Accelerated Understanding v1.0 landed today as a 3,000-line enterprise package: 188 requirements, twelve services, a 15-month programme. I put it through a full adversarial review against the live SEOS code, the packages that came before it, and the outside world. This is what holds, what breaks, and what we build first.
Package M proposes Accelerated Understanding as a comprehension and decision-assurance layer above J, K and L. It compiles a versioned Understanding State for a named decision: claims bound to evidence, typed reasoning, a decomposed uncertainty vector, counterfactuals, four projection depths that must preserve the same material meaning, and a human attestation record. It is the right idea and it is the natural next layer for SEOS.
The review ran six independent lenses over the whole document (internal consistency, architecture feasibility, external fact-check, product and category, fit against the live repo and our real capacity, document quality), then sent every critical and high finding to two refuters with orders to kill it. 24 findings survived. The verdict in one line: the doctrine is right and the document around it is written for a company we are not yet. It assumes a 30 to 46 person organisation, six governance boards, a hosted K, a merged L, Neo4j, a PKI, an ABAC policy engine and a model gateway. None of those exist today.
These are the parts where the differentiator is a data structure or a rule, not a slogan. They match what PRISM and L.1 already enforce in code, and they should become SEOS law across every package.
Truth remains external to AU. AI proposes, humans authorize. Insufficient evidence produces no-decision, not confident prose. Meaning is invariant across role and depth. lines 294 to 333
Keep verbatimEvery pass sees the immutable source spine, and every pass emits a signed delta listing added, revised and removed claim IDs against a policy snapshot. The one place the differentiator is concrete. Fig 2, line 556
Keep verbatim"Assurance class is selected by decision consequence and policy, never by the desired speed or tone of the answer." The best sentence in the document. It restates Package D's four-rung action ladder, which is a point in its favour. lines 399 to 430
Keep, bind to DGrounding, traceability, consistency, calibration, assumptions, freshness, equivalence, comprehension. Aggregates may prioritise but never authorize. Understanding Debt as a decision-scoped backlog is a Postgres view waiting to be written. lines 659 to 717
Keep verbatimClean baseline, sparse evidence, conflicting authority, stale evidence, causal trap, projection trap, adversarial source, model disagreement, historical decision, restricted evidence. The most build-ready content in the package. lines 1236 to 1269
Build first"Safe now" through "Never without proof", and "Do not make legal exclusivity claims until a professional patentability and freedom-to-operate review is complete." Correct, and it applies to our own title page. lines 2882 to 2900
Keep verbatimEvery row below survived two refuters: one checking that the document really says or omits what the finding claims, one checking that the criticism itself is correct and matters to us. Line numbers refer to the v1.0 text. Three findings were killed in that process and six were narrowed; they are listed at the end of the section so nothing is hidden.
The investment case is written for a 30 to 46 FTE vendor
A gated 15-month programme with no currency, headcount cost, design partner, ACV or run cost anywhere in 3,013 lines. The capacity table sums to 30 to 46 people; six boards and named executive roles are to be appointed in the first 30 days. Release gates require IV&V reports and Architecture Board minutes nobody can produce. lines 83 to 85, 1486 to 1562, 1646 to 1696
The semantic checksum does not cover meaning
Line 764 digests claim IDs, polarity, scope, status and bands. That proves invariant-set integrity, not prose fidelity. "canonicalize" is specified nowhere, materiality has no rule or owner, and Glance carries only "top risk" yet must match the full canonical digest. The only meaning-level check is an NLI model that ADR-M-006 defers to Wave 1 with admitted false-pass risk, while the release gate presents "zero critical semantic drift" as checksum-enforced. lines 745 to 764, 2203 to 2208, 2777 to 2781
L is load-bearing and not on main
Every action and release routes through Package L, presented as existing. L.1 is accepted and L.2 to L.8 have landed on feature/package-l, but the branch is unmerged and the backend is unhosted. The document never states L's status or an L-absent behaviour. lines 137 to 149, 867 to 955, 2350
Neo4j is mandated against our own June decision
Section 9, M-USG-007 and ADR-M-002 hard-wire Neo4j. The 16 June infrastructure memo chose Postgres plus Apache AGE and named Neo4j as the trap for air-gapped customers (GPLv3 Community edition or a per-deployment Enterprise fee). The same document mandates disconnected deployment. Both cannot be true. lines 557 to 597, 1949, 2755 to 2761
Six stores, twelve services, and a second audit ledger
Postgres, Neo4j, vector index, object storage, audit ledger and cache, run on customer-operated Kubernetes, against a product that today is a static export, Supabase edge functions and one FastAPI container. The au-audit-ledger is a second audit trail next to the one Packages B, C, G and H mandate, which M's own non-negotiable 1 forbids. lines 791 to 866, 1141 to 1143
The status model contradicts itself
The UAC table reserves "Released" for UAC-4 and caps UAC-0 at "Draft only", yet "released" is used 18 times as the normal terminal status for every class. Figure 6 is one linear path that omits invalidated and superseded from the enum at line 640. The UAC ladder is never mapped to Package D's four existing action classes. lines 404 to 429, 640, 1102 to 1130
Packages A to I are never cited, and four of them are re-specified
Package I owns the classification levels M's trust zones invoke without naming. Package D owns the AI approval ladder that UAC-0 to 4 restates with a fifth rung. B, C, G and H own the audit trail. C and I already cover the five-row deployment table and M-SEC-015. Of the eight workbench surfaces, only Counterfactual Lab and Comprehension Check are net-new against the 144-view catalogue. UAC-4's regulated-release language also aims at the certification regime we replaced in June with ISO 27001 plus SOC 2, which M's compliance list omits entirely. lines 425 to 430, 1041 to 1062, 1083, 1134 to 1148
Per-person comprehension tracking is a high-risk AI system under the EU AI Act
Annex III point 4(b) covers AI intended to monitor and evaluate the performance and behaviour of persons in work-related relationships. M-CMP-001 mandates a per-person Comprehension State, M-CMP-004 and 005 score people on recall, interpretation and causal understanding, and M-CMP-009 escalates repeated misunderstanding to a human reviewer. The carve-outs ("without making an employment judgment", "no covert profiling") do not change classification, because Annex III turns on intended use. The plan's enterprise release lands on the Annex III application date. GDPR Article 88 and works-council consent rights in Germany and the Netherlands sit on top. Section 19 names only voluntary standards. The role-level default in M-CMP-003 is the one mode that stays clear, and the document does not know why. lines 1063 to 1101, 2258 to 2307
PRISM is never mentioned, and M re-specifies it
M-DEC-001, 002, 009 and 010 and the Decision Room describe decision records, rejected alternatives, bias findings, a quality vector and an audit ledger. PRISM v3 has shipped exactly those on /proto since 28 August: PrismDecisionRecord, PrismAlternativeRecord, PrismBiasFinding, DecisionQuality, prism_audit. M.11 and the Decision Room are Extend, not Build. lines 489 to 507, 2308 to 2363
The IP sequence is backwards, and there is no assignee
Freedom-to-operate counsel is scheduled in Wave 0 and pilots sign agreements before any priority filing, but the pilot deck is itself the disclosure. The EPC has absolute novelty, so any non-confidential circulation of sections 3.1 and 3.2 kills European rights outright; the US grace period does not travel. Novelty is intact today: the send was co-founder to co-founder on a controlled document, and neither /proto nor the repo contains "residual evidence", "semantic checksum" or "Understanding State". No entity exists yet to be the applicant. lines 244 to 291, 1481, 1694, 2877
The whitespace matrix scores vocabulary, not capability
Rows are named in the author's coined terms, AU gets "Proposed" for nothing built, and the desk review is a same-day read of thirteen vendor landing pages. It ignores the two fields closest to the idea: assurance-case tooling (OMG SACM, GSN, Adelard ASCE, Assurance 2.0 defeaters) and Palantir's decision lineage. "Category-defining hypothesis" sits on the title page of a document routed to investment review, while D.2 only permits "not located as a directly equivalent public product claim". lines 20, 152 to 243, 2887
Three encoder pass lists, figures that contradict their tables, two pilots that become three
Table 8.1 has seven passes, Figure 2 has six (no Verify), the WBS and M-ENC-001 have six without Compile, and gate G4 has no producing pass. Figure 1 sends enterprise sources into K and decisions out of K where the text says J ingests and L executes. Figure 3 uses seven relationship labels not in table 9.1. Lines 76, 1433 and 1689 say two pilots; section 27 defines A, B and C, with a 25 percent time-reduction criterion against a baseline study the plan admits is unrun. lines 526 to 553, 1102 to 1130, 1563 to 1579
Identity, ABAC, PKI and separation of duties are assumed everywhere and absent
M-SEC-001 wants object-level authorization at five boundaries, ADR-M-004 wants OPA or Cedar in Wave 0, ADR-M-011 wants PKI in Wave 2, M-DEC-006 wants four-role separation. The repo has five gate accounts, HS256 verify-only, four project-membership roles, a permissions module that is a placeholder returning its input unchanged, and no tenant column in any migration. lines 2340, 2427, 2768, 2804
Passes self-report their invariant results; the loophole is downgrade, not delete
The delta envelope carries protectedInvariantResults under the producing pass's own signature and nothing says the verifier recomputes them. Materiality is pass-assigned and non-monotone, and line 698 permits "downgrade claim" as a disposition with no named authority, so shrinking the material set is the cheapest route to 100 percent provenance coverage. lines 556, 666, 694 to 699, 1873
Bitemporal reconstruction needs a bitemporal J that does not exist
M-USG-003 and M-USG-010 require validity time and transaction time on every material relationship. seos_nodes and seos_edges have no temporal columns, the J critical-path entry covers only ontology and permissions, and nobody has costed version history against the one-billion-relationship envelope. lines 1187 to 1189, 1464 to 1467, 1929, 1964
Service levels asserted as Must with no derivation
p95 60 seconds for a fresh compile of seven chained passes including flip-boundary search and an NLI check; 300 concurrent compiles; 100 million objects, one billion relationships, 5,000 users; all "subject to measured architecture validation" in one place and SHALL in another. No tokens-per-compile figure anywhere, and no pilot-sized profile /proto can be measured against. lines 1150 to 1193, 2599 to 2616
AU copies controlled content into five stores with no residency rules
C1 forbids a shadow repository; section 14.1 then stores evidence fragments, payloads, projections and embeddings. Revocation propagation is specified only for the cache, nothing says what text the vector index is built from, and the trust zones use "classify" as a verb with no reference to Package I's enumerated levels. lines 300, 849 to 866, 1041 to 1062
All 188 requirements are Must, and verify method is constant per family
Zero Should or May despite both being defined. Every CON requirement is Inspection including the fail-closed one, every RSN is Analysis including the one M-VER-005 tests by mutation, every CMP is Demonstration including a negative requirement. "Smallest practical fragment", "minimal set", "estimate cognitive budgets" carry no threshold, so the trace-matrix gate cannot close. lines 1700 to 2743
No wedge, and no evidence the core bet works
Eight personas, eight use cases and all four projection depths are mandatory by Wave 2, including a Glance view for executives who receive briefs from chief engineers, not from tools. Seven passes with typed causal reasoning and flip-boundary search have no stated method, no reference to the J.4 context code that already exists, and no worked example of a single compiled decision. Wave 0 measures "value" on a schema prototype with no interface. lines 334 to 398, 519, 1430 to 1434, 1692
Section 30 is a policy poster, and B.2 asks for a second repository
The implementation directive is one paragraph of prohibitions with no repo placement, no interface stubs for J, K or L, no acceptance tests, and a delivery order that omits M.7. B.2 prescribes an eleven-service monorepo against the one-codebase rule and a team that ships from one Next.js plus Python repo. Supabase migrations also need exactly one home before any au_* table lands. lines 1697 to 1699, 2812 to 2814
The review universe in section 3 is seven ALM and PLM vendors. The nearest prior art sits outside it, and some of it sits inside our own repository. What is genuinely novel survives this list, and it is stronger for being stated against real neighbours instead of "Not located".
What is actually novel after this: machine-verifiable binding of claims to graph evidence, supersession on dependency change, the computed flip boundary as a minimal intervention set, and comprehension closure. Say that. All four patents, the standards map and the vendor references were verified as real and accurately described; the bibliography is sound, the matrix built on it is not.
Read against the live code, Package M is not a greenfield build. Most of the compiler's inputs exist as exported functions today, and the decision record it wants to invent is already in production.
One use case, one persona, two depths, no L dependency. UC-01 change impact for a systems or chief engineer, Brief and Deep projections, UAC-0 and UAC-1, on the live /proto graph. The output is one real decision compiled on real project data, demoable to a chief engineer under NDA, which is the evidence Wave 0 says it wants and does not schedule.
Question Frame
Question, decision type, role bound to the existing Role type, baseline as the current graph revision, depth, assurance class, protected facts picked from graph nodes. M.1; M-REQ-001 to 003, M-CON-002.
Evidence compile over the project graph
lib/au/compile.ts on top of the J.4 context engine, the EQL planner, the grounding validator and the impact services. Output: evidence manifest, authoritative or inferred or unverified class, provenance coverage, stale detection. M.2 and M.3; M-EVD-001, 002, 004, 005, 007, 013.
Understanding State persisted
Types from schema 9.2, an au-compile edge function, migration 005 with immutable versions, status, material claim IDs, quality vector and semantic checksum. Persistence is net-new; nothing in either checkout defines it yet. M.2; M-USG-001, 002, 004, 006; M-CON-003, 004; M-PRJ-003.
Three explicit passes with delta records
P0 Frame, P1 Bind, P5 Compile, one signed delta each. P3 Challenge imports the prism-engine output as Conflict and Assumption objects instead of building a new challenge model. M.4 partial; M-ENC-001, 003.
Brief and Deep projections with a real checksum gate
Per-claim source reveal, declared omissions, a specified canonicalize, subset equality for the shallower view, JSON export stamped with state ID, version, baseline and status. M.8 partial; M-PRJ-004, 005, 007, 011.
Attestation in L-absent mode
An au_attestations row with actor, role, scope, policy version and disposition including no-decision, attester never equal to requester enforced in SQL, shown in the PRISM decision log. The ledger is prism_audit extended, not a sibling. M.11 partial; M-DEC-003, 004, 006, 009, 010.
Ten golden cases and one acceptance test per exit criterion
Hand-authored from the corpus classes: sparse evidence, projection trap and restricted evidence at minimum. The three registered demo bundles carry enough requirements, verification cases, risks and change requests for a real compiled decision. M-VER-001 seed.
Deferred on purpose: the graph projection store, vector index, object store, Glance and Audit depths, counterfactual execution and FMI, the time machine, external adapters, SHACL, the ABAC engine, PKI, release through L, and every per-person comprehension feature (that last one on legal grounds, not scope discipline). Your neural-operator work is the natural surrogate engine for the Counterfactual Lab when M.9 comes round, far cheaper than full FMI co-simulation.
Effort: about 25 working days serial, 3 to 5 calendar weeks with the agent fleet in parallel and your PRs on the schema path. Two decisions first, hours if made and weeks if not: one migration home, and one checkout of origin/main to build on.
Thirteen changes that turn the draft into the SEOS baseline. None of them touch the doctrine.
Package M is the right next layer and its constitution is the best statement of what SEOS is for that either of us has written. What it needs is to be brought down to the company we are and the code we have: Postgres plus AGE, PRISM extended, L-absent until L is merged, role-level comprehension only, and one provisional filed first.
I start the seven-step slice on a clean checkout of origin/main this week. When the first Understanding State compiles on the eferry graph, that is the Wave 0 evidence, and v1.1 gets written against a thing that runs instead of a thing that is described.