Cartridges · the extensibility model

One engine.Your strategy inside it.

A cartridge is a domain pack: the grammar for how one field's decisions are made, running on an engine that never changes. The engine standardises the lifecycle — how a decision is compiled, governed, recorded and measured. It does not standardise the strategy.

The boundary

A cartridge declares.It never overrides.

Three tiers, nested, and the enforcement points inward. A question plugin sits inside a cartridge, which sits inside the host. Each tier may declare what it needs upward. None of them can reach down and change what the tier below enforces — which is why adding a domain cannot weaken the governance of any other.

01

Host

The decision engine
Decides
  • The compile path — scope, signals, readiness, candidates, guardrails, scoring, routing, artifact, outcome
  • Guardrail enforcement, below the model rather than requested of it
  • The append-only ledger and the hash chain over it
  • Claim ceilings, autonomy ceilings and who may sign
Cannot

Be overridden by anything above it. No cartridge can widen a ceiling, skip a gate or write to a closed ledger entry.

02

Cartridge

A domain pack
Decides
  • The decision grammar for one domain — what a candidate looks like, which signals it requires
  • Guardrail values: floors, caps, exposure bands, approval thresholds
  • Vocabulary mapping onto the organisation's own nouns
Cannot

Reach the execution layer, alter the ledger, or raise its own authority. It declares what it needs and the host decides whether that is answerable.

03

Question plugin

One answerable question
Decides
  • One question's scope contract — which axes it binds and at which grain
  • Its signal set, its solver and its readiness thresholds
  • What it refuses to answer when evidence is missing
Cannot

Exist in more than one state than the evidence supports. If a required signal is absent it reports the gap rather than estimating around it.

What stays yours

The lifecycle is ours.The judgement is yours.

The operating judgement that makes an enterprise different is the last thing it should have to hand over to run on shared infrastructure. A customer cartridge exists so it does not have to.

Your policies, not ours

Risk appetite, margin floors, approval chains and exposure limits are values you set. The engine enforces them; it has no opinion about what they should be.

Your proprietary logic stays private

A customer cartridge holds the operating judgement that makes you different. It runs on the host, it is not pooled with anyone else's, and it is not trained on.

Your vocabulary, not a schema

Cartridges map onto the nouns your organisation already uses. Nobody renames a business to fit a data model.

The lifecycle is standard, the strategy is not

What every cartridge shares is how a decision is compiled, governed, recorded and measured. What it decides remains yours to author.

Which cartridges exist

Fifteen retail decisions are catalogued with what each one decides and exactly how far it is built — rather than listed twice on two pages.

The decision catalog
Which industries follow

Retail is the first encoded decision network. The same engine, a different grammar — and the arc says which horizon each industry sits on.

The arc
Author one

Bring the decisiononly you know how to make.

The interesting cartridge is rarely the standard one. Bring the call your team makes from judgement nobody else has, and we will compile it against your evidence and your policy — advisory and dry-run, with the reasoning attached.