Before the Rust rewrite and the move to a multi-agent fleet architecture, this was the original proof of concept: a single VS Code workspace, ten questions reasoned cold, exported as an encrypted bundle, and re-imported into a fresh workspace, where the same ten questions came back as instant, zero-token cache hits. It's a recorded video, not a live transcript, kept here because it's the actual origin of the idea rather than a re-shoot.
After benchmarking the idea against multiple processes, the real savings weren't in one developer's session. They were in eliminating repeated reasoning across a fleet of agents. So it got rebuilt: a Rust-native server built to serve a fleet of agents, not one.
No staged screenshots, no fabricated numbers. Every block below is the actual, unedited terminal output of a live run against the real engine, with real OpenAI calls. Expand any transcript to see the whole thing, start to finish.
ContractAgent extracts terms from a vendor contract. ComplianceAgent asks a genuinely new question,
not a repeat, and reasons using ContractAgent's card as context, then commits its own
card that depends_on it. RiskAgent does the same off Compliance's card. Three real,
distinct answers, chained by a real dependency graph.
docker run --rm -it ghcr.io/leangridlabs/sce-demo-verticals:latest -s legal
====================================================================
LawFirmA Vendor Contract Review — Semantic Cache Engine Demo
====================================================================
Server: http://127.0.0.1:35100
OpenAI: enabled (real LLM reasoning)
Contract v1: C:\sce-docs\scratch\contracts\contract_v1.txt (.txt — plain legal text)
· Working directory: C:\Temp\sce_legal_demo_vzmcpoed
· Demo namespace: account:demo-230834
====================================================================
PHASE 0 — Server Health Check
====================================================================
✓ Server status: ok (version 0.1.0)
====================================================================
PHASE 1 — Contract Ingestion (v1 — plain text, not Markdown)
====================================================================
· Source fixture: contract_v1.txt (11,129 bytes)
· Format: Plain text (.txt) — ChunkerRegistry dispatches PlainTextChunker
· Stable path: C:\Temp\sce_legal_demo_vzmcpoed\vendor_contract.txt
· Namespace: org:LawFirmA
✓ Ingested 5 clauses/sections
✓ Plain-text contract indexed — no Markdown required
====================================================================
PHASE 2 — ContractAgent Cold Reasoning (Key Obligations & Commercial Terms)
====================================================================
── Resolve → expected route: generic or agent_handoff (cold, no prior card)
· Agent: ContractAgent@LawFirmA-VendorContracts
· Question: What are the key obligations and commercial terms in this vendor services agreement, inclu...
· Route: agent_handoff
· Cache miss — reading contract directly for cold reasoning
── Cold Reasoning
· Calling OpenAI (gpt-4o-mini) for real cold reasoning...
✓ OpenAI response received (1310 + 406 = 1716 tokens)
ContractAgent answer (v1):
Here are the key obligations and commercial terms extracted from the vendor services agreement:
- **Effective Date**: March 1, 2024
- **Initial Term**: Two (2) years
- **Termination Conditions**:
- Either party may terminate for convenience with thirty (30) days prior written notice.
- Immediate termination for material breach if not cured within thirty (30) days of written notice.
- **Fees and Payment**:
- Client pays fees as set forth in each Statement of Work (SOW).
- Invoices due within thirty (30) days of invoice date.
- Invoices submitted monthly in arrears detailing Services, Deliverables, and expenses.
- Disputed payments may be withheld if Client notifies Vendor within fifteen (15) days of receipt.
- **Deliverables Acceptance**: Client must accept Deliverables within fifteen (15) business days of delivery.
- **Liability Cap**: Aggregate liability limited to total fees paid or payable by Client in the twelve (12) months preceding the claim (1× annual contract value).
- **Indemnification Obligations**:
- Vendor indemnifies Client against third-party claims due to:
- Vendor's material breach.
- Vendor's gross negligence or willful misconduct.
- Infringement of third-party intellectual property rights by Deliverables (with exceptions).
- **Exceptions to Indemnification**:
- Modifications by Client without Vendor's consent.
- Combination with third-party materials not approved by Vendor.
- Use outside the scope of the license granted.
- **Data Privacy Requirements**:
- Compliance with applicable data protection laws (GDPR, CCPA).
- Definition of "Personal Data" and "Incident" included.
- **Breach Notification Timeline**: Vendor must notify Client of any Incident involving Personal Data.
- **Governing Law**: Not explicitly stated in the provided text.
This summary captures the essential obligations and terms of the agreement.
── Committing reasoning card
✓ Card committed: c8b45d1d-3f02-4b... tokens=1716 (exact)
====================================================================
PHASE 3 — Reasoning Graph (Compliance → Risk → Negotiation, each depends_on the last)
====================================================================
── ComplianceAgent — builds on ContractAgent's card
· Agent: ComplianceAgent@LawFirmA-VendorContracts
· Route: graph_assisted (new question — reasons using ContractAgent's card as context)
GDPR COMPLIANT (Article VII references EU 2016/679)
CCPA COMPLIANT (Article VII references Cal. Civ. Code §1798.100)
HIPAA COMPLIANT (BAA required before PHI processing — §7.5)
Data retention clause COMPLIANT (§7.4 specifies 30-day post-termination retention)
Breach notification ISSUE (§7.3 — 72-hour window meets regulatory standard)
· Calling OpenAI for compliance analysis, grounded in ContractAgent's extracted terms...
✓ Card committed: e9731a13-ae60-40... tokens=689 (exact) depends_on=ContractAgent's card
── RiskAgent — builds on ComplianceAgent's card
· Agent: RiskAgent@LawFirmA-VendorContracts
· Route: graph_assisted (new question — reasons using ComplianceAgent's card as context)
Liability cap 1× annual fees HIGH RISK (Industry standard is 3× — current 1× exposes Client)
SLA penalty schedule defined ACCEPTABLE (No financial remedy for availability failures)
Breach notification 72h window HIGH RISK (Meets regulatory standard)
Mutual indemnification absent HIGH RISK (Vendor-only indemnification — Client has no exposure cap)
· Calling OpenAI for risk analysis, grounded in ComplianceAgent's findings...
✓ Card committed: 3fe65074-0c95-48... tokens=431 (exact) depends_on=ComplianceAgent's card
── NegotiationAgent — builds on RiskAgent's card
· Agent: NegotiationAgent@LawFirmA-VendorContracts
· Route: graph_assisted (new question — reasons using RiskAgent's card as context)
Proposed redlines:
§6.1 Liability cap Increase from 1× to 3× annual fees
§6.3 Indemnification Add mutual indemnification for Client-side liability
§8.3 SLA remedy Add financial credit schedule: 5%/10%/20% at descending tiers
§7.4 Data retention Reduce from 30 to 15 days; require written destruction cert
§7.5 HIPAA Vendor to represent 45 C.F.R. Part 164 safeguards explicitly
§9.1 Governing law Negotiate Delaware jurisdiction for IP-neutral venue
✓ Card committed (indexable=false): acf4446b-129b-4c... tokens=160 (estimated) depends_on=RiskAgent's card
── Verifying negotiation redlines are excluded from recall
✓ NegotiationAgent: not recallable (route=graph_assisted) — audit-only as intended
====================================================================
PHASE 6 — ROI Report
====================================================================
Metric This Run
────────────────────────────────────────────────────
New cards committed 9
Recall hits 0
Cards with token data 4
Tokens invested (cold reasoning) 2,996
Tokens saved (warm recalls) 0
Agent sessions avoided 0
────────────────────────────────────────────────────
Savings ratio 0.0%
· Cards committed this run. Recalls will accumulate savings over time.
====================================================================
Demo Complete
====================================================================
Run again with --openai-key for real LLM cold reasoning.
A 4-agent chain (Interpretation → Compliance → Enforcement → Audit) reasons over a real regulation, each card depending on the last, signed with a chain-of-custody hash. Then the regulation is amended. Cascade invalidation purges the whole affected chain, not just one answer, and every agent re-derives its conclusion under the new rules automatically. The assessed penalty jumps from $5M (capped) to $625M (cap eliminated for willful violation) with zero manual re-work.
docker run --rm -it ghcr.io/leangridlabs/sce-demo-verticals:latest -s regulatory
SCE Regulatory Workflow Demo
Agency: RegAgencyA
Regulation: State Data Privacy Act, 2024 (SDPA-2024 + Amendment No. 1)
Agents: InterpretationAgent, ComplianceAgent, EnforcementAgent, AuditAgent
Format: .docx (DocxChunker, Heading1-boundary article splitting)
Account: RegDemo-287c438a
LLM: OpenAI gpt-4o-mini
· Generating regulation fixtures (DOCX, zero third-party deps)...
✓ reg_v1.docx: 2,861 bytes (8 articles)
✓ reg_v2.docx: 2,794 bytes (8 amendment sections)
· Stable temp path: C:\Temp\sce-reg-lslkbdlq
====================================================================
PHASE 0 — Server Health Check
====================================================================
✓ Server status: ok (version 0.1.0)
· Stability: deterministic recall engine — no LLM drift
· Auditability: every card carries committed_by, reasoning_chain, content hash
· Subsystem integrity: database + vec_store + embedding model all healthy
====================================================================
PHASE 1 — Regulation Ingestion (SDPA-2024, DOCX format)
====================================================================
· Document: State Data Privacy Act, 2024 (SDPA-2024)
· Format: .docx — ChunkerRegistry dispatches DocxChunker (heading-boundary chunks)
· Fixture: reg_v1.docx (2,861 bytes)
· Stable path: C:\Temp\sce-reg-lslkbdlq\regulation.docx
· Namespace: org:RegAgencyA
✓ Ingested 8 statutory articles/sections
· Regulation indexed by article — each Article becomes a searchable chunk
· Source path registered for cascade invalidation on amendment
====================================================================
PHASE 2 — InterpretationAgent Cold Reasoning (Statutory Interpretation)
====================================================================
── Resolve → expected route: generic or agent_handoff (cold, no prior card)
· Agent: InterpretationAgent@RegAgencyA
· Question: What are the key obligations, definitions, enforcement mechanisms, and penalty structures ...
· Route: agent_handoff
· Cache miss — reading regulation document via local DOCX reader for cold reasoning
── Cold Reasoning — Statutory Interpretation
· Calling OpenAI (gpt-4o-mini)...
✓ OpenAI response (934+814=1748 tokens)
InterpretationAgent statutory memo (SDPA-2024 v1):
Here are the key provisions extracted from the State Data Privacy Act, 2024 (SDPA-2024):
### ARTICLE I — SHORT TITLE AND PURPOSE
- **Short Title**: State Data Privacy Act, 2024 (SDPA-2024).
- **Purpose**: Establish rights for consumers regarding personal data and impose obligations on controllers and processors for responsible data stewardship.
### ARTICLE II — DEFINITIONS
- **Covered Entity**:
- A commercial entity conducting business in the State.
- Collected or controlled personal data of over 100,000 consumers in the previous year or derived over 25% of gross revenue from the sale of personal data.
- **Personal Data**: Information linked or reasonably linkable to an identified or identifiable natural person.
- **Data Breach**: Unauthorized acquisition of personal data compromising its confidentiality, integrity, or availability.
- **Controller**: Person determining the purpose and means of processing personal data.
- **Processor**: Person processing personal data on behalf of a controller.
### ARTICLE III — COVERED ENTITIES AND APPLICABILITY
- **Applicability**: Applies to all Covered Entities processing personal data of State residents.
- **Exemptions**:
- Financial institutions under the Gramm-Leach-Bliley Act (GLBA) for data subject to that Act.
- Healthcare providers under HIPAA for protected health information.
- Small businesses with fewer than 50 full-time employees and annual gross revenues below $5,000,000.
### ARTICLE IV — DATA SUBJECT RIGHTS
- **Consumer Rights**:
- Access personal data collected about them.
- Correct inaccurate personal data.
- Request deletion of personal data.
- Obtain a portable copy of personal data in a machine-readable format.
- Opt out of the sale or sharing of personal data for targeted advertising or profiling.
- **Response Timeline**: Controllers must respond to verified consumer requests within 45 days, with a single 45-day extension allowed upon written notice.
### ARTICLE V — CONTROLLER OBLIGATIONS
- **Obligations**:
- Limit data collection to what is necessary (data minimization).
- Implement reasonable security measures (administrative, technical, physical).
- Maintain a written data protection policy on their website.
- Execute written data processing agreements (DPAs) with all processors.
- Conduct and document data protection impact assessments (DPIAs) for high-risk processing activities.
### ARTICLE VI — DATA BREACH NOTIFICATION
- **Notification Requirement**: Upon discovery of a Data Breach, notify the State Attorney General and affected consumers within 72 hours.
- **Notification Contents**:
- Description of the incident and personal data categories involved.
- Estimated number of affected records.
- Contact information of the entity's Privacy Officer.
- Description of remediation measures taken or proposed.
- **Extension**: A 24-hour extension may be requested from the Attorney General for good cause.
### ARTICLE VII — ENFORCEMENT AND PENALTIES
- **Enforcement**: The State Attorney General has exclusive authority to enforce the Act.
- **Civil Penalties**:
- Up to $100 per affected record per violation.
- Aggregate penalties for a single Data Breach event shall not exceed $5,000,000.
- **Additional Remedies**: The Attorney General may seek injunctive relief, disgorgement of profits, and equitable remedies.
- **Fund**: All civil penalties are deposited into the State Consumer Protection Fund.
- **Private Right of Action**: There is no private right of action under this Act.
### ARTICLE VIII — EFFECTIVE DATE AND RULEMAKING
- **Effective Date**: The Act takes effect on January 1, 2024.
- **Rulemaking Deadline**: The Attorney General must promulgate implementing regulations by July 1, 2024.
- **Compliance Deadline**: Covered Entities must achieve full compliance by October 1, 2024.
── Committing statutory interpretation card
✓ Card committed: 807d8a36-dfb0-4d... tokens=1748 (exact)
· Content fingerprint (blake3): fcc59265606b8c5a76183d441d38d4a5...
====================================================================
PHASE 3 — ComplianceAgent Warm Recall (Zero Cold-Reasoning Tokens)
====================================================================
── Resolving statutory interpretation — expected route: recall
· Agent: ComplianceAgent@RegAgencyA
· Entity under review: FinCorp Bank NA (Regional bank — GLBA primary, but analytics division processes >1M consumer records outside GLBA scope)
· Route: recall (cache hit — 0 LLM tokens)
── Compliance check — FinCorp Bank NA against SDPA-2024 v1
Entity coverage COMPLIANT (Analytics division: >100K consumers, outside GLBA scope)
Data minimization policy COMPLIANT (FinCorp DMP v3.1 on file — satisfies ARTICLE V(a))
Data processing agreements COMPLIANT (DPAs executed with all 47 third-party processors)
DPIA program COMPLIANT (Annual DPIA conducted for all high-risk processing)
Privacy Officer designated COMPLIANT (J. Harrington, CPO — registered with AG)
Consumer rights workflow COMPLIANT (45-day response SLA in place — ARTICLE IV compliant)
Breach notification protocol COMPLIANT (Internal SOP: notify AG within 72h — ARTICLE VI compliant)
DPO requirement COMPLIANT (Not required under SDPA-2024 v1 (Article X not yet enacted))
Private right of action risk COMPLIANT (No private right of action under SDPA-2024 v1 — ARTICLE VII)
✓ FinCorp Bank NA compliance status under SDPA-2024 v1: FULLY COMPLIANT
· No corrective actions required under current regulation
====================================================================
PHASE 4 — EnforcementAgent Decision (Incident: FinCorp Data Breach)
====================================================================
── Incident facts
· Entity: FinCorp Bank NA
· Records exposed: 2,500,000
· Notification delay: 96 hours (limit: 72h under v1)
· Concealment alleged: Yes
── Resolve → expected route: generic (no prior enforcement card)
· Route: generic
── Enforcement decision (deterministic — no LLM, no drift)
EnforcementAgent decision:
Enforcement decision against FinCorp Bank NA — under SDPA-2024 v1:
• Entity coverage: COVERED (analytics division processes 2,500,000 consumer records outside GLBA scope)
• Notification violation: YES — notified AG at 96h; required ≤72h (overrun: 24h)
• Violation severity: CRITICAL
• Civil penalty: $100/record × 2,500,000 records = $250,000,000
• Aggregate cap: $5,000,000 — assessed penalty: $5,000,000
• Private right of action: AVAILABLE — 2,500,000 consumers may seek $1,000–$5,000 statutory damages each
• Corrective action: Implement breach notification protocol; appoint Privacy Officer; commission independent forensic audit within 60 days
✓ Assessed civil penalty: $5,000,000 (capped from $250,000,000)
✓ Corrective action window: 60 days
── Committing enforcement decision card
✓ Card committed (indexable=false): 60f3542d-b3c7-49... depends_on: InterpretationAgent card
· Content fingerprint (blake3): 401bec7e70393cd8a1351e2b68dbdc9b...
====================================================================
PHASE 5 — AuditAgent Card Signing (Attestation + Chain-of-Custody)
====================================================================
· AuditAgent verifies card availability before signing — each resolve is a cache hit
· Signed-at timestamp: 2026-10-01T03:09:01Z
── Signing InterpretationAgent card
· Route: recall — card verified in cache
⚿ Card: 807d8a36-dfb0-4d...
⚿ Fingerprint (server blake3): fcc59265606b8c5a76183d441d38d4a5...
⚿ Signature (SHA-256): 776f01b1951da37c8894369814bd505e...
⚿ Signed by: AuditAgent@RegAgencyA
⚿ Signed at: 2026-10-01T03:09:01Z
── Signing EnforcementAgent card
· Route: generic — card verified in cache
⚿ Card: 60f3542d-b3c7-49...
⚿ Fingerprint (server blake3): 401bec7e70393cd8a1351e2b68dbdc9b...
⚿ Signature (SHA-256): a25c7921ab808600eba8c45bce7c69a9...
⚿ Signed by: AuditAgent@RegAgencyA
⚿ Signed at: 2026-10-01T03:09:01Z
── Chain-of-custody hash
⚿ Chain hash (sig₁||sig₂): 703f2cf9ef219762dc698adb884d2d45...
· Chain hash binds both attestations — any tamper breaks the chain
── Committing audit attestation card
✓ Audit card committed (indexable=false): e55a637c-3d87-45... depends_on: 2 cards
✓ Chain-of-custody established — tamper-evident attestation recorded in SCE
── Verifying enforcement + audit cards are excluded from recall
✓ EnforcementAgent: not recallable (route=generic) — audit-only as intended
✓ AuditAttestation: not recallable (route=generic) — audit-only as intended
====================================================================
PHASE 6 — Regulation Update (v1 → v2) + Cascade Invalidation
====================================================================
── Overwriting stable path with Amendment No. 1
✓ Copied reg_v2.docx → regulation.docx (same source_path, new content hash)
· Amendment No. 1: $250/record penalties, 48h HV window, private right of action, DPO req
── Purging all v1 cards by source path (cascade invalidation)
✓ Purge: ok (regulation.docx)
· All v1 cards purged: InterpretationAgent, EnforcementAgent, AuditAttestation
── Re-ingesting Amendment No. 1
✓ Re-ingested 8 amended articles/sections
── Flushing LRU fast-lane cache
✓ Fast-lane cache flushed
── Verifying cascade — resolve must now be generic (v1 card invalidated)
✓ Cascade confirmed: route is agent_handoff — v1 interpretation card purged
── InterpretationAgent re-reasons under Amendment No. 1
· Calling OpenAI for v2 statutory interpretation...
✓ OpenAI v2 response (945+837=1782 tokens)
InterpretationAgent statutory memo (SDPA-2024-A1):
Here is a concise interpretation of the changes made by Amendment No. 1 to the State Data Privacy Act, organized by Article:
### ARTICLE II — DEFINITIONS (AMENDED)
- **New Definitions Added:**
- **Data Broker:** A commercial entity that collects and sells, licenses, or discloses personal data of consumers without a direct relationship.
- **AI Inference Platform:** A service that derives or predicts personal data attributes through automated processing.
- **High-Volume Processor:** A Covered Entity processing personal data of over 1,000,000 consumers in the previous calendar year.
### ARTICLE III — COVERED ENTITIES (AMENDED)
- **Scope of Application:**
- Applies to Covered Entities, Data Brokers, and AI Inference Platforms processing personal data of State residents.
- **Small Business Exemption:**
- Reduced from fewer than 50 to fewer than 25 full-time employees.
- **Registration Requirements:**
- Data Brokers must register annually with the Attorney General and pay a $500 fee.
- **Record Keeping:**
- AI Inference Platforms must maintain auditable logs of inference decisions for at least 36 months.
### ARTICLE VI — DATA BREACH NOTIFICATION (AMENDED)
- **Notification Requirements:**
- **High-Volume Processors:** Must notify the Attorney General and affected consumers within 48 hours of awareness of a Data Breach (no 24-hour extension).
- **Other Covered Entities:** Retain a 72-hour notification window.
- **Additional Notification Content:**
- Must include a preliminary root cause analysis and interim containment measures taken within the first 24 hours.
### ARTICLE VII — ENFORCEMENT AND PENALTIES (AMENDED)
- **Civil Penalties:**
- Increased from $100 to $250 per affected record per violation.
- Elimination of the $5,000,000 aggregate cap for willful or reckless violations.
- **Criminal Penalties:**
- Up to $50,000 per incident for responsible officers of a Covered Entity that willfully conceals a confirmed Data Breach.
- **Reporting:**
- The Attorney General must publish an annual public enforcement report.
- **Penalty Revenue Distribution:**
- Revenue divided equally between the State Consumer Protection Fund and a new Consumer Privacy Restitution Fund.
### ARTICLE IX — PRIVATE RIGHT OF ACTION (NEW)
- **Consumer Rights:**
- Consumers whose data is compromised due to a Covered Entity's non-compliance can sue in court.
- Statutory damages range from $1,000 to $5,000 per violation.
- Class actions are authorized, and prevailing consumers can recover attorney fees and costs.
- **Cumulative Rights:**
- This private right of action is in addition to enforcement by the Attorney General.
### ARTICLE X — DATA PROTECTION OFFICERS (NEW)
- **Designation Requirement:**
- Covered Entities with over 250 full-time employees must appoint a qualified Data Protection Officer (DPO) by September 1, 2025.
- **DPO Responsibilities:**
- Monitor compliance, conduct annual audits, serve as the contact for consumer data rights requests, and advise on Data Protection Impact Assessments (DPIAs).
- **Registration and Publication:**
- DPO must register with the Attorney General within 30 days and their contact information must be published on the entity's website.
### ARTICLE XI — COMPLIANCE DEADLINES
- **Effective Date:**
- The Amendment takes effect on March 1, 2025.
- **Compliance Deadlines:**
- Covered Entities must comply with amended Article III and new Article X by September 1, 2025.
- High-Volume Processors must comply with the 48-hour breach notification requirement by June 1, 2025.
- **Immediate Effect:**
- All other amended provisions are effective immediately upon March 1, 2025.
This summary outlines the key obligations, definitions, enforcement mechanisms, and compliance requirements introduced by the Amendment to the State Data Privacy Act.
── Committing v2 interpretation card
✓ v2 card committed: 6a920dc2-c580-4c... tokens=1782 (exact)
====================================================================
PHASE 7 — Post-Cascade Re-Evaluation (Amendment No. 1 Rules)
====================================================================
── ComplianceAgent — Re-evaluating FinCorp under Amendment No. 1
· Route: recall (cache hit — 0 LLM tokens)
Entity coverage COMPLIANT (Still covered — analytics division unchanged)
Data minimization / DPAs COMPLIANT (Unchanged — ARTICLE V still compliant)
DPIA program COMPLIANT (Unchanged — ARTICLE V still compliant)
Consumer rights workflow COMPLIANT (45-day SLA unchanged — ARTICLE IV still compliant)
Breach notification (HV) GAP IDENTIFIED (GAP: FinCorp SOP is 72h; Amendment requires ≤48h for High-Volume)
DPO designation GAP IDENTIFIED (GAP: 4,200 employees > 250 threshold; DPO required by September 1, 2025 (ARTICLE X))
Private right of action risk GAP IDENTIFIED (NEW exposure: 2,500,000 consumers may now sue — ARTICLE IX)
Criminal penalty exposure GAP IDENTIFIED (Willful concealment allegation → potential $50K/incident/officer)
✗ FinCorp Bank NA compliance status under SDPA-2024-A1: 2 COMPLIANCE GAPS
· Required: update breach notification SOP to 48h; designate and register DPO
── EnforcementAgent — Re-applying enforcement decision under Amendment No. 1
· Route: generic (v1 enforcement card purged — fresh reasoning required)
EnforcementAgent revised decision (Amendment No. 1):
Enforcement decision against FinCorp Bank NA — under SDPA-2024-A1:
• Entity coverage: COVERED (analytics division processes 2,500,000 consumer records outside GLBA scope)
• Notification violation: YES — notified AG at 96h; required ≤48h (overrun: 48h)
• Violation severity: CRITICAL
• Civil penalty: $250/record × 2,500,000 records = $625,000,000
• Aggregate cap: ELIMINATED (willful violation) — assessed penalty: $625,000,000
• Criminal referral: PENDING — willful concealment alleged ($50,000/incident/officer)
• Private right of action: AVAILABLE — 2,500,000 consumers may seek $1,000–$5,000 statutory damages each
• DPO requirement: APPLICABLE — 4,200 employees exceeds 250-employee threshold; DPO must be designated by September 1, 2025
• Corrective action: Implement breach notification protocol; appoint Privacy Officer; commission independent forensic audit within 60 days
✓ Revised assessed penalty: $625,000,000 (aggregate cap ELIMINATED — willful violation)
── Committing v2 enforcement decision card
✓ v2 enforcement card (indexable=false): 3cf2c4cc-d1e8-41... depends_on: v2 interpretation card
── AuditAgent — Re-signing v2 cards under Amendment No. 1
· Signed-at: 2026-10-01T03:09:10Z
· v2 InterpretationAgent card: route=recall
· v2 EnforcementAgent card: route=generic
⚿ v2 InterpretationAgent sig: c390315439702a97921f7a35fef292fd...
⚿ v2 EnforcementAgent sig: 8f92004603965990bd7087c1776477a8...
⚿ v2 Chain hash: f58809ada3e62ac24b4d9e94f89881c7...
── Committing v2 audit attestation card
✓ v2 audit card committed (indexable=false): cbc4062d-4212-44... depends_on: 2 v2 cards
✓ Chain-of-custody updated — v2 attestation supersedes v1 signatures
── Verifying v2 enforcement + audit cards are excluded from recall
✓ v2 EnforcementAgent: not recallable (route=generic) — audit-only as intended
✓ v2 AuditAttestation: not recallable (route=generic) — audit-only as intended
====================================================================
PHASE 8 — ROI Report
====================================================================
Metric This Run
────────────────────────────────────────────────────
New cards committed 11
Recall hits 4
Cards with token data 3
Tokens invested (cold reasoning) 4,910
Tokens saved (warm recalls) 7,060
Agent sessions avoided 4
────────────────────────────────────────────────────
Savings ratio 59.0%
✓ This run: 4,910 tokens invested → 7,060 saved across 4 recalls (59.0% reduction)
· What regulators see in this demo:
· Interpretation → Compliance → Enforcement → Audit → Cascade → Re-sign
· Deterministic outcomes at each phase — no LLM drift, no hallucination
· Tamper-evident card hashes + audit signatures + chain-of-custody
· Amendment No. 1 automatically propagated — zero manual re-work
Against a real 75-page public document (the Federal Reserve Board's Financial Stability Report, November 2025, a genuine public-domain U.S. government publication, not a synthetic filing), the same 50-question probe set is re-run after each of 4 rounds of new cards get committed. No per-question routing is asserted, only the aggregate hit rate, which should rise as the card base grows and the document graph fills in. Hit rate in this run: 0% → 50% → 76% → 92% → 96%, confirmed monotonic.
docker run --rm -it ghcr.io/leangridlabs/sce-demo-verticals:latest -s fedfsr
========================================================================
Federal Reserve Board Financial Stability Report (November 2025) -- Compounding Cache-Warming Test
========================================================================
------------------------------------------------------------------------
ROUND 0 -- Baseline probe (no cards ingested or committed)
------------------------------------------------------------------------
-> Fresh DB: sce-fedfsr-test.db
-> Server started (pid 17768)
Baseline done routes: {'generic': 50}
------------------------------------------------------------------------
INGEST PDF
------------------------------------------------------------------------
-> {'status': 'ok', 'cards': 136, 'changed': True} (1.0s)
------------------------------------------------------------------------
ROUND 1 -- Commit wave ['A1', 'A2', 'A3'] + re-probe full B-set
------------------------------------------------------------------------
-> Committed 5 new cards for groups ['A1', 'A2', 'A3'] (10 already recalled, ~28016 tokens grounded from real extracted text)
-> Cumulative reasoning cards committed so far: 5 (136 static structure cards from ingest are unchanged since Round 0)
Round 1 probe done routes: {'graph_assisted': 17, 'generic': 25, 'agent_handoff': 5, 'recall': 3}
------------------------------------------------------------------------
ROUND 2 -- Commit wave ['A4', 'A5', 'A6'] + re-probe full B-set
------------------------------------------------------------------------
-> Committed 6 new cards for groups ['A4', 'A5', 'A6'] (9 already recalled, ~28517 tokens grounded from real extracted text)
-> Cumulative reasoning cards committed so far: 11 (136 static structure cards from ingest are unchanged since Round 0)
Round 2 probe done routes: {'graph_assisted': 29, 'generic': 12, 'agent_handoff': 2, 'recall': 7}
------------------------------------------------------------------------
ROUND 3 -- Commit wave ['A7', 'A8', 'A9'] + re-probe full B-set
------------------------------------------------------------------------
-> Committed 8 new cards for groups ['A7', 'A8', 'A9'] (7 already recalled, ~43349 tokens grounded from real extracted text)
-> Cumulative reasoning cards committed so far: 19 (136 static structure cards from ingest are unchanged since Round 0)
Round 3 probe done routes: {'graph_assisted': 33, 'generic': 4, 'recall': 11, 'agent_handoff': 2}
------------------------------------------------------------------------
ROUND 4 -- Commit wave ['A10'] + re-probe full B-set
------------------------------------------------------------------------
-> Committed 3 new cards for groups ['A10'] (2 already recalled, ~6392 tokens grounded from real extracted text)
-> Cumulative reasoning cards committed so far: 22 (136 static structure cards from ingest are unchanged since Round 0)
Round 4 probe done routes: {'graph_assisted': 33, 'recall': 13, 'agent_handoff': 2, 'generic': 2}
------------------------------------------------------------------------
BONUS ROUND -- Repeat final probe (Tier 0 fast-lane check)
------------------------------------------------------------------------
Repeat probe done routes: {'graph_assisted': 33, 'recall': 13, 'agent_handoff': 2, 'generic': 2}
Final-round results saved -> fedfsr-probe-warm.json
Exporting opt-log traces ...
-> 390 traces -> fedfsr-routes.jsonl
========================================================================
Fed Financial Stability Report (Nov 2025) -- Compounding Cache-Warming Report
========================================================================
Same 50-question B-set (Set B), probed fresh after each round of new
cards is committed. No per-question routing is asserted — only the
AGGREGATE hit rate (recall + graph_assisted + agent_handoff), which
should rise as the card base grows and the document graph fills in.
------------------------------------------------------------------------
Round cards recall graph handoff generic hit-rate
------------------------------------------------------------------------
Round 0 (no cards) 0 0 0 0 50 0.0%
Round 1 (+['A1', 'A2', 'A3']) 5 3 17 5 25 50.0%
Round 2 (+['A4', 'A5', 'A6']) 11 7 29 2 12 76.0%
Round 3 (+['A7', 'A8', 'A9']) 19 11 33 2 4 92.0%
Round 4 (+['A10']) 22 13 33 2 2 96.0%
Repeat (Tier 0 check) 22 13 33 2 2 96.0%
[OK] Hit rate rose from 0.0% (no cards) to 96.0% (full card base) — compounding cache-warming confirmed
[OK] Hit rate increased monotonically round-over-round
========================================================================
OPT-LOG TIER BREAKDOWN (all rounds)
========================================================================
Tier0-LRU 38
Tier1b-Jaccard 4
Tier2-Cosine(BM25) 41
agent_handoff 19
generic 109
graph_assisted 179
========================================================================
FINAL-ROUND PROBE LATENCY (ms)
========================================================================
p50=13.6 p95=50.4 max=73.3
A 3-agent chain builds real depends_on links. Legal flags the final answer before citing
it in a regulatory response. The audit walk uses nothing but the real /cards/:id/audit
endpoint, hop by hop, back to the source document, showing the actual answer text,
reasoning steps, and content hash at every link. No internals, no scoring math.
docker run --rm -it ghcr.io/leangridlabs/sce-demo-verticals:latest -s provenance
====================================================================
Human-Auditable Provenance — Semantic Cache Engine Demo
====================================================================
Server: http://127.0.0.1:35100
OpenAI: enabled (real LLM reasoning)
· Working directory: C:\Temp\sce_provenance_demo_wpv_ubcy
· Demo namespace: account:demo-231051
====================================================================
PHASE 0 — Server Health Check
====================================================================
✓ Server status: ok (version 0.1.0)
====================================================================
PHASE 1 — Policy Document Ingestion
====================================================================
· Ingesting at stable path: C:\Temp\sce_provenance_demo_wpv_ubcy\data_retention_policy.md
· Namespace: org:GenericCo
✓ Ingested 1 chunks
====================================================================
PHASE 2 — PolicyAgent Cold Reasoning (builds the root of the chain)
====================================================================
── Resolve → expected route: generic or agent_handoff (cold, no prior card)
· Agent: PolicyAgent@GenericCo
· Route: agent_handoff
· Calling OpenAI (gpt-4o-mini) for real cold reasoning...
✓ OpenAI response received (115 + 45 = 160 tokens)
PolicyAgent answer:
- Customer records must be retained for a minimum of 3 years from the date of last account activity.
- Records may be purged after the 3-year retention period, unless there is an active legal hold in place.
── Committing reasoning card (root of the provenance chain)
✓ Card committed: b07e5f38-bd35-4c... tokens=160 (exact)
====================================================================
PHASE 3 — ComplianceAgent builds on PolicyAgent's card
====================================================================
· Agent: ComplianceAgent@GenericCo
· Route: generic (new question — reasons using PolicyAgent's card as context)
· Calling OpenAI, grounded in PolicyAgent's answer...
ComplianceAgent answer:
- The 2-year backup rotation practice does not comply, as customer records must be retained for a minimum of 3 years.
- Purging records after 2 years would violate the requirement to retain them until the end of the 3-year period from the last account activity.
── Committing reasoning card (depends_on PolicyAgent's card)
✓ Card committed: 55abe1a5-5ced-40... tokens=165 (exact) depends_on=PolicyAgent's card
====================================================================
PHASE 4 — RiskAgent builds on ComplianceAgent's card
====================================================================
· Agent: RiskAgent@GenericCo
· Route: generic (new question — reasons using ComplianceAgent's card as context)
· Calling OpenAI, grounded in ComplianceAgent's finding...
RiskAgent answer:
- **Regulatory Non-Compliance**: The failure to retain customer records for the mandated 3-year period exposes the organization to potential penalties or sanctions from regulators during an audit.
- **Increased Audit Scrutiny**: The identified gap may lead to heightened scrutiny from regulators, increasing the likelihood of further investigations into record-keeping practices and overall compliance measures.
- **Legal Liability**: Purging records prematurely could result in legal challenges or liabilities if customers or regulators seek access to those records, potentially damaging the organization's reputation and financial standing.
── Committing reasoning card (depends_on ComplianceAgent's card)
✓ Card committed: 0f3f92c3-f437-4f... tokens=226 (exact) depends_on=ComplianceAgent's card
====================================================================
PHASE 5 — FLAGGED FOR REVIEW: Legal cites RiskAgent's exposure assessment in a regulatory response letter
====================================================================
── Auditor: "Verify this assessment's provenance before we submit it."
── Hop 1 — auditing card 0f3f92c3-f437-4f...
Question: Given that compliance gap, what is our exposure if a regulator requests older records during an audit?
Committed by: RiskAgent@GenericCo
Committed at: 2026-10-01T03:10:58.972685700+00:00
Source document: C:\Temp\sce_provenance_demo_wpv_ubcy\data_retention_policy.md
Content hash: 217c4a9efe82691c73c21831151056a4...
Integrity: VERIFIED
Signature (ed25519): b3a5q5GuZMgBnOEhRXGL+xjugGO+0i4J... key_id=036ddaae11f1c705
Recalled: 0 time(s) (0 logged recall event(s))
Answer:
- **Regulatory Non-Compliance**: The failure to retain customer records for the mandated 3-year period exposes the organization to potential penalties or sanctions from regulators during an audit.
- **Increased Audit Scrutiny**: The identified gap may lead to heightened scrutiny from regulators, increasing the likelihood of further investigations into record-keeping practices and overall compliance measures.
- **Legal Liability**: Purging records prematurely could result in legal challenges or liabilities if customers or regulators seek access to those records, potentially damaging the organization's reputation and financial standing.
Reasoning chain (what this agent actually did):
- Recalled ComplianceAgent's compliance gap finding (graph_assisted context)
- Assessed audit exposure from the identified backup-retention shortfall
Depends on: 55abe1a5-5ced-40... ("Does our current 2-year backup rotation practice comply with")
── Hop 2 — auditing card 55abe1a5-5ced-40...
Question: Does our current 2-year backup rotation practice comply with this retention policy?
Committed by: ComplianceAgent@GenericCo
Committed at: 2026-10-01T03:10:56.037066500+00:00
Source document: C:\Temp\sce_provenance_demo_wpv_ubcy\data_retention_policy.md
Content hash: 0b3ee067b9a322eed6e8e2f76af57024...
Integrity: VERIFIED
Signature (ed25519): PV+5rhOf/uWo+W02ZQGo6z3iHTavUc8D... key_id=036ddaae11f1c705
Recalled: 0 time(s) (0 logged recall event(s))
Answer:
- The 2-year backup rotation practice does not comply, as customer records must be retained for a minimum of 3 years.
- Purging records after 2 years would violate the requirement to retain them until the end of the 3-year period from the last account activity.
Reasoning chain (what this agent actually did):
- Recalled PolicyAgent's retention analysis (graph_assisted context)
- Compared 2-year backup rotation against the 3-year policy minimum
Depends on: b07e5f38-bd35-4c... ("What are the customer-record retention obligations under thi")
── Hop 3 — auditing card b07e5f38-bd35-4c...
Question: What are the customer-record retention obligations under this data retention policy?
Committed by: PolicyAgent@GenericCo
Committed at: 2026-10-01T03:10:53.738874+00:00
Source document: C:\Temp\sce_provenance_demo_wpv_ubcy\data_retention_policy.md
Content hash: 9fe581c4e6192b7180f28035c18d0270...
Integrity: VERIFIED
Signature (ed25519): RH/uZTuK28tTXPDiw9va0kq07UPT4d1y... key_id=036ddaae11f1c705
Recalled: 0 time(s) (0 logged recall event(s))
Answer:
- Customer records must be retained for a minimum of 3 years from the date of last account activity.
- Records may be purged after the 3-year retention period, unless there is an active legal hold in place.
Reasoning chain (what this agent actually did):
- Resolved policy document via SCE ingest index
- Located Section 4 (Retention Period) via structural anchor
- Extracted retention threshold: 3 years from last activity
✓ Root of the chain reached — this card has no further dependencies
====================================================================
PHASE 6 — Human-Readable Audit Summary
====================================================================
3-hop provenance chain, newest first:
[1] RiskAgent@GenericCo 2026-10-01T03:10:58.972685700+00:00 OK
"Given that compliance gap, what is our exposure if a regulator requests older records during an audit?"
↓ depends on
[2] ComplianceAgent@GenericCo 2026-10-01T03:10:56.037066500+00:00 OK
"Does our current 2-year backup rotation practice comply with this retention policy?"
↓ depends on
[3] PolicyAgent@GenericCo 2026-10-01T03:10:53.738874+00:00 OK
"What are the customer-record retention obligations under this data retention policy?"
✓ All 3 cards in this chain verified intact — the answer submitted to legal traces back through 2 prior agent decision(s) to the original policy document, with every link's content hash matching what was actually committed.
✓ This is the full audit: no internals, no scoring math — just committed_by, timestamps, source document, content hash, the actual answer text and reasoning steps at each hop, and the depends_on chain. A compliance reviewer can do exactly what this script just did, by hand, with a card ID and a browser.
====================================================================
PHASE 7 — ROI Report
====================================================================
New cards committed 4
Recall hits 0
Tokens invested (cold reasoning) 551
Tokens saved (warm recalls) 0
────────────────────────────────────────────────────
Savings ratio 0.0%
====================================================================
Demo Complete
====================================================================
Add --openai-key or set OPENAI_API_KEY for real LLM reasoning.