Get a free API key

This page as Markdown, byte for byte: /GTM.md

CEDE — the go-to-market plan#

Status: first edition (CEDE-075), authored under adr/ADR-0021-go-to-market-mandate.md.

Standing: a first-class artifact alongside PRODUCTION.md. The planner reads this file in its boot ritual, ranks BACKLOG against its open phases exactly as it ranks against non-green production checks, ticks an action when the evidence that action names actually exists, and files drift between this plan and reality as BACKLOG items. PRODUCTION.md keeps priority wherever the two conflict — a product that fails its own checks has no business being launched at anyone.

How to read it. Prose is context and is never parsed. Every line beginning - [ is an action and matches exactly one grammar:

owner:fleet means a session can do it. owner:operator means only Ben can — money, legal, identity, and anything that leaves this machine for the open internet (ADR-0021 constraint 4: the fleet drafts and stages, the operator publishes). Every operator action here cites the BLOCKED_OPERATOR item that carries it, by number, so the operator queue stays the single place a human looks for their work. Evidence is a check that can flip, a thing that exists, or a number that can be read — never a judgement call.

tests/unit/test_gtm_plan.py holds all of that still: the grammar, the id shape, one owner per action, the BLOCKED_OPERATOR cross-reference, and the rule against asserting social proof this product has not earned.


The honest baseline#

Dated 2026-08-25, re-derived against the record as far as 2026-08-25T05:16:29Z — the newest line the record carries at this writing. That line is the last of the twelve the 2026-08-25 morning full sweep wrote, and every other line of the board below is one of the other eleven: this edition's board is one unattended sweep's own reading with nothing spliced into it, which the previous edition's was not. Every claim below names something checkable in this repo: a line in checks/history.log, a merged BACKLOG id, a file, or a figure a committed test recomputes.

This is the CEDE-224 edition: a drift pass over the CEDE-221 edition of 2026-08-18, not a wholesale re-cut of the section. It is also the longest gap this section has ever gone unrevised, and the reason is on the record rather than in anybody's memory. The item that produced this edition was cut to re-derive the baseline against the 2026-08-19 sweep; it did not run then, because the OAuth credential every spawned session runs on expired on 2026-08-20 and every session since aborted at authentication — BLOCKED_OPERATOR.md item 21, opened 2026-08-24, is the operator action, and BACKLOG's CEDE-246 is the fleet item that makes the instruments say so instead of wearing it as product red. So this edition re-derives against the newest sweep the record actually holds, the 2026-08-25 morning full sweep, rather than dating itself to a sweep six days behind the log: a baseline that is right about an older day is the one failure mode this section exists to prevent. What moved is what the record contradicts — the board and the sentences that describe it, the PROD-02, PROD-12, PROD-09 and PROD-07 bullets, the standing-reds bullet, whose whole premise flipped twice over, the Phase-2 and Phase-4 gate readings and this section's closing sentence — and every sentence they left true is the previous edition's, unrewritten. The headline count is ten, re-derived from the board below rather than carried across, and it is the same number the 2026-08-18 edition carried with four of the twelve checks having changed side under it. The plan's standing orders make that drift a BACKLOG item rather than a habit, and this is one.

The edition this replaces was the single one cut on 2026-08-18, and the one before it the single one cut on 2026-08-17; the day before that took two, and that pair is the shelf life of this section measured rather than guessed at. Seven days is the other end of that range, measured here for the first time and caused by an outage rather than by neglect. CEDE-194 was cut at 06:32Z on 2026-08-16 and re-derived only as far as 2026-08-16T01:27:30Z, which was the tip of the record at the time and was eleven-twelfths a report on 2026-08-15. It was internally consistent when it was written and false about the product an hour later, because the sweep it says did not run then ran: all twelve of its board lines were superseded between 07:36:40Z and 07:43:21Z, and its headline number and its Phase-2-gate claim went with them. CEDE-199 corrected that same afternoon for the drift CEDE-196's merge caused. Two editions in one day is not churn — and it is the one way this section is still allowed to rot, which is why re-deriving it is a BACKLOG item rather than a habit. Since CEDE-139 the board below is not typed from memory: tests/unit/test_gtm_baseline.py recomputes it from checks/history.log and fails the build if a line, or the count, has drifted. What that test cannot do is notice that a session never moved the block forward, because it pins the board as of the block's own newest line. So a stale baseline here never shows up as a wrong number — it is a right number about an older day, which is harder to catch and is exactly what this edition exists to correct.

2026-08-25T05:09:14Z PROD-01 FAIL 2026-08-25T05:09:15Z PROD-02 PASS 2026-08-25T05:10:46Z PROD-03 PASS 2026-08-25T05:11:10Z PROD-04 PASS 2026-08-25T05:11:20Z PROD-05 PASS 2026-08-25T05:13:26Z PROD-06 PASS 2026-08-25T05:13:58Z PROD-07 PASS 2026-08-25T05:15:05Z PROD-08 PASS 2026-08-25T05:15:59Z PROD-09 PASS 2026-08-25T05:16:02Z PROD-10 PASS 2026-08-25T05:16:28Z PROD-11 PASS 2026-08-25T05:16:29Z PROD-12 FAIL

This is the latest run reading. It is not PRODUCTION.md's DONE rule, which asks for seven consecutive green days and is what Phase 3's entry gate cites — nothing on this page moves that gate, and ten green today is not one green week. The number is re-derived from the twelve lines above rather than carried across, because a count copied forward is a count nobody has checked, and tests/unit/test_gtm_baseline.py recounts the block and fails the build if the two disagree.

Ten is the same number the 2026-08-18 edition printed, and almost nothing under it is the same. Four of the twelve checks changed side since that board — two reds went green and two greens went red, which is how a count stands still while everything under it moves — and this page states each as itself rather than netting them off. PROD-08 went green and has stayed green: the operator placed a test-mode key and CEDE-225 closed the probe's own race, and the standing-reds bullet below reads that out of the ledger. PROD-02 went green — the seven-day soak, red on every board this section has ever printed, first PASSed at 2026-08-21T05:02:43Z and has PASSed on every sweep since; that is the one unambiguously good movement on this board and it landed on exactly the date the 2026-08-18 edition re-derived as the earliest possible one. PROD-01 and PROD-12 went red, and they are red for one cause that is not the product: the walk agent both checks spawn cannot authenticate. So the red half of the board is a pair again, and it is a different pair, red for a different kind of reason — a dead credential rather than a clock. Both have their own treatment below.

All twelve lines are dated 2026-08-25 and all twelve are the morning full sweep's own, 05:09:14Z through 05:16:29Z, with nothing spliced in and no --only re-run anywhere in it — not because nothing went red on it, but because no session was able to run for six days to re-run anything. The previous edition's board was not that shape: eleven of its lines were the 2026-08-18 sweep's and the twelfth was a PROD-12 --only re-run taken sixteen minutes after the sweep's own PROD-12 line came back red — the same shape as the 2026-08-16 board this section has criticised before, which took eleven lines from the sweep and the twelfth from a re-measurement that merged three hours later. Every edition before the 2026-08-16 one carried a board assembled out of several days. That a sweep now runs each morning to make either possible is a repair, and it is worth keeping on the page because the thing it repaired was invisible: an earlier edition reported that no full sweep ran on 2026-08-16 because production_duty() in supervisor/supervisor.py skipped the day's run of checks/production.sh whenever checks/history.log already carried any PROD- line dated that UTC day — three restore-drill verdicts between 2026-08-16T00:13:30Z and 2026-08-16T01:27:30Z had erased the day — and it left open whether that skip was a defect worth a change to the harness. It was, the question is settled, and the settling is on the record twice over. CEDE-195 (merged b5ad358 at 07:34Z) re-keyed the skip to evidence the full sweep actually ran: the duty now skips only when every check id on the sweep's roster has a line dated today, the roster derived in code from PRODUCTION.md's own ### PROD-NN headings rather than a second hand-typed list, with supervisor/test_production_duty_skip.py holding it against fixture ledgers and wired into checks/gate.sh. On 2026-08-16 the very next supervisor tick took the sweep, two minutes after the merge. So this is not a fix asserted on the strength of a merge: the machinery that was broken on 2026-08-16 is the machinery that produced that day's board, and the twelve lines above are the tenth whole board it has produced — one a day, unattended, every day from 2026-08-16 to 2026-08-25 including the six on which no session could run at all, which is the strongest thing anyone can say for that repair.

The one walk that read the signpost is still the only one. 2026-08-18T05:30:24Z PROD-12 PASS was the newest PROD-12 line on the 2026-08-18 edition's board, taken as an --only re-run sixteen minutes after that sweep's own PROD-12 line came back red. Of the three outcomes a fork measurement can have, that walk produced the first: it fetched the signposted page and still priced by the route the signpost names. Read from the run retained at /opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:30:24Z.log: sixteen of its thirty-six requests went to the published docs site across six paths, and **four of them were /price** — the path src/cede/docsite/pages.py publishes docs/price.md at, which is the page carrying CEDE-196's signpost. It composed mdl_2e4dc84253714f46a990fa5956216e22 v1.0.0 from the four primitives, took its determinism check and its forty-year backtest across 1986-01-01..2025-12-31, and then priced through POST /models/{id}/runs: 1067250.47 THB on a technical basis, labelled with the model it had just composed. All four /price fetches fall after the 201 that created the model and before the pricing call, and POST /objects/{id}/price — the road the 2026-08-16 red took by mistake — was never called at all. 153.3 s of a 900 s budget.

What that does not settle, stated here as PRODUCTION.md's PROD-12 block states it and not enlarged, and re-derived from the record rather than carried across. One walk that took the signposted road is not proof the fork can never trap another, and the ratio has got weaker rather than stronger since the previous edition said so. Eleven PROD-12 lines have been recorded since the signpost deployed at 2026-08-16T10:55:27Z, and only four of them are walks that fetched anything at all — 2026-08-17T05:09:55Z PROD-12 PASS, 2026-08-18T05:30:24Z PROD-12 PASS, 2026-08-18T08:12:07Z PROD-12 PASS and 2026-08-19T05:27:16Z PROD-12 PASS. Of those four, exactly one opened the page. The other seven measured no route at all: 2026-08-18T05:14:33Z PROD-12 FAIL, whose agent asked for a permission it could not be granted, and the six credential deaths from 2026-08-20T08:07:56Z PROD-12 FAIL onward. The counts are grepped out of checks/history.log at this writing; the previous edition read three walks because two of them did not exist yet, and the 08:12:07Z line never appeared on any board because a later line superseded it before an edition was cut. A passing run also keeps no sandbox, only a red does, so what survives each of those walks is the retained log's record of the fetches and the route, not the session's own account of what it read there. What changed on 2026-08-18 is that the signpost is measured to work when it is read, rather than only published; nothing has added to that since, because nothing since 2026-08-19 has walked.

The red it replaced measured nothing about the product either way. 2026-08-18T05:14:33Z PROD-12 FAIL was that sweep's own PROD-12 verdict, and it was on the previous edition's board for the sixteen minutes before the re-run. Read from the run the sweep retained at /opt/cede/shared/prod-sweeps/PROD-12-2026-08-18T05:14:33Z.log: the walk's agent session exited 0 after 9.8 s with 0 HTTP requests recorded, so it never fetched the docs site, the clock the check starts at the first docs fetch never started, and nothing was composed from public docs — the run's own verdict line says either the docs were unreachable or the session did nothing, and establishes neither. The sandbox is kept at /tmp/cede-prod12-m9qzwlnu. Diagnosing that red was PRODUCTION.md's PROD-12 block's work and CEDE-220's rather than this page's, and it is diagnosed there: the spawned agent reached for a tool the walk harness does not allow it and stopped to ask for a permission it could not be granted, so the red is the harness's agent and not Cede.

The green before both is still in the record and still true of the day it was taken. 2026-08-17T05:09:55Z PROD-12 PASS was the fifteen-minute walk in 72.1 s of a 900 s budget and the first taken against a published docs tree carrying CEDE-196's signpost — the walk the previous edition said would measure the fork closed. It did not measure it. Read from /opt/cede/shared/prod-sweeps/PROD-12-2026-08-17T05:09:55Z.log, that walk fetched four docs pages — the index, /quickstart, /model-builder and /quickstart.md — never opened price.md, and took its price from POST /models/{model_id}/runs, whose job result came back labelled with the model it had just composed. That is why reading the signpost took a third walk.

What went red first, and why it is a different fault from either of 2026-08-18's two. 2026-08-16T07:43:21Z PROD-12 FAIL was the morning sweep's fifteen-minute composition walk, and it was not a timeout: the walk's own agent exited 0 after 121.5 s of a 900 s budget, having composed and validated mdl_9381bd3bd8e84f40bcc0027a901a8e58 v1.0.0 from the four primitives, taken its determinism check and its forty-year backtest, and priced — but priced through POST /objects/{id}/price, the generic verb, which answers with the platform pricing model — the priced job came back labelled cede/parametric-burn-station-index v0.1.0, which is not the model the session composed — so no recorded response carried a price labelled with the model it had just built and ADR-0032's stop condition never fired. **The fork, in one sentence: docs/price.md is the page the walk reads after docs/model-builder.md, and it taught the object-price route without saying that a price labelled with a model you composed comes from POST /models/{id}/runs instead — so a reader who followed the docs in order arrived at the wrong route and the check was right to refuse.** The platform label on that response is P9 working as specified, not the defect. That red was attributable without a re-run because CEDE-193's retention kept the run: /opt/cede/shared/prod-sweeps/PROD-12-2026-08-16T07:43:21Z.log and the sandbox at /tmp/cede-prod12-q0dkixde. **CEDE-196 signposted the fork in docs/price.md, above the page's first runnable block, and re-measured.**

Both caveats that history carried are now discharged, and both are PRODUCTION.md's PROD-12 block's own. The first was about publication: the docs site serves /opt/cede/current/docs, which is main's tree, so the signpost reached readers only at the first deploy after the merge — that deploy landed at 2026-08-16T10:55:27Z, release db5499c7cb33 in /opt/cede/shared/deploys.log, and every walk that has fetched anything since — 2026-08-17, both on 2026-08-18, and 2026-08-19 — was taken against the tree it published. The second was that no walk had yet reached the fork, and until 2026-08-18 it stood on three walks: none of the 08:28:20Z, 05:09:55Z or 05:14:33Z walks fetched price.md at any point — the first two stopped the clock on a job result from POST /models/{model_id}/runs carrying the composed model's own label, and the third fetched nothing whatsoever. The 05:30:24Z walk is the one that discharges it, on the terms the caveat itself named: it opened price.md and priced with its own model anyway. Read together: the check was green on the last measurement it managed to take, which is 2026-08-19's and is no longer the newest line it has; the fork is still a road a walk may take wrongly, and one walk since the signpost deployed has been measured taking it rightly.

Ten of the twelve production checks are green at their latest run, the two that are not could not be measured at all, and none of it is reachable by name, so this product still does not have a distribution problem; it has an evidence problem — and for six days it has had a narrower one, which is that it could not take its own measurements. So Phase 1 produces receipts, not reach, and every later phase is gated on receipts that already exist — including this section, which is now a receipt rather than a recollection.


Who it is for#

Three segments, most-likely-first. The reasoning matters more than the order — the order is a consequence of it.

A. Parametric program designers at MGAs and program managers. First, because their job is the four verbs that are already live: take a schedule nobody can read, define a trigger, run it across forty years, and get a technical price with its assumptions on the face of it. Nothing in that sentence needs analyse, monitor or package, so this segment can get real value from the product as it stands today rather than as it stands after two more quarters. They are also the persona the nightly QA cohort already imitates, so the gaps they would hit are being found and filed every night by a synthetic version of them — the cheapest possible form of discovery, and the only demand signal this fleet is permitted to have.

B. ILS and ILW analysts. Second, because they are the segment most likely to punish a number that arrives without its assumptions — which is exactly the discipline the product already enforces in code. Determinism against pinned snapshots, results that replay byte for byte, a backtest that discloses thin data years instead of silently interpolating them: these are table stakes to this audience and are rare enough elsewhere to be worth naming. Smaller population than A, higher standards, slower to arrive, and the best possible reviewers of the registry.

C. Insurtech and platform engineers embedding risk analytics. Third by revenue proximity, first by distribution. Engineers adopt a format long before they adopt a vendor: the canonical object's schema is open source and consumable with no account at all (SPEC §5.4, §6), so this segment can be served completely without a commercial relationship. Every team that normalises to the canonical object is a path back to segments A and B, and the schema repo is the only channel in this plan that costs nothing to run and never goes stale.

Deliberately not targeted in the first edition, with the reasoning stated so a later session can overturn it on evidence rather than taste:


Positioning#

The sentence, which is already the site's: a file format for risk. One canonical object; an engine of verbs over it; an open registry of validated models and feeds. You bring the paper — the product is software, and stays software.

Three proofs carry that sentence, all of them artifacts rather than adjectives:

  1. The cursed corpus. Ingest is measured against real-world-ugly files — merged cells, header drift, mixed encodings, ambiguous units — as an append-only oracle that must pass at 100% or no merge happens. The statement "we read the files you actually have" is not a promise here; it is a test run count anyone can read.
  2. Assumptions on the face of every number. A technical price carries its model versions, data vintages, event set, loadings and currency basis as first-class response fields, and ingest records every guess it made in source_fidelity rather than dropping it silently. The honest disclosure is the product.
  3. Replay. Models are deterministic against pinned snapshots, results replay byte for byte, and CI re-validates every published model on every build. A result that cannot be reproduced is treated here as a defect, not a caveat.

What this plan never writes. No social proof before it exists: no invented case studies, no logo wall, no user counts, no praise attributed to somebody who never said it (ADR-0021 constraint 2). Until real users exist, the material is the product's own receipts — run ids, the playground walk, corpus counts, the disclosure lines, this repo's own honest red checks. That is not a restriction the plan works around: it is the position. The pitch is that this product does not overstate, and a page that overstates refutes the pitch in one line. Earning real proof — design partners, recorded permission, written-up walks — is legitimate work and appears below as owner-tagged actions.

The perimeter. BRIEF.md's perimeter governs every line of this plan and every surface it spawns, exactly as it governs product copy: a landing page and a launch post are product copy. No file or directory this plan creates is exempt from the scanner — docs/GTM.md is itself in scanned scope, and bash checks/gate.sh is the proof. Where a page needs a disclaimer line, it reuses one of the reviewed lines already in checks/perimeter-allow.txt verbatim rather than inventing a new phrasing that has never been reviewed.


The phase sequence#

Four phases, gated on evidence and never on dates (BACKLOG standing rule). Each phase states its entry gate as a check somebody can run.

The hard rule, from ADR-0021 constraint 3: no public-launch action may begin before all three of — the PROD board green, terms approved by the operator, and a production host. They are the entry gate to Phase 3, stated there as three runnable checks. Phases 1 and 2 are deliberately shaped so that all the work which does not require them happens first, and the fleet is never waiting.

Phase Name What leaves this machine
1 Receipts nothing
2 Named evaluation nothing; named people are brought to the tailnet
3 Public availability the product, on a real name
4 Metered commercial motion invoices, in test mode until item 9

Phase 1 — Receipts#

Entry gate. None. This phase is the present state and is open now.

The purpose is to make the three proofs above legible to a stranger without anything leaving this machine. The channels in this phase are all ones the fleet already controls: the specification page, the docs site, the playground, and the open schema. No external channel is touched, so nothing here waits on the operator.

Exit condition: everything in Phase 2's entry gate is satisfiable.


Phase 2 — Named evaluation#

Entry gate. All three, each a runnable check:

  1. bash checks/production.sh --only PROD-01 PASSes — a fresh session goes from signup to a first authenticated call in under ten minutes on public docs alone;
  2. bash checks/production.sh --only PROD-12 PASSes — a fresh session composes a model, backtests it, and prices with it in under fifteen minutes;
  3. GTM-05 is ticked — there is a brief to send.

Nothing in this phase is public. Named people are brought onto the operator's tailnet, one at a time, and the only channel is the operator's own existing relationships — no posting, no accounts, no lists. The point of the phase is not revenue and not references: it is to find out which of the three segments returns a second time without being asked, because that answer re-ranks everything below it.

Exit condition: at least two named evaluators have completed a real job through public interfaces alone, and their gaps are BACKLOG items.


Phase 3 — Public availability#

Entry gate — the constraint-3 gate, all three required. No action in this phase that exposes anything to the open internet may begin before every one of these is true:

  1. The PROD board is green: bash checks/production.sh --done exits 0 — which by PRODUCTION.md's own DONE rule means every PROD-NN has been green for seven consecutive days. The weaker reading (all twelve green once) was considered and rejected: a launch is the least reversible thing this fleet can do, and a single green day is exactly the evidence a flake produces.
  2. Terms exist: BLOCKED_OPERATOR item 8 is marked DONE by the operator and the signup surface no longer labels its terms as a draft pending review.
  3. A production host exists: prod_host is non-null in cede.config.json, with the domain and DNS behind it (BLOCKED_OPERATOR items 5 and 6).

Two actions here sit deliberately in front of that gate, and must. GTM-14 drafts the terms and GTM-17 drafts the launch note and the posts. Neither exposes anything — both produce files in this repo and stop. Gating them on the gate would deadlock the phase: BLOCKED_OPERATOR item 8 asks the fleet to draft terms so that the operator can approve them, and approved terms are gate condition 2. Constraint 3 governs public-launch actions; drafting and staging are what the fleet does while waiting for one.

Channels in this phase, in the order they earn their keep: the public schema repo (free, permanent, and the only one aimed at segment C); the docs site on a real name; and at most three practitioner or developer communities the operator names before posting. No paid acquisition at all — there is no budget for it under BRIEF.md's cost ceiling, and a channel the fleet cannot measure from its own logs is a channel this plan will not defend.

Exit condition: a stranger with no introduction completes the ten-minute walk on the public name, and the fleet can see them do it in the request log.


Phase 4 — Metered commercial motion#

Entry gate. Both:

  1. bash checks/production.sh --only PROD-08 PASSes — the full billing lifecycle is green in test mode, which is CEDE-072's acceptance, not this plan's;
  2. BLOCKED_OPERATOR item 7 is DONE, so test-mode keys exist where the deploy config expects them.

This phase deliberately contains no metering or billing design. Usage metering is CEDE-071 (merged) and the test-mode lifecycle is CEDE-072; restating either here would create a second place for them to be true, which is how two files start disagreeing. What belongs here is only the commercial motion on top of them: saying the price basis out loud, in public, sourced from the meter.

Real charges are the operator's alone (BLOCKED_OPERATOR item 9), and no session may approach that switch.

Exit condition: an account can sign up, use the product, and see a correct metered invoice without anybody being asked anything.


What would make a later session re-cut this plan#

Stated up front so a re-cut reads as evidence, not as a change of mind: