How the loop works
Five stages, one data layer, one meter. Everything below the products is shared — identity, audit, delivery, the model gateway — and every product keeps its own database and its own row-level security.
How an exit in your HRMS becomes a line on a CFO's statement
Reads the nightly snapshot under an approved mapping; derives an exit event for one person; records the run and time. Raw rows never leave the reader.
Pulls the change; regretted attrition for that org unit recomputes; a detector notices a three-sigma rise and emits an org-unit signal — never a name.
Resolves a manager cohort under lawful basis; holds 20% back; sends a grounded nudge in Teams; follows up at 30 days; reads lift at 90.
Values the lift with your cost constant, carries the confidence interval, marks it causal, and prints "what we do not claim" beside it.
Python decides. The model writes.
Python decides
- Which column becomes which field — from a closed vocabulary, after a human approves
- Who is eligible for a nudge, and who is held back
- Every number, threshold, randomisation and confidence interval
- The k-floor that withholds a result
- Every rupee on a Value Statement
The model writes
- One short, grounded nudge sentence citing your document
- An answer strung on the clause it came from
- A proposed mapping it is not allowed to execute
- A summary whose numbers are rendered from data, never typed
This is what makes the platform auditable, repeatable and safe to run on employee data. A wrong model output can, at worst, be rejected — never acted on.
Hub upstream, subscribers downstream, ledger beside them
Sangam
Readers for files, SFTP, S3, read-only SQL and vendor APIs. A masked profile goes to an in-VPC model that proposes a mapping; your data owner approves; ingestion is deterministic. One person directory, one consent ledger, lineage on every row.
Three products, own databases
Sutradhar, Gargi and Margdarshak each pull cursor feeds from Sangam into their own store under their own row-level security. No shared tables between products, ever.
Shared services
One identity broker (Google, Zoho, Microsoft Entra), one model gateway with per-tenant routing and an in-region default, one hash-chained audit log per tenant, one delivery service with one frequency cap.