P5 (Wave 3, docs) — REQ-196, 197, 202, 203, 213 New deck (unified narrative): - docs/presentations/nova-no-humans-platform.md — source of truth (18 slides) - docs/presentations/nova-no-humans-platform-marp.md — Marp deck - docs/presentations/nova-no-humans-platform-talking-points.md — presenter cues 5-act arc: Problem -> Vision -> How -> Proof -> Roadmap x3 structure at deck level (slide 1 = arc preview, slides 2-15 = tell them, slide 16 = recap + ask) x3 per slide (opens with what it covers, delivers, closes with benefit callout) Fluid transitions (every slide references the previous slide's close) Act indicator in Marp footer Grill binding decisions applied: - G-Q4: D-122 honesty sentence on slide 7 - G-Q8: stake line (18V+0 consumers) on slide 1 - G-Q9: 4 filler benefit closes rewritten - G-Q10: slide 12 split into Zero-Touch Efficiency + Cost & ROI - G-Q11: preempt on slide 14 (deferrals are measurement infra, not autonomy) - G-Q13: Act 3->4 transition rewritten - G-Q14: slide 9 benefit reframed to trust substrate - G-Q15: ROI formula inline + N=0 caveat on slide 13 - G-Q16: slide 16 ask reframed as business decision Retired (D-130): - how-the-platform-works.md + marp + html + talking-points (DELETED) - the-developer-experience.md + marp + html + talking-points (DELETED) ---ci--- project: acdl phase: 5 milestone: v1.17 status: execute ---/ci---
25 KiB
Nova — The No-Humans Infrastructure Platform
Source of truth (Step 1 of the 4-step deck process). Unified narrative deck merging
how-the-platform-works+the-developer-experience. 5-act arc: Problem → Vision → How → Proof → Roadmap. x3 structure at deck level (opening = arc preview, body = tell them, closing = recap + ask) AND per slide (opens with what it covers, delivers, closes with benefit callout). Act indicator in the Marp footer:Act N/5: <act name>.Honesty model: every metric cited is grounded (cites a source file), derived (documented formula), or deferred (cites a blocking decision ID). No fabricated numbers. Deferred metrics marked
<span class="badge planned">Planned</span>.v1.17 — Strategic Direction, Leadership Metrics & Unified Story (REQ-196, REQ-197)
Slide 1 — Arc Preview (the "what I'm going to tell you" deck-level opening)
This deck proves Nova is the no-humans infrastructure platform — and shows you the metrics that make the claim defensible.
Today: 18 capabilities verified, 0 consumer estates in production. This deck shows what's proven, what's pipeline-ready, and what's honestly deferred.
The 5-act arc:
- Problem — why the operator is the bottleneck
- Vision — Nova's strategic direction (NORTH_STAR)
- How — the pipeline, Decision Ledger, attestation gates
- Proof — grounded metrics that make the claim defensible
- Roadmap — deferred metrics with unblock paths + the ask
Benefit: you leave this deck knowing which claims are proven today, which are pipeline-ready, and which are deferred with a documented unblock path — no marketing, just grounded evidence.
Speaker notes: The stake line (18V + 0 consumers) sets the honesty frame. The audience knows from slide 1 that this is not a hype deck — it's an evidence deck. The arc preview orients them for the next 15 slides.
Slide 2 — The No-Humans Imperative
This slide shows why the operator is the bottleneck — and why removing them from operations (not accountability) is the imperative.
- The cost of humans-in-the-loop: L1/L2 ops hours, escalation latency, the trust gap (autonomous claims without proof)
- The operator is the bottleneck: provisioning takes days, not minutes; escalations pile up; the trust gap means "autonomous" is a marketing claim, not a defensible one
- The attestation model: autonomy in operations, human at stage gates — not "no humans ever"
- Cites
docs/NO_HUMANS_THESIS.md(the thesis, grounded proof, deferred proof, anti-claims)
Benefit: you now know the problem framing — autonomy in operations, human at stage gates, is the path forward.
Speaker notes: The key reframing: "no-humans" means no human in the loop of normal operations. Stage-gate attestation (QA for production, SRE for operational readiness) remains human by design. This is not about removing humans from accountability — only from operations.
Transition: "Having defined the problem, here is Nova's strategic direction toward solving it."
Slide 3 — Nova's Vision
This slide states Nova's vision — infrastructure operations become invisible, with provable trust.
Infrastructure operations become invisible. Every environment provisioned, every incident healed, every risk remediated — by an autonomous system whose trustworthiness is provable, not promised. Human attestation remains required at stage gates — QA signs off for production, SRE greenlights based on operational readiness — but the operator is never in the loop of normal operations.
- The attestation model: human attestation required at stage gates (QA for production, SRE for operational readiness); autonomy in operations, not in accountability
- Cites
docs/NO_HUMANS_THESIS.md(the thesis, grounded proof, deferred proof, anti-claims incl. D-122 honesty)
Benefit: you now know the destination — invisible operations with provable trust, not promised trust. And you know the attestation model: humans at stage gates, not in the ops loop.
Speaker notes: The vision is ambitious but precise. "Provable, not promised" is the key phrase — it's the difference between a marketing claim and a defensible one. The attestation clarification is stated up front so the audience doesn't mishear "no-humans" as "no accountability."
Transition: "The vision is ambitious — here are the 4 strategic objectives that make it concrete."
Slide 4 — Strategic Objectives + Anti-Goals
This slide pairs what Nova is building toward (4 objectives) with what Nova refuses to build (5 anti-goals).
4 Strategic Objectives:
- Demonstrate production-grade zero-touch operations — autonomy as the default, not the demo
- Establish provable trust in AI decisions — Decision Ledger, confidence scoring, circuit breakers, blast-radius controls
- Deliver compounding, quantifiable ROI — each quarter must reduce spend, free hours, avoid downtime measurably
- Become the default substrate for agentic infrastructure consumption — the platform AI agents reach for first
5 Anti-Goals (what Nova is NOT):
- Not a Terraform, Kubernetes, or hyperscaler competitor
- Not a general-purpose AI agent platform
- Not a system that removes humans from accountability
- Not for legacy, untagged, or freeform infrastructure
- Not sold to operators
From NORTH_STAR.md.
Benefit: you now know the scope boundaries — Nova is purpose-built for infrastructure operations, sold to leadership on outcomes, and explicitly not a general-purpose AI platform or a hyperscaler competitor.
Speaker notes: The anti-goals are as important as the objectives. They tell the audience what Nova will NOT be distracted by. Anti-goal #3 (not removing humans from accountability) reinforces the attestation model from slide 3.
Transition: "The objectives are committed to measurable targets — here is the 12–18 month scorecard, with honest grounding status."
Slide 5 — 12–18 Month Targets (the scorecard)
This slide shows the committed targets — numbers a board member can repeat back — with their grounding status.
Current-milestone targets (grounded or derived this milestone):
| Domain | Target | Status |
|---|---|---|
| MTTR (p95) | < 60 seconds | grounded (platform-run) |
| Cloud Spend Reduction | ≥ 25% on pilot estates | partial (Infracost grounded; CUR deferred D-096) |
| L1/L2 Ops Hours Avoided | ≥ 70% of pre-Nova FTE | derived (N internal runs; prod activates post-pilot) |
| Platform ROI | ≥ 250% annually | derived (formula; N internal runs caveat) |
| Decision Ledger Coverage | 100% of AI actions | grounded (this milestone builds it) |
| Attestation Coverage | 100% of prod/dr promotions | grounded |
Post-Pilot targets (pipeline grounded; denominator activates with a pilot estate):
| Domain | Target | Status |
|---|---|---|
| Touchless Resolution Rate | ≥ 99% | partial (pipeline grounded; 0 consumers today) |
| Human Escalation Frequency | < 0.1% | partial (pipeline grounded; 0 consumers today) |
| AI Decision Accuracy | ≥ 99.5% | partial (pipeline grounded; 0 consumers today) |
Deferred targets: Predictive vs Reactive ≥3:1 Planned · Drift Auto-Reversal ≥95% Planned
Benefit: you now know the destination numbers — and which ones are measurable today vs deferred honestly. The Post-Pilot targets are committed; the pipeline works; the numbers fill when a pilot estate runs.
Speaker notes: The three-section split (current / post-pilot / deferred) is the honesty model. The "partial" status means the measurement pipeline is grounded but the denominator is zero (0 consumers). This is the same honesty as Cloud Spend (Infracost grounded, CUR deferred). A board member can see exactly which numbers are real today and which are waiting for a pilot.
Transition: "The targets are committed — here is how Nova works to achieve them."
Slide 6 — The Platform Pipeline
This slide shows the contract-to-evidence pipeline — how intent becomes verified infrastructure without an operator.
graph LR
A[Contract] --> B[Resolver]
B --> C[Adapter]
C --> D[Terraform Plan]
D --> E[Checkov Policy]
E --> F[Confidence Signal]
F --> G{HITL Gate}
G -->|dev: autonomous| H[Apply]
G -->|qa/prod/dr: attested| H
H --> I[Evidence + Outbox]
- Contract → resolver → adapter → terraform plan → Checkov (policy) → confidence signal → HITL gate (dev autonomous; qa/prod/dr attested) → apply → evidence
- Grounded in
scripts/run_platform.sh+core/contract_resolver.py+adapters/terraform/adapter.py+core/confidence_signal.py
Benefit: you now know the path from intent to evidence — and where the human appears (stage gates only, not in the ops loop).
Speaker notes: The pipeline is the engine. The key insight: dev is autonomous (no HITL gate); qa/prod/dr require human attestation. The confidence signal is the "AI" — it's a 6-input weighted score, not an LLM. The HITL gate is where the human appears, but only for qa/prod/dr, not for dev.
Transition: "The pipeline produces decisions — here is how every decision is captured and made accountable."
Slide 7 — The Decision Ledger
This slide shows the Decision Ledger — every AI decision captured with confidence, alternatives, and outcome.
- Architecture:
outbox_writer.pyextended → SQLite append-only hash-chain table ai.decision.madeevents: decision_id=run_id, chosen_action=band, confidence=score, alternatives=perInput, human_override=HITL block, outcome backfilled from apply.completedattestation.recordedevents: qa/prod/dr sign-offs (approver, env, concerns, result)- D-121, D-122, D-132. Honors D-083 (no S3 Object Lock/JWS — local hash-chain this milestone)
D-122 honesty: Nova's "AI" is the confidence-gated policy engine (confidence_signal + HITL gate), not an LLM planner. The Decision Ledger captures this real decision path — not a fabricated "AI agent" that doesn't exist yet.
Benefit: you now know why 'autonomous' is defensible — every decision is immutable, queryable, and accountable. And you know exactly what 'AI' means here: a confidence-gated policy engine, not a black-box LLM.
Speaker notes: The D-122 honesty sentence is critical. If the audience walks away thinking Nova has an LLM planner, we've violated the "no fabrication" constraint. The Decision Ledger is the trust substrate (NORTH_STAR Objective #2) — it's the moat. Features can be copied; an immutable, queryable decision history cannot.
Transition: "Decisions are captured — here is how stage-gate attestation keeps humans in accountability."
Slide 8 — The 8-Concern Attestation Matrix
This slide shows the 8-concern attestation matrix — the designed controls that keep humans at stage gates.
| Concern | Env | Freshness | Type |
|---|---|---|---|
| functional_correctness | qa | 24h | operator-supplied |
| performance_baseline | qa | 7d | operator-supplied |
| security_posture | qa | 24h | operator-supplied |
| contract_nfrs | qa/prod/dr | — | offline-testable |
| operational_readiness | prod | 30d | operator-supplied |
| incident_response | prod | 90d | operator-supplied |
| capacity_cost | prod | 30d | operator-supplied |
| resilience_dr_drill | prod | 180d | operator-supplied |
| resilience_chaos | prod | 90d | operator-supplied |
| resilience_backup | prod | 30d | operator-supplied |
| dr_region_deploy | dr | 180d | operator-supplied |
- Offline-testable concerns run for real; operator-supplied concerns accept signed evidence artifacts
- Separation-of-duties on prod (the approver can't be the same person who built it)
- Grounded in
core/attestation_matrix.py+core/hitl_gates.py
Benefit: you now know the gate model — autonomy in operations, human in accountability, by design. The 8-concern matrix is what makes "no-humans in ops" safe.
Speaker notes: The attestation matrix is the human-in-the-loop safeguard. It's not a rubber stamp — it's a structured, freshness-validated, separation-of-duties-enforced gate. This is what Anti-Goal #3 means: "not a system that removes humans from accountability."
Transition: "You've now seen how Nova works — the pipeline, the Decision Ledger, the attestation gates. But 'how it works' is not 'proof it works.' The next four slides show the measured evidence: capability health, trust metrics, efficiency, and cost — every number grounded in a real file, not a marketing claim."
Slide 9 — Telemetry Architecture
This slide shows how Nova instruments itself — the CloudEvents envelope, the cold store, and the PowerBI export.
graph TB
A[Platform components] --> B[CloudEvents 1.0 envelope]
B --> C[metrics/events.jsonl]
B --> D[metrics/decision_ledger.db]
B --> E[metrics/runs/]
C --> F[Collector]
D --> F
E --> F
F --> G[metrics/nova_metrics.db]
G --> H[metrics/powerbi/]
H --> I[PowerBI dashboards]
- Platform components → CloudEvents 1.0 envelope →
metrics/events.jsonl+metrics/runs/+metrics/decision_ledger.db→ collector →metrics/nova_metrics.db(SQLite cold store) →metrics/powerbi/(CSV/JSON views) → PowerBI - D-120 (Nova-native), D-125 (hybrid events/files), D-126 (cold-only)
- Planned: Hot-path (live ops dashboard) — D-126
Benefit: you now know that every metric in this deck is traceable to a real emitted event — the architecture IS the trust substrate. When a CFO asks 'where does this number come from?', the answer is a file path, not a Slack thread.
Speaker notes: The architecture is deliberately minimal (Nova-native, no Kafka/Prometheus/ClickHouse). The hot path is deferred (D-126) — the cold store is sufficient for batch/historical analysis. The key point: every number in the Proof act is traceable to a file path. This is the "no fabrication" constraint made architectural.
Transition: "The architecture is sound — here is the measured proof."
Slide 10 — Capability Health + Confidence Distribution
This slide shows the grounded proof: capability health and confidence distribution from real runs.
Capability Health: 18 Verified + 4 Skipped (post-D-096 teardown) from .ciagent/REGRESSION_REPORT.json
| Status | Count |
|---|---|
| Verified | 18 |
| Skipped | 4 |
| Broken | 0 |
| Decayed | 0 |
- The 4 Skipped are live-AWS capabilities (CAP-013..016) — honestly skipped because resources are torn down (D-096), not a failure
- Confidence distribution: from
metrics/nova_metrics.dbfact_confidence— score histogram, band breakdown (pass/halt)
Benefit: you now know the platform is verified — 18 capabilities pass, 4 are honestly skipped, 0 broken. The honesty model (Skipped ≠ failure) is what makes the Verified count credible.
Speaker notes: The 18V+4S number is the single most important proof point. It says "the platform works, and we're honest about what we can't test." The 4 Skipped are live-AWS capabilities — they're skipped because the live AWS resources are torn down (D-096), not because they're broken. When live AWS is re-provisioned, they reactivate.
Transition: "Capability health is necessary — here is the trust substrate that makes autonomy defensible."
Slide 11 — Decision Ledger + Attestation Coverage
This slide shows the trust metrics — Decision Ledger coverage and attestation coverage, both 100%.
- Decision Ledger Coverage: 100% of platform runs emit
ai.decision.madewith outcome backfill (source:metrics/decision_ledger.db) - Attestation Coverage: 100% of prod/dr promotions attested by a human (source:
hitl_gates.py+ outboxapprover_*attributes) - AI Decision Accuracy: decisions not followed by apply.failed/incident within 5min
- The trust-snapshot report (
metrics/TRUST_SNAPSHOT.md) with chain-integrity verdict - Planned: Tamper-Evident Ledger Checkpoints (D-083)
Benefit: you now know the trust is provable — not a marketing claim, a queryable record. The Decision Ledger is the moat; features can be copied, an immutable decision history cannot.
Speaker notes: The trust metrics are the "provably trustworthy" proof. Decision Ledger Coverage = 100% means no AI decision is ever lost. Attestation Coverage = 100% means no prod/dr promotion lands without a human sign-off. The chain-integrity verdict (from the trust snapshot) proves the ledger hasn't been tampered with.
Transition: "Trust is provable — here is the operational efficiency that makes the ROI real."
Slide 12 — Zero-Touch Efficiency
This slide shows the zero-touch efficiency metrics — touchless resolution, human escalation, and MTTR.
- Touchless Resolution Rate: runs without operational HITL block ÷ total (attestation gates excluded)
- Human Escalation Frequency: operational HITL blocks only (confidence-driven; attestation sign-offs excluded)
- MTTR (platform-run): apply.failed → successful retry (D-131)
Post-Pilot caveat: these three metrics are computed on N internal runs today; the production-denominator activates when a pilot estate runs (see NORTH_STAR Post-Pilot Targets section).
Benefit: you now know the zero-touch efficiency is measurable — the pipeline works today on internal runs, and the denominator expands to production estates when a pilot activates.
Speaker notes: The Post-Pilot caveat is the honesty model. The pipeline is grounded (it works); the denominator is zero (0 consumers). This is not a fabricated "99% touchless" claim — it's "the measurement works, and the numbers fill when a pilot runs."
Transition: "Efficiency is half the ROI story — here is the cost side."
Slide 13 — Cost & ROI
This slide shows the cost estimates and the ROI formula — with honest caveats about the current denominator.
- Cost Estimates via Infracost: pre-apply, grounded (reads plan JSON, offline)
- ROI formula (shown inline):
Platform ROI = (FTE hours saved × blended rate + cloud savings + avoided downtime) ÷ platform op cost - N=0 caveat: "These derived metrics are computed on N internal runs today; the production-denominator activates post-pilot. The formula is grounded; the production numbers are not yet."
- FTE Hours Saved (derived), Platform ROI (derived formula)
- Planned: Live CUR Reconciliation (D-096), Drift Auto-Reversal (D-096)
Benefit: you now know the ROI formula — and you know it's computed on internal runs today, not fabricated production numbers. The formula is ready; the production denominator activates with a pilot.
Speaker notes: The ROI formula is shown inline — not hidden in a footnote. The N=0 caveat is stated explicitly. This is the "no fabrication" constraint in action: we show the formula, we show the caveat, we don't pretend the production numbers exist.
Transition: "The proof is grounded — here is what is honestly deferred."
Slide 14 — What's Deferred — and Why
This slide pairs each deferred metric with its blocking decision — honesty about what isn't measured yet.
To be clear: these deferrals are measurement infrastructure, not whether the platform runs without humans. The platform IS autonomous in operations. What's deferred is the evidence pipeline for certain metrics — not the autonomy itself.
| # | Deferred Metric | Blocking Decision |
|---|---|---|
| 1 | Live Infrastructure Health | D-096 |
| 2 | Live Outbox Write Rate | D-096 |
| 3 | Tamper-Evident Ledger Checkpoints | D-083 |
| 4 | Onboarding Funnel (granted) | D-113/D-114/D-119 |
| 5 | Drift Auto-Reversal | D-096 + no scheduler |
| 6 | Live CUR Reconciliation | D-096 |
| 7 | SLA / Unplanned Downtime | D-096 |
| 8 | Predictive vs Reactive | future emitter |
From docs/METRICS_DEFERRED_ROADMAP.md.
Benefit: you now know the boundaries — what Nova measures today, and exactly what blocks the rest. The autonomy is real; the measurement gaps are documented.
Speaker notes: The preempt is critical: these deferrals are measurement infrastructure, not autonomy. The platform runs without humans in operations. What's deferred is the evidence pipeline for live-infra health, drift detection, predictive remediation — not the autonomy itself. Showing this slide to leadership demonstrates honesty, not weakness.
Transition: "The proof is honest — here is the roadmap from here to the 12–18 month targets."
Slide 15 — Roadmap to the North Star
This slide shows the path from v1.17's grounded metrics to the 12–18 month targets — the unblock path for each deferred metric.
- Each deferred metric → blocking decision → unblock requirement → candidate milestone
- The hot-path activation section (post-D-096, Nova-native only, D-120)
- Re-evaluation triggers: D-096 lift, D-083 lift, onboarding-grant lift
From docs/METRICS_DEFERRED_ROADMAP.md.
Benefit: you now know the path — every deferred metric has an unblock requirement and a candidate milestone. Nothing is hand-waved; everything has a plan.
Speaker notes: The roadmap is the bridge from "honestly deferred" to "here's how we get there." Each deferred metric has a specific unblock requirement and a candidate future milestone. The re-evaluation triggers ensure the metrics layer evolves when the blocking decisions lift.
Transition: "The roadmap is clear — here is the recap and the ask."
Slide 16 — Recap + Ask (the "what I told you" deck-level closing)
This slide recaps the 5 acts and states the ask.
Recap:
- Problem: the operator is the bottleneck; autonomy in operations, human at stage gates
- Vision: invisible operations with provable trust (NORTH_STAR)
- How: pipeline + Decision Ledger + 8-concern attestation matrix
- Proof: 18V+4S, 100% ledger coverage, 100% attestation, grounded ROI formula
- Roadmap: deferred metrics have unblock paths
The ask: "The ask is a business decision: approve a pilot estate to activate the production-denominator metrics (Touchless Resolution, Human Escalation, AI Decision Accuracy), and approve the tamper-evident ledger build-out (D-083 lift) to move from local hash-chain to S3 Object Lock + JWS. These two decisions move Nova from 'pipeline-ready' to 'production-proven.'"
Benefit: you leave with a clear business decision to make — approve a pilot + the ledger build-out — and the confidence that every claim in this deck is grounded, derived, or honestly deferred.
Speaker notes: The ask is a business decision, not insider language. "Approve a pilot estate" is something a C-suite can decide. "Approve the ledger build-out" is a budget decision. The recap reinforces the 5-act arc — the audience leaves with the structure, not a pile of facts.
Appendix Slide A1 — Metrics Glossary
This appendix defines every KPI in one line with its grounding badge.
| KPI | Definition | Status |
|---|---|---|
| Touchless Resolution Rate | runs without operational HITL block ÷ total | partial (Post-Pilot) |
| Human Escalation Frequency | operational HITL blocks ÷ total | partial (Post-Pilot) |
| AI Decision Accuracy | decisions not followed by failure within 5min | partial (Post-Pilot) |
| MTTR (p95) | apply.failed → successful retry | grounded |
| Confidence-Gate Halt Rate | runs with band=block ÷ total | grounded |
| Provisioning Lead Time | run.completed − run.started | grounded |
| Deployment Frequency | count(run.completed) per day | grounded |
| Cost Savings (Infracost) | sum(delta_usd where delta < 0) | partial (CUR deferred) |
| FTE Hours Saved | run count × manual baseline × rate | derived (N=0 caveat) |
| Platform ROI | (labor + cloud + avoided downtime) ÷ op cost | derived (N=0 caveat) |
| Decision Ledger Coverage | decisions with outcome ÷ total | grounded |
| Attestation Coverage | prod/dr attested ÷ total prod/dr | grounded |
| Policy Compliance Rate | 1 − failed_assets ÷ total | grounded |
Benefit: you now have a reference for every metric mentioned in the deck.
Appendix Slide A2 — Operating Model & Cost
This appendix shows the real cost figures + the zero-cost steady state.
- Cost figures from
COST.md: $0.001883 over 8 days, ~$0.007/month, S3-dominated, zero BAU compute - Zero-cost steady state: all resources torn down post-v1.11 (D-096); the platform runs offline
- References the pre-mortem (
PRE_MORTEM.md: v1.10 decay root cause + four forward failure modes + structural mitigations)
Benefit: you now know the operating cost is negligible — and the structural mitigation that prevents decay.
End of deck. 16 main slides + 2 appendix slides = 18 total. Both old decks (
how-the-platform-works+the-developer-experience) are retired (D-130).