Audit trail · shape before GA
Human sovereignty, checkable
The journal is what the AEGIS kernel writes after it gates a CEP-Rank proposal. CEP-Rank scores; this page is the audit record — not a second ranker. A described journal is a promise. A shaped log is something a risk committee can inspect. This page publishes the record shape ahead of general availability. It is illustrative and redacted. It is not a live customer API and not a measured pilot extract.
Public notes
Decision-journal shape.
Record fields a reviewer can inspect before general availability. Not a live export.
CEP-Rank is rules plus scored correlation.
LLM narrates only. Not in the rank path. Not a trained production model.
Dedicated enclave, not SaaS.
Guest ≠ enrolled. Telemetry stays in the customer or lab enclave.
Order-of-operations tape.
Scripted scenario for a 90-second brief. Not measured. Not an agency endorsement.
Field Mandate stages.
What we sell. Staged acceptance. No invented ARR or certification wall.
Named programs, no invented metrics.
Honesty surface first. Measured tape only after a lab ranker exists.
Record shape
Compact field list a reviewer can inspect. Scroll the sample. It is illustrative, not a live export.
{
"ts": "2026-08-17T02:18:00Z",
"hypothesis_id": "H-0412",
"rank": 1,
"kind": "rules_scored_correlation",
"gate": "HUMAN_ONLY",
"proposed_act": "contain_session",
"narration": "LLM summary of already-ranked signals — not the rank.",
"evidence": [
{"source": "ATT&CK", "id": "T1566", "note": "citation reserved"},
{"source": "plane_join", "planes": ["untrusted", "wan"]}
],
"operator": {"decision": "accept|reject|defer", "at": null},
"llm_in_rank_path": false
}
What we are not claiming: this JSON is not from a paid pilot. Evidence IDs will be retrieval-grounded (CVE/NVD/ATT&CK) in a later increment so the HUMAN_ONLY reviewer sees sourcing, not only a score. A sandboxed AUTO_SAFE dry-run against replayed data is the Field Mandate sales motion after the first SOW — not enabled on this site.
