01Decision, objective, and constraint registry
Version the decision, owner, subjects, population, unit, target, prediction time, horizon, action window, alternatives, current process, objective, constraints, costs, benefits, harm thresholds, authority, affected parties and prohibited uses.
Operating contract: Available data does not define the decision, proxy is not objective, expected value is not realized value, one stakeholder's utility is not universal benefit, optimization is not authorization and no-action must remain an explicit alternative.
02Time-safe feature and outcome ledger
Preserve source, entity, event, availability, ingestion and revision times, feature versions, collection and selection processes, missingness, labels, outcome windows, censoring, policy regimes, interventions, exposure, corrections, access and retention.
Operating contract: Event time is not availability time, revised value was not known earlier, missing is not zero, unlabeled is not negative, outcome after intervention is not untreated truth and a retrospective join must not leak into a historical decision snapshot.
03Model, evaluation, and scenario ledger
Bind datasets, splits, baselines, candidates, features, code, environments, metrics, thresholds, segment results, calibration, intervals, stress tests, privacy accounting where used, scenarios, assumptions, constraints, sensitivity and recommendation candidates.
Operating contract: Random split is not always time-safe, discrimination is not calibration, aggregate score is not segment safety, interval is not certainty, privacy noise is not anonymity, correlation is not causation and recommendation is not a decision.
04Decision, action, and outcome ledger
Record evidence viewed, choice, rejection, override, rationale, approval, target, action, execution, exposure, outcome maturity, realized result, comparator, external shock, error classification, drift, harm, correction, threshold change, rollback, replacement and retirement.
Operating contract: Approved is not executed, executed is not effective, observed outcome is not causal effect, override is not error, quiet monitoring is not stability and retraining must not overwrite the evidence behind prior decisions.