SyntheraOS
PACKAGE M REVIEW Open the live build →Live build →
Technical review · 2 Sep 2026 · for Naxief

Package M: the doctrine stays, the document gets rebuilt.

Accelerated Understanding v1.0 landed today as a 3,000-line enterprise package: 188 requirements, twelve services, a 15-month programme. I put it through a full adversarial review against the live SEOS code, the packages that came before it, and the outside world. This is what holds, what breaks, and what we build first.

0
requirements in v1.0, every one marked Must
0
confirmed findings, each survived two independent refuters
0
earlier packages M re-specifies without citing them
0
mentions of PRISM, which already ships half the Decision Room
0
provisional to file before anyone outside sees it
0
weeks to the first real Understanding State on /proto
01

Executive summary

Package M proposes Accelerated Understanding as a comprehension and decision-assurance layer above J, K and L. It compiles a versioned Understanding State for a named decision: claims bound to evidence, typed reasoning, a decomposed uncertainty vector, counterfactuals, four projection depths that must preserve the same material meaning, and a human attestation record. It is the right idea and it is the natural next layer for SEOS.

The review ran six independent lenses over the whole document (internal consistency, architecture feasibility, external fact-check, product and category, fit against the live repo and our real capacity, document quality), then sent every critical and high finding to two refuters with orders to kill it. 24 findings survived. The verdict in one line: the doctrine is right and the document around it is written for a company we are not yet. It assumes a 30 to 46 person organisation, six governance boards, a hosted K, a merged L, Neo4j, a PKI, an ABAC policy engine and a model gateway. None of those exist today.

02

What stays exactly as written

These are the parts where the differentiator is a data structure or a rule, not a slogan. They match what PRISM and L.1 already enforce in code, and they should become SEOS law across every package.

Constitution

C1 to C12

Truth remains external to AU. AI proposes, humans authorize. Insufficient evidence produces no-decision, not confident prose. Meaning is invariant across role and depth. lines 294 to 333

Keep verbatim
Evidence

Residual evidence spine and signed deltas

Every pass sees the immutable source spine, and every pass emits a signed delta listing added, revised and removed claim IDs against a policy snapshot. The one place the differentiator is concrete. Fig 2, line 556

Keep verbatim
Assurance

The UAC ladder

"Assurance class is selected by decision consequence and policy, never by the desired speed or tone of the answer." The best sentence in the document. It restates Package D's four-rung action ladder, which is a point in its favour. lines 399 to 430

Keep, bind to D
Quality

A vector, never a score

Grounding, traceability, consistency, calibration, assumptions, freshness, equivalence, comprehension. Aggregates may prioritise but never authorize. Understanding Debt as a decision-scoped backlog is a Postgres view waiting to be written. lines 659 to 717

Keep verbatim
Evaluation

The governed corpus classes

Clean baseline, sparse evidence, conflicting authority, stale evidence, causal trap, projection trap, adversarial source, model disagreement, historical decision, restricted evidence. The most build-ready content in the package. lines 1236 to 1269

Build first
Claims

The claims ladder and line 86

"Safe now" through "Never without proof", and "Do not make legal exclusivity claims until a professional patentability and freedom-to-operate review is complete." Correct, and it applies to our own title page. lines 2882 to 2900

Keep verbatim
03

What breaks, ranked

Every row below survived two refuters: one checking that the document really says or omits what the finding claims, one checking that the criticism itself is correct and matters to us. Line numbers refer to the v1.0 text. Three findings were killed in that process and six were narrowed; they are listed at the end of the section so nothing is hidden.

Critical

01

The investment case is written for a 30 to 46 FTE vendor

A gated 15-month programme with no currency, headcount cost, design partner, ACV or run cost anywhere in 3,013 lines. The capacity table sums to 30 to 46 people; six boards and named executive roles are to be appointed in the first 30 days. Release gates require IV&V reports and Architecture Board minutes nobody can produce. lines 83 to 85, 1486 to 1562, 1646 to 1696

CRITICAL
02

The semantic checksum does not cover meaning

Line 764 digests claim IDs, polarity, scope, status and bands. That proves invariant-set integrity, not prose fidelity. "canonicalize" is specified nowhere, materiality has no rule or owner, and Glance carries only "top risk" yet must match the full canonical digest. The only meaning-level check is an NLI model that ADR-M-006 defers to Wave 1 with admitted false-pass risk, while the release gate presents "zero critical semantic drift" as checksum-enforced. lines 745 to 764, 2203 to 2208, 2777 to 2781

CRITICAL
03

L is load-bearing and not on main

Every action and release routes through Package L, presented as existing. L.1 is accepted and L.2 to L.8 have landed on feature/package-l, but the branch is unmerged and the backend is unhosted. The document never states L's status or an L-absent behaviour. lines 137 to 149, 867 to 955, 2350

CRITICAL
04

Neo4j is mandated against our own June decision

Section 9, M-USG-007 and ADR-M-002 hard-wire Neo4j. The 16 June infrastructure memo chose Postgres plus Apache AGE and named Neo4j as the trap for air-gapped customers (GPLv3 Community edition or a per-deployment Enterprise fee). The same document mandates disconnected deployment. Both cannot be true. lines 557 to 597, 1949, 2755 to 2761

CRITICAL
05

Six stores, twelve services, and a second audit ledger

Postgres, Neo4j, vector index, object storage, audit ledger and cache, run on customer-operated Kubernetes, against a product that today is a static export, Supabase edge functions and one FastAPI container. The au-audit-ledger is a second audit trail next to the one Packages B, C, G and H mandate, which M's own non-negotiable 1 forbids. lines 791 to 866, 1141 to 1143

CRITICAL
06

The status model contradicts itself

The UAC table reserves "Released" for UAC-4 and caps UAC-0 at "Draft only", yet "released" is used 18 times as the normal terminal status for every class. Figure 6 is one linear path that omits invalidated and superseded from the enum at line 640. The UAC ladder is never mapped to Package D's four existing action classes. lines 404 to 429, 640, 1102 to 1130

CRITICAL
07

Packages A to I are never cited, and four of them are re-specified

Package I owns the classification levels M's trust zones invoke without naming. Package D owns the AI approval ladder that UAC-0 to 4 restates with a fifth rung. B, C, G and H own the audit trail. C and I already cover the five-row deployment table and M-SEC-015. Of the eight workbench surfaces, only Counterfactual Lab and Comprehension Check are net-new against the 144-view catalogue. UAC-4's regulated-release language also aims at the certification regime we replaced in June with ISO 27001 plus SOC 2, which M's compliance list omits entirely. lines 425 to 430, 1041 to 1062, 1083, 1134 to 1148

CRITICAL
08

Per-person comprehension tracking is a high-risk AI system under the EU AI Act

Annex III point 4(b) covers AI intended to monitor and evaluate the performance and behaviour of persons in work-related relationships. M-CMP-001 mandates a per-person Comprehension State, M-CMP-004 and 005 score people on recall, interpretation and causal understanding, and M-CMP-009 escalates repeated misunderstanding to a human reviewer. The carve-outs ("without making an employment judgment", "no covert profiling") do not change classification, because Annex III turns on intended use. The plan's enterprise release lands on the Annex III application date. GDPR Article 88 and works-council consent rights in Germany and the Netherlands sit on top. Section 19 names only voluntary standards. The role-level default in M-CMP-003 is the one mode that stays clear, and the document does not know why. lines 1063 to 1101, 2258 to 2307

CRITICAL

High

09

PRISM is never mentioned, and M re-specifies it

M-DEC-001, 002, 009 and 010 and the Decision Room describe decision records, rejected alternatives, bias findings, a quality vector and an audit ledger. PRISM v3 has shipped exactly those on /proto since 28 August: PrismDecisionRecord, PrismAlternativeRecord, PrismBiasFinding, DecisionQuality, prism_audit. M.11 and the Decision Room are Extend, not Build. lines 489 to 507, 2308 to 2363

HIGH
10

The IP sequence is backwards, and there is no assignee

Freedom-to-operate counsel is scheduled in Wave 0 and pilots sign agreements before any priority filing, but the pilot deck is itself the disclosure. The EPC has absolute novelty, so any non-confidential circulation of sections 3.1 and 3.2 kills European rights outright; the US grace period does not travel. Novelty is intact today: the send was co-founder to co-founder on a controlled document, and neither /proto nor the repo contains "residual evidence", "semantic checksum" or "Understanding State". No entity exists yet to be the applicant. lines 244 to 291, 1481, 1694, 2877

HIGH
11

The whitespace matrix scores vocabulary, not capability

Rows are named in the author's coined terms, AU gets "Proposed" for nothing built, and the desk review is a same-day read of thirteen vendor landing pages. It ignores the two fields closest to the idea: assurance-case tooling (OMG SACM, GSN, Adelard ASCE, Assurance 2.0 defeaters) and Palantir's decision lineage. "Category-defining hypothesis" sits on the title page of a document routed to investment review, while D.2 only permits "not located as a directly equivalent public product claim". lines 20, 152 to 243, 2887

HIGH
12

Three encoder pass lists, figures that contradict their tables, two pilots that become three

Table 8.1 has seven passes, Figure 2 has six (no Verify), the WBS and M-ENC-001 have six without Compile, and gate G4 has no producing pass. Figure 1 sends enterprise sources into K and decisions out of K where the text says J ingests and L executes. Figure 3 uses seven relationship labels not in table 9.1. Lines 76, 1433 and 1689 say two pilots; section 27 defines A, B and C, with a 25 percent time-reduction criterion against a baseline study the plan admits is unrun. lines 526 to 553, 1102 to 1130, 1563 to 1579

HIGH
13

Identity, ABAC, PKI and separation of duties are assumed everywhere and absent

M-SEC-001 wants object-level authorization at five boundaries, ADR-M-004 wants OPA or Cedar in Wave 0, ADR-M-011 wants PKI in Wave 2, M-DEC-006 wants four-role separation. The repo has five gate accounts, HS256 verify-only, four project-membership roles, a permissions module that is a placeholder returning its input unchanged, and no tenant column in any migration. lines 2340, 2427, 2768, 2804

HIGH
14

Passes self-report their invariant results; the loophole is downgrade, not delete

The delta envelope carries protectedInvariantResults under the producing pass's own signature and nothing says the verifier recomputes them. Materiality is pass-assigned and non-monotone, and line 698 permits "downgrade claim" as a disposition with no named authority, so shrinking the material set is the cheapest route to 100 percent provenance coverage. lines 556, 666, 694 to 699, 1873

HIGH
15

Bitemporal reconstruction needs a bitemporal J that does not exist

M-USG-003 and M-USG-010 require validity time and transaction time on every material relationship. seos_nodes and seos_edges have no temporal columns, the J critical-path entry covers only ontology and permissions, and nobody has costed version history against the one-billion-relationship envelope. lines 1187 to 1189, 1464 to 1467, 1929, 1964

HIGH
16

Service levels asserted as Must with no derivation

p95 60 seconds for a fresh compile of seven chained passes including flip-boundary search and an NLI check; 300 concurrent compiles; 100 million objects, one billion relationships, 5,000 users; all "subject to measured architecture validation" in one place and SHALL in another. No tokens-per-compile figure anywhere, and no pilot-sized profile /proto can be measured against. lines 1150 to 1193, 2599 to 2616

HIGH
17

AU copies controlled content into five stores with no residency rules

C1 forbids a shadow repository; section 14.1 then stores evidence fragments, payloads, projections and embeddings. Revocation propagation is specified only for the cache, nothing says what text the vector index is built from, and the trust zones use "classify" as a verb with no reference to Package I's enumerated levels. lines 300, 849 to 866, 1041 to 1062

HIGH
18

All 188 requirements are Must, and verify method is constant per family

Zero Should or May despite both being defined. Every CON requirement is Inspection including the fail-closed one, every RSN is Analysis including the one M-VER-005 tests by mutation, every CMP is Demonstration including a negative requirement. "Smallest practical fragment", "minimal set", "estimate cognitive budgets" carry no threshold, so the trace-matrix gate cannot close. lines 1700 to 2743

HIGH
19

No wedge, and no evidence the core bet works

Eight personas, eight use cases and all four projection depths are mandatory by Wave 2, including a Glance view for executives who receive briefs from chief engineers, not from tools. Seven passes with typed causal reasoning and flip-boundary search have no stated method, no reference to the J.4 context code that already exists, and no worked example of a single compiled decision. Wave 0 measures "value" on a schema prototype with no interface. lines 334 to 398, 519, 1430 to 1434, 1692

HIGH
20

Section 30 is a policy poster, and B.2 asks for a second repository

The implementation directive is one paragraph of prohibitions with no repo placement, no interface stubs for J, K or L, no acceptance tests, and a delivery order that omits M.7. B.2 prescribes an eleven-service monorepo against the one-codebase rule and a team that ships from one Next.js plus Python repo. Supabase migrations also need exactly one home before any au_* table lands. lines 1697 to 1699, 2812 to 2814

HIGH

Narrowed or killed by the refuters

04

The blind spot

The review universe in section 3 is seven ALM and PLM vendors. The nearest prior art sits outside it, and some of it sits inside our own repository. What is genuinely novel survives this list, and it is stronger for being stated against real neighbours instead of "Not located".

What the matrix saysWhat already exists
Residual evidence spine, three auditable threads, counterfactual flip boundary: "Not located" at six vendors
Assurance-case tooling: OMG SACM 2.2, GSN, Adelard ASCE, Assurance 2.0 defeaters, SEI eliminative argumentation, LLM defeater generation (CoDefeater, 2024). Claim, evidence, argument, residual doubt and human attestation, thirty years old with an OMG standard.
Versioned decision-specific Understanding State, historical explanation at prior knowledge time: "Not located" or "Adjacent"
Palantir Ontology decision lineage: decisions recorded against data version and application, exposed to humans and agents. Excluded from the benchmark with no stated reason.
Classification, approval tiers, audit trail, air-gap deployment: specified fresh in M
Our own Packages B, C, D, G and I. The nearest prior art for a third of M is in docs/spec of the same repo.
Comprehension tracking governed by ISO 42001, ISO 23894 and NIST AI RMF
EU AI Act Annex III 4(b) and GDPR Article 88 as the operating envelope for any per-person record. Voluntary standards do not substitute for a conformity assessment.
The reasoning thread as a new kind of artefact
Design-rationale lineage (IBIS, QOC, SEURAT) and ADR tooling. Low severity, but it belongs in the map.
Four patents cited with no assignee
Two of them (US20250165226A1, WO2025024326A2) appear to belong to one DoD-adjacent competitor with an "interconnected digital engineering platform" pitch. Flagged by the fact-check lens, not yet verified.

What is actually novel after this: machine-verifiable binding of claims to graph evidence, supersession on dependency change, the computed flip boundary as a minimal intervention set, and comprehension closure. Say that. All four patents, the standards map and the vendor references were verified as real and accurately described; the bibliography is sound, the matrix built on it is not.

05

What SEOS already has for it

Read against the live code, Package M is not a greenfield build. Most of the compiler's inputs exist as exported functions today, and the decision record it wants to invent is already in production.

PRISM v3
Decision records, alternatives, bias findings, decision quality vector and the prism_audit ledger, live on /proto since 28 August. Maps onto UnderstandingRequest and State, M-DEC-009, Conflict and Assumption, qualityVector, and the AU ledger.
extend, not build
J.4 context engine
buildAIContextFromProjectGraph, the EQL query planner, the grounding validator and the ranking service. This is the evidence compiler's first pass, already written.
evidence compiler base
Impact services
analyzeImpact over the graph and simulateImpact behind the live impact-simulator page. The Impact Lens and P4 start here.
impact lens base
Package L
L.1 accepted on 30 August, L.2 to L.8 landed on feature/package-l. Unmerged, unhosted. "Merged and hosted" is the entry gate for anything that routes a release through L.
wave 3 gate
Infra memo, 16 June
Postgres plus Apache AGE, never serverless, one codebase, Neo4j as a costed Plan-B only. M's storage section has to be rewritten against it, not around it.
standing decision
Migrations 001 to 004
Rate limits, auth plus prism_audit, PRISM v3 RLS, S6 audit list. The only migration home today. au_states and au_attestations land there, and we record one ADR that says so.
where au_* lands
06

What we build first

One use case, one persona, two depths, no L dependency. UC-01 change impact for a systems or chief engineer, Brief and Deep projections, UAC-0 and UAC-1, on the live /proto graph. The output is one real decision compiled on real project data, demoable to a chief engineer under NDA, which is the evidence Wave 0 says it wants and does not schedule.

01

Question Frame

Question, decision type, role bound to the existing Role type, baseline as the current graph revision, depth, assurance class, protected facts picked from graph nodes. M.1; M-REQ-001 to 003, M-CON-002.

3 to 4 days
02

Evidence compile over the project graph

lib/au/compile.ts on top of the J.4 context engine, the EQL planner, the grounding validator and the impact services. Output: evidence manifest, authoritative or inferred or unverified class, provenance coverage, stale detection. M.2 and M.3; M-EVD-001, 002, 004, 005, 007, 013.

5 to 6 days
03

Understanding State persisted

Types from schema 9.2, an au-compile edge function, migration 005 with immutable versions, status, material claim IDs, quality vector and semantic checksum. Persistence is net-new; nothing in either checkout defines it yet. M.2; M-USG-001, 002, 004, 006; M-CON-003, 004; M-PRJ-003.

4 to 5 days
04

Three explicit passes with delta records

P0 Frame, P1 Bind, P5 Compile, one signed delta each. P3 Challenge imports the prism-engine output as Conflict and Assumption objects instead of building a new challenge model. M.4 partial; M-ENC-001, 003.

3 days
05

Brief and Deep projections with a real checksum gate

Per-claim source reveal, declared omissions, a specified canonicalize, subset equality for the shallower view, JSON export stamped with state ID, version, baseline and status. M.8 partial; M-PRJ-004, 005, 007, 011.

4 days
06

Attestation in L-absent mode

An au_attestations row with actor, role, scope, policy version and disposition including no-decision, attester never equal to requester enforced in SQL, shown in the PRISM decision log. The ledger is prism_audit extended, not a sibling. M.11 partial; M-DEC-003, 004, 006, 009, 010.

2 to 3 days
07

Ten golden cases and one acceptance test per exit criterion

Hand-authored from the corpus classes: sparse evidence, projection trap and restricted evidence at minimum. The three registered demo bundles carry enough requirements, verification cases, risks and change requests for a real compiled decision. M-VER-001 seed.

3 days

Deferred on purpose: the graph projection store, vector index, object store, Glance and Audit depths, counterfactual execution and FMI, the time machine, external adapters, SHACL, the ABAC engine, PKI, release through L, and every per-person comprehension feature (that last one on legal grounds, not scope discipline). Your neural-operator work is the natural surrogate engine for the Counterfactual Lab when M.9 comes round, far cheaper than full FMI co-simulation.

Effort: about 25 working days serial, 3 to 5 calendar weeks with the agent fleet in parallel and your PRs on the schema path. Two decisions first, hours if made and weeks if not: one migration home, and one checkout of origin/main to build on.

07

What v1.1 needs

Thirteen changes that turn the draft into the SEOS baseline. None of them touch the doctrine.

08

Recommendation

▶ Adopt the doctrine. Rewrite the package as v1.1 together. Start the UC-01 slice now.

Package M is the right next layer and its constitution is the best statement of what SEOS is for that either of us has written. What it needs is to be brought down to the company we are and the code we have: Postgres plus AGE, PRISM extended, L-absent until L is merged, role-level comprehension only, and one provisional filed first.

I start the seven-step slice on a clean checkout of origin/main this week. When the first Understanding State compiles on the eferry graph, that is the Wave 0 evidence, and v1.1 gets written against a thing that runs instead of a thing that is described.