Explain what happened
Trace each warranted outcome to exact inputs, release, rationale, authority, and evidence.
The control layer for product safety
Turn customer-owned activity into explainable Findings, authorised Decisions, and verified reversible action.
Observed at 14:11:19 · causal chain intact
Detection is only the beginning.
Evidence · authority · outcome
Why Jouleyard
Most safety tools stop at a score or an API response. Jouleyard is built for the consequential work in between—and after.
Trace each warranted outcome to exact inputs, release, rationale, authority, and evidence.
Signals inform. Findings explain. Only an authorised path can decide and act.
Acceptance is not confirmation. Reconcile each requested effect against customer state.
Two dangerous leaps
Automation becomes unsafe when an observation quietly becomes authority, or a delivery receipt quietly becomes truth.
Detection can inform an accountable judgement. It cannot make one by side effect.
A provider receipt is evidence of delivery. Only authoritative observation can establish the result.
One accountable loop
Five distinct stages. Four visible boundaries. One causal chain an operator can actually follow.
Customer source
Typed adapters consume the customer’s durable stream. Clean streamed Events are evaluated transiently and leave no Jouleyard product-domain row.
p03 · offset 884,201
Proof, not posture
Data restraint by design
Jouleyard coordinates the safety loop without becoming the system of record for your product. Governed evidence begins only when a suspicious claim warrants it.
Jouleyard product-domain rows
When a Finding is warranted, exact governed evidence and causal links begin—deliberately, not indiscriminately.
Current alpha
The first complete workflow is message safety: evaluate a customer-owned Event against one exact release, retain a Finding only when warranted, authorise a reversible quarantine request, and verify the customer’s real state.
Discuss a design-partner workflow ↗Common questions
Good safety architecture should get clearer under scrutiny.
No. Jouleyard is the governed control layer around detectors and other capabilities. A model may emit a typed Signal; it cannot silently issue a Decision or ActionIntent.
No. Clean streamed Events are evaluated transiently and create no Jouleyard product-domain row. Governed durable evidence begins at Finding unless an earlier bounded purpose is explicitly declared.
Only an authorised deterministic policy or human path may create a Decision. A consequential ActionIntent can follow only from an eligible Decision; detectors, connectors, Joules, and agents hold no hidden authority.
It means an authoritative observation of the customer’s product state matches the requested effect. A successful delivery response alone remains accepted—not confirmed.
Jouleyard is in alpha. The current delivery phase is proving one replay-safe message-safety loop from deterministic authority through reversible quarantine and reconciliation.
Build with boundaries
Bring one real product-safety workflow. We’ll help you make the evidence, authority, effect, and outcome inspectable.