Development evidence · 30 August 2026

Built is not the same as available.

This page records what the current build of Lagstyr demonstrably does, what still needs proving in a real installation, and the gates — in order — between here and a first customer. Every claim is dated, and nothing on this page is a promise about timing.

How to read our labels

Four labels, used the same way everywhere.

We use status language narrowly, so a technical achievement never becomes an availability claim by implication. Every status label on this site means exactly one of these four things.

Built & lab-tested

Works end to end on controlled test data

The capability exists in the product code, is covered by automated tests, and has been run through complete journeys — but on synthetic data we control, not a customer's.

Built, not yet proven live

Exists in code; the proof needs a real installation

The capability is built, but its most important evidence — running in a real deployment, against real outside systems, on a real buyer's documents — has not happened yet.

Planned

Designed, not built

The intent and often the specification exist. The code, or the proof, does not.

Not available

Nothing to install, trial, or buy today

No installation, hosted environment, trial, pilot, demo, or production support is currently offered — full stop.

Latest evidence milestone · 29 August 2026

Contract documents reach governed work through visible, bounded stages.

This is our own lab evidence, run by us on synthetic data. It shows the capability works and refuses correctly. It is not a customer's documents, a live connection to a customer's systems, or an independent assessment.

Input

A realistic, reproducible test set

102 synthetic documents we generated and hold all rights to — 727 PDF pages across 13 document types. We hold 26 documents back from tuning, and we record the correct answer for every page, field, and search in advance, so results are scored against a fixed answer key rather than judged after the fact.

Observed

Document reading stays inside hard limits

100 of the 102 documents index through the production path. All 118 scanned, image-only pages are read by text-recognition software inside the installation — nothing is sent to an outside service. The two remaining documents (one over the page limit, one an unsupported file type) are rejected outright rather than half-processed.

Observed

Extracted contract terms keep their receipts

23 indexed supplier contracts each yield the expected renewal date, notice period, obligations, and automatic-renewal risk — and every extracted value points at the exact passage of the source document it came from.

Observed

Extraction never becomes company record by itself

The AI can propose; only a person can make it official. When a reviewer accepts a proposal, everything in it is recorded in one step or not at all. Documents that are unsigned, unreliable, contradictory, or ownerless are refused whole — nothing is half-recorded.

Observed

The operator can see the whole journey

The console joins the evidence, the human decision, the scheduled work, the outward action, and the measurement — without inventing progress. Where a number has no evidence yet, it is shown as not configured, never rounded up into success.

Built, not yet proven live

What this milestone does not prove

A real buyer's documents and their review, a live round trip into a supplier's actual system, a provisioned installation, and observed production operation. Those proofs belong to the gates below.

Evidence log

Dated entries, newest first.

Each entry records something that was proven, with its date. Expect new entries roughly monthly while development continues — if this log goes quiet, read the silence as information.

29 Aug 2026

Contract-to-governed-work milestone

The evidence above: bounded document reading, extraction with exact sources, human-only promotion to record, and inspectable journeys, on the frozen 102-document test set.

27 Aug 2026

Mutation-testing sweep completed

Faults were deliberately injected across the authority chain and the governed surfaces that reach it — the code where a missed fault matters most — to test whether the test suite notices. Every surviving mutant was individually examined and recorded in a written ledger — including one wrong entry, kept struck-through rather than deleted.

18 Aug 2026

Clean-room launch proof

The full installation launch journey was run end to end in an isolated environment, by us, from documented steps and a reproducibly built install kit. The exercise also caught a broken release-publishing pipeline — that finding is in the record, which is the point of the exercise.

The foundation

The foundation is substantial — and heavily checked.

These capability groups exist in the product code today. Behind them sit more than 4,500 automated tests, deliberate fault-injection (mutation) testing with a written disposition ledger, properties proved over the entire risk-routing space (every tier enumerated, not sampled), and a release gate with named human approvers — one that has already refused a release, which is the control working.

built & lab-tested

Management record

Stable identity for people, companies, agents, suppliers, and contracts; documents with their sources and history; decisions, obligations, reports; retention, governed deletion, and legal holds.

built & lab-tested

Authority kernel

The core service every action must pass through: who may act, in what scope, within which limits; the T0–T3 autonomy ladder; approvals, conflict checks, separation of duties, emergency stop and restore.

built & lab-tested

Operator surface

Queues that bring work needing judgement to the right person, decision cards that carry the evidence with the proposal, registers, exceptions, and management reporting.

built & lab-tested

Agent work loop

Agent runs, tasks, proposals, and approvals — with every change to prompts, skills, and models going through the same explicit approval as any other material change.

built, not yet proven live

Effect verification

Actions on outside systems are precisely defined, safe to retry, and checked after the fact: the owning system is read back to confirm what actually changed, and differences are reconciled rather than assumed away.

built, not yet proven live

Measurement and learning

Costs, benefits, and outcomes measured against the decision that authorised the work — with exact definitions beside every number, so wider autonomy is an evidence-based decision.

Built, not yet proven live

What still needs a real installation to prove.

These exist in code or in supported specifications. Their most important proof requires a provisioned deployment, live outside systems, or a real buyer's data — none of which has happened yet.

Built, not yet proven live

Customer-controlled deployment

The installation design, isolation model, operations material, and backup-and-restore paths exist and are rehearsed in isolated environments. The first real installation has not been provisioned.

Built, not yet proven live

Connections into outside systems

Several governed write-back connections are built or partly built. None is commissioned against a real customer environment, so none is presented as an available connector.

Built, not yet proven live

Real-world document fitness

PDF and scanned-image reading, bounded English text recognition, and supplier-contract extraction are proven on our synthetic test set. A real buyer's documents — with their mess, their languages, and their owners' review — are not yet.

Built, not yet proven live

Operating value

The outcome view and its calculation definitions are built. Time, cost, quality, and benefit claims stay switched off until a real installation records the evidence they require.

Built, not yet proven live

Operational characteristics

Capacity, availability, upgrade behaviour, and support response can only be proven by running deployments under real load, over time.

The path to availability

What happens next, in order.

Each gate opens on evidence, not on a date — so we publish the sequence and the conditions, and deliberately no schedule. This is the same rule our own operating guide prescribes: every gate is evidence, not a date.

  1. 01

    Proving installation

    Provision the first real deployment — our own group’s, in its own cloud — from the completed installation specification, and operate it: restore drills, upgrades, and real load. The specification is finished; provisioning is deliberately held until the build is complete.

  2. 02

    Design-partner pilot (Gate A)

    A small, controlled pilot with a handful of companies. Admission requires the privacy, security, and data-handling gates to pass before any customer document enters the system. Admission criteria will be published here when the gate opens — and registered interest is how we will find candidates.

  3. 03

    Proven continuity (Gate B)

    Today the only availability promise an installation may make is: one server, restorable from backup — the installer refuses any configuration claiming more. Contracted continuity is offered only after it has been demonstrated, not before.

  4. 04

    Supported general release

    No newer build becomes the supported release until independent off-site recovery evidence exists; newer builds publish as candidates only. (The currently pinned version predates that gate — it is grandfathered, not proven recoverable, and we say so plainly.) General availability follows the pilots, on the same evidence-first terms.

Two intended ways to run it

An installation cannot quietly change what it is.

Every installation locks to one of two operating profiles on the same kernel. Choosing a profile records how an installation is meant to run — it is not proof that one has run, and neither profile is offered for installation today.

Control Starter

Run by an approved partner, for you

For complex smaller businesses: curated connectors, assisted setup, business-hours support, and recovery from backup rather than a promised uptime percentage.

Authority Platform

Run by your own team, in your own cloud

For customers who operate the deployment themselves: bring-your-own-cloud (BYOC — the product runs in your cloud account, not ours), your identity systems in charge, tightly controlled outbound connections, and no third-party root access.

Not available

Neither profile is currently offered for installation

The install tooling refuses any configuration claiming more continuity than one restorable server — that refusal is deliberate. Not offering either profile yet is our own decision: a policy gate, not a technical one.

Not available

What you cannot obtain from Lagstyr today.

  • A customer installation
  • A hosted or shared sandbox
  • A trial or pilot
  • A product demo
  • Early-access credentials
  • Production support or SLAs
  • Certified compliance artefacts

One of these will change first: the design-partner pilot is the next gate, and when it opens, its admission criteria will be published on this page. Until then, the website collects expressions of interest only — registering does not apply for access, place an order, or begin an evaluation, and it is how pilot candidates will be found.

Follow the evidence as it lands.

Register for occasional development and availability updates — including when the design-partner gate opens.

Register your interest