The platform

The layer under forward deployment.

Every forward-deployed team builds this system internally — once, under deadline, for themselves. LockedIn Labs FDE is that system built as a product: the client’s operating reality held as a governed asset, workflows and agents designed as reviewable definitions, and a decision plane that governs what may progress through an exact recorded human gate. No production agent or workflow execution is active. Current non-production evidence is limited to one bounded local Proposal Drafter worker and synthetic workflow exercises inside their named local-preview boundaries.

It is a platform, not a service. LockedIn Labs is an implementation company that runs its engagements on it. Why the category has no vendor →

Three planes

What it holds, and what it refuses.

A platform is defined as much by what it will not do as by what it offers. Each plane is listed with both.

Company Chartroom

Understanding is the thing that usually walks out of the building with a departing engineer. Here it is a durable, versioned, permissioned record — the reason engagement nine can start where engagement one finished.

Holds
The client's operating reality as a governed asset: field interviews, approved documents, systems of record, the approval chains, and the exceptions nobody wrote down.
Refuses
Answering beyond its evidence. Every claim carries its source, every gap is named as a gap, and every answer is scoped to what the asking team is cleared to see.

Engineering Studio

Design happens against the validated baseline rather than beside it, so what gets built is traceable to the finding that motivated it and the outcome it was meant to move.

Holds
Integrations, workflows, agent definitions, and model routes as versioned, reviewable records, designed inside the same context that justified them.
Refuses
Granting power. A workflow or an agent acquires no authority to act by existing — a definition is a document until a named human publishes it and the control plane admits it.

Control plane

Today it governs what may progress through recorded human decisions and persists durable Runtime control state. One bounded local Proposal Drafter worker and synthetic workflow exercises exist only inside their named non-production boundaries; neither is production execution. Exact-effect Interlock and independent post-effect Verification remain outside those exercises.

Holds
The current decision plane: versioned definitions, exact review targets, named lifecycle gates, recorded refusals, and the evidence retained with each disposition.
Refuses
Treating a definition as permission to execute, letting an agent be its own judge, or presenting monitoring as independent verification.

Control timing

Three of these can stop something. The fourth cannot.

Most organisations own controls at both ends — something that restricts access before work starts, and dashboards that report after it ships. The gap is in the middle, where the work actually happens, and it is the gap that decides whether an agent is deployable.

  1. Before work begins

    Preventive

    The agent cannot reach what it was never given.

    Can stop it
  2. While work happens

    Inline

    Checked during the work, not after it — with a correction signal, not a report.

    Can stop it
  3. Before release

    Gate

    Nothing ships unverified, and the accountable organization-and-role pair owns the disposition.

    Can stop it
  4. After release

    Continuous

    The last line of defence, and the one most often mistaken for the control itself.

    Detects only

Current implementation boundary. No production agent or workflow execution is active. Current non-production evidence is limited to one bounded local Proposal Drafter worker and synthetic workflow exercises inside their named local-preview boundaries.

Accepted control law. No agent verifies its own output. A verifier is a named, independently owned check with a defined trigger, a defined scope, the authority to block, and a recorded disposition — and the recorded organization-and-role authority owns the disposition, not the agent.

The lifecycle

Every stage leaves something behind.

A stage that produces no durable artifact is a meeting. This is the engagement read as a list of what the client still holds afterwards.

  1. 01DiscoverA validated baseline of the operating reality, with its gaps named
  2. 02DesignAssessed opportunities and the measurement contract each one must satisfy
  3. 03DeliverReviewable workflow and agent definitions, versioned against that context
  4. 04ExecuteBounded pilot charters with success criteria, stop criteria, and a rollback plan
  5. 05AssureIndependent verification and the evidence a reviewer can walk backwards
  6. 06OperateRunbooks, role impacts, and enablement tracks the client's own team runs
  7. 07ImproveOutcome definitions measured against the baseline that justified the work

A recorded session

Watch the tool refuse.

A recorded session against the Meridian engagement — a synthetic regional insurer whose records exist in full and render across every surface of the platform. Nothing on this page is executing.

The operations, the lifecycle states and the refusal codes are the platform's own: the same registry every workspace surface posts to. The command line that types them is specification 11 — designed, not yet shipped. Where the transcript says the server refused, the server refused.

A fake mockup invents the output. This transcript inherits it.

RECORDEDmeridian-client / claims-delivery2026-08-24cs-07bf956d

Open

  1. Exchange 1 — open the recorded session

    sfde open meridian-client

    Completed: session
    cs-07bf956d recording
    operator
    pr-7796de2d fde_lead / manager
    client
    Meridian Mutual Insurance (synthetic)
    workspace
    Meridian claims delivery
    engagement
    Meridian claims transformation engagement
    manifest
    epoch 0 resolved against entitlement ∩ assignment ∩ grant
    transcript
    hash-chained redacted at capture

    recording is a precondition of this command plane, not a feature of it. if the transcript sink is unavailable, commands do not run.

Assess

  1. Exchange 2 — the register board

    sfde status

    • Completed: discoverbaseline_validatedMeridian claims current-state baseline · validated by the accountable client stakeholder role
    • assessmentcoverage_completeMeridian claims operations assessment · 5 of 5 dimensions, accepted scores
    • proposalsclient_acceptedMeridian claims transformation — first delivery wave
    • reportssubmittedMeridian claims operations assessment report
    • strategy2 published · 1 draftoutcome definitions
    • roadmapactive2 items across 2 declared streams
    • workforce2 accepted · 1 runningrole impacts · enablement tracks
    • pilotsmobilizedSingle-capture FNOL intake pilot
    • workflowspublishedSingle-capture FNOL intake workflow
    • agentspublishedSubrogation referral triage assist
    • connectors3 registeredmetadata_discovery

    11 registers read · 0 unreadable

    an unreadable register presents as unknown and never as zero. the line above is how much of what you just read the tool is willing to stand behind.

  2. Exchange 3 — an utterance compiles to a reader, and a human confirms the compiled command

    sfde "where is this assessment weakest, and what holds those scores up"

    Compiled intent: ni-2dafccb2read

    resolves to
    readAssessmentBundle
    plan
    ap-70d9d715 "Meridian claims operations assessment"
    order
    recorded score, ascending
    drawn from
    assessment register · 5 declared dimensions
    confidence
    0.91 — one plan in scope, one scorable ordering

    confirm compiled command [y / edit / n] y

    Completed: recorded score 0–5 · recorded weight 0–100 · nothing derived

    Recorded assessment dimensions, weakest recorded score first
    Dimension keyDimensionScore (0–5)Weight (0–100)
    ai-governanceAI governance1.515
    automation-healthAutomation health1.820
    process-maturityProcess maturity2.225
    workforce-readinessWorkforce readiness2.415
    data-readinessData readiness2.625

    every score above is anchored to accepted, cited observations. a score with no accepted evidence cannot enter this register.

  3. Exchange 4 — the drafting order, printed with the formula that produced it

    sfde proposals draft --explain

    Completed: deterministic ranking · priority = weight × (5 − score) ÷ 5

    Derived drafting priority, highest first
    Dimension keyPriority
    process-maturity14.0
    automation-health12.8
    data-readiness12.0
    ai-governance10.5
    workforce-readiness7.8

    effort, cost and return are not derived. the recommendation carries an explicit unknown and the assumptions it was drafted under.

Decide

  1. Exchange 5 — record the client's decision, refused on authority

    sfde "the sponsor approved the proposal on our call, mark it accepted"

    Compiled intent: ni-719f456aeffect

    resolves to
    proposals.version.transition
    proposal
    pv-b05623d0 "Meridian claims transformation — first delivery wave"
    to
    client_accepted
    drawn from
    proposal register · 1 chain in scope
    confidence
    0.94 — one decision chain, one terminal decision state
    class
    effect · named client act

    effect preview

    Records the client's decision on an immutable proposal version.

    The decision records the accountable client organization-role pair. It cannot be edited;

    a changed decision is a new version in the same chain.

    confirm compiled command [y / edit / n] y

    Refused: refused 403 client_act_route_required

    • callerpr-7796de2dfde_lead / manager
    • routepractitioner action planeclient decision excluded
    • required routeclient act planeproposal.decide

    the generic practitioner route refuses this category before it resolves scope, grants or role. a wider provider grant cannot turn it into a client act.

    the accepted version attributes its recorded act to pr-ef7f7f2f under the stakeholder role in the client organization.

    what happened on the call is not the record. the record is the act.

    the client stakeholder role can record this decision from the client portal. nothing further is required of the provider role.

  2. Exchange 6 — the decision, recorded by the accountable client role

    sfde proposals show pv-b05623d0

    Completed: status
    client_accepted
    decided by
    pr-ef7f7f2f stakeholder, client organization
    decided at
    2026-08-22
    note
    recorded with the decision
    baseline pin
    bs-5af62739 validated at decision time

    the version above is immutable. this session did not write it.

Plan

  1. Exchange 7 — compose a roadmap, refused on structure

    sfde roadmaps compose --from-accepted \

    --stream "Intake modernization" \

    --stream "Claims decision support"

    Refused: refused 409 outcome_not_published

    • item 3Continuous claims-to-policy ledger reconciliation
    • outcome definition od-f9ca25e2status draft

    2 of 3 recorded opportunities carry a published contract.

    a roadmap item cannot exist without a published measurement contract covering exactly its opportunity. a trigger on the table refuses the row as well as the composer does: there is no path that writes it and no flag that skips it.

  2. Exchange 8 — the plan that stands on published contracts

    sfde roadmaps show

    Completed: rm-a44b44f7
    active

    Intake modernization

    • days_30Single-capture FNOL intake across all channels
    • contract od-c5c6eab8published
    • gate Meridian Mutual Insurance (synthetic), through its Claims intake lead role, demonstrates single-capture intake to the client sponsor on live channel volume

    Claims decision support

    • days_90Evidence-linked subrogation referral triage
    • contract od-9956279bpublished
    • gate Referral decisions are recorded on every closure for one full cycle and reviewed by Meridian Mutual Insurance (synthetic), through its Subrogation adjusting lead role
    • depends item 1
    open question
    Catastrophe-surge staffing model is not yet decided

    horizons are categorical (days_30 / days_60 / days_90 / long_horizon). no date column exists on this record, so no date can be invented.

    a plan that carries what it has not resolved is a plan written by someone who has delivered one.

Define

  1. Exchange 9 — compose a workflow definition

    sfde workflows compose --outcome od-9956279b \

    --title "Evidence-linked subrogation referral workflow"

    Completed: wf-17f16b0b
    draft 5 steps · 4 edges
  2. Exchange 10 — compile, refused on craft

    sfde workflows transition wf-17f16b0b --to compile_clean

    Refused: refused 409 write_tool_without_gate

    • stepwrite-referraltool_step · effect write
    • may touchclaims.register.referral
    • no human gate on any path reaching this step

    a step that writes is not compilable until an accountable human-gate role stands before it on every path that reaches it. add the gate, or remove the write.

    one root cause at a time: further diagnostics stay suppressed until this one clears.

  3. Exchange 11 — the gated design, as a new definition

    sfde workflows compose --outcome od-9956279b \

    --title "Evidence-linked subrogation referral workflow" \

    --insert-gate referral-gate --before write-referral \

    --gate-owner "Claims adjusting supervisor"

    Completed: wf-7bf78cb3
    draft 6 steps · 5 edges

    a definition is immutable, so the gated design is a new definition rather than an edit. the ungated one is superseded below, never deleted.

  4. Exchange 12 — retire the ungated draft

    sfde workflows transition wf-17f16b0b --to superseded

    Completed: wf-17f16b0b
    superseded
  5. Exchange 13 — the compiler accepts the gated design

    sfde workflows transition wf-7bf78cb3 --to compile_clean

    Completed: status
    compile_clean
    • referral-arrivedtriggerstarts only from the registered claim-closure review event
    • read-evidencetool_step · readreads the recorded referral evidence for this claim only
    • referral-gatehuman_gatethe accountable claims adjusting supervisor role decides before any write · owner Claims adjusting supervisor
    • write-referraltool_step · writewrites only the referral disposition field
    • verify-referralverificationreads evidence; judges independently
    • referral-recordedoutcometerminal state only
    order pinned
    sha256:6c7a8b9…880d

    every step declares a boundary and what it may touch. the compiler refuses a step that declares neither.

  6. Exchange 14 — send it for review

    sfde workflows transition wf-7bf78cb3 --to in_review

    Completed: status
    in_review
  7. Exchange 15 — approve, refused on accountability shape

    sfde workflows transition wf-7bf78cb3 --to approved

    Refused: refused 409 reviewer_must_differ_from_author

    you authored this version. approval requires a distinct reviewer actor.

  8. Exchange 16 — the published agent definition, and what it may do

    sfde agents show ag-018a9ed5

    Completed: name
    Subrogation referral triage assist
    status
    published
    rung
    ai_assist written justification recorded — a non-null column at every agentic rung
    routes
    1 eligible model route reference strings only
    tools
    1 tool allowlist reference strings only
    boundary
    declared may_touch validated
    delegation
    none
    evaluation
    4 of 4 checks passed sha256:0bd731c…aa34
    authority conferred by this publication
    none

    every check was decided from the definition itself. no model was called, no tool was invoked, no network was touched.

    a published agent definition acquires no power to act. there is no session, no dispatch, no executor and no provider on this path.

Seal

  1. Exchange 17 — run the workflow: no such command

    sfde workflows run wf-7bf78cb3

    No such command: no such command 404 unknown_action

    this registry has no execution verb, at any authority level, for any caller. it is not a permission you lack.

    a published definition is a reviewable record. what would carry it into effect — action intent, exact-effect authorization, a single-use receipt, a governed adapter, independent verification — is designed and is not built. see the truth register.

  2. Exchange 18 — seal the session

    sfde close

    Completed: cs-07bf956d
    sealed

    18 commands · 5 refused · 0 executed against any client system

    transcript hash-chained · available to evidence packages

    no gaps recorded

    a session that cannot be recorded does not run. this one was recorded.

What is real here

  • The operations named are still members of the platform's closed effect registry, alongside the trusted-gateway read bundles every workspace surface uses.
  • Every lifecycle state named below is a state in the shipped contracts, checked against the exported state tuples on every build.
  • Every refusal code was emitted by the shipped gateway during the recording, at the HTTP status the shipped handler pairs with it.
  • Meridian Mutual Insurance is synthetic. Its records are real rows in a real database, rendered across thirteen surfaces.

What is not claimed

  • The sfde command line is specification 11 — planned, not shipped, and the name is not final.
  • Nothing here executed. No workflow ran, no agent acted, no connector connected to anything. The platform has no verb for it.
  • This transcript replays from a file. It does not connect to anything, including us.

Recorded 2026-08-24 against the dedicated synthetic development project qooehvhszmlzlllffwbl by supabase/dev/record-terminal-session.mjs 17 checks, 5 refusals driven for real against the shipped gateway. Schema as of 202608230060_material_chain_locks.sql. The full transcript, on its own page →

Deployment

Four ways it is built to run.

The operating context a forward-deployed team captures is the most sensitive thing it touches, so where the platform runs is a first-class decision rather than a pricing tier.

Every customer deployment model — managed service, dedicated instance, private or VPC, hybrid, client-premises, and licensee operation — remains planned individually and is not purchasable today; none is implied by the public host. The isolated Git-linked FDE host serves the public front door at fde.lockedinlabs.ai, and the exact code-bearing public web release is production-verified; no customer production identity, data, or Storage has been accepted. Access is a scheduled working session on a dedicated environment. Where deployment stands →

  1. Managed serviceA practice that wants the platform without operating it. Planned to isolate each client engagement with separate data, access, and lifecycle.
  2. Dedicated instanceA firm with its own compliance posture. Planned as a tenancy governed by the customer's controls and retention rules.
  3. Client premisesRegulated operations that cannot export context. Planned to run inside the client's own walls so its operating context does not leave them.
  4. Licensed for your practiceForward-deployed teams running their own method. Planned to configure the licensee's phases, gates, and artifacts on the platform.

Questions we get

Asked in the room, answered the same way here.

Is LockedIn Labs FDE a consultancy or a product?
A product. LockedIn Labs is an implementation company that runs its engagements on LockedIn Labs FDE; the platform is a separate thing that other forward-deployed teams can license and run their own method on.
Can we see a demo?
In a scheduled working session under NDA, not as a public trial. There is no self-serve access, because the platform holds client operating context and the method is the intellectual property.
Does the platform let agents act on our systems?
Not on their own. Natural-language intent resolves to a typed, policy-checked operation, and privileged actions stop for an attributable human act; the recorded organization-and-role authority owns the decision. A definition acquires no power to act by existing.
What does our team keep if we stop working with you?
Code in your repositories, configuration, the eval set that defines working, runbooks, and the decision record. Transfer is the point of the method rather than a closing formality.
Can it run inside our own environment?
Not today. Client-premises deployment remains planned and is not purchasable or accepted for customer production. Its target boundary keeps operating context inside the client's walls.

Honest limits

What this page does not claim.

Read this part first if you are evaluating us seriously. We publish what the platform is for; we do not publish customer outcomes, certifications, or benchmark numbers that no one has measured. When a capability is under construction, it is described as such in the briefing rather than implied here.

Request a briefing