module tour · configured for an asset-management tenant
All figures illustrative · synthetic demo · unlaunched product preview

The modules behind the engagements

Every module is build-once / config-many: a new firm is a configuration seed, never a fork. Each panel below is one module, configured for a synthetic manager.
ModulePipes — data ingestionevery source declared as data · pipes.tenant.json
PipeScheduleLast runValidation at the doorState
Bloomberg back-officedaily 06:00 ET06:02 · run 8841shape ✓ · 12,412 rows vs 12,380±5% ✓LOADED
Custodian — Schwab positionsdaily 05:45 ET05:48 · run 8842shape ✓ · account set complete ✓LOADED
Fund admin — SS&C NAV packdaily 06:15 ET06:20 · run 8844expected 4 files · got 3 ✗HELD — QUARANTINED
FactSet pricesdaily 05:30 ET05:30 · run 88458,110/8,114 ids · 4 mapped-out ✓LOADED
A pipe is a declaration, not a script: source, schedule, expected shape, and tolerance live in the tenant seed. The held SS&C pack is the module doing its job — yesterday's good data stands until today's arrives whole.
ModuleSentinel — alarms & run-healththree axes, alarmed separately · nothing fails silently
RuleAxisThresholdOn breachNow
Feed freshnessfreshness> 30 min past schedulenotify ops · page after 2h6/6 FRESH
Delivery completenesscoverageany short deliveryhold load · quarantine · notify1 HELD (SS&C)
Job successrun-healthnon-zero exitretry ×2 · then escalate14/14 GREEN
Backup freshnessfreshness> 26h since last goodalarm — a stale backup is an incident8h AGO
The incident feed shows the SS&C hold at 06:20 with who was told and when. An alarm that fires into a log nobody reads is the same as no alarm — every rule names a person-visible destination.
ModuleRecon — agreement checksboth sides shown · aging escalates
CheckSidesCadenceOpen breaksState
Positionscustodians vs. booksdaily 06:301 · aged 3 daysESCALATED
Cashcustodians vs. booksdaily 06:301 · $1,500.00OPEN
Trades capturedOMS vs. custodian activitydaily 06:350CLEAN
NAV tie-outadmin pack vs. internalmonthlyheld — awaiting full SS&C packWAITING
A break carries its two sides and its age. Three days old, it stops being a line item and becomes somebody's morning — the escalation is in the module, not in someone's memory.
ModuleProvenance — lineage explorerany figure, traced to its source
$412,882,116
Firm AUM · Capital Account Summary p.1 · as of Jun 30 TRACED
The trace is generated from the run record, never typed. If a figure cannot produce this chain, the report build refuses it — a number that cannot name its source does not ship.
ModuleRailkeep — backup & demonstrated restorean instance is a row · present is not matching
InstanceLast backupLast demonstrated restoreKey custodyState
Research warehousetoday 01:10 · 4.2 GBJun 28 · drill #31 · byte-for-byte ✓key matches escrow ✓COVERED
Reporting storetoday 01:25 · 1.1 GBJun 28 · drill #31 · byte-for-byte ✓key matches escrow ✓COVERED
Document vaulttoday 01:40 · 9.8 GBMay 30 · drill #30 · byte-for-byte ✓key matches escrow ✓COVERED
Wrong-key controlJun 28 · drill #31bretired key presentedREFUSED BY NAME
Coverage is judged from the registry, so a system missing from the list is a visible gap, not an invisible one. Key custody checks the backup key matches escrow — a stale key restores an identity everyone already stopped trusting.
ModuleRegistry — model & config governanceversioned · validated · approved
ItemVersionChangeValidationApproval
Risk model — Axioma AXWW4v4.2vendor v4.1 → v4.2 · Jun 12parallel run 10 days · drift within toleranceCIO-mem 26-014
Pricing waterfallv9muni fallback source added · May 03back-compare 90 days · 0 breaks introducedops-mem 26-011
Security master mappingv3114 new listings mapped · Jun 27identifier cross-check cleanauto · rules v7
Tenant seedv18new custodian pipe declared · Jun 20preflight ✓ · staged → promotedops-mem 26-016
Which model, which version, what changed, who signed — answered from the log, not from memory. Configuration changes ride the same rail as model changes, because a config change can move a number just as far.
ModuleReports — scheduled productionbuilt from governed data · holds are honest
ReportScheduleAs-ofStatusDistribution
Capital Account Summarydaily 06:40Jun 30BUILT · 06:41portal · 3 recipients
Exposure & concentration packdaily 06:45Jun 30BUILT · 06:46portal · risk seat
Admin NAV tie-outmonthlyJun 30HELD — short SS&C packheld with reason shown
Trustee reporting packquarterlyQ2BUILT · Jul 02vault · trustee seat
A held report says why, on its face. Shipping a report built on a short delivery would be the silent failure every other module exists to prevent.
ModuleRecords — documents & audit trailfiled to entities · append-only
DocumentFiled toAddedTrail (latest)
Custody agreement — Schwabentity: master fundJan 12viewed · trustee seat · Jun 29
Q2 admin NAV packentity: master fund · period: Q2Jul 02filed by pipes · run 8844
Restore drill log #31system: railkeepJun 28generated · immutable
Valuation policy v9policy registerMay 03superseded v8 · archived, not deleted
The trail is append-only: who filed, who viewed, what superseded what. Nothing is deleted — a superseded policy is archived with its history, which is exactly what a due-diligence exam wants to walk.
ModuleAccess — seats & capabilitiesleast privilege · reviewed on a date, not "eventually"
SeatRoleCapabilitiesLast reviewState
coo@firmownerfull · 41 capabilitiesJun 01REVIEWED
analyst@firmresearchread: platform, reports · 12Jun 01REVIEWED
trustee seatviewerread: trustee pack only · 3Jun 01REVIEWED
backup servicebackupdoc_view_all · write: nothingJun 01LEAST-PRIVILEGE
Service accounts get the narrowest role that works — the backup seat reads everything and writes nothing. The review column carries a date because "we review access" without a date is a sentence, not a control.