Causalytics
  • Veritas
  • Research
    • Weekly briefs
    • Specifications
  • About
  • Contact
Skip to main content
  1. 00The handoff chain
  2. 01The asker
  3. 02IT leaders
  4. 03Governance
  5. 04Builders
  6. 05Reviewers
  7. 06Operators
  8. 07Auditor
  9. 08Domain builder

Veritas / The request layer for enterprise software

One request.
Every seat around it.

In Veritas a request stays one living record, from the first sentence someone types to what production shows months later. Eight kinds of people touch that record. Each one sees it from their own world.

Scroll to follow one illustrative request, VR-0412, through every seat.

The asker IT leaders Governance Builders & agents Reviewers Operators The auditor Domain builders
VR-0412 · the first sentence

Vendor invoices sit in three inboxes and we keep paying late fees.

Follow the request

00 Why this exists

Six handoffs later,
the solution has already drifted.

A request travels from the person who needs it to a PM, a business analyst, a developer, the AI team, the analytics team, and back. Everyone rewrites it a little. Nobody holds the original.

  1. Requester
  2. PM
  3. BA
  4. Developer
  5. AI team
  6. Analytics
  7. Requester

Instead of

  • Each team working from the previous team's summary.
  • Scope added by whoever touched it last.
  • Success measured by whatever was easiest to count.
  • The requester finding out at launch that it solves a different problem.

With Veritas

Nobody passes a summary along. The requester's own words stay at the top of one record, and every seat, from the PM and analyst to the developers, the AI team, and analytics, works from that record and adds to it. Changing the intent creates a new revision that goes back through the gates, not a quiet rewrite in the next team's ticket.

Hand along the record, not the story.

Without a record6 handoffs · 7 versions
  1. one intake path
  2. no late fees
  3. the right approver
  4. within a day
  5. scope nobody asked for
  1. RequesterReq
  2. PMPM
  3. BABA
  4. DeveloperDev
  5. AI teamAI
  6. AnalyticsData
  7. RequesterReq
  1. RequesterVendor invoices sit in three inboxes and we keep paying late fees. Every invoice should reach the right approver within a day.
  2. PMFinance wants one AI inbox for invoices to cut late fees.
  3. BAREQ-7.1: extract invoice fields from a shared mailbox into the ERP.
  4. DeveloperOCR pipeline on a nightly batch job.
  5. AI teamAdded a model that auto-codes general ledger accounts.
  6. AnalyticsSuccess = invoices digitized and OCR accuracy.
  7. RequesterThe invoices are digitized. We still pay late fees.Not what I asked for

0 of 4 intents survived · 2 invented along the wayWith Veritas: every seat reads and extends the same record.

01 The asker

Say it the way you'd say it in the hallway.

You know what's wrong better than anyone. You shouldn't have to translate it into a specification to be taken seriously.

  • Operations supervisor
  • Customer service lead
  • Marketing lead
  • Finance analyst
  • Plant scheduler
  • Program coordinator

Instead of

  • Waiting at number 212 in the IT backlog.
  • Filling in a requirements template, writing user stories, or picking a technology you shouldn't need to know about.
  • Building a shadow spreadsheet only you can maintain, or a vibe-coded tool nobody else can support.

With Veritas

Describe what you saw and what should be different, in your own words. Veritas saves it as the first line of a record and does the looking: what the organization already says about it, what already exists, which rules might apply. Follow-up questions are shaped to your request, and you can always see who it's waiting on.

VR-0412+ your words
requirements_template_v7.docx "As a user, I want…" Choose a platform ▾ IT ticket · queue position 212 invoice_tracker_FINAL(3).xlsm

What did you see?

Vendor invoices sit in three inboxes and we keep paying late fees.

What should be different?

Every invoice reaches the right approver within a day, with no late fees.

Saved as VR-0412 · requester: AP supervisor, finance operations · waiting on: intake triage

02 CIOs and IT leaders

One front door.
A portfolio, not a pile.

Every department wants its own AI tool, and some are already vibe-coding one on the side.

  • CIO
  • CTO
  • Head of IT
  • Enterprise architect
  • PMO lead
  • Transformation lead

Instead of

  • Requests arriving by email, hallway, and steering committee.
  • Discovering the third version of the same tool after it ships.
  • Prioritizing by whoever asked loudest.

With Veritas

Every request comes through the same door and lands on the same board: what's waiting, on whom, and which requests may duplicate something the organization already owns or is already building. Veritas recommends priority and sequencing against your own strategy; the material portfolio calls stay yours, with your name on them.

Build less. Build the right things.

VR-0412+ portfolio position
38requests
4waiting on security
3possible duplicates
1front door
IntakeAssessingIn reviewBuilding
Finance opsInvoice routing
HRPolicy Q&A bot
FinanceExpense audit
MarketingCampaign copy tool
OperationsShift scheduler
ProcurementInvoice OCR bot
LegalClause finder
SalesQuote builder
FinanceForecast refresh
MarketingChurn scoring
FacilitiesWork-order triage
ITAccess review helper
OperationsDock appointments
HROnboarding checklist
QualityIncident tagging
Customer serviceCall summaries
Illustrative portfolio. Tagged tiles may duplicate something already owned or already requested; people decide.

03 AI governance and compliance

Decide on evidence,
not on a slide deck.

You're the one who has to say yes or no to AI use cases, usually from a deck and a hallway conversation.

  • AI governance lead
  • Chief risk officer
  • Compliance officer
  • ISO/IEC 42001 AIMS owner
  • Model risk manager

Instead of

  • Reading a pitch and guessing what it touches.
  • Working out again, for every request, which rules apply.
  • Approvals that rest on how confident the model sounded.

With Veritas

Each request arrives with its applicability already worked out by deterministic rules against a versioned registry: is it AI, is it consequential, is it federal, is it inside your ISO/IEC 42001 scope. The authorities in force are frozen with the record. Gates pass on reviewed evidence, never on a model's confidence, and anything unproven stays unknown until someone supplies the evidence.

VR-0412+ applicability & gates

Applicability · deterministic rules

  • Does it involve AI?…Yes
  • Consequential impact?…No · no decisions about people
  • Federal scope?…Unknown → evidence requirement
  • Inside the ISO/IEC 42001 scope?…In declared scope
Authority snapshot frozen with VR-0412cycle 2

Gate · payment approval controls

Model confidence
97%
Held · evidence not reviewedPassed · reviewer attached test evidence
Confidence is not evidence.

04 Developers and coding agents

A locked contract,
not a vague ask.

Downstream, the build doesn't start from a Slack message. It starts from a contract.

  • Software engineer
  • Data scientist
  • Low-code builder
  • Coding agent
  • Vendor team

Instead of

  • Reconstructing the requirement from a thread.
  • Learning about the compliance rule in code review.
  • Scope that grows one "quick change" at a time.

With Veritas

The contract is compiled from the governed record: requirements, controls, no-gos, acceptance criteria, and stop conditions. Generated files are fingerprinted against it. If the contract changes, the build goes back. A coding agent gets boundaries it can check itself against and a defined place to stop instead of improvising.

Build once. Build right.

VR-0412+ build contract
build-contract.yaml · VR-0412 · cycle 2
requirement: route every invoice to its approver within one business day
control:     read-only access to the ERP vendor master
no_go:       approve or pay an invoice
no_go:       change vendor bank details
accept:      every test invoice reaches the right approver
stop_if:     approver unknown → hold and report
digest:      sha256:9f1c…e04a  locked
- no_go:     approve or pay an invoice
+ requirement: auto-approve invoices under $500
build 7files match the locked contract ✓contract changed · returned for review ↩

05 The reviewers who sign off

Named sign-off.
Nobody grades their own work.

Security, privacy, legal, the business owner, the deployment authority: each attests to what they own.

  • Security
  • Privacy
  • Legal
  • Business owner
  • Finance controls
  • Deployment authority

Instead of

  • "Looks fine" in an email thread.
  • The person who built it confirming that it works.
  • Exceptions granted in a comment and never revisited.

With Veritas

Attestations are recorded by role, for the current review cycle, with a rationale. Which roles must sign depends on the request: AI work adds AI governance, sensitive data adds privacy, high-impact use adds legal. The person who built it can't be the one who verifies it. A waiver needs its own named approver and an expiry date, so an exception is a decision with an end, not a loophole, and ISO/IEC 42001 conformity requirements can't be waived at all.

Today these are named attestations. Authenticated identity is a prerequisite before production use.

VR-0412+ attestations
  • Business ownermatches the askAttested
  • Strategistpriority set · related request linkedAttested
  • Securityaccess scoped read-onlyAttested
  • AI governanceinside the declared AIMS scopeAttested
  • Privacyvendor bank data minimizedAttested
  • AIMS ownerinside AIMS scope · SoA updatedAttested
  • Verificationbuilder of build 7 → independent verifierBuilder ≠ verifierVerified
  • Deployment authoritynot the builder or verifierAttested

Waiver W-3 · single sign-on integration pending

Separate approver: CISO · expires in 94 days

06 The people running it

Launch is a checkpoint,
not the finish line.

Tools don't stop at launch. Neither does the record.

  • Product owner
  • Operations lead
  • Site reliability
  • Finance systems
  • Model monitoring

Instead of

  • A dashboard nobody connects back to why the tool exists.
  • Quiet drift until someone complains.
  • Rolling back to last quarter's build and hoping.

With Veritas

Production observations attach to the same record that authorized the tool. When one is recorded as a breach of its threshold, the request reopens for review and keeps the observation that caused it. The updated assessment and contract go back to people, and the old build can't simply be redeployed: its approvals belonged to a cycle that has closed.

VR-0412+ production observations
In production · build 7Reopened for review · observation #31

Invoices approved within a day threshold 90%

obs #31 88% · late fees back · recorded on VR-0412

reassessment assessment, gates, contract → back to people

redeploy build 7 blocked · approvals belong to cycle 2

07 The auditor

Months later, one view.
No archaeology.

From the first sentence someone typed to the latest production observation.

  • Internal audit
  • External assessor
  • Certification body
  • Quality lead
  • Regulator liaison

Instead of

  • Rebuilding history from inboxes and meeting notes.
  • Asking who approved what, under which version of the rules.
  • Today's policy retrofitted onto last year's decision.

With Veritas

One lineage with every authority, applicability finding, control, decision, exception, and release in between, each as it stood at the time. Opening an old record never attaches today's rules to it.

Today the lineage is logically append-only. Tamper-evident storage is a prerequisite before production use.

Every point on the line is a seat you just scrolled past.

VR-0412full lineage
  1. Day 1“Vendor invoices sit in three inboxes and we keep paying late fees.”
  2. Day 1Applicability found · authority snapshot frozen
  3. Day 4Assessment generated · 3 unknowns become evidence requirements
  4. Day 9Prioritized · related request linked · decided by name
  5. Day 16Gates passed on reviewed evidence · 1 waiver with expiry
  6. Day 18Build contract locked · sha256:9f1c…e04a
  7. Day 317 role attestations · independent verification
  8. Day 33Released · build 7
  9. Day 141Observation #31 breaches threshold
  10. Day 141Reopened · cycle 3 back with people

08 The domain builder

Same record.
A completely different world.

Some people turn what they know about a field into a working tool other people can rely on.

  • Subject-matter expert
  • Industry consultant
  • Specialist firm
  • Researcher

What changes

The record stays the same. What changes is the world around it: the corpus Veritas searches, the authorities in its registry, and the shape of the assessment it generates.

The flagship use case

ConstructPolicies is for restoration and reconstruction contractors researching which codes and agency rules apply to a job, with cited source passages and coverage audited per jurisdiction. It points to the sources; it doesn't issue compliance determinations.

See ConstructPolicies →

CP-0027same record · new corpus
Santa Clarita · audited Unincorporated LA County · audited next · not yet covered

Fire-damaged roof on a job in a very high fire hazard severity zone. What applies?

  • LikelyExterior wildfire exposure requirementsCalifornia Building Code, ch. 7A · cited passage
  • PossibleLocal amendment to the building codeJurisdiction ordinance · effective date shown
  • Can't tell yetAgency rule tied to permit timingMissing fact: permit date

Not an illustration

Seen in the running system.

We ran the same invoice request through Veritas for a fictional company, Alder & Finch Distribution, with the models switched off. These are the screens it produced.

Veritas mission control: four synthetic requests with their status and lane, and the invoice routing request waiting on a gate reviewer.
02 · IT leadersOne front doorFour requests from four departments, each showing what it is waiting on and on whom.
Veritas related tools table ranking the ERP approval workflow first for the invoice routing request, followed by the procurement OCR bot and vendor portal.
02 · IT leadersWhat already existsBefore anything is built, Veritas ranks the organization's existing tools against the request. The licensed ERP approval workflow comes first.
Veritas governed build contract showing the business outcome, stop conditions, explicit no-gos, and a lineage card with the contract digest.
04 · BuildersThe locked contractThe requester's outcome, stop conditions, and no-gos travel into the contract, bound to its digest and authority snapshot.
Veritas build lane verification trail: released to build lane, candidate generated and validated, result registered, independently verified.
04 · BuildersThe verification trailA coding agent built it, CI published it, and a different, named person verified it.
Veritas approvals table listing named reviewers by role with their decisions and rationales, including two deployment authority entries.
05 · ReviewersNamed attestationsSeven role sign-offs. The verifier also signed as deployment authority; Veritas refused to authorize release until a separate authority signed.
Veritas exceptions table showing one waiver on access control, requested by security, approved by the CISO, expiring 2026-12-30.
05 · ReviewersA waiver with an endRequested by security, approved separately by the CISO, and dated to expire.
Veritas production observations: three weekly values within the 90 percent threshold, then an 88 percent breach with its cause.
06 · OperatorsThe breach that reopened itThree weeks inside the threshold, then 88%. Recording the breach reopened the request as review cycle 2.

Synthetic company, people, and data. Captured from Veritas with models switched off (deterministic fallback). Some table columns are hidden for width and local file paths are omitted.

Also at the table

Four more people the record
quietly works for.

The AIMS owner

Records whether the organization has adopted ISO/IEC 42001, for what scope, and from when. Until that decision exists, AI work can't enter the build lane, and no requester or model can make it for them.

The strategy owner

Their strategy and prior decisions are what every request is compared against. Veritas recommends a disposition; they make the call, by name.

The data owner

Data sensitivity is triaged at intake. If a request touches sensitive data, privacy review becomes a required sign-off before release, not a discovery after it ships.

The platform owner

Runs Veritas on the organization's own infrastructure, points it at approved local models, or switches the models off and keeps the workflow.

The thread through every seat

The request
is the product.

In a prompt-to-app tool, the prompt disappears the moment the app appears. Nobody asked whether it should exist, whether it already exists, what rules apply, or who is accountable.

In Veritas the ask stays one living record from the first sentence to production. The organization's own strategy, policies, and existing tools are consulted before anything is built, and people make the decisions that matter.

Built for an organization that has to answer for what it ships.

Prompt-to-app

“Build me an AI invoice processor”
  • Should it exist?
  • Does it already?
  • What rules apply?
  • Who is accountable?

Veritas

“Vendor invoices sit in three inboxes and we keep paying late fees.”
  1. Intake
  2. Observation
  3. Applicability
  4. Assessment
  5. Strategy
  6. Gates
  7. Contract
  8. Review
  9. Monitoring
  10. Audit
production observation → reassessment ↺

Where it runs

Your infrastructure.
Your models.
Or none at all.

Veritas runs on your own infrastructure against approved local models. Models do the interpretation; deterministic code owns the state, the gates, and the authorization. Switch the models off and the workflow degrades to deterministic behaviour instead of disappearing.

  1. 1Signal intakedeterministic
  2. 2Observationretrieval + model reuse analysisretrieval or local text scan
  3. 3Applicabilitydeterministic
  4. 4Assessmentmodel-shapeddeterministic fallback
  5. 5Portfolio strategymodel-relateddeterministic fallback
  6. 6Control gatesreviewed evidence
  7. 7Build contractmodel-organizeddeterministic compile
  8. 8Human reviewpeople
  9. 9Monitoringdeterministic
  10. 10Auditdeterministic

model-assisted deterministic people

Design partners

Which seat are you in?

Bring one request your organization struggles to govern, from whichever seat you sit in, and run it through the full record with us. Veritas is early: a working single-node system, not yet a production service. Attestations are named rather than authenticated, the audit lineage is not yet tamper-evident, and production observations are recorded by people rather than ingested automatically. The request followed on this page is illustrative.

Discuss a design partnership ↗How Veritas works

© 2026 Causalytics Impact · A public benefit company

 
  • Briefs RSS

  • Impact Passport

  • Research foundations