governance · the posture

Audit-first — and on the record.

You do not have to take a measure on trust. Every reading carries its citations, the belief updates behind it, and an audit trail — so a number can be checked rather than believed.

That is the guarantee: a record you can check. How the engine is built is on the record too, below.

The discipline behind the engine

How the engine is built is on the record. For anyone deciding whether to rely on a measure it produces, that record is what shows it is real and built seriously.

Decisions on the record

Every architectural choice is an Architecture Decision Record — the question, the options, the trade-offs, the call, and the date. Nothing structural changes without one. The record is continuous and kept; the history is the argument.

Reasoning on the record

The audit log is not paperwork wrapped around the engine. It is the engine’s output: every interpretation, every challenge, every estimate update, recorded. Transparency here is structural, not a marketing line.

Five contracts that block, not suggest

Test, traceability, bug, scope, topology. Each is a gate the work cannot bypass — a change that breaks a contract does not merge. Discipline that is optional is not discipline; these are not optional.

A bar the hardest claim must clear

The engine’s most demanding claim has a published readiness standard and a validation harness behind it. The bar holds even when the honest answer is “not yet” — and saying “not yet” in public is itself part of the standard.

governance · the record

Every architectural decision, on the record

Not a claim about the discipline — the discipline itself. Every row below is a real Architecture Decision Record in this repository, read straight from source and rendered at build time. There is no hand-maintained summary to drift from what actually shipped.

ADRDecisionStatusDate
000Stage Gate Discipline (Constitution)ACCEPTED · founder-locked 2026-05-232026-05-23
001Strict Contracts and the Violation Moment ProtocolProposed2026-05-09
002The Three Epistemology Modes and the Five Canonical CommitmentsProposed2026-05-09
003Internal Core, External Ring, and Consumer-Count-Dependent GovernanceProposed2026-05-09
004Agent One Verdict Schema (amends ADR-003)Proposed2026-05-09
005Stochastic Engine Architecture (Hybrid LLM Citation + Dirichlet-Multinomial Bayesian)Proposed2026-05-11
006Deterministic and Composite Mode ArchitecturesProposed2026-05-11
007Marker library schema codificationAccepted2026-05-12
008User-in-the-loop citation overrideAccepted (specification only — implementation lands in a follow-up PR)2026-05-12
009ADR-to-PRD/SRS/BC doc-sync CI gateAccepted2026-05-12
010Rich marker schema: framework_context, band_progression, extraction_hintsAccepted2026-05-12
011Compass content source-of-truth + resync disciplineAccepted2026-05-12
012Calibration Governance: Anchor Case Schema and Tier One Pass CriteriaActive — original Draft 2026-05-13; Revision A approved Sprint B13 2026-05-172026-05-13
013Framework-Calibrated Status: `calibration_source` and `calibration_tier`Draft — D-4 reconciled with ADR-012 Rev A on 2026-06-03 (B23), see note below2026-05-14
014L6 Surface Layer ArchitectureAccepted2026-05-14
015Pulse Session ModelAccepted2026-05-15
016Target-Setting and Gap ComputationAccepted2026-05-16
017V2.0 Validation MethodologyAccepted — original 2026-05-16; Revision B approved 2026-06-03 (B23)2026-05-16
018L6 Frontend Stack: Next.js + Firebase Auth + Firestore + Cloud RunAccepted2026-05-17
019Admin console data model + universal auditProposed (DRAFT · parked for founder review)2026-05-19
020Tenant model: org / groups / usersProposed (DRAFT · parked for founder review)2026-05-19
021Dynamic RBAC permission matrixProposed (DRAFT · parked for founder review)2026-05-19
022Modular monolith via npm workspacesProposed (DRAFT · founder-approved direction 2026-05-20)2026-05-20
023Deferred Items Registry · contractProposed (DRAFT · founder-approved direction 2026-05-20)2026-05-20
024compass-platform extraction routine · contractProposed (DRAFT · founder-approved direction 2026-05-20)2026-05-20
025Ring module internal layered architecture · contractProposed (DRAFT · founder-approved direction 2026-05-20)2026-05-20
026Widget feed contract (Bridge surface)Accepted2026-05-24
027Membership model convergence with compass-platform EPIC E81Accepted (B16/T1 landed PR #134 · B16/T1b landed PR #136 · permission_override decision in ADR-028 PR #135)2026-05-24
028Permission override routes kept (no tension with E81)Accepted2026-05-24
029Actions surface canonical shapeAccepted (2026-05-27, post-T4 deploy)2026-05-27
030Drift event canonical shapeAccepted (2026-05-27, post-T3 deploy · founder browser smoke confirmed Bridge shelf 4/4 live · drift_alert widget + /admin/drift list page rendering real candidates · Convert-to-action prompt-flow operational)2026-05-27
031Drift→Action pipeline (V1.x placeholder)Placeholder · V1.x scoping deferred per founder lock 2026-05-272026-05-27
032Audit Firestore sink + query contractAccepted (2026-05-29, post-T3 deploy · founder browser smoke confirmed /admin/audit-log rendering durable events with normalized event_id + org_id hoist · drift_candidate_surfaced doc written via FirestoreAuditSink + queried back through the explorer)2026-05-27
033Sign-off chain (session · action · objective)Accepted (2026-05-29 · B20 closed · live on rev kerte-dev-web-00051-q4r)2026-05-29
034Notifications stack (in-app V1.0)Accepted (2026-05-29 · B20 closed · live on rev kerte-dev-web-00051-q4r)2026-05-29
035Audit Seçim C: retention + redaction + exportAccepted (2026-05-29 · B20 closed · live on rev kerte-dev-web-00051-q4r)2026-05-29
036Parameters surface (implements the B16-planned param primitive)Accepted (2026-05-29 · B20 closed · live on rev kerte-dev-web-00051-q4r)2026-05-29
037Custom roles + hybrid authorityAccepted (2026-05-31 · B21 close-out · D-1..D-10 implemented + verified on prod rev 00055-22z)2026-05-29
038Option-source registry (PA-governed dropdown data sources)Accepted (2026-06-02 · B22 close-out · D-1..D-8 implemented + prod-verified rev 00060-wbm)2026-06-01
039Artifact Engine Architecture (clean, kerte-dev-native)Accepted (architecture locked 2026-06-03; founder-approved). Stage-1 spec2026-06-03
040Engagements — consultant binding via membership projectionAccepted2026-06-12
041Framework-anchor bank (D1)Accepted2026-06-13
042Strengths / Growth / Risks + Top-3 (D3)Accepted2026-06-13
043Evidence-aware re-assessment diff (D4)Accepted2026-06-13
044Playbook gap render — never "—" beside a real target (D2 fix)Accepted2026-06-13
045Per-subdomain §3 framework anchors (D1 Option A)Accepted2026-06-15
046Prompt caching for the citation extractor (cost control)Accepted2026-06-15
047Advisory content-judge (D5)Accepted2026-06-15
048Workbook as narrative cards + CSV (the #1 content gap)Accepted2026-06-15
049Roadmap action drafter — both muscles (B)Accepted2026-06-15
050Deterministic roadmap risk register + RACI (B2)Accepted2026-06-15
051Wire the D5 advisory judge into the curation UI (C)Accepted2026-06-15
052Workbook per-question prose (both muscles)Accepted2026-06-16
053Admin compass-authoring CRUD — E1 Browse (read-only)Accepted2026-06-16
054Admin compass-authoring CRUD — E2 Weights overlayAccepted2026-06-16
055Advisory answer insight for the assessment respondentAccepted2026-06-17
056Admin compass-authoring CRUD — E2.5 Question weights overlayAccepted2026-06-18
057Admin compass-authoring CRUD — E3 Question content overlayAccepted2026-06-19
058Overlay-active runs carry their calibration into the deliverableAccepted2026-06-19
059The compass overlay must reach the respondent wizard (B1/H1 fix)Accepted2026-06-19
060NIST CSF 2.0 Capability Compass (the 4th compass)Accepted (2026-06-25)2026-06-25
061ReviewCockpit — reusable admin triage componentAccepted (2026-06-25)2026-06-25
062Self-service data export + account deletion (V1.1 privacy sub-features)Accepted (2026-06-30)2026-06-30
063Session revocation — active-session list + "sign out everywhere"Accepted (2026-07-01)2026-07-01
064COBIT 2019 compass — first standards-batch migration from compass-platformAccepted (2026-07-01)2026-07-01
065ITIL 5 compass — authored from verified official structureAccepted (2026-07-01)2026-07-01
066ISO 27001 compass — standards-batch portAccepted (2026-07-01)2026-07-01
067TOGAF compass — standards-batch portAccepted (2026-07-01)2026-07-01
068DAMA-DMBOK compass — standards-batch port (batch complete)Accepted (2026-07-01)2026-07-01
069Software Engineering & AI-Augmented Delivery compass — IT-operational wave (1/5)Accepted (2026-07-17)2026-07-17
070AI & Innovation compass — IT-operational wave (2/5)Accepted (2026-07-17)2026-07-17
071IT Strategy & Governance compass — IT-operational wave (3/5)Accepted (2026-07-17)2026-07-17
072Customer Analytics & Data compass — IT-operational wave (4/5)Accepted (2026-07-17)2026-07-17
073Project, Program & Portfolio Management (P3M) compass — IT-operational wave (5/5, wave complete)Accepted (2026-07-17)2026-07-17
074Digital Resilience compass — Business wave (1/2)Accepted (2026-07-17)2026-07-17
075Corporate AI Readiness compass — Business wave (2/2, wave complete)Accepted (2026-07-17)2026-07-17
076Vibe Coder & AI-Augmented Engineer compass — Career wave (1/7)Accepted (2026-07-17)2026-07-17
077Product Manager Track compass — Career wave (2/7)Accepted (2026-07-17)2026-07-17
078Data Scientist Track compass — Career wave (3/7)Accepted (2026-07-17)2026-07-17
079UX Designer Track compass — Career wave (4/7)Accepted (2026-07-17)2026-07-17
080Solo Founder Readiness compass — Career wave (5/7)Accepted (2026-07-17)2026-07-17
081AI Architect Career Compass — Career wave (6/7)Accepted (2026-07-17)2026-07-17
082Mid-career Switch Readiness compass — Career wave (7/7, wave complete)Accepted (2026-07-17)2026-07-17
083ETC Master Compass — full compass catalog migration completeAccepted (2026-07-17)2026-07-17
084Sign-in OAuth: popup, not redirect — reverses a compass-platform lessonAccepted (2026-07-23)2026-07-23
085Assessment depth & mix (Pulse/Deep question-run sizing + continuous-scale closed-form rendering)Accepted (2026-07-27 · founder-locked, revision 1 — content-port scope,2026-07-27
086GDS (Gerçek Doğrulama Sistemi): WHEN × WHAT × WHO, plus artifact-drift and scope-creep guardsProposed2026-07-29
087Unify Handoff into the Action Pipeline: platform-development vs compass-dependent actionsProposed2026-07-29
088A marker's framework citation becomes a typed reference; `tags` keeps its own vocabularyaccepted2026-08-10
089A compass may be defined by data, alongside the twenty-four defined by codeAccepted (founder, 2026-08-10)2026-08-10
090A measurement is a round, and a session is what a round leaves behindAccepted (founder, 2026-08-17). Specified in [SRS-rounds-amendment-1](../../product/SRS-rounds-amendment-1.md).2026-08-17
091A marker's band ladder must say something about that markerAccepted (founder, 2026-08-18) — option C. Applied the same day by2026-08-18
092A question's citation should be a typed reference, not a prefix conventionAccepted (founder, 2026-08-19) — option 2, corrected: aliases first, then2026-08-19
093A question declares how it is answered; the directory stops decidingAccepted (founder, 2026-08-20) — *"Soru tiplerini de soru bazında veritabanında2026-08-20
094Cybersecurity's mode split, after every domain gets both instrumentsWITHDRAWN, undeployed (founder, 2026-08-20). Superseded by2026-08-20
095The question's voice decides its widget; cybersecurity's calibration is not spent to fix itAccepted (founder, 2026-08-20 — chose option 3 over splitting the subdomains).2026-08-20
096Rename the cybersecurity subdomain "Cyber Governance & Risk Management" to "Security Awareness & Culture"Active2026-08-24
097Re-mass the stochastic prior: Dirichlet(1,1,1,1,1) → Dirichlet(0.25,…)Active2026-08-24

Generated at build time from docs/architecture/decisions/ADR-*.md — the file is the source of truth, this table is a read-only projection of it.

The five things the engine will not negotiate

Most of the engine is configurable. Exactly five things are not. They are the reason a measure means the same thing across every compass:

  • The four-step method — As-Is → To-Be → Gap → Roadmap. The skeleton does not bend.
  • Three epistemology modes — deterministic, stochastic, composite. A fourth needs an ADR.
  • The 1.0–5.0 maturity scale — the words per band can be tuned; the numbers cannot.
  • Behavioral evidence with a deterministic floor — the canonical stochastic implementation.
  • Audit logging — every interpretation, challenge, and update, recorded. Not optional.

Everything else — endpoints, names, defaults, adapters — can change under ordinary decision discipline. These five change only with a major version and explicit owner approval.

using kerte

If you want to use it

Most teams run it here. Anything beyond that — your own methodology carried by the same engine — is a conversation. One door covers it.