Portfolio Atlas
What changed in the book — and where to look now. All insured names synthetic.
SCOPE
{{ sg.label }}
{{ sg.value }}
{{ sg.delta }}
{{ sg.sub }}
EVIDENCE FIELD · 90 DAYS
{{ pfLensNote }}
{{ lensVolLabel }}
51 renewals ≤ 90d — 34 arrive with bundles
coverage {{ lensVcr }}%
{{ fieldTickLabel }}
MAYJUNJULTODAY →
governed volume
evidence coverage
drift pressure
write refused — contract held
AI-active 428
streaming · consented 61
write-tier refused 3
reached notice of loss 0
insureds 3,118
Receipt formatOVERT · royalty-free covenant · overt.is
Counter-signatureindependent witness · topology disclosed
Verificationoffline · no GLACIS account required
Signalsper-epoch · CI-bounded · denominator disclosed
NOW / NEXT DECISION
{{ nowTitle }}
{{ nowMeta }}
{{ nowBody }}
One evidence layer under every AI-touching entity in the book.
One runtime record, usable across the book — whatever the vertical.
ENTITY TYPES ON THE ATLAS
Organizations
Workforce identities
Endpoints
AI agents
Apps & vendors
Model / API calls
Evidence Fabric
Six layers, one receipt spine — select an entity to light its path, gaps, and blast radius. Payload-free.
LAYER
{{ selName }}
{{ selMeta }}
{{ selBody }}
{{ fabBlast }}
{{ sc.t }}
3,120 orgs · 3,917 identities · 4,212 endpoints · 312 agents · 84 apps · 19 model APIs · 1 witness
The Book
Where exposure sits relative to evidence quality. Size = governed volume · color = drift posture · halo = renewal ≤ 90d.
EVIDENCE FRONTIER
denominator, growing: {{ govCallsBig }}
SELECTED · EVIDENCE OBJECT
{{ frSelName }}
{{ frSelMeta }}
{{ frSelBody }}
underwriting threshold · click a node to focus it everywhere
{{ bookLensNote }}
INSUREDLINECONTRACTDRIFT · 14DRECEIPTSRENEWAL
{{ i.line }}
⌗ {{ i.hash }}
{{ i.receipts }}
{{ i.renewal }}
FLEET — ENDPOINTS × WORKFORCE
4,212 endpoints · 3,917 workforce identities · metadata-only, payload-free evidence
{{ fr.label }}
nominal
open exception
contained — write blocked
each bar ≈ a cohort slice · click a cohort to open its strip
{{ fleetSelName }}
{{ fleetSelMeta }}
{{ fleetSelSig }}
{{ fleetMore }} · identities pseudonymous by construction · metadata-only, payload-free evidence — no content, no keystrokes, no screens
{{ dosName }}
{{ dosKind }} · {{ dosId }} ENTITY DOSSIER
TRAIL
▸
{{ dosCrumbCur }}
CAUSAL SPINE — IDENTITY TO ATTESTATION
the same six stations for every entity type
{{ sp2.stage }}
{{ sp2.v }}
{{ sp2.sub }}
source · signed receipt chain
freshness · {{ dosFresh }}
verification · offline · witness-countersigned
privacy · payload-free — metadata only
JUMP
lens & scope travel with you
{{ dosDetTitle }}
{{ df.k }}
{{ df.v }}
{{ df.sub }}
CASE LENS · HEALTHCARE — HARDEST CONDITIONS
ambient/clinical AI is the stress test for runtime evidence · synthetic
CONSENT STATE
3 / 3
grants in force · revocable · each grant itself signed
HUMAN-IN-THE-LOOP
99.2%
draft-tier outputs accepted by a clinician · measured
ZERO-EGRESS BOUNDARY
HELD
plaintext never leaves the insured environment
OVERRIDE TRAIL
14 signed
every human override is itself a receipt
INFERENCE RECEIPTS
41.2M
one signed receipt per inference · payload-free
THE CAUSAL ARC — BASELINE TO DECISION
combined drift pressure vs the sealed day-30 baseline · rcpt_9f27c4e1… ✓ signed · witnessed open in Decision →
SIGNALS — DEVIATION FROM BASELINE · SIM
{{ ch.name }}
bound {{ ch.bound }}{{ ch.val }}
{{ driftRouteNote }}
INSURED'S ENVIRONMENT
plaintext · prompts · clinical content — stays here
ARBITER — runtime in the insured's own environment · agnostic proxy
→
EVIDENCE CONSUMER RECEIVES
{ attestation_hash,
heartbeat_epoch }
heartbeat_epoch }
+ typed categorical judgments
"the gateway processes plaintext in the request path; commits only the hash; plaintext is never persisted, logged, or exported." — COMPANION CLAUSE, VERBATIM
TYPED ALERT — WHAT THE EVIDENCE CONSUMER RECEIVED 07-12
{ category: "drift-breach",
task_class: "regulated-claims",
action: "refused",
insured_ref: "ins_mrd_7f2a",
epoch: 1784851200 }
// no clinical content, by construction
export: encrypted API · signed file · case system INTEGRATION PATH
{{ ct.n }}
{{ ct.title }}
GRANTED
{{ ct.body }}
→ {{ ct.benefit }}⌗ {{ ct.hash }}
DRAFT TIER (a human accepts the output)
On evidence-plane outage, proceeds open + logged as "governance evidence unavailable" — never a silent success.
AUTONOMOUS WRITE TIER
On drift or staleness breach, the action is refused — fails closed. A degraded note is not a governed action.
Controls
One signed object binds entity, allowed actions, evidence, enforcement, and receipt route — wording and code are the same artifact.
CONTROL CONTRACT · {{ ccState }}
⌗ {{ ccHash }}
{{ ccObjText }}
signed by org · counter-signed by independent witness · verify offline — no GLACIS service in the loop
{{ ca.k }}
{{ ca.v }} {{ ca.tag }}
⬢ independently verifiable — provable from the receipt chain alone · ◇ operator-dependent — asserted by the operator and labeled as such
ENFORCEMENT SEQUENCE — {{ ccTypeName }}
RESPONSE
1 · INPUT
{{ ccS1 }}
{{ ccS1sub }}
→
2 · EVALUATE
{{ ccS2 }}
{{ ccS2sub }}
→
3 · T+0 · {{ ccS3Mode }}
{{ ccS3Word }}
{{ ccS3Sub }}
→
4 · SIGN
{{ ccS4 }}
counter-signed — every outcome signs, allow included
{{ ccSeqNote }}
LIFECYCLE — ONE CHAIN FOR EVERY CONTRACT
{{ cl2.label }}
{{ cl2.v }}
SCOPE INHERITANCE — TIGHTEN-ONLY
{{ cs2.k }}
{{ cs2.v }}
{{ cs2.sub }}
{{ ccApplies }} · a child may tighten its parent — never silently loosen it
AGENT INVENTORY — SPRAWL, ENUMERATED
{{ ag.id }}
{{ ag.cls }}
⌗ {{ ag.hash }}
1. Declared scope. The Insured shall maintain a declared register of governed entities and their allowed actions, distinguishing draft-tier output accepted by a human from autonomous writes.
2. Behavioral bounds. Each governed action shall operate within declared drift, staleness, and posture bounds, reviewed at renewal.
3. Fail conduct. Autonomous writes in breach shall be refused; draft-tier actions during evidence outage shall proceed and be recorded as unevidenced.
4. Evidence of conduct. Each governed decision shall emit a signed, payload-free receipt into a tamper-evident record available to the Insured.
early endorsements called this object a "charter" — the hashes carry that lineage unchanged
Decision Workbench
{{ dwQuestion }}
SIMULATE DECISION CONTEXT
foregrounding changes what you read first — never the record
DECISION DELTA · MERIDIAN SCRIBE{{ dwCycle }}
EVIDENCE BASISLAST CYCLETHIS CYCLE — VERIFIED
{{ cr.m }}
{{ cr.before }}
{{ cr.now }} {{ cr.d }}
{{ cr.tag }}
{{ bundleNow }} receipts
inclusion + consistency proofs
independent witness
verified offline
1 admitted gap — 41 min
{{ dwNarr }}
the record is identical in every mode — the mode changes the question, never the evidence
RECEIPT BUNDLE — MANIFEST
observed · derived · ◇ asserted · missing
{{ bm.k }}
{{ bm.v }}
{{ bm.tag }}
COUNTER-CASE — WHAT A SKEPTIC PRESSES
41-min admitted gap · vendor attestation is operator-asserted (◇) · Ticketing SaaS uncontracted · override frequency +0.5pt and rising
a bundle that argues against itself is worth more than one that only flatters
THE DECISION
{{ dwBadge }}
Evidence informs judgment. GLACIS does not set price, terms, appetite, or claim outcomes.
$ glacis-verify bundle-decision-2027/
✓CHAIN OK
{{ bundleNow }} receipts verified
SYNTHETIC EXPORT · DEMONSTRATIVE
✓ inclusion + consistency proofs · RFC 6962
✓ independent witness · counter-signed
✓ runs offline — no GLACIS service in the loop
! 1 declared gap · 41 min · self-admitted
CASE OVERLAY · UTAH AI SANDBOX — BOUNDED
one jurisdiction's case study — the atlas itself is jurisdiction-agnostic · synthetic
REGULATOR-FACING ATTESTATION · QUARTERLY
period: 2026-Q2 receipts: 8,412,306 verified violations: 12 · all contained refusals: 3 · fail-closed declared gaps: 1 · 41 min signed: org + independent witness
the regulator verifies offline — same OVERT schema every lens uses, no special export
CROSS-COMPANY COHORT OVERLAP
3 organizations sit in both the book and the sandbox cohort. Learnings flow back pattern-level only — no cross-company payloads, nothing company-identifiable.
Presenter crib
Open on Portfolio · press RUN THE STORY · eight beats, one page. Not part of the walkthrough.
{{ cb.num }}
{{ cb.beat }}{{ cb.screen }}
{{ cb.line }}
Q — "WHO HOLDS THE KEYS?"
Offline chain verification is what's claimed — the bundle checks on your laptop with no GLACIS service in the loop. Independent external witness is the production roadmap, stated plainly — and OVERT, the open standard we published, is the ladder we climb it on.
Q — "SHOW ME LOSS DATA."
That is precisely the falsifiable question Phase 1 exists to answer — nobody has this data; the first portfolio to instrument gets it.