Executive Operating View
Architecture principle
Every operational object is an entity. Every important relationship is typed, time-bound, source-linked, and tenant-scoped. Agents may propose or execute only within explicit policy, and every action produces an evidence record. Counts above are live from /api/entities for the signed-in tenant.
Programs & Geographies
| Program | Region | Owner | Status | Milestones | Outcome |
|---|
People, Volunteers & Donors
| Entity | Type / Role | Detail | Tenant |
|---|
Typed, Time-Bound Entity Graph
Knowledge & Multimodal Ingestion
Ingested records (citable)
Ingest a new record (Program Lead+)
Ingestion writes a citable record and an audit event.
Governed Operations Agent
Finance & Compliance
| Fund | Type | Balance | Control | Evidence |
|---|
Attempt a financial write
Server gate: Executive role + approval flag required. Rejections return 403 and write an evidence receipt you can see in Governance.
Propose → approve workflow (money moves only on Executive approval)
A proposal does NOT move money. An Executive approves or rejects it; approval applies the balance change and writes an evidence receipt.
| Proposal | Fund | Amount | Purpose | Status | Created by | Decision |
|---|
Governance & Audit
Policy gates
✓ Tenant isolation (server-side, token-scoped)
✓ Role-based access (Viewer read-only, 403 enforced)
✓ Time-valid relationships (?at= query-time evaluation)
✓ Human approval for financial writes (FIN-001)
✓ Source-linked AI outputs (CITE-001)
✓ Append-only action evidence (no update/delete routes)
Evidence timeline (live, append-only)
Evidence pack
Tenant-scoped JSON export: entity counts, relationship count, evidence receipts, audit events, and the latest stored proof-suite record.
Build / Buy / Integrate
| Capability | Decision | Reason |
|---|---|---|
| Canonical entity graph | BUILD | Strategic data model and portability layer |
| Identity / SSO | BUY | Commodity security surface; integrate proven provider |
| Fund accounting | INTEGRATE | Do not recreate accounting system of record |
| Donor payments | INTEGRATE | Use existing processor/CRM adapter |
| Knowledge/RAG | BUILD | Governed retrieval across operational domains |
| Agent evidence layer | BUILD | Auditability and policy enforcement are differentiators |
| BI exports | INTEGRATE | Expose APIs/views; avoid dashboard lock-in |
Scale path
Scale by tenant isolation, stateless APIs, queues for ingestion/automation, indexed retrieval, object storage, async workers, and measured hot paths. Avoid premature microservices. (Architecture brief: revival_reference_model/ARCHITECTURE.md. This V2 app is a reference model with synthetic data — not production scale evidence.)
Proof — Adversarial Test Results
HTTP-level tests against the running server: cross-tenant read/write, role 403, expired-vs-historical relationships, financial-write rejection + receipt, uncited-claim rejection. Results below are read from the stored run record (tests/last-run.json) — never faked in the UI. Re-run: node tests/proof-suite.mjs.