Digital
Engineering GeneratedSpec proposes a PR. Serious SaaS Mode requires CodeIndexReceipt, CodeImpact, affected tests, CI, rollback, and closure diff within write_set.
HELM AI Enterprise
HELM reads company and code work, finds gaps, drafts specs for review, routes approved actions through PEP/CPI, writes proof back, and summarizes recurring Night Shift work without making the report source truth.
Operating loop
Recurring operation
Low-risk allowlisted work can run only inside explicit policy. Risky work escalates. Forbidden work denies. Simulator-labeled physical gateway examples stay labeled as simulator proof.
Engineering GeneratedSpec proposes a PR. Serious SaaS Mode requires CodeIndexReceipt, CodeImpact, affected tests, CI, rollback, and closure diff within write_set.
Support proposes a bounded refund. Small allowlisted refunds may ALLOW with receipt; high-risk refunds ESCALATE; forbidden refunds DENY.
AMR mission gateway receives a simulator-labeled mission. Missing safety profile DENYs; approved mission needs safety, telemetry, emergency halt readiness, and command/outcome receipts.
Concrete example
| Stage | What changes |
|---|---|
| Artifact | A customer promise and a release ticket disagree about what will ship this week. |
| Review item | HELM emits a TruthConflict so a human can decide whether the gap matters. |
| Draft | A GeneratedSpec proposes the release-note update, owner, tests, approval, and proof need. |
| Boundary | The approved action crosses CPI and PEP before any issue, PR, or message is dispatched. |
| Receipt | The final decision records policy, approval, action payload, and closure evidence. |
Authority rule
Query answers, drift labels, and GeneratedSpecs stay proposals until reviewed, approved, and routed through HELM.
All side-effectful action crosses PEP/CPI and produces receipts.