Pelayo OS · Decision Provenance Operating System
226
Governed decision protocols
L0–L6
Accountability stack
Model‑agnostic
Architecture
4h / 24h / 72h
Revalidation SLAs
01Why now

Your AI makes thousands of decisions. Can you prove any of them?

Regulators are asking. Boards are liable. Courts are ruling. The EU AI Act, SEC disclosure rules, and sector-specific guidance all converge on one question: “Why did your AI make that decision, and can you prove it was made correctly?”

Most organizations have:

  • AI models running decisions
  • Data pipelines feeding them
  • Workflows executing outputs

What they don't have:

  • × An audit trail from input to accountability
  • × A decision ledger that holds up under scrutiny
  • × A governance layer that outlives the model

The gap is not AI capability.

The gap is Decision Provenance.

02What is decision provenance

Not model governance. Decision governance.

Model governance asks: “Is the model fair, accurate, and safe?” Decision provenance asks: “Can you reconstruct every step, from the data that entered to the person who is accountable, and prove it was valid at the time?”

Pelayo OS wraps every AI-driven decision in a seven-layer governance stack:

  1. L0

    Truth

    What data was used? Where did it come from? When was it last validated?

  2. L1

    Model

    Which reasoning engine rendered the decision? Is it the right tool for this class?

  3. L2

    Tools

    What systems executed it? APIs, workflows, integrations?

  4. L3

    Context

    What governance rules, skills, and constraints were active?

  5. L4

    Harness

    How was the decision orchestrated? Agents, loops, orchestration?

  6. L5

    Ops

    What did it cost? What was the latency? Were there anomalies?

  7. L6

    Accountability

    Who approved it? What is the evidence chain? Who is liable?

L0 is what the decision knew. L6 is who owns it when it goes wrong.”

Can you prove your last 10 AI decisions?

Our 48-hour Decision Provenance Audit maps your current AI decision landscape and identifies where your evidence chains break.

Start the audit, €2,500, fully credited toward implementation →
03How it works

Seven layers. One decision. Zero ambiguity.

Every decision governed by Pelayo OS passes through seven layers, from the raw truth of the inputs to the immutable accountability of the ledger.

  1. L0

    Truth — Decision Inputs

    “What did the decision know?”

    • Data provenance & lineage
    • Freshness validation
    • Source authority scoring
    • Bias & quality gates

    Output: A certified input package, every datum tagged with origin, age, and trust score.

  2. L1

    Model — Decision Engine

    “What reasoned the decision?”

    • Model selection by decision class
    • Capability enforcement (Code Execution + Extended Thinking where required)
    • Interchangeability without governance loss
    • Version locking & drift detection

    Output: The right model, for the right decision, with the right constraints.

  3. L2

    Tools — Decision Instruments

    “What executed the decision?”

    • MCP, APIs, integrations
    • Tool authorization & scope
    • Execution logging
    • Failure & fallback protocols

    Output: A complete instrument record, every tool invoked, every parameter passed.

  4. L3

    Context — Decision Rules

    “What governed the decision?”

    • Active skills & protocols
    • Synapse map (rule dependencies)
    • Governance constraints
    • Jurisdiction-specific rules

    Output: The rule context at the moment of decision, frozen and hash-signed.

  5. L4

    Harness — Decision Execution

    “How was the decision orchestrated?”

    • Agent loops & workflows
    • Human-in-the-loop gates
    • Cost-per-task routing
    • Execution trace

    Output: A full orchestration log, who did what, when, in what order.

  6. L5

    Ops — Decision Telemetry

    “What did the decision cost?”

    • Token & compute cost tracking
    • Latency & throughput metrics
    • Anomaly detection
    • Cost-drift alerts (7-day / 30-day rolling)

    Output: Operational intelligence, every decision measured, every trend flagged.

  7. L6

    Accountability — Decision Ledger

    “Who owns the decision?”

    • RBAC & approval chains
    • Evidence registry
    • Hash-chain immutability
    • Decision owner & liability mapping

    Output: An immutable ledger entry, defensible in court, legible to a board, auditable by a regulator.

04Governance velocity

Decisions have half-lives

A decision without an expiration date is a liability without a horizon. Pelayo OS assigns every decision a half-life based on its stakes.

Decision classHalf-lifeExamplesRevalidation SLA
Strategic180 daysM&A, board resolutions, capital allocation72 hours
Operational90 daysCredit approval, hiring, procurement, clinical support24 hours
Tactical30 daysRouting, scheduling, content moderation, inventory4 hours
Decision Rendered → Evidence Logged → Validity Clock Starts

Trigger Detected (regulatory change / model drift / incident / policy update)

Revalidation Required → Quarantine / Patch / Sunset

Triggers include: regulatory or policy changes, model drift or performance degradation, cost anomalies or telemetry thresholds, human override or incident escalation, scheduled expiration.

“Time is not a bug in governance. It is the feature.”
05Model-agnostic by design

Swap the engine. Keep the governance.

Claude today. Kimi tomorrow. GPT-5 next quarter. Pelayo OS decouples the decision from the model. Change L1 without losing L0–L6. Your governance layer persists. Your accountability endures.

Supported integrations:

  • Claude (Anthropic), primary
  • Kimi (Moonshot AI)
  • OpenAI GPT models
  • Local / self-hosted models
  • Custom reasoning engines
Architecture at a glance
BUILT FOR SCALE, HARDENED BY DESIGN

226+ governed decision protocols across 6 domains.

HMAC-signed immutable state logs, tamper-evident by default.

Red Team hardened, every protocol stress-tested for failure modes.

Cost governance: unit-cost mandate, context budgets, vendor subsidy hedges.

FRACTAL L0/L1/L2: every protocol has entry, execution, and mastery tiers.

Hash-chain enforcement, every decision linked to its predecessor.

See the stack in action

Book a 30-minute architecture walkthrough. We'll map one of your high-stakes decisions through L0–L6 and show you where your current gaps are.

06Use cases

Decisions that demand provenance

If an AI decision affects a person's livelihood, health, freedom, or capital, it needs a trail.

FINANCIAL SERVICES

Credit, Compliance, Capital

  • Credit Decision Provenance — why a loan was denied, what data, what fair-lending rules, what model version. Reconstruct in 90 seconds.
  • AML Alert Triage — what threshold triggered the flag, what logic was applied, who reviewed. Full chain of custody.
  • Trading Algorithm Governance — what strategy was active, what kill-switch rules, what was the decision chain before the market event.
Buyer: CRO, Head of Compliance, CFO
HEALTHCARE

Clinical, Operational, Ethical

  • Clinical Decision Support — why the AI recommended a treatment, what guidelines, what contraindications, what human override.
  • Prior Authorization — what criteria were applied, what evidence was required, what was the appeals path and timeline.
  • Quality & Safety Monitoring — what protocols were active during the adverse event, what decisions led to the outcome.
Buyer: CMO, Quality Director, Chief Compliance Officer
LEGAL & REGULATORY

Contracts, Filings, Liability

  • Contract Review AI — what clauses were flagged, what precedent was cited, what risk score and confidence level.
  • Regulatory Filing Preparation — what sources were used, what regulation version, what validation steps, what sign-off chain.
  • Litigation Support — can you produce the decision record the court requested, in what format, with what integrity guarantees.
Buyer: General Counsel, Chief Compliance Officer, External Counsel
PUBLIC SECTOR

Eligibility, Permitting, Enforcement

  • Benefits Eligibility — what rules engine was used, what data sources, what human override, what appeal rights were preserved.
  • Permit & Licensing Decisions — what criteria were evaluated, what documentation was required, what was the timeline, who approved.
  • Enforcement Actions — what evidence triggered the action, what discretion was applied, what review process followed.
Buyer: Public Sector CIO, Agency Director, Legal Affairs
SUPPLY CHAIN & OPERATIONS

Procurement, Routing, Risk

  • Vendor Selection — what scoring model, what due diligence data, what conflict-of-interest checks, what approval tier.
  • Inventory & Routing Decisions — what demand signal, what constraint logic, what cost optimization rules, what disruption response.
  • Sustainability & ESG Compliance — what standards were applied, what audit trail, what certification status.
Buyer: VP Supply Chain, Chief Procurement Officer, COO
HUMAN CAPITAL · PROVEN DOMAIN

Pay, Equity, Workforce

  • Pay Equity Analysis — what data was used, what methodology, what regulatory version, what was the remediation decision.
  • Workforce Planning — what scenario models, what business assumptions, what stakeholder input, what approval chain.
  • EUPTD Compliance — what pay transparency rules, what RTI request pipeline, what inference-attack prevention.
Buyer: CHRO, Total Rewards Director, HR Compliance Lead
07FAQ

Questions we get asked

Do we need to replace our existing AI models?
No. Pelayo OS wraps around any model, Claude, Kimi, GPT, or custom. The governance layer is independent of the reasoning engine.
How long does implementation take?
Most organizations see their first governed decision protocol live within 2 weeks. Full L0–L6 coverage across 2–3 domains typically takes 6–8 weeks.
Is this only for large enterprises?
No. The Essential package (€299) is designed for teams with one critical decision domain who need provenance without enterprise overhead.
What regulations does this help with?
EU AI Act, GDPR Article 22 (automated decision-making), SEC AI disclosure rules, and sector-specific guidance: finance (CRD/CRR, MiFID II), healthcare (FDA AI/ML guidance), and others.
Can we integrate with our existing GRC or audit tools?
Yes. L6 outputs are designed for ingestion into GRC suites, SIEMs, and board reporting platforms via API.
What happens when a decision expires?
The Governance Velocity protocol triggers revalidation. The decision enters quarantine, is patched with updated rules and data, or is sunset with full audit trail.
The question every board will ask

“If a regulator, a judge, or a board member asks you why your AI made a decision that affected a person's livelihood, their health, or their capital, can you prove it was the right decision, made the right way, by the right rules, at the right time, with the right accountability?”

Pelayo OS is the only answer that starts with:

“Yes. And here is the evidence chain.”