What was asked
The decision as framed, the options on the table, the envelope and the risk appetite the committee set.
Decision record
What the committee knew, what it chose, who disagreed and what would reopen it, stored with the run it relied on. The log is append-only and hash-chained, and every engine run replays to an identical result. When someone asks why a project was funded, the answer is already written down.
Available today. Each engine run stores digests of its inputs, parameters and output, its seed and its engine version, and can be replayed to an identical result. Signed checkpoints can be verified with a public key.
What a record holds
Minutes say what was decided. A Capibud record also keeps what the committee was looking at when it decided, so the decision can be re-examined on its own terms rather than with hindsight.
The decision as framed, the options on the table, the envelope and the risk appetite the committee set.
Digests of inputs, parameters and output, the seed, the engine version and the industry pack version pinned to the decision.
Votes with their rationale, dissent with its reasoning, conditions, and the alternatives the committee did not choose.
Tripwires: thresholds that reopen the decision if live data crosses them, checked by the brain on every scan.
One decision, four beats
An illustrative sanction decision from the question to the replay two years later. Double-click any figure for its details.
Illustrative decision. The figures are not taken from a client project.
Anatomy of a record
This is the record behind the decision in the player above. Every line points somewhere: a value to its cell, slide or page line, a run to its digests, a vote to the person who cast it.
| Decision | Fund the polypropylene unit at FID? |
|---|---|
| Options | A · full build, two trainsB · stage train 2 · C · defer 12 months |
| Inputs | 6 files, each value traced to its cell, slide or page line |
| Industry pack | v14 · pinned |
| Run | 7f3a…c21e4,000 correlated scenarios · 16 shared factors |
| Digests | Inputs, parameters and output |
| Seed · engine | 4417 · 3.2 |
| Votes | 4 for option A; 1 dissent for option B, with its reasoning |
| Decision | Approved · option A at $264M |
| Tripwire | Reopen if copper rises above $11.2k/t |
| Audit block | #1043 · chained to #1042 |
Illustrative record, matching the player above. Not client data.
Append-only, hash-chained
Each entry in the audit log carries a hash of its own contents and of the entry before it. Change one figure and the hashes stop agreeing. Re-hash that entry and the next one stops agreeing. Rewrite everything up to the head and the head no longer matches the signed checkpoint.
What the chain does not do. It detects edits, deletions and truncation. Someone with privileged access to both the database and the local anchors could still replace the whole history. Signed checkpoints held somewhere independent close that gap; independent custody of checkpoints and RFC 3161 timestamping are on the roadmap.
Illustrative. A short toy hash stands in for the SHA-256 digests Capibud stores.
Votes, dissent and tripwires
The engine produces the ranges. People make the decision. The record keeps both, so that a good decision with a bad outcome can be told apart from a bad decision.
Each member votes with a rationale: approve, approve with conditions, disagree and commit, reject or abstain. Collecting votes before discussion keeps the loudest voice from setting the answer.
Who supported this, and on what grounds?
A dissenting view is stored with its reasoning, beside the alternative it argued for, and stays attached to the decision for as long as the decision stands.
Did anyone see this coming?
Thresholds that reopen the decision if live data crosses them. The brain checks them on every scan; a breach, or a close approach, becomes a proposal to revisit the decision.
When should we look at this again?
When the outcome is recorded, the forecast frozen at decision time is scored against it, and the score feeds the calibration scorecard that later committee packs draw on.
Were our ranges honest?
Every change, the same way
Committee decisions are one kind of change. Re-phasing a project, adding contingency or adopting a brain proposal go through the same path and land in the same record.
Preview
Approve
Apply and undo
Today and next
Capibud is available to design partners as a deployment inside your own environment. We separate what runs today from what is planned.
| Area | Available today | Roadmap |
|---|---|---|
| Audit | Append-only, hash-chained log with verification; signed checkpoints that can be verified with a public key; run replay to an identical result; backup and restore drill | Independent custody of checkpoints, for example a write-once bucket in a separate account; RFC 3161 timestamping |
| Approvals | Preview before every change; maker-checker; approvals re-validated against what the approver reviewed | No change planned |
| Deployment | Runs on hardware or cloud you control, as a single node or container | Managed regional hosting; sovereign and air-gapped pods with customer-held keys |
| Certifications | None yet | SOC 2 Type II and ISO 27001 programme |
Capibud does not move funds or place orders. "Apply" changes a plan inside Capibud and nothing else. More on security and deployment.
Questions auditors ask
How decisions are made is on the capital committee page; how tripwires are watched is on the brain.
Yes. Each engine run stores digests of its inputs, parameters and output, its seed and its engine version, and replays to an identical result. The industry pack and parameters are the versions in force on the day, not whatever is current later.
The question and the options on the table, the run the committee relied on, votes with their rationale, dissent with its reasoning, the alternatives not chosen, and the tripwires that would reopen the decision.
No. The audit log is append-only and hash-chained, so a later change is a new entry, never an edit, and edits, deletions and truncation are detected. Signed checkpoints can be verified with a public key; independent custody and RFC 3161 timestamping are on the roadmap.
No. “Apply” changes a plan inside Capibud and nothing else. Every change is previewed, routed through your delegation of authority, written to the record and can be undone.
A Decision Sprint runs one real decision on your own files in six weeks and leaves you with its full record.