So it never answers directly. The question compiles to a contract from a whitelist, you read the contract, the engine executes it — and the model never touches the data or the figures. Below: the method, live, and the gate catching a derived number.
Type a question. It compiles into a formal query — shown to you before anything runs. Approve it, and the engine executes. The sentence is not the contract; this is.
Sees the whitelist as tool specs. Its whole output is one tool call: an intent plus enum values. No prose, no data access, no arithmetic.
Executes the approved contract over the pinned synthetic dataset. Every figure is engine output, rounded once, with provenance attached.
Eight intents exist. The model may only pick one and fill its parameters from enums; off the rails is refused — at the schema, and a second time server-side. There is no SQL anywhere in this system, which is why there is nothing to inject into.
One figure the engine computed was withheld from the narrator. The model filled the gap by doing the arithmetic itself — correctly. The gate rejected it anyway. Nothing here is staged; this is one real run, recorded, and you can replay the same scenario live in the cockpit.
8 intents on the rails · the model never touched a figure · every number recomputed from source · the recorded failure is reproducible live.
Reading is open. The recorded failure is open. Live compilation spends Bedrock, so it asks for your email first: one code, no account, and twenty runs at a time. Used them up? Verify again and carry on. That is also how I know who stopped by. The real publishing pipeline is mine to approve. Autonomy is earned, even here.