How far a company's model reaches, level by level.
Robert Blust · Software Engineer & Architect
Model. Gated. Governed. Served. Published. Each level adds one thing that reads from the model, and none of them asks you to write it again.
init writes the instance: core at a named release, a manifest that records it file by file, the check, the agent skills and a commit hook.
The model is a folder of Markdown. Nothing else is needed to start.
Put the folder in a repository, and its workflow runs the same check on every pull request, at the release the manifest names. Protect the main branch, and a reference that names nothing never reaches it.
Every repository around the model is held to one Markdown form, declares what it takes from another in pins.json, and is told which of those pins are behind. A repository without a model takes the same machinery with adopt.
It is our machinery, not our rules: your seats, your repositories, your conventions.
A rule says what must, must not or may happen, and why. A risk says what could go wrong. A control says what stops it, and points at the check that does.
The control is the page; the check stays code.
A read-only server answers an agent over MCP, and a chat answers a visitor, both from the model at one named commit, naming the pages each answer rests on.
The site draws its stage, its pages and their structured data from the model at a pinned commit, and the editor reads the same files. Change a page, move the pin, and the site says it.
On October 2, 2026, the software pack went from a release to our own model, our first bounded context, the website, the server and the editor, one pinned step at a time.
Each level pins the one below it: a tag for what it runs, a commit for what it shows. A pin moves when someone decides it should.
The same day, one pin we had not moved stopped every check in an organization. Moving it fixed them all.
The levels are a ladder, not a checklist. Each one pays for itself before you take the next. Start with one command.