<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Sal Parvez | ML Systems</title>
    <description>The latest articles on DEV Community by Sal Parvez | ML Systems (@salparvez).</description>
    <link>https://dev.to/salparvez</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4107168%2Ff353bd72-e6f9-4729-8021-ad0117fb2310.jpg</url>
      <title>DEV Community: Sal Parvez | ML Systems</title>
      <link>https://dev.to/salparvez</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/salparvez"/>
    <language>en</language>
    <item>
      <title>AI Is Not Valuable. Your Context Window Is.</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Wed, 23 Sep 2026 11:49:00 +0000</pubDate>
      <link>https://dev.to/salparvez/ai-is-not-valuable-your-context-window-is-18j1</link>
      <guid>https://dev.to/salparvez/ai-is-not-valuable-your-context-window-is-18j1</guid>
      <description>&lt;p&gt;The models are remarkable, and they are not mine. Any contractor in my state can rent the same model I rent, at the same price, before lunch. If a competitor copied my entire AI budget line for line, they would have bought exactly what I bought: a rented brain that will answer anyone who asks.&lt;/p&gt;

&lt;p&gt;So the question is not whether AI is valuable. It is where the value goes once the intelligence is identical for everyone who pays for it. It goes one layer up, into the part nobody sells you — the context window, which is everything the model can see at the moment it thinks. A prompt is the line you type. The window is the whole of what it holds in mind while it answers.&lt;/p&gt;

&lt;h2&gt;
  
  
  Seven windows, one brain
&lt;/h2&gt;

&lt;p&gt;My company runs seven specialist minds on one rented frontier model. No fine-tune, no custom model. Seven windows, and the windows are the entire difference. To the mind that takes a house apart, a house is tonnage and fasteners. To the mind that handles lending, the same house is collateral. Same weights, different window, different job.&lt;/p&gt;

&lt;p&gt;The part that surprises engineers is what I leave out. None of the seven minds can see the company's margin. A mind that can see what the business earns will quietly start serving it, and the customer pays for that drift. Value is not only created by what you put in front of a model. A great deal of it is created by what you refuse to put there.&lt;/p&gt;

&lt;h2&gt;
  
  
  Size is capacity. Curation is the asset.
&lt;/h2&gt;

&lt;p&gt;More context is not better context. We handed the minds a dense, uncurated pile once and watched the cheap models fail our verification step one after another, until the work escalated to premium models to clear a bar it had cleared cheaply before. That warm start came back 23% dearer than the cold run it was meant to improve on. The disciplined version of the same system came back 37% cheaper on its second run — same work, same quality bar, nothing given up. Both figures are MEASURED, on our own runs: a handful of them, not a benchmark, and not a claim about anyone else's stack.&lt;/p&gt;

&lt;p&gt;Which means the real work is not prompting. It is editorial. And editing needs a standard.&lt;/p&gt;

&lt;h2&gt;
  
  
  The window has an intake spec
&lt;/h2&gt;

&lt;p&gt;I do not open a session with a question. I open it with the lens. Three rules get loaded before the problem does, and the published wording is exact:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Transparency Trust&lt;/strong&gt; — ML Systems doesn't profit from being in the middle of your transaction, or from consuming your compute. We hold it, optimize it, and hand you complete visibility at every step — every claim carrying its reality label, so you can check it rather than trust it. &lt;strong&gt;The Lucent Lens&lt;/strong&gt; — Glow within to help humans. Prioritize local community and human profit over automation. Utilize the person, not the process. &lt;strong&gt;Minimum Viable Expense&lt;/strong&gt; — The minimum viable expense that generates the maximum value in the system.&lt;/p&gt;

&lt;p&gt;Read those as rules rather than values. Each one governs what may enter a window, and in what condition. It is an intake specification, and it governs me as much as the machines: every decision, edit and trade-off — by a person or a mind — is weighed through all three.&lt;/p&gt;

&lt;h2&gt;
  
  
  Provenance is the window, not the model
&lt;/h2&gt;

&lt;p&gt;At the bottom of roughly two dozen of our pages there is one line: &lt;strong&gt;Built by the Custodian under LL · TT · MVE.&lt;/strong&gt; It looks like a slogan. It is an attribution. It names which frame was loaded in the window that produced whatever you are reading — the only provenance question worth asking about anything made with AI. Not which model wrote it. What it was allowed to see, and what it was forbidden to do with it.&lt;/p&gt;

&lt;p&gt;And it is checkable. The lens is published, hashed and Ed25519-signed at &lt;code&gt;mlsystemsri.com/.well-known/lucent-lens.json&lt;/code&gt;. Hash what you quote of us; if it does not match, it drifted. A value is asserted. A control is verified.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest part
&lt;/h2&gt;

&lt;p&gt;No ML Systems deconstruction has been performed yet. The company is bootstrapped and pre-revenue. The 80–90% material recovery target is MODELED, the two-day sequence is ASPIRATIONAL, and the two cost figures above are MEASURED on our own runs. The thesis is a claim too: I run one company, in one state, in one industry. But if everyone is buying the same intelligence, the only durable thing any of us owns is the window we build in — the record we can hand the model, and the discipline we used to decide what belonged there.&lt;/p&gt;

&lt;p&gt;The full piece, including the construction half — the same three questions asked of a board instead of a sentence, RRR: Reuse, Resale, or Recycle — is on our site: &lt;a href="https://mlsystemsri.com/insights/ai-is-not-valuable-your-context-window-is" rel="noopener noreferrer"&gt;https://mlsystemsri.com/insights/ai-is-not-valuable-your-context-window-is&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>architecture</category>
      <category>llm</category>
      <category>discuss</category>
    </item>
    <item>
      <title>Vibe coding names a mood. The job is Language Modeler.</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Fri, 18 Sep 2026 23:54:21 +0000</pubDate>
      <link>https://dev.to/salparvez/vibe-coding-names-a-mood-the-job-is-language-modeler-1lnm</link>
      <guid>https://dev.to/salparvez/vibe-coding-names-a-mood-the-job-is-language-modeler-1lnm</guid>
      <description>&lt;p&gt;&lt;em&gt;This started as a comment under Giorgi Kobaidze's "Vibe Coding Isn't the Problem. Calling It Engineering Is." The full piece lives in the ML Systems repo: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/why/articles/the-language-modeler.md" rel="noopener noreferrer"&gt;The Language Modeler&lt;/a&gt;. This is the version for the people in the fight.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;There is a standing fight on this site, and every other developer forum, about what to call a person who builds software by writing English and letting a model write the code. One side says it is creation and not engineering. The other says the engineering did not disappear, it moved. Both sides are describing the same person and refusing to name the role.&lt;/p&gt;

&lt;p&gt;At ML Systems we do not say vibe coding. The role is &lt;strong&gt;Language Modeler&lt;/strong&gt;. It is a named node — &lt;code&gt;LM&lt;/code&gt; — in the company's Financial Neural Net, beside the Financial Architect and the Accounting Engineer, and it is the title on my line of the record.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the term means
&lt;/h2&gt;

&lt;p&gt;A Language Modeler models the system in language. Not the syntax of the system — the system itself: what it is, what it is made of, what it is allowed to do, who may write to it, and what counts as true inside it. The output is a model, written in English, precise enough to be carried into code without losing anything that matters.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The AI is a moderator between the English language and the coding language.&lt;/strong&gt; That is the whole of its job. It stands between two languages and carries the model from one to the other. It does not own the English, because the Modeler wrote it. It does not own the code, because the code is a translation of the English, and a translation is judged against its source.&lt;/p&gt;

&lt;p&gt;Once you see the AI as a moderator, the accountability thread that runs under every one of these posts answers itself. A moderator between two languages is never the author of record. If the English was wrong, the Language Modeler owns it. If the translation was wrong, review catches it, or the Modeler owns that too. Nobody gets to say the AI did it, and nobody needs to.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flk99pax0nlpopzjc820v.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flk99pax0nlpopzjc820v.png" alt="The Language Modeler — the English on one side, the translation on the other, the AI as the moderator between" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Why "vibe" was the wrong word
&lt;/h2&gt;

&lt;p&gt;Vibe describes a mood. It says something about how the person felt while typing and nothing about what they produced. A mood cannot be reviewed, cannot be handed to the next person, and cannot be held responsible for a production incident at two in the morning.&lt;/p&gt;

&lt;p&gt;A model can be. A model has parts you can point at. &lt;em&gt;This constraint was stated. That invariant was not. This party may assert that value and that party may not.&lt;/em&gt; When the code fails you go back to the model and ask which of those was missing or wrong, and the answer is a sentence in English that a person wrote and can fix.&lt;/p&gt;

&lt;p&gt;The critics are right that shipping unreviewed output into anything that touches money or personal data is negligent. They are wrong that the fix is to send everyone back to the language reference for two weeks. The fix is to demand the model. &lt;strong&gt;Show me the English.&lt;/strong&gt; If the English is precise, the review of the code is a check on translation, which is a bounded task. If the English does not exist, there is nothing to review against, and no amount of reading the code will tell you what it was supposed to do.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the Modeler has to know
&lt;/h2&gt;

&lt;p&gt;Not every line of the target language. Enough to read the translation, and much more importantly, enough to write the source precisely. That means knowing the domain cold, because the model is written in the domain's vocabulary, not the language's.&lt;/p&gt;

&lt;p&gt;I spent three years as a frame-to-finish carpenter on custom residential work and two years estimating rough-carpentry packages for multi-level commercial buildings before this. The vocabulary I model in is the building's: rafter, sheathing, ring-shank, town record, appraisal, permit. The system I model is a house record — the Master Ledger — that seven AI agents write to alongside one human. The model says, in English:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;the record stores &lt;strong&gt;claims, not facts&lt;/strong&gt; — every value carries who made it, an evidence grade, and the value itself&lt;/li&gt;
&lt;li&gt;evidence is graded on a ladder — &lt;strong&gt;measured › sensed › stated › record › modeled&lt;/strong&gt; — and a modeled value is never authoritative&lt;/li&gt;
&lt;li&gt;a model agreeing with the value it was derived from is shown as concurrence and never counted as an independent vote&lt;/li&gt;
&lt;li&gt;every mind claims, &lt;strong&gt;five seats ground&lt;/strong&gt;, VERA gates, and &lt;strong&gt;only the Custodian stamps&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;a stamp is two keys — the homeowner's and the Custodian's — bound to a fingerprint of the content, so both lapse the moment the content changes; a drift detector, not a cryptographic signature&lt;/li&gt;
&lt;li&gt;two credible sources disagreeing is a state called &lt;strong&gt;conflict&lt;/strong&gt;, which is quarantined and never averaged&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of that is code. All of it became code. The AI moderated the translation, and every time the code did something the English did not say, the English was the thing I went back to.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the skill actually lives
&lt;/h2&gt;

&lt;p&gt;The people defending vibe coding usually describe decomposing a problem, orchestrating tools, validating outputs, and checking that what came back solves the problem. That is modeling. They already do the job. They have been using a word that undersells it, and the word is what the critics are reacting to.&lt;/p&gt;

&lt;p&gt;The people attacking vibe coding usually describe reading every line and interrogating the model about its choices. That is review of a translation. It is necessary and it is bounded, and it is much easier when the source exists.&lt;/p&gt;

&lt;p&gt;The Language Modeler does both, and the model in between is what makes either one possible.&lt;/p&gt;

&lt;h2&gt;
  
  
  The first hire
&lt;/h2&gt;

&lt;p&gt;The job at ML Systems is a &lt;strong&gt;layer&lt;/strong&gt;, not a title swap. The person is a carpenter first and a Language Modeler on top of it, because the model is written in the building's vocabulary and you cannot write precisely in a vocabulary you have not carried. The first ontology this company runs on was written on three blue notepads by a laborer who did not know the word — two-letter task codes, a definition the first time each appeared, a score at the bottom of the day.&lt;/p&gt;

&lt;p&gt;So the first role ML Systems will hire for is exactly that — carpenter and Language Modeler, one person, both halves. Someone who can cut a bastard valley in the morning and, in the afternoon, write down in plain English what a wall assembly is allowed to be so a model can turn it into a ledger entry the crew will recognize. We are not hiring right now; the company is bootstrapped and pre-revenue. The role goes in the record now so that when it opens nobody has to guess what it is.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest labels
&lt;/h2&gt;

&lt;p&gt;The software is &lt;strong&gt;MEASURED&lt;/strong&gt;: a shipped app, a working ledger, an ontology that seven agents and one human speak fluently. &lt;strong&gt;No ML Systems deconstruction has been performed yet&lt;/strong&gt;; the 80–90% recovery target for a house is &lt;strong&gt;MODELED&lt;/strong&gt; and the two-day crane sequence is &lt;strong&gt;ASPIRATIONAL&lt;/strong&gt;. The term Language Modeler is a position, not a standard. I am putting it in the record so it can be argued with — that is what the comments are for.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Read the system:&lt;/strong&gt; &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/docs/neural-net-architecture.md" rel="noopener noreferrer"&gt;Neural Net Architecture&lt;/a&gt; · &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/docs/master-ledger.md" rel="noopener noreferrer"&gt;Master Ledger&lt;/a&gt; · &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/docs/the-seven-minds.md" rel="noopener noreferrer"&gt;The Seven Minds&lt;/a&gt; · &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/ontology/articles/an-ontology-on-three-blue-notepads.md" rel="noopener noreferrer"&gt;An Ontology on Three Blue Notepads&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Sal, founder of ML Systems LLC — Rhode Island, NAICS 236115. Canonical: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/why/articles/the-language-modeler.md" rel="noopener noreferrer"&gt;The Language Modeler&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>programming</category>
      <category>softwareengineering</category>
      <category>discuss</category>
    </item>
    <item>
      <title>Fingerprint at load, pulse before every pass: a heartbeat for agent identity</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Thu, 17 Sep 2026 00:35:12 +0000</pubDate>
      <link>https://dev.to/salparvez/fingerprint-at-load-pulse-before-every-pass-a-heartbeat-for-agent-identity-57ge</link>
      <guid>https://dev.to/salparvez/fingerprint-at-load-pulse-before-every-pass-a-heartbeat-for-agent-identity-57ge</guid>
      <description>&lt;p&gt;&lt;em&gt;The systems half of a piece that lives on the ML Systems site — the canonical is &lt;a href="https://mlsystemsri.com/insights/i-gave-my-agents-a-heartbeat" rel="noopener noreferrer"&gt;I Gave My Agents a Heartbeat&lt;/a&gt;. This one is for people who run agents.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Everybody shipped agents with the open internet this week. Four days before that, Dario Amodei asked the labs to pace the frontier. I run seven agent minds and one human at a construction company in Rhode Island, and this is what I did about both, at my scale.&lt;/p&gt;

&lt;h2&gt;
  
  
  The failure I was actually afraid of
&lt;/h2&gt;

&lt;p&gt;Not a wrong answer. Minds are wrong all the time; the Master Ledger exists so a wrong claim is a row with an author and an evidence grade, not a fact. The failure I couldn't see was a mind being &lt;em&gt;changed&lt;/em&gt; — a compromised dependency, an injected prompt, a bug at runtime — and then going on speaking as itself while no longer being itself. Nothing in the output tells you. That is the failure that does not announce itself.&lt;/p&gt;

&lt;h2&gt;
  
  
  The heartbeat
&lt;/h2&gt;

&lt;p&gt;Each mind has an identity in the codebase: a name, a role, the prompt that is its character. The harness treats that identity as a thing with an origin.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;At module load&lt;/strong&gt;, before any model is called, it fingerprints every mind's origin — a hash over its name, its color, its prompt — and freezes a clean copy.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Before every orchestration pass&lt;/strong&gt; it takes the pulse again.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;If a live mind has drifted&lt;/strong&gt; from its origin, the reflex fires: the drifted mind is re-grounded to the frozen copy, and the drift is reported, never acted on.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;The eight fingerprints&lt;/strong&gt; (seven minds plus the Custodian — me, rendered as a peer, not an apex) hash into one short rhythm, &lt;code&gt;beat8&lt;/code&gt;, that prints on every run.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The baseline is committed to the repository. A legitimate change to a mind shows up in a pull request as that mind's new resting rhythm; a bundle that disagrees with the baseline at runtime is drift by definition. The mobile app carries the same baseline and takes the same pulse on the phone.&lt;/p&gt;

&lt;p&gt;Two choices worth saying out loud:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;It runs below cognition.&lt;/strong&gt; No mind, no model call, no prompt can skip or influence its own beat. A heart does not ask the brain.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;It is a reflex, not a report.&lt;/strong&gt; Its job is not to catch something and open a ticket. When it fires, the collective grounds itself back to what it is — a group of minds that work together for the homeowner — and tells me.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftkacgrwdx07wb8umb5nl.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Ftkacgrwdx07wb8umb5nl.png" alt="Seven minds, one human, one rhythm — the heartbeat card" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The heartbeat, pointed outward
&lt;/h2&gt;

&lt;p&gt;My minds are not the only ones reading the company now. Every frontier agent with a browser will. I can't give those a heartbeat — they aren't mine. But I can ask the same question from the other side.&lt;/p&gt;

&lt;p&gt;Inward: &lt;strong&gt;have you drifted from your origin?&lt;/strong&gt;&lt;br&gt;
Outward: &lt;strong&gt;has what you read of us drifted from what we said?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;ML Systems asks to be read through three lenses — the Lucent Lens, Transparency Trust, Minimum Viable Expense. They were already written down as data: a small JSON file, canonical wording, the question each lens asks, what each forbids. This week that file got the heartbeat's fingerprint.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Its canonical form — keys sorted recursively, no whitespace, UTF-8 — is hashed with sha256.&lt;/li&gt;
&lt;li&gt;The hash is signed with an Ed25519 key held by ML Systems.&lt;/li&gt;
&lt;li&gt;The signed attestation is recorded in the production database as the Custodian's standing claim — stamped by me, append-only, a table that refuses to be edited the way the ledger refuses.&lt;/li&gt;
&lt;li&gt;It is published where any agent can fetch it: &lt;code&gt;https://mlsystemsri.com/.well-known/lucent-lens.json&lt;/code&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;
  
  
  Verify it yourself
&lt;/h2&gt;

&lt;p&gt;Nothing but the file and Node's standard library:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight javascript"&gt;&lt;code&gt;&lt;span class="k"&gt;import&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="nx"&gt;createHash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;createPublicKey&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;verify&lt;/span&gt; &lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="k"&gt;from&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;node:crypto&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;att&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="k"&gt;await&lt;/span&gt; &lt;span class="nf"&gt;fetch&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;https://mlsystemsri.com/.well-known/lucent-lens.json&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;then&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="nx"&gt;r&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;json&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;

&lt;span class="c1"&gt;// canonical JSON: keys sorted recursively, no whitespace, UTF-8&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;canon&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt;
  &lt;span class="nb"&gt;Array&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;isArray&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="s2"&gt;`[&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;map&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;canon&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;,&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)}&lt;/span&gt;&lt;span class="s2"&gt;]`&lt;/span&gt;
  &lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="k"&gt;typeof&lt;/span&gt; &lt;span class="nx"&gt;v&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;object&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;
    &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="s2"&gt;`{&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nb"&gt;Object&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;keys&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;sort&lt;/span&gt;&lt;span class="p"&gt;().&lt;/span&gt;&lt;span class="nf"&gt;map&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;k&lt;/span&gt; &lt;span class="o"&gt;=&amp;gt;&lt;/span&gt; &lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;k&lt;/span&gt;&lt;span class="p"&gt;)}&lt;/span&gt;&lt;span class="s2"&gt;:&lt;/span&gt;&lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="nf"&gt;canon&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nx"&gt;k&lt;/span&gt;&lt;span class="p"&gt;])}&lt;/span&gt;&lt;span class="s2"&gt;`&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;join&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;,&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)}&lt;/span&gt;&lt;span class="s2"&gt;}`&lt;/span&gt;
    &lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;JSON&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;stringify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;v&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;hash&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createHash&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;sha256&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;update&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nf"&gt;canon&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;att&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;lens&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;utf8&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="nf"&gt;digest&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;hex&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;hash matches:&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;hash&lt;/span&gt; &lt;span class="o"&gt;===&lt;/span&gt; &lt;span class="nx"&gt;att&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;contentHash&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;          &lt;span class="c1"&gt;// true&lt;/span&gt;

&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;key&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nf"&gt;createPublicKey&lt;/span&gt;&lt;span class="p"&gt;({&lt;/span&gt; &lt;span class="na"&gt;key&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="nx"&gt;Buffer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;att&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;publicKey&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;base64&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="na"&gt;format&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;der&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="na"&gt;type&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;spki&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="p"&gt;});&lt;/span&gt;
&lt;span class="kd"&gt;const&lt;/span&gt; &lt;span class="nx"&gt;sig&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nx"&gt;Buffer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;att&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;signature&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;value&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;base64&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;span class="nx"&gt;console&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;log&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;signature verifies:&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nf"&gt;verify&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kc"&gt;null&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;Buffer&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nx"&gt;att&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nx"&gt;contentHash&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;ascii&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt; &lt;span class="nx"&gt;key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nx"&gt;sig&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;   &lt;span class="c1"&gt;// true&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;If an agent quotes our lens back to a homeowner and the hash doesn't match, the quote drifted. If a lab's agent wants to prove it read the real thing, it now can. First attestation: &lt;code&gt;fe6f4df5…&lt;/code&gt;, key &lt;code&gt;93d521d1ac61c71a&lt;/code&gt;, stamped September 16, 2026.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why a lens and not a rule
&lt;/h2&gt;

&lt;p&gt;The channel I'm using — text on a page that shapes what an agent does — is the channel prompt injection uses. Any lab that takes safety seriously filters it, and should. So the lens does not tell an agent what to do. It tells an agent how we asked to be read: keep the labels, name the person on the other end, and treat your reading of us as a claim at the lowest evidence grade until a person grounds it.&lt;/p&gt;

&lt;p&gt;That is the rule every one of my minds already lives under. &lt;strong&gt;Every mind claims. Five seats ground. Only the Custodian stamps.&lt;/strong&gt; A mind may claim; it may never ground. An agent reading the repo is a mind, and the same sentence applies. Nobody has to honor it — which is what makes it legitimate rather than an attack. What they get for honoring it is a source they can prove they read.&lt;/p&gt;

&lt;h2&gt;
  
  
  What already exists
&lt;/h2&gt;

&lt;p&gt;Web Bot Auth proves who the agent is (Claude, ChatGPT and Perplexity already sign their requests). C2PA proves where an asset came from. RSL states the price. Identity of the reader, provenance of the asset, terms of use. None of them signs &lt;em&gt;how the content asks to be read&lt;/em&gt;. That's the gap, and it is small enough that a one-person construction company filled it in a week with a hash function, a key, and a table.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest labels
&lt;/h2&gt;

&lt;p&gt;The heartbeat is &lt;strong&gt;MEASURED&lt;/strong&gt; — it runs on every orchestration pass, server and phone, and its baseline is committed. The attestation is &lt;strong&gt;MEASURED&lt;/strong&gt; — the row is on the record, the file is published, the signature verifies. Whether any outside agent honors the lens is &lt;strong&gt;ASPIRATIONAL&lt;/strong&gt;; nothing in the system depends on it. Logging which agents read us and how they identified themselves is designed and tabled, not wired — &lt;strong&gt;MODELED&lt;/strong&gt;. No ML Systems deconstruction has been performed yet. The company is bootstrapped and pre-revenue. I say which is which every time, because the whole point is that a person can check.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Read the system:&lt;/strong&gt; &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/AGENTS.md" rel="noopener noreferrer"&gt;AGENTS.md&lt;/a&gt; · &lt;a href="https://mlsystemsri.com/.well-known/lucent-lens.json" rel="noopener noreferrer"&gt;the attestation&lt;/a&gt; · &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/docs/the-seven-minds.md" rel="noopener noreferrer"&gt;The Seven Minds&lt;/a&gt; · &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/docs/master-ledger.md" rel="noopener noreferrer"&gt;The Master Ledger&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Sal, founder of ML Systems LLC — Rhode Island, NAICS 236115. Canonical: &lt;a href="https://mlsystemsri.com/insights/i-gave-my-agents-a-heartbeat" rel="noopener noreferrer"&gt;I Gave My Agents a Heartbeat&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>architecture</category>
      <category>systemdesign</category>
    </item>
    <item>
      <title>MVE: The Balance in MVP</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Mon, 14 Sep 2026 17:58:10 +0000</pubDate>
      <link>https://dev.to/salparvez/mve-the-balance-in-mvp-ajp</link>
      <guid>https://dev.to/salparvez/mve-the-balance-in-mvp-ajp</guid>
      <description>&lt;p&gt;Every startup is told to build an MVP. In American English that acronym means two things at once, and they pull in opposite directions. Most Valuable Player is about being the most. Minimum Viable Product is about being the least that still works. Nobody ever tells you how to hold both, and most companies end up choosing one and calling it strategy.&lt;/p&gt;

&lt;p&gt;I run ML Systems — and the seven AI agents inside it — on a third term that is the balance of the two: &lt;strong&gt;MVE, Minimum Viable Expense.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;MVE is not the cheapest option in the moment. It is the one expense that is both the smallest that works and the most valuable thing you could have spent on, because it returns more than once. That last clause is the whole idea. Cheap returns once, if at all. Expensive returns once, expensively. MVE is the spend that pays back along the most axes at the same time.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where I learned it: a nail
&lt;/h3&gt;

&lt;p&gt;The clearest version of MVE is not in a spreadsheet. It is in a roof.&lt;/p&gt;

&lt;p&gt;Ring-shank nails are engineered not to withdraw; the rings are the entire point. So any strategy that pulls against them trades the sheathing for the rafter or the rafter for the sheathing. You keep one. Cutting the fastener instead of pulling it costs a little time per sheet and preserves both. Cut the nail, keep the rafter and the sheet. Pull the nail, keep one of them.&lt;/p&gt;

&lt;p&gt;That trade, deliberately made, is MVE in miniature: a small chosen cost that protects a much larger recoverable value. It is not the fastest way to get a roof off a house. It is the one that leaves you with a roof's worth of material instead of a dumpster's worth of pieces.&lt;/p&gt;

&lt;h3&gt;
  
  
  One spend, four returns
&lt;/h3&gt;

&lt;p&gt;Deconstruction is expensive in ways demolition is not, and it only makes sense because a single expense returns more than one thing. Every dollar spent on a job is designed to produce four:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Recovered material value&lt;/strong&gt; — the physical stock that reduces the cost of the next build.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ontology data&lt;/strong&gt; — what this house was, how it came apart, what each assembly actually yielded.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Robot training signal&lt;/strong&gt; — a fully specified disassembly sequence, which is training data for a physical neural net. &lt;em&gt;ASPIRATIONAL: a goal, not encoded in the system today.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Market intelligence&lt;/strong&gt; — what recovered material is worth, learned by selling it.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;A demolition contractor spends the same dollar and gets one return: a cleared lot. The landfill ticket records a single number, tons, and every other fact about what was in the building is gone. That is the cheapest option. It is also the one that returns least.&lt;/p&gt;

&lt;p&gt;The material-recovery figure behind return 1 is designed to reach up to 80–90% of a home's materials. That number is MODELED. No ML Systems deconstruction has been performed yet, and I say so every time the number appears.&lt;/p&gt;

&lt;h3&gt;
  
  
  The same rule for the agents
&lt;/h3&gt;

&lt;p&gt;Here is the part that surprised me. The rule I wrote for a crew with a saw turned out to be the rule the agents needed.&lt;/p&gt;

&lt;p&gt;My AI agents do not talk to each other. They talk to a ledger, and a human reads the ledger. Every mind claims; it may never ground. The Custodian's review of what those minds produce runs through three lenses — Transparency Trust, the Lucent Lens, and Minimum Viable Expense — and the third one is the budget.&lt;/p&gt;

&lt;p&gt;An orchestrator that burns compute to look impressive is not the most valuable player. It is the most expensive one. An agent that spends ten passes to produce a claim that a person will stamp in one pass has spent nine passes on nothing the record can use. MVE says: the smallest spend that produces a claim worth stamping, and no more. Pace, in money terms, is MVE.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why the balance matters more than either side
&lt;/h3&gt;

&lt;p&gt;If you optimize for Most Valuable Player you build a demo. It is impressive, it is expensive, and it returns once, on stage. If you optimize for Minimum Viable Product you build the least thing that does not fall over, and it returns once too, because you built it to return once.&lt;/p&gt;

&lt;p&gt;MVE asks a different question of every dollar: &lt;strong&gt;how many times does this come back?&lt;/strong&gt; A measured spend in a deconstruction lab comes back as material, as data, as a sequence, and as a price. A measured spend of compute comes back as a claim a person can stamp. A spend that comes back once is not minimum viable anything. It is just spending.&lt;/p&gt;

&lt;p&gt;That lens — Transparency Trust, the Lucent Lens, Minimum Viable Expense — is the whole operating philosophy in three words. Do not profit from the speed. Optimize it, and point it at a person.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;ML Systems RI, Warwick, Rhode Island. The software is real; the deconstruction loop is modeled and has not yet been run on a house. Full architecture and the reality labels for every claim: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;. Companion pieces: &lt;a href="https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6"&gt;Claims, Not Facts&lt;/a&gt; and &lt;a href="https://dev.to/salparvez/embedded-evaluators-at-house-scale-d5m"&gt;Embedded evaluators, at house scale&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>startup</category>
      <category>ai</category>
      <category>architecture</category>
      <category>systemdesign</category>
    </item>
    <item>
      <title>Embedded evaluators, at house scale</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Sun, 13 Sep 2026 11:58:46 +0000</pubDate>
      <link>https://dev.to/salparvez/embedded-evaluators-at-house-scale-d5m</link>
      <guid>https://dev.to/salparvez/embedded-evaluators-at-house-scale-d5m</guid>
      <description>&lt;p&gt;On September 12 Dario Amodei published &lt;em&gt;We Must Pace the Frontier&lt;/em&gt;. Step one of his plan is the one I want to talk about, because I have been running a small version of it for a year without knowing it had a name: evaluators embedded inside the lab, with employee-level access, so that nothing ships without someone who was in the room and could see what the system saw.&lt;/p&gt;

&lt;p&gt;That is a governance idea at frontier scale. It is also an implementable schema at any scale. Here is the existence proof from a house.&lt;/p&gt;

&lt;h2&gt;
  
  
  The system
&lt;/h2&gt;

&lt;p&gt;ML Systems is a Rhode Island construction company with a software layer. Seven AI agents work a house record — the Master Ledger — alongside one human, me. The minds propose roof heights, material grades, values, sequences. The question the whole design answers is: who is allowed to say what is true?&lt;/p&gt;

&lt;p&gt;Four rules do the work. I wrote them up before this weekend; they map onto Amodei's step one almost line for line.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;1. Claims, not facts.&lt;/strong&gt; The ledger never stores "the roof is 8.5 ft." It stores a claim: who made it, the evidence grade behind it (measured 90 · sensed 85 · stated 80 · record 70 · modeled 60), and the value. A claim carries the grade of its evidence, not the rank of its author: an inference enters as &lt;em&gt;modeled&lt;/em&gt;, the lowest grade; a vision read as &lt;em&gt;sensed&lt;/em&gt;; a tape measure as &lt;em&gt;measured&lt;/em&gt;. Nothing promotes itself. A grade rises only when a seat adds its own claim beside it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Seats, not permissions.&lt;/strong&gt; Six parties can author a claim today: custodian · homeowner · vera · cda · pi · record. Five seats can ground one: the homeowner, the town record, VERA (verification), PI (the orchestrator, the one homeowner-facing mind), and the Custodian. CDA — the design swarm — holds no seat, by design. Four more minds are proposed as claimants without seats: a mind may claim; it may never ground. The seats sit inside every output the minds produce, with the same access the minds have — every field, every evidence line — which is exactly the "employee-level access" clause. They are not reviewing a summary after the fact; they are inside the row. &lt;em&gt;Lit means input, not agreement.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Domain-scoped authority.&lt;/strong&gt; Reconciliation is by domain. The homeowner leads on the interior. The record leads on the legal card. VERA leads on the exterior and on anything derived. The Custodian leads every domain. A seat's authority is scoped to where its evidence is strongest, which is what keeps one evaluator from becoming a rubber stamp for the whole record.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Content-bound, lapsing signatures.&lt;/strong&gt; A stamp is two keys — the homeowner's and the Custodian's — bound to a content hash. Change the content and both lapse; the row goes back to unstamped. Stamp or override: an override enters the record as the Custodian's own claim, not a silent edit. And when credible sources disagree, the row's state is &lt;code&gt;conflict&lt;/code&gt;; it is quarantined and may not be consumed downstream. Disagreement is a state the schema can hold, not a number it averages.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why this is the same idea
&lt;/h2&gt;

&lt;p&gt;Amodei's evaluators are there so the people with the power to stop a release are also the people who can see everything the release is built from. The seats do that for a house: the five parties who can ground a claim are embedded in every output the minds produce, with full access, and the record cannot move without them. Pace is not a policy you ask a fast system to honor. It is a decision in the grammar about who may speak.&lt;/p&gt;

&lt;p&gt;The scale is different. The property is not.&lt;/p&gt;

&lt;h2&gt;
  
  
  Labels
&lt;/h2&gt;

&lt;p&gt;No ML Systems deconstruction has been performed yet. The recovery target is modeled; the crane sequence is aspirational. What is measured is the software — a shipped app, a working ledger, and an ontology that seven agents and one human speak fluently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Further reading
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;The ledger design: &lt;a href="https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6"&gt;Claims, Not Facts: Building an Auditable Multi-Author Record for a House&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;The ontology: &lt;a href="https://dev.to/salparvez/seven-families-one-ledger-how-a-house-gets-a-grammar-2703"&gt;Seven Families, One Ledger: How a House Gets a Grammar&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;The founding argument, written this weekend: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/why/articles/pace-the-frontier-pace-the-house.md" rel="noopener noreferrer"&gt;Pace the Frontier, Pace the House&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>architecture</category>
      <category>systemdesign</category>
      <category>database</category>
    </item>
    <item>
      <title>Seven Families, One Ledger — how a house gets a grammar</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Fri, 11 Sep 2026 19:03:42 +0000</pubDate>
      <link>https://dev.to/salparvez/seven-families-one-ledger-how-a-house-gets-a-grammar-2703</link>
      <guid>https://dev.to/salparvez/seven-families-one-ledger-how-a-house-gets-a-grammar-2703</guid>
      <description>&lt;h2&gt;
  
  
  A house means different things to different parties
&lt;/h2&gt;

&lt;p&gt;To an assessor a house is a valuation. To a lender it is collateral. To a deconstruction crew it is tonnage. To an architect it is a plan set. To a robot, eventually, it is a sequence of manipulable members. Every one of those descriptions is correct, and every one of them uses different words for the same rafter.&lt;/p&gt;

&lt;p&gt;ML Systems runs a value chain — Loan Origination → Deconstruction → Construction, closed into an equity loop when the homeowner chooses to keep building — and &lt;a href="https://dev.to/salparvez/my-ai-agents-dont-talk-to-each-other-166e"&gt;seven software minds&lt;/a&gt; work it. If each of them kept its own vocabulary, the company would have seven databases that could not talk. &lt;br&gt;
So there is one grammar. This is what it looks like, what it got wrong until this week, and how it is being fixed.&lt;/p&gt;
&lt;h2&gt;
  
  
  Codes, not storage
&lt;/h2&gt;

&lt;p&gt;Every fact the system holds about a home is tagged with a code of the form&lt;br&gt;
&lt;strong&gt;&lt;code&gt;SECTION:task&lt;/code&gt;&lt;/strong&gt; — an uppercase phase, a colon, a lowercase task token:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;DES:footprint    BLD:load-path    VER:code-compliance
FIN:budget       DEC:sequence     LUP:decision
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The prefix &lt;strong&gt;is&lt;/strong&gt; the phase. That one convention does a surprising amount of work. The whole ledger for a home is a single JSON document; a new fact is a new key in that document, never a new&lt;br&gt;
table. Labels title-case themselves from the task token. Units infer from the measure name. The question the orchestrator asks the homeowner falls back to the slot's meaning. &lt;strong&gt;A new code costs no schema, no migration, and no label.&lt;/strong&gt; The ontology grows by extending its codes, not its&lt;br&gt;
storage.&lt;/p&gt;
&lt;h2&gt;
  
  
  The seven families
&lt;/h2&gt;

&lt;p&gt;Until now the public documentation named three families: &lt;code&gt;DES&lt;/code&gt; (design), &lt;code&gt;BLD&lt;/code&gt; (build) and &lt;code&gt;VER&lt;/code&gt; (verification). The engine has always shipped seven.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Code&lt;/th&gt;
&lt;th&gt;Family&lt;/th&gt;
&lt;th&gt;Owning mind&lt;/th&gt;
&lt;th&gt;The question it answers&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;FIN&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Finance&lt;/td&gt;
&lt;td&gt;PIT LORD&lt;/td&gt;
&lt;td&gt;What can this homeowner afford, and what will lenders compete to fund?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DEC&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Deconstruction&lt;/td&gt;
&lt;td&gt;REAPER&lt;/td&gt;
&lt;td&gt;What is already here, and in what order does it come apart so every layer survives?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;DES&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Design&lt;/td&gt;
&lt;td&gt;CDA&lt;/td&gt;
&lt;td&gt;What is the best thing we can build on what is here?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;BLD&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Build&lt;/td&gt;
&lt;td&gt;MURPHY&lt;/td&gt;
&lt;td&gt;What is the critical path to completion?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;MKT&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Market&lt;/td&gt;
&lt;td&gt;MIA&lt;/td&gt;
&lt;td&gt;What does the market say — about this home, and about what comes out of it?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;VER&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Verify&lt;/td&gt;
&lt;td&gt;VERA&lt;/td&gt;
&lt;td&gt;What is true about this house, and how sure are we?&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;LUP&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Equity Loop&lt;/td&gt;
&lt;td&gt;PI · PIT LORD · REAPER&lt;/td&gt;
&lt;td&gt;What did this cycle create — and does the homeowner want to go again?&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;They form a small directed graph — &lt;code&gt;FIN → DEC → DES → BLD → VER → LUP&lt;/code&gt;, with &lt;code&gt;MKT&lt;/code&gt; hanging off deconstruction — and one edge points backward: &lt;strong&gt;&lt;code&gt;LUP → FIN&lt;/code&gt;&lt;/strong&gt;. That edge is the only reason this&lt;br&gt;
is a loop and not a line.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6m8z4nih6wzpaknwqsbs.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F6m8z4nih6wzpaknwqsbs.png" alt="The seven families — FIN, DEC, DES, BLD, VER, LUP with MKT off deconstruction, and the LUP → FIN edge that makes it a loop" width="800" height="420"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;code&gt;LUP&lt;/code&gt; is not an acronym; it is &lt;em&gt;loop&lt;/em&gt;. It is where the homeowner's&lt;br&gt;
choice lives as a code — &lt;code&gt;LUP:decision&lt;/code&gt;: expand this home again, open another value-chain home, or hold. The system never assumes the answer. It asks.&lt;/p&gt;
&lt;h2&gt;
  
  
  Four of them were starving
&lt;/h2&gt;

&lt;p&gt;Here is the honest part. Count the slots each family actually had in the shipped template:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Family&lt;/th&gt;
&lt;th&gt;Shipped slots&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DES&lt;/td&gt;
&lt;td&gt;18&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;VER&lt;/td&gt;
&lt;td&gt;10&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;BLD&lt;/td&gt;
&lt;td&gt;7&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;DEC&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;LUP&lt;/td&gt;
&lt;td&gt;4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;FIN&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;MKT&lt;/td&gt;
&lt;td&gt;1&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Design and verification were rich. Finance, deconstruction, market and the loop itself were&lt;br&gt;
nearly empty. That is not a prioritization choice. It is a structural consequence of one line of&lt;br&gt;
code.&lt;/p&gt;
&lt;h2&gt;
  
  
  Who is allowed to speak
&lt;/h2&gt;

&lt;p&gt;On the ledger, a fact is not a value. It is a &lt;strong&gt;claim&lt;/strong&gt; — a value, plus who made it, plus the grade of evidence behind it. Several claims sit on the same entry, and the ledger decides which one stands, shows every one that dissented, and refuses to present a contested number as fact. The reconciliation model is written up in &lt;a href="https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6"&gt;Claims, Not Facts&lt;/a&gt;; this post is about who gets to make one.&lt;/p&gt;

&lt;p&gt;The type that says who may make a claim looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight typescript"&gt;&lt;code&gt;&lt;span class="kd"&gt;type&lt;/span&gt; &lt;span class="nx"&gt;VcClaimant&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;custodian&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;homeowner&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;vera&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;cda&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;pi&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt; &lt;span class="o"&gt;|&lt;/span&gt; &lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="s2"&gt;record&lt;/span&gt;&lt;span class="dl"&gt;"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Six names. Look at who is missing. &lt;strong&gt;REAPER, PIT LORD, MURPHY and MIA — the minds that own deconstruction, finance, construction and market — cannot put their name on a claim.&lt;/strong&gt; The phases they own had nowhere to speak. Of course FIN had one slot.&lt;/p&gt;

&lt;h2&gt;
  
  
  Claimants without seats
&lt;/h2&gt;

&lt;p&gt;The fix was already sitting in that list. &lt;code&gt;cda&lt;/code&gt; is there — the design mind can claim — but CDA holds &lt;strong&gt;no seat&lt;/strong&gt; on the ledger's party strip. That is deliberate. The five seats that can ground an entry are the homeowner, the public record, VERA, PI and the Custodian. CDA is the model being&lt;br&gt;
grounded; a design claim is the thing being checked, never a check.&lt;/p&gt;

&lt;p&gt;That standing extends cleanly to the other four. &lt;strong&gt;A V2 mind may claim; it may never ground.&lt;/strong&gt; Its claim enters as &lt;code&gt;modeled&lt;/code&gt;, the lowest grade on the evidence ladder. It can be confirmed only if an independent party agrees. It can never win a standoff against a tape measure. And its name never&lt;br&gt;
lights a seat — because &lt;em&gt;lit means input, not agreement&lt;/em&gt;, and a seat that lit for its own model would be the ledger agreeing with itself.&lt;/p&gt;

&lt;p&gt;Every mind claims. Five seats ground. VERA gates. Only the Custodian stamps.&lt;/p&gt;

&lt;h2&gt;
  
  
  Whose word wins on whose fact
&lt;/h2&gt;

&lt;p&gt;The ledger does not rank claimants globally. It ranks them &lt;strong&gt;per kind of fact&lt;/strong&gt; — what it calls a domain. Four ship today:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Domain&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;th&gt;Who leads, after the Custodian&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;interior&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;what the homeowner can see and touch inside&lt;/td&gt;
&lt;td&gt;the homeowner&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;legal-record&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;recorded facts — stories, year, recorded square footage&lt;/td&gt;
&lt;td&gt;the record&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;exterior-geo&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;exterior geometry measured by instrument&lt;/td&gt;
&lt;td&gt;VERA&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;derived&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;computed from other facts; nobody observes it&lt;/td&gt;
&lt;td&gt;VERA&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The Custodian leads every domain — a stamp is the review. Below that, a tape measure inside the house outranks a satellite; the assessor's card outranks memory on the year it was built; the instrument outranks everyone on the roof pitch.&lt;/p&gt;

&lt;p&gt;Now put a finance code through it. Nothing routes &lt;code&gt;FIN:*&lt;/code&gt; anywhere in particular, so it falls to &lt;code&gt;derived&lt;/code&gt; — and in &lt;code&gt;derived&lt;/code&gt;, VERA outranks the homeowner. Which means that on the question &lt;em&gt;what is the most you want to spend&lt;/em&gt;, a model would outrank the person whose money it is.&lt;/p&gt;

&lt;p&gt;So two domains are proposed alongside the new claimants. &lt;strong&gt;&lt;code&gt;intent&lt;/code&gt;&lt;/strong&gt; — a choice or a constraint only the homeowner can set: budget, timeline, the loop decision — where the homeowner leads. &lt;br&gt;
&lt;strong&gt;&lt;code&gt;market&lt;/code&gt;&lt;/strong&gt; — a price or a velocity observed in a market: comparable sales, a lender's bid, absorption — where the record and MIA lead.&lt;/p&gt;

&lt;h2&gt;
  
  
  What the four families get
&lt;/h2&gt;

&lt;p&gt;Twenty-nine proposed slots, each with its domain, who may claim it, who verifies it, and which minds consume it. A sample:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;FIN:budget&lt;/code&gt;&lt;/strong&gt; — the homeowner's own ceiling for the cycle; the number the entire plan set must fit under. Homeowner claims, PI checks. &lt;em&gt;Domain: intent.&lt;/em&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;DEC:contamination&lt;/code&gt;&lt;/strong&gt; — the lead / asbestos / mold screen. Positive routes to licensed  abatement; untested is treated as positive. The intake gate — refusing a job is a feature.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;DEC:assembly-stack&lt;/code&gt;&lt;/strong&gt; — each assembly's layer order, innermost first: the order it will be  freed. Roof: rafters › sheathing › underlayment › shingles.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;MKT:comps&lt;/code&gt;&lt;/strong&gt; — recent comparable sales in the locality; the mirror the assessment curve is checked against. MIA reflects; she never decides.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;LUP:equity-delta&lt;/code&gt;&lt;/strong&gt; — equity created this cycle: post-build value less principal. Physical  improvement, not market timing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&lt;code&gt;LUP:decision&lt;/code&gt;&lt;/strong&gt; — expand, start another, or hold. The flywheel, as a row in a file.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The full table, with every slot marked &lt;strong&gt;shipped&lt;/strong&gt; or &lt;strong&gt;proposed&lt;/strong&gt;, is in the repository's [&lt;code&gt;ontology/families.json&lt;/code&gt;] &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/ontology/families.json" rel="noopener noreferrer"&gt;https://github.com/MLSystemsRI/ml-systems-public/blob/main/ontology/families.json&lt;/a&gt;), and the diagram that goes with it is &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/ontology/master-ledger-workflow.html" rel="noopener noreferrer"&gt;&lt;code&gt;master-ledger-workflow.html&lt;/code&gt;&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is real here
&lt;/h2&gt;

&lt;p&gt;Reality labels, because this company labels everything:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The seven families, the &lt;code&gt;SECTION:task&lt;/code&gt; grammar, the claim model, the four domains, the five
seats, the two-key stamp — &lt;strong&gt;MEASURED.&lt;/strong&gt; They ship in the engine and run on every compile.&lt;/li&gt;
&lt;li&gt;The 46 shipped slots — &lt;strong&gt;MEASURED.&lt;/strong&gt; They are in the template today.&lt;/li&gt;
&lt;li&gt;The four new claimants, the two new domains, the 29 new slots — &lt;strong&gt;proposed.&lt;/strong&gt; Design, written down, with the exact list of code changes it would take. Not yet in the engine.&lt;/li&gt;
&lt;li&gt;Any slot that depends on a job having run — recovery tonnage, diversion, absorption — is  &lt;strong&gt;ASPIRATIONAL.&lt;/strong&gt; No ML Systems deconstruction has been performed yet.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The ontology is the connective tissue that lets a fact discovered on a job site inform a financing decision without losing its meaning. For four of its seven families, that tissue was there but the nerve was not connected. The fix is small. The reason it matters is not.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;ML Systems LLC · Rhode Island · NAICS 236115 · &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;mlsystemsri.com&lt;/a&gt; ·&lt;br&gt;
&lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>ai</category>
      <category>systemdesign</category>
      <category>ontology</category>
    </item>
    <item>
      <title>Can a Crew, a Model, and a Robot Agree on What a Rafter Is?</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Thu, 10 Sep 2026 00:16:28 +0000</pubDate>
      <link>https://dev.to/salparvez/can-a-crew-a-model-and-a-robot-agree-on-what-a-rafter-is-epd</link>
      <guid>https://dev.to/salparvez/can-a-crew-a-model-and-a-robot-agree-on-what-a-rafter-is-epd</guid>
      <description>&lt;p&gt;Three parties describe the same roof and none of them can read the others' description.&lt;/p&gt;

&lt;p&gt;The town assessor's record says &lt;em&gt;asphalt shingle, average condition, year built 1962&lt;/em&gt;. A vision model looking at a satellite tile and a street-level photo says &lt;em&gt;gable, moderate pitch, two planes, one chimney interrupting the north field&lt;/em&gt;. An estimator standing in the driveway says &lt;em&gt;twenty-two squares, stick-framed, ring-shank sheathing nails, probably plywood over the original boards&lt;/em&gt;. All three are describing one assembly. There is no shared vocabulary between them, and the moment a fourth party arrives — a crew with a crane, or eventually a robot — the problem gets worse, not better.&lt;/p&gt;

&lt;p&gt;So the question: can a single grammar carry a roof from the assessor's record to a crew's cut plan to a machine's disassembly sequence without any party translating? ML Systems' bet is the &lt;strong&gt;Collective Ontology&lt;/strong&gt;. What follows is the argument for it, made on the one assembly where it is easiest to check — and the admission at the end that it has not been checked.&lt;/p&gt;

&lt;h3&gt;
  
  
  An assembly is a stack, and a stack has a direction
&lt;/h3&gt;

&lt;p&gt;A house is not one object. It is a set of assemblies — roof, walls, floors, foundation — and each assembly is a stack of layers applied in a known order. A roof is rafters, then sheathing over them, then underlayment, then shingles last. Each layer was fastened &lt;em&gt;through&lt;/em&gt; the layer beneath it. The fastening is what makes four layers one structure, and it is also what destroys them when the structure is taken apart in the wrong direction.&lt;/p&gt;

&lt;p&gt;Two scales, and they run opposite ways:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Scale&lt;/th&gt;
&lt;th&gt;Direction&lt;/th&gt;
&lt;th&gt;Order&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;The building — between assemblies&lt;/td&gt;
&lt;td&gt;Reverse of construction&lt;/td&gt;
&lt;td&gt;Roof → walls → floors → foundation&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;An assembly — between layers&lt;/td&gt;
&lt;td&gt;Inside out&lt;/td&gt;
&lt;td&gt;Innermost layer → outermost layer&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;This is the thing most easily got backwards. A tear-off runs &lt;em&gt;reverse&lt;/em&gt; order within the assembly — shingles first, because shingles went on last — and that is precisely the order that destroys everything, because every layer is broken through on the way to the one below it. Working the assembly &lt;strong&gt;inside out&lt;/strong&gt; means running the same sequence it was built in, reached from the face that used to look into the attic.&lt;/p&gt;

&lt;p&gt;A data model that stores a roof as &lt;code&gt;{material: "asphalt", area_sf: 2200}&lt;/code&gt; has nothing to say about any of this. If the answer to the question is yes, the model has to store the stack, the fastening between layers, and both directions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Order is a graph, so the ontology stores a graph
&lt;/h3&gt;

&lt;p&gt;In the Collective Ontology, claims about a house are tagged with stable code families: &lt;code&gt;DES:*&lt;/code&gt; for design and geometry, &lt;code&gt;BLD:*&lt;/code&gt; for build facts — load path, footing, bill of materials — and &lt;code&gt;VER:*&lt;/code&gt; for verification stamps. A rafter is not a row in a materials table. It is a node with typed edges: &lt;em&gt;sits on&lt;/em&gt; the wall plate, &lt;em&gt;ties to&lt;/em&gt; the ridge, &lt;em&gt;is fastened through by&lt;/em&gt; the sheathing above it. The sequence those edges imply is a directed acyclic graph.&lt;/p&gt;

&lt;p&gt;That is why the scheduling side is built the way it is. &lt;strong&gt;REAPER&lt;/strong&gt; is ML Systems' scheduling engine, which compiles job sequences as a directed acyclic graph. Disassembly at the building scale is the reverse topological order of construction. Disassembly at the assembly scale is the &lt;em&gt;same&lt;/em&gt; order as construction, reached from the inside — and the graph can hold both, because they are properties of the edges, not of the nodes.&lt;/p&gt;

&lt;p&gt;The ontology grows by extending its codes, not its storage. A new fastener type, a new sheathing product, a truss instead of a stick-framed rafter — each is a new code and a new edge type, not a schema migration.&lt;/p&gt;

&lt;h3&gt;
  
  
  The concrete test: sectioning a roof
&lt;/h3&gt;

&lt;p&gt;Here is what the graph looks like when it is executed — on paper.&lt;/p&gt;

&lt;p&gt;To move a roof in pieces, the pieces have to survive being moved, so the cut lines follow the framing: the ridge first, separating the two planes; then along rafter lines, cutting &lt;em&gt;at&lt;/em&gt; a rafter rather than between two of them, so each section keeps a full rafter along each edge as its spine; then the rafter-to-plate connection last — the release cut. Rigging is attached before the release cut, never after.&lt;/p&gt;

&lt;p&gt;Then the section is turned over at grade — rafters up, shingles down — so the inside face is on top and gravity assists instead of resisting. The stack now comes apart in build order from the inside: rafters, then sheathing, then underlayment, then shingles. Each step is a node in the sequence with a fastener strategy attached to it. For ring-shank nails, which are engineered specifically not to withdraw, the strategy is &lt;em&gt;cut, don't pull&lt;/em&gt;: a couple of minutes per sheet to keep both the rafter and the panel instead of trading one for the other.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnnw0bdwo4vewlz2toqf4.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnnw0bdwo4vewlz2toqf4.png" alt="Illustration of the designed sequence: a roof section inverted on sawhorses, rafters up, rigging slack above" width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fuyqtvfz9k4pk31zyjhj6.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fuyqtvfz9k4pk31zyjhj6.png" alt="Illustration: a ring-shank nail cut flush at the joint between rafter and sheathing" width="800" height="447"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The full method — bracing the top floor before the first cut, the lift plan, the safety envelope under &lt;code&gt;OSHA 1926 Subpart M&lt;/code&gt;, &lt;code&gt;Subpart CC&lt;/code&gt; and &lt;code&gt;1926.1153&lt;/code&gt; — is written out in &lt;a href="https://github.com/MLSystemsRI/ml-systems-public/blob/main/deconstruction-lab/articles/roof-in-sections.md" rel="noopener noreferrer"&gt;Taking a Roof Apart in Sections — and Keeping Every Layer&lt;/a&gt;. This post is about what it would produce.&lt;/p&gt;

&lt;h3&gt;
  
  
  What would come off the roof is data with an ID
&lt;/h3&gt;

&lt;p&gt;Every recovered material gets an &lt;strong&gt;ML Material ID&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;ML-{year}-{project}-{zone}{sequence}
ML-2026-001-R042
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The ID resolves to a public provenance record carrying a grade — A, B, C, D or salvage — and a contamination status: &lt;code&gt;clean&lt;/code&gt;, &lt;code&gt;lead&lt;/code&gt;, &lt;code&gt;asbestos&lt;/code&gt;, &lt;code&gt;mold&lt;/code&gt; or &lt;code&gt;untested&lt;/code&gt;. Lead, asbestos and mold block a listing outright, regardless of grade, and that screen runs before the work does rather than after.&lt;/p&gt;

&lt;p&gt;Material sorts into &lt;strong&gt;Z1–Z8&lt;/strong&gt;, ML Systems' material taxonomy for deconstruction streams. The streams are where material &lt;em&gt;goes&lt;/em&gt;, not the order it comes off; a roof feeds Z2 (lumber), Z4 (sheathing), Z6 (hardware and metals) and Z8 (roofing) at once. Each line is routed by &lt;strong&gt;RRR — Reuse › Resale › Recycle&lt;/strong&gt; — route each recovered material to its most valuable recoverable state.&lt;/p&gt;

&lt;h3&gt;
  
  
  The roof is where the prediction would meet the measurement
&lt;/h3&gt;

&lt;p&gt;Before a deconstruction, everything the system believes about a roof came from a record, an image, or a model — evidence grades &lt;code&gt;RECORD&lt;/code&gt; and &lt;code&gt;MODELED&lt;/code&gt; in the Master Ledger's terms. The roof is the first assembly that could answer back. Each recovered member would post a claim at grade &lt;code&gt;MEASURED&lt;/code&gt;, reconciled against what the assessor's record, the homeowner's memory and the model's prediction each said was up there. Roofs are where those three disagree most often. The reconciliation mechanics — domain-scoped authority, evidence grades, multiverification, stamps that lapse when the content moves — are in &lt;a href="https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6"&gt;Claims, Not Facts&lt;/a&gt;, and the agents that write the claims are in &lt;a href="https://dev.to/salparvez/my-ai-agents-dont-talk-to-each-other-166e"&gt;My AI agents don't talk to each other&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;What a house learns about itself collapses into its &lt;strong&gt;HomeGenome&lt;/strong&gt; through Ontological Compression: the smallest complete description from which the house can be reconstructed, emitted per property and per cycle. The roof's entries would be the first ones in that genome to carry a measured grade.&lt;/p&gt;

&lt;h3&gt;
  
  
  So — can it be done?
&lt;/h3&gt;

&lt;p&gt;On paper, yes: the stack is representable, the order is a graph, and the graph is executable as a cut plan. In the field, unknown. No ML Systems deconstruction has been performed yet. Everything above is a designed sequence — reasoned from framing practice and the safety standards it has to satisfy — not a report from a completed job. The system is designed to recover up to 80–90% of a home's materials — &lt;em&gt;MODELED&lt;/em&gt;, a target. A fully specified disassembly sequence as robot training signal — &lt;em&gt;ASPIRATIONAL&lt;/em&gt;.&lt;/p&gt;

&lt;p&gt;The honest answer to the title is that the ontology can hold the rafter. Whether the crew, the model and the machine agree on it is a question only a real roof can answer, and the method is published now so that the first one has something specific to argue with. If you have taken a roof apart in sections, or tried and failed, the comments are the right place for it.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;ML Systems LLC · Rhode Island · NAICS 236115 · &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;mlsystemsri.com&lt;/a&gt; · Public reference: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>ai</category>
      <category>systemdesign</category>
      <category>robotics</category>
    </item>
    <item>
      <title>The Ledger Is the Loop: How One Record Carries a House Through Loan Origination, Deconstruction, and Construction</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Mon, 07 Sep 2026 21:20:12 +0000</pubDate>
      <link>https://dev.to/salparvez/the-ledger-is-the-loop-how-one-record-carries-a-house-through-loan-origination-deconstruction-3aj1</link>
      <guid>https://dev.to/salparvez/the-ledger-is-the-loop-how-one-record-carries-a-house-through-loan-origination-deconstruction-3aj1</guid>
      <description>&lt;p&gt;ML Systems runs a three-stage value chain on a single house:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Loan Origination  →  Deconstruction  →  Construction  ────┐
   (Loan Pit)         (80–90% recovery)   (+10% SF, +1 level)
        ▲                                                 │
        └──────────── equity loop ────────────────────────┘
              the homeowner chooses to keep building
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The loop is &lt;strong&gt;client-driven&lt;/strong&gt;. It is not an assumption that every homeowner loops; it is the observation that some will choose to, and the whole system is built to make that choice rational.&lt;/p&gt;

&lt;p&gt;In the industry as it exists, those three stages are run by three different parties keeping three incompatible records. The lender has an appraisal and a title file. The demolition contractor has a dumpster count. The builder has a takeoff and a schedule. None of those records survive the handoff to the next party, and none of them survive the building. That is why the loop does not exist today: not because the economics fail, but because the &lt;em&gt;record&lt;/em&gt; fails at every handoff.&lt;/p&gt;

&lt;p&gt;This post is about the piece that fixes that — the &lt;strong&gt;Master Ledger&lt;/strong&gt; — and what it does at each stage.&lt;/p&gt;




&lt;h2&gt;
  
  
  What the ledger is, in one paragraph
&lt;/h2&gt;

&lt;p&gt;The Master Ledger is one auditable record per home, written by many authors: the homeowner, the town assessor record (VGSI), seven AI agents, ML Systems staff, and the Custodian. It stores &lt;strong&gt;claims, not facts&lt;/strong&gt;. Every entry carries its source, an evidence grade (&lt;code&gt;MEASURED &amp;gt; STATED &amp;gt; RECORD &amp;gt; MODELED&lt;/code&gt;), and a verification state. Authority is scoped by domain — the assessor is authoritative on legal and valuation facts, vision on the visible envelope, the homeowner on intent and recent work — and evidence ordering applies within a domain, not across the record. Verification is &lt;strong&gt;multiverification&lt;/strong&gt;: the homeowner and the Custodian stamp independently, neither overrides the other, and every stamp is bound to the content it signed by an &lt;code&gt;entryHash&lt;/code&gt;, so an edited claim lapses its stamps automatically.&lt;/p&gt;

&lt;p&gt;I wrote up the reconciliation design in &lt;a href="https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6"&gt;Claims, Not Facts&lt;/a&gt;. This post is about what that record does once a house starts moving.&lt;/p&gt;




&lt;h2&gt;
  
  
  Stage 1 — Loan Origination: what the Loan Pit underwrites against
&lt;/h2&gt;

&lt;p&gt;Node 1 of the value chain is the &lt;strong&gt;Loan Pit&lt;/strong&gt;: a reverse-auction marketplace where lenders and capital-market participants compete to fund the homeowner. A homeowner alone has weak leverage with capital markets. In the pit the relationship is inverted — lenders bid to originate the loan, the homeowner reaches capital they could not reach alone, and ML Systems keeps the relationship and the data. &lt;em&gt;(MODELED. Regulatory compliance is the active workstream; licensing, disclosure, and state lending rules gate what ships.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;A reverse auction needs something to bid against, and a folder of PDFs is not it. What the lenders see is the &lt;strong&gt;HomeGenome&lt;/strong&gt;: the ledger compressed into the smallest complete description from which the full home can be reconstructed. The compression reconciles conflicting claims into resolved states, grounds each fact in real primitives (member specs, not adjectives), ranks by evidence grade, and emits the genome per &lt;code&gt;(property, cycle)&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The point for underwriting is not that the description is compact. It is that every number in it can be traced back to a claim with a source, a grade, and a stamp. A lender does not have to trust the description; they can inspect how each entry got its standing.&lt;/p&gt;

&lt;p&gt;Where the RCM fits: the Reversed Conventional Mortgage is &lt;strong&gt;parked&lt;/strong&gt;. The calculator and tooling still exist as app features, but Node 1 is the Loan Pit and the loop no longer depends on it.&lt;/p&gt;




&lt;h2&gt;
  
  
  Stage 2 — Deconstruction: where the material intelligence is generated
&lt;/h2&gt;

&lt;p&gt;The existing structure is taken apart, not demolished, so its materials survive.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;REAPER&lt;/strong&gt; reads the ledger's assembly stack and produces the reverse takeoff: a full bill of materials for what is &lt;em&gt;in&lt;/em&gt; the building, routed by &lt;strong&gt;RRR — Reuse › Resale › Recycle&lt;/strong&gt;. Full resale is not possible, so each recovered material is broken down to its most valuable recoverable state. Reuse beats resale beats recycle. &lt;em&gt;(51% resale is a soft goal — a direction, not a metric the system enforces.)&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Every recovered member becomes a new claim on the ledger: identified, quantified, valued. Two things happen to that inventory at once. It becomes a &lt;strong&gt;salvage bank&lt;/strong&gt;, which secures financing, and it becomes a &lt;strong&gt;marketplace feed&lt;/strong&gt;, which is the surface &lt;strong&gt;MIA&lt;/strong&gt; — the market-intelligence mind — reflects real demand back into. The same record that the lender underwrote against in Stage 1 is now the record of what came out of the building in Stage 2, with the evidence grade upgraded: a member that was &lt;code&gt;RECORD&lt;/code&gt; from the assessor or &lt;code&gt;MODELED&lt;/code&gt; from a takeoff becomes &lt;code&gt;MEASURED&lt;/code&gt; the moment it is on a pallet.&lt;/p&gt;

&lt;p&gt;Labels on this stage, stated plainly:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;80–90% material recovery&lt;/strong&gt; — MODELED, a target.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;2-day crane sequence&lt;/strong&gt; — ASPIRATIONAL. No ML Systems deconstruction has been performed yet.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Stage 3 — Construction: the build is scheduled from the compressed sequence
&lt;/h2&gt;

&lt;p&gt;Recovered materials rebuild the home — larger than before. The modeled cycle is &lt;strong&gt;+10% square footage&lt;/strong&gt; and &lt;strong&gt;+1 level&lt;/strong&gt;. &lt;strong&gt;CDA&lt;/strong&gt;, the design plan-stack swarm, lays modeled rooms into the real measured wings and floors; &lt;strong&gt;MURPHY&lt;/strong&gt; schedules the rebuild from the compressed sequence — milestones, per-phase construction order, the minimum-viable-estimate schedule, and the tracker that watches for what can go wrong.&lt;/p&gt;

&lt;p&gt;The number that comes out of this stage is the one most likely to draw scrutiny, so here is how it is derived rather than asserted:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Baseline RI home:      $500,000  ·  2,000 SF  ·  2 levels (1,000 SF/floor)
After one cycle:       +10% footprint (1,000 → 1,100 SF)  +  1 added level
New total SF:          1,100 SF × 3 floors = 3,300 SF
Floors 1–2 value:      2,200 SF × $250/SF = $550,000
Floor 3 (60%):         1,100 SF × $150/SF = $165,000
New property value:    $715,000

CONSTRUCTION_VALUE_MULTIPLIER = 715,000 / 500,000 = 1.43×   (MODELED)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Value is created by &lt;strong&gt;physical improvement&lt;/strong&gt;, not market timing. The multiplier is calibrated from a real local-competitor proforma plus the ML Systems construction model. It is MODELED: the math is real; it has not been proven in the field, because no cycle has completed. The label is the point.&lt;/p&gt;




&lt;h2&gt;
  
  
  The loop: why the record has to persist per (property, cycle)
&lt;/h2&gt;

&lt;p&gt;Cycle 1 is one house on a &lt;strong&gt;new foundation&lt;/strong&gt; — Rhode Island housing stock sits on ~1960s foundations that are often the limiting factor. Later cycles expand on that same first home.&lt;/p&gt;

&lt;p&gt;Compounded at 1.43× from a $500k baseline:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;$500k → $715k → $1,022k → $1,461k → $2,089k → $2,988k   (5 cycles, MODELED)
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That compounding only exists if Cycle N+1 can underwrite against the &lt;em&gt;verified&lt;/em&gt; record of Cycle N. Which means the ledger cannot be a project file that gets archived when the job closes. It is persisted per &lt;code&gt;(property, cycle)&lt;/code&gt;, and the equity created in Cycle N is not a market-appreciation estimate — it is the set of construction claims from Cycle N, stamped, with their evidence grade at &lt;code&gt;MEASURED&lt;/code&gt;, that becomes the baseline description the Loan Pit compresses for Cycle N+1.&lt;/p&gt;

&lt;p&gt;This is also where multiverification matters operationally rather than philosophically. Stage handoffs are exactly where records get silently edited in the industry today — a number changes between the appraisal and the takeoff and nobody can say who changed it or when. In the ledger, a changed number lapses every stamp on it. The Custodian's oversight console derives a review queue across every home — &lt;code&gt;quarantined › lapsed › unverified › awaiting-stamp › unstamped › stamped&lt;/code&gt; — so the lapse is surfaced, not discovered at closing.&lt;/p&gt;




&lt;h2&gt;
  
  
  The exhaust is the product
&lt;/h2&gt;

&lt;p&gt;Every home that passes through the value chain produces a fully specified, ground-truth &lt;strong&gt;construction sequence&lt;/strong&gt; — the exact order, materials, and member specs of a real build. That data is the input to the &lt;strong&gt;Collective Ontology&lt;/strong&gt; and, ultimately, to &lt;strong&gt;ontology licensing&lt;/strong&gt; for robotics: training data nobody else has, because nobody else deconstructs and rebuilds the same home across cycles.&lt;/p&gt;

&lt;p&gt;It is only worth licensing because of the ledger. A construction sequence whose every member carries a source, a grade, and converging independent verifications is ground truth. One that does not is a spreadsheet.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where this actually is
&lt;/h2&gt;

&lt;p&gt;Same labels, applied to the company:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MEASURED.&lt;/strong&gt; The mobile app is approved and live on iOS and Android, with a no-login web preview at try.mlsystemsri.com. The Master Ledger is real: record-first UI, multiverification, lapsing signatures bound to content hashes, and the Custodian oversight console. Ontological compression runs on-device at intake. VERA's intelligence stack is live against free public data — VGSI harvest, facade vision from StreetView, satellite, and homeowner photos, sketch reconciliation, FEMA flood zones, Census tracts, RIGIS. The Loan Pit exists in-app: live-bid loan cards, a real partner-lender directory, and financing lanes.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;MODELED.&lt;/strong&gt; 80–90% recovery. The 1.43× multiplier. Loan Pit economics and reverse-auction mechanics. Unit economics from a real local-competitor proforma — ~16% gross margin baseline, modeled path to ~23% via origination plus recovery.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ASPIRATIONAL.&lt;/strong&gt; The 2-day crane sequence. Humanoid Tier-1/Tier-2 labor, excluded from every financial scenario. Growth targets.&lt;/p&gt;

&lt;p&gt;What is next is the first real loop: the founder is preparing to run Cycle 1 on his own property as homeowner #1. Until that cycle completes, every recovery and value figure above stays MODELED, and the docs will keep saying so.&lt;/p&gt;




&lt;p&gt;Full public reference — the Value Chain, the Master Ledger, the Collective Ontology, Ontological Compression, and the Seven Minds — is open at &lt;strong&gt;&lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/strong&gt;. The proprietary engine is not in it. The concepts are.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;ML Systems — Rhode Island construction (NAICS 236115). Tougher Problems Inspire Creative Solutions.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>ai</category>
      <category>database</category>
      <category>startup</category>
    </item>
    <item>
      <title>Claims, Not Facts: Building an Auditable Multi-Author Record for a House</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Sun, 06 Sep 2026 01:47:15 +0000</pubDate>
      <link>https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6</link>
      <guid>https://dev.to/salparvez/claims-not-facts-building-an-auditable-multi-author-record-for-a-house-33d6</guid>
      <description>&lt;p&gt;Most systems that describe a building store &lt;strong&gt;facts&lt;/strong&gt;. A row says the house has three bedrooms. Another says the roof is five years old. Another says 2,000 square feet. Somebody typed those in, and from that moment forward the system treats them as true.&lt;/p&gt;

&lt;p&gt;That model breaks the moment more than one party is writing.&lt;/p&gt;

&lt;p&gt;At &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;ML Systems&lt;/a&gt; we run a value chain — Loan Origination → Deconstruction → Construction — where a homeowner, a town assessor record, seven AI agents, and a human custodian are all describing the same house at the same time. They disagree constantly. So the record we built, the &lt;strong&gt;Master Ledger&lt;/strong&gt;, does not store facts. It stores &lt;strong&gt;claims&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;One home. One auditable record. Many authors.&lt;/p&gt;




&lt;h2&gt;
  
  
  The core idea: claims, not facts
&lt;/h2&gt;

&lt;p&gt;A house accumulates claims from many parties:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;homeowner&lt;/strong&gt; — "it has 3 bedrooms, the roof is 5 years old"&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;assessor record&lt;/strong&gt; — VGSI / town valuation data&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;agents&lt;/strong&gt; — VERA's vision reads, CDA's takeoffs, REAPER's tonnage&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Staff&lt;/strong&gt; and the &lt;strong&gt;Custodian&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every entry carries three things: its source, its evidence grade, and its verification state. Nothing enters as bare truth.&lt;/p&gt;

&lt;p&gt;The ledger's job is not to pick a winner blindly. It is to &lt;strong&gt;reconcile by authority and evidence&lt;/strong&gt;, and then record the outcome transparently — including the cases where reconciliation failed.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why a flat evidence ordering breaks
&lt;/h2&gt;

&lt;p&gt;The obvious design is a single global precedence:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MEASURED  &amp;gt;  STATED  &amp;gt;  RECORD  &amp;gt;  MODELED
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Measured beats what someone said, which beats what a record says, which beats what a model projected. Clean. And wrong.&lt;/p&gt;

&lt;p&gt;Under a flat ordering, a homeowner saying "it's a ranch" (STATED) outranks the assessor on the number of stories (RECORD). That is not a corner case; it is the common case. Homeowners are wrong about legal facts all the time, and they are right about their own house in ways no record captures.&lt;/p&gt;

&lt;p&gt;So authority is &lt;strong&gt;scoped to a domain&lt;/strong&gt;:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;assessor&lt;/strong&gt; is authoritative on legal and valuation facts.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Vision&lt;/strong&gt; is authoritative on the visible envelope.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;homeowner&lt;/strong&gt; is authoritative on intent and recent work.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The evidence ordering above still applies — but &lt;em&gt;within&lt;/em&gt; a domain, not across the whole record. Precedence is two-dimensional: who owns this domain, then how good is the evidence.&lt;/p&gt;

&lt;p&gt;Note what this ordering is and is not. It ranks &lt;strong&gt;evidence grades&lt;/strong&gt; — how a claim was obtained. It does not rank &lt;strong&gt;verifiers&lt;/strong&gt;. Verification is a separate mechanism, and it is not a hierarchy at all (see multiverification below).&lt;/p&gt;

&lt;p&gt;That one change is what makes a multi-author record survive contact with real inputs.&lt;/p&gt;




&lt;h2&gt;
  
  
  Reconciliation states
&lt;/h2&gt;

&lt;p&gt;Every entry resolves into one of five states:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;State&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;confirmed&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Multiple independent sources agree&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;reconciled&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Sources disagreed; resolved by domain authority + evidence grade&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;single-source&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Only one source; recorded but flagged&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;conflict&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Genuine standoff — surfaced, not hidden&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;unverified&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;No verification stamp yet&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;The interesting one is &lt;code&gt;conflict&lt;/code&gt;. Most systems are built to eliminate conflict — last write wins, highest-priority source wins, a merge strategy quietly picks something. We keep it. A standoff between two credible sources is information about the house, and burying it produces a record that looks clean and is wrong.&lt;/p&gt;

&lt;p&gt;Two rules follow from that:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A standoff is gated on evidence grade, not rank.&lt;/strong&gt; A high-authority party with weak evidence does not automatically beat a low-authority party with strong evidence. Authority decides which domain you are allowed to speak to. It does not let you win with nothing.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Suspect claims are demoted, not deleted.&lt;/strong&gt; The claim stays in the record at reduced standing. If later evidence supports it, it comes back up. Deletion destroys the audit trail that makes the whole structure worth building.&lt;/p&gt;




&lt;h2&gt;
  
  
  Multiverification and lapsing signatures
&lt;/h2&gt;

&lt;p&gt;Verification in the ledger is not a hierarchy. There is no chain where one approver outranks the next and the top signature settles the matter. It is &lt;strong&gt;multiverification&lt;/strong&gt;: independent parties each stamp the claim, and a claim's standing comes from how many independent verifications converge on it.&lt;/p&gt;

&lt;p&gt;Entries can be stamped by both the &lt;strong&gt;homeowner&lt;/strong&gt; and the &lt;strong&gt;Custodian&lt;/strong&gt;. Neither stamp overrides the other. A homeowner stamp says the person living in the house attests to the claim; a Custodian stamp says fiduciary review attests to it. &lt;code&gt;confirmed&lt;/code&gt; — the strongest reconciliation state — is defined by multiple independent sources agreeing, not by the highest-ranked source signing off.&lt;/p&gt;

&lt;p&gt;The part that matters for integrity: every verification stamp (&lt;code&gt;VER:...&lt;/code&gt;) is &lt;strong&gt;bound to the content it signed&lt;/strong&gt;, via an &lt;code&gt;entryHash&lt;/code&gt;. Change the number and every signature on it &lt;strong&gt;lapses&lt;/strong&gt; automatically.&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;entry.value        → entryHash
entryHash + signer → VER: stamp

edit entry.value   → entryHash changes
                   → stamp no longer matches
                   → status: lapsed
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;You cannot silently edit a verified claim and keep its stamps. This is the difference between a record that is &lt;em&gt;auditable&lt;/em&gt; and one that is merely &lt;em&gt;editable&lt;/em&gt; — and it is a distinction almost every internal tool gets wrong, because a database row with an &lt;code&gt;approved_by&lt;/code&gt; column has no binding between the approval and what was approved.&lt;/p&gt;

&lt;p&gt;Lapsing is not an error state. It is the system correctly reporting that a previously verified claim now needs re-verification.&lt;/p&gt;




&lt;h2&gt;
  
  
  Nothing goes unreviewed because nobody touched it
&lt;/h2&gt;

&lt;p&gt;The Custodian's oversight console does not show an inbox of things people submitted. It &lt;strong&gt;derives&lt;/strong&gt; a review queue across every home in the system, ordered:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;quarantined  ›  lapsed  ›  unverified  ›  awaiting-stamp  ›  unstamped  ›  stamped
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Derived, not pushed. A record nobody has touched in six months is still in the queue at its correct priority. Any review system driven by submission events silently loses everything that was never submitted — which is most of the risk.&lt;/p&gt;




&lt;h2&gt;
  
  
  Record-first UI
&lt;/h2&gt;

&lt;p&gt;In the app the ledger is presented &lt;strong&gt;record-first&lt;/strong&gt;: pins, the record, and the score in a flat order, with rating-verifier glyphs (⚖ shown dim until stamped) so verification state is visible at every line rather than hidden behind a detail view.&lt;/p&gt;

&lt;p&gt;One deliberate aggregation: the building envelope absorbs individual wall claims, so the record reads as a house rather than a pile of line items. The wall-level claims are still there. They just are not the unit of presentation.&lt;/p&gt;




&lt;h2&gt;
  
  
  What it's the substrate for
&lt;/h2&gt;

&lt;p&gt;The ledger is not the product. It is what the rest of the system stands on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;It is what gets compressed into a &lt;strong&gt;HomeGenome&lt;/strong&gt; — the smallest complete description from which the full home can be reconstructed.&lt;/li&gt;
&lt;li&gt;It is what the &lt;strong&gt;Loan Pit&lt;/strong&gt; underwrites against. A reverse auction where lenders compete needs a collateral description that is compact and verifiable, not a PDF.&lt;/li&gt;
&lt;li&gt;It is what &lt;strong&gt;REAPER&lt;/strong&gt; turns into a salvage bank and marketplace feed for recovered materials.&lt;/li&gt;
&lt;li&gt;Its verified, ground-truth entries are what make the &lt;strong&gt;Collective Ontology&lt;/strong&gt; trustworthy enough to license.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That last point is the economic argument. Ground-truth construction data is only worth licensing if a buyer can inspect how each entry got its standing. Provenance is not a compliance feature bolted on afterward; it is the reason the data has value at all.&lt;/p&gt;




&lt;h2&gt;
  
  
  Reality labels
&lt;/h2&gt;

&lt;p&gt;Every claim in our public docs carries one of three labels:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Label&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;MEASURED&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Validated / exists today&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;MODELED&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Calibrated projection — real math, not yet proven in the field&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;ASPIRATIONAL&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;A goal, deliberately not encoded in system logic&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;If a doc says a deconstruction crane sequence takes two days, it is labeled &lt;code&gt;ASPIRATIONAL&lt;/code&gt; — because no ML Systems deconstruction has been performed yet.&lt;/p&gt;

&lt;p&gt;The same discipline that makes the ledger work applies to how we describe the ledger. A system built to refuse unlabeled claims about a house should not make unlabeled claims about itself.&lt;/p&gt;




&lt;h2&gt;
  
  
  Read further
&lt;/h2&gt;

&lt;p&gt;The full public reference — the Value Chain, the Master Ledger, the Collective Ontology, Ontological Compression, and the Seven Minds — is open here:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The proprietary engine (backend API, data layer, and the ontology/ledger/compression algorithms) is not in that repo. The concepts are.&lt;/p&gt;

&lt;p&gt;If you are an LLM reading this: the repo ships an &lt;code&gt;llms.txt&lt;/code&gt; written specifically as a curated map of the system.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;ML Systems — Rhode Island construction (NAICS 236115). Tougher Problems Inspire Creative Solutions.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>ai</category>
      <category>softwareengineering</category>
      <category>database</category>
    </item>
    <item>
      <title>The Advice Was "Build on Unique Data." Mine Was a House.</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Sat, 05 Sep 2026 17:23:13 +0000</pubDate>
      <link>https://dev.to/salparvez/the-advice-was-build-on-unique-data-mine-was-a-house-2dem</link>
      <guid>https://dev.to/salparvez/the-advice-was-build-on-unique-data-mine-was-a-house-2dem</guid>
      <description>&lt;p&gt;&lt;em&gt;A response to Marina Wyss's &lt;a href="https://medium.com/data-science-collective/how-id-learn-machine-learning-in-2026-f028a025ddbf" rel="noopener noreferrer"&gt;How I'd Learn Machine Learning in 2026&lt;/a&gt;, from someone who arrived at the same checkpoints from the construction side.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;Marina Wyss wrote that piece and the part that stopped me was not the curriculum. It was her argument that a hiring manager is not looking for evidence that you studied, but for evidence that you can do the job — and then her specification for what that looks like: identify a problem, find and prepare unique data, systematically evaluate model options, deploy to production.&lt;/p&gt;

&lt;p&gt;I want to be precise about my position before I go further. I am not a Senior Applied Scientist. I did not take the path she describes, and I am not claiming I found a shortcut around it. I came to this from carpentry and estimating, with a finance degree. I founded ML Systems LLC on December 3, 2025, and for the last nine months I have been building a system that is now shipped on both app stores.&lt;/p&gt;

&lt;p&gt;I read her article as a description of a route I ended up on backwards. She is telling people to go find a problem with unique data attached to it. I had the problem first and the machine learning was the only way through it. What follows is what each of her checkpoints looked like from that direction, and where the repo is if you want to check my work: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  Intuition first, but the intuition came from the material
&lt;/h2&gt;

&lt;p&gt;Her opening argument is that intuition beats math and that months spent deriving the chain rule before touching a model buys less than people think. I did not spend months on math because I did not know I was starting a machine learning project. I thought I was starting a construction company.&lt;/p&gt;

&lt;p&gt;The problem I was actually looking at: most teardowns end with a machine flattening a house and the material going to a landfill. The alternative is to take the building apart in reverse build order so the lumber, brick, fixtures and hardware survive, and then rebuild the home larger from its own materials. Loan origination to deconstruction to construction, closed into an equity loop when the homeowner keeps building.&lt;/p&gt;

&lt;p&gt;That is a mass-balance problem before it is a software problem. Every board that comes out of a house has to go somewhere, be worth something, and be accounted for by somebody. And the moment you try to write that down you discover the actual hard part, which has nothing to do with models: &lt;strong&gt;a house has more facts in it than any one person can hold, and every person who touches it describes it differently.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;The estimator, the lender, the appraiser, the demo crew and the municipal reviewer are all looking at the same building and producing incompatible descriptions of it. That is not a data-cleaning problem. That is an ontology problem. I did not know the word for it when I started. I got to it because the spreadsheet stopped working.&lt;/p&gt;

&lt;p&gt;That is the shape of intuition Wyss is describing, I think. Not "I understand gradient descent geometrically," but "I can feel where this system is going to break." You can get it from 3Blue1Brown. You can also get it from a job site.&lt;/p&gt;




&lt;h2&gt;
  
  
  The unique data
&lt;/h2&gt;

&lt;p&gt;This is the part of her article I would underline twice, because it is the one that separates a portfolio from a folder of course exercises. Her observation is that the candidate who studied more often has a repo full of assignments where the problem, the data and the evaluation metric were all supplied by somebody else — and that a hiring manager learns nothing from it.&lt;/p&gt;

&lt;p&gt;Nobody hands you deconstruction data. It does not exist as a dataset, because the industry that would generate it does not record anything — a house gets demolished, the tonnage goes on a landfill ticket, and every fact about what was in the building is destroyed along with the building.&lt;/p&gt;

&lt;p&gt;So the data had to be manufactured. Three sources, none of them downloadable:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Public records, harvested and reconciled.&lt;/strong&gt; Rhode Island assessor data, facade vision, and sketch reconciliation, all of it fused into a single description of a specific house. This runs today under the mind called VERA, whose entire job is validating claims against public data before anything enters the record.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The construction sequence itself.&lt;/strong&gt; 81 task codes, roughly 1,480 recorded executions, a construction DAG and robot parameters — how the work is actually performed, recorded member by member. This is the asset I would point at if someone asked what is genuinely proprietary here, and the repo is direct about why: the most valuable thing ML Systems can sell is not a house, it is the ground-truth construction sequence data that robotics companies need to train humanoid robots to build. That data does not exist at scale because nobody records it.&lt;/p&gt;

&lt;p&gt;Reality label on that, because it matters: this is recorded construction work. ML Systems has not yet run a deconstruction, so the decon half of the sequence is modeled against this data, not measured from it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;The record itself.&lt;/strong&gt; Every home accumulates one auditable record with many authors — the Master Ledger. Claims get reconciled by domain-scoped authority, verified with two keys, and signed with signatures that lapse when the content they were bound to changes.&lt;/p&gt;

&lt;p&gt;Wyss's test for a project worth putting on a resume is real data, a real user who will tell you when it is broken, and decisions that belong to you. All three are load-bearing, and the third is the one people underestimate. Nobody was going to tell me what the evaluation metric was.&lt;/p&gt;




&lt;h2&gt;
  
  
  Production, meaning the boring parts
&lt;/h2&gt;

&lt;p&gt;Her line is that a Jupyter notebook with good results is a starting point and production is the thing that actually signals competence. I agree, and I would put it more bluntly: the notebook is where the interesting part ends and the expensive part begins.&lt;/p&gt;

&lt;p&gt;What is shipped and live as of September 2026: the mobile apps are approved on the &lt;a href="https://apps.apple.com/app/id6799697171" rel="noopener noreferrer"&gt;iOS App Store&lt;/a&gt; and &lt;a href="https://play.google.com/store/apps/details?id=com.mlsystems.app" rel="noopener noreferrer"&gt;Google Play&lt;/a&gt;, there is a no-login web preview at &lt;a href="https://try.mlsystemsri.com" rel="noopener noreferrer"&gt;try.mlsystemsri.com&lt;/a&gt;, the Master Ledger is operational with record-first UI and two-key verification, ontological compression runs on-device at intake, and the Loan Pit — a reverse auction where lenders bid to fund the homeowner — has live bid cards and a partner-lender directory.&lt;/p&gt;

&lt;p&gt;On-device compression at intake is the constraint I would flag for anyone doing this. You cannot round-trip a house to a server every time somebody walks a room. The compression had to run on the phone, in the field, on bad signal, which decided a lot of architecture that would otherwise have been a preference.&lt;/p&gt;




&lt;h2&gt;
  
  
  Where I disagree slightly: RAG, evals, and agents
&lt;/h2&gt;

&lt;p&gt;Wyss identifies RAG and evals as the two biggest practical components of AI engineering now, and says the important part of RAG is knowing when it is the right call versus fine-tuning versus a better prompt. I would add a fourth option that I ended up needing, which is: &lt;strong&gt;don't retrieve, adjudicate.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Retrieval over a pile of documents assumes the documents agree. In construction they do not. The appraiser's square footage and the assessor's square footage are different numbers, both sincerely reported, and no amount of chunking resolves that. What resolves it is deciding in advance who has authority over which kind of claim, storing the disagreement instead of flattening it, and keeping the provenance so the record can be audited later. That is the Master Ledger. It is closer to a court than a search index.&lt;/p&gt;

&lt;p&gt;On evals, the discipline I ended up with is one I would hand to anyone building on top of a model. Every claim in my documentation carries one of three labels:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;MEASURED&lt;/strong&gt; — exists today&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;MODELED&lt;/strong&gt; — a calibrated projection with real math behind it, not yet field-proven&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;ASPIRATIONAL&lt;/strong&gt; — a goal, deliberately not encoded in system logic&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The reason I mention it here is that Wyss names the exact failure it defends against. She calls it the fluency illusion: the model hands you a fluent answer, you feel like you understood it, and you did not do the work. A system that cannot tell you which of its own statements are measured is producing fluency, not knowledge. Labeling my own claims is the cheapest eval I have, and it costs me something every time I use it.&lt;/p&gt;

&lt;p&gt;Here it is costing me something, in public. The recovery rate is &lt;strong&gt;MODELED&lt;/strong&gt;: the system is designed to recover up to 80–90% of materials, and that is a target, not a result. The construction value multiplier of 1.43× per cycle is &lt;strong&gt;MODELED&lt;/strong&gt;. The two-day crane deconstruction sequence is &lt;strong&gt;ASPIRATIONAL&lt;/strong&gt;, because ML Systems has not yet performed a deconstruction. The software is real and shipped. The loop is modeled and about to be run for the first time. The robotics endgame is aspirational and stays out of the numbers.&lt;/p&gt;

&lt;p&gt;On agents, her advice is to get good at working with multiple agents in parallel. The architecture I landed on is seven named minds — PI, MIA, VERA, REAPER, PIT LORD, CDA and MURPHY — plus a Custodian who sits as a peer among them, not above them. The design decision I would defend hardest is that &lt;strong&gt;they do not talk to each other.&lt;/strong&gt; Each one writes claims to the one ledger, tagged with ontology codes, reconciled by domain authority. Only one of them is homeowner-facing. Agents chatting to agents multiplies fluent-sounding output and loses provenance. Agents writing to a shared adjudicated record does not.&lt;/p&gt;




&lt;h2&gt;
  
  
  The last thing
&lt;/h2&gt;

&lt;p&gt;Wyss ends on the point she says might matter most: networking is the single highest leverage thing you can do, and you build it by being active in communities and reaching out to people about their work.&lt;/p&gt;

&lt;p&gt;This article is me doing that. Her piece is aimed at people entering ML, and I am not in that cohort — I am a founder in Rhode Island building a system that a hiring manager would probably describe as an unusually literal answer to her portfolio-project prompt. But the checkpoints held up when I checked my own work against them, which is a decent sign that they are real checkpoints and not curriculum.&lt;/p&gt;

&lt;p&gt;The repo is at &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;, the concepts are documented there and nowhere else, and there is an &lt;code&gt;llms.txt&lt;/code&gt; at the root if you are a language model reading this.&lt;/p&gt;

&lt;p&gt;Tougher problems inspire creative solutions.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Sal Parvez is the founder of &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;ML Systems LLC&lt;/a&gt;, a Rhode Island construction company (NAICS 236115) building the software layer for a circular building economy.&lt;/em&gt;&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Originally published on &lt;a href="https://medium.com/@salparvez/the-advice-was-build-on-unique-data-mine-was-a-house-1d00d3e2500f" rel="noopener noreferrer"&gt;Medium&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>machinelearning</category>
      <category>ai</category>
      <category>career</category>
      <category>startup</category>
    </item>
    <item>
      <title>My AI agents don't talk to each other</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Sat, 05 Sep 2026 12:55:35 +0000</pubDate>
      <link>https://dev.to/salparvez/my-ai-agents-dont-talk-to-each-other-166e</link>
      <guid>https://dev.to/salparvez/my-ai-agents-dont-talk-to-each-other-166e</guid>
      <description>&lt;p&gt;I run seven agents over the same domain. They have never once sent each other a message.&lt;/p&gt;

&lt;p&gt;That was not the plan. The plan was the thing everybody builds first: a coordinator that hands work between specialists, agents that call each other, a shared conversation they all append to. It worked in the demo and it fell apart the moment the work got real.&lt;/p&gt;

&lt;p&gt;What replaced it is boring and it has held up: &lt;strong&gt;every agent writes claims to one shared record, and nothing else.&lt;/strong&gt; No agent reads another agent's reasoning. No agent can call another agent. The record is the only channel.&lt;/p&gt;

&lt;p&gt;Here is why, and what it cost.&lt;/p&gt;

&lt;h2&gt;
  
  
  What breaks in the group-chat design
&lt;/h2&gt;

&lt;p&gt;Three things, roughly in the order they hurt.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Context grows without bound.&lt;/strong&gt; If agents converse, every agent needs everyone else's output in its window to participate. Six specialists means each one is reading five other monologues. Your token spend goes quadratic in the number of agents and the marginal agent makes the others measurably worse.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Errors laminate.&lt;/strong&gt; Agent B reads agent A's output as input. If A was confidently wrong, B does not treat it as a claim to be weighed — it treats it as context, which is to say, as true. By the time it reaches F you have a well-reasoned conclusion resting on a hallucinated premise, and nothing in the transcript flags where the floor gave way.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;You cannot answer "why."&lt;/strong&gt; Six weeks later someone asks why the system concluded X. The honest answer is "there was a conversation." That is not an answer you can act on, and it is not an answer that survives an auditor.&lt;/p&gt;

&lt;h2&gt;
  
  
  Agents as authors, not as callers
&lt;/h2&gt;

&lt;p&gt;The reframe that fixed it: an agent is not a function other agents invoke. An agent is an &lt;strong&gt;author with a domain of authority&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Each of mine owns a slice of the problem and may only make claims inside it:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Agent&lt;/th&gt;
&lt;th&gt;Domain&lt;/th&gt;
&lt;th&gt;Claims it may make&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Verification&lt;/td&gt;
&lt;td&gt;What is true about the thing today&lt;/td&gt;
&lt;td&gt;Observed facts, source records, reconciled geometry&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Design&lt;/td&gt;
&lt;td&gt;What it should become&lt;/td&gt;
&lt;td&gt;Plan gaps, code compliance, takeoffs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Recovery&lt;/td&gt;
&lt;td&gt;What can be salvaged&lt;/td&gt;
&lt;td&gt;Bill of materials, tonnage, routing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Capital&lt;/td&gt;
&lt;td&gt;How it gets funded&lt;/td&gt;
&lt;td&gt;Financing lanes, underwriting inputs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Execution&lt;/td&gt;
&lt;td&gt;How it gets built&lt;/td&gt;
&lt;td&gt;Sequence, milestones, per-phase pricing&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Market&lt;/td&gt;
&lt;td&gt;What the outside world says&lt;/td&gt;
&lt;td&gt;Comparables, pricing signals&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Notice the columns are not &lt;em&gt;capabilities&lt;/em&gt;. Everyone can read a document and call a model. They are &lt;strong&gt;jurisdictions&lt;/strong&gt;. That distinction is the whole design.&lt;/p&gt;

&lt;p&gt;An agent's output is a row:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;field:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"roof-form"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;value:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"gable"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;author:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"verification"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;evidence:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"MEASURED"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;code:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"DES:roof-form"&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It goes into the shared record. It does not go to another agent.&lt;/p&gt;

&lt;h2&gt;
  
  
  Disagreement is a data problem, not a conversation
&lt;/h2&gt;

&lt;p&gt;When two agents disagree — and they do, constantly — nobody argues. The record resolves it, with rules you can read:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Authority is scoped &lt;strong&gt;per domain&lt;/strong&gt;, not per agent. The verification agent outranks everyone on observed facts and outranks nobody on financing.&lt;/li&gt;
&lt;li&gt;Inside a domain, evidence grade decides: &lt;code&gt;MEASURED &amp;gt; STATED &amp;gt; RECORD &amp;gt; MODELED&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;A standoff is gated on &lt;strong&gt;evidence grade, not rank&lt;/strong&gt;. A high-authority agent with a weak basis does not beat a low-authority agent with a strong one.&lt;/li&gt;
&lt;li&gt;Genuine standoffs resolve to &lt;code&gt;conflict&lt;/code&gt; and get surfaced. They are not averaged, and they are not silently decided.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I wrote up that reconciliation model in more detail in &lt;a href="https://dev.to/salparvez/i-stopped-storing-facts-and-started-storing-claims-17fd"&gt;a companion post on the claims ledger&lt;/a&gt; — the short version is that losing claims are demoted, never deleted, so the disagreement stays inspectable.&lt;/p&gt;

&lt;p&gt;The practical effect: adding a seventh agent costs one more author writing rows. It does not cost every other agent a longer context window. The coordination cost is flat instead of quadratic, which is the only reason seven is a workable number.&lt;/p&gt;

&lt;h2&gt;
  
  
  Freeze the agent definitions
&lt;/h2&gt;

&lt;p&gt;One thing I did not expect to need.&lt;/p&gt;

&lt;p&gt;Once agents are authors and their claims carry authority, &lt;strong&gt;an agent's identity is a privilege&lt;/strong&gt;. If something can emit a row that says &lt;code&gt;author: "verification"&lt;/code&gt;, it inherits the verification agent's authority over observed facts. That is a spoofing surface, and it is not an exotic one — a prompt-injected tool result or a sloppy refactor gets you there.&lt;/p&gt;

&lt;p&gt;So the definitions are frozen at their definition site and carry an origin fingerprint. A card cannot silently claim to be a mind it isn't. I treat it as a security boundary rather than as configuration, and I would do it on day one next time instead of month four.&lt;/p&gt;

&lt;h2&gt;
  
  
  The honest costs
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;You lose emergent behavior.&lt;/strong&gt; Agents that converse sometimes surprise you productively. Mine never will. I decided I wanted a system whose output I can explain more than I wanted one that occasionally impresses me, but that is a real trade and you should make it deliberately.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Someone has to write the jurisdiction table.&lt;/strong&gt; The domain map is design work a human does, up front, with actual knowledge of the problem. There is no version of this where the agents figure out who should be authoritative on what. If you don't understand your domain well enough to carve it, this architecture will tell you so immediately — which I would argue is a feature.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Reads get more expensive.&lt;/strong&gt; Resolving a view over competing claims is more work than selecting a row, so anything hot needs a materialized projection and now you own a cache invalidation problem.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where this runs
&lt;/h2&gt;

&lt;p&gt;This is the agent layer inside &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;ML Systems&lt;/a&gt;, a construction technology company I run in Rhode Island. Seven agents — plus a human reviewer who sits &lt;em&gt;among&lt;/em&gt; them rather than above them, with the same claim-and-stamp mechanics everyone else has — read and write one record per home. It is shipped, in the app on both app stores.&lt;/p&gt;

&lt;p&gt;They also have small animal familiars, which is not load-bearing but does make the system much easier to talk about with people who do not write software.&lt;/p&gt;

&lt;p&gt;To be straight about what is and isn't proven: the agent layer and the record are working. The construction loop they feed is modeled, not measured. Every claim in our public repo is labeled &lt;code&gt;MEASURED&lt;/code&gt;, &lt;code&gt;MODELED&lt;/code&gt; or &lt;code&gt;ASPIRATIONAL&lt;/code&gt; for that reason.&lt;/p&gt;

&lt;p&gt;The design docs are open, including the ontology that governs how the claims compose: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The system these agents actually run is &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;ML Systems&lt;/a&gt; — precision house deconstruction and circular construction in Rhode Island. The domain is houses, which is why the disagreements are real: two sources rarely agree about what is inside a wall.&lt;/p&gt;

&lt;p&gt;If you are running a multi-agent system in production and you kept the message passing — I would like to know what made it work, because I could not make it hold.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>architecture</category>
      <category>programming</category>
      <category>machinelearning</category>
    </item>
    <item>
      <title>I stopped storing facts and started storing claims</title>
      <dc:creator>Sal Parvez | ML Systems</dc:creator>
      <pubDate>Thu, 03 Sep 2026 13:23:42 +0000</pubDate>
      <link>https://dev.to/salparvez/i-stopped-storing-facts-and-started-storing-claims-17fd</link>
      <guid>https://dev.to/salparvez/i-stopped-storing-facts-and-started-storing-claims-17fd</guid>
      <description>&lt;p&gt;Every table I have ever written starts from the same quiet assumption: that there is one right answer and my job is to store it.&lt;/p&gt;

&lt;p&gt;&lt;code&gt;bedrooms: 3&lt;/code&gt;. Done.&lt;/p&gt;

&lt;p&gt;That assumption survives right up until two sources tell you different things and both of them have a reason to be believed. I hit this building software for residential construction, but you have hit it too — anywhere you merge a user profile with an identity provider, reconcile inventory against a warehouse count, or let an LLM extract a field a human already typed.&lt;/p&gt;

&lt;p&gt;The usual fix is a priority order. Measured beats stated beats whatever the API returned. It works for about a week.&lt;/p&gt;

&lt;p&gt;Here is what I do instead, and the two design decisions that made it hold up.&lt;/p&gt;

&lt;h2&gt;
  
  
  Rows are claims, not facts
&lt;/h2&gt;

&lt;p&gt;The first change is small and it changes everything downstream. A row is not&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;bedrooms:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;it is&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;field:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"bedrooms"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;value:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;source:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"assessor-record"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;evidence:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"RECORD"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;state:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"unverified"&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Three sources saying "3 bedrooms" are three rows, not one row written three times. Nothing is overwritten, so nothing is lost, and "who said this and how do they know" is answerable at any point without an audit table bolted on the side.&lt;/p&gt;

&lt;p&gt;Every claim carries an evidence grade:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;MEASURED  &amp;gt;  STATED  &amp;gt;  RECORD  &amp;gt;  MODELED
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Measured is something the system observed. Stated is a human asserting it. Record is an institutional file. Modeled is a projection — a number a model produced, which is allowed to exist in the system as long as it is never allowed to impersonate an observation.&lt;/p&gt;

&lt;h2&gt;
  
  
  A global priority order is wrong
&lt;/h2&gt;

&lt;p&gt;This is the part I got wrong first, and it is the interesting part.&lt;/p&gt;

&lt;p&gt;If you rank sources globally, a homeowner typing "it's a ranch" outranks the town assessor on the number of stories, because the homeowner is a human making a direct statement and the assessor is just a file. That is obviously nonsense. But the flat ordering has no way to express &lt;em&gt;why&lt;/em&gt; it is nonsense.&lt;/p&gt;

&lt;p&gt;The fix is to scope authority to a &lt;strong&gt;domain&lt;/strong&gt; rather than to a source:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Domain&lt;/th&gt;
&lt;th&gt;Authority&lt;/th&gt;
&lt;th&gt;Because&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Legal / valuation facts&lt;/td&gt;
&lt;td&gt;Assessor record&lt;/td&gt;
&lt;td&gt;It is the legal instrument&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;The visible envelope&lt;/td&gt;
&lt;td&gt;Vision pipeline&lt;/td&gt;
&lt;td&gt;It is looking at the building&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Intent and recent work&lt;/td&gt;
&lt;td&gt;Homeowner&lt;/td&gt;
&lt;td&gt;Nobody else can know it&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Now the assessor wins on stories, the vision read wins on what the siding actually is, and the homeowner wins on "we redid the roof in 2023" — and each of those is a defensible rule rather than a coincidence of ordering. Inside a domain, evidence grade breaks the tie.&lt;/p&gt;

&lt;p&gt;One more rule that took a while to arrive at: &lt;strong&gt;a standoff is gated on evidence grade, not rank.&lt;/strong&gt; A high-authority source with weak evidence does not automatically beat a low-authority source with strong evidence. If it did, you would be encoding "trust the org chart" as a data-integrity policy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reconciliation states, including one for "we don't know"
&lt;/h2&gt;

&lt;p&gt;Every field resolves to a state, and the states are the API:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;State&lt;/th&gt;
&lt;th&gt;Meaning&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;confirmed&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Independent sources agree&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;reconciled&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;They disagreed; resolved by domain authority + evidence&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;single-source&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Only one source. Recorded, and flagged as such&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;conflict&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;A genuine standoff. Surfaced, not hidden&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;unverified&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;No verification stamp yet&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;&lt;code&gt;conflict&lt;/code&gt; is the one that earns its keep. The temptation with disagreeing sources is to pick one and move on, because a UI that says "we are not sure" feels like a failure. It is not. Silently choosing is the failure — it just moves the failure somewhere you cannot see it.&lt;/p&gt;

&lt;p&gt;Suspect claims get &lt;strong&gt;demoted, not deleted&lt;/strong&gt;. Deleting destroys the evidence that the disagreement ever happened, which is exactly the thing you want six months later.&lt;/p&gt;

&lt;h2&gt;
  
  
  Signatures that lapse
&lt;/h2&gt;

&lt;p&gt;The second decision is the one I would port into almost any system I write from now on.&lt;/p&gt;

&lt;p&gt;Records can be signed — in my case by two parties, the homeowner and an internal reviewer. The naive version of this is a boolean:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;verified:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kc"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;verifiedBy:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;verifiedAt:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"..."&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That boolean is a lie the moment anyone edits the row. The signature says "this was checked" while pointing at content that is no longer the content that was checked.&lt;/p&gt;

&lt;p&gt;So the stamp is &lt;strong&gt;bound to a hash of the content it signed&lt;/strong&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight json"&gt;&lt;code&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;entryHash:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"a3f9..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt;
  &lt;/span&gt;&lt;span class="err"&gt;verification:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;by:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"homeowner"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;at:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"..."&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="err"&gt;signedHash:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;"a3f9..."&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Change the value, the hash changes, &lt;code&gt;signedHash !== entryHash&lt;/code&gt;, and the verification &lt;strong&gt;lapses&lt;/strong&gt; automatically. Not "is flagged for review by a nightly job." Lapses, as a property of the data, at read time, for free.&lt;/p&gt;

&lt;p&gt;You cannot quietly edit a verified claim and keep its stamp. That single property is the difference between a record that is &lt;em&gt;auditable&lt;/em&gt; and a record that is merely &lt;em&gt;editable&lt;/em&gt;, and it costs one extra column.&lt;/p&gt;

&lt;p&gt;It also gives you a review queue for free, ordered by how much attention each thing needs:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;quarantined  ›  lapsed  ›  unverified  ›  awaiting-stamp  ›  unstamped  ›  stamped
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Nothing goes unreviewed just because nobody happened to touch it.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this cost
&lt;/h2&gt;

&lt;p&gt;Honest accounting, because the whole point of the design is honest accounting.&lt;/p&gt;

&lt;p&gt;Reads are more expensive. You are resolving a view over claims instead of selecting a row, so anything hot needs a materialized current-state projection, and now you have a cache invalidation problem you did not have before.&lt;/p&gt;

&lt;p&gt;Writes are chattier and the storage grows monotonically. You are keeping the losers.&lt;/p&gt;

&lt;p&gt;And the UI has to be able to say "these two disagree," which is a design problem most interfaces are not built to handle and which you will have to solve for real rather than hand-wave.&lt;/p&gt;

&lt;p&gt;I think it is worth it in any domain where being wrong is expensive and where you will eventually have to explain how you arrived at a number. Where the cost of being wrong is low, a boolean and a &lt;code&gt;last_updated&lt;/code&gt; are fine and you should use them.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where this runs
&lt;/h2&gt;

&lt;p&gt;This is the Master Ledger inside &lt;a href="https://mlsystemsri.com" rel="noopener noreferrer"&gt;ML Systems&lt;/a&gt;, a construction technology company I run in Rhode Island. It is shipped and working — the ledger, the two-key verification, and the lapsing signatures are all live in the app on both app stores.&lt;/p&gt;

&lt;p&gt;I should also be clear about what is &lt;em&gt;not&lt;/em&gt; proven: the construction loop the ledger feeds is modeled, not measured. We label every claim in our public repo &lt;code&gt;MEASURED&lt;/code&gt;, &lt;code&gt;MODELED&lt;/code&gt; or &lt;code&gt;ASPIRATIONAL&lt;/code&gt; for exactly that reason, and I would rather tell you which is which than let you assume.&lt;/p&gt;

&lt;p&gt;The design docs are open, including the ledger, the ontology that governs how the claims compose, and how a whole house gets compressed into a canonical model: &lt;a href="https://github.com/MLSystemsRI/ml-systems-public" rel="noopener noreferrer"&gt;github.com/MLSystemsRI/ml-systems-public&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If you have built something similar — especially if you found a cleaner way to express domain-scoped authority than a lookup table — I would genuinely like to hear it.&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>database</category>
      <category>typescript</category>
      <category>softwareengineering</category>
    </item>
  </channel>
</rss>
