Synthetic scenario · illustrative product experience
Designed operating model · target state, conditional on model deployment, validation and governance

04:12 — The Second Night

The first night took a war room. In this designed target state the same class of allegation is contained, verified and packaged automatically overnight — and the MLRO receives exactly one message with three choices. Approve, reject into human review, or pick an alternative. The human is always allowed to be slower than the machine.

About this demonstration

Every scenario is a deterministic, synthetic demonstration set in a fictional universe (Aster Market, Lumen Digital, PSP-A/PSP-B). It shows a designed decision discipline — not a live deployment, a customer result or a production claim. Nothing is submitted, stored or tracked; the full boundaries sit under ‘What this does not prove’ at the end of each story.

Questions about what is real here? Read the FAQ →

← All scenarios
  1. 01CaptureFix the signal, source and purpose before interpreting them.
  2. 02GovernApply the relevant scope, policy and mandatory boundary.
  3. 03DecideChoose a posture without hiding held or unresolved work.
  4. 04ChallengeExpose review, exceptions and the next accountable owner.
  5. 05ProveAssemble an inspectable artifact with its limits still visible.
Skip to the outcome ↓
01 · SIGNAL · 04:12

Design contract: the reviewed registry's ML indicator is a stub — no live model, no measured false-positive rate and no autonomous termination is claimed. Model validation, drift monitoring, versioning and explainability are conditions of this target state, not delivered facts.

TrustStack ORION · DEMO04:12
One message. Three choices.

Case DCK-DEMO-2044 — Lumen Digital

Allegation match on 1 listing

policy prohibited-items@demo-4.1

model risk-screen@demo-2 · conf 0.94 · DESIGNED

Auto-actions taken (designed)
  • Listing quarantined
  • Payouts scoped-held
  • KYB re-verified — no change
  • Evidence pack EVP-DEMO-2044 assembled
RecommendationCONDITIONAL RELEASE — category ban, 30-day monitor

What executed after your tap

  • Scoped hold released · category ban applied
  • 30-day enhanced monitoring scheduled
  • Bank notified via the recorded template
  • Decision record DR-DEMO-2044 signed with your approval
02 · DECIDE
Your decision — one thumb
03 · CHALLENGE

What ran while you slept

Seven automated steps, one human gate. Every step carries its policy version, model version with confidence, and an input snapshot. Expand any step.

  1. 04:12:07Signal captured

    A marketplace listing signal matched the allegation class. Input snapshot SNAP-DEMO-9917 recorded under policy prohibited-items@demo-4.1.

  2. 04:12:08Model scored — designed

    risk-screen@demo-2 returned 0.94 confidence with reason codes. Designed and conditional: the reviewed registry's ML indicator is a stub.

  3. 04:12:09Listing quarantined

    The listing left the storefront with an appeal path. Takedown log TKD-DEMO-2044.

  4. 04:12:11Payouts scoped-held

    A payout-only hold applied for MER-DEMO-204; sales continue into escrow. HOLD-DEMO-2044.

  5. 04:12:38Identity re-verified

    KYB refresh confirmed the beneficiary unchanged. KYB-DEMO-204-R2.

  6. 04:13:02Case assembled

    DCK-DEMO-2044 opened with every action attached under correlation corr_demo_2044.

  7. 04:13:04Evidence packaged · human gate set

    EVP-DEMO-2044 assembled; the release decision waits for the MLRO — the one gate no policy may cross.

Your mission

Hold the one decision that matters while the designed machine holds everything else.

The night ran to its single human gate: the release decision waits on your phone.

Flow

Seven automated steps executed and recorded; nothing beyond the gate has moved.

Guardrail

The designed model recommends; only the MLRO's decision releases anything.

Ownership

The MLRO owns the release; the machine owns the record of what it did.

Evidence

Every automated step carries its policy version, model version, confidence and input snapshot.

Why this matters

Automation earns trust when its one human gate is unmistakably real.

OUTCOME

One decision, one tap, one record

Whatever you choose, the record shows what the machine did, what it recommended, and where the human stayed in charge.

DEMO · READY TO REVIEW
Your decisionApprove the recommendation
Human gateRelease decision · MLRO — the one gate no policy may cross
Inspect Decision Record DR · DEMO
decision_recordFIXTURE
case
DCK-DEMO-2044
merchant
MER-DEMO-204 · Lumen Digital
policy
prohibited-items@demo-4.1
model
risk-screen@demo-2 · conf 0.94 · DESIGNED
auto_actions
quarantine · scoped hold · KYB re-check · evidence pack
human_gate
release decision · MLRO
evidence_pack
EVP-DEMO-2044
correlation_id
corr_demo_2044

Not recorded by engine — No value is inferred from surrounding data.

Your scenario artifact

Night Log — one decision, one tap

The seven automated steps, the one human gate, and the decision you took at 04:12.

TrustStack ORIONNight Log — one decision, one tap
DEMO · demo-universe-1

Designed operating model — target state, conditional on model deployment, validation and governance. Synthetic DEMO.

The night, automated

  • Signal → score → quarantine → scoped hold → re-verify → case → evidence
  • Every step stamped with policy and model versions
  • Input snapshots preserved for reconstruction

The human gate

  • The release decision waited for the MLRO
  • Reject always routes to human review with nothing executed
  • Alternatives remain maker proposals behind the checker gate

Design contract

  • Model validation, drift monitoring and explainability are conditions, not claims
  • No autonomous termination exists in the designed flow
  • The ML indicator in the reviewed registry is a stub

The morning after

  • A summary report stands ready for the 09:00 review
  • The case and pack answer any bank or partner question
  • The first night took a war room; this one took one thumb

What this shows

  • How a designed automation path can keep every human control point explicit — and provable.
  • How policy versions, model versions and input snapshots make an automated night reconstructable.
  • Why reject is a first-class outcome: the human is always allowed to be slower than the machine.

What this does not prove

  • No live model, measured false-positive rate or production automation is demonstrated; the registry's ML indicator is a stub.
  • No autonomous account termination is claimed, designed or implied.
  • Model validation, drift monitoring and governance are presented as required conditions, not as delivered evidence.
Aster Decision Dossier

Aster Market

Each scenario adds a different synthetic artifact without changing the shared facts.

1 / 6Explored chapters
  1. 03:17
    Continuity Drill Brief03:17 — The Continuity Room
    Continue with the same synthetic facts
  2. 09:00
    Shared Merchant Decision MemoOne Merchant — Five Realities
    Continue with the same synthetic facts
  3. 14:00
    Evidence Review ReportProof Lab — Try to Break the Decision
    Continue with the same synthetic facts
  4. Day 3
    RFI Response PackDay 3 — The Freeze
    Continue with the same synthetic facts
  5. Day 90
    90-Day Pilot BlueprintBuild Your Control Map
    Continue with the same synthetic facts
  6. 04:12
    Night Log — one decision, one tap04:12 — The Second Night
    Current chapter

Explore all six chapters to close the night.

Continue the shared story

Replay the first night — the one humans ran at 03:17

Continue
90-day pilot · targets agreed up front · scale, revise or stop at day 90 Run this discipline on your traffic Open the atlas of all fourteen modules →