A property decision is not one answer. It is a state supported by evidence.
Illustrative worked example — fictional property
One decision record, before and after new evidence
Not a live listing and not an analysis. It shows the structure a real STRATAFORM decision record carries.
- Source
- Interpretation
- Position
- Uncertainty
- Open point
- Next action
- Position
- Within supported range
- Supported by
- Price evidence · Surface evidence · Location context
- Uncertainty
- Medium
- Open point
- Updated cadastral plan missing
- Human authority
- Required — the system does not authorise purchase
- Provider
- NOT_APPLICABLE_DETERMINISTIC
- Previous version
- None — first materialisation
- Position
- Re-evaluated within supported range, narrower
- Supported by
- Price evidence · Verified surface · Location context
- Uncertainty
- Lower — one open point closed, one remains
- Open point
- Updated cadastral plan still missing
- Human authority
- Required — the system does not authorise purchase
- Provider
- NOT_APPLICABLE_DETERMINISTIC
- Previous version
- V1 preserved, not overwritten
Geometra contribution · 112 sqm · accepted after review by the person who holds the decision
Scoped invitation → contribution → explicit review → canonical evidence
Evidence changed · position re-evaluated · previous version preserved · the buyer still decides
No material change → no new version. The record stays at V2.
This is the technology layer of STRATAFORM. It exists so a technical reader can check how decision state is produced, how evidence relates to conclusions, where uncertainty stays visible, what happens when information changes, and where human authority remains. STRATAFORM.app is where decisions are carried out; STRATAFORM.eu explains the buyer problem; Chainplug.ai holds the parent architecture.
Decision Trace
A server-authoritative, append-only record holds the material decision state. It carries the version, the conclusions, the relationship between each conclusion and the evidence supporting it, the reasoning that remained explicitly unbound to any source, who produced it, who initiated it, provider or model provenance where a model participated, the requirement for human authority, the link to the previous version, and the attribution of what changed.
It is not a log. It is not a blockchain. It is the decision itself, versioned, with identical state deliberately producing no duplicate version.
Evidence to position
A material conclusion is never a naked output. It is stored with what supports it, what limits confidence in it, what is unbound or missing, what remains open and what action follows. The chain below is the shape of the record, not a diagram of an intention.
Change observability
New material evidence or a canonical correction triggers re-evaluation. A material change produces a new observable version and preserves the previous one. An identical re-evaluation produces no new version at all. Freshness is exposed as CURRENT, OUT_OF_SYNC, TRACE_MISSING or RETRY_REQUIRED, so a stale decision cannot silently look current.
Human authority
Deterministic and AI components may acquire, structure, compare, derive, expose uncertainty and recommend a next action. People retain acceptance, professional verification, responsibility and the purchase decision. The record itself states this: human authority required, purchase not authorised.
Producer is not verifier
A producer cannot certify their own case deliverable. The separation is enforced at the authority boundary of the data layer, not by interface convention. The same principle governs external contribution: received is not verified, and a contribution is not canonical truth until an authorised acceptance promotes it.
Collaborative accountability
A scoped invitation creates a role-bound contributor. The contribution is persisted, reviewed explicitly, accepted or rejected, integrated into canonical evidence only where authorised, and the Decision Trace is then re-evaluated. Scope covers the record, the open point, the role, the responsibility, expiry, revocation, attribution and historical preservation. The buyer remains the decision-maker throughout.
Multilingual decision integrity
The original contribution is preserved. A machine reading projection is preserved separately. An optional human correction is attributed separately again. Translation is a reading layer: it is not truth and it is not evidence. A message is not evidence, and changing locale does not change a decision. Production-grade translation across all 36 locales is not claimed; the proven path today is narrower.
Model independence
For the proven paid record, provider identity was NOT_APPLICABLE_DETERMINISTIC: no generative model participated in deriving the decision. STRATAFORM is not built on the assumption that a language model must produce the answer. Models may participate where appropriate, but evidence, provenance, authority, uncertainty, decision state and human responsibility must survive model substitution. Complete vendor independence across every subsystem is not claimed.
Authority and security architecture
Access decisions are made server-side. Capabilities are bounded and revocable. Database-level authority boundaries, append-only attribution where required, public-exposure guards, URL sink and SSRF controls, secret scanning and classified privileged-function boundaries are in force. These are stated as architecture; the enforcement detail is deliberately not published.
Technology status inventory
Every named capability on this site carries a status. Nothing below mixes what runs today with what remains architecture or research.
- Proven liveObserved running on a real, paid decision record in the live system.Proven live
- Implemented · not provenCode exists and executes, but no public evidence run is cited here.Implemented · not proven
- PartialWorks within a narrower boundary than the general claim would suggest.Partial
- DormantBuilt or specified as architecture, not participating in the live decision path.Dormant
- Future / researchDirection of work. Not available and not implied to be available.Future / research
Live STRATAFORM system
Running today in STRATAFORM and observed on a real decision record.
- Decision TraceProven live
A server-authoritative, append-only record of material decision state: version, conclusions, conclusion-to-evidence relationships, explicitly unbound reasoning, producer attribution, initiator attribution, provider or model provenance where applicable, the human-authority requirement, the previous-version relationship and change attribution.
Boundary · This is not a log and it is not a blockchain. It is the decision state itself, versioned. Identical state does not create a duplicate version.
- Conclusion-to-evidence bindingProven live
A material conclusion is stored together with what supports it, what limits confidence in it, and which reasoning remained unbound to any source.
Boundary · The proven path is the Decision Trace path. Not every STRATAFORM subsystem is claimed to use this structure universally.
- Material-change observabilityProven live
New material evidence or a canonical correction triggers re-evaluation. A material change produces a new observable version; an identical re-evaluation produces none. Freshness is exposed as CURRENT, OUT_OF_SYNC, TRACE_MISSING or RETRY_REQUIRED.
Boundary · Re-evaluation observes change. It does not decide on the buyer's behalf.
- Preserved human authorityProven live
The record carries human_authority_required = true and authorises_purchase = false. Deterministic and AI components may acquire, structure, compare, derive, expose uncertainty and recommend a next action. Acceptance, professional verification, responsibility and the purchase decision stay with people.
Boundary · No autonomous transaction authority exists anywhere in the system.
- Producer ≠ verifierProven live
A producer cannot certify their own case deliverable. The separation is enforced at the authority boundary of the data layer, not by interface convention.
Boundary · Implementation detail of the enforcement is deliberately not published.
- Collaborative accountabilityProven live
Scoped invitation, role-bound contributor, persisted contribution, explicit review, acceptance or rejection, integration into canonical evidence where authorised, then Decision Trace re-evaluation. Scope covers record, open point, role, responsibility, expiry, revocation, attribution and historical preservation.
Boundary · Received ≠ verified. Contribution ≠ canonical truth. The buyer remains the decision-maker.
- Multilingual decision integrityPartial
The original contribution is preserved, a machine reading projection is preserved separately, and an optional human correction is attributed separately again. Contextual multilingual messaging exists on the same foundation.
Boundary · Translation is a reading layer: translation ≠ truth, translation ≠ evidence, message ≠ evidence, locale change ≠ decision change. Production-grade translation is not claimed for all 36 locales; the proven path is narrower.
- Scoped authority and fail-closed controlsProven live
Access decisions are made server-side. Capabilities are bounded and revocable. Database-level authority boundaries, append-only attribution where required, public-exposure guards, URL sink and SSRF controls, secret scanning and classified privileged-function boundaries are all in force.
Boundary · Stated as architecture, not as a published security checklist.
- Model independence of decision stateProven live
For the proven paid record, provider identity was NOT_APPLICABLE_DETERMINISTIC: no generative model participated in deriving the decision. Evidence, provenance, authority, uncertainty, decision state and human responsibility survive model substitution.
Boundary · Models may participate where appropriate. Complete vendor independence across every subsystem is not claimed.
Foundational architecture
Real architectural work, frozen as a baseline, distinct from live execution.
- Chainplug Constitutional KernelImplemented · not proven
The shared constitutional layer that governs identity, language, consent, thresholds and transitions across ecosystem properties. Real architectural work, frozen as a baseline.
Boundary · Frozen and distinct from the live STRATAFORM buyer execution path. Architectural existence is not live execution.
- Kernel admission and experience constitutionsImplemented · not proven
The written rules for what may be admitted as evidence, how a surface must behave, and which visual primitives are permitted.
Boundary · Governs this property and the specification. It does not run inside the live buyer decision path.
Dormant / research
Built, specified or intended — and explicitly not powering a live decision.
- TITAN and TITAN BrainDormant
The trust runtime layer designed to carry evidence, reasoning, governance and uncertainty with a conclusion after it leaves the system that produced it.
Boundary · Not powering the live buyer today. Read every TITAN page on this site as architecture and research, never as a live capability.
- Sigil (portable sealed artefact)Dormant
The sealed, portable artefact form of a conclusion, specified alongside the trust runtime.
Boundary · Specification and architecture. Not issued by the live buyer path.
- Advanced decision replayDormant
Re-executing a past decision against exactly the evidence available at that moment.
Boundary · Demonstrated here on fictional worked examples only. Version history in the live system is preserved; full replay is not a live buyer feature.
- AI agent infrastructure and domain adaptersFuture / research
Named agents, external agent access and adapters for domains beyond Italian residential property.
Boundary · Direction of work. No public API is exposed and no agent participates in a live decision.
- Predictive and institutional capabilitiesFuture / research
Forecasting, portfolio-scale and institutional deployments of the same evidence architecture.
Boundary · Unlocked only after validation. Listed so the direction is inspectable, not to imply availability.