Expound/Products

One standard, four products

Finality Assurance™ Standards (FAS) is a new kind of computation, not just another policy engine. It goes wherever a consequential decision is made, across the systems and AI agents you already run. It is targeted: start with one consequential decision and measure it against the way you handle that decision today.

Availability

What ships, and when.

FAS is available now. The three products that follow are in development, with no public release date; ask about design-partner access. The standard came out of building the Work Management product, which was used to govern its own development.

ProductWhat it doesStatus
Finality Assurance StandardsFASComputes whether consequential work is complete and what may happen next on that evidence.Available
Model RouterGoverned Multi-Route Selection (GMRS) + Constrained Policy Reinforcement Learning (CP-RL)Selects the whole way a job gets done, not which model answers.In development · no public date
Mechanistic Conflation EngineMCEFinds places where two different things were treated as one, and turns each confirmed finding into a control that stops it happening again.In development · no public date
Work ManagementAccepted WorkThe authority layer over organizational work.In development · no public date

FAS is the first product and the foundation. Each product that follows is built on it.

Questions buyers ask

Five questions buyers ask before they license FAS.

The products

Available

Finality Assurance Standards

FAS

Not looks done, but proven done: on evidence a second party can re-check without calling you.

Status
Available now
License
Proprietary standard; licensed
Conformance
Tested and certifiable
Implementations
Multiple languages
Integrates at
Application, control-plane, model, or infrastructure boundary

What it does

FAS computes whether consequential work is complete and what may happen next on that evidence. For each call it identifies the required evidence, excludes routes that cannot meet the requirements, computes what may be relied on now, limits what may happen next, and decides whether the evidence-cleared result counts as Accepted Work.

The problem it addresses

Done is asserted rather than computed, and every department and tool is free to invent its own meaning for authorized, ready, accepted, closed and current. Nothing computes what a named party may rely on, for what, until when.

What changes

The settable status field stops being the answer. A verdict is computed from evidence attached to the decision, against requirements written down before the work rather than assembled after it, and it is recomputed when anything underneath changes.

Technical value

One vocabulary for verdicts, case files, evidence classes and claim limits, specified precisely enough for a licensed implementation to be tested against it for conformance. The evidence each call needs is looked up from its context and an approved profile, not hard-coded.

Business value

Permission to rely on a result becomes something you can grant, limit, transfer and withdraw on the record, instead of something people assume. An audit reads what is attached instead of piecing it together.

Component map: six governed inputs on the left, the Finality Kernel in the center, four computed outputs on the right, and the verifier, Four-Corners Test, Continuous Finality, SVM and executors around itComponent map: six governed inputs on the left, the Finality Kernel in the center, four computed outputs on the right, and the verifier, Four-Corners Test, Continuous Finality, SVM and executors around it
What the kernel takes in, what it computes, and what runs around it. The kernel does not invent requirements, choose a route, approve itself, or perform the outside action.
Stage 9 · 10:56–12:58Full recording
The Finality Kernel, the Semantic Virtual Machine, and the components around the kernel.

Capabilities

Finality Kernel

The core computation. It takes the requirements, the classified evidence, who has authority, whether it is all still current and the exact action being asked about, and returns a case file (the Account), an answer (the Verdict) and a permission to act (the reliance license).

Obligation rosters

The list of what must be proved for each kind of decision: versioned, written down in advance, and applied by one general evaluator rather than hard-coded case by case.

Graded verdicts

Four grades (BLOCKED, UNKNOWN, DEGRADED, VERIFIED), where the whole result gets the grade of its weakest requirement. More than one way to pass, each tied to a specific decision.

Claim and reliance licenses

What may be said about a result, and who may act on it, for what and until when: two separate records with a fixed shape. Your industry supplies the ranking of decisions.

Independent verifier

Read-only; can narrow, hold or refuse a result, and can never raise one.

Four-Corners Test™

Whether a second party can reconstruct the determination from what is attached and nothing else.

Continuous Finality™

Who relied on what is recorded at the time; when something changes, everything affected is found, permissions are narrowed or withdrawn with notice, and history is preserved.

Semantic Virtual Machine

If a step is not allowed by the rules, the SVM will not run it.

Confidence Ladder™

Limits what may be claimed about whether a result reproduces, from R0 to R3, based on kept evidence. It shapes what you may say; it never grants permission to act.

Accepted Work

Only work that cleared its evidence requirements counts. A refusal is a legitimate outcome, not a failure to deliver.

In development

Model Router

GMRS + CP-RL

Today’s routers pick a model. The work needs a route.

Status
In development · no public date
License
Dual: AGPL and commercial
Built on
FAS
Selects
Model or person · tools · evidence · checks · stopping rules · budgets · escalation
Cannot
Choose what evidence counts, or create Accepted Work

What it does

It selects the whole way a job gets done, not which model answers. A route is the model or the person, the tools, the evidence to be gathered, the checking to be performed, the stopping rules, the budgets, and when to escalate.

The problem it addresses

Routing today ranks models on cost, latency and a quality score. Nothing checks that the chosen path could even produce the evidence the question needs, and an optimizer that can loosen its own rules effectively has none.

What changes

Eligibility is decided before anything is ranked. Routes that cannot produce what the result has to prove are ruled out first; a control from the conflation engine enters as a hard rule, not a preference; and sending the job to a person is a route the rules can choose like any other. If no eligible route remains, the router stops and names what was missing rather than returning the best of a bad set.

Technical value

A route is a commitment, not a preference. Two routes can use the same model and still be different routes, because the evidence, checks and stopping rules attached to them differ, and so does the full cost of reaching an outcome. The route that was selected is tied to the route that actually ran.

Business value

Spend follows what the decision actually requires, and no score buys its way around a hard requirement. The learning half ranks eligible routes and can never widen the set.

Harvey-ball comparison of today's model routers against GMRS plus CP-RL across eleven dimensionsHarvey-ball comparison of today's model routers against GMRS plus CP-RL across eleven dimensions
What each layer keeps track of. A router selects a model; a governed route selects the whole path, and when nothing is eligible it holds and names the condition that failed.
Six-stage flow: typed call context, call-specific evidence set, GMRS admissibility, CP-RL ranking, route execution, kernel reliance decisionSix-stage flow: typed call context, call-specific evidence set, GMRS admissibility, CP-RL ranking, route execution, kernel reliance decision
One call through the router. The requirements are looked up for this call, routes that cannot meet them are ruled out, eligible routes are ranked, the route runs and returns evidence, and the kernel decides what may be relied on.
Stage 8 · 8:41–10:56Full recording
Evidence requirements looked up for each call; routes that cannot meet them ruled out before ranking.

Capabilities

Governed Multi-Route Selection

Keeps only the routes that can produce the evidence this call needs. Eligibility comes before ranking.

Constrained Policy RL

Ranks eligible routes only. It cannot decide eligibility, change evidence requirements, weaken obligations, widen what may be claimed, or promote itself.

Governed hold

When no route is eligible, the output is a clear refusal that names what was missing: something you can act on, not a silent best effort.

Escalation as a route

A person is a route like any other, with its own evidence requirements, chosen by the rules rather than bolted on when automation fails.

MCE controls as constraints

A route whose model has a known failure the work cannot tolerate is ruled out, not just marked down.

Promotion gate

A newly learned policy goes live only through a governed decision with its own evidence. The learner must be able to be told no.

In development

Mechanistic Conflation Engine

MCE

A defect found once becomes a defense everywhere it applies.

Status
In development · no public date
License
Separately licensable
Releases
No public date; follows the Model Router
May
Detect · cap · refuse · quarantine · propose
May not
Write the verdict, decide finality, or promote its own findings

What it does

A conflation is treating two different things as if they were the same: a command returning as the change happening, a valid signature as an authorized signer. MCE scans agentic work for them, and turns a validated finding into a control that stops it recurring.

The problem it addresses

Before a result reaches anyone, a run decides what question is being answered, which evidence is relevant, whether a failed step should be retried, whether an observed effect establishes the intended outcome, and whether the work is complete. Those are different questions, and success at one establishes nothing about another.

What changes

Known kinds of failure are enforced by fixed rules rather than rediscovered team by team, and a newly spotted one enters only as a candidate. Nothing the discovery side notices takes effect until it has been approved by someone outside it.

Technical value

It cuts across the whole system rather than sitting at one step in a sequence. It limits what the other parts may do, and it scans the controls themselves: a detector that cannot fail, a control present but never applied, a cure that reintroduces what it was written against.

Business value

A failure family under standing control stops being rediscovered team by team. What it hands the router is a hard rule, not a preference.

Capabilities

Execution conflation

A command that ran, read as the change having happened. A command returning is not the intended effect happening.

Method conflation

A test that failed, read as proof the safeguard works.

Authority conflation

A record existing, read as the record having been properly issued; a valid signature read as an authorized signer.

Trust-domain conflation

Two separate processes read as two independent sources.

Custody conflation

A secret deleted today, read as never having been exposed.

Governed promotion

A confirmed detector becomes a permanent, machine-enforced control only after approval from outside the discovery side.

In development

Work Management

Accepted Work

There is no field named state to set.

Status
In development · no public date
Role
The first full implementation of FAS; it governed its own development
Organizes around
Capabilities: build · stabilize · keep · retire
Unit
Accepted Work, and its cost
Replaces
Authority claimed by ticketing, CI, release, audit, observability
Leaves in place
The work each of those tools is actually good at

What it does

It is the authority layer over organizational work: the system that decides whether a piece of work can be relied upon, and does not let anyone overturn that by saying so.

The problem it addresses

Authority over what done means is claimed separately today by ticketing, requirements, test management, continuous integration, release and change, security closure, audit, observability and knowledge bases, none of which was built to agree with the others. A checkmark is three assertions in one gesture: that the work was planned, that it was done, and that acceptance was achieved.

What changes

Nobody drags a card to Done, types a percent complete, or signs a readiness checklist, because those are not operations here. Progress and readiness are computed from what actually landed. Typing a computed value into a status field is treated as a bug, not a feature.

Technical value

Every change of state passes through one gate, carrying its authorization and evidence, so no tool, dashboard, agent or person has a back door to the verdict. People set policy, handle exceptions and decide contested cases: they authorize, and they do not edit the verdict.

Business value

The unit of measure is Accepted Work and its cost, not output. A refusal is a legitimate outcome, not a failure to deliver. When permission to rely on something is withdrawn, the work that rested on it is found automatically and comes back with its reasons attached.

Capabilities

Capability-first, not project-first

The organizing unit is a lasting ability with an owner, evidence obligations, a map of what it depends on, and a computed status: build, stabilize, keep or retire. Every tool underneath plugs into it.

Computed lifecycle

Readiness and state derived from what landed, under obligations declared before the work starts.

One registered boundary

Every state change carries authorization and evidence through a single gate. No back door.

Producer never grades

The actor that produced a piece of work never grades it.

Governed exceptions

Held, classified, explained, with the missing requirement named: a record, not an override.

Accepted Work per Dollar

Governed value against the full cost of all attempts. Refused attempts stay in the denominator.

Dependency-driven reopening

When Continuous Finality withdraws reliance, dependent work returns to the queue with its reasons attached.

Governed feature flags

A flip is an approved change with declared evidence, and everything that depended on the old behavior is recomputed. A flag flip is a release.

Self-governed construction

Used to govern its own construction from early on; the standard is what remained after enough of those changes.

How Work Management is organized

Capabilities, not projects.

It begins from what an organization must be able to do: compute acceptance, control who can change state, produce evidence, verify independently, deploy accepted work, watch what is running, and preserve knowledge. Every harness, workflow engine, registry and deployment tool then plugs in underneath rather than being the architecture.

A capability is a durable ability, not a roadmap label. It carries an owner, who it serves, its business value, target maturity, what it depends on, evidence obligations, exit criteria, health metrics, governance debt, acceptance state, and its contribution to Accepted Work. From health, evidence and governance debt the system computes one of four statuses.

BUILDNeeded and not yet mature. Invest.
STABILIZEExists, but evidence or health is slipping.
KEEPMature, evidenced, healthy.
RETIRESuperseded or no longer needed. A computed terminal state; lineage preserved.

Because dependencies form a governed graph, the questions executives ask become queries: what can we delegate on the evidence, what blocks the release, what did accepted work cost.

What becomes possibleWhat it replacesWhy it works
Governed feature flagsMutable runtime booleans anyone with write access can flipA flip is an approved change with declared evidence, recomputation of everything affected, and a dated record
Computed lifecycle and readinessDragged cards, percent-complete fields, status meetingsState is derived from what actually landed, with a receipt showing how
Computed admissionApproval clicks and sign-off chainsThe decision is computed from evidence against a declared roster; a person contributes evidence and policy, not a checkmark
Delivery in a contracted orderRun-order conventions and tribal deploy knowledgePrerequisites are an order a machine can check; violations are refused up front, not discovered as incidents
Recorded reliance edgesInstitutional memory of who depends on whatReliance is recorded when taken, so withdrawal, notification and unwind are computations
Blast-radius previewImpact guesswork before a risky changeEverything a proposed change would affect, directly or indirectly, is computed before it is approved
Attempts that say what they were forCI readouts judged by exit statusEvery attempt says what it was for, so a test that was supposed to fail and passed is read as the failure it is

Licensing at a glance

Proprietary, published, licensed, conformance-tested.

ProductLicense modelNotesStatus
Finality Assurance StandardsProprietary standard, published and licensedConformance testing; certification of conforming implementationsAvailable now
Model Router (GMRS + CP-RL)Dual: AGPL and commercialOpen core, commercial terms for enterpriseIn development; no public date
Mechanistic Conflation EngineSeparately licensableFollows the Model RouterIn development; no public date
Work ManagementCommercial; reference implementation of the familyGoverns its own constructionIn development; no public date

FAS is a proprietary, published standard, the model Dolby, UL and Qualcomm use. The specification is owned and published by its author, it is licensed, an implementation is tested against it for conformance, and a conforming implementation can be certified. Patent pending.

What makes it a standard is not who owns it. It is that the specification is precise enough for a licensed implementation to be tested against it for conformance. A reliance object only its author’s agents can produce, and only its author’s systems can read, is that author’s own status field under a new name.

Deployment

You choose where it runs.

The standard does not dictate one integration point, which is the practical reason to start with it. It plugs in at whichever layer suits each kind of work (the application, the control plane, the model and orchestration layer, or the infrastructure), with no single central runtime.

Where it can sit

Major cloud services; model gateways and agent runtimes; central or distributed enterprise control planes; libraries, sidecars and gateways; on-premises, cloud, hybrid, confidential, edge and disconnected environments; and selected firmware, secure-enclave and chip-level controls.

What placement changes

What may be claimed, not the rules. Evidence that comes from inside the system that did the work proves the process ran, not that the effect independently happened, and the Account records which.

What is not flexible

How results are read. Wherever the computation sits, anyone using a consequential result gets it by taking a license, because a read that goes around the license cannot be found when the result is later withdrawn.

How to start

Start with the standard, whether or not you adopt the systems.

01

Run the test

Take one determination your agents produced this week. Run the Four-Corners Test on it. No tooling needed.

02

Name one decision

One that you would struggle to defend afterward. Ask whether its obligations can be written down and its evidence classes named.

03

License FAS

The standard is the place to start. Implementations exist in multiple languages; you pick the integration point.

04

Conform, then build on it

Conformance testing and certification go through the lab. The router, MCE and the Work Management product arrive on the same standard.