⌂ Home · ◂ Agentic · CFO Doctrine · Portfolio Verifier

CFO Doctrine · Full Portfolio Verifier

Meta-dashboard for all 13 synthetic cases across the 9-layer CFO doctrine map + 3 meta-skills. Fires each in order, captures sealed hash + verdict + recall, verifies UI page renders.
Layer coverage: 1 · 3 statements as system (APEX) · 2 · Frameworks (SPECTRUM) · 3 · Ratios / peers (OMNI + TRINITY) · 4 · Q-of-E forensics (AURELIA + MERIDIAN + TRINITY) · 5 · Consolidation (CASCADE) · 6 · Cross-border tax (GLOBAL) · 7 · Capital / liquidity (PILLAR) · 9 · Contagion / network (NEXUS). Plus governance (SENTINEL), macro-context (ATLAS MACRO), services P&L (SERVICE).
Cases fired
0/13
of 13 synthetic cases
Verdict · PASS
0
recall + FP + INDETERMINATE all pass
Verdict · PARTIAL
0
recall borderline
Verdict · FAIL
0
investigate immediately
Byte-determinism
rerun sealed hash match

Per-case scorecard

#CaseLayer / PVerdictRecallAmount bandFP refusalINDETERMINATEGraph · entities / eventsBrain (dry-run)Sealed hashUI

Brain promote WORM ledger (KOKON→ARIN payload attempts · since service restart)

Two independent sweeps run on page load: dry-run validation, then live promotion. Counters below reflect the in-memory WORM ledger since the KOKON process last restarted; ARIN's server-side ledger holds the full history.
Dry-run sweep · contract validation
Cases dry-run
Dry-run PASS
Dry-run FAIL
Live sweep · promotion to ARIN Brain
Cases live-fired
Endpoint missing
Accepted (contract-clean)

Read-filter sweep (AG-36 · CONTRACT_CLEAN default)

KOKON's brain client default-drops any edge whose fact_status ≠ CONTRACT_CLEAN so the r1 WITHHELD lane never surfaces in downstream reads. This strip samples a depth-1 /neighborhood on each of 13 case nodes, then reports edges kept vs dropped by the client-side filter. Drift signal: non-zero drops on a supposedly r2-only tenant.
Cases sampled
Edges surfaced (raw)
Edges kept (CONTRACT_CLEAN)
Edges dropped (r1 / no status)
Contract-clean %

SLO status (F3 · rolling p50 / p95 / p99 per critical endpoint)

Rolling 500-sample window per endpoint. Green = within budget · red = breach · slate = under min-sample threshold (20). Live drift signal for latency degradation before an SLA breaches.
Overall
Targets total
OK
Breached
Not verifiable
EndpointSamplesp50 msp95 msp99 msp95 budgetVerdict

Brain gateway status (ARIN ontology-query v1)

…probing…

Realized case outcomes (R1-R3 · hit-rate vs sealed predictions)

Every closure records realized verdict vs the sealed model prediction. Hit rate = % where realized matches predicted. Also writes CASE_OUTCOME_REALIZED to the gov ledger so the outcome enters the tamper-evident chain.
Total closures
Hit rate
Matched
Missed
Closed · 7 d

Governance ledger (G1-G3 · hash-chained · tamper-evident)

Append-only ledger for privileged operations (backups, secret rotations, chaos drills, ARIN contract runs). Each row's sealed_hash chains to the previous. The verifier walks the whole chain — any tamper breaks it. Regulator evidence surface for Wave 7.
Chain
Total rows
Verified rows
Last event
Last kind
SeqTimestampKindActorOutcomeExternal ref

Brain freshness (B5 · ARIN generated_at SLI)

How stale is the ARIN-side brain data? Read from Counts.generated_at every 5 min. FRESH < 6 h · AGING < 24 h · STALE ≥ 24 h. Independent from uptime — brain can be up but serving old data.
Verdict
Age
generated_at
Consecutive fails

ARIN passive health beacon (B3 · 60 s cadence · 1 h ring)

Background ticks the gateway every 60 s and stores the last 60 outcomes. Uptime % is a cheap upstream health signal without polling from the browser. Red = ARIN unreachable this window; green = live and responding.
Configured
Samples
Uptime %
Last success
Last error