a premium on both sides.
- **Apply**: Use in org design and career development; AEs build proof literacy, FDEs build commercial literacy.
**Assertion vs. Instrument**
The era demands an instrument where sellers used to rely on assertion; the root cause of every deal failure is assertion where an instrument was required, and the fix is always to install the instrument.
- **Apply**: The universal diagnostic lens. Any diagnosis ending in "push harder at quarter-end" is rejected.
**The Compression** → canonical entry in **AI Product Engineering**. Applied here in this seat's context.
### The Deal Engine (Stages 0–5)
**Stage 0 — Object Check**
Name what is actually being sold — assistance, usage, or verifiable outcome — since proof, price, and paper all follow the object.
- **Apply**: First move in any deal. Flag object/price and object/proof mismatches at once (e.g., outcomes sold on a seat price, outcomes proved with a demo).
**Stage 1 — The Account Gates**
Five gates, ALL required (workflow density, data reachability, champion material, economic visibility, survivable procurement), plus two filters (reference gravity, expansion room); trophies and easy closes are declined in writing into the refusal log.
- **Apply**: Qualify and select accounts. Treat the account list as a portfolio of future proof; map sibling workflows before the first contract.
**Stage 2 — The People**
Pass the behavioral champion test, build the champion's career case both ways, arm them with weapons that survive retelling, and hold the multi-thread stage gate — no proposal ships until economic buyer, a user leader, and procurement have each been met.
- **Apply**: Stakeholder work on every deal. Single-threaded deals die with a resignation letter.
**Stage 3 — The Case and the Proof**
Build the case skeleton (baseline → mechanism → commitment → payback in the buyer's own numbers) as one maturing document with the proof instrument, then sell the paid, time-boxed production wedge rather than climbing the demo ladder.
- **Apply**: When proof is needed. Pre-agree verification; ≤ 30 days to first verified win; hand deployment machinery to the FDE skill at this stage.
**Stage 4 — The Gauntlet and the Paper**
Map procurement/security/legal with the champion in week one and run their clock concurrent with the proof's; deploy the artillery early and paper the deal (ownership schedule, pricing ladder, expansion frame, handover clause) via a mutual action plan.
- **Apply**: From meeting one. Volunteered early = accelerant; extracted late = concessions. Closing is the plan's last checkbox.
**Stage 5 — Price and Compounding**
Price by the attribution × autonomy grid, hold discount discipline (defend on the gauge page, trade structure not price), and show the compounding — unit prices fall on the substrate while account value rises.
- **Apply**: Commercial terms and renewals. Never seat-price agentic work; grade the account by NRR.
### Mode Cards
**Account Scorecard**
Candidates in rows, the five gates and two filters in columns, the buyer-market's real numbers in the cells; output is a ranked list, chosen accounts with a 90-day proof thesis, declined accounts with written reasons, and an expansion-room map.
- **Apply**: For ICP, territory, and qualification questions. Never rank on logo, deal size, or inbound enthusiasm — gates only.
**Deal Design**
Run Stages 0–5 into a dated arc (scorecard → champion test → case + schedule → gauntlet → paid wedge → suite frozen → first win → graduation → outcome conversion → expansion signature), marking the trust clock and procurement clock each week.
- **Apply**: To plan strategy for a named opportunity. Include the gauge-page design and its distribution list (the CFO reads it). Routinely spawns Proof Design and Gauntlet Prep.
**Champion Builder**
Stakeholder map in the five languages, champion identified by behavioral test, career case drafted both ways, arsenal assembled, and a multi-thread plan with named seconds per thread.
- **Apply**: For stakeholder mapping and internal politics. Flag single-thread as a stage-gate violation, not a style note.
**Case Builder**
Deliver the one-page case — baseline from the buyer's own data (name the source), mechanism as named gauges, commitment priced, payback with confidence stated — attention-denominated where possible, with the verification pre-agreement as a clause.
- **Apply**: For ROI and CFO meetings. Reject any case built on industry benchmarks or vendor-claimed averages — a CFO discounts both.
**Proof Design**
Structure the paid production wedge — wedge choice, golden-set plan (60–100 adjudicated cases, buyer's expert signing), suite freeze date, the 30-day clock, weekly gauge publication, and staged graduation — priced honestly.
- **Apply**: When a buyer asks for a pilot/PoC/demo. Kill demo-ladder requests with the replacement offer: prove it on their cases, against their expert's standard, on a clock — and they own the instrument that proved it.
**Gauntlet Prep**
Produce the gauntlet map (every approval, reviewer, document, with dates) and the artillery pack (ownership schedule, clean-joint demonstration plan, security answers-by-architecture brief, handover clause), all volunteered before demanded.
- **Apply**: For procurement, security review, legal, and vendor risk. Output the concurrent-clock schedule.
**Pricing Architect** → canonical entry in **AI Economics**. Applied here in this seat's context.
**Expansion Review**
Audit the account against the acquire-expand-scale curve — base still clearing gauges, gauge page circulating beyond the champion, scorecard running in the open, substrate generalizing, multi-threaded beyond the founding sponsor — with NRR computed and trended.
- **Apply**: For renewal, expansion, and account growth. The renewal motion is "the gauges never stopped publishing"; if they stopped, that is the finding.
**Sales Org Design**
Design pods (AE + FDE + fractional specialists per account), not territories, with more builders than sellers since proof capacity is the revenue constraint; compensate against the ladder, never signature alone.
- **Apply**: For team design, quotas, comp, and hiring. Name the diagonal career cross-pollination — AEs build proof literacy, FDEs commercial literacy.
**Deal Diagnosis**
File a stalled or lost deal to one of six families (demo trap, pilot purgatory, single thread, procurement ambush, discount spiral, expansion assumption); the family names the fix, and the root cause is always assertion where the era demands an instrument.
- **Apply**: For rotting deals and win-loss. Install the instrument the family calls for; reject "push harder at quarter-end."
### Named Laws & Rules
**The Wedge Test**
No wedge, no deal, whatever the logo — an account must sit on recurring, high-volume work that would pass the wedge test.
- **Apply**: First filter in the workflow-density gate before committing effort to any account.
**The Career-Capital Test (Behavioral Champion Test)**
A champion is proven behaviorally, not verbally — has this person done something for the deal that cost them something? Until yes, they are contacts, not a champion.
- **Apply**: Use to identify true champions; drives whether a deal is genuinely threaded.
**Arm the Champion**
Equip the champion with weapons that survive retelling — the one-page case in the buyer's numbers, the gauge page, the ownership schedule — because the deal is argued in rooms you are not in.
- **Apply**: Once a champion passes the behavioral test; an advocate with only enthusiasm is unarmed.
**The Multi-Thread Stage Gate**
No proposal ships until the economic buyer, a user leader, and procurement have each been met; single-threaded deals die with a resignation letter.
- **Apply**: A hard stage gate before any proposal. Assign named seconds for every thread.
**The Death of the Demo**
Refuse the demo ladder — a demo gives no information, a PoC only proves the curation, and an open pilot is purgatory.
- **Apply**: When buyers request demonstration; replace with the paid production wedge.
**The Paid Proof Filter**
The proof is sold, not given; a buyer who paid attends, and unpriced pilots teach buyers not to commit. Pricing the proof filters unserious buyers and funds the field team.
- **Apply**: Structuring any proof phase; a customer refusing to pay is the filter working.
**The Concurrent Clock**
Run the procurement/security/legal clock concurrent with the proof's clock, never after it.
- **Apply**: Map the gauntlet in week one and interleave its steps with the proof timeline.
**The Gauntlet as Artillery**
The ownership schedule volunteered before demanded, the clean joint demonstrated, the handover test offered unprompted — volunteered early accelerates, extracted late concedes.
- **Apply**: Deploy the artillery pack early in the gauntlet; sequence rule is all volunteered before demanded.
**The Mutual Plan**
A mutual action plan from meeting one lists every step with owners and dates on both sides; closing is the plan's last checkbox.
- **Apply**: From the first meeting through expansion signature, with procurement steps interleaved.
**Trade Structure, Not Price**
Defend on the gauge page and trade structure (term, scope, earlier expansion) rather than price; every concession against verified payback reprices the proof, and refusals are logged.
- **Apply**: Under discount pressure; the discipline that prevents the discount spiral.
**Never Seat-Price Agentic Work (The Seat Trap)**
Agentic value priced by human chairs is the deflationary trap; seats are for assistance only.
- **Apply**: Whenever scope is agentic — move to the grid and the ladder.
**The Guarantee**
Outcome terms require the frozen suite (otherwise a dispute schedule) and a guarantor — the field motion standing behind the outcome.
- **Apply**: When writing outcome-priced contracts.
**Price the Compounding**
Unit prices fall on the substrate while account value rises — present both lines to the buyer.
- **Apply**: In pricing conversations and the compounding curve artifact.
**NRR Grades the Design**
Net revenue retention is the grade of the whole commercial design; outcome-priced accounts out-retain seat-priced ones.
- **Apply**: Grade every account by NRR; feed it to firm-level and moat reviews.
**The Gauges Never Stopped Publishing**
The renewal motion is simply that the gauges kept publishing; if they stopped, that is the finding.
- **Apply**: Expansion and renewal reviews.
**Proof Capacity Is the Constraint**
Proof capacity, not selling capacity, is the revenue constraint — so a pod needs more builders than sellers.
- **Apply**: Org and pod design; ratio check on any sales team.
**Pay Against the Ladder**
Compensate against the ladder (proof fees, outcome conversion, expansion, NRR), never signature alone.
- **Apply**: Designing seller compensation.
**The Refusal Log** → canonical entry in **The Forward-Deployed Engineer**. Applied here in this seat's context.
### Lenses & Composite Frames
**Five Languages, One Deal**
The same deal is spoken in five stakeholder languages — economic buyer (payback), champion (the career bet), users (does Tuesday improve), procurement (price, terms, dependency), security/legal (risk, the late veto).
- **Apply**: Stakeholder mapping; translate the deal into each language and thread each with a named second.
**The Portfolio of Future Proof**
The account list is not a revenue pipeline but a portfolio of future proof — each chosen account a reference and expansion asset.
- **Apply**: Account selection; weigh reference gravity and expansion room, not logo or deal size.
**The Case in Their Numbers**
Build the business case on the buyer's own data with a named source — baseline, mechanism (as gauges), commitment, payback — never on industry benchmarks or vendor-claimed averages.
- **Apply**: Any ROI or CFO-facing case; a CFO discounts benchmarks and vendor averages on sight.
**Attention-Denominated Payback**
Denominate payback in attention returned where possible, not only dollars.
- **Apply**: Framing the case's payback line.
**The Production Wedge as Proof**
Proof lives in production — their cases, their expert's signed suite frozen early, gauges published weekly to the sponsor, ≤ 30 days to a verified win, graduation dated and signed.
- **Apply**: The replacement for the demo ladder; hand deployment machinery to the FDE skill here.
**Attribution × Autonomy**
Price by a two-axis grid — seats for assistance, usage for unattributed autonomy, outcomes where the suite can verify.
- **Apply**: The pricing decision engine for any AI-era deal.
**The Ladder Unlocked by Proof**
Pricing is a ladder whose phases convert on proof events — proof fee, then outcome terms on graduation, with rate mechanics tied to the gauge panel.
- **Apply**: Designing the pricing term sheet and conversion triggers.
**Proof Conversion & Discount Integrity**
The core sales meters are proof conversion, cycle-to-proof, outcome-deal share, NRR, pod productivity, and discount integrity — each with definition, reading, target, and trend, alongside the refusal log.
- **Apply**: The meter readout panel; at maturity, these meters are the board deck.
**The Pod** → canonical entry in **The Forward-Deployed Engineer**. Applied here in this seat's context.
### Motion Maturity Ladder (S0–S5)
**The Motion Maturity Model**
Sales-motion maturity runs S0 (the demo team) → S1 (gates exist, refusal log begins) → S2 (proof is production) → S3 (the gauntlet is artillery) → S4 (price follows proof) → S5 (the position, where references sell the pipeline and meters are the board deck).
- **Apply**: Grade a team honestly against the ladder; most teams claiming S4 are S1 with a new deck, and the tell is the refusal log — empty means the gates are theater.
<a id='13-the-enterprise-buyer'></a>
---
## The Enterprise Buyer
### Core Orientation
**The Asymmetry**
The seller runs the meeting perhaps fifty times a year and has met every objection a hundred times; the buyer runs it two or three times in a career for a purchase this size. Selling is a practiced craft with a literature and a budget; buying is an amateur sport played against professionals.
- **Apply**: Enter every vendor engagement aware you are outmatched in repetitions. Treat the asymmetry as the reason to lean on instruments rather than instinct or relationship.
**Instruments Substitute for Repetitions**
Because the buyer will never accumulate the reps the seller has, the discipline supplies instruments — checklists, gates, scored artifacts — that stand in for experience the buyer lacks.
- **Apply**: When you have done this twice and the vendor has done it fifty times, reach for the instrument, not for a hunch. The tool holds the line where memory cannot.
**The New Purchase Carries a Second Risk**
The old purchase was capability and the risk was whether you would use it; the new purchase is an outcome produced by machinery installed inside your operation, carrying a second risk — an embedded vendor is either the fastest capability transfer available or the deepest dependency ever sold, decided in the paper and the handover, not the demo.
- **Apply**: When buying AI outcomes and agentic software, scrutinize the paper and the handover as the place dependency is decided; do not let the demo stand in for diligence.
**Compression: Own the Standard. Verify the Title. Keep the Loop.**
The whole discipline compresses to three imperatives — own the definition of correct, verify who owns what and when, and retain the decision loop.
- **Apply**: Use as the one-line test of any buying decision: if you don't own the standard, can't verify the title, or have surrendered the loop, the purchase is mispriced.
**The Decision Loop Is the Traded Asset**
What an embedded AI vendor ultimately trades in is the buyer's decision loop; keeping the loop is what separates capability transfer from dependency.
- **Apply**: Ask of any embedded system whether you still hold the loop it runs, or whether the vendor now holds it. Guard the loop as the asset actually at stake.
---
### The Engine — VERIFIED and Its Governing Rule
**VERIFIED (the buyer's qualification)**
The eight-letter qualification that governs every purchase — V: Verification owned, E: Economics read, R: Rights scheduled, I: Incentives separated, F: Feasibility on your floor, I: Independence priced, E: Exposure governed, D: Drift instrumented. Each letter poses a question answered only by an artifact.
- **Apply**: Run as the spine of any buy decision. Produce, per letter, the artifact demanded, the artifact received, and a grade; deliver the eight-letter board with priced exposures and a go/price/walk verdict.
**Every Letter Holds an Artifact, Not an Assurance**
The rule that governs VERIFIED: each letter is answered by a concrete artifact (a signed case set, a unit read, a dated schedule, two named people, a scored proof run, an exit bill, a named owner, a gauge) — never by a verbal assurance. What VERIFIED refuses is the letter nobody checked.
- **Apply**: When grading any letter, demand the object. An assurance never grades as an artifact; a letter nobody checked is itself the finding.
**The Three Gates**
VERIFIED runs at three points on the purchase arc — V·E·I before contact; F·R·E at the wedge's clock; I·D before signature — then annually. A failed letter does not stop the purchase; it prices it as logged exposure.
- **Apply**: Sequence the qualification against the purchase's timeline rather than running all eight at once. Gates may be compressed under pressure but never bypassed — not for a board introduction, an executive relationship, or urgency.
**The Purchase Arc (The Engine)**
The purchase has its own arc in four movements: Before any vendor (write the standard, separate advocacy from audit, stand up intake, run V·E·I); Through the flood (read the outreach, build the shortlist from gates, source references, understand the paid map); The proof and the paper (run the proof, write the schedule/exit/gauge/names, run F·R·E then I·D, assemble the board); The life of the contract (read the gauge, log drift, rehearse the exit, grade renewal on outcomes, re-run VERIFIED annually).
- **Apply**: Locate where you are on the arc before advising. The standard runs before the proof; the proof before the paper; nothing runs before advocate and auditor are two people.
---
### Named Laws, Rules, and Hard Thresholds
**The Standard Comes First**
The standard — your cases, your definition of correct, your thresholds, written and signed by the domain expert who owns it — must exist before the first vendor meeting. A buyer without a standard is buying the vendor's.
- **Apply**: Build sixty to a few hundred real cases from your own operators, including gray areas, adjudicated and signed, before contact. Never adopt the vendor's definition of correct.
**Advocacy Is Not Audit**
The champion who needs the purchase to succeed cannot be the person who grades it. Two names, or the evaluation is theater.
- **Apply**: Before anything runs, name a separate advocate and auditor. When the executive relationship makes the advocate obvious, name the auditor from outside the sponsoring unit — the one letter that cannot be compressed.
**Proof on Your Floor**
Feasibility is scored on your cases, on your floor, against thresholds set before results exist. A demo on curated data only proves the vendor curates well.
- **Apply**: Run the proof as a paid production wedge on your data with your expert adjudicating. Refuse vendor data and vendor scoring.
**The Ownership Schedule Has Dates**
"You own your data" is not a schedule; a clause is not a schedule. A real schedule states what lands, in what format, on what date, verified how, and who owns it after handover.
- **Apply**: When told ownership is "covered in the MSA," read it aloud and demand artifact × format × delivery date × verification method × post-handover owner.
**The Priced Exit**
The cost of leaving — in money and months — must be computed and written into the file before signature and rehearsed once a year. An unpriced exit is a captured account that has not noticed yet.
- **Apply**: Compute extraction, re-integration, retraining, parallel running, and contractual tail. The number is for you, not the vendor, and changes the negotiation you are in.
**Rehearse the Exit**
The priced exit is not enough; it must be rehearsed annually — put on the calendar before the next renewal, not after. A priced exit never rehearsed is not the maturity it claims to be.
- **Apply**: Schedule the rehearsal as a standing annual event. A B4 claim with an exit that has never been rehearsed is really B2.
**Drift Instrumented Before Signature**
Drift — the system quietly ceasing to work the way it did — must be instrumented before signature with a specified gauge, cadence, and owner, not discovered at renewal.
- **Apply**: Specify the gauge page you read (not the vendor's reports), the cadence, and its owner as a pre-signature obligation. Same data, different reader.
**Renewal Is Graded on Outcomes, Not on Spend to Date**
Renewal is graded on what was delivered against the thresholds you set; prior investment is not evidence. Sunk cost is not a renewal argument.
- **Apply**: At renewal, grade the outcome. "We've already spent two million with them" is a sunk-cost fallacy; if no thresholds were ever set, say so plainly — that is the finding, and it is about you, not the vendor.
**Named Owners Before Go-Live**
A named owner for the system's behavior and a named owner for the data, on the buyer's side, must exist before go-live.
- **Apply**: Refuse go-live until both names are assigned. If a vendor won't name an accountable person, escalate once, then walk.
**The Unchosen Source**
Every reference call must include at least one source the vendor did not choose. Vendor-chosen references are coached accounts.
- **Apply**: Accept the perfect customer the vendor offers, and also speak with one you found yourself. Ask the coached account the question it cannot answer.
**Nothing Skips the Gates**
No board introduction, executive relationship, or urgency bypasses the gates. They may be compressed; they are not skipped, and the compression is said out loud.
- **Apply**: Treat a board introduction as a channel, not a diligence. Show the compressed timeline so nobody wonders whether the bar was lowered.
---
### Distinctive Mental Models
**The Absorption Line**
The line separating perishable compensation from durable requirement — reading what a vendor offer half-submerges (perishables) versus what stands on a plinth (durables) over time.
- **Apply**: When evaluating an offer, sort what is perishable (discounts, credits, temporary capability) from what is durable (the requirement, the standard, the workflow) and price accordingly.
**The Vendor's Homework**
A demo or proof run on the vendor's own curated data — it proves the vendor did their homework, not that the product survives contact with your work.
- **Apply**: Name it when a vendor scores their product on their own cases; move the proof to your floor. A vendor who refuses proof on your cases is a walk.
**The Pilot That Defends a Budget**
A pilot run without a written standard scores against the vendor's demo criteria and exists to defend a budget rather than establish whether it works.
- **Apply**: When asked to "run a pilot to see if it works" with no standard, write the standard first, then run a paid production wedge. The pilots weren't failing; they were never given a definition of success the buyer owned.
**Procurement Theater**
A procurement process that selects for vendors who are good at procurement rather than good at the work.
- **Apply**: Watch for a process optimizing for the wrong thing; build the shortlist from your gates, not from a process that rewards polished vendors.
**The Coached Reference**
A reference the vendor selected and prepared — it will not answer what a buyer actually needs to know.
- **Apply**: Neutralize by adding an unchosen source and asking: "What did you end up building yourselves that you expected to get from them? And what broke in month four?"
**The Paid Map**
Analyst quadrants and assessor reports are a market map on a paid channel — analysts as a channel, assessors who sell the remediation for the assessment they wrote.
- **Apply**: Read analyst rankings as a paid market map, never as a shortlist. Build the shortlist from your gates.
**Capex Theater**
A program with a steering committee, a budget, and ceremony but no standard — the appearance of governance without the definition of correct.
- **Apply**: When a program has oversight machinery but no signed standard, name the missing standard as the actual gap.
**Title Search: KEPT, PARTIAL, CAPTURED**
A dependency map in which each row — suite, record, standard, prompts, checks, connectors, operators — is marked KEPT, PARTIAL, or CAPTURED. Most firms discover fewer captured rows than feared and more partial ones than they knew.
- **Apply**: Draw the map to see where title actually sits. To escape capture, pick the single cheapest CAPTURED row and move it to PARTIAL this quarter — capture is escaped one row at a time, not by a migration project.
**The Sovereignty Gradient**
The chosen degree of independence per workflow — sovereignty is not all-or-nothing but a gradient set deliberately per workflow.
- **Apply**: For each workflow, choose where on the gradient you want to sit rather than defaulting. In the strategic tier, sovereignty comes before price.
**The Handover Acceptance Test**
The test at handover that makes the rest of the paper true — the ownership schedule, the exit, and the drift gauge are real only if the handover actually delivers.
- **Apply**: Specify the acceptance test that verifies the handover; without it, the schedule is a promise. It is the clause that makes the others enforceable.
**The Behavior-Change Audit (what the security review misses)**
The audit of model and prompt changes over time — the thing a one-time security review does not catch because behavior changes after signature.
- **Apply**: Add a change-management clause for model and prompt changes; a security review that had the artifacts it needed clears faster, but behavior drift is a separate, continuing audit.
**The Refusal Log** → canonical entry in **The Forward-Deployed Engineer**. Applied here in this seat's context.
**Chosen Capture**
Capture that happens because the switching costs are borne by the team that would have to switch — so no one chooses to switch, and dependency deepens by default.
- **Apply**: Watch for capture that is being chosen by omission; price the exit and rehearse it so switching remains a real option rather than an unowned cost.
**The Vendor's Margin Predicts Their Behavior**
What the outcome costs the vendor to produce and their margin structure predicts their renewal behavior and their appetite for outcome terms.
- **Apply**: Read the vendor's grid position and unit economics from the buyer's side; use the margin read to anticipate renewal and pricing moves before they arrive.
**Retail the Proof, Wholesale the Terms**
In enterprise buying, run the proof case-by-case (retail) while negotiating terms once for all units (wholesale) — one purchase serving many units.
- **Apply**: When rolling out across many business units, retail the proof and wholesale the terms; run the gauntlet concurrently rather than serially.
**Fast Yes With Clean Title**
Intake designed so business units can say yes quickly while still acquiring clean title — the alternative to buying in the dark or policing shadow purchasing.
- **Apply**: Build intake that enables a fast yes with clean title; absorb shadow purchasing rather than policing it.
**The Gauge-Page Reader**
A named reviewer seat whose job is to read the drift gauge page on cadence — one of the three reviewer seats in the buying function.
- **Apply**: Assign the gauge-page reader as a standing seat so post-signature drift has an owner who actually reads it.
**Partnership as Purchase With Reciprocal Capture**
A partnership is a purchase with reciprocal capture — price the logo, the reference, the case study; split title on co-development; treat distribution through the vendor's channels as your own growth channel.
- **Apply**: Qualify a partnership as a purchase first, then price what each side captures. Set the title-split on co-development before any joint work starts.
**Your Co-Development Is Their Product Research**
One of the three alliance failure modes — what you fund as co-development becomes the vendor's product roadmap and research, captured by them.
- **Apply**: In any co-development, name this risk and secure title-split up front so your investment does not silently become their product.
**Alliance Inheritance**
What you join when you buy — the alliances, standards, and obligations that come attached — some opened to you, some held from you, read by a rule.
- **Apply**: When buying into a vendor with alliances, map what you inherit as opened vs held and apply the reading rule before committing.
**The Four-Part Build Test**
The test for build-vs-buy: strategic workflow, regulatory density, data gravity, repeat volume. High on these favors build (or bootstrap-and-absorb).
- **Apply**: Score the workflow on the four parts to decide build, buy, or both. If build, stand up the internal practice; if both, put the absorption date in the contract.
**Bootstrap and Absorb**
The "both" path — buy to bootstrap, then absorb the capability in-house, with the absorption date written into the contract.
- **Apply**: When choosing both, contract the absorption date up front so the transition is scheduled rather than hoped for.
---
### Lenses — Modes of the Discipline
**QUALIFY (VERIFIED)**
The mode that runs the eight-letter board: per letter the artifact demanded, received, and graded; the gate at which each ran; priced exposure for every failed letter; a go/price/walk verdict.
- **Apply**: Use when the question is "should we buy this / which vendor / shortlist." An assurance never grades as an artifact; the unchecked letter is the finding.
**THE STANDARD**
The mode that builds the definition of correct: case-set construction plan (sources, operators, gray-area share, count, adjudicator, signature), thresholds in the business's numbers, where the standard lives and who holds it, the derived rubric.
- **Apply**: Use when writing the RFP, requirements, or evaluation criteria. Runs before THE PROOF. Never adopt the vendor's definition of correct.
**THE PROOF**
The mode that designs the wedge: production scope, paid, bounded; your cases; the scoring method and adjudicator; thresholds fixed in advance; a timebox; what a fail means.
- **Apply**: Use for any pilot, POC, or trial. No vendor data, no vendor scoring, no unbounded pilots.
**THE PAPER**
The mode that writes the contract instruments: the ownership schedule (artifact × format × date × verification), exit terms, drift and gauge obligations, accountability names both sides, the handover acceptance test, and the change-management clause for model and prompt changes.
- **Apply**: Use for contract, MSA, DPA, terms, ownership, and IP. Clauses without dates are not schedules.
**THE EXIT**
The mode that prices leaving: the exit bill in money and months, the dependency map, the sovereignty gradient chosen per workflow, and the annual rehearsal plan.
- **Apply**: Use for lock-in, switching, and "what if we want to leave." Produce the number, the map, and the rehearsal date.
**THE PRICE**
The mode that reads vendor pricing from the buyer's side: grid position, what margin structure predicts about renewal, total cost including attention consumed, the hybrid transition to expect, and the renewal model.
- **Apply**: Use for seats vs credits vs usage vs outcomes and renewal quotes. Outcome pricing without a shared verification instrument is a dispute schedule — for both sides.
**THE LIFE OF THE CONTRACT**
The mode no vendor's process covers: the gauge page you read, the cadence and its owner, the drift log, the refusal log, the incident path, the annual VERIFIED re-run, the renewal grading sheet.
- **Apply**: Use when it's live and something's wrong, or renewal is coming. Produce the post-signature operating card.
**THE BUYING FUNCTION**
The mode that designs the organization: the three ownerships (the standard, the data, the vendor relationship), intake for fast yes with clean title, the three reviewer seats including the gauge-page reader, the federated-vs-central call, and how shadow purchasing is absorbed rather than policed.
- **Apply**: Use for team, intake, center of excellence, or shadow purchasing questions. Produce the function chart and intake flow.
**THE BOARD**
The mode for oversight: the four board questions (the exit bill, the concentration, the sovereignty gradient, the accountability names), board-level metrics that aren't vendor marketing, the audit-committee angle, and the handling of board-introduced vendors (introduction welcomed, gates compressed not skipped, said out loud).
- **Apply**: Use for board papers and oversight. The four questions are the spine of an AI vendor policy.
**SOURCING**
The mode for evidence-gathering: the reference plan including an unchosen source, the questions a coached account cannot answer, the back-channel approach, the reciprocity position, reading analysts as a market map, and the RFP decision (when it destroys value).
- **Apply**: Use for references, peers, analysts, and "who else uses this." Produce the sourcing plan and the question list.
**THE SETTING**
The mode that adapts the discipline to scale — Mid-market (no procurement function, buyer is often champion, one-to-two-quarter cycle, minimum viable VERIFIED); Enterprise (gauntlet run concurrently, retail the proof and wholesale the terms); Strategic tier (sovereignty before price, co-investment, executive symmetry, the institution as buyer) — plus the crossings between them.
- **Apply**: Use when the question involves company size or scale. Borrow the discipline from instruments where there is no process; watch what fails when a mid-market habit meets enterprise scale, or enterprise process suffocates a thirty-day wedge.
**THE ALLIANCE**
The mode for partnerships: partnership as a purchase with reciprocal capture, title-split on co-development, distribution as the buyer's own growth channel, the three failure modes (including your co-development is their product research), and alliance inheritance.
- **Apply**: Use for partnership, co-development, joint GTM, and alliances. Set the title-split before any joint work starts.
**BUILD, BUY, OR BOTH**
The mode for the make-or-buy decision: the four-part test (strategic workflow, regulatory density, data gravity, repeat volume), the internal practice if build, bootstrap-and-absorb if both with the absorption date in the contract.
- **Apply**: Use for "should we build this instead." Hand the economics of the build to AI Economics and the purchase to QUALIFY.
**FAILURE DIAGNOSIS** → canonical entry in **Harness Engineering**. Applied here in this seat's context.
### Room Craft and Counter-Moves
**The Seller's Counter-Moves (every instrument has a predictable answer)**
Each buyer instrument meets a predictable seller counter that converts a buyer's instrument into a vendor's service; the reply always returns the instrument to the buyer's side of the table, and none is adversarial — a good vendor agrees to all nine, and their agreement is itself a signal.
- **Apply**: Expect the counter and know the reply (e.g., "that's covered in the MSA" → read it aloud; "we'll connect you with the perfect customer" → gratefully, and also one we found ourselves). Treat agreement as a positive signal, refusal as diagnostic.
**The Fast Lane**
When the clock is short, skip the arc and run four checks in order — Rights, Independence, Exposure, Drift — reporting them as priced exposures rather than objections. Signing with two logged exposures and a date beats refusing to sign and being overruled.
- **Apply**: Use when "the contract is on my desk and I'm expected to sign this week." Also covers the already-captured case (draw the map, price the exit, move one row) and the blind renewal (grade on outcomes; negotiate a shorter term with a standard attached rather than a discount).
**When to Walk (the decision table)**
Walking is a defined position, not a bluff: refusal of proof on your cases, no ownership schedule after two asks, an exit that can't be estimated, refusal to name an accountable person, every gate arriving with a deadline, a refused remediation date, or everything agreed and nothing written — each maps to walk (or buy smaller/shorter).
- **Apply**: Define the walk before you need it. A buyer who has never defined the walk has already priced their own position at zero; the goal is not to walk but a purchase made with eight artifacts.
**The Room (language for the four hardest moments)**
The sentences a buyer who has done this fifty times has and a buyer who has done it twice does not: declining the demo-first sequence, separating advocacy from audit without insulting the champion, asking the reference question a coached account can't answer, naming a bypass without accusing anyone, and refusing a deadline without refusing the deal.
- **Apply**: Use the scripted language in the four hardest moments so the discipline survives contact with real people and relationships.
---
### Maturity Model (B0–B5)
A ladder from vendor-defined correct to a contract with a life — B0: vendors define correct; B1: the standard exists and is signed; B2: advocacy and audit are separate names; B3: proof runs on the buyer's floor with thresholds set in advance; B4: rights scheduled and the exit priced before signature; B5: the contract has a life (gauges read on cadence, drift logged, VERIFIED re-run annually, renewals graded on outcomes).
- **Apply**: Locate the buying organization on the ladder. The tell: B4 claimed with an exit that has never been rehearsed is really B2.
*Analysis by The Business Engineer · businessengineer.ai*
---
# PART VIII — THE PRACTICE LAYER
Fifteen instruments distilled from published practice. They are cycle-agnostic: written for any capital buildout, vendor market, product decision, or multi-print season, never tied to one quarter, company, or figure.
## The operating modes
The mode is identified before anything is produced, from the request itself.
| Mode | Triggers | What it runs |
|---|---|---|
| **Strategic Analysis** (default) | "analyze", "break down", "deep dive", a company or industry name | The full engine, Layers 0–4 |
| **Visual Intelligence** | "visualize", "diagram", "chart", "plate", "infographic" | The visual register (Instrument O) |
| **Framework Lookup** | "mental model", "which framework", "find the model" | Parts I–II search and application |
| **Capital-Cycle Print** | an earnings print, "has X absorbed / paid for / overshot the build" | Instrument A |
| **Season Map** | "map of the cycle", multi-print synthesis, "capstone", tracker | Instrument F |
| **Buyer-Side Capture Audit** | "lock-in", "dependency audit", "exit cost", "clear title" | Instruments E and J |
| **Valuation** | "what is it worth", "multiple", "run-rate", "residual" | Instrument I |
| **Deployment Decision** | "deploy", "rollout", "proof of value", "landing" | Instrument K |
| **Organization Climb** | "our people are faster", "transformation", "reorg", "ratio" | Instrument L |
| **Roles and Grid** | "hire", "who owns", "team", "chief AI officer" | Instrument L |
| **Junction and Geopolitics** | "export controls", "sovereign", "chokepoint", "standard" | Instrument M |
| **Financing Structure** | "off balance sheet", "how is it funded", "credit" | Instruments C and D |
## Framework selection — the routing table
| Question | Reach for |
|---|---|
| How does this business work? | VTDF (66), Value Chain, the four evaluation lenses |
| Is it defensible? | Moat Hierarchy (38), Five Defensible Moats (39), Compound Moat (40) |
| How does it grow? | Flywheels (59–65), Traction-Momentum-Flywheel (62), Scalability Matrix (35) |
| What is blocking it? | Constraint Mapping (15), Bottleneck Cascade, Hidden Driver Detection (14) |
| How should it compete? | Weak Spot Analysis (46), Margin Conflict (47), Three Archetypes (45) |
| Where should it enter? | Strategy Lever (28), Blue Sea (29), MVA (30), Adjacent Niche (32) |
| Which seat is this print in? | Name the Seat (154), Absorption Capacity (114), Incidence Runs Opposite (166) |
| Is this earnings number real? | Sign of the Distortion (228), Related-Party Triple (160), Definition Moved (181) |
| What is it worth? | Multiple Comes Last (220), The Residual (222), Hidden Piers (223), Worthless Cases (224) |
| Where does the AI bill land? | Cost of Goods (174), Discovery Tax (175), Transmission Belt (149) |
| Who owns the junction? | Harness Is a Router (190), Barbell (192), Second Index (204), Only Door (205) |
| Will the next release absorb this? | Absorption Line (198), Co-Adaptation (193), Exhaust Flywheel (194) |
| Should we buy it, on what terms? | The Asymmetry (229), VERIFIED (230), Procurement Theater (231), Clear Title (136) |
| Why is our AI gain not in the margin? | Neutral Gain (239), Ascent Through Scales (240), Governed Middle (241), Ratio Rule (244) |
| Who should own AI here? | Four Ownerships (251), Absorb/Displace/Converge (252), The Grid (253) |
| Why did this become political? | Junction Rule (141), Independence Swap (142), Permission Layer (143), Cascade (140) |
| Is this a bubble? | Node-by-Node (137), Two Species (138), Amplifier Not Bubble (122), Fifth Clock (139) |
---
## A. The Capital-Cycle Print
**Format**: a question title — *Has [company] [absorbed / paid for / overshot / skipped / reached / escaped / priced / funded / bought / financed / conceded / collected] the build?* One falsifiable question per print, closed with a verdict. One verb per node; never reuse a verb in a season.
**Anatomy, in order**:
1. **Name the seat** (Model 154) before running any test. The ten seats each have their own tests; running the builder's tests on a bystander produces a confident wrong answer.
2. **Strip the marks first.** Separate the operating engine from revaluation gains, other income, and equity marks — and check the direction, because compensation charges and extinguishment losses distort the other way.
3. **Run the split.** Operating absorption and cash absorption are two tests that can disagree inside one company. Always run both.
4. **Place the node.** Each print resolves one named cross-company question that prior prints could not. If it resolves nothing new, it is a data update, not a piece.
5. **Verdict and carry.** One sentence answering the title question, plus what this node feeds into the season map.
The tape is a lens used at most once, late, and never as the load-bearing evidence: positioning moves in hours, macro in weeks, capital structure in years, asset returns over the build cycle. The price move is a minor observation; the structure is the analytical object.
## B. The Incidence Taxonomy
Every capital cycle has seats, and the seat decides the test. The builder pays in capex; the bystander pays through a shared input; the distributor pays through discovery; the control group opted out and expensed what others capitalized; the supplier is paid by the build; the funder supplies its capital; the integrator floats its working capital; the value-capture pole is paid by it and finances none of it; the rail clears what the build cannot summarize; the taxed pays in attention. Full definitions: Models 154–173 and 174–189.
**The financial-clock ladder**, built print by print: strain is company-specific, not sector-wide; the cost lands outside the builders too; inside one company the operating and cash clocks can diverge; at contracted floors, market risk converts into counterparty risk.
## C. The Financing Acid Test
Scores how a buildout is financed — concealment against visibility, self-funding against external dependence. Three axes, six gauges: **structure ratio** (risk-weighted off-book obligations over total forward obligation) and **velocity spread** (off-book growth minus capex growth: is the marginal dollar leaving the balance sheet); **external dependence** (external capital share of capex, capex as a share of operating cash flow) and **coverage** (total forward obligation over multi-year forward operating cash flow); **counterparty credit floor** (sub-investment-grade share of the forward obligation) and **take-out gap** (refinancing capacity over refinancing need).
**Design constraints, non-negotiable**: never divide a stock by a flow; risk-weight off-book tiers by deferral against transfer; every concealment gauge needs a cash-flow denominator or it becomes a scare index; render as needles on one shared calibration rail, because the spread between gauges is the finding and a composite averages it away; calibrate against a historical baseline to prove the instrument moves both ways; always publish the stated limits.
**Bands**: sound, financialized, stretched, fragile, pre-break.
**Stated limits**: trade-credit float at the assembly point is invisible to all six gauges; there is no supply-side column, so a supplier financing its own customers is scored only through the credit floor; and financing fragility alone rarely reaches pre-break, because the remaining distance is always the demand question. Financing structures are not the bubble; they are the amplifier a bubble would run through.
## D. The Reconciliation
Three tests that legitimately give three different answers — the disagreement is the answer.
1. **Income statement**: revenue against depreciation, never against capex.
2. **Capital**: cumulative capital deployed per dollar of revenue, plus the hurdle — required revenue equals capital deployed times the sum of one over asset life and the required return, divided by gross margin. Publish the sensitivity; asset life and gross margin are the highest-leverage variables. External estimates agree by vintage rather than by independence, so say so, and re-run the method at current run-rates rather than citing a figure that has aged.
3. **Funding**: where the money comes from and whether its character changed. Allocation becomes obligation.
**The counting rule**: count each end-customer dollar once, at the tier where the customer transacted. Strip intra-stack purchases; exclude tiers that are costs of tiers above. Naive addition of published run-rates overstates substantially.
**The counting asymmetry**, stated wherever the hurdle appears: capital is counted across the whole build while revenue is counted only where it transacts. The two honest repairs are to count capital only at the tier that deployed it, or to count revenue gross at every tier — never one of each. On compounding: when purchases of property and equipment run at roughly three times recognized depreciation, revenue must approximately triple over three years to cover the depreciation wave, which is about forty-four percent a year, not thirty-seven.
## E. The Enterprise Capture Test
The closing question: after the engagement ends, does the enterprise hold clear title to what compounds?
**Grades per artifact**: KEPT (exit is a config change), PARTIAL (exit is a project), CAPTURED (exit is a rebuild, and rebuilds are where exit plans go to die). **Capture levels per workload**: captured, aware, anchored, adapted, kept. **Doctrine**: the property line — own the junctions, rent the ends, across five junctions (control, capability, choice, cost, compound). **Three depths**: a ten-question screen in an afternoon, a board memo in two weeks, a full dependency audit. Interviews set the map; artifacts set the score. **Composite**: exit cost weighted by criticality, re-scored quarterly, with the priced-exit table as the deliverable that makes it real.
## F. The Layered-Map Season Method
For any multi-print cycle: define the layer map and the clocks up front, because each layer commits capital on its own horizon; one node per print, each resolving one named question; datapoints accumulate in a tracker while a separate master plan holds the spine and section order; mint named models per print and inventory them for the capstone; assemble when the season closes.
**The clocks**, instantiated per cycle: physical (years, committed, cannot un-decide), financial (quarters, engineered), efficiency (fastest, software absorbing physical constraint), adoption (demand-side telemetry), and political (return-insensitive state demand, which sets a floor rather than clearing a hurdle).
**The map is not the credit map**: value capture runs horizontally through layers, contagion runs vertically through the financing stack, and risk sits at the joints. Buildouts break bottom-up. Cheap early failures are information.
## G. Editorial and Epistemic Discipline
Bold the claim, never the evidence: one to three load-bearing sentences per section, and the bold phrases read end to end must carry the whole argument. Define the frame once at the top, then cascade; never stack framing premises through a piece. Every number sits inside an explanation of what it means. Never quote a point estimate without its range; include a confidence assessment and a list of what would change your mind in major reports; own errors openly in the body, because an error a reader finds first discredits everything around it. Refuse report-mill sizings. Zero-based baselines on every chart: if the caption says flat, the chart must look flat. Label composites as composites once, in an italic aside.
**External audience always.** Every deliverable is self-standing: no references to the drafting process, prior versions, or the conversation. Just write the thing.
## H. Register I — The Editorial Card
For artifacts where the data is the point: dashboards, scorecards, decks, comparison tables. White ground, teal and red accents, section labels in small caps, era cards with hairline borders, hero cards with a red border, large stat numbers, one compression block with a red left bar. Use it when the numbers are the subject. For anything that sits above a heading in a written piece, use Register II (Instrument O).
### I. The Valuation Toolbox (nine questions, the multiple last)
Ask in order: (1) what are you counting (the counted top line, Model 221); (2) what does it cost to produce (cost per accepted outcome, levers pulled versus available, the ceiling is not the average); (3) what compounds (residue, substrate, standard, owned model, junctions; rarely what the company sells); (4) owned versus rented (title; the exit priced both ways); (5) what is perishable (the absorption line → the residual); (6) whose money (two engines in both directions; trace every line to its payer; the circle); (7) what capital (builders: the three tests and the hurdle; financed builds: the acid test; labs: revenue per megawatt; apps: the margin path; EV equals equity plus debt plus what the balance sheet hides); (8) what kills it (three worthless cases with triggers); (9) the multiple on the residual, borrowed by layer, reconciled to the reported number by naming the question that made the gap.
**Instruments with formulas**: counted top line (tier → strip → exclude → gross-to-net → run-rate-to-year); margin path (measured, levers, trajectory with dates and capital, tail modelled separately); residual-adjusted cash flow (durable share grows with the compounding assets, perishable share decays per release, terminal value on the durable share only, discount rate by layer); circle-adjusted revenue (payer classes: own budget, partner credits, pilot allowance, the circle); EV bridge with hidden piers; probability-weighted worthless cases; layer multiple table.
**Meters**: counted-to-reported ratio · measured margin plus lever count · residual fraction · circle share · hidden-obligation multiple · reconciliation gap. **Grading**: V0–V5, where a maturity claimed with a gross run-rate in the headline is V0. **Hard rule**: the hostile reading is written first (Model 227), and every output states that it is analysis, not investment advice.
### J. VERIFIED (the buyer's qualification)
Eight letters, every letter an artifact: Verification owned (the frozen suite is the buyer's) · Economics read (the vendor's margin predicts its behaviour) · Rights scheduled (title on what compounds, in the contract) · Incentives separated (the champion is not the auditor) · Feasibility on your floor (the proof ran on the buyer's data and systems) · Independence priced (exit in engineer-months, rehearsed yearly) · Exposure governed (the behaviour-change audit beside the security review) · Drift instrumented (the drift log has an owner and a cadence). Run V·E·I before contact, F·R·E at the wedge's clock, I·D before signature, then annually. A failed letter does not block the purchase; it prices it. What VERIFIED refuses is the letter nobody checked.
**The theater screen** (Model 231) runs before the board: which parts of the evaluation could the vendor have staged. **The outcome-pricing stance**: outcome pricing is an end state; underwrite the hybrid and choose the ramp (Model 215).
### K. DEPLOY (the deployment decision sequence)
Discovery (four gates, the outcome in the customer's units, saying no in writing) · Envelope (the seven-layer shape, the data path, the autonomy tier and its junction, buy/build/rent, the model chosen last) · Proof (the MVP as contract, evaluations as acceptance, guardrails, approval, rollback) · Landing (the concurrent gauntlet, reviews volunteered, VERIFIED read from the vendor's side) · Outcome (baseline before, gauge page after, a return the finance seat accepts) · Yield (the harvest: reference architecture, product requirement, the refusal log). Grading rule: every letter has a date. Three rooms, one truth at three altitudes: engineers, the CTO and CISO, the executives. Run a book of business, never a single account, and track letters per account.
### L. The Climb (organization, seats, roles)
**Engine**: Stages 0–5 across four scales. Prime diagnostic: "Your people are faster. Is the firm ahead?" **Hard thresholds**: no ratio without a measured gate; residue capture at or above 90%; paved-road coverage including a shadow estimate; conversion time under ninety days; no naked revenue per employee; same-dated ratios; the import test is mandatory. **Six gauges**: loop share, adjudication ratio, residue capture, paved-road coverage, conversion time, aim traceability; headcount is excluded. **The memo rule**: a memo before the paved road is a walk-back waiting to happen. **The grid** (11 functions across, 5 accountable functions down) is the staffing instrument; the top row must hold the four ownerships regardless of titles; the seat that owns the standard never builds the loops. **The first rung**: a ninety-day apprenticeship whose credential is the case study with its failures. **Grading**: O0–O5 and W0–W5, where a stage claimed with a headcount number or a pilot count on the board page is one stage lower than claimed.
### M. The Junction Read (techno-geopolitics)
For any technology or buildout: (1) run the three tests, sited / standardised / chokeable; (2) find the junction, the intersecting technologies that turn an industry into a map; (3) locate the permission layer, who can revoke; (4) run the five clocks, adding the political one; (5) name the independence swap the adoption is making and when the dependency invoices; (6) read the fence at its thinnest point; (7) ask which power form the junction favours and what it does to war; (8) price the domestic bill and the institution that will be created to settle it; (9) state the three-generation lag and the falsification tests. Structure the piece as a cross-section: physical base → techno-industrial system → power system, with capital, institutions, and permissions as cross-cutting layers, not stages.
### N. The Thread — Shared Instruments Across the Library
The instruments are the framework; each discipline uses them, none replaces them. Reuse by name, never re-derive: the SUITE (the frozen referee) · the CHARTER (one page: outcome, standard, thresholds, surfaces, boundaries, tier, owner) · the GAUGE PAGE (the retention and renewal instrument) · the TWO SURFACES (human and agent) · the JUNCTION (where a private rule is encoded and enforced) · the RESIDUE (the decision loop's second output) · the PROPERTY LINE (own the junctions, rent the ends) · the DRIFT CHECK (re-scored on every release) · the ABSORPTION LINE (perishable versus durable) · the COUNTING RULE (each dollar once, at the tier it transacted) · the CIRCLE (supplier money returning as customer revenue) · the SEAT (the ten seats on the clock). Every long-form deliverable closes with a Thread section mapping the instruments used to where each is treated in full.
### O. Register II — Editorial Ink (supersedes the card/palette spec for essay plates)
**Selection rule**: if the plate sits above a heading in a written piece, use Register II; use the card register (Register I) only when the artifact IS the data (dashboards, scorecards, decks).
**Spec**: canvas 1240×900, pure white ground, palette ink #17171B / teal #0D6E6B / teal-2 #12908C / vermilion #C4342A / ochre #D19A2E / muted #7A756C / faint #D9D2C4; Georgia display, Inter kickers, mono ticks. Grid: kicker y=76, title y=134 (44px, carrying the section heading verbatim), subtitle y=178, rule y=202, drawing zone y=210–790, compression rule 810 / line 840, footer 876.
**Non-negotiables**: no boxes as containers (a box may be a drawn object, never a wrapper); one plate is one conceptual drawing, nameable in five words; every stroke rendered twice with slight bow and jitter; drawn glyphs only (rasterizers drop font arrows and checkmarks); full canvas, never banner strips; hatching and washes instead of flat fills; house furniture on every plate (teal top rule and masthead, title and italic dek, hero mechanism, labelled supporting detail, compression block with red left bar, two numbered questions, italic takeaway over the footer rule); no dates on plates; filenames as descriptive slugs numbered in paragraph order; every argument section gets a plate.
**Metaphor vocabulary**: valves on a pipe (moving constraint) · screw clamp (binding constraint) · pendulums of different lengths (different clocks) · geological strata (layer stack) · buckets in rain, one under an umbrella (differing absorption) · roots versus canopy (long-lived versus short-lived assets) · two figures carrying a slab (concentrated obligation) · slicer fanning tranches (securitisation) · castle and moat with birds flying over (uncopyable input) · meshed gears of two sizes (supply in years, demand in quarters) · gauge wired to a piggy bank · locomotive crossing trestled chasms (buildout through panics) · balance with hatched pans · a sieve with question-rows (valuation) · a lever with a pyramid on the long arm (consulting leverage) · a lens aperture between strata and a graph (the only door) · four gates in series (the window's defenses) · a staircase with a missing rung.
**Verification**: run the collision checker (text-vs-text with per-glyph advance widths, text-vs-shape, clip bounds, drawing zone bounds with the art wrapped in its own group) plus a full-resolution render of the hero and any dense plate, plus a contact sheet. If a drawn object is unreadable, swap the metaphor rather than adding a label. When preview is unavailable, say verification was programmatic only. Generate repetitive plate families from one template.
---
---
## THE QUALITY CHECKLIST
**Analytical rigor**
- [ ] The engine ran, Layers 0–4, no layer skipped
- [ ] The seat was named before any test (154)
- [ ] Mechanism identified, not just what happened but why
- [ ] Structural, not narrative — all four Layer 0 tests passed
- [ ] Marks stripped in both directions (228); the circle traced (160)
- [ ] The hostile reading written before the base case (227)
- [ ] The worthless case named with its trigger (224)
- [ ] The absorption line drawn: perishable against durable (198)
- [ ] Every ratio checked for stock over flow; every point estimate carries a range; the counting asymmetry stated wherever capital and revenue are counted on different bases
- [ ] The import test run on any borrowed case (245)
- [ ] Bottleneck mapped, flywheel identified, cross-domain connection made
- [ ] Compressed to one sentence, and actionable
**Writing register**
- [ ] Plain sentences, mostly one idea each; anything over roughly forty words split — measured, not asserted
- [ ] No fragment-lists posing as paragraphs; bold budget of ten to twelve load-bearing claims; em-dashes rationed and never stacked three deep
- [ ] Terms earned before use: the plain idea first, the name after; no jargon fired in sequence
- [ ] Compression means fewer ideas given room, not all ideas with the connective tissue removed
- [ ] Rhythm varied; identical sentence patterns repeated is the generated-text signature
- [ ] Self-standing external document: no drafting seams, no prior versions, no throat-clearing
- [ ] A dated why-now near the front of any framework piece; the instrument's limitation named inside the piece
**Presentation**
- [ ] Visual first; the primary output is a drawn mechanism, a chart, or a diagram
- [ ] Correct register: II for essay plates, I for data artifacts
- [ ] Attribution present on every artifact
- [ ] Verified by measurement — long-sentence counts, collision checks, spot renders — never by assurance
---
## EDITION NOTES
What this edition changed, so the differences from earlier files are known rather than discovered:
- **The core is 261, not 110 or 136.** Models 1–110 keep the full register and regain the Key Q the consolidated draft had dropped. Models 111–136 carry the capital-cycle families. Models 137–261 add nine categories: the supercycle premise and the fifth clock, the ten seats, incidence at the top of the stack, the intelligence stack, measurement under pressure, valuation, the enterprise, the organization, and the historical rhymes.
- **Fifty duplicate entries were resolved**, each to a single canonical home with pointers from the other seats.
- **The count is honest.** Models and apparatus are counted separately; the earlier headline figure counted mode cards, maturity rungs, and templates as frameworks.
- **Corrections of record.** The tape is demoted from the print's opener to a lens used once and late. The hurdle's convergence claim is replaced by the vintage argument and the counting asymmetry. The compounding rate is corrected to about forty-four percent a year. The acid test gains two stated limits — trade-credit float and the missing supply-side column. A fifth clock is added for return-insensitive state demand. The card-and-palette visual spec is superseded by Register II for essay plates.
---
*The disciplines say what and why. The engineering volumes say how. The playbooks say where and with whom. The core says which mechanism is running underneath all of it. This library holds all of it, in one instrument.*
**Analysis by The Business Engineer — by Gennaro Cuofano**
SHA-256: 3376b6d22bc47553df2ec5a30158f56cad916cee57dd5fd7c45f163d157c8e0b