Blueprint
The three agreed diagrams, block by block, with the honest build status of each. This page and the published diagrams read the same source of truth (docs/diagrams/status.json, updated 2026-07-19T18:54Z). A block is only "In production" when it is real and verified live — no mocks count.
Level 1 — A Empresa Agêntica (value chain)
Request intake real (requests page + chat), live.
Mandate triage is model-driven in production (provenance real); heuristic stays as the honest offline fallback.
Every squad agent makes its own real model call in production, individually metered; deterministic executors remain only for offline/tests, always labelled simulated.
Real independent review + human approval gate, live behind the passkey identity.
Delivery package carries genuinely authored content after human approval.
All six house rules real: identidade (passkeys), permissões (mandato+gates), custos (medição real+caps), risco (triage real), qualidade (revisor real+evals), auditoria (ledger+API).
Real roles×effort pricing (metered); deterministic arithmetic verifier always runs.
Real legal consultation (GDPR/Lei 58/2019, minors, IP) layered on the static guardrail.
Real staffing/team-design consultation via consult_specialist.
Real feasibility/architecture consultation layered on the static guardrail.
Real analysis with REAL URL ingestion via Gravit MCP extract; refuses to invent when a source is empty.
Real procurement consultation (build-vs-buy, licences, exit clauses).
Real QA consultation (acceptance criteria, test strategy, AI evals).
Real security consultation (passkeys, vault custody, prompt injection).
Tasks, runs, chat — real and live.
Artifacts with immutable version history — real and live.
WebAuthn passkeys live; owner passkey REGISTERED and verified in production (2026-07-19). Every spend/approval requires an owner session.
Namespaced memory + write gate + EMBEDDED hybrid search (pgvector, gte-small); agents recall prior memory before authoring.
Registo canónico: 8 agentes + 8 skills + 4 workflows + 9 políticas + 16 tools, drift bloqueado pelo validador. Cresceu com o Study Generator (agent.study-author) e o par Brand Designer/Designer do brand-book.
Costs page: real vs simulated, actual tokens, per-case totals; /api/company/costs for machines.
Global audit page + per-case ledgers + machine-readable /api/company/audit.
Approval gate + workflow engine real and live.
8 policies enforced in code + validator; Governance page live (limits, spent-today, switches); caps are owner-only env changes.
Level 2 — Anatomia da Squad
Solution Architect designs for real (per-run metered).
Business Analyst authors for real (per-run metered).
O workflow brand-book agora staffa design a sério: Brand Designer (estratégia + sistema visual) e Designer (artwork final — wordmark/monogram/favicon SVG, real, sem paid API) fazem chamadas reais de modelo, cada uma com o seu revisor independente.
Sem workflow atual que a exija — idem: real quando houver trabalho operacional a atribuir.
O Concierge É a função de suporte ao cliente: porta de entrada real (Claude tool-loop), acompanha e resolve em produção.
Skill cognitive-modes (5 modos / heterónimos de Pessoa) INJETADA em todos os prompts reais — 4 agentes + 8 especialistas; cartão canónico referenciado pelos agentes.
Approvals UI real; gains WebAuthn identity in P1.
Independent reviewer is a separate real model call; critical findings block approval; remediation loop live.
Models, memory, MCP toolbelt and 8 specialists all live.
Level 3 — Arquitetura tecnológica
Web cockpit + M2M read API /api/company/* (machine token from the Vault, or owner session).
Formal mandate + real model classification live.
Claude tool-loop concierge REAL in production, metered, behind the passkey spend gate.
Motor determinístico com 4 workflows canónicos (proposta comercial + research brief + brand book + study generator), paridade STEP_ORDER validada. Study generator: pesquisa real (arXiv + Semantic Scholar) → síntese narrativa → deck + site + simulador explicável, revistos como estudo (não como proposta).
Canonical cards + engine registry, drift-blocked by validator.
Analyst, architect, writer and reviewer are real LLM agents with per-run real costs; E2E: $0.60/case, remediation loop live.
Gravit MCP connector live (95 tools), health-checked on the Connectors page; real ingestion proven. Generic Connector Factory (2026-07-19) adds non-MCP connectors from the Cofre credential index — Replicate/FLUX scaffolded first, stays not_configured until the owner delivers REPLICATE_API_TOKEN.
8/8 specialists real: 3 embedded in the workflow, all reachable via the concierge, each individually metered.
Memory real + embedded; hybrid recall feeds the real agents.
Hybrid search live: parametric filters + vector ranking (match_agentic_memory on thlq).
Durable Supabase replica (snapshot write-behind + restore-on-boot) + embedded memory tables; JSON file on the volume stays the fast primary. Secrets canonical in the Vault.
Identity (passkeys), memory write gate, spend gate AND hard budget caps (per-case/per-day) enforced before every real call.
HITL gate live with the owner's biometric identity registered — approvals and spend are owner-session-only. Owner Autonomy Mode (2026-07-19): an optional passkey-signed Owner Warrant can auto-approve gates for 7 days; never bypasses the .run/STOP tripwire, budget caps, or unresolved critical findings. Inert until the owner signs one.
Real metering + enforced budget caps + x402 accept-side ready behind default-OFF flag.
Ledger + runs traced per case, global audit view, M2M audit endpoint.
Golden-case eval harness with recorded runs (docs/evals/EVALS.md): first run caught a real pricing defect; after the fix 7/7 PASS, reviewer 88/100.