Static spine = the 9 AIM cells (who does it & at what level). Right column = the new top-level processes. Click a process to light up the activities it threads across the cells; click an activity, role, or artifact for what we know. Roles carry their instructions; artifacts point to their file. The model is the single source of truth.
activity defined named only — detail to come role (click for instructions); filled = shaped artifact (click to open); filled = exists
Freshness (separate layer): green = up to date orange = probably needs an update / parked red = needs update(no marker = no opinion yet)
BUSINESS — why & what
INFORMATION — meaning, coordination
TECHNOLOGY — build & run
STRATEGIC
Cell 1Strategic Business
CEO
1.1grant a mandate (authority + budget)
1.2set risk appetite & trade limits
1.3approve / decline a decision
1.4add capital with a researched reason
artifactsThe Mandate
Cell 2Strategic Information
CIO
2.1give a cost/benefit verdict (advisory)
2.2recommend an emergency-change call
2.3set the information-isolation principle
artifactsThe Isolation Principle
Cell 3Strategic Technology
IT ArchitectCTO (parked)
3.1produce an architecture decision
3.2rethink the stack (via change)
artifactsThe Architecture Advice
TACTICAL
Cell 4Tactical Business
Process Owner
4.1draft a rulebook / instruction change
4.2maintain the rulebook (rules-as-data)
4.3keep the role-interaction map (no overlap / no conflict)
Two halves separated by the store: Gather writes raw pieces · Compute reads them and judges · Change modifies the machine. Configure & Approve and Technology are cross-cutting. Click one to trace its activities across the grid.
GATHER WRITE
Acquire a piece → validate it against the process rules (accept/reject) → write accepted rows to the store. Runs OUTSIDE the tool in isolated roles/Spaces: creative freedom in HOW, a fixed handover format. Gather VALIDATES (does it fit the rules?), it never judges.
Trigger: A cadence, a human event (portfolio upload), or a request from another process (score-driven enrichment). Outcome: New timestamped rows in the store. Produces data, never a decision.
7.11 → 7.1 → 7.13 → 7.2 → 7.3 → 7.4 → 7.14 → 7.15
Sub-processes: discover new candidates (7.1, creates records) · enrich a record (7.4, appends; 3 triggers: discovery / freshness / score-driven) · ingest the portfolio (human TR upload) · gather the price (manual now → automated later, fast clock) · gather the environment (IBB / sector, content TBD). The intake gate is the accept/reject conformance check.
COMPUTE READ → JUDGE
Read accepted pieces from the store → produce a judgment or artifact. The tool does the math. JUDGMENT IS ALWAYS COMPUTE — deterministic (the score, Lane A) and stochastic role-judgments (Lane B) both live here.
Trigger: Fresh data arrived, a cadence, or a human / process 'run now'. Outcome: A computed judgment/artifact (score, advice, dashboard, finding). Produces a result, never live action.
Sub-processes: calculate the score (9.5, every stock, rank the list) · tier the enrichment (load control: top 10 daily / next 40 weekly / rest monthly — a Compute→Gather loop) · produce the trade advice (7.8, named) · create the dashboard (absorbs detect + rank, named) · evaluate the machine (5.5, lowest priority). 'Form judgments' removed — those are pieces written by Enrich.
CHANGE MODIFY SELF
Modify the machine's own rules or tool through the governed lifecycle. First-class and vital. Two lanes by WHAT changes: Lane A = calculations (heavy, testable); Lane B = instructions (light, fast). The process-description file is canonical; the Space instruction is its deployment.
Trigger: A role's improvement suggestion, a human business request, or an incident / data-quality issue. Outcome: An approved + deployed change committed to the canonical rulebook/process file (version recorded), or a rejected / reverted one.
Sub-processes: route a change to the right lane (CH1, by target: Lane A calc / Lane B instruction) · deploy from the canonical file (CH2, file first → then the Space; a direct Space edit = drift) · run the governed lifecycle (CH3, govern → plan → safe window → sandbox → validate → deploy → smoke test; named). Entry points: improvement (5.5), incident (8.1), architecture (3.1), emergency (2.2).
CONFIGURE & APPROVE HUMAN LAYER
Cross-cutting human layer (NOT a process). The human sets the ENVELOPE up front (mandate, risk appetite, capital, limits) and the AUTO/MANUAL switch per decision point, then APPROVES where a point is set to manual.
Trigger: Standing config + a decision point set to 'manual'. Outcome: An envelope (mandate, limits) and a human approval / acknowledgement.
1.1 → 1.2 → 1.4 → 1.3 → 7.11
AUTO/MANUAL is PER decision point (default = machine decides). Lifecycle: start manual (unproven) → graduate to auto (trusted) → a change can reset to manual. LEVELS = granularity (Level 0 = whole gathering, Level 1 = one piece) — DEFERRED. The cadence trigger (7.11) is the human's 'run now' at T2.
TECHNOLOGY — black box (for now) SUBSTRATE
Realizes all three business processes and holds the substrate. Cells 3 / 6 / 9 left alone for now — treated as a black box. Re-enters SOON for implementation advice, notably when we pick the storage shape.
Trigger: A business process needs to run / store / be answered about. Outcome: A running machine: the store, the runtime, recovery, capability answers.
9.6 → 5.4 → 9.4 → 8.4
THE STORE — append-only timestamped rows (the membrane between Gather and Compute); storage shape (event-log vs typed columns + blob) is PARKED. OPERATE / runtime — cadence, kill switch, recovery. Capability Q&A. Implementation: automating the Trade Republic price pull (TR has no API).
How to use: zoom out to the grid, read a cell's activities, then click a process on the right to see which activities it threads across cells.
The boundary: Gather VALIDATES (does it fit the rules?); Compute JUDGES (what does it mean?). A judgment is ALWAYS Compute — even when a role/Space produces it.
The score (9.5) is computed by the TOOL (Technology), not by an AI role — that is why Compute dips into Cell 9.
Two change lanes (by WHAT changes): Lane A = a calculation change (heavy, testable, CAB, deferred re-check); Lane B = an instruction change (light, fast, no CAB, reversible). Roles hold NO calculations — math is forced to Lane A.
Source of truth: the process-description file is canonical → the Space instruction is its deployment. A direct Space edit is drift, flagged by the compliance audit (5.7).
Discussion to-do
Parked threads — things we discussed but have not fully used yet. Pick them up later; colour = freshness.
Live model↔Space bindingRole instructions live in TWO places: the model (canonical) + the Space (deployment). No Space API today — deployment is a versioned copy-paste, drift caught by 5.7. Revisit a true live binding when role execution moves onto the tool (Architecture Advice stage 2). Same for the rulebook.
Storage shape of the storeEvent-log vs typed columns + blob. Decide WITH Technology now that the roles are shaped. Blocks The Store / 9.6.
Server move — execute stage 1Architecture advice is locked (read-only model + artifacts behind one login). Next: SysAdmin/DevOps writes the deploy document; human runs it over SSH.
Per-role access controlOne shared login now. When do we split access per role, and how (the tool, not the OS)?
AUTO/MANUAL levels (granularity)Level 0 = whole gathering, Level 1 = one piece. Deferred. Pick up when we wire the human layer.
Gather the environment (IBB/sector)Sub-process named, content TBD — what exactly do we read and how do we score the sector?
Emergency change lanePath from 2.2 exists but is not walked. Detail when we walk the incident flow.
Automate the Trade Republic price pullTR has no API — manual now, fast clock. How do we automate without an API?
CTO roleParked. Do we ever need it, or does the IT Architect cover strategic Technology alone? (just-in-time-role rule).
Execution coordination = CM (gap CLOSED)No separate Execution Coordinator role. The CM coordinates execution as part of its existing 'intake to closed' job (5.1): sequences the work + assigns to the DOERS (SysAdmin/DevOps + Developer; Support for data-only spec changes). Honors attached CAB conditions DURING the build; QM verifies at the gate. The old GAP is closed.
CM aggregate = synthesize + shortlist (LOCKED)At AGGREGATE the CM SYNTHESIZES complementary domain answers into one coherent change; where answers are genuinely RIVAL it carries a SHORTLIST with analysis and lets the HUMAN choose at CAB (no pre-deciding). CM adds NEUTRAL FRAMING only — flags conflicts/gaps/dependencies, sequences pieces, invents no solution. Closes the old narrow-vs-shortlist knob.
Triage = 4 outcomes (Support, final)Triage outputs ONE of four: user error / known problem (holding state) / corrective change / improvement change. Support decides the label and it is FINAL. Corrective + improvement enter the flow; the corrective/improvement tag is a carried attribute feeding urgency + lane router (5.2).
Known-problem registerOne of the four triage outcomes. A KNOWN PROBLEM is a holding state — needs its own register + a promote-to-change path. Not yet modelled.
Online input form (BUILD)The front door for entering a request is an ONLINE INPUT FORM — a real hosted web artifact. Captures BASE (submitter, the request, date) + CARRIED (triage outcome, contributing sources, column-valid hint(s), impacted column(s)); the MACHINE stamps the request number and validates required fields (incomplete = not accepted, try again). Produces the request that enters the flow. To be built.
How a role responds to a CR (role-owned)The CM runs the solution round and round-count is a PARAMETER — but HOW a role responds to a CR (reply format + what it may say) is the role's PRIVATE rule in its own space instructions, NOT in the flow. Expected shape: solution / impact (pos+neg) / costs / risks. A shared task drafted just-in-time per role.
Human = ON-DEMAND cross-column consultIn the solution round the HUMAN is consulted ON DEMAND — the CM may query the human about anything across columns whenever stuck (a standing resource, no fixed step). A deliberate, named exception to isolation, reserved for the human only.
Who the CM asks (per change)The CM DECIDES PER CHANGE which roles in an impacted column to ask (column owner vs specific operators) and records the choice on the change record. Locked.
Two distinct CR touchpoints per roleA role meets the change process at TWO structured moments (not one): (1) RESPOND TO A CR — solution round, State 4: PROPOSE solution/impact±/costs/risks in own column (sees only own column); (2) INPUT CAB — State 7: sees the WHOLE change, then APPROVE / OBJECT / CONDITION from own column's perspective. Same column-discipline, different stance (propose vs judge). (State 1 raising = input INTO Support, not counted here.) Each is a role-owned rule, drafted just-in-time.
CAB board + isolation boundary (LOCKED)CAB = impacted cells (roles the CM asked) + standing governance (Quality Manager + Process Owner, every CAB) + the human. ISOLATION IS RELAXED at the CAB: all members see the whole synthesized change + cost/benefit (isolation ran States 4–5, then opens). Human is SOVEREIGN: objection = advisory (may override); accepted condition ATTACHES and execution must honor it.
Perplexity credits = both sides of C/B (wired)The human enters currently-available Perplexity credits (Functional Spec). USED at COST/BENEFIT (State 6): credits CONSUMED = cost, credits SAVED in future = benefit; the analysis shows spend vs saving against available credits. CHG-001 saves ~4h/day of hand-building = a credit/effort benefit.