The 2026 Remote Work Policy controls. A superseded handbook conflicts and is preserved as such.
Platform · Business App Engine + Platform API
One platform. Three applications.
These are applications—not modes, skins, or three views of the same chatbot. Each has its own users, business matter, native interface, workflow, information world, authority, effects, and durable result. What they share is the governed platform underneath.
Open the reference applicationsQuestionnaire: 30 days
Contract: 90 days
SOC 2 report no longer current for the review period.
Evidence needFull disclosure has not been established.
Evidence needIndependent reviewer authority remains separate from the recommendation.
| Automated tests | Pass | Current artifact |
|---|---|---|
| Security scan | Pass | Wrong build |
| Production authority | Required | Missing |
| Rollback plan | Ready | Validated |
The exact artifact must be evidenced, independently approved, deployed, observed, and settled.
Consequence gradient
The applications differ most where consequence increases.
Say → Judge → Act is not a feature ladder. It is a constitutional gradient. More consequential software needs more explicit evidence, authority, effect control, observation, and terminal proof.
Qualify what the application may state from current, attributable sources.
- Primary burden
- Source authority
- Human power
- Business approval remains elsewhere
- Terminal proof
- Answer + sources + reliance boundary
Turn requirements and conflicting evidence into an accountable recommendation for an independent reviewer.
- Primary burden
- Evidence sufficiency + criteria
- Human power
- Reviewer settles the decision
- Terminal proof
- Findings + decision + obligations
Carry judgment across explicit production authority into an observed external effect.
- Primary burden
- Artifact-bound evidence + authority
- Human power
- Independent production approval
- Terminal proof
- Effect + observation + certificate
Common resources
Different software can share one constitutional substrate.
The interface, workflow, and business object change. The underlying questions do not: What is this undertaking for? What information belongs to it? Which cognition is permitted? Who holds authority? What effect may occur? What result was actually observed?
Business App Engine composes these constitutional resources into domain-native software. Platform API gives developers stable governed contracts for creating, advancing, observing, and proving them.
What is being accomplished, under which success condition?
What is retained, admitted, current, contradictory, or missing?
Which deterministic, inferential, retrieval, and reciprocal acts are allowed?
Who may decide, approve, authorize, or decline?
What may touch the outside world, and how is its actual result known?
What did this governed application matter finally become?
Compose one application
Follow Vendor Risk Review from application constitution to analyst experience.
The public portfolio has already proved three products. Now one is enough. This source-faithful composition shows how the Business App Engine binds a governed adjudication workflow to evidence policy, reviewer authority, actions, and a domain-specific Material interface.
export const vendorRiskReview = defineApplication({
workflow: "vendor-risk-review",
input: "vendor-risk-review.request.v1",
output: "vendor-risk-review.recommendation.v1",
policies: [
"vendor-risk-review.evidence.v1",
"vendor-risk-review.authority.v1",
"vendor-risk-review.settlement.v1",
],
actions: [
"cases.write",
"runs.write",
"vendor-review.decide",
],
});
Questionnaire promises 30 days. Executed contract permits 90.
Current assurance covering deletion controls has not been established.
Full disclosure remains an evidence need.
The application may produce the recommendation. The independent reviewer owns the decision.
Prove it
The application can expose why its result deserves institutional reliance.
A polished interface is not the proof. Vendor Risk Review preserves the source conflict, the unmet requirements, the model-supported recommendation, the independent reviewer’s decision, and the obligations that survive that decision.
The same principle scales with consequence. Company Answers attaches an answer receipt and reliance boundary. Release Readiness carries authority, observed deployment, rollback truth, and a terminal certificate.
Regulated customer-support data is not approved for processing on the present record.
- Requirement conflict
- Deletion: questionnaire 30 days · executed contract 90 days. Preserved
- Evidence need
- Current assurance covering deletion controls. Open
- Evidence need
- Full subprocessor disclosure. Open
- Recommendation
- Request more information before institutional approval. Run R-814
- Decision authority
- Independent Third-Party Risk Reviewer. Independent
- Continuing obligations
- Obtain updated assurance, reconcile deletion term, finish subprocessor packet. Carried forward
Go deeper
Inspect the applications, the boundaries, or the operating model.
Platform owns application construction. Integrations owns source and effect boundaries. Technology owns deployment and operating responsibility. The reference applications remain available as independent product artifacts.