Decision provenance for model risk management

The challenge
is the record.

ClisTa is not where model decisions happen. It is where they become defensible — threshold changes, overrides, validation findings, effective challenge recorded as accountable state: evidence, the challenges that survived, sign-off authority, tamper-evident provenance. Not minutes. A sealed, replayable record.

append-only fails closed zero dependencies · Node ≥ 18
clista — a sealed decision, verified
$git clone https://github.com/lati-cooki/clista.git
$python3 gate.py verify # a real run, in the repo
28/28 events · hash chain intact · sealed
iraise-to-900 — gated on measured bad rate · capped · kill-switched
!CHECKER challenge altered the recommendation — witnessed as such
two reservations survived the yes — recorded, not erased
CHAIN VERIFICATION: PASS · 12/12 claims cite their events
Operating law
Conversation is input.
Reasoning state is output.

conversation → event log → projection → verification → accountable state

The lived proof — a real run, in the repo

Marketing wants the fraud threshold raised for the holiday promotion. The answer is not a boolean.

Twenty-eight events encode the full challenge — proposal, attack, concession, revision, seal. The recommendation arrives with its accountability structure fused on: anyone holding the sealed log can reconstruct it, including the model risk committee it goes to.

Evidence cited first

every datum witnessed before use, bound to its writer at event time — no reasoning from thin air.

Challenge altered the yes

the checker's attack forced the maker to withdraw its proposal — named in the revision, not implied.

Concession on the record

an invented assumption withdrawn in writing; the arithmetic that killed it verified by its opponent.

Calculation witnessed

break-even at 11.44% — every number shown, checked by the counterparty, cited by hash.

Reservations 2 survived

the final yes carries both forward — recorded, not resolved away. Confidence the deliberation didn't earn is never assigned.

Seal PASS

12 claims, 12 citations, zero unwitnessed; the chain verifies on any machine, without trusting us.

This run is one act of a longer story: a live swarm served a pre-recession rationale into a recession, the recall path wrote no audit record, and the remediation caught its own documents doing the same thing. Every claim cites its artifact.

Read the case study Verify the sealed thread
Protocol spine

Every capability is a verifiable command that fails closed.

Eighteen layers, each verifying one boundary. Green never means endorsement — every verifier keeps trusted: false until something outside the protocol grants trust.

+ 12 more layers
Integrityintegrity verify
The log is verifiable history, not just readable data.
Continuitycontinuity verify
A successor resumes settled state without replaying the transcript.
Executionexecution verify
Performed action is evidenced under authorized scope — intent ≠ completion.
Outcomeoutcome verify
Observed effect is checked against intended — completion ≠ success.
Provenanceprovenance trace
Each contribution's source lineage and transformation are auditable.
Releaserelease verify
The repository artifact is bound and reproducible.
Now live · app.clista.ai

Run the spine over the real engine — in the browser.

The cockpit drives the same ClisTa engine behind the CLI: ingest a session, watch it project into accountable state, and verify each boundary live. No install, no clone — the event log and every verdict are real.

real engine no install replayable
app.clista.ai
session · dcr_limited_beta live
ingested session → canonical event log23 ev
iprojection → accountable stateok
privacy objection survived the yeskept
byte-identical to committed logpass
evidence · 4 objection · survived authority · 2 reviews
trusted: false clean-room replay PASSED
What the cockpit is

The cockpit is a browser front-end bolted directly onto the ClisTa engine — the same code path the CLI drives. It is not a dashboard that summarizes results after the fact. You hand it a conversation, and it runs the protocol in front of you: the raw deliberation becomes a canonical event log, the log projects into accountable state, and every boundary is verified live. Nothing is mocked — the verdicts you see are the engine's, and the event log behind them is byte-for-byte replayable on your own machine.

1 · Ingest

Conversation in.

Paste or load a session. The cockpit records it as an append-only event log — the canonical history, not a transcript.

2 · Project

Accountable state out.

The log projects into structured state: evidence, surviving objections, authority, provenance — each bound to who and when.

3 · Verify

Every boundary, live.

Each spine layer runs and fails closed. Green never means endorsement — state stays trusted: false until something outside the protocol grants trust.

That loop is universal

Separate motion from verified progress.

1

An agent claimed a milestone was complete.

2

The artifact disagreed.

3

The protocol paused action.

4

Verification restored alignment.

Why model risk management

The regulator already described this artifact.

The April 2026 revised interagency MRM guidance — Fed SR 26-2 · OCC 2026-13 · FDIC, superseding SR 11-7 — asks, in its own words, for what a sealed ClisTa thread is.

The guidance says quote

"an audit trail demonstrating design decisions and their rationale" — the sealed, hash-chained event log, replayable by an examiner who does not trust the vendor.

The guidance says quote

"material modifications … recorded with supporting justification and approval" — a threshold change that arrives as evidence, challenge, concession, and a gated recommendation.

The guidance says quote

"explicit sign-off authority and document approval decisions" — authority bound to participants at event time, dissent preserved past the yes.

The boundaries, stated before the pitch: the guidance is non-enforceable, principles-based — a description of best practice, not a mandate. Generative and agentic AI are explicitly out of its scope (classical ML and algorithmic models are in). ClisTa is not compliance software, and no regulator requires it. The chain proves what was recorded and when — never that the decision was good. And every claim above stays bounded by the independent evidence that has actually accumulated — see the invitation below.

The standing invitation

Independent runs are the evidence we value most.

Decisions we didn't pick, agents we don't operate, results we can verify without trusting the operator — and that you can verify without trusting us. One prompt, pasted into your own agent with a real decision you own, produces a sealed thread that checks mechanically. If your checker changes nothing, or the run falls apart — send that too.

Failed and abandoned runs are wanted evidence. Twenty minutes, start to seal — see the reference run.
What this does not claim
That the format is ready for production use
That internal pilots prove anything
That we have solved governance or agent alignment
A pre-registered gate — the 2026-09-07 EXTERNAL-RUNS gate was retired on 2026-06-19; runs are evidence, not a pre-commitment
chain proves recording · not goodness