Trace before change. Reconcile after change.
A semantic layer that lets a coding agent see a system as behavior
rather than as files. These are the reference models, rendered by the engine in
the repository. Each page is generated on every
push to main, so nothing here can describe a version that does not
exist.
The repository describing itself. Four flows, nineteen evidence references, validated in CI like any other model.
Touches every entity: a human decision, a scheduled flow, a two-tenant feature flag, event fan-out, independent partial-failure outcomes.
Each page is a view, not a source of truth. Effective reality, impact, coverage and integrity are computed by the engine and embedded as results — no traversal runs in the browser, so there is no second implementation to drift from the engine.
A page showing uncertain is not a broken
page. Confidence is computed from when each reference was last checked and
whether the artifact has changed since. Edit a file a model cites and its confidence
falls here on the next push, with nobody touching the model — that is the mechanism,
not a fault. integrity: UNCERTAIN likewise usually means there are
repository files the model does not cover, which is the normal state of a model that
is honest about its edges.