1. Home
  2. Product
  3. Decision record

Decision record

Every decision, replayable years later.

What the committee knew, what it chose, who disagreed and what would reopen it, stored with the run it relied on. The log is append-only and hash-chained, and every engine run replays to an identical result. When someone asks why a project was funded, the answer is already written down.

DECISION RECORD · APPEND-ONLY ILLUSTRATIVE #1041Industry pack v14 hash 3e0b… prev a91f… #1042Run · seed 4417 hash 7f3a… prev 3e0b… #1043Vote · approved 4–1 hash c55d… prev 7f3a… #1044Tripwire armed hash 0b72… prev c55d… REPLAY · TWO YEARS ON 7f3a…c21e Same inputs✓ Same seed4417 Same engine3.2 Identical result

Available today. Each engine run stores digests of its inputs, parameters and output, its seed and its engine version, and can be replayed to an identical result. Signed checkpoints can be verified with a public key.

What a record holds

The decision, and everything it rested on

Minutes say what was decided. A Capibud record also keeps what the committee was looking at when it decided, so the decision can be re-examined on its own terms rather than with hindsight.

01 · The question

What was asked

The decision as framed, the options on the table, the envelope and the risk appetite the committee set.

02 · The run

What it relied on

Digests of inputs, parameters and output, the seed, the engine version and the industry pack version pinned to the decision.

03 · The choice

Who decided what

Votes with their rationale, dissent with its reasoning, conditions, and the alternatives the committee did not choose.

04 · The watch

What reopens it

Tripwires: thresholds that reopen the decision if live data crosses them, checked by the brain on every scan.

One decision, four beats

Frame, simulate, decide, replay

An illustrative sanction decision from the question to the replay two years later. Double-click any figure for its details.

How the committee decides

Illustrative decision. The figures are not taken from a client project.

Anatomy of a record

One page that answers "why did we do this?"

This is the record behind the decision in the player above. Every line points somewhere: a value to its cell, slide or page line, a run to its digests, a vote to the person who cast it.

  • Pinned, not live. The industry pack and parameters are the versions in force on the day, not whatever is current when someone looks.
  • Alternatives kept. The options the committee did not choose stay in the record with the run each relied on.
  • Nothing overwritten. A later change is a new entry in the chain, never an edit to an old one.
Decision record illustrative
DecisionFund the polypropylene unit at FID?
OptionsA · full build, two trainsB · stage train 2 · C · defer 12 months
Inputs6 files, each value traced to its cell, slide or page line
Industry packv14 · pinned
Run7f3a…c21e4,000 correlated scenarios · 16 shared factors
DigestsInputs, parameters and output
Seed · engine4417 · 3.2
Votes4 for option A; 1 dissent for option B, with its reasoning
DecisionApproved · option A at $264M
TripwireReopen if copper rises above $11.2k/t
Audit block#1043 · chained to #1042

Illustrative record, matching the player above. Not client data.

Append-only, hash-chained

Try to change the past

Each entry in the audit log carries a hash of its own contents and of the entry before it. Change one figure and the hashes stop agreeing. Re-hash that entry and the next one stops agreeing. Rewrite everything up to the head and the head no longer matches the signed checkpoint.

What the chain does not do. It detects edits, deletions and truncation. Someone with privileged access to both the database and the local anchors could still replace the whole history. Signed checkpoints held somewhere independent close that gap; independent custody of checkpoints and RFC 3161 timestamping are on the roadmap.

  1. #1040The interactive chain needs JavaScript.

Illustrative. A short toy hash stands in for the SHA-256 digests Capibud stores.

Votes, dissent and tripwires

A record of judgement, not only of numbers

The engine produces the ranges. People make the decision. The record keeps both, so that a good decision with a bad outcome can be told apart from a bad decision.

Independent votesBefore discussion

Each member votes with a rationale: approve, approve with conditions, disagree and commit, reject or abstain. Collecting votes before discussion keeps the loudest voice from setting the answer.

Who supported this, and on what grounds?

DissentKept, not minuted out

A dissenting view is stored with its reasoning, beside the alternative it argued for, and stays attached to the decision for as long as the decision stands.

Did anyone see this coming?

TripwiresWatched by the brain

Thresholds that reopen the decision if live data crosses them. The brain checks them on every scan; a breach, or a close approach, becomes a proposal to revisit the decision.

When should we look at this again?

Outcome scoringWhen the result is known

When the outcome is recorded, the forecast frozen at decision time is scored against it, and the score feeds the calibration scorecard that later committee packs draw on.

Were our ranges honest?

Every change, the same way

Preview, approve, apply, undo

Committee decisions are one kind of change. Re-phasing a project, adding contingency or adopting a brain proposal go through the same path and land in the same record.

Preview

  • Every change is previewed before it is applied.
  • The apply is bound to the exact preview a person saw.
  • If the plan has moved underneath it, a fresh preview is required.

Approve

  • Routed by your delegation-of-authority matrix.
  • Maker-checker, escalation and cumulative-change rules.
  • Approvals re-validated against what the approver reviewed.

Apply and undo

  • The final approval applies the change.
  • The change is written to the append-only record.
  • It can be undone, and the undo is recorded too.

Today and next

What is available now, and what is on the roadmap

Capibud is available to design partners as a deployment inside your own environment. We separate what runs today from what is planned.

AreaAvailable todayRoadmap
AuditAppend-only, hash-chained log with verification; signed checkpoints that can be verified with a public key; run replay to an identical result; backup and restore drillIndependent custody of checkpoints, for example a write-once bucket in a separate account; RFC 3161 timestamping
ApprovalsPreview before every change; maker-checker; approvals re-validated against what the approver reviewedNo change planned
DeploymentRuns on hardware or cloud you control, as a single node or containerManaged regional hosting; sovereign and air-gapped pods with customer-held keys
CertificationsNone yetSOC 2 Type II and ISO 27001 programme

Capibud does not move funds or place orders. "Apply" changes a plan inside Capibud and nothing else. More on security and deployment.

Questions auditors ask

Before the first review

How decisions are made is on the capital committee page; how tripwires are watched is on the brain.

Can a past decision be replayed?

Yes. Each engine run stores digests of its inputs, parameters and output, its seed and its engine version, and replays to an identical result. The industry pack and parameters are the versions in force on the day, not whatever is current later.

What does a decision record hold?

The question and the options on the table, the run the committee relied on, votes with their rationale, dissent with its reasoning, the alternatives not chosen, and the tripwires that would reopen the decision.

Can the record be edited after the fact?

No. The audit log is append-only and hash-chained, so a later change is a new entry, never an edit, and edits, deletions and truncation are detected. Signed checkpoints can be verified with a public key; independent custody and RFC 3161 timestamping are on the roadmap.

Does Capibud move funds or place orders?

No. “Apply” changes a plan inside Capibud and nothing else. Every change is previewed, routed through your delegation of authority, written to the record and can be undone.

Make your next decision replayable.

A Decision Sprint runs one real decision on your own files in six weeks and leaves you with its full record.

Talk to us →