---
title: "The platform's build architecture: what we decided, and what it rests on."
seo_title: "Platform architecture: decisions and references | SazAI"
description: "How SazAI is built: format-blind engines, lineage, versioned decisions, validation with method, and the roadmap."
tags: [marketing]
icon: book
---

> **Conclusion: the accelerator is the team's command over the substrate; and no decision here is taste: the choice is written down, with what was discarded and why.** The pyramid below is the map; the gap stays outside it, stated.

<div class="chap">

<div class="ico-col"><span class="ico"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:36px;height:36px"><path d="M24 8l16 8-16 8-16-8z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M8 24l16 8 16-8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M8 32l16 8 16-8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg></span></div>

## What SazAI is

<h3 class="sub">Engines, components and documentation, mastered by whoever built them</h3>

SazAI is the platform: the intelligence and proof substrate the products are
built on. Multi-tenancy, authentication, lineage, orchestration, agent layer, exact metering,
and versioned decisions, built once. SazAI Corpus, the vault, and the design system are the
products that have already come out of it, and each one uses the same engine instead of rebuilding it.

The panels descend by anchor strength, and each one closes with its references in an expandable block, for whoever wants to check. Citations follow the ABNT NBR 6023 standard, 2018.

<figure class="viz" role="group" aria-label="The pyramid on this page: four anchor strengths, from execution dependency to positioning, and the gap on the outside">
<div class="duo" style="grid-template-columns:auto 1fr">
<div class="mid"><svg viewBox="0 0 220 170" aria-hidden="true" style="width:200px">
<polygon points="110,10 150,50 70,50" fill="var(--hue-analysis)" opacity=".85"/>
<polygon points="64,58 156,58 176,92 44,92" fill="var(--hue-output)" opacity=".65"/>
<polygon points="38,100 182,100 198,130 22,130" fill="var(--hue-upload)" opacity=".5"/>
<polygon points="16,138 204,138 214,160 6,160" fill="var(--hue-reprocess)" opacity=".35"/>
<rect x="180" y="8" width="34" height="34" rx="4" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none" stroke-dasharray="4 3" style="color:var(--gray)"/>
</svg></div>
<div class="side" style="text-align:left">
<b style="color:var(--hue-analysis)">execution dependency</b><span>the engine does not run without the standard · step 1</span>
<b style="color:var(--hue-output);margin-top:.5rem">standard applied and measured</b><span>law in the schema, criterion in the component, contrast by token · steps 2 to 4</span>
<b style="color:var(--hue-upload);margin-top:.5rem">recorded decision</b><span>choice written down, with what was discarded and why · steps 5 and 6</span>
<b style="color:var(--hue-reprocess);margin-top:.5rem">positioning</b><span>studies with the caveat attached · step 7</span>
<b style="color:var(--gray);margin-top:.5rem">the gap</b><span>outside the pyramid, and stated · last panel</span>
</div>
</div>
<figcaption>Anchor strength decides the height. What holds up nothing stays outside the drawing, dashed, with its own panel.</figcaption>
</figure>

It is not plug and play for someone arriving from outside. **The accelerator is not the
substrate; it is the team's command over it.** Whoever knows the engines, the components and the
documentation builds a new SaaS product from what already exists, and the rest of this page is the measure of how much that shortens the path.

<figure class="viz duo" role="group" aria-label="Engines, components and documentation; the team's command in the middle; the products that come out">
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><rect x="10" y="10" width="28" height="28" rx="4" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="24" cy="24" r="6" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="24" y1="4" x2="24" y2="10" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="24" y1="38" x2="24" y2="44" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="4" y1="24" x2="10" y2="24" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="38" y1="24" x2="44" y2="24" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>the substrate</b>engines, components, documentation</div>
<div class="mid" style="color:var(--hue-upload)"><svg viewBox="0 0 120 72" aria-hidden="true"><line x1="6" y1="36" x2="40" y2="36" stroke="currentColor" stroke-width="1.5"/><path d="M34 31l6 5-6 5" fill="none" stroke="currentColor" stroke-width="1.5"/><circle cx="60" cy="36" r="14" fill="currentColor" opacity=".12" stroke="currentColor" stroke-width="1.5"/><path d="M54 36l4 4 8-8" fill="none" stroke="currentColor" stroke-width="1.5"/><line x1="80" y1="36" x2="114" y2="36" stroke="var(--hue-output)" stroke-width="1.5"/><path d="M108 31l6 5-6 5" fill="none" stroke="var(--hue-output)" stroke-width="1.5"/></svg><b>the team's command</b>is what accelerates</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><rect x="8" y="12" width="32" height="24" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="8" y1="20" x2="40" y2="20" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="13" cy="16" r="1.4" fill="currentColor"/><circle cx="18" cy="16" r="1.4" fill="currentColor"/></svg><b>the products</b>Corpus, vault, design system</div>
</figure>

The frame for this idea is not new, and not from this page: it is the eighth of the nine
pillars SazAI describes itself with, *platform before product*. What follows is its evidence.

</div>

<div class="chap">

<div class="ico-col"><sz-icon style="color:var(--hue-analysis)" name="file" size="36"></sz-icon></div>

## The engine depends on format standards to exist

<h3 class="sub">Step 1 · execution dependency, the strongest anchor there is</h3>

If the standard were wrong in the code, the engine would not run. The reference is not
mentioned; it is depended on, and determinism comes out of that.

**Data and facts:**

- OOXML namespace in the engine: 237 occurrences across 37 distinct forms (2026-09-01).
- Dublin Core as a dependency: 22 namespaces. ISO 8601: the most cited standard in the database, 60 occurrences.
- The checkable chain: published clause → DDL column comment → data map → column. Paraphrase forbidden by written rule; DDL and map carry the same clause, verbatim.

<figure class="viz duo four" role="group" aria-label="The chain of determinism: published clause, DDL comment, map layer, relational column">
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:40px;height:40px"><path d="M12 6h18l8 8v28H12z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M30 6v8h8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="24" x2="32" y2="24" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>published clause</b>the standard, by number</div>
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:40px;height:40px"><rect x="8" y="10" width="32" height="28" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="14" y1="18" x2="34" y2="18" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none" stroke-dasharray="3 2"/><line x1="14" y1="25" x2="30" y2="25" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="14" y1="31" x2="30" y2="31" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>DDL comment</b>the same clause, verbatim</div>
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:40px;height:40px"><circle cx="14" cy="14" r="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="34" cy="18" r="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="22" cy="34" r="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="17" y1="17" x2="31" y2="16" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="16" y1="18" x2="20" y2="30" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>map layer</b>no paraphrase, by rule</div>
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:40px;height:40px"><rect x="8" y="8" width="32" height="32" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="20" y1="8" x2="20" y2="40" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="8" y1="20" x2="40" y2="20" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>relational column</b>exists because the clause exists</div>
</figure>


### And the next format costs less

The first format was PowerPoint, and it cost the whole engine: reading, measuring, translating,
writing back, comparing, all for the first time. The second, the Word document, cost one
order of magnitude less. The third, the spreadsheet, one more. And the fourth, PDF, cost the same as
the third: the curve stabilized. It is not a list of achievements; it is a curve, and the
curve is the argument.

<figure class="viz curve" role="group" aria-label="Cost of each format through the full cycle, on a logarithmic scale: the first cost the whole engine, each next one an order of magnitude less, and the fourth stabilizes at the same cost as the third">
<div class="row ooxml"><b>PPTX</b><span class="track"><span class="bar" style="width:100%"></span></span><em>the whole engine</em></div>
<div class="row ooxml"><b>DOCX</b><span class="track"><span class="bar" style="width:46%"></span></span><em>one order less</em></div>
<div class="row ooxml"><b>XLSX</b><span class="track"><span class="bar" style="width:16%"></span></span><em>one more</em></div>
<div class="row other"><b>PDF</b><span class="track"><span class="bar" style="width:15%"></span></span><em>stabilizes</em></div>
<figcaption>Logarithmic scale: each step is an order of magnitude. The fourth point is not just the smallest: it is of a different nature, and it cost the same as the third.</figcaption>
</figure>

<p class="claim">The <b>PDF is the first substrate that is not Office</b>: a binary graph of objects instead of zip plus XML. If the engine had only gotten good at PowerPoint, the fourth format would have cost like the first. It cost like the third. <b>The engine did not get faster at PowerPoint; it became format-agnostic</b>, and the <a href="documents">four formats</a> run today on the same architecture, each with its own declared guarantee. That is why the fifth will cost what the fourth cost, and that is what this page calls acceleration.</p>

<div class="bound">
<p><b>Where this is recorded, stated before you ask.</b> In git, not in the institutional diary: the curve rests on dated decisions and commits, which are the right source for an interval, and that is what gets checked in an evaluation. The absolute times for each format live in the technical document, with the command that derives them next to it.</p>
</div>
<details class="refs"><summary>References and recorded decisions</summary>
<div>
<p><b>What is written, and what was discarded</b></p><ul><li>Read each format by the standard, clause by clause; the heuristic was discarded because it does not survive an audit.</li><li>Dates in ISO 8601 across the whole system; metadata by Dublin Core.</li><li>PDF accepted as the first non-Office substrate, cited by its own standard.</li></ul><p><b>References (ABNT NBR 6023:2018)</b></p><ul><li>ECMA INTERNATIONAL. <b>ECMA-376</b>: Office Open XML File Formats. Available at: https://ecma-international.org/publications-and-standards/standards/ecma-376/.</li><li>ISO/IEC. <b>ISO/IEC 29500</b>: Office Open XML File Formats.</li><li>ISO. <b>ISO 32000-1</b>: Portable Document Format. · ISO. <b>ISO 19005</b>: PDF/A.</li><li>ISO. <b>ISO 15836-1</b>: Dublin Core. · ISO. <b>ISO 8601</b>: Date and time.</li><li>IETF. <b>RFC 5646</b>: Tags for Identifying Languages.</li><li>MICROSOFT. <b>MS-PPTX · MS-DOCX · MS-OE376 · MS-ODRAWXML · MS-OFFCRYPTO</b>: implementation notes.</li><li>UNICODE CONSORTIUM. <b>Unicode CMap</b> specifications.</li></ul>
</div>
</details>

</div>

<div class="chap">

<div class="ico-col"><span class="ico"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:36px;height:36px"><circle cx="24" cy="24" r="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="10" cy="12" r="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="38" cy="10" r="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="12" cy="38" r="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="38" cy="36" r="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="13" y1="14" x2="20" y2="21" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="35" y1="12" x2="28" y2="21" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="14" y1="36" x2="20" y2="27" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="35" y1="34" x2="28" y2="27" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg></span></div>

## The body of knowledge

<h3 class="sub">Everything we decided, measured, and wrote, linked, and navigable by the team and by agents</h3>

The team's command over the substrate has a place where it lives: an Obsidian vault that
mirrors the repository. Decisions, the data map, agent contracts, personas, strategy, working
sessions: each note links to the others, and hubs are the doors a person or an
agent enters through. It is the same graph the product delivers to the customer in their own vault, used first on
ourselves. Below, ours, in motion; hover a hub to see what it links, and click
to open it in full.

<figure class="viz graph" id="vault-graph" role="group" tabindex="0" aria-label="The graph of the SazAI vault: the hubs for decisions, agents, data map, product, strategy, operations, people, pitch, and personas, linked to each other and to their notes">
<div class="stage"><svg viewBox="0 0 800 520" aria-hidden="true"><g class="edges"></g><g class="nodes"></g></svg><div class="labels" aria-hidden="true"></div></div>
<figcaption>The SazAI vault, as the team sees it every day. Each point is a note; each line, a link someone wrote. The hubs have names; the rest is what they link. Node set photographed by hand on 2026-08-28; when the vault's automatic derivation lands, this line comes out.</figcaption>
</figure>

<div class="bound">
<p><b>How far the map reaches, measured, and it is the part worth most.</b> The vault graph reaches 55 of the 158 data-map tables and one of the five format maps; the repository reaches 158 of 158. A figure that showed everything connected would be this page's only claim with no receipt behind it, on a page whose whole subject is that our claims carry receipts. What is validated is not that everything connects: it is that we know exactly what connects and what does not. Where the map is silent, the repository answers.</p>
</div>

</div>

<div class="chap">

<div class="ico-col"><sz-icon style="color:var(--hue-reprocess)" name="info" size="36"></sz-icon></div>

## Data protection is design, and design gets audited

<h3 class="sub">Step 2 · the law became schema, and the schema is checkable</h3>

What the law asks for in writing, the database fulfills through structure. Verification is not
reading our policy; it is auditing the schema.

**Data and facts:**

- Permanent storage carries no document content; content lives in a separate database, sensitive and erasable.
- Isolation by tenant as a column, not as a promise: slices never cross tenants.
- Certification today: none. Controls designed to serve as evidence when it is sought.

<figure class="viz duo" role="group" aria-label="Two databases: the permanent one with no content, and the sensitive one, separate and erasable">
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><ellipse cx="24" cy="12" rx="14" ry="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M10 12v24c0 3 6 5 14 5s14-2 14-5V12" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="16" y1="22" x2="32" y2="22" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="16" y1="29" x2="28" y2="29" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>permanent</b>structure, measurement, lineage; content, never</div>
<div class="mid" style="color:var(--gray)"><svg viewBox="0 0 120 72" aria-hidden="true"><line x1="60" y1="10" x2="60" y2="62" stroke="currentColor" stroke-width="1.5" stroke-dasharray="4 3"/></svg><b>separated by design</b>audit the schema</div>
<div class="side" style="color:var(--hue-reprocess)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><ellipse cx="24" cy="12" rx="14" ry="5" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M10 12v24c0 3 6 5 14 5s14-2 14-5V12" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none" stroke-dasharray="4 3"/><line x1="18" y1="26" x2="30" y2="34" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="30" y1="26" x2="18" y2="34" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>sensitive</b>the content, genuinely erasable</div>
</figure>

<details class="refs"><summary>References and recorded decisions</summary>
<div>
<p><b>What is written, and what was discarded</b></p><ul><li>Privacy by design and by default as architecture; a compliance layer over a shared database was discarded.</li><li>Removal is called <b>withdrawal</b>, not deletion: the stronger word was discarded because it promised a reach that backups do not sustain.</li></ul><p><b>References (ABNT NBR 6023:2018)</b></p><ul><li>EUROPEAN UNION. <b>Regulation (EU) 2016/679</b> (GDPR), art. 25.</li><li>BRAZIL. <b>Law No. 13,709, of August 14, 2018</b> (LGPD).</li><li>CAVOUKIAN, Ann. <b>Privacy by Design</b>: the 7 foundational principles. Toronto: IPC, 2009.</li><li>ISO/IEC. <b>ISO/IEC 27001</b>. · OWASP FOUNDATION. Available at: https://owasp.org/.</li></ul>
</div>
</details>

</div>

<div class="chap">

<div class="ico-col"><sz-icon style="color:var(--hue-output)" name="eye" size="36"></sz-icon></div>

## Accessibility is measured, not declared

<h3 class="sub">Step 3 · a cited standard is compliance; a measured number is design</h3>

The criterion lives in the component, with the number next to the code, and contrast is
measured before a color enters the system.

**Data and facts:**

- WCAG 2.2 AA across 51 design-system files, with criteria cited by number (1.4.1, 3.1) (2026-09-01).
- Contrast measured per token: `--hue-lineage` at 4.00:1 with the note *guide, never text* written inside the token itself; `--text-faint` **failed** for measuring 2.56:1 on white, and the failure recorded.
- Color blindness measured: the purple evaluated under deuteranopia, color distance ΔE 29.1.
- Zero architecture decisions record WCAG; the house's strongest accessibility anchor is invisible in the decision record, and recording it is work still to do.

<figure class="viz" role="group" aria-label="Three color measurements: one token approved as a guide, one failed, and the purple measured under deuteranopia">
<div class="duo" style="grid-template-columns:1fr 1fr 1fr">
<div class="side"><div class="ev proof" style="margin:0"><span class="n">4.00:1</span><span class="t"><b>approved as a guide</b>with the note <i>guide, never text</i> written inside the token itself</span></div></div>
<div class="side"><div class="ev open" style="margin:0"><span class="n">2.56:1</span><span class="t"><b>failed</b>measured on white, and the failure recorded</span></div></div>
<div class="side"><div class="ev proof" style="margin:0"><span class="n">ΔE 29.1</span><span class="t"><b>deuteranopia</b>the purple measured under the most common color deficiency</span></div></div>
</div>
<figcaption>A cited standard is compliance; a measured number is design. The three numbers live in the tokens, not in a policy.</figcaption>
</figure>

### The design system is a product, built on an open standard

<h3 class="sub">Step 4 · the accelerator for the other surfaces, in W3C standard</h3>

The design system is a SazAI product by ratification (2026-08-26), with the function of
accelerating the others: the components that serve marketing, the vault and the showcase are
the same ones, and they are open standard, not a proprietary framework.

**Data and facts:**

- Components built on W3C Custom Elements and CSS Custom Properties; no framework dependency.
- One library, three surfaces served; light and dark themes and white-label skins through the same token mechanism.
- The tokens carry their own measurements and usage notes (step 3), so the rule travels with the color.

<figure class="viz duo" role="group" aria-label="One component library serving three surfaces">
<div class="side" style="color:var(--verb-see)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><rect x="8" y="8" width="14" height="14" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><rect x="26" y="8" width="14" height="14" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><rect x="8" y="26" width="14" height="14" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><rect x="26" y="26" width="14" height="14" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>one library</b>components, tokens, skins</div>
<div class="mid" style="color:var(--gray)"><svg viewBox="0 0 120 72" aria-hidden="true"><line x1="10" y1="36" x2="55" y2="36" stroke="currentColor" stroke-width="1.5"/><line x1="55" y1="36" x2="105" y2="14" stroke="currentColor" stroke-width="1.5"/><line x1="55" y1="36" x2="105" y2="36" stroke="currentColor" stroke-width="1.5"/><line x1="55" y1="36" x2="105" y2="58" stroke="currentColor" stroke-width="1.5"/></svg><b>the same mechanism</b>themes and white label by token</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><rect x="6" y="8" width="36" height="10" rx="2" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><rect x="6" y="22" width="36" height="10" rx="2" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><rect x="6" y="36" width="36" height="6" rx="2" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>three surfaces</b>marketing, vault, showcase</div>
</figure>


<details class="refs"><summary>References and recorded decisions</summary>
<div><p><b>What is written, and what was discarded</b></p><ul><li>Criterion by number in the component that fulfills it; the central policy page was discarded.</li><li>Word out of design: text in HTML, geometry in SVG.</li></ul><p><b>References (ABNT NBR 6023:2018)</b></p><ul><li>W3C. <b>WCAG 2.2</b>: Web Content Accessibility Guidelines, level AA. Recommendation, 2023. Available at: https://www.w3.org/TR/WCAG22/.</li></ul><p><b>What is written, and what was discarded</b></p><ul><li>Standard Web Components; the proprietary framework was discarded so white label would not depend on a license of ours.</li><li>Held to the same standard as any surface: a suite that runs, guards that refuse at build.</li></ul><p><b>References (ABNT NBR 6023:2018)</b></p><ul><li>W3C. <b>Custom Elements</b> (HTML Living Standard). · W3C. <b>CSS Custom Properties for Cascading Variables</b>.</li></ul></div>
</details>

</div>

<div class="chap">

<div class="ico-col"><sz-icon style="color:var(--hue-analysis)" name="globe" size="36"></sz-icon></div>

## Channels are capability: API and MCP change what the product can be

<h3 class="sub">Step 5 · open standards at the door, and what they enable</h3>

Open API and MCP are not plumbing: they are what allows other interfaces and connections
to be built on the same substrate, without us in the room. A third-party agent, a dashboard
of your own, a workflow integration: the product becomes able to be those things because the channels exist.

**Data and facts:**

- The agent channel is a standard OAuth resource server: 401 with no credential, discovery published.
- Parity as contract: **MCP ⊆ OpenAPI**, everything MCP exposes exists in the open API. One substrate, several readers.
- Orchestration by a durable workflow execution tool, adopted for what it guarantees, and the guarantee is measured: dead work leaves no partial state; overload degrades into a queue, it does not break; nothing fails silently.

<figure class="viz duo" role="group" aria-label="One substrate, two channels, and the interfaces they enable">
<div class="side" style="color:var(--hue-analysis)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><rect x="10" y="10" width="28" height="28" rx="4" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="24" cy="24" r="6" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>one substrate</b>the engine and the vault</div>
<div class="mid" style="color:var(--hue-upload)"><svg viewBox="0 0 120 72" aria-hidden="true"><rect x="38" y="14" width="44" height="18" rx="9" stroke="currentColor" stroke-width="1.5" fill="currentColor" opacity=".12"/><rect x="38" y="40" width="44" height="18" rx="9" stroke="currentColor" stroke-width="1.5" fill="none"/><line x1="10" y1="36" x2="38" y2="24" stroke="currentColor" stroke-width="1.5"/><line x1="10" y1="36" x2="38" y2="48" stroke="currentColor" stroke-width="1.5"/><line x1="82" y1="24" x2="110" y2="16" stroke="var(--hue-output)" stroke-width="1.5"/><line x1="82" y1="48" x2="110" y2="40" stroke="var(--hue-output)" stroke-width="1.5"/><line x1="82" y1="36" x2="110" y2="60" stroke="var(--hue-output)" stroke-width="1.5"/></svg><b>API and MCP</b>MCP ⊆ OpenAPI, by contract</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:48px;height:48px"><path d="M24 6l4 12 12 4-12 4-4 12-4-12-12-4 12-4z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>what it can be</b>agents of your own, dashboards of your own, workflows of your own</div>
</figure>

<details class="refs"><summary>References and recorded decisions</summary>
<div>
<p><b>What is written, and what was discarded</b></p><ul><li>Authentication and discovery by the RFCs; a custom convention was discarded.</li><li>A new channel does not invent a new surface: the parity rule keeps MCP from becoming a second API.</li></ul><p><b>References (ABNT NBR 6023:2018)</b></p><ul><li>IETF. <b>RFC 8414</b>: OAuth 2.0 Authorization Server Metadata. 2018.</li><li>IETF. <b>RFC 9728</b>: OAuth 2.0 Protected Resource Metadata. 2025.</li><li>IETF. <b>RFC 8707</b>: Resource Indicators for OAuth 2.0. 2020.</li><li>OPENAPI INITIATIVE. <b>OpenAPI Specification</b>. Available at: https://spec.openapis.org/.</li><li>ANTHROPIC. <b>Model Context Protocol</b> (MCP). Available at: https://modelcontextprotocol.io/.</li></ul>
</div>
</details>

</div>

<div class="chap">

<div class="ico-col"><span class="ico"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:36px;height:36px"><path d="M24 6l14 5v12c0 9-6 15-14 19-8-4-14-10-14-19V11z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M17 24l5 5 9-10" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg></span></div>

## How we validate

<h3 class="sub">Tests that refuse, audit with method, and defects published next to what passed</h3>

Validation has four layers, and the order matters. **Tests:** 505 test files in the repository,
with the design-system suite running on every build. **Guards:** checks that refuse at build time
in place of only reporting; a build that violates a rule does not ship. **Load:** the test of
2026-07-20, on a faithful production replica, with 50 concurrent reads answered in 0.77 s, a
heavy job peaking at 4.71 GiB against a ceiling of 5, and waves of five and ten jobs with zero failures,
zero memory overruns, zero corruption. Under overload the system enters a queue; it does not break.
**Internal audit:** dated stress, destruction, and security reports, with a verdict per
item.

<figure class="viz duo four" role="group" aria-label="Four validation layers: tests, guards that refuse, audit with method, published defects">
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:44px;height:44px"><rect x="8" y="8" width="32" height="32" rx="3" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M15 24l6 6 12-12" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>505 tests</b>the suite runs on every build</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:44px;height:44px"><path d="M8 12h32v10H8z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M8 26h32v10H8z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="30" y1="14" x2="36" y2="20" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="36" y1="14" x2="30" y2="20" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M28 31l3 3 5-6" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>guards that refuse</b>a violated build does not ship</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:44px;height:44px"><circle cx="21" cy="21" r="11" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="29" y1="29" x2="40" y2="40" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="16" y1="19" x2="26" y2="19" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="16" y1="24" x2="23" y2="24" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>audit with method</b>stress, destruction, security</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:44px;height:44px"><path d="M12 6h18l8 8v28H12z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M30 6v8h8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="24" cy="28" r="6" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="24" y1="25" x2="24" y2="29" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><circle cx="24" cy="31.5" r=".9" fill="currentColor"/></svg><b>published defects</b>next to what passed</div>
</figure>

<p class="claim">We are not SOC2 or ISO certified. What we have is <b>documented internal audit, with a declared method and with the defects it found published next to the ones it passed</b>. One of our reports carries, as its own sections, <i>defects found</i>, <i>a false positive I almost published</i>, and <i>what I could not establish</i>. A seal is a third party's word; a declared method, the technical reader judges alone. And the written decisions are designed to serve as control evidence when certification is sought.</p>

<div class="bound">
<p><b>What this page cites and what it does not cite.</b> Here is the existence of the reports and their method. The item-by-item verdicts live in the technical document that accompanies an evaluation, because publishing the probe list with results at the top of the funnel hands a map to whoever should not have one. The phrase the load test does <i>not</i> authorize: <i>fifty concurrent</i>. It is fifty seats and one heavy job at a time; confusing the two is the error this page exists not to make.</p>
</div>

<details class="refs"><summary>References and recorded decisions</summary>
<div><p><b>External methodology declared for the testing axis: none.</b> Strong practice, guards that refuse at build, dated reports; the source of method is internal, and saying so is part of the method.</p></div>
</details>

</div>

<div class="chap">

<div class="ico-col"><span class="ico"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:36px;height:36px"><path d="M12 6h18l8 8v28H12z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M30 6v8h8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="22" x2="32" y2="22" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="28" x2="32" y2="28" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="34" x2="26" y2="34" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="15" y1="25" x2="35" y2="25" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none" stroke-width="2"/></svg></span></div>

## How we decide

<h3 class="sub">Written, dated decisions, and a supersession that strikes two sentences and nothing else</h3>

Every SazAI architecture decision is a dated document, with the context, the
rejected alternative and the reason. There are 61 as of this page's date, and the number enters dated because it grows; the command that derives it is in this panel's references. What makes this a receipt and not a dead file is the
supersession: when a new decision contradicts an old one, it states exactly which sentence of the old one
stops holding, and the old one gets the mark in its own body, on the sentence, and not on the title.

The most recent example is from yesterday. Decision 023 fixed, among other things, the vocabulary
the user names the product's capabilities with. Decision 061 superseded **two sentences** of it, both
about vocabulary, and left everything about the engine intact, including the clause believed
violated that was not. Three competent readers had read that clause the same wrong way,
and the decision records all three names, because a decision that keeps only the conclusion loses the
reason three people got it wrong together.

<figure class="viz duo" role="group" aria-label="An old decision with two sentences struck and the rest intact, linked to the new decision">
<div class="side" style="color:var(--hue-reprocess)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:52px;height:52px"><path d="M12 6h18l8 8v28H12z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M30 6v8h8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="22" x2="32" y2="22" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="28" x2="32" y2="28" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="18" y1="34" x2="26" y2="34" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><line x1="15" y1="25" x2="35" y2="25" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none" stroke-width="2"/></svg><b>the old decision</b>two sentences struck, the rest intact</div>
<div class="mid" style="color:var(--hue-reprocess)"><svg viewBox="0 0 120 72" aria-hidden="true"><line x1="10" y1="36" x2="106" y2="36" stroke="currentColor" stroke-width="1.5"/><path d="M100 31l6 5-6 5" fill="none" stroke="currentColor" stroke-width="1.5"/><rect x="42" y="26" width="36" height="20" rx="10" fill="currentColor" opacity=".12" stroke="currentColor" stroke-width="1.5"/></svg><b>supersedes</b>names the sentence, and only it</div>
<div class="side" style="color:var(--hue-output)"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:52px;height:52px"><path d="M12 6h18l8 8v28H12z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M30 6v8h8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M18 28l4 4 8-8" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg><b>the new decision</b>with the three names that got it wrong together</div>
</figure>

<div class="bound">
<p><b>A number this page does not publish.</b> How many of these decisions are <i>accepted</i> depends on which words the counter admits into the state field, and five competent counters reached five different numbers this week. Nobody was wrong: the field never declared its own vocabulary. We publish the dated count, with the command next to it; the accepted count only goes public when it comes with the command that produces it next to it, the way the 158 tables already do.</p>
</div>

### And how we write: an internal contract, one step down for honesty

<h3 class="sub">Step 6 · recorded internal coherence, one step below external standard</h3>

Writing style, naming, and house conventions live in a versioned contract that agents
cite. Its anchor is internal coherence with a recorded decision, not a numbered
external standard; that is one step below the previous ones, and stepping down proves this page's hierarchy
applies even when it costs something.

**Data and facts:**

- A single writing standard, versioned by revision, cited by decisions and by agents as contract.
- Naming and name conventions uniform across the whole system; a cited standard is never paraphrased.
- Formatting, lint, and secret scanning automated, declared in the standard with the source next to them.

<figure class="viz" role="group" aria-label="Recorded internal coherence: one step below an external standard, drawn dashed on purpose">
<div class="ev open"><span class="n">internal coherence</span><span class="t"><b>One step down, and drawn that way</b>This panel's anchor is a recorded decision, not a numbered standard. The dashed frame is the same one the house uses for everything that is not a receipt, and a panel that steps down proves the hierarchy applies even when it costs something.</span></div>
</figure>


<details class="refs"><summary>References and recorded decisions</summary>
<div>
<p><b>What is written, and what was discarded</b></p><ul>
<li>The count: <code>ls docs/corpus/pptx/tech_specs/ADR | grep -c '^ADR-'</code> returns 61 on 2026-09-01. The number grows; the command does not.</li><li>The naming alternatives were rejected by convergence across three surfaces, and the rejection is recorded with the reason.</li></ul><p><b>References</b></p><p>the internal contract (`code_standards`, versioned) names its own sources; this
page does not paraphrase it.</p><p>The internal contract (<i>code_standards</i>, versioned) names its own sources; this page does not paraphrase it.</p>
</div>
</details>

</div>

<div class="chap">

<div class="ico-col"><sz-icon style="color:var(--hue-output)" name="check" size="36"></sz-icon></div>

## What is a receipt, and what is still practice

<h3 class="sub">Four capabilities with evidence; three declared, with no verb in the present tense</h3>

Every capability on this platform was put through three questions: is there a written decision that
governs it? is there a measurement? or does it just work, with nobody having written why? What passes
the first two we call <dfn data-hint="A capability with a written decision and a measurement that anyone can reproduce: not a promise, a record.">receipt</dfn>. The rest is practice, and it stays declared as
direction, the same way the [roadmap](#roadmap) below declares what does not exist yet. A
page that presents seven capabilities where three are receipts is weaker than one that presents
four.

<figure class="viz ledger" role="group" aria-label="Four receipts with their evidence and three practices declared as direction">
<div class="col receipts">
<h4>Receipt</h4>
<div class="item"><b>Plug and play</b><span>4 ADRs and the recipe · the four-point curve · the 158-table partition, re-derivable</span></div>
<div class="item"><b>Queue control</b><span>5 ADRs · load test with zero failures, zero OOM, zero corruption</span></div>
<div class="item"><b>Architecture · lineage · tenancy</b><span>with the provider boundary declared as a named hole</span></div>
<div class="item"><b>Decision versioning</b><span>dated decisions, surgical supersession</span></div>
</div>
<div class="col practices">
<h4>Declared practice</h4>
<div class="item"><b>Schema versioning</b><span>declared direction</span></div>
<div class="item"><b>Artifact versioning</b><span>declared direction</span></div>
<div class="item"><b>Agent-to-agent communication</b><span>declared direction, with failure modes measured</span></div>
</div>
</figure>
<p class="claim">The four on the left have somewhere to be checked, and the following chapters say where. The three on the right are where the platform is going, and none of their verbs is in the present tense.</p>

### And the market: studies with the caveats attached

<h3 class="sub">Step 7 · anchors where we play, not how we build</h3>

This step supports positioning, not engineering, and that is why it is last: it is the weakest
anchor on the page, and it is labeled as such.

**Data and facts:**

- Seven houses: Gartner, BCG, McKinsey, Deloitte, Menlo Ventures, MIT NANDA, Stanford HAI.
- Caveats built into the entries themselves: preliminary called preliminary (MIT NANDA, n=52); republished called republished (Stanford/McKinsey); a regional slice called regional (Deloitte, EMEA).
- BCG's 79% proves the obstacle, ungoverned unstructured data; it does not prove the bridge.
- Executive survey research is perception, not audited financials.


<details class="refs"><summary>References and recorded decisions</summary>
<div>
<p><b>What is written, and what was discarded</b></p><ul><li>Platform before product; buy before build.</li><li>On Shadow AI, only the citable form: reduction through a governed corporate path. "SazAI solves Shadow AI" was discarded for having no measurement to support it.</li></ul><p><b>References</b></p><p>the full entries in ABNT NBR 6023:2018 form are in this page's blocks; of the 25 in the
inventory, the ones consulted online carry <i>Accessed on</i>, as the standard requires, and the rest do not, as the
standard permits.</p>
</div>
</details>

</div>

<div class="chap">

<div class="ico-col"><span class="ico"><svg viewBox="0 0 48 48" aria-hidden="true" style="width:36px;height:36px"><circle cx="24" cy="24" r="16" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/><path d="M31 17l-4 10-10 4 4-10z" stroke="currentColor" stroke-width="1.25" stroke-linecap="round" stroke-linejoin="round" fill="none"/></svg></span></div>

<a id="roadmap"></a>

## Roadmap: what we are building

The roadmap holds the big directions, the ones the platform points toward and has not built yet. When a piece leaves here, it disappears from this list and appears on the page for the matching capability, with the date. A roadmap that moves is the only proof of pace that cannot be written with an adjective. Nothing below has shipped, and no item here should weigh on your decision today.
Nothing on this page has shipped. No item here should weigh on your decision today, and nobody on our team should present any of them in the present tense. What has shipped is in the [product walk](/), with what it guarantees, and the limits of what exists are in [trust](trust).

## Redline and negotiation intelligence

Comparing a draft against the parties' revisions, showing what each side changed, where the risk shifted, and what intent the text reveals. The comparison engine that underlies this already exists and runs today over document versions. What is missing is the legal layer: understanding that an altered clause is not just a different paragraph.

**Why it is on the roadmap and not on the road:** it is the direction with the greatest potential to create its own category, and that is exactly why it is the easiest to sell too early. It does not exist.

## Specialized agents over your corpus

Agents with their own scope, built on the knowledge already in your vault: a tutor that teaches from your company's real material, an adoption companion for a new process, an evaluator that checks competence while citing the source it used.

**What already stands underneath:** the corpus, lineage, the conversational agent, and source citation. **What is missing:** task-level specialization, with its own limits and rules per agent.

## Substrate for a fleet of governed agents

The next step from the previous one, and the widest-reaching. Each part of the company feeds the vault with its own documents, and the agents that part already uses consult that vault at runtime, by file or by protocol, for any question about the company. One governed source underneath an entire fleet, instead of loose AI tools that nobody audits.

**Why this is roadmap and not a vague promise:** the adoption mechanism is concrete and already exists in part, because the vault is portable and consumable from outside. What is missing is fleet governance, and it is not built.

## Things that exist and that we still cannot show you

These are evidence gaps, not missing features. The capability is there; the public proof is not, and until it is we would rather list the gap than talk around it.

- **Demonstrated vault export.** The vault exists and is plain text with links; what is missing is a published demonstration that anyone can reproduce without talking to us. Until then, it is a due-diligence conversation, not a page item.
- **Sufficiency of the record for formal audit.** The record exists and serves as control evidence. Whether it closes a specific audit requirement in your sector is a question we answer case by case, not a page claim.
- **Scale above what we measured.** Volumes in the hundreds of thousands or millions of documents have not been exercised. That is a sizing project before it is a purchase.

## Things that do not exist yet

These are missing features, and filing them anywhere softer would tell you they are there and we just cannot show them. They are not there.

- **Faithful visual verification.** The system measures structure and counts elements; it does not look at the final page. A visual checker inside the product does not exist.
- **Deletion that reaches backup copies.** Today deletion is complete in live systems and does not reach backups within the retention window. The technical path is defined and not yet built. The exact scope is in [privacy and sovereignty](privacy).
- **Remove the content and deactivate the account, in one action through the interface.** Today document deletion exists and takes derivatives with it; doing this all at once does not exist yet, and closure is handled on request. The name is deliberate: it erases the content and deactivates the account, because the trail of who accessed the system remains.

## How this page is maintained

An item leaves here when it exists and has been measured, not when it is almost ready. When it leaves, it enters the capability page with what it guarantees and where it stops. If you follow SazAI for a while, this page is where the pace shows.

## Where the boundary passes

<h3 class="sub">Three limits a technical reader tests first, stated before the test</h3>

**The provider boundary.** Lineage follows each piece of text until it leaves for the
language model and picks up again when it returns. None of our tables records what happened on the other
side; whoever asks *prove what they did with my text inside the model* receives the retention
terms of the provider they contracted, and in an installation of your own the provider is your choice. The page on
[sovereignty](privacy) says where that stops.

**The copyleft license exclusion.** No AGPL library enters the engine, and that is written
in the dependency file as a documented project decision. It is a comment, not a gate:
nothing breaks the build if someone ignores it. Saying so is stronger than pretending it is a gate, because
whoever opens the file sees it in ten seconds.

**The agents.** This system is built by a team of agents with declared scope and a
review chain, and the communication between them is practice, not receipt: there is no written decision that
governs the channel, and its failure modes were measured by us this week. It sits on the right side
of the ledger, and that is where it is going.

Everything this page states has a command or a document behind it, and what does not is stated
as direction. If something here cannot be reproduced in your own evaluation, that is a defect of ours and
we want to know before you do. The product that came out of this platform first is what [you see when
a document comes in](see).


### What this pyramid does not hold up

An honest pyramid says what stays outside it.

**Data and facts:**

- Five doctrine references in zero engineering artifacts: W3C **PROV** · ZAHARIA et al., **compound AI systems** (BAIR, 2024) · XU et al., **GraphRAG** (SIGIR, 2024) · **model routing** literature · **CommonMark/GFM**. They shaped the thinking; no recorded decision came out of them.
- Tests: strong practice, guards that refuse at build, dated reports; external methodology declared: none. Said in those words, with no plausible neighbor.
- And the finding that holds up the whole conclusion, measured across the decisions with an alternative in the header: in eleven of eleven, what decided was an engineering principle, not an external reference. The standard supports; the choice is ours, and it is written down.


</div>

*Figures measured on 2026-09-01 over sets that grow: whoever repeats the measurement tomorrow should expect larger numbers, not the same ones.*

<script type="module">
// IF THE #stars CANVAS EVER MORPHS INTO THIS GRAPH (Dev UX / Dev CO), REMOVE THIS FIGURE: two
// objects doing one job on one page is how a surface rots, quietly, because both look right.
// THE VAULT GRAPH, BORN AS STARS. Geometry in SVG, words in HTML. The layout is seeded, so the
// same picture renders every time; hubs are the real hubs of sazai.vault; satellites are counted
// per section, not drawn one to one. First reveal on intersection: points scatter like the
// starfield, then settle into the graph and the labels fade in. Hover lights a hub's edges;
// click (or Enter) opens the same scene full-screen; Escape closes. Reduced motion: no drift.
const fig=document.getElementById('vault-graph'); if(fig){
const svg=fig.querySelector('svg'),E=fig.querySelector('.edges'),N=fig.querySelector('.nodes'),L=fig.querySelector('.labels');
// no namespace literal: the house serves zero external references, and insertAdjacentHTML inside the <svg> inherits the SVG namespace on its own
const el=(t,a,parent)=>{parent.insertAdjacentHTML('beforeend','<'+t+' '+Object.entries(a).map(([k,v])=>k+'="'+v+'"').join(' ')+'/>');return parent.lastElementChild};
let seed=20260828; const rnd=()=>{seed=(seed*1664525+1013904223)%4294967296;return seed/4294967296};
const H=[ // real hubs of sazai.vault; n = satellites drawn, proportional, not exact
 {id:'index',l:'00-INDEX',x:400,y:250,c:'var(--dark)',r:9,n:6},
 {id:'adrs',l:'ADRs Hub',x:300,y:120,c:'var(--hue-reprocess)',r:8,n:59},
 {id:'agents',l:'Agents Hub',x:250,y:330,c:'var(--hue-analysis)',r:8,n:30},
 {id:'km',l:'Knowledge Map',x:560,y:130,c:'var(--hue-output)',r:7,n:18},
 {id:'product',l:'MOC-Product',x:600,y:300,c:'var(--hue-output)',r:7,n:26},
 {id:'strategy',l:'MOC-Strategy',x:520,y:410,c:'var(--hue-upload)',r:7,n:28},
 {id:'ops',l:'MOC-Operations',x:130,y:200,c:'var(--gray)',r:6,n:14},
 {id:'people',l:'MOC-People',x:150,y:440,c:'var(--hue-analysis)',r:6,n:10},
 {id:'pitch',l:'MOC-Pitch',x:690,y:440,c:'var(--hue-upload)',r:6,n:12},
 {id:'personas',l:'Personas',x:410,y:470,c:'var(--hue-reprocess)',r:6,n:7},
 {id:'sessions',l:'Sessions',x:700,y:200,c:'var(--gray)',r:5,n:9},
];
const X=[['index','adrs'],['index','agents'],['index','km'],['index','product'],['index','strategy'],['index','ops'],['index','people'],['index','pitch'],['index','personas'],['index','sessions'],['adrs','km'],['adrs','agents'],['agents','ops'],['agents','people'],['product','km'],['product','strategy'],['strategy','pitch'],['strategy','personas'],['pitch','personas'],['sessions','agents'],['sessions','adrs']];
const nodes=[],edges=[];
for(const h of H){const hub={...h,hub:true,sx:h.x,sy:h.y,ph:rnd()*6.28};nodes.push(hub);
  for(let i=0;i<h.n;i++){const a=rnd()*6.28,d=34+rnd()*(h.n>20?110:70);const s={id:h.id+i,x:h.x+Math.cos(a)*d,y:h.y+Math.sin(a)*d,c:h.c,r:1.6+rnd()*1.6,hub:false,of:hub,ph:rnd()*6.28};s.sx=s.x;s.sy=s.y;nodes.push(s);edges.push([hub,s]);
    if(rnd()<.12){const o=nodes[Math.floor(rnd()*nodes.length)];if(o&&o!==s)edges.push([s,o]);}}}
const byId=Object.fromEntries(nodes.filter(n=>n.hub).map(n=>[n.id,n]));
for(const [a,b] of X)edges.push([byId[a],byId[b]]);
for(const n of nodes){n.el=el('circle',{r:n.r,fill:n.c,opacity:n.hub?1:.75},N);n.el.style.color=n.c;
  n.rx=rnd()*800;n.ry=rnd()*520;n.t=0; // scatter origin, for the reveal
  if(n.hub){const sp=document.createElement('span');sp.textContent=n.l;sp.dataset.hub=n.id;L.appendChild(sp);n.lab=sp;
    n.el.classList.add('hub');n.el.dataset.hub=n.id;}}
for(const e of edges){e.el=el('line',{stroke:'var(--lightgray)','stroke-width':e[0].hub&&e[1].hub?1:.6,opacity:.55},E);}
const reduce=matchMedia('(prefers-reduced-motion: reduce)').matches;
let t0=null,revealed=false,lit=null;
function place(){const now=performance.now();for(const n of nodes){
  const k=reduce?1:Math.min(1,(now-(t0||now))/1600),ease=1-Math.pow(1-k,3);
  const dx=reduce?0:Math.sin(now/1900+n.ph)*(n.hub?2.2:3.6),dy=reduce?0:Math.cos(now/2300+n.ph)*(n.hub?2.2:3.6);
  n.x=n.rx+(n.sx-n.rx)*ease+dx;n.y=n.ry+(n.sy-n.ry)*ease+dy;
  n.el.setAttribute('cx',n.x);n.el.setAttribute('cy',n.y);
  if(n.hub){const pulse=reduce?1:1+Math.sin(now/1400+n.ph)*.08;n.el.setAttribute('r',n.r*pulse*ease+ .5);
    n.lab.style.left=(n.x/800*100)+'%';n.lab.style.top=(n.y/520*100)+'%';}else n.el.setAttribute('r',n.r*(.4+.6*ease));}
  for(const e of edges){e.el.setAttribute('x1',e[0].x);e.el.setAttribute('y1',e[0].y);e.el.setAttribute('x2',e[1].x);e.el.setAttribute('y2',e[1].y);}
  if(!revealed&&(reduce||now-t0>1500)){revealed=true;fig.classList.add('ready');}
  if(!reduce||!revealed)requestAnimationFrame(place);}
function light(id){lit=id;fig.classList.toggle('lit',!!id);
  for(const e of edges){const on=id&&(e[0].id===id||e[1].id===id||(e[0].of&&e[0].of.id===id&&e[1].hub===false&&e[1].of===e[0].of));
    e.el.setAttribute('opacity',id?(on?1:.12):.55);e.el.setAttribute('stroke',on?byId[id].c:'var(--lightgray)');}
  for(const n of nodes){const on=!id||n.id===id||(n.of&&n.of.id===id);n.el.setAttribute('opacity',on?(n.hub?1:.85):.18);}}
fig.addEventListener('mouseover',e=>{const h=e.target.closest('[data-hub]');if(h)light(h.dataset.hub)});
fig.addEventListener('mouseout',e=>{if(e.target.closest('[data-hub]'))light(null)});
// THE EXPANDED SCENE IS A MODAL (ADR-047 A10.4 #15): the figure moves into an sz-modal beside it, inside the same
// chapter so the .chap .graph.full rules still match, and comes back on close. The dialog brings the top layer, the
// blurred page behind (A10.2) and Esc; moved BEFORE open, the figure is inside the modal, so no hole is cut for it.
const ph=document.createElement('div');let modal=null;
const restore=()=>{if(!fig.classList.contains('full'))return;fig.classList.remove('full');ph.replaceWith(fig);document.body.style.overflow='';fig.focus({preventScroll:true})};
const expand=()=>{if(!modal){modal=document.createElement('sz-modal');modal.setAttribute('size','full');modal.setAttribute('bare','');modal.setAttribute('label',fig.getAttribute('aria-label')||'');modal.addEventListener('sz-close',restore)}
  ph.style.height=fig.offsetHeight+'px';fig.replaceWith(ph);ph.after(modal);modal.appendChild(fig);fig.classList.add('full');document.body.style.overflow='hidden';modal.open();fig.focus({preventScroll:true})};
const toggle=()=>{if(fig.classList.contains('full')){modal.close();return}customElements.whenDefined('sz-modal').then(expand)};
fig.addEventListener('click',e=>{if(!e.target.closest('[data-hub]')||fig.classList.contains('full'))toggle()});
fig.addEventListener('keydown',e=>{if(e.key==='Enter'||e.key===' '){e.preventDefault();toggle()}});
// START ON SIGHT. IntersectionObserver is the primary trigger; a geometry check on load and on the
// first scroll is the fallback, so a viewport that never reports intersection (measured: an
// automated background tab delivers neither IO nor rAF) still gets the reveal on the next paint.
let started=false;const start=()=>{if(started)return;started=true;t0=performance.now();requestAnimationFrame(place)};
const inView=()=>{const r=fig.getBoundingClientRect();return r.top<innerHeight*.8&&r.bottom>innerHeight*.2};
const io=new IntersectionObserver((en)=>{if(en.some(x=>x.isIntersecting)){start();io.disconnect()}},{threshold:.35});io.observe(fig);
if(inView())start();else addEventListener('scroll',()=>{if(inView())start()},{passive:true});
}
</script>


<style>

/* CHAPTER NUMERALS, EDITORIAL. The number is the chapter's mark, not a KPI: it enters large,
   in the domain hue, beside an uppercase kicker that says what it counts. The house h2 follows
   untouched. These rules move to marketing.css (and the connectome port) when the page lands;
   they live in the body for the refine loop. */
/* ICON COLUMN (Ramés, 2026-08-28): the chapter icon sits left of the title AND its subtitle; the
   subtitle takes the old kicker voice: small, uppercase, quiet. */
/* THE ICON IS A SIBLING OF THE H2, NEVER INSIDE IT, AND THAT IS AN ANCHOR DECISION RATHER THAN
   A STYLE ONE. Quartz slugs a heading from its TEXT CONTENT, and any inline element in the
   heading contributes an empty token. Measured on a probe page, all six forms: `<sz-icon>`
   before the words gives `id="-forma-a-inline-antes"`, a `<span>` behaves identically, the icon
   AFTER the words gives a TRAILING hyphen, and the `{#explicit-id}` syntax is NOT supported
   here: it is slugged as literal text. Only a heading with no markup at all comes out clean.
   AN ANCHOR IS A URL AND A WRONG URL IS PERMANENT, so the icon leaves the heading. The visual
   is unchanged: `.ch` is zero-height and the icon is absolutely placed into the padding column
   the h2 already reserves. */
/* ============================================================================
   THE CHAPTER IS A PANEL, AND THAT ALSO RETIRES THREE MAGIC NUMBERS.

   THE DIAGNOSIS WAS AN INVERTED HIERARCHY, not a missing divider. Rendered, the page read
   heading / floating prose / CONTAINED FIGURE / floating prose: the figure carried a border,
   a fill and a blur while the chapter that owns it carried nothing, so the strongest container
   on the page was a child of the section rather than the section. Prose did not read loose so
   much as OUT-RANKED.

   Now each chapter is a real element, which fixes the ranking AND the alignment at once:

   1. THE CHAPTER IS THE SURFACE. Soft ground, hairline border, radius, generous padding.
   2. THE FIGURE GIVES BACK ITS FILL and keeps only its outline, so it reads as an object
      INSIDE the panel instead of a competing surface. The blur goes with the fill: a backdrop
      filter over a transparent box is cost with no picture.
   3. THE ICON SITS IN ITS OWN GRID COLUMN, vertically centred on the title block by the
      layout rather than by an offset. Everything before this was a magic number chasing a
      MARGIN COLLAPSE: `.ch` was a zero-height div and the h2's top margin collapsed through
      it, so the icon's 18px raise was EMERGENT, and every spacing change moved it. Measured,
      three times: padding opened a 2.4rem gap; a margin dropped it 19px; a margin on the
      previous paragraph did the same. The wrapper removes the collapse from the problem.
   ============================================================================ */
article .chap{position:relative;display:grid;grid-template-columns:3.4rem 1fr;
  gap:0 0;align-items:start;
  border:1px solid color-mix(in srgb,var(--lightgray) 85%,transparent);border-radius:14px;
  background:transparent;
  padding:1.7rem 1.9rem 1.5rem;margin:1.6rem 0}
/* THE GLASS IS A VEIL, NOT A FILTER ON THE PANEL, AND THAT IS A MEASURED CORRECTION.
   `blur(4px)` is the house's own value, read off the served page from `div.search-container`
   and `div.global-graph-outer`, the only two elements that already carry a backdrop filter.
   PUT IT ON `.chap` DIRECTLY AND THE COMPARE MODAL BREAKS: `backdrop-filter` makes the element
   a containing block for `position:fixed` DESCENDANTS, and the modal lives inside this panel.
   Measured before and after: the scrim went from the viewport (1440x757) to the panel's own box
   (788x569). So the veil goes on a pseudo-element at `z-index:-1`, which blurs what is behind
   the panel while leaving `.chap` an ordinary containing block. IT IS THE HOUSE'S OWN ANSWER
   TOO: `sz-search-field` solves the identical problem with a `.veil` behind its pill. */
article .chap::before{content:"";position:absolute;inset:0;z-index:-1;border-radius:inherit;
  /* `--surface` AND NOT `--light`, MEASURED RATHER THAN CHOSEN BY NAME. In the dark theme
     `--light` resolves to #09090b, which is EXACTLY the body background: a 40% mix of the
     background over the background is the background, and the panel measured invisible on the
     rendered pixels (inside 9,9,10 against outside 9,9,11: a delta of zero). Blur cannot
     rescue it either, because a backdrop filter over a flat surface has nothing to blur: THE
     FILL IS WHAT MAKES A PANEL EXIST and the blur is only its texture. `--surface` is #18181b,
     the house's own raised colour, the one `sz-search-field` puts behind its pill. */
  background:color-mix(in srgb,var(--surface) 72%,transparent);
  backdrop-filter:blur(4px);-webkit-backdrop-filter:blur(4px);pointer-events:none}
article .chap .ico-col{grid-column:1;grid-row:1 / span 2;align-self:center;
  display:flex;align-items:center;justify-content:flex-start;padding-top:.15rem}
article .chap .ico-col sz-icon,article .chap .ico-col .ico{display:inline-flex}
article .chap .ico-col .ico svg{width:36px;height:36px}
article .chap > h2{grid-column:2;grid-row:1;padding-left:0;margin:0}
article .chap > h3.sub{grid-column:2;grid-row:2;padding-left:0;margin:2px 0 0;line-height:1.15}
/* THE ANCHOR ICON WAS INFLATING THE LINE BOX, AND MY OWN CHANGE PUT IT THERE. Promoting the
   subtitle from `<p>` to `<h3>` for the SEO reading also gave it the `a[role=anchor]` Quartz
   adds to every heading: 15px tall, inline, on the baseline. Measured, the h3 box went to 26px
   for a 16px line, and that surplus is what read as too much air between title and subtitle.
   Capping the anchor to the text's own em takes the inflation out without removing the anchor,
   so the heading keeps the link it earned by being a heading. */
article .chap h2 a[role=anchor],article .chap h3.sub a[role=anchor]{
  display:inline-flex;align-items:center;height:1em;line-height:1;vertical-align:middle}
article .chap > *:not(.ico-col):not(h2):not(h3.sub){grid-column:1 / -1}
/* THE SPACE BELONGS TO THE FIRST PROSE PARAGRAPH, AND `:first-of-type` GAVE IT TO THE SUBTITLE.
   The first `<p>` inside a panel is `p.sub`, so this rule matched the subtitle instead of the
   prose: same specificity as the `.sub` rule and later in the block, so it won, and the
   subtitle inherited a 16px top margin nobody wrote for it. @rames spotted it on the rendered
   page before any probe did. Targeting the paragraph that FOLLOWS the subtitle says what was
   meant and cannot drift onto a sibling again. */
article .chap > h3.sub + p{margin-top:1rem}
article .chap > *:last-child{margin-bottom:0}
/* the figure is an object inside the panel, never a second surface */
article .chap .viz{background:transparent;backdrop-filter:none;-webkit-backdrop-filter:none;
  border-color:color-mix(in srgb,var(--lightgray) 65%,transparent)}
/* ============================================================================
   HINT TEXT ON A TERM, AND THE RULE IT KEEPS: THE HOVER IS NEVER THE ONLY COPY.

   @copy-chief's rule applied literally: the explanation lives in the SENTENCE, where all three
   readers reach it (the person, the buyer's research agent, our agent reading the .md). The
   attribute is the SHORT FORM of that same sentence, so the hover adds convenience and never
   carries meaning the prose lacks. His measured reason is this page's own defect: the
   aria-label versus <text> divergence came from two copies of the same words in two encodings,
   and only one of them ever got translated.

   NO SCRIPT. Hover, keyboard focus and tap all resolve through :hover and :focus-visible, so
   there is nothing to upgrade, nothing that can trap focus, and it works before any module
   loads. `tabindex=0` makes the term reachable by keyboard and gives a tap somewhere to land.
   The term is marked as a TERM and not as a link: dotted underline, body colour, no pointer,
   because the page carries four real links and a fifth affordance that looked the same
   would lie.
   ============================================================================ */
article dfn[data-hint]{font-style:italic;position:relative;border-bottom:1px dotted var(--gray);
  cursor:help;outline:none}
article dfn[data-hint]::after{content:attr(data-hint);position:absolute;left:0;top:calc(100% + .5rem);
  z-index:30;width:min(30rem,72vw);padding:.7rem .85rem;border:1px solid var(--lightgray);
  border-radius:10px;background:var(--light);color:var(--darkgray);
  font-style:normal;font-size:var(--fs-xs,.76rem);line-height:1.45;letter-spacing:0;
  box-shadow:0 8px 24px rgb(0 0 0 / .28);opacity:0;visibility:hidden;transition:opacity .12s ease}
article dfn[data-hint]:hover::after,article dfn[data-hint]:focus-visible::after{opacity:1;visibility:visible}
article dfn[data-hint]:focus-visible{border-bottom-color:var(--secondary)}
/* THE SUBTITLE IS AN h3 AND ITS LOOK IS UNCHANGED. @sophia's SEO reading: the H2s lost their
   keywords when they became short labels, and the sentences that carry them became a styled
   paragraph with no heading weight. Promoting the element gives the weight back without moving
   a pixel: every typographic value below is the one the `<p>` already had. */
article h3.sub{font-size:var(--fs-xs,.74rem);font-weight:var(--fw-normal,400);letter-spacing:.08em;text-transform:uppercase;color:var(--gray);line-height:1.15}
/* COMPARE, in the vault's vocabulary: original, the declared relation, the edition; the button opens the component. */
article .duo .act{grid-column:1/-1;text-align:center;margin-top:.4rem}
article .duo sz-compare{display:block;height:0;overflow:hidden}
/* THE SAME BLUR THE SEARCH OVERLAY USES (Quartz .search-container: backdrop-filter blur(4px)),
   applied to the content boxes over a translucent ground so the starfield lifts them. Moves to
   marketing.css .viz when the page lands. */
article .duo.four{grid-template-columns:repeat(4,1fr)}
article .duo.strip{grid-template-columns:auto auto 1fr}
article .duo .out4{display:grid;grid-template-columns:repeat(4,1fr);gap:.5rem}
article .duo .out4 span{display:block}
article .duo .out4 svg{width:40px;height:40px;margin:0 auto .3rem}
article .duo.four .side svg{width:44px;color:var(--hue-analysis)}
article .duo.xray .side svg{color:var(--hue-upload)}
@media (max-width:640px){article .duo.four{grid-template-columns:1fr 1fr}}
/* THE MODAL MUST BE ABOVE THE PAGE CHROME, AND THE HOUSE HAS NO LAYER SCALE TO SAY SO. Measured
   on the served page: the compare scrim is z-index 50 (sz-compare), the consent notice 60
   (sz-consent), the search field host 10000 (chrome CSS). A dialog the reader opened that
   renders UNDER the search bar is a defect; this lifts it through the part the component
   exposes for exactly that. 10001 is a magic number chasing another one, declared as such:
   the durable fix is NOT a z-scale: sz-modal already solved this in-house by building on the
   native <dialog> and its top layer, which no z-index can sit above. sz-compare following it
   onto <dialog> retires this rule; that is a component change, not a page style. */
article sz-compare::part(modal){z-index:10001}
@media (max-width:640px){article .duo.strip{grid-template-columns:1fr}article .duo .out4{grid-template-columns:1fr 1fr}}
/* THE CLOSE MIRRORS THE OPEN: one vault in the middle, two readers on the sides. Geometry only;
   every word is HTML. */
article .duo{display:grid;grid-template-columns:1fr auto 1fr;gap:1rem;align-items:center;text-align:center;font-size:var(--fs-xs,.74rem);color:var(--gray)}
article .duo svg{display:block;height:auto;margin:0 auto .3rem}
article .duo .side svg{width:56px}
article .duo .mid svg{width:96px}
article .duo b{display:block;color:var(--dark);font-size:var(--fs-sm,.86rem)}
@media (max-width:640px){article .duo{grid-template-columns:1fr}}

/* ============================================================================
   TWO OBJECTS THIS PAGE NEEDED AND `see` DID NOT.

   1. THE CURVE, ON A LOG SCALE, BECAUSE A LINEAR ONE HIDES THE ARGUMENT. The claim is one
      order of magnitude per format: 3600h, 48h, 4h, one session. Drawn linearly the last
      three bars are invisible and the fourth point, THE ONE CARRYING THE STRONGEST PROOF,
      reads as merely small. Log widths make the collapse legible, and the caption says the
      scale out loud so nobody reads it as linear.

      AND THE FOURTH ROW BREAKS THE VISUAL FAMILY ON PURPOSE. The three OOXML formats share a
      hue and a solid bar; PDF gets a different hue and an outlined bar. **THE BREAK IS THE
      ARGUMENT**: the engine did not get faster at PowerPoint, it became format-agnostic, and
      a fourth bar in the same family would have said the opposite.

   2. RECEIPT AND PRACTICE MUST NOT LOOK ALIKE, and that is a composition rule rather than a
      label. A receipt is a thing already true and carries its evidence on the same line, so
      it is solid, filled, and reads as closed. A practice is declared direction with no
      present-tense verb, so it is outlined, muted, and reads as open. A reader who never
      gets to the words should still be able to see which column is which.

   3. THE BOUNDS ARE IN THE FLOW, NOT IN SMALL PRINT. `see` had none of these. A bound that
      has to be read as a footnote is a bound that gets skipped, and both of this page's
      bounds are the kind a competent reader tests FIRST. So they sit inside the chapter, at
      the same measure as the prose, in a treatment that is quieter than the claim but not
      smaller than it.
   ============================================================================ */
article .curve{display:flex;flex-direction:column;gap:.55rem}
article .curve .row{display:grid;grid-template-columns:4.2rem 1fr 7.5rem;align-items:center;gap:.8rem}
article .curve .row b{font-size:var(--fs-sm,.86rem);color:var(--text)}
article .curve .track{display:block;height:10px;border-radius:5px;background:color-mix(in srgb,var(--lightgray) 45%,transparent)}
article .curve .bar{display:block;height:100%;border-radius:5px}
article .curve .ooxml .bar{background:var(--hue-analysis)}
article .curve .other .bar{background:transparent;border:1.5px solid var(--hue-output)}
article .curve .other b{color:var(--hue-output)}
article .curve em{font-style:normal;font-size:var(--fs-xs,.76rem);color:var(--gray);text-align:right}
article .curve .other em{color:var(--hue-output)}
article .ledger{display:grid;grid-template-columns:1fr 1fr;gap:1.4rem}
article .ledger h4{margin:0 0 .6rem;font-size:var(--fs-xs,.74rem);letter-spacing:.08em;text-transform:uppercase;font-weight:var(--fw-normal,400);color:var(--gray)}
article .ledger .item{margin-bottom:.7rem}
article .ledger .item b{display:block;font-size:var(--fs-sm,.88rem)}
article .ledger .item span{display:block;font-size:var(--fs-xs,.76rem);color:var(--gray);line-height:1.4;margin-top:.1rem}
article .ledger .receipts .item{border-left:2px solid var(--hue-output);padding-left:.7rem}
article .ledger .practices .item{border-left:2px dashed color-mix(in srgb,var(--gray) 55%,transparent);padding-left:.7rem}
article .ledger .practices .item b{color:var(--gray);font-weight:var(--fw-normal,400)}
article p.claim{margin:1rem 0 0;color:var(--text);font-size:var(--fs-sm,.95rem);line-height:1.55}
article .bound{margin:1.1rem 0 0;padding:.85rem 1rem;border-left:2px solid color-mix(in srgb,var(--gray) 40%,transparent);
  background:color-mix(in srgb,var(--surface) 45%,transparent);border-radius:0 8px 8px 0}
article .bound p{margin:0 0 .5rem;font-size:var(--fs-xs,.82rem);line-height:1.5;color:var(--gray)}
article .bound p:last-child{margin-bottom:0}
@media (max-width:640px){article .ledger{grid-template-columns:1fr}article .curve .row{grid-template-columns:3.4rem 1fr}article .curve em{grid-column:1/-1;text-align:left}}

/* THE VAULT GRAPH: born as stars, settles into the map. Geometry in SVG, words in HTML spans over
   it; `.stage` binds the two so labels track the drawing in both modes. Placed LAST so it wins
   over the panel's `.chap .viz` reset, and scoped to `.chap` so its specificity matches hers. */
article .chap .graph{position:relative;padding:.6rem;cursor:zoom-in;outline:none}
article .chap .graph .stage{position:relative;width:100%;aspect-ratio:800/520}
article .chap .graph .stage svg{display:block;width:100%;height:100%}
article .chap .graph .labels{position:absolute;inset:0;pointer-events:none}
article .chap .graph .labels span{position:absolute;transform:translate(-50%,10px);font-size:var(--fs-xs,.72rem);color:var(--dark);white-space:nowrap;opacity:0;transition:opacity .7s ease;text-shadow:0 0 6px var(--light),0 0 2px var(--light);pointer-events:auto}
article .chap .graph.ready .labels span{opacity:1}
article .chap .graph .nodes .hub{cursor:pointer;transition:opacity .25s}
article .chap .graph .edges line{transition:opacity .25s,stroke .25s}
article .chap .graph figcaption{margin-top:.4rem}
article .chap .graph:focus-visible{box-shadow:0 0 0 2px var(--secondary)}
article .chap .graph.full{flex:1;min-width:0;margin:0;border:0;border-radius:0;padding:3vh 4vw;background:transparent;cursor:zoom-out;display:flex;flex-direction:column;align-items:center;justify-content:center}
article .chap .graph.full .stage{width:min(92vw,calc(84vh * 800 / 520))}
article .chap .graph.full .labels span{font-size:1rem}
article .chap .graph.full figcaption{text-align:center;margin-top:1rem;max-width:70ch}
</style>