HCS-GaaS — Governance & Evidence
Governance-as-a-Service packages the HUMENS Canonical Schema (HCS™) spine: evidence, Learn → Predict → Act → Regulate (LPAR™), and Chief Human Operator (CHO) oversight. This is the single public home for that spine (the former Protocol page redirects here). Not a standalone consulting category.
HCS — governed execution spine
HCS is the governed schema, evidence, and control layer for structured operational events, audits, workflows, and escalation. Sensitive operations are translated into governed events, evaluated against policy, recorded as evidence, and regulated through a closed loop. See also Platform and the glossary.
- External APIs do not bypass governance.
- HCS decides governance — providers and forecasts do not.
- Every sensitive operation should become evidence.
- Auditability does not imply training or execution eligibility.
LPAR — Learn, Predict, Act, Regulate
LPAR is the closed-loop process ensuring that learned patterns inform prediction and action only through governed regulation — not direct execution authority.
Chief Human Operator (CHO)
CHO is the human authority — the person (or delegated role) who can approve, deny, hold, freeze, rollback, or escalate when policy requires a human decision. Where CHO is required, automation does not bypass governance. CHO is not a status label and not a synonym for “Oversight.”
HUMENS measures CHO effectiveness with operating metrics (similar in spirit to OEE): how often work is reviewed before action, how often it is stopped, and how much time and attention review costs. That makes human control a discipline — not a vague role.
CHO does not guarantee compliance and does not replace auditors, regulators, or licensed professionals.
CHOSE — how the CHO works
CHOSE is the process the CHO uses to organize governed work: Checked · Halted · Oversight · Secured · Evaluated (Secure / Evaluation·Evaluator depending on context — the same loop). The machine runs LPAR; the human runs CHOSE.
- Checked
- Reviewed and cleared for the next step (when wired to live workflow).
- Halted
- Fail-closed: stopped, frozen, rejected, or escalated (e.g. production M0 NOT GO).
- Oversight
- Governed but not cleared — awaiting CHO action or evidence. Yellow, not green. Not fabricated approval.
- Secured
- Controls and evidence posture locked for the scope under review (Secure in shorthand).
- Evaluated
- Scored against policy / bar by the evaluator function — promotion is never automatic green.
Work is filed under the 12 canonical pillars (Leadership, Governance, Security, Trust, Finance, Commercial, Operations, Compliance, Legal, Engineering, Quality, Intelligence). Each pillar can carry a hash-anchored audit binder — the evidence pack assembled from the ledger, never invented. A binder in Oversight is incomplete or waiting; a cleared binder is exportable proof.
Staff at /access/ open the internal CHOSE binder view for the pillar tree, owner queue, and live export when the ledger returns evidence. This public page is the model; that surface is the proof.
Glossary (use these meanings on every surface)
- HCS™
- HUMENS Canonical Schema — the governed execution spine: schema, policy, evidence, escalation.
- LPAR™
- Learn → Predict → Act → Regulate — the machine closed loop. Action only through regulation.
- CHO
- Chief Human Operator — the human who can still clear or stop. A role, not a status.
- CHOSE™
- Checked · Halted · Oversight · Secured · Evaluated — how CHO work is organized and stated.
- Oversight
- A CHOSE state: governed, awaiting clearance. Not the job title for CHO.
- Audit binder
- Hash-anchored evidence pack for a domain, node, or customer scope. Fail-closed: empty until the ledger returns a hash. Binders are proof; Oversight is a status of that proof.
- HCS-GaaS
- Governance-as-a-Service — packaging HCS + LPAR + CHO/CHOSE for a client domain.
- TaaL™
- Telemetry-as-Language — turns domain events into a structured language for scoring, labeling, storage, and reasoning.
- Quant / Domain Reasoning
- Product that runs TaaL and sells Quant-TaaS: scored, labeled, automatable domain data under HCS+LPAR. Domains: Fiat, Crypto, Mortgage, Real Estate. Paper trading gates apply only to Fiat and Crypto.
- Quant-TaaS™ / TaaS
- Telemetry-as-a-Service — Quant’s commercial SKU: governed domain telemetry and recommendations for future process automation.
- CaaS-VAP / CaaS-VPP
- Compute SKUs (fiber-first VAP; energy-land VPP thesis). Not Quant domains.
- HUMENS-R1-⟨Domain⟩
- Per-domain governed agent: shared base + that domain’s binder + telemetry. Recommends; does not live-fire alone.
HCS-GaaS — proactive and post-mortem modes
Governance-as-a-Service packages the HCS spine for client domains: send domain data through LPAR, score it against a fail-closed bar, arm only what clears, then govern every execution and halt non-compliant actions. Binders are the client-facing proof — hash-anchored, never fabricated.
- Proactive (inline) — endpoints call HCS before the action; missing clearance ⇒ HALT (no side effect).
- Post-mortem (async) — events land in HCS after the fact; binders + compliance score; drift opens CHO review and can flip a path to proactive.
- Stat bar before arm — calibrate on holdout / approved sources; CHO arms production; promotion is never automatic green.
First customer spine: Realtymatics (Arizona records / assessor anchor + activity layers). See also Platform. Commercial terms are draft until a signed GaaS agreement.
Evidence capture principles
- Operational events bind to schema and policy.
- Evidence supports audit and review — not unchecked automation.
- Governance clearance authorizes action; label clearance authorizes learning.
- Forecast is input to governance, never execution authority.