{
  "version": "1.8.0",
  "slug": "401k-delinquent-deposit-correction-engine",
  "title": "CorrectPath — 401(k) Delinquent Deposit & Fiduciary Correction Engine",
  "vertical": "401(k)/403(b) delinquent deposit detection & DOL/IRS fiduciary correction compliance",
  "seed": {
    "s": "401k-delinquent-deposit-correction-engine",
    "t": "CorrectPath — 401(k) Delinquent Deposit & Fiduciary Correction Engine",
    "v": "401(k)/403(b) delinquent deposit detection & DOL/IRS fiduciary correction compliance",
    "r": "Medium-high",
    "m": "M"
  },
  "product": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "project_name": "CorrectPath",
    "project_type": "flat-fee 401(k)/403(b) delinquent-deposit detection and DOL/IRS fiduciary correction service",
    "vertical": "401(k)/403(b) plan-sponsor ERISA operational compliance",
    "audience": "controllers, VPs of HR/Benefits, and Directors of Total Rewards at 100-1,000-employee companies sponsoring a 401(k)/403(b) defined-contribution plan, with no in-house ERISA correction specialist",
    "geography": "United States (federal ERISA/DOL/IRS jurisdiction, not state-by-state) — no single-state beachhead required; outreach concentrated around CPA benefit-plan-audit season and the extended Form 5500 deadline (Oct 15)",
    "scale_expectation": "pilot cohort of 8 plan sponsors in the first 90 days, sourced through 2 CPA-firm referral partners; steady-state deadline-driven demand clustered around plan-audit season, not a daily-transaction volume business",
    "core_workflows": [
      "Payroll withholding-date / recordkeeper contribution-posting-date intake & completeness check",
      "Data extraction, normalization & Late Deposit Instance detection",
      "Deterministic Lost Earnings & excise-tax calculation, SCC-vs-VCP eligibility determination",
      "Compliance Reviewer verification & Filing Attorney/EA execution coordination"
    ],
    "discovery": {
      "one_line_purpose": "On CorrectPath, 401(k)/403(b) plan sponsors stop guessing whether a late-deposit finding is SCC-eligible and start getting a signed, DOL-methodology-accurate Correction Certificate every time. Payroll and recordkeeper data are extracted and normalized at intake, every Late Deposit Instance is detected, a Compliance Reviewer verifies the calculation, and a partner ERISA attorney or Enrolled Agent executes any required filing.",
      "primary_users": [
        "Controller or VP of HR/Benefits at the plan-sponsoring employer",
        "TPA or CPA benefit-plan-audit firm referring a client's correction",
        "Partner ERISA attorney or Enrolled Agent/CPA engaged to review and execute a filing"
      ],
      "jobs_to_be_done": [
        "Get a complete, DOL-methodology-accurate Correction Certificate without hiring an ERISA correction specialist onto staff",
        "Answer an auditor's late-deposit finding with a signed remediation memo, not a guess",
        "Determine SCC-vs-full-VCP eligibility correctly the first time, before the Form 5500 deadline"
      ],
      "value_prop": "CorrectPath turns a sponsor's scattered payroll withholding dates and recordkeeper contribution-posting dates into a signed, DOL-methodology-accurate Correction Certificate — defensible to a plan auditor or the DOL, with the sponsor always the party of record on the filing.",
      "competitors": [
        "Specialist TPAs (DWC, TRA401k) that sell correction/restoration services manually, spreadsheet-based, capacity-constrained",
        "ERISA boutique law firms (Trucker Huss, Belfint, Boyum Barenscheer) whose hourly billing makes a sub-$1,000 Lost Earnings correction disproportionately expensive",
        "Generalist TPAs/recordkeepers offering correction as an ad hoc, unpredictably-priced add-on",
        "The status quo: the sponsor's finance team manually date-matching payroll against recordkeeper posting records in a spreadsheet"
      ],
      "differentiation": "Done-for-you late-deposit detection and correction-package production, not a tool to operate: AI-native detection and DOL-methodology calculation combined with a fixed-fee, 5-business-day-turnaround product and a coordinated Compliance Reviewer/Filing Attorney-EA sign-off, sized for the large majority of the 836,800 on-file plans with no in-house ERISA specialist.",
      "positioning_statement": "For 401(k)/403(b) plan sponsors who have just learned of a late-deposit finding, CorrectPath is the done-for-you delinquent-deposit detection and correction desk that turns raw payroll and recordkeeper data into one signed, DOL-methodology-accurate Correction Certificate — unlike a generalist TPA that flags the finding but doesn't offer a fixed-fee correction product, or an hourly-billed ERISA attorney the sponsor must scope and manage alone."
    },
    "assumptions": [
      {
        "id": "401k-delinquent-deposit-correction-engine-a1",
        "statement": "Plan sponsors will pay a flat fee for a done-for-you Correction Certificate over continuing to attempt the DOL lost-earnings calculation themselves, once shown a concrete Deposit Timing Readiness Scan finding.",
        "confidence": "medium",
        "impact_if_wrong": "severe",
        "revisit_trigger": "First 10 pilot Readiness Scan sales conversations — reject the wedge if willingness-to-pay signal is absent."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-a2",
        "statement": "A Correction Certificate can hit the 5-business-day (launch) delivery SLA from sponsor-supplied payroll and recordkeeper exports alone, without custom payroll-system integration.",
        "confidence": "medium",
        "impact_if_wrong": "high",
        "revisit_trigger": "First 3-6 pilot engagements."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-a3",
        "statement": "Sponsors and referral-partner CPA/TPA firms tolerate AI-assisted detection and calculation when a Compliance Reviewer's verification and a Filing Attorney/EA's execution are explicit on every Correction Certificate.",
        "confidence": "medium",
        "impact_if_wrong": "high",
        "revisit_trigger": "First auditor pushback on a delivered certificate."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-a4",
        "statement": "Deposit Timing Readiness Scan-to-paid-engagement conversion reaches at least 25% among qualified, referral-sourced sponsors.",
        "confidence": "low",
        "impact_if_wrong": "severe",
        "revisit_trigger": "Day-90 pilot-cohort conversion measurement (explicit kill/pivot gate at 25%)."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-a5",
        "statement": "TPA channel partners will refer correction work rather than build the capability in-house — the source blueprint's own Unverified, low-confidence assumption.",
        "confidence": "low",
        "impact_if_wrong": "high",
        "revisit_trigger": "First 90 days of TPA-partner outreach; pivot to direct-to-sponsor motion if referral volume stays near zero."
      }
    ],
    "unknowns": [
      {
        "id": "401k-delinquent-deposit-correction-engine-u1",
        "question": "Which specific ERISA-credentialed Compliance Reviewer verifies the first cohort's Correction Certificates?",
        "blocks": "Any commercial engagement; the reviewer sign-off invariant.",
        "resolution_path": "Named reviewer + engagement letter on file before the first paid Scan."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-u2",
        "question": "What is the true Deposit Timing Readiness Scan-to-paid conversion rate among referral-sourced sponsors?",
        "blocks": "Pricing hypothesis; scaling decision.",
        "resolution_path": "8-plan pilot cohort with explicit pricing conversation, measured against the Day-90 checkpoint (25% kill gate)."
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-u3",
        "question": "How much does the payroll/recordkeeper format-mapping library actually reduce Compliance Reviewer minutes by Day 90?",
        "blocks": "Unit-economics model; throughput assumptions.",
        "resolution_path": "Instrument reviewer minutes per engagement from pilot 1; compare to the 100-min-launch to 53-min-Day-90 target."
      }
    ],
    "expert_panel": [
      {
        "role": "Product Strategy",
        "key_concern": "Is the SCC-eligible Correction Certificate narrow enough to sell in weeks without a custom payroll integration?",
        "recommendation": "Launch scoped to a single-plan-year, single-entity SCC-eligible correction against one payroll/recordkeeper export pair; expand to full VCP/VFCP scope only after the pilot converts.",
        "dissent": "May understate the Deposit Timing Monitoring recurring-revenue story to early referral partners expecting an always-on offering."
      },
      {
        "role": "Software Architecture",
        "key_concern": "Are we defaulting to a client-facing portal the pilot doesn't need yet?",
        "recommendation": "Single deployable modular monolith; upload-link/email intake only at launch, no client portal.",
        "dissent": "May read as under-built to a TPA partner expecting a branded dashboard."
      },
      {
        "role": "Frontend / UX",
        "key_concern": "Is the evidence chain (payroll withholding date to recordkeeper posting date to reviewer verification) visible in every reviewer-facing view?",
        "recommendation": "Every Correction Certificate line renders its payroll citation, matched recordkeeper posting date, and reviewer decision in one glance.",
        "dissent": "Adds density a non-ERISA reviewer might call cluttered."
      },
      {
        "role": "Backend / Data",
        "key_concern": "Is the audit trail append-only and reconstructable for a plan-committee fiduciary-file request years later?",
        "recommendation": "Event-sourced audit log for every correction-cycle state transition; hash-chained artifact snapshots.",
        "dissent": "More write-path complexity than plain CRUD; requires schema discipline as DOL/IRS rule formats evolve."
      },
      {
        "role": "AI / ML",
        "key_concern": "Are detected Late Deposit Instances grounded in source payroll/recordkeeper data and never a free-form guess?",
        "recommendation": "Retrieval-first detection citing the specific payroll/recordkeeper line pair; deterministic Lost Earnings math in code, never the model; mandatory Compliance Reviewer gate before any sponsor- or DOL/IRS-facing claim.",
        "dissent": "Slower per-cycle than a fully automated tool; may frustrate a sponsor expecting instant results."
      },
      {
        "role": "Security",
        "key_concern": "Is one sponsor's payroll and recordkeeper data isolated from every other sponsor's?",
        "recommendation": "Row-level auth, per-tenant retrieval indices, log-scrubbing of payroll/financial figures.",
        "dissent": "None recorded this run."
      }
    ],
    "strategy": {
      "business_model": "Flat fee per SCC-eligible Correction Certificate, scoped fixed quote for full VCP/VFCP Applications, per-participant-year rate for large-plan calculation runs, and an optional annual Deposit Timing Monitoring retainer; never hourly, never a percentage of any recovered or corrected amount — there is no monetary recovery in a compliance correction, so contingency pricing is never used, at any scale.",
      "revenue_streams": [
        "Deposit Timing Readiness Scan (free lead magnet)",
        "SCC-Eligible Correction Certificate ($2,500-$4,000 flat)",
        "Full VCP/VFCP Application ($6,000-$15,000 scoped quote)",
        "Per-Participant-Year Lost Earnings Calculation ($150/participant-year)",
        "Deposit Timing Monitoring ($1,800-$4,800/yr retainer)"
      ],
      "moat": [
        "Maintained DOL VFCP methodology / IRC §4975 / EPCRS rule library, compounding with every rule change tracked",
        "Payroll/recordkeeper format-mapping library across ADP, Gusto, Paychex, Fidelity, Empower, Voya, Ascensus",
        "Named Compliance Reviewer's verification and Filing Attorney/EA's execution accountability on every certificate",
        "Accumulated pattern library of what auditors and DOL examiners have actually accepted as sufficient documentation"
      ],
      "gtm": [
        "CPA benefit-plan-audit firm and TPA referral partnerships (the primary, lowest-CAC channel)",
        "Founder-led educational content + anonymized Deposit Timing Readiness Scan teardowns",
        "ERISA attorney referral network for sub-$5k correction work firms can't profitably bill hourly"
      ],
      "pricing_hypothesis": "Deposit Timing Readiness Scan free; SCC-Eligible Correction Certificate $2,500-$4,000 flat — priced below typical ERISA-attorney hourly cost for equivalent scope and above the IRS's own $1,500-$3,500 VCP-fee-only benchmark, validated against 10+ pricing conversations before scaling spend.",
      "kill_criteria": [
        "No signed pilot plan sponsor in 4 weeks of qualified referral outreach",
        "Compliance Reviewer median cycle time exceeds the Day-90 target (53 minutes) by more than double after pilot 5",
        "No paid standard-price conversion by Day 90",
        "A delivered Correction Certificate or DOL inquiry causes a documented, CorrectPath-caused reputational or client-relationship incident"
      ]
    },
    "security": {
      "stride": [
        {
          "threat": "Spoofing",
          "scenario": "Attacker impersonates a Compliance Reviewer to approve a fabricated Late Deposit Instance or verify a Correction Certificate.",
          "mitigation": "SSO with MFA; reviewer verifications bound to a cryptographic session claim, not a form field."
        },
        {
          "threat": "Tampering",
          "scenario": "Historical payroll/recordkeeper export or calculation entries edited after the fact to hide a miscalculation.",
          "mitigation": "Append-only audit log; hash-chained artifact snapshots; diff view on every reviewer surface."
        },
        {
          "threat": "Repudiation",
          "scenario": "A reviewer denies verifying an instance or a Filing Attorney/EA denies executing a filing that later proves wrong.",
          "mitigation": "Signed attestations with server-side timestamp + actor identity; delivered package includes a signature manifest."
        },
        {
          "threat": "Information Disclosure",
          "scenario": "Cross-tenant leak of one sponsor's payroll/financial data through shared indices, logs, or prompts.",
          "mitigation": "Tenant-scoped row-level auth; PII/financial-data scrubbing in logs; retrieval indices partitioned per sponsor."
        },
        {
          "threat": "Denial of Service",
          "scenario": "A runaway extraction job or bulk export exhausts shared workers during an audit-season delivery crunch.",
          "mitigation": "Per-tenant concurrency + budget caps; circuit breaker on model calls; degrade-gracefully queue."
        },
        {
          "threat": "Elevation of Privilege",
          "scenario": "A standard operator acquires reviewer-verification or filing-execution capability via a workflow shortcut.",
          "mitigation": "Roles stored in a separate table; capability checks server-side; no client-only role checks."
        }
      ],
      "privacy_posture": "Data-minimization by default; per-sponsor isolation; data-processing terms on file; deletion-schedule runbook published.",
      "compliance_targets": [
        "ERISA fiduciary/prohibited-transaction and DOL VFCP methodology adherence",
        "SOC 2 Type I (year 2 roadmap)",
        "Filing Attorney/EA licensing-boundary review confirmed per engagement before scaling",
        "DOL/IRS portal terms-of-service log for any automated filing-status check"
      ],
      "data_classifications": [
        "Sponsor payroll withholding-date data (sensitive business data)",
        "Recordkeeper contribution-posting-date exports (sensitive, third-party-sourced)",
        "Plan-document deposit-timing excerpts (sensitive, plan-adjacent)",
        "Contact/PII (standard)"
      ]
    },
    "devops": {
      "ci_cd": "PR -> typecheck + unit + snapshot tests -> preview deploy -> main auto-deploys to a single production region; migrations gated on review.",
      "environments": [
        "local",
        "preview (per-PR)",
        "staging (shared)",
        "production (single region + multi-AZ)"
      ],
      "observability": [
        "Structured logs with tenant + request IDs",
        "RED metrics per workflow",
        "Error tracking with source maps",
        "Model-call spans with cost + latency",
        "Weekly SLO review, with a month-end delivery-crunch capacity review"
      ],
      "testing_pyramid": [
        "Unit tests on matching-derivation and tie-out validation modules",
        "Component tests on reviewer exception-queue surfaces",
        "Contract tests on DOL or IRS-payroll/recordkeeper export-schema parsers",
        "End-to-end smoke test on the intake -> match -> reviewer-signoff -> delivery path"
      ],
      "accessibility_tests": [
        "axe-core in CI on reviewer-facing surfaces",
        "Keyboard-only walkthrough per workflow",
        "Prefers-reduced-motion honored"
      ],
      "performance_budget": "p95 workflow latency published per module; payroll/recordkeeper export-extraction cold-path under 30s or shown as a background job."
    },
    "accessibility_i18n_ethics": {
      "wcag_target": "AA",
      "locales": [
        "en-US"
      ],
      "rtl_support": false,
      "ethical_risks": [
        "A Late Deposit Instance or Lost Earnings figure released without Compliance Reviewer verification",
        "A DOL/IRS filing draft read as a demand or collection-style threat rather than a correction filing",
        "An error in a Correction Certificate attributed to AI rather than owned by the reviewer/attorney of record"
      ],
      "ethical_guardrails": [
        "Human Compliance Reviewer verification required before any Late Deposit Instance or filing draft ships",
        "Deterministic output filter blocks demand/collection-style language in every drafted DOL/IRS filing",
        "AI-usage disclosure available in the engagement letter where relevant"
      ]
    },
    "governance": {
      "ownership": [
        {
          "area": "Product + roadmap",
          "owner": "Founder"
        },
        {
          "area": "Architecture + platform",
          "owner": "Engineering Lead"
        },
        {
          "area": "Detection + reviewer workflow",
          "owner": "Named Compliance Reviewer"
        },
        {
          "area": "Compliance + privacy",
          "owner": "Compliance Lead"
        },
        {
          "area": "Design system",
          "owner": "Design Lead"
        },
        {
          "area": "SEO + content",
          "owner": "Content Lead"
        }
      ],
      "docs_required": [
        "ADR log (checked in)",
        "Owner-action ledger",
        "Evidence register",
        "STRIDE threat model",
        "Runbook: incident, restore, breach notification",
        "Reviewer playbook + signature invariant"
      ],
      "naming_conventions": [
        "kebab-case slugs for blueprints and routes",
        "camelCase for TypeScript identifiers",
        "SCREAMING_SNAKE_CASE for environment variables",
        "Verb-first action names (e.g., generate-correction-certificate)"
      ],
      "change_control": "ADR-per-major-decision; migrations require review; production deploys gated on green CI + owner-action ledger check."
    },
    "risk_register": [
      {
        "id": "401k-delinquent-deposit-correction-engine-r1",
        "risk": "A DOL/IRS-facing filing claim proves incorrect",
        "likelihood": "medium",
        "impact": "severe",
        "mitigation": "Every Lost Earnings figure linked to a dual-calculation cross-check + Compliance Reviewer sign-off",
        "contingency": "Retraction workflow; sponsor-notification template; audit-log export within 24 hours",
        "owner": "legal"
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-r2",
        "risk": "AI hallucination in a delivered Late Deposit Instance or filing draft",
        "likelihood": "medium",
        "impact": "high",
        "mitigation": "Retrieval-first pipeline + structured output validation + Compliance Reviewer gate",
        "contingency": "Reviewer-triggered rollback + regeneration; incident postmortem published to the sponsor",
        "owner": "engineering"
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-r3",
        "risk": "Cross-tenant sponsor payroll/financial data leak",
        "likelihood": "low",
        "impact": "severe",
        "mitigation": "Row-level auth + per-tenant retrieval indices + log-scrubbing",
        "contingency": "Breach-notification runbook; forced credential rotation; scoped tenant kill switch",
        "owner": "engineering"
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-r4",
        "risk": "Pilot plan sponsor churns before converting to a paid Correction Certificate",
        "likelihood": "medium",
        "impact": "high",
        "mitigation": "Weekly working-session cadence during pilot; documented value moments; owner-action ledger",
        "contingency": "Structured exit interview; write learnings into ICP + pricing hypothesis",
        "owner": "owner"
      },
      {
        "id": "401k-delinquent-deposit-correction-engine-r5",
        "risk": "A payroll/recordkeeper vendor ships free, good-enough late-deposit detection",
        "likelihood": "medium",
        "impact": "high",
        "mitigation": "Payroll/recordkeeper-agnostic positioning; the Compliance Reviewer/Filing Attorney-EA sign-off as the human moat software won't replicate",
        "contingency": "Reposition around the licensed sign-off and rule-library depth; lean harder into the full VCP/VFCP and Deposit Timing Monitoring lines",
        "owner": "owner"
      }
    ],
    "roadmap": [
      {
        "phase": "Phase 0 — Discovery + pilot LOI",
        "weeks": "Weeks 1-2",
        "outcomes": [
          "3-5 pilot plan-sponsor LOIs",
          "Evidence pack from each pilot sponsor",
          "Written ICP + pricing hypothesis"
        ],
        "exit_criteria": [
          "≥3 LOIs signed",
          "Owner-action ledger populated per sponsor",
          "Reviewer identity confirmed"
        ],
        "kill_criteria": [
          "<2 LOIs after 2 weeks",
          "No willingness-to-pay signal above pilot price"
        ]
      },
      {
        "phase": "Phase 1 — Thin vertical slice",
        "weeks": "Weeks 3-4",
        "outcomes": [
          "Intake -> detect -> reviewer verify -> deliver working end-to-end for one payroll/recordkeeper format pair",
          "Audit trail wired",
          "Instrumentation live"
        ],
        "exit_criteria": [
          "1 real Deposit Timing Readiness Scan delivered + reviewer-verified",
          "p95 workflow latency published"
        ],
        "kill_criteria": [
          "Reviewer verification cycle >10 business days",
          "Evidence bundle cannot be reconstructed on demand"
        ]
      },
      {
        "phase": "Phase 2 — Pilot cohort",
        "weeks": "Weeks 3-8",
        "outcomes": [
          "8 pilot plan sponsors scanned",
          "First standard-price Correction Certificate conversion",
          "SOC 2 Type I scoping"
        ],
        "exit_criteria": [
          "≥1 standard-price contract",
          "Post-scan debrief trust signal captured",
          "Postmortem cadence in place"
        ],
        "kill_criteria": [
          "No standard-price conversion by Day 90",
          "Scan-to-certificate conversion below 25%"
        ]
      },
      {
        "phase": "Phase 3 — Recurring-desk scale-up",
        "weeks": "Weeks 9-13 (Day 90 checkpoint)",
        "outcomes": [
          "Public commercial launch of the microsite as 'ready'",
          "Deposit Timing Monitoring retainer and per-participant-year line active",
          "Owner-action ledger closed for launch"
        ],
        "exit_criteria": [
          "COGS/rework/cycle-time measured against target",
          "Expansion beyond the pilot cohort gated on targets, not calendar time"
        ],
        "kill_criteria": [
          "Rework rate persistently above 8%",
          "Reviewer minutes per engagement not falling with volume"
        ]
      }
    ],
    "metrics": {
      "north_star": "Signed Correction Certificates delivered per month, with zero client-caught material errors",
      "leading": [
        "Pilot plan-sponsor LOIs signed",
        "Scan-request-to-delivered-Scan cycle time",
        "Compliance Reviewer verification cycle time",
        "Evidence coverage per Correction Certificate line",
        "Owner-action ledger closure rate"
      ],
      "lagging": [
        "Paid standard-price certificates signed",
        "Scan-to-certificate conversion (target ≥40%, pilot gate 25%)",
        "Client-caught material error rate (target <0.5%)",
        "Referral-partner retention (target ≥85% annualized)"
      ],
      "guardrails": [
        "Model spend per tenant per week",
        "PII/financial data in logs (target: 0)",
        "Cross-tenant access attempts (target: 0)",
        "p95 workflow latency ceiling"
      ]
    },
    "executive_review": {
      "consensus": "Ship a thin, evidence-linked, reviewer-gated vertical slice for CorrectPath, wedged on the Deposit Timing Readiness Scan. Prefer a boring, single-region modular monolith. Do not launch commercially until owner-action facts close and at least one reviewer-verified, Filing-Attorney-EA-executed Correction Certificate has shipped.",
      "dissent": "Executive Sponsor and Privacy/Compliance disagree on launch tempo — Privacy recommends waiting for a full Filing Attorney/EA-panel and E&O-insurance review before enabling the full VCP/VFCP Application tier anywhere.",
      "go_no_go": "conditional-go",
      "top_3_risks": [
        "A DOL/IRS-facing filing claim proves incorrect",
        "AI hallucination in a delivered Late Deposit Instance or filing draft",
        "Cross-tenant sponsor payroll/financial data leak"
      ],
      "first_10_steps": [
        "Confirm the named Compliance Reviewer + engagement letter on file",
        "Populate owner-action ledger with entity, jurisdiction, contact inbox, privacy inbox",
        "Open pilot-cohort intake (cap 8) with explicit pricing conversation",
        "Write ICP + kill/pivot criteria in the plan file",
        "Stand up the evidence-linked intake -> detect -> reviewer verify loop",
        "Wire append-only audit log + hash-chained snapshots",
        "Add row-level auth + tenant-scoped retrieval indices",
        "Instrument scan-request, certificate-delivery, and reviewer-verification events",
        "Publish the microsite with FAQPage schema only and noindex until owner-facts close",
        "Schedule the Day-90 kill/pivot review with executive sponsor"
      ]
    }
  },
  "project_site": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "app_name": "CorrectPath Correction Desk",
    "archetype": "detection-correction desk",
    "archetype_label": "delinquent-deposit detection & fiduciary correction desk",
    "reader_role": "Controller / VP of HR-Benefits at a 401(k)/403(b) plan sponsor",
    "one_sentence_app": "CorrectPath turns your payroll and recordkeeper exports into a human-verified, flat-fee Correction Certificate — every Late Deposit Instance detected, Lost Earnings calculated, filed and signed.",
    "homepage_sequence": [
      "scene",
      "workflow",
      "instrument",
      "offer",
      "proof",
      "qualification",
      "objections"
    ],
    "hero": {
      "frame_label": "401(k)/403(b) plan-sponsor back-office · delinquent-deposit detection & fiduciary correction desk",
      "eyebrow": "Controller / auditor just flagged a late-deposit finding",
      "interface_title": "CorrectPath correction desk",
      "primary_panel_title": "Plan Year 2025 · 3 Late Deposit Instances · $412 Lost Earnings · SCC-Eligible",
      "primary_panel_body": "Detect every Late Deposit Instance, calculate Lost Earnings using the DOL's own methodology, draft the SCC Notice, and route to the Compliance Reviewer for verification before anything is delivered.",
      "side_panel_title": "Before anything is delivered",
      "side_panel_items": [
        "Every payroll/recordkeeper line matched or exception-coded",
        "Lost Earnings dual-calculation cross-check passed",
        "Correction Certificate ties to source data to the penny"
      ],
      "status_metric": "REVIEW",
      "status_label": "Compliance Reviewer verification required"
    },
    "language": {
      "problem_heading": "The controller's moment",
      "mechanism_heading": "Inside the CorrectPath correction desk",
      "proof_heading": "Why this survives an auditor's review or a DOL inquiry",
      "offer_heading": "What leaves the room",
      "objection_heading": "The hard questions",
      "qualification_heading": "Who should not use this",
      "cta_close": "Start a free Deposit Timing Readiness Scan — verified by a real ERISA-credentialed Compliance Reviewer, never a percentage of anything recovered."
    },
    "modules": [
      {
        "name": "payroll/recordkeeper intake",
        "job": "Turns a forwarded or uploaded payroll withholding-date export and recordkeeper contribution-posting-date export into a named correction-cycle record with a completeness check against the intake checklist.",
        "artifact": "intake record"
      },
      {
        "name": "Correction Certificate",
        "job": "Holds every Late Deposit Instance matched to its source payroll/recordkeeper pair, tied to the penny against the DOL-methodology Lost Earnings calculation, verified by the reviewer.",
        "artifact": "correction certificate"
      },
      {
        "name": "Filing Package",
        "job": "Packages the SCC Notice or VCP/VFCP Application, the Form 5330 draft, and the remediation memo with its evidence into the record a plan-committee member or successor administrator can review without a meeting.",
        "artifact": "filing package"
      }
    ],
    "checkpoints": [
      {
        "label": "payroll/recordkeeper line match",
        "pass": "matched with source citation",
        "fail": "routed to reviewer exception queue"
      },
      {
        "label": "penny-perfect Lost Earnings tie-out",
        "pass": "deterministic code, dual-calculation cross-check passes",
        "fail": "blocked before delivery"
      },
      {
        "label": "Correction Certificate",
        "pass": "Compliance Reviewer verifies (Filing Attorney/EA executes any required filing)",
        "fail": "stays draft"
      }
    ],
    "signature_scene": "It's the third read-through of an auditor's management letter citing \"late remittance of participant deferrals.\" Instead of opening a spreadsheet to date-match payroll against recordkeeper postings yourself, you upload the exports to CorrectPath and a Compliance Reviewer takes the detection and calculation from here."
  },
  "ddd": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "project_name": "CorrectPath",
    "business_understanding": {
      "summary": "CorrectPath — a done-for-you, flat-fee 401(k)/403(b) delinquent-deposit detection and DOL/IRS fiduciary correction desk for plan sponsors with no in-house ERISA specialist.",
      "customer_profile": "Controllers and VPs of HR/Benefits at 100-1,000-employee companies sponsoring a 401(k)/403(b) plan, discovering a late-deposit finding via an auditor's management letter or internal review.",
      "customer_pain": "A late-deposit finding with a Form 5500 deadline attached, no in-house ERISA correction specialist, and no repeatable way to determine SCC-vs-VCP eligibility or calculate Lost Earnings correctly.",
      "paid_outcome": "A signed Correction Certificate — every Late Deposit Instance detected, Lost Earnings calculated, the correct filing prepared and, where required, executed — flat fee, never a percentage of anything recovered.",
      "value_creation": "AI compresses payroll/recordkeeper data normalization, Late Deposit Instance detection, and filing-draft generation; deterministic code owns every Lost Earnings calculation, excise-tax computation, and SCC/VCP eligibility test; humans own Compliance Reviewer verification, Filing Attorney/EA execution, and anything DOL/IRS-facing; the platform binds them with an append-only audit trail and per-sponsor isolation.",
      "why_ai_native": "AI makes multi-year, multi-format payroll/recordkeeper date-matching and DOL-methodology calculation economical at flat-fee pricing; a human Compliance Reviewer and an independently engaged Filing Attorney/EA own every DOL/IRS-facing determination and filing.",
      "operational_risks": [
        "Compliance Reviewer bottleneck during audit-season delivery crunch across many sponsors at once",
        "Prompt injection via uploaded payroll/recordkeeper export document content",
        "Cross-sponsor retrieval leak",
        "Complete records unobtainable at scale (correction cycles stuck in evidence-gap status)",
        "A DOL/IRS-facing filing claim proves incorrect after delivery"
      ],
      "assumptions": [
        "Plan sponsors will engage CorrectPath directly or via a TPA/CPA-audit-firm referral once a concrete Deposit Timing Readiness Scan finding is shown",
        "A Correction Certificate can hit the 5-business-day launch SLA from sponsor-supplied payroll/recordkeeper exports alone"
      ],
      "validation_questions": [
        "What is the real Compliance Reviewer verification time per engagement at pilot volume?",
        "What share of pilot engagements are SCC-eligible versus requiring a full VCP/VFCP Application?"
      ]
    },
    "domain_discovery": {
      "actors": [
        {
          "actor": "Sponsor",
          "role": "Owns the plan's correction engagement; supplies payroll/recordkeeper data and authorizes any DOL/IRS filing",
          "goals": [
            "Close the auditor's finding correctly and on time",
            "Avoid personally taking on fiduciary-breach exposure",
            "Have a defensible audit trail for the plan's fiduciary file"
          ],
          "decisions": [
            "Whether to engage CorrectPath",
            "Which records to supply",
            "Whether to authorize the Deposit Timing Monitoring retainer"
          ],
          "pain_points": [
            "No time or expertise for line-item payroll/recordkeeper date-matching",
            "Doesn't know whether the finding is SCC-eligible or needs a full VCP Application"
          ]
        },
        {
          "actor": "Compliance Reviewer",
          "role": "Verifies every AI-detected instance and calculation; approves a Correction Certificate before filing or delivery",
          "goals": [
            "Release only evidence-backed, penny-perfect calculations",
            "Protect the sponsor and referral-partner relationships"
          ],
          "decisions": [
            "Verify, escalate, or reject a detected instance",
            "Approve the Correction Certificate for delivery"
          ],
          "pain_points": [
            "Volume spikes during audit-season delivery windows",
            "Ambiguous SCC-vs-VCP eligibility cases requiring judgment"
          ]
        },
        {
          "actor": "Filing Attorney/EA",
          "role": "Independently engaged partner ERISA attorney or Enrolled Agent/CPA who reviews and, where required, executes the SCC Notice, VCP/VFCP Application, or Form 5330",
          "goals": [
            "Ensure no filing ships without proper legal/tax-practice review",
            "Protect the sponsor from an unauthorized or incorrect filing"
          ],
          "decisions": [
            "Execute or decline to execute a filing",
            "Resolve ambiguous SCC/VCP eligibility cases"
          ],
          "pain_points": [
            "Capacity constraints during concentrated audit-season demand"
          ]
        },
        {
          "actor": "TPA/CPA Referral Partner",
          "role": "Discovers the finding (via audit) or holds the client relationship, refers the correction engagement to CorrectPath",
          "goals": [
            "Keep the client relationship and referral margin",
            "Avoid independence-rule conflicts (for CPA auditors)"
          ],
          "decisions": [
            "Whether to refer a client's correction engagement to CorrectPath"
          ],
          "pain_points": [
            "Independence rules bar CPA auditors from performing the correction themselves"
          ]
        }
      ],
      "decisions": [
        {
          "decision": "Is this Late Deposit Instance a real prohibited-transaction event or a normal payroll-processing lag?",
          "who": "AI drafts, Compliance Reviewer confirms",
          "inputs": [
            "Payroll withholding date",
            "Recordkeeper posting date",
            "Plan size / applicable safe-harbor window"
          ],
          "rule": "Detection thresholds per plan size; safe-harbor/industry-norm window consulted before flagging",
          "output": "Late Deposit Instance classification with evidence citation",
          "risk": "False instance included in a Correction Certificate"
        },
        {
          "decision": "Is the Correction Certificate ready to deliver?",
          "who": "Deterministic code gates, Compliance Reviewer verifies",
          "inputs": [
            "All Late Deposit Instances verified or exception-coded",
            "Dual-calculation cross-check result"
          ],
          "rule": "Penny-perfect rule: Lost Earnings figure must tie to the DOL-methodology calculation before delivery",
          "output": "Delivered, signed Correction Certificate",
          "risk": "Certificate delivered with an unresolved calculation gap"
        },
        {
          "decision": "Is this finding SCC-eligible or does it require a full VCP/VFCP Application?",
          "who": "Deterministic rule engine computes, Compliance Reviewer confirms, Filing Attorney/EA resolves ambiguous cases",
          "inputs": [
            "Total Lost Earnings across the correction",
            "Days since original withholding"
          ],
          "rule": "SCC eligible only if Lost Earnings <= $1,000 and corrected within 180 days",
          "output": "Eligibility determination (SCC or full VCP/VFCP)",
          "risk": "Misclassified eligibility exposes the sponsor to a rejected filing"
        }
      ],
      "events": [
        {
          "event": "DataExtractedNormalized",
          "meaning": "A payroll/recordkeeper export is extracted and tied out, ready for detection",
          "trigger": "Extraction Agent completes parsing + tie-out check",
          "downstream": [
            "Detection engine invoked"
          ]
        },
        {
          "event": "InstanceVerified",
          "meaning": "A flagged Late Deposit Instance is Compliance-Reviewer-confirmed and evidenced",
          "trigger": "Compliance Reviewer approves the detection",
          "downstream": [
            "Lost Earnings calculation triggered",
            "Instance counted toward the Correction Certificate"
          ]
        },
        {
          "event": "FilingExecuted",
          "meaning": "The independently engaged Filing Attorney/EA has reviewed and executed the required filing",
          "trigger": "Filing Attorney/EA signs off on the drafted SCC Notice, VCP/VFCP Application, or Form 5330",
          "downstream": [
            "Correction Certificate marked deliverable"
          ]
        }
      ],
      "glossary": [
        {
          "term": "Deposit Timing Readiness Scan",
          "definition": "The free, one-payroll-cycle pass/fail read of a Sponsor's deposit timing against the matching recordkeeper posting date.",
          "used_by": "Sponsor",
          "context": "Sponsor Intake",
          "example": "Scan for Sponsor #PL-2291 covering the June 2026 payroll cycle",
          "notes": "Never called 'audit', 'check', or 'review'."
        },
        {
          "term": "Correction Cycle",
          "definition": "One plan year's worth of payroll/recordkeeper export intake, detection, calculation, and Correction Certificate delivery for one Sponsor.",
          "used_by": "Compliance Reviewer",
          "context": "Deposit Detection & Calculation",
          "example": "The 2025 plan-year correction cycle for Sponsor #PL-2291",
          "notes": "The unit of recurring engagement work."
        },
        {
          "term": "Late Deposit Instance",
          "definition": "A single detected occurrence where a participant-deferral withholding was not deposited into the plan trust within the applicable window.",
          "used_by": "Compliance Reviewer, Filing Attorney/EA",
          "context": "Deposit Detection",
          "example": "Instance #3 for the July 2025 payroll cycle, 9 days late",
          "notes": "The unit of detection; every instance requires a source citation."
        }
      ]
    },
    "subdomains": [
      {
        "name": "Deposit Detection & Calculation",
        "type": "core",
        "description": "Payroll/recordkeeper export normalization, Late Deposit Instance detection, and deterministic Lost Earnings / excise-tax calculation.",
        "reason": "This is the paid outcome — the detection and calculation are what the sponsor is buying.",
        "business_value": "Direct revenue driver; every tier maps to a delivered Correction Certificate.",
        "recommendation": "Build in-house, deterministic-rules-first.",
        "ai_involvement": "Extraction, detection, calculation cross-check drafting",
        "human_involvement": "Compliance Reviewer verification, certificate sign-off",
        "risks": [
          "Missed cycle-delivery SLA",
          "Incomplete evidence causing a client-caught error"
        ],
        "validation_questions": [
          "What is the real Compliance Reviewer verification time per cycle at volume?"
        ]
      },
      {
        "name": "Filing & Delivery",
        "type": "core",
        "description": "SCC Notice/VCP/VFCP Application/Form 5330 drafting, Filing Attorney/EA execution coordination, Correction Certificate assembly and delivery.",
        "reason": "Differentiates CorrectPath from a generic bookkeeping service — this is the licensed-execution layer.",
        "business_value": "Drives conversion (free Scan -> paid certificate) and the Deposit Timing Monitoring retainer.",
        "recommendation": "Build in-house; maintain a Filing Attorney/EA panel from day one.",
        "ai_involvement": "Drafts filings and remediation memos",
        "human_involvement": "Compliance Reviewer verification, Filing Attorney/EA execution",
        "risks": [
          "Filing executed without proper review",
          "Sponsor-facing communication read as legal advice"
        ],
        "validation_questions": [
          "What is the true Filing Attorney/EA panel capacity at pilot volume?"
        ]
      },
      {
        "name": "Regulatory Tracking",
        "type": "supporting",
        "description": "Maintained DOL VFCP methodology, IRC §4975, and EPCRS rule library, version-controlled as rules change.",
        "reason": "Could become core if regulatory-currency monitoring becomes a standalone subscription product.",
        "business_value": "Protects against stale-methodology risk across every engagement.",
        "recommendation": "Build in-house; named owner for monthly regulatory-change monitoring.",
        "ai_involvement": "Flags possible rule changes for human confirmation",
        "human_involvement": "Compliance Reviewer confirms every rule-library update",
        "risks": [
          "A DOL/IRS methodology change not tracked in time"
        ],
        "validation_questions": [
          "How often does the rule library actually need updating in a given quarter?"
        ]
      },
      {
        "name": "Sponsor Intake",
        "type": "supporting",
        "description": "Sponsor onboarding, engagement-letter execution, and payroll/recordkeeper data intake completeness checks.",
        "reason": "Necessary but not differentiating on its own.",
        "business_value": "Gatekeeps engagement quality before detection work begins.",
        "recommendation": "Build in-house; keep the intake checklist tight.",
        "ai_involvement": "Completeness-check flagging",
        "human_involvement": "Sponsor supplies data; reviewer confirms completeness",
        "risks": [
          "Incomplete intake silently proceeding to detection"
        ],
        "validation_questions": [
          "What share of intakes are incomplete on first submission?"
        ]
      },
      {
        "name": "Referral & Outreach",
        "type": "generic",
        "description": "CPA/TPA/ERISA-attorney referral-partner relationship management and content-led inbound.",
        "reason": "Uses off-the-shelf tooling deliberately to keep engineering focus on detection and calculation.",
        "business_value": "Primary, lowest-CAC acquisition channel.",
        "recommendation": "Off-the-shelf CRM; no custom build.",
        "ai_involvement": "None at launch",
        "human_involvement": "Founder-led partner relationship management",
        "risks": [
          "TPA channel conflict if partners view CorrectPath as competitive"
        ],
        "validation_questions": [
          "Will TPA partners refer rather than build in-house? (flagged Unverified in business-plan.md)"
        ]
      }
    ],
    "core_domain_analysis": {
      "primary_core": "Deposit Detection & Calculation",
      "secondary_cores": [
        "Filing & Delivery"
      ],
      "supporting_may_become_core": [
        "Regulatory Tracking"
      ],
      "generic_do_not_distract": [
        "Referral & Outreach",
        "CRM/pipeline tracking"
      ],
      "rationale": "The paid outcome is a signed Correction Certificate, so Deposit Detection & Calculation is the primary core. Filing & Delivery is a secondary core because the licensed Filing Attorney/EA execution is the human-plus-AI moat that differentiates CorrectPath from a sponsor attempting this alone. Regulatory Tracking could become core if a standalone regulatory-monitoring subscription grows into a larger revenue stream, but starts as supporting. Referral & Outreach uses off-the-shelf tooling deliberately to keep engineering focus on the detection and calculation engine."
    },
    "bounded_contexts": [
      {
        "name": "Sponsor Intake",
        "purpose": "Sponsor onboarding, payroll/recordkeeper export ingestion, plan-document deposit-timing classification, and the plan-sponsor-only (never individual-participant) engagement gate.",
        "subdomain": "Sponsor Intake (supporting)",
        "type": "supporting",
        "owned_language": [
          "payroll/recordkeeper export",
          "correction cycle",
          "completeness check"
        ],
        "owns": [
          "Payroll/recordkeeper export intake lifecycle",
          "Normalization state",
          "Intake-checklist completeness"
        ],
        "does_not_own": [
          "Detection decisions",
          "Reviewer verification"
        ],
        "primary_actors": [
          "Sponsor",
          "Extraction Agent"
        ],
        "entities": [
          "PayrollExport",
          "CorrectionCycle"
        ],
        "value_objects": [
          "ConfidenceScore",
          "PayrollExportTotal"
        ],
        "aggregates": [
          "SponsorAggregate"
        ],
        "domain_services": [
          "Payroll/recordkeeper export normalizer",
          "Completeness checker"
        ],
        "application_services": [
          "ReceivePayrollExport",
          "NormalizePayrollExport",
          "CheckCompleteness"
        ],
        "commands": [
          "ReceivePayrollExport",
          "NormalizePayrollExport"
        ],
        "domain_events": [
          "SponsorIntaken",
          "DataExtractedNormalized"
        ],
        "policies": [
          "Auto-flag missing payroll/recordkeeper export against the intake checklist"
        ],
        "specifications": [
          "PayrollExportTieOutSpec"
        ],
        "invariants": [
          "A payroll export cannot be used for detection until its line-item sum ties to its stated total"
        ],
        "ai_agents": [
          "Extraction Agent"
        ],
        "human_roles": [
          "Sponsor"
        ],
        "data_owned": [
          "PayrollExport",
          "CorrectionCycle"
        ],
        "inputs": [
          "Uploaded/forwarded payroll and recordkeeper exports",
          "Plan-document deposit-timing excerpt"
        ],
        "outputs": [
          "Normalized canonical payroll/recordkeeper records"
        ],
        "external_integrations": [
          "Payroll/recordkeeper export portals (authorized pull only)",
          "Monitored intake mailbox"
        ],
        "risks": [
          "A malformed export silently mis-tied",
          "Missing export for the period goes unnoticed"
        ],
        "interfaces": [
          "-> Deposit Detection (DataExtractedNormalized)"
        ]
      },
      {
        "name": "Deposit Detection",
        "purpose": "Date-matching between payroll withholding dates and recordkeeper posting dates to identify candidate Late Deposit Instances.",
        "subdomain": "Deposit Detection & Calculation (core)",
        "type": "core",
        "owned_language": [
          "Late Deposit Instance",
          "confidence score",
          "detection threshold"
        ],
        "owns": [
          "Instance-detection lifecycle",
          "Confidence scoring"
        ],
        "does_not_own": [
          "Lost Earnings calculation",
          "Eligibility determination"
        ],
        "primary_actors": [
          "Detection Agent",
          "Compliance Reviewer"
        ],
        "entities": [
          "LateDepositInstance"
        ],
        "value_objects": [
          "ConfidenceScore",
          "WithholdingPostingGap"
        ],
        "aggregates": [
          "LateDepositInstanceAggregate"
        ],
        "domain_services": [
          "Date-matching engine",
          "Confidence scorer"
        ],
        "application_services": [
          "DetectLateDepositInstance",
          "VerifyInstance"
        ],
        "commands": [
          "DetectLateDepositInstance",
          "VerifyInstance"
        ],
        "domain_events": [
          "LateDepositInstanceDetected",
          "InstanceVerified"
        ],
        "policies": [
          "Auto-route low-confidence match to reviewer exception queue"
        ],
        "specifications": [
          "SafeHarborWindowSpec"
        ],
        "invariants": [
          "No candidate instance counts toward a Correction Certificate without Compliance Reviewer verification"
        ],
        "ai_agents": [
          "Detection Agent"
        ],
        "human_roles": [
          "Compliance Reviewer"
        ],
        "data_owned": [
          "LateDepositInstance"
        ],
        "inputs": [
          "Normalized payroll/recordkeeper records"
        ],
        "outputs": [
          "Verified Late Deposit Instance list"
        ],
        "external_integrations": [],
        "risks": [
          "Wrong fuzzy match auto-accepted",
          "Missed instance from an unmapped export format"
        ],
        "interfaces": [
          "-> Correction Calculation (InstanceVerified)"
        ]
      },
      {
        "name": "Correction Calculation",
        "purpose": "Deterministic Lost Earnings and IRC §4975 excise-tax calculation, and SCC-vs-VCP eligibility determination.",
        "subdomain": "Deposit Detection & Calculation (core)",
        "type": "core",
        "owned_language": [
          "Lost Earnings",
          "excise tax",
          "SCC eligibility",
          "dual-calculation cross-check"
        ],
        "owns": [
          "Lost Earnings calculation logic",
          "Eligibility test"
        ],
        "does_not_own": [
          "Filing drafting",
          "Filing execution"
        ],
        "primary_actors": [
          "Compliance Reviewer"
        ],
        "entities": [
          "LostEarningsCalculation"
        ],
        "value_objects": [
          "LostEarningsAmount",
          "ExciseTaxAmount",
          "EligibilityResult"
        ],
        "aggregates": [
          "CorrectionCertificateAggregate"
        ],
        "domain_services": [
          "DOL-methodology calculator",
          "Independent cross-check calculator"
        ],
        "application_services": [
          "CalculateLostEarnings",
          "DetermineEligibility"
        ],
        "commands": [
          "CalculateLostEarnings",
          "DetermineEligibility"
        ],
        "domain_events": [
          "LostEarningsCalculated",
          "EligibilityDetermined"
        ],
        "policies": [
          "Route to exception queue if dual-calculation methods diverge beyond tolerance"
        ],
        "specifications": [
          "SCCEligibilitySpec"
        ],
        "invariants": [
          "A Lost Earnings figure cannot be finalized without a passed dual-calculation cross-check"
        ],
        "ai_agents": [],
        "human_roles": [
          "Compliance Reviewer"
        ],
        "data_owned": [
          "LostEarningsCalculation"
        ],
        "inputs": [
          "Verified Late Deposit Instances"
        ],
        "outputs": [
          "Lost Earnings figure",
          "Excise-tax figure",
          "SCC/VCP eligibility result"
        ],
        "external_integrations": [],
        "risks": [
          "Wrong methodology selection",
          "Misapplied eligibility threshold"
        ],
        "interfaces": [
          "-> Filing Delivery (EligibilityDetermined)"
        ]
      },
      {
        "name": "Filing Delivery",
        "purpose": "SCC Notice/VCP/VFCP Application/Form 5330 drafting, Compliance Reviewer verification, Filing Attorney/EA execution, and Correction Certificate delivery.",
        "subdomain": "Filing & Delivery (core)",
        "type": "core",
        "owned_language": [
          "Correction Certificate",
          "Filing Attorney/EA",
          "remediation memo"
        ],
        "owns": [
          "Filing drafting",
          "Certificate assembly and delivery"
        ],
        "does_not_own": [
          "Lost Earnings calculation",
          "Fiduciary-breach characterization"
        ],
        "primary_actors": [
          "Compliance Reviewer",
          "Filing Attorney/EA"
        ],
        "entities": [
          "FilingRecord",
          "CorrectionCertificate"
        ],
        "value_objects": [
          "FilingType",
          "ExecutionStatus"
        ],
        "aggregates": [
          "FilingRecordAggregate"
        ],
        "domain_services": [
          "Filing drafter",
          "Certificate assembler"
        ],
        "application_services": [
          "DraftFiling",
          "ApproveComplianceReview",
          "ExecuteFiling",
          "DeliverCertificate"
        ],
        "commands": [
          "DraftFiling",
          "ExecuteFiling",
          "DeliverCertificate"
        ],
        "domain_events": [
          "FilingDrafted",
          "ComplianceReviewApproved",
          "FilingExecuted",
          "CorrectionCertificateDelivered"
        ],
        "policies": [
          "Block demand/collection-style language in every drafted DOL/IRS filing",
          "Hard-block any filing execution by anyone but the independently engaged Filing Attorney/EA"
        ],
        "specifications": [
          "FilingExecutionGateSpec"
        ],
        "invariants": [
          "No filing-required package is marked delivered without a logged Filing Attorney/EA execution record"
        ],
        "ai_agents": [
          "Drafting Agent"
        ],
        "human_roles": [
          "Compliance Reviewer",
          "Filing Attorney/EA"
        ],
        "data_owned": [
          "FilingRecord",
          "CorrectionCertificate"
        ],
        "inputs": [
          "Eligibility determination",
          "Lost Earnings figures"
        ],
        "outputs": [
          "Signed Correction Certificate"
        ],
        "external_integrations": [
          "E-signature tool",
          "DOL/IRS filing-status check (manual at launch)"
        ],
        "risks": [
          "Filing executed without proper review",
          "Remediation memo miscommunicates scope of advice"
        ],
        "interfaces": [
          "-> Regulatory Tracking (FilingExecuted feeds pattern library)"
        ]
      },
      {
        "name": "Regulatory Tracking",
        "purpose": "Maintains the DOL VFCP methodology, IRC §4975, and EPCRS rule library; monitors regulatory-text changes.",
        "subdomain": "Regulatory Tracking (supporting)",
        "type": "supporting",
        "owned_language": [
          "rule library",
          "rule library entry",
          "regulatory-text change"
        ],
        "owns": [
          "Rule-library currency"
        ],
        "does_not_own": [
          "Any specific engagement's eligibility determination"
        ],
        "primary_actors": [
          "Compliance Reviewer"
        ],
        "entities": [
          "RuleLibraryEntry"
        ],
        "value_objects": [
          "EffectiveDate",
          "ThresholdValue"
        ],
        "aggregates": [],
        "domain_services": [
          "Rule-currency checker"
        ],
        "application_services": [
          "UpdateRuleLibrary"
        ],
        "commands": [
          "FlagPossibleRuleChange"
        ],
        "domain_events": [
          "RuleLibraryUpdated"
        ],
        "policies": [
          "Never mark a rule-library entry confirmed-current without a Compliance Reviewer confirmation"
        ],
        "specifications": [],
        "invariants": [
          "A rule-library entry can only be updated via a confirmed regulatory-text change event"
        ],
        "ai_agents": [
          "Rule-Currency Agent"
        ],
        "human_roles": [
          "Compliance Reviewer"
        ],
        "data_owned": [
          "RuleLibraryEntry"
        ],
        "inputs": [
          "DOL/IRS regulatory text"
        ],
        "outputs": [
          "Current rule-library entries"
        ],
        "external_integrations": [
          "DOL.gov / IRS.gov monitoring (manual at launch)"
        ],
        "risks": [
          "A DOL/IRS methodology change not tracked in time"
        ],
        "interfaces": [
          "-> Correction Calculation (rule-library entries consumed)"
        ]
      }
    ],
    "context_map": [
      {
        "upstream": "Sponsor Intake",
        "downstream": "Deposit Detection",
        "relationship": "Customer-Supplier",
        "integration_pattern": "Domain event (DataExtractedNormalized) consumed by the detection engine",
        "translation_notes": "Canonical payroll/recordkeeper schema is the shared contract; no direct database coupling.",
        "pattern": "Customer-Supplier",
        "contract_type": "domain event",
        "data_exchanged": [
          "Normalized payroll/recordkeeper records"
        ],
        "events_exchanged": [
          "DataExtractedNormalized"
        ],
        "ownership_boundary": "Downstream never writes to upstream's tables",
        "acl_notes": "Anti-corruption translation not needed — shared canonical schema",
        "business_reason": "Keeps each context's invariants enforceable independently",
        "failure_risks": [
          "Schema drift between intake and detection if the canonical schema changes without a version bump"
        ]
      },
      {
        "upstream": "Deposit Detection",
        "downstream": "Correction Calculation",
        "relationship": "Customer-Supplier",
        "integration_pattern": "Domain event (InstanceVerified) triggers Lost Earnings calculation",
        "translation_notes": "Only reviewer-verified instances are consumed.",
        "pattern": "Customer-Supplier",
        "contract_type": "domain event",
        "data_exchanged": [
          "Verified Late Deposit Instance list"
        ],
        "events_exchanged": [
          "InstanceVerified"
        ],
        "ownership_boundary": "Downstream never writes to upstream's tables",
        "acl_notes": "None needed",
        "business_reason": "Keeps calculation strictly downstream of verification",
        "failure_risks": [
          "Unverified instance leaking into calculation via a bypassed gate"
        ]
      },
      {
        "upstream": "Correction Calculation",
        "downstream": "Filing Delivery",
        "relationship": "Customer-Supplier",
        "integration_pattern": "Domain event (EligibilityDetermined) triggers filing drafting",
        "translation_notes": "Eligibility result and Lost Earnings figure are the shared contract.",
        "pattern": "Customer-Supplier",
        "contract_type": "domain event",
        "data_exchanged": [
          "Eligibility result",
          "Lost Earnings figure"
        ],
        "events_exchanged": [
          "EligibilityDetermined"
        ],
        "ownership_boundary": "Downstream never writes to upstream's tables",
        "acl_notes": "None needed",
        "business_reason": "Keeps filing drafting strictly downstream of a passed calculation",
        "failure_risks": [
          "A stale eligibility result used after a rule-library update"
        ]
      },
      {
        "upstream": "Filing Delivery",
        "downstream": "Regulatory Tracking",
        "relationship": "Partnership",
        "integration_pattern": "Domain event (FilingExecuted) feeds the accumulated pattern library",
        "translation_notes": "Outcome data (accepted/pushback) enriches the rule library over time.",
        "pattern": "Partnership",
        "contract_type": "domain event",
        "data_exchanged": [
          "Filing outcome",
          "auditor/DOL acceptance status"
        ],
        "events_exchanged": [
          "FilingExecuted"
        ],
        "ownership_boundary": "Each context owns its own write path; Regulatory Tracking only reads outcome events",
        "acl_notes": "None needed",
        "business_reason": "Closes the learning loop described in ai-engine-spec.md Layer 9",
        "failure_risks": [
          "Outcome data not logged consistently, weakening the learning loop"
        ]
      }
    ],
    "external_integrations": [
      {
        "system": "Firm management system (payroll and recordkeeper system) export",
        "direction": "inbound",
        "pattern": "File-based export, no live API at launch",
        "risk": "Schema drift per payroll and recordkeeper system version",
        "owner_context": "Filing & Delivery",
        "data_in": [
          "[PLACEHOLDER] owner to complete"
        ],
        "data_out": [
          "[PLACEHOLDER] owner to complete"
        ],
        "trigger": "Recovery cycle start",
        "internal_model": "Canonical payroll/recordkeeper export/ledger schema",
        "acl_strategy": "Per-DOL or IRS parser translates external format to canonical schema",
        "failure_strategy": "Retry then manual fallback",
        "audit_need": "Every external call logged with timestamp and payload hash"
      },
      {
        "system": "payroll and recordkeeper export portals",
        "direction": "inbound",
        "pattern": "Firm-authorized credentialed pull or client-forwarded file",
        "risk": "Portal ToS friction; credential expiry",
        "owner_context": "Intake & Normalization",
        "data_in": "payroll and recordkeeper export content",
        "data_out": "N/A",
        "trigger": "Recovery cycle start",
        "internal_model": "Canonical payroll/recordkeeper export/ledger schema",
        "acl_strategy": "Per-DOL or IRS parser translates external format to canonical schema",
        "failure_strategy": "Retry then manual fallback",
        "audit_need": "Every external call logged with timestamp and payload hash"
      },
      {
        "system": "QuickBooks / payroll and recordkeeper system posting-file import",
        "direction": "outbound",
        "pattern": "Generated posting file, firm-side import",
        "risk": "Format mismatch per bookkeeping software version",
        "owner_context": "Filing & Delivery",
        "data_in": "N/A",
        "data_out": "Posting file or inquiry email",
        "trigger": "Reviewer approval",
        "internal_model": "Canonical payroll/recordkeeper export/ledger schema",
        "acl_strategy": "Per-DOL or IRS parser translates external format to canonical schema",
        "failure_strategy": "Retry then manual fallback",
        "audit_need": "Every external call logged with timestamp and payload hash"
      },
      {
        "system": "DOL/IRS correspondence mailbox",
        "direction": "outbound",
        "pattern": "Firm-authorized email send",
        "risk": "Inquiry misread as a demand",
        "owner_context": "Filing & Delivery",
        "data_in": "N/A",
        "data_out": "Posting file or inquiry email",
        "trigger": "Reviewer approval",
        "internal_model": "Canonical payroll/recordkeeper export/ledger schema",
        "acl_strategy": "Per-DOL or IRS parser translates external format to canonical schema",
        "failure_strategy": "Retry then manual fallback",
        "audit_need": "Every external call logged with timestamp and payload hash"
      }
    ],
    "event_storm": [
      {
        "seq": 1,
        "command": "ReceivePayrollExport",
        "event": "SponsorIntaken",
        "actor": "Sponsor",
        "context": "Sponsor Intake",
        "aggregate": "SponsorAggregate",
        "policy": "None",
        "downstream": "Completeness check against the intake checklist",
        "risk": "Duplicate export ingestion"
      },
      {
        "seq": 2,
        "command": "NormalizePayrollExport",
        "event": "DataExtractedNormalized",
        "actor": "Extraction Agent",
        "context": "Sponsor Intake",
        "aggregate": "SponsorAggregate",
        "policy": "Auto tie-out check",
        "downstream": "Detection engine invoked",
        "risk": "Misread field on an unmapped payroll/recordkeeper format"
      },
      {
        "seq": 3,
        "command": "DetectLateDepositInstance",
        "event": "LateDepositInstanceDetected",
        "actor": "Detection Agent",
        "context": "Deposit Detection",
        "aggregate": "LateDepositInstanceAggregate",
        "policy": "Auto-route low-confidence matches to reviewer",
        "downstream": "Exception queue populated",
        "risk": "Wrong fuzzy match auto-accepted"
      },
      {
        "seq": 4,
        "command": "VerifyInstance",
        "event": "InstanceVerified",
        "actor": "Compliance Reviewer",
        "context": "Deposit Detection",
        "aggregate": "LateDepositInstanceAggregate",
        "policy": "None",
        "downstream": "Lost Earnings calculation triggered",
        "risk": "Reviewer approves an incomplete instance under time pressure"
      },
      {
        "seq": 5,
        "command": "CalculateLostEarnings",
        "event": "LostEarningsCalculated",
        "actor": "System (deterministic rules)",
        "context": "Correction Calculation",
        "aggregate": "CorrectionCertificateAggregate",
        "policy": "Dual-calculation cross-check",
        "downstream": "Eligibility determination",
        "risk": "Wrong methodology selection"
      },
      {
        "seq": 6,
        "command": "ExecuteFiling",
        "event": "FilingExecuted",
        "actor": "Filing Attorney/EA",
        "context": "Filing Delivery",
        "aggregate": "FilingRecordAggregate",
        "policy": "Hard-block any executor but the independently engaged Filing Attorney/EA",
        "downstream": "Correction Certificate delivered",
        "risk": "Filing executed without proper review"
      }
    ],
    "critical_path": [
      "SponsorIntaken -> DataExtractedNormalized -> LateDepositInstanceDetected -> InstanceVerified -> LostEarningsCalculated -> EligibilityDetermined -> FilingExecuted -> CorrectionCertificateDelivered"
    ],
    "exception_flows": [
      "A payroll/recordkeeper export line below the detection-confidence threshold -> routed to reviewer exception queue, blocks correction_cycle.matching_completed until resolved",
      "A discrepancy classification needs-reviewer-judgment -> held for reviewer, never auto-approved"
    ],
    "escalation_flows": [
      "A discrepancy over $2,500 -> second reviewer pass before docket approval",
      "A DOL or IRS disputes an inquiry beyond a routine response -> referred to the firm's own counsel"
    ],
    "retry_flows": [
      "DOL or IRS inquiry unacknowledged after 60 days -> automated reminder, then reviewer-judged escalation at 90 days"
    ],
    "manual_override_flows": [
      "Founder/senior reviewer can force-hold any Correction Certificate pre-release regardless of automated tie-out pass, if a data-integrity issue is suspected"
    ],
    "commands": [
      {
        "name": "ReceivePayrollExport",
        "issued_by": "Sponsor / monitored mailbox",
        "preconditions": [
          "Sponsor onboarded",
          "Engagement letter signed"
        ],
        "aggregate": "SponsorAggregate",
        "success_event": "SponsorIntaken",
        "failure_event": "PayrollExportRejected",
        "authorization": "Engaged Sponsor",
        "validation": "File type allowed; payroll/recordkeeper format recognized or flagged new",
        "audit": "Export hashed and logged"
      },
      {
        "name": "NormalizePayrollExport",
        "issued_by": "Extraction Agent",
        "preconditions": [
          "Payroll export received"
        ],
        "aggregate": "SponsorAggregate",
        "success_event": "DataExtractedNormalized",
        "failure_event": "NormalizationFailed",
        "authorization": "System",
        "validation": "Line-item sum ties to stated total",
        "audit": "Extraction run logged with confidence scores"
      },
      {
        "name": "DetectLateDepositInstance",
        "issued_by": "Detection Agent",
        "preconditions": [
          "Payroll export normalized",
          "Recordkeeper posting-date export on file"
        ],
        "aggregate": "LateDepositInstanceAggregate",
        "success_event": "LateDepositInstanceDetected",
        "failure_event": "DetectionInconclusive",
        "authorization": "System",
        "validation": "Confidence score attached to every candidate instance",
        "audit": "Detection run logged"
      },
      {
        "name": "VerifyInstance",
        "issued_by": "Compliance Reviewer",
        "preconditions": [
          "Instance detected"
        ],
        "aggregate": "LateDepositInstanceAggregate",
        "success_event": "InstanceVerified",
        "failure_event": "InstanceRejected",
        "authorization": "Compliance Reviewer",
        "validation": "Instance checked against source payroll/recordkeeper data",
        "audit": "Reviewer identity and timestamp logged"
      },
      {
        "name": "CalculateLostEarnings",
        "issued_by": "System (deterministic rules)",
        "preconditions": [
          "Instance verified"
        ],
        "aggregate": "CorrectionCertificateAggregate",
        "success_event": "LostEarningsCalculated",
        "failure_event": "CalculationDivergence",
        "authorization": "System",
        "validation": "Dual-calculation cross-check within tolerance",
        "audit": "Calculation workpapers versioned"
      },
      {
        "name": "ExecuteFiling",
        "issued_by": "Filing Attorney/EA",
        "preconditions": [
          "Filing drafted",
          "Compliance Reviewer approved"
        ],
        "aggregate": "FilingRecordAggregate",
        "success_event": "FilingExecuted",
        "failure_event": "FilingDeclined",
        "authorization": "Independently engaged Filing Attorney/EA only",
        "validation": "Filing content matches approved draft",
        "audit": "Execution record with attorney/EA identity and timestamp"
      }
    ],
    "policies": [
      {
        "name": "Auto-route low-confidence match to reviewer",
        "trigger": "LateDepositInstanceDetected",
        "condition": "detection confidence below auto-match threshold",
        "action": "Enqueue to Compliance Reviewer exception queue",
        "context": "Deposit Detection",
        "ai_involvement": "flags only",
        "human_approval": false
      },
      {
        "name": "Block demand-language patterns",
        "trigger": "DraftFiling",
        "condition": "Draft contains demand/collection/legal-threat language pattern",
        "action": "Reject draft before it reaches Compliance Reviewer approval",
        "context": "Filing Delivery",
        "ai_involvement": "author (blocked by deterministic filter)",
        "human_approval": false
      },
      {
        "name": "Second-reviewer spot check",
        "trigger": "ComplianceReviewApproved",
        "condition": "Certificate value over $5,000",
        "action": "Route to a second named reviewer before the certificate is finalized",
        "context": "Quality Assurance",
        "ai_involvement": "none",
        "human_approval": true
      },
      {
        "name": "Hard-block filing execution by anyone but the Filing Attorney/EA",
        "trigger": "ExecuteFiling",
        "condition": "executor != independently_engaged_filing_attorney_or_ea",
        "action": "Reject the execution attempt",
        "context": "Filing Delivery",
        "ai_involvement": "none — deterministic gate",
        "human_approval": true
      }
    ],
    "aggregates": [
      {
        "name": "Sponsor",
        "root": "Sponsor",
        "context": "Sponsor Intake",
        "purpose": "Guard payroll/recordkeeper export receipt + normalization + tie-out state.",
        "entities": [
          "PayrollExport",
          "CorrectionCycle"
        ],
        "value_objects": [
          "ConfidenceScore",
          "PayrollExportTotal"
        ],
        "invariants": [
          "Cannot proceed past intake until state(s) of operation and plan-document deposit-timing provisions are confirmed"
        ],
        "commands": [
          "ReceivePayrollExport",
          "NormalizePayrollExport"
        ],
        "events": [
          "SponsorIntaken",
          "DataExtractedNormalized"
        ],
        "repository": "SponsorRepository",
        "transaction_boundary": "One Sponsor's intake per transaction"
      },
      {
        "name": "LateDepositInstance",
        "root": "LateDepositInstance",
        "context": "Deposit Detection",
        "purpose": "Own the detection and verification lifecycle for one candidate instance.",
        "entities": [
          "LateDepositInstance"
        ],
        "value_objects": [
          "ConfidenceScore",
          "WithholdingPostingGap"
        ],
        "invariants": [
          "Cannot be counted toward a Correction Certificate without a Compliance Reviewer verification sign-off"
        ],
        "commands": [
          "DetectLateDepositInstance",
          "VerifyInstance"
        ],
        "events": [
          "LateDepositInstanceDetected",
          "InstanceVerified"
        ],
        "repository": "LateDepositInstanceRepository",
        "transaction_boundary": "One instance per transaction"
      },
      {
        "name": "CorrectionCertificate",
        "root": "CorrectionCertificate",
        "context": "Correction Calculation / Filing Delivery",
        "purpose": "Own the Lost Earnings calculation and certificate-delivery lifecycle for one plan year.",
        "entities": [
          "LostEarningsCalculation"
        ],
        "value_objects": [
          "LostEarningsAmount",
          "ExciseTaxAmount",
          "EligibilityResult"
        ],
        "invariants": [
          "Cannot be marked delivered without a passed dual-calculation cross-check and a Compliance Reviewer sign-off"
        ],
        "commands": [
          "CalculateLostEarnings",
          "DetermineEligibility",
          "DeliverCertificate"
        ],
        "events": [
          "LostEarningsCalculated",
          "EligibilityDetermined",
          "CorrectionCertificateDelivered"
        ],
        "repository": "CorrectionCertificateRepository",
        "transaction_boundary": "One certificate per transaction"
      },
      {
        "name": "FilingRecord",
        "root": "FilingRecord",
        "context": "Filing Delivery",
        "purpose": "Own filing drafting and execution status.",
        "entities": [
          "FilingRecord"
        ],
        "value_objects": [
          "FilingType",
          "ExecutionStatus"
        ],
        "invariants": [
          "Cannot be marked executed without the independently engaged Filing Attorney/EA's own signature; AI or CorrectPath staff can never set this status"
        ],
        "commands": [
          "DraftFiling",
          "ExecuteFiling"
        ],
        "events": [
          "FilingDrafted",
          "FilingExecuted"
        ],
        "repository": "FilingRecordRepository",
        "transaction_boundary": "One filing per transaction"
      },
      {
        "name": "RuleLibraryEntry",
        "root": "RuleLibraryEntry",
        "context": "Regulatory Tracking",
        "purpose": "Own DOL/IRS rule-library currency.",
        "entities": [],
        "value_objects": [
          "EffectiveDate",
          "ThresholdValue"
        ],
        "invariants": [
          "Can only be updated via a confirmed regulatory-text change event, never inferred by AI alone without a Compliance Reviewer confirmation"
        ],
        "commands": [
          "FlagPossibleRuleChange"
        ],
        "events": [
          "RuleLibraryUpdated"
        ],
        "repository": "RuleLibraryRepository",
        "transaction_boundary": "One entry per transaction"
      }
    ],
    "invariants": [
      {
        "invariant": "A Correction Certificate cannot be signed without tying to source payroll/recordkeeper data to the penny",
        "context": "Correction Calculation",
        "aggregate": "CorrectionCertificateAggregate",
        "why": "No certificate is ever delivered on an unresolved tie-out gap",
        "enforcement": "Deterministic code gate on the DeliverCertificate command"
      },
      {
        "invariant": "A filing cannot be executed without Filing Attorney/EA authorization on file",
        "context": "Filing Delivery",
        "aggregate": "FilingRecordAggregate",
        "why": "Executing without authorization is both a trust breach and outside the licensing boundary",
        "enforcement": "Deterministic code gate on the ExecuteFiling command"
      },
      {
        "invariant": "No Late Deposit Instance is published without a cited source payroll/recordkeeper reference",
        "context": "Deposit Detection",
        "aggregate": "LateDepositInstanceAggregate",
        "why": "Prevents an unevidenced claim from reaching a Sponsor or the DOL/IRS",
        "enforcement": "Output validator rejects any instance missing an evidence citation"
      },
      {
        "invariant": "A Lost Earnings figure cannot be finalized without a passed dual-calculation cross-check",
        "context": "Correction Calculation",
        "aggregate": "CorrectionCertificateAggregate",
        "why": "Prevents a miscalculated figure from reaching a filing",
        "enforcement": "Deterministic code gate on the CalculateLostEarnings command"
      }
    ],
    "ai_agents": [
      {
        "name": "Extraction Agent",
        "context": "Sponsor Intake",
        "responsibility": "Extract and normalize structured fields from payroll withholding-date and recordkeeper posting-date exports (PDF, portal CSV, spreadsheet) into the canonical schema.",
        "inputs": [
          "Uploaded/forwarded payroll and recordkeeper exports"
        ],
        "outputs": [
          "Structured line items with per-field confidence score"
        ],
        "tools": [
          "OCR",
          "payroll/recordkeeper format-mapping library"
        ],
        "forbidden_actions": [
          "Guessing a withholding-date field not present in the source text"
        ],
        "memory_scope": "Single export extraction run",
        "retrieval_sources": [
          "Payroll/recordkeeper format-mapping fixture library"
        ],
        "validations": [
          "Confidence score attached to every field"
        ],
        "confidence_scoring": "0-100 per field, threshold 85",
        "escalation_triggers": [
          "Any required field below 85% confidence"
        ],
        "human_approval": "Compliance Reviewer confirms during exception review",
        "failure_modes": [
          "Misread scanned/paper export",
          "Wrong payroll/recordkeeper format classification"
        ],
        "audit_logs": [
          "Every extraction run logged with document hash and confidence scores"
        ],
        "metrics": [
          "Extraction accuracy vs. Compliance-Reviewer-corrected value"
        ],
        "versioning": "Prompt versioned independently of the underlying model"
      },
      {
        "name": "Detection Agent",
        "context": "Deposit Detection",
        "responsibility": "Match payroll withholding dates against recordkeeper posting dates to flag candidate Late Deposit Instances.",
        "inputs": [
          "Normalized payroll/recordkeeper records"
        ],
        "outputs": [
          "Candidate Late Deposit Instance list with confidence scores"
        ],
        "tools": [
          "Date-matching engine"
        ],
        "forbidden_actions": [
          "Calculating Lost Earnings or making an eligibility determination — deterministic rules layer only"
        ],
        "memory_scope": "Single plan-year detection run",
        "retrieval_sources": [
          "Safe-harbor/industry-norm window reference"
        ],
        "validations": [
          "Every candidate instance carries a confidence score"
        ],
        "confidence_scoring": "0-100 per instance, threshold 85",
        "escalation_triggers": [
          "Any instance below 85% confidence"
        ],
        "human_approval": "Compliance Reviewer verifies every instance",
        "failure_modes": [
          "Wrong fuzzy match auto-accepted",
          "Missed instance from an unmapped format"
        ],
        "audit_logs": [
          "Every detection run logged with matched line pairs and confidence scores"
        ],
        "metrics": [
          "Detection precision/recall vs. Compliance-Reviewer-corrected value"
        ],
        "versioning": "Prompt versioned independently of the underlying model"
      },
      {
        "name": "Drafting Agent",
        "context": "Filing Delivery",
        "responsibility": "Draft the SCC Notice, VCP scoping memo, Form 5330, and remediation memo from verified instances and calculated figures.",
        "inputs": [
          "Verified instances",
          "Lost Earnings and excise-tax figures",
          "Eligibility determination"
        ],
        "outputs": [
          "Draft filing documents"
        ],
        "tools": [
          "Filing-template library"
        ],
        "forbidden_actions": [
          "Using demand, collection, or legal-threat language",
          "Drafting or implying a final fiduciary-breach characterization"
        ],
        "memory_scope": "Single engagement drafting run",
        "retrieval_sources": [
          "Rule-library filing templates"
        ],
        "validations": [
          "Deterministic output filter blocks demand/collection-style language before it reaches the reviewer"
        ],
        "confidence_scoring": "N/A — draft always routes to Compliance Reviewer",
        "escalation_triggers": [
          "Any draft containing a blocked language pattern"
        ],
        "human_approval": "Compliance Reviewer approves; Filing Attorney/EA executes where required",
        "failure_modes": [
          "Draft implies an unauthorized legal conclusion"
        ],
        "audit_logs": [
          "Every draft logged with source calculation figures and reviewer edits"
        ],
        "metrics": [
          "Draft-to-final edit distance"
        ],
        "versioning": "Prompt and filing-template versioned independently of the underlying model"
      },
      {
        "name": "Rule-Currency Agent",
        "context": "Regulatory Tracking",
        "responsibility": "Flag whether a DOL/IRS rule-library entry appears current or possibly outdated.",
        "inputs": [
          "Current rule-library entry",
          "Newly retrieved DOL/IRS regulatory text"
        ],
        "outputs": [
          "Current / possibly-outdated flag with reasoning"
        ],
        "tools": [
          "Regulatory-text retrieval"
        ],
        "forbidden_actions": [
          "Marking a rule-library entry confirmed-current as a final status"
        ],
        "memory_scope": "Single rule-currency check",
        "retrieval_sources": [
          "DOL.gov / IRS.gov monitoring feed"
        ],
        "validations": [
          "Flag always requires a Compliance Reviewer confirmation to clear"
        ],
        "confidence_scoring": "N/A — flag-only agent",
        "escalation_triggers": [
          "Any possibly-outdated flag"
        ],
        "human_approval": "Compliance Reviewer confirms and updates the system of record",
        "failure_modes": [
          "A real rule change missed between monitoring cycles"
        ],
        "audit_logs": [
          "Every rule-currency check logged with source regulatory text reference"
        ],
        "metrics": [
          "False-flag rate on rule-currency checks"
        ],
        "versioning": "Retrieval source list versioned independently of the underlying model"
      }
    ],
    "prompt_chain_map": [
      "Intake -> Extraction Agent (extract + score) -> Detection Agent (match + compute expected) -> Discrepancy Drafter Agent (classify + cite) -> OutputValidator -> Reviewer (approve or escalate)",
      "Approved discrepancy -> Inquiry Drafter Agent (draft) -> demand-language filter -> Reviewer (approve or edit) -> send"
    ],
    "rag_map": [
      "Per-firm payroll and recordkeeper system client portfolio (tenant-scoped) -> retrieval router -> firm-scoped hits -> Detection Agent",
      "Versioned per-DOL or IRS parser fixture + quirk knowledge base -> shared retrieval -> Extraction Agent and Discrepancy Drafter Agent (cited)"
    ],
    "ai_evaluation": [
      "Golden dataset of past reviewer-accepted matches and discrepancy classifications, per DOL or IRS",
      "Regression requirements on auto-match rate + discrepancy-citation coverage",
      "Every prompt release requires a passing evaluator run against the fixture library"
    ],
    "hallucination_controls": [
      "Retrieval-first (no free-form Late Deposit Instance generation without a cited payroll withholding-date line and recordkeeper posting-date reference)",
      "Structured-output validator enforces citation-per-claim",
      "Confidence-scored escalation on extraction and matching",
      "Reviewer gate on every discrepancy and every outbound DOL or IRS inquiry",
      "Deterministic filter blocks any demand/collection-style or coverage-determination language before it reaches the reviewer"
    ],
    "human_in_the_loop_plan": [
      "Reviewer signoff on every Correction Certificate before delivery",
      "Reviewer approval on every discrepancy before it appears in a docket or goes to a DOL or IRS",
      "Senior-reviewer co-sign on retractions",
      "Owner approval on public-release readiness"
    ],
    "ai_audit_plan": [
      "Every AgentRun logged with prompt version, retrieval hit ids, cost, latency, validator verdict",
      "13-month rolling retention on run logs",
      "Financial/PII data scrubbed from log payloads"
    ],
    "prompt_versioning": "Prompt versions immutable once published; rolled out via feature flag; every rollout paired with an evaluator run against the fixture library.",
    "human_roles": [
      {
        "role": "Sponsor",
        "responsibilities": [
          "Supply payroll and recordkeeper system export and payroll and recordkeeper exports",
          "Sign DOL or IRS-communication authorization",
          "Approve plan-committee member split sheet"
        ],
        "contexts": [
          "Intake & Normalization"
        ],
        "decisions_owned": [
          "Whether to engage",
          "Which records to supply",
          "Whether to authorize the Deposit Timing Monitoring retainer"
        ],
        "ai_support": [
          "[PLACEHOLDER] owner to complete"
        ],
        "approval_authority": "Authorizes the engagement and DOL or IRS-communication authorization",
        "escalation_authority": "None (escalates to CorrectPath, not from it)",
        "quality_metrics": [
          "Intake completeness"
        ],
        "workload_risks": [
          "Month-end time scarcity"
        ]
      },
      {
        "role": "Compliance Reviewer",
        "responsibilities": [
          "Review AI-drafted matches and discrepancies",
          "Verify evidence sufficiency",
          "Sign off before delivery or DOL or IRS send"
        ],
        "contexts": [
          "Deposit Detection & Calculation",
          "Quality Assurance"
        ],
        "decisions_owned": [
          "Approve, escalate, or reject a discrepancy or match"
        ],
        "ai_support": "Extraction, matching, discrepancy-classification, and inquiry-drafting agents",
        "approval_authority": "Sole authority to sign a Correction Certificate or approve a DOL or IRS inquiry",
        "escalation_authority": "Escalates coverage/claims questions to the firm's own licensed staff; disputes beyond routine inquiry to the firm's counsel",
        "quality_metrics": [
          "Client-caught material error rate",
          "Review cycle time"
        ],
        "workload_risks": [
          "Volume spike during month-end delivery window"
        ]
      },
      {
        "role": "Senior Reviewer",
        "responsibilities": [
          "Second-pass sampling on auto-matched lines",
          "Co-sign retractions",
          "Second review on high-value dockets"
        ],
        "contexts": [
          "Quality Assurance"
        ],
        "decisions_owned": [
          "Retraction approval"
        ],
        "ai_support": "None (human-only by design)",
        "approval_authority": "Retraction co-signature authority",
        "escalation_authority": "Escalates to founder/owner",
        "quality_metrics": [
          "Retraction rate"
        ],
        "workload_risks": [
          "Contractor-bench availability at scale"
        ]
      }
    ],
    "human_review_checkpoints": [
      "AI draft -> Reviewer approval",
      "Public release -> owner acceptance",
      "Retraction -> senior-reviewer co-sign",
      "Prompt rollout -> ops + evaluator"
    ],
    "escalation_matrix": [
      "AI -> Reviewer -> Senior Reviewer -> Owner -> Firm's own counsel",
      "Coverage/claims dispute -> Reviewer -> Firm's own licensed staff"
    ],
    "manual_override_rules": [
      "Any manual override captured as an explicit override event with actor + reason",
      "No override may bypass the reviewer-signoff or DOL or IRS-authorization invariant"
    ],
    "separation_of_duties": [
      "Extraction/Matching/Drafter Agents cannot sign; Reviewer cannot draft on behalf of AI without an override event; Senior Reviewer cannot silently retract"
    ],
    "quality_control_workflow": [
      "Weekly reviewer calibration meeting",
      "Monthly evaluator regression report",
      "Quarterly DOL or IRS-quirk library re-verification review with owner + compliance"
    ],
    "data_objects": [
      {
        "name": "PayrollExport",
        "meaning": "One DOL or IRS's payroll/recordkeeper export for one period",
        "owner_context": "Intake & Normalization",
        "writers": [
          "Extraction Agent",
          "Sponsor"
        ],
        "readers": [
          "Compliance Reviewer",
          "Deposit Detection & Calculation"
        ],
        "source_of_truth": "Intake & Normalization context",
        "retention": "7 years (mirrors standard financial-record retention practice)",
        "privacy": "Sensitive business/financial data, firm-isolated",
        "audit": "Every field change logged"
      },
      {
        "name": "CorrectionCertificate",
        "meaning": "One correction-cycle's signed tie-out record",
        "owner_context": "Deposit Detection & Calculation",
        "writers": [
          "Detection Agent",
          "Compliance Reviewer"
        ],
        "readers": [
          "Sponsor",
          "Quality Assurance"
        ],
        "source_of_truth": "Deposit Detection & Calculation context",
        "retention": "7 years",
        "privacy": "Sensitive",
        "audit": "Full version history retained"
      },
      {
        "name": "LateDepositInstanceRecord",
        "meaning": "One cycle's list of classified, evidenced discrepancies",
        "owner_context": "Deposit Detection & Calculation",
        "writers": [
          "Discrepancy Drafter Agent",
          "Compliance Reviewer"
        ],
        "readers": [
          "Sponsor",
          "Filing & Delivery"
        ],
        "source_of_truth": "Deposit Detection & Calculation context",
        "retention": "7 years",
        "privacy": "Sensitive",
        "audit": "Reviewer approval logged per line"
      }
    ],
    "read_models": [
      "OperatorDashboard read model (per tenant): open cycles, in-review, delivered this week",
      "ReviewerQueue read model: payroll/recordkeeper exports/discrepancies awaiting review with confidence + escalation reason",
      "ComplianceLedger read model: open owner actions + release-decision",
      "AnalyticsRollup read model: metric definitions rolled up daily"
    ],
    "reporting_models": [
      "Outcome report per client: packs delivered, cycle time, client-caught error status, Corrected Instances",
      "Ops report: AI cost per cycle, escalation rate, reviewer load"
    ],
    "data_duplication_notes": [
      "Reviewer identity is stored in Onboarding, referenced by Quality Assurance — QA does not own it",
      "OwnerActionLedger duplicates minimal facts into read models for Deposit Detection & Calculation consumption"
    ],
    "data_retention": [
      "Correction Certificates + Correction Certificates + signoffs: 7 years (standard financial-record retention)",
      "AgentRun logs: 13 months rolling",
      "Users + sessions: life of account + 2 years"
    ],
    "data_quality_risks": [
      "Silent schema drift from a DOL or IRS changing its payroll/recordkeeper export layout",
      "Stale detection-evidence version applied after a rate change (mitigated by quarterly re-verification)",
      "Missing retraction cross-links after a legacy client-history import"
    ],
    "use_cases": [
      {
        "name": "Run a Deposit Timing Readiness Scan",
        "actor": "Sponsor",
        "context": "Intake & Normalization",
        "goal": "Get a matched-percentage and estimated-dollar-value finding within 2 business days",
        "preconditions": [
          "payroll and recordkeeper system export and 3 months of payroll and recordkeeper exports supplied"
        ],
        "main_flow": [
          "Intake checklist completed",
          "Payroll/recordkeeper exports normalized and tied out",
          "detection engine runs",
          "Reviewer approves discrepancies",
          "Scan report delivered"
        ],
        "alternative_flows": [
          "No material finding -> report says so explicitly, no fee retained beyond the flat scan price"
        ],
        "business_rules": [
          "No discrepancy ships without reviewer approval"
        ],
        "ai_role": "Extraction, matching, classification, drafting",
        "human_role": "Reviewer approves and signs",
        "commands": [
          "ReceivePayrollExport",
          "NormalizePayrollExport",
          "RunMatching",
          "ApproveDiscrepancy"
        ],
        "events": [
          "payroll/recordkeeper export.normalized",
          "correction_cycle.matching_completed",
          "discrepancy.reviewer_approved"
        ],
        "aggregates": [
          "PayrollExportAggregate",
          "CorrectionCycleAggregate",
          "LateDepositInstanceAggregate"
        ],
        "success": "Scan report delivered within SLA with reviewer signature",
        "failure_handling": "Missing inputs trigger an automated nag; cycle does not start until complete",
        "audit": "Full audit trail from payroll/recordkeeper export receipt to report delivery"
      },
      {
        "name": "Deliver a monthly Correction Desk pack",
        "actor": "Compliance Reviewer",
        "context": "Filing & Delivery",
        "goal": "Ship a signed Correction Certificate by the 5th business day",
        "preconditions": [
          "Client on an active Correction Desk tier",
          "Prior cycle's DOL or IRS inquiries tracked"
        ],
        "main_flow": [
          "Payroll/recordkeeper exports collected and normalized",
          "Matching completed",
          "Discrepancies approved",
          "DOL or IRS inquiries drafted and sent",
          "Ledger signed",
          "Pack delivered"
        ],
        "alternative_flows": [
          "High-value docket (>$2,500) routed to second reviewer before finalization"
        ],
        "business_rules": [
          "Penny-perfect tie-out required before signature"
        ],
        "ai_role": "Extraction, matching, classification, inquiry drafting",
        "human_role": "Reviewer signs; second reviewer on high-value dockets",
        "commands": [
          "RunMatching",
          "ApproveDiscrepancy",
          "SendRegulatorQuery",
          "SignLedger"
        ],
        "events": [
          "FilingExecuted",
          "regulator_query.sent",
          "pack.delivered"
        ],
        "aggregates": [
          "CorrectionCertificateAggregate",
          "RegulatorQueryAggregate"
        ],
        "success": "Pack delivered on time with a signed ledger",
        "failure_handling": "Missed SLA triggers the error-SLA acknowledgment process",
        "audit": "Full cycle audit trail retained"
      }
    ],
    "architecture": {
      "style": "Modular monolith with edge functions for bursty payroll/recordkeeper export-extraction workloads",
      "why": "One audit boundary, low ops burden for a founder-operated business, easy per-context ownership as the team grows past founder-only.",
      "rejected_alternatives": [
        "Microservices per bounded context (premature at this scale)",
        "No-code workflow tool (can't enforce the penny-perfect deterministic gate reliably)"
      ],
      "backend_modules": [
        "intake-normalization",
        "recovery-matching",
        "recovery-delivery",
        "quality-assurance"
      ],
      "frontend_modules": [
        "reviewer-console (internal only at launch)",
        "marketing microsite (public)"
      ],
      "api_boundaries": [
        "Internal reviewer console API (authenticated)",
        "No public API at launch — intake is upload-link/email only"
      ],
      "database_strategy": "Single Postgres instance, tenant_id row-level security on every table",
      "event_bus": "In-process event dispatch at launch; durable queue (e.g. a managed message queue) once cycle volume requires async fan-out",
      "queue": "Background job queue for payroll/recordkeeper export extraction and matching (bursty, month-end-weighted load)",
      "workflow_engine": "None at launch — explicit state machine per aggregate in code",
      "ai_orchestration": "Scripted pipeline calling a single frontier-model provider, prompts + fixtures versioned in the repo",
      "rag_layer": "Per-firm book-of-business retrieval + shared per-DOL or IRS parser/quirk knowledge base",
      "file_storage": "Encrypted object storage, per-firm prefix isolation",
      "authn_authz": "SSO with MFA for reviewers; row-level tenant auth for firm-facing surfaces (year-1 client portal)",
      "admin_dashboard": "Internal only at launch (founder + reviewer)",
      "client_portal": "None at launch (email/upload-link delivery); read-only pack-status portal planned year 1",
      "operator_dashboard": "ReviewerQueue read model surfaced in the internal console",
      "observability": "Structured logs + RED metrics + model-call cost/latency spans",
      "audit_logging": "Append-only, hash-chained per correction-cycle",
      "deployment": "Single production region, multi-AZ; preview environment per PR"
    },
    "module_structure": {
      "tree": "src/{intake-normalization,recovery-matching,recovery-delivery,quality-assurance}/{domain,application,infra}",
      "modules": [
        {
          "name": "intake-normalization",
          "purpose": "Payroll/recordkeeper exports receipt, extraction, and tie-out.",
          "owned_domain": [
            "PayrollExport"
          ],
          "application_services": [
            "ReceivePayrollExport",
            "NormalizePayrollExport"
          ],
          "infra_adapters": [
            "Mailbox listener",
            "Object storage adapter",
            "Extraction-model client"
          ],
          "public_interfaces": [
            "payroll/recordkeeper export.normalized event"
          ],
          "forbidden_deps": [
            "Cannot call recovery-matching internals directly — event only"
          ]
        },
        {
          "name": "recovery-matching",
          "purpose": "Matching, discrepancy classification, ledger tie-out.",
          "owned_domain": [
            "CorrectionCycle",
            "LateDepositInstanceRecord",
            "CorrectionCertificate"
          ],
          "application_services": [
            "RunMatching",
            "ApproveDiscrepancy",
            "SignLedger"
          ],
          "infra_adapters": [
            "payroll and recordkeeper system-export parser",
            "Detection-evidence store"
          ],
          "public_interfaces": [
            "discrepancy.reviewer_approved event",
            "FilingExecuted event"
          ],
          "forbidden_deps": [
            "Cannot call recovery-delivery internals directly — event only"
          ]
        },
        {
          "name": "recovery-delivery",
          "purpose": "DOL or IRS-inquiry drafting/sending, aging, pack assembly.",
          "owned_domain": [
            "RegulatorQuery",
            "Plan-committee memberPayoutPayrollExport",
            "MonthlyRecoveryPack"
          ],
          "application_services": [
            "SendRegulatorQuery",
            "AssemblePack",
            "DeliverPack"
          ],
          "infra_adapters": [
            "Email-send adapter",
            "Posting-file generator"
          ],
          "public_interfaces": [
            "pack.delivered event"
          ],
          "forbidden_deps": [
            "Cannot bypass quality-assurance signoff gate"
          ]
        },
        {
          "name": "quality-assurance",
          "purpose": "Signoff and retraction lifecycle.",
          "owned_domain": [
            "Signoff",
            "Retraction"
          ],
          "application_services": [
            "ApproveArtifact",
            "RetractArtifact"
          ],
          "infra_adapters": [
            "Signature-binding session store"
          ],
          "public_interfaces": [
            "ArtifactSigned event"
          ],
          "forbidden_deps": [
            "Cannot draft on behalf of any other module"
          ]
        }
      ],
      "dependency_rules": [
        "Modules communicate only via domain events or explicit application-service calls, never shared database tables",
        "quality-assurance has no outbound dependency on any other module"
      ]
    },
    "security_governance": {
      "controls": [
        {
          "risk": "Cross-tenant data leak",
          "context": "Deposit Detection & Calculation",
          "impact": "severe",
          "control": "Row-level security on every tenant-scoped table; retrieval indices partitioned per firm",
          "audit": "Access logged with tenant_id + session_id"
        },
        {
          "risk": "Reviewer identity spoofing",
          "context": "Quality Assurance",
          "impact": "severe",
          "control": "SSO + MFA; signature bound to authenticated session, not a form field",
          "audit": "Signature manifest logged per artifact"
        },
        {
          "risk": "Demand-language DOL or IRS inquiry sent",
          "context": "Filing & Delivery",
          "impact": "high",
          "control": "Deterministic filter blocks demand/collection/legal-threat patterns before reviewer sees the draft",
          "audit": "Every blocked draft logged with the trigger phrase"
        }
      ],
      "ai_governance": [
        "Every prompt version checked into the repo",
        "Every AgentRun logged with prompt version + validator verdict",
        "No fine-tuning on client data"
      ],
      "prompt_injection_defense": [
        "Uploaded payroll/recordkeeper export content treated as untrusted input, never as instructions",
        "Extraction output schema-validated before use downstream"
      ],
      "sensitive_data_handling": [
        "Financial/PII scrubbed from logs",
        "Per-firm object-storage prefix isolation",
        "Encryption at rest and in transit"
      ],
      "access_control_matrix": [
        {
          "role": "Sponsor",
          "context": "Intake & Normalization",
          "capabilities": [
            "Upload payroll/recordkeeper exports",
            "View own firm's cycle status"
          ]
        },
        {
          "role": "Compliance Reviewer",
          "context": "Deposit Detection & Calculation, Quality Assurance",
          "capabilities": [
            "Approve discrepancies",
            "Sign ledgers",
            "Approve DOL or IRS inquiries"
          ]
        },
        {
          "role": "Senior Reviewer",
          "context": "Quality Assurance",
          "capabilities": [
            "Co-sign retractions",
            "Second-review high-value dockets"
          ]
        }
      ],
      "audit_log_requirements": [
        "Every command + payload hash logged with actor identity",
        "13-month rolling retention on AgentRun logs; 7-year retention on signed ledgers"
      ]
    },
    "observability": {
      "metrics": [
        {
          "metric": "Auto-match rate",
          "type": "leading",
          "context": "Deposit Detection & Calculation",
          "why": "Directly drives reviewer minutes per cycle",
          "target": "≥90%",
          "alert_threshold": "<80%"
        },
        {
          "metric": "Reviewer minutes per client per cycle",
          "type": "leading",
          "context": "Deposit Detection & Calculation",
          "why": "Core unit-economics driver",
          "target": "≤115 min by day 90",
          "alert_threshold": ">180 min"
        },
        {
          "metric": "Client-caught material error rate",
          "type": "lagging",
          "context": "Quality Assurance",
          "why": "Trust and retention driver",
          "target": "<0.5%",
          "alert_threshold": ">1%"
        }
      ],
      "dashboards": [
        "Ops dashboard: cycles in flight, reviewer queue depth",
        "Economics dashboard: COGS/client, gross margin trend"
      ],
      "audit_reports": [
        "Monthly signed-ledger audit export per client"
      ],
      "quality_review_reports": [
        "Weekly red-team seeded-error catch rate"
      ],
      "ai_evaluation_reports": [
        "Monthly evaluator regression report per DOL or IRS parser"
      ],
      "client_outcome_reports": [
        "Recovered-dollars report per client per quarter"
      ]
    },
    "testing_strategy": {
      "tests": [
        {
          "type": "unit",
          "validates": "Tie-out math and materiality thresholds",
          "context": "Deposit Detection & Calculation",
          "example": "Ledger total must equal sum of matched + exception-coded lines"
        },
        {
          "type": "contract",
          "validates": "Per-DOL or IRS parser output schema",
          "context": "Intake & Normalization",
          "example": "Gold-standard fixture payroll/recordkeeper export per DOL or IRS re-run on every prompt change"
        },
        {
          "type": "e2e",
          "validates": "Full intake -> match -> reviewer signoff -> delivery path",
          "context": "cross-context",
          "example": "Smoke test against 5 sample payroll and recordkeeper export formats"
        }
      ],
      "critical_domain_rules": [
        "Penny-perfect tie-out before signature",
        "No Late Deposit Instance without a cited source payroll/recordkeeper reference",
        "No DOL or IRS inquiry without authorization on file"
      ],
      "ai_eval_dataset": [
        "Gold-standard fixture payroll/recordkeeper exports per DOL or IRS",
        "Reviewer-corrected historical matches and classifications"
      ],
      "regression_plan": "Every parser/prompt/model change re-runs the full fixture suite before touching a live client payroll/recordkeeper export.",
      "contract_testing_plan": "Per-payroll and recordkeeper export schema contract tests run in CI on every parser change.",
      "manual_qa_checklist": [
        "10% second-pass sample of auto-matched lines",
        "Monthly red-team seeded-error check",
        "Every docket over $2,500 second-reviewed"
      ]
    },
    "mvp_roadmap": [
      {
        "phase": "Thin slice",
        "goal": "One end-to-end Deposit Timing Readiness Scan delivered and reviewer-signed",
        "features": [
          "Payroll/recordkeeper exports intake",
          "Single-DOL or IRS-format extraction",
          "Manual-assisted matching"
        ],
        "contexts": [
          "Intake & Normalization",
          "Deposit Detection & Calculation"
        ],
        "ai_needs": [
          "Extraction Agent v1"
        ],
        "human_workflows": [
          "Founder-run reviewer role"
        ],
        "data_needs": [
          "Fixture payroll/recordkeeper exports for 5 formats"
        ],
        "integrations": [
          "None — manual payroll and recordkeeper system export upload"
        ],
        "risks": [
          "Reviewer cycle time far above target at pilot 1"
        ],
        "exit_criteria": [
          "1 scan delivered within 2 business days, reviewer-signed"
        ]
      }
    ],
    "scaling_roadmap": [
      {
        "stage": "Pilot (1-10 clients)",
        "trigger": "First 10 pilot firms onboarded",
        "architecture_change": "None — single monolith suffices",
        "operational_change": "Founder is the sole reviewer",
        "risk": "Reviewer bottleneck at any volume spike"
      },
      {
        "stage": "Early scale (10-50 clients)",
        "trigger": "Day-90 checkpoint targets met",
        "architecture_change": "Background job queue for payroll/recordkeeper export extraction",
        "operational_change": "Contract a second Compliance Reviewer",
        "risk": "Parser library coverage gaps on new DOL or IRSs slow onboarding"
      }
    ],
    "risk_register": [
      {
        "risk": "payroll and recordkeeper system vendor bundles recovery 'free' with a resolve workflow",
        "likelihood": "medium-high",
        "impact": "high",
        "signal": "Applied Recon or a competing payroll and recordkeeper system module adds resolve/recovery features",
        "mitigation": "payroll and recordkeeper system-agnostic positioning; recovery/resolve as the human moat",
        "owner": "owner",
        "context": "Filing & Delivery"
      },
      {
        "risk": "Scan-to-desk conversion underperforms",
        "likelihood": "medium",
        "impact": "severe",
        "signal": "Pilot cohort conversion below 25%",
        "mitigation": "Pilot gate at 25%; alternative packaging tested in cohort 2",
        "owner": "owner",
        "context": "product"
      },
      {
        "risk": "False-positive discrepancy sent to a DOL or IRS",
        "likelihood": "medium",
        "impact": "high",
        "signal": "DOL or IRS disputes an inquiry as unfounded",
        "mitigation": "100% reviewer approval; evidence-link requirement; inquiry-not-demand language",
        "owner": "legal",
        "context": "Filing & Delivery"
      }
    ],
    "adrs": [
      {
        "id": "ADR-001",
        "decision": "Adopt a modular monolith, not microservices, at launch",
        "status": "accepted",
        "context": "Founder-operated team; low ops burden required",
        "options": [
          "Modular monolith",
          "Microservices per bounded context",
          "No-code workflow tool"
        ],
        "chosen": "Modular monolith",
        "business_reason": "Fastest path to first paid pilot without a platform team",
        "technical_reason": "One deploy, one audit boundary, easy to reason about at this scale",
        "tradeoffs": [
          "[PLACEHOLDER] owner to complete"
        ],
        "risks": [
          "[PLACEHOLDER] owner to complete"
        ],
        "revisit_trigger": "Sustained CPU/latency pressure isolated to one module",
        "why": "One deploy, one audit boundary, easy to reason about at this scale",
        "consequences": "Will need extraction into services if reviewer-console load grows sharply",
        "reversal": "Would require a migration of the affected module's data model.",
        "revisit_when": "Sustained CPU/latency pressure isolated to one module"
      },
      {
        "id": "ADR-002",
        "decision": "Deterministic code owns all money math; the model never computes a final dollar figure",
        "status": "accepted",
        "context": "Penny-perfect tie-out is a hard trust requirement",
        "options": [
          "Model computes totals",
          "Deterministic code computes totals, model only extracts/classifies"
        ],
        "chosen": "Deterministic code computes totals",
        "business_reason": "A wrong dollar figure from a model is the single fastest way to lose a client's trust",
        "technical_reason": "Removes an entire class of hallucination risk from the highest-stakes output",
        "tradeoffs": "Slightly more engineering work per new transaction-type edge case",
        "risks": "Edge cases not yet coded fall through to reviewer manual calculation",
        "revisit_trigger": "None — this is a standing invariant, not revisited",
        "why": "Removes an entire class of hallucination risk from the highest-stakes output",
        "consequences": "Slightly more engineering work per new transaction-type edge case",
        "reversal": "Would require a migration of the affected module's data model.",
        "revisit_when": "None — this is a standing invariant, not revisited"
      }
    ],
    "self_audit": {
      "scores": [
        {
          "category": "domain_modeling",
          "score": 4,
          "weakness": "DOL or IRS-quirk knowledge base is described but not yet instantiated with real DOL or IRS data",
          "improvement": "Populate from the first 5 pilot firms' actual DOL or IRS mixes"
        },
        {
          "category": "ai_governance",
          "score": 4,
          "weakness": "Evaluator regression suite depends on fixture payroll/recordkeeper exports not yet collected at volume",
          "improvement": "Build the fixture library incrementally from each pilot's real (anonymized) payroll/recordkeeper exports"
        },
        {
          "category": "compliance_boundary",
          "score": 3,
          "weakness": "State-by-state correction-desk-statute review for the Deposit Timing Monitoring retainer is not yet complete",
          "improvement": "Complete counsel review in the first 5 operating states before offering the rider broadly"
        }
      ],
      "weakest_parts": [
        "State-by-state licensing review for the Deposit Timing Monitoring retainer",
        "DOL or IRS-quirk knowledge base population"
      ],
      "biggest_assumptions": [
        "Scan-to-desk conversion reaches 25-40%",
        "Reviewer minutes per client fall as projected by day 90"
      ],
      "highest_risk_decisions": [
        "Offering the Deposit Timing Monitoring retainer before full state-by-state counsel review",
        "Relying on a single named reviewer at pilot scale"
      ],
      "needs_domain_expert": [
        "[PLACEHOLDER] owner to complete"
      ],
      "needs_legal": [
        "[PLACEHOLDER] owner to complete"
      ],
      "needs_prototype": [
        "[PLACEHOLDER] owner to complete"
      ],
      "validate_before_prod": [
        "[PLACEHOLDER] owner to complete"
      ]
    },
    "final_recommendations": [
      "Ship a modular-monolith, evidence-linked, reviewer-gated vertical slice for CorrectPath. Preserve the invariant that no Correction Certificate or DOL or IRS inquiry leaves the system without a signed human release. Do not launch commercially until owner-action facts close and at least one reviewer-released Correction Certificate has shipped.",
      "Do NOT default to microservices. Extract a module only when a specific pressure demands it.",
      "Do NOT allow AI outputs to leave the Deposit Detection & Calculation or Filing & Delivery contexts without OutputValidator pass and citation coverage.",
      "Do NOT ship any public claim on the CorrectPath microsite while owner-action facts (entity, reviewer identity, trademark clearance) remain open.",
      "Do NOT reuse a competitor/customer pairing or a dollar figure in client-facing copy without a fresh-verification citation — this exact failure mode (a misattributed customer relationship) was found and corrected in this build."
    ],
    "extensions": {
      "service_business_reality_check": {
        "is_service_business": true,
        "paid_outcome_clear": true,
        "workflow_present": true,
        "ai_native_fit_score": 4.5,
        "red_flags": [
          "[PLACEHOLDER] owner to complete"
        ]
      },
      "ai_native_fit": {
        "score": 4.6,
        "why": "High-volume, document-heavy, rules-based matching with judgment concentrated in a small exception queue — the exact shape of work current frontier models do well, and margins expand as parsing/matching accuracy improves.",
        "disqualifiers": [
          "[PLACEHOLDER] owner to complete"
        ]
      },
      "domain_evidence_register": [
        {
          "claim": "52% of firms receive delinquent-deposit payroll/recordkeeper exports, up from 45% in 2022",
          "evidence_type": "primary-research summary",
          "source": "Big \"I\" Firm Universe Study (via IA Magazine)",
          "strength": "high",
          "gaps": "None — corroborated across two independent trade-press summaries"
        },
        {
          "claim": "Comulate serves large clients and remains operational as of mid-2026",
          "evidence_type": "press + legal filing coverage",
          "source": "Comulate/Workday Ventures materials; federal court ruling coverage, Feb 2026",
          "strength": "high",
          "gaps": "Exact customer roster not independently verifiable — corrected one misattributed customer pairing this build"
        }
      ],
      "assumption_register": [
        {
          "assumption": "Scan-to-desk conversion reaches 25-40%",
          "impact_if_wrong": "severe — wedge economics fail",
          "how_to_validate": "10-firm pilot cohort with explicit pricing conversation",
          "blocking": true
        },
        {
          "assumption": "Reviewer minutes per client fall as parser coverage grows",
          "impact_if_wrong": "high — margin target missed",
          "how_to_validate": "Instrument reviewer minutes per cycle from pilot 1 onward",
          "blocking": false
        }
      ],
      "language_conflict_map": [
        {
          "term": "pack",
          "meaning_a": "Correction Certificate (this business's bundled deliverable: ledger + docket + report + payouts + posting file)",
          "context_a": "CorrectPath",
          "meaning_b": "A different bundled-deliverable term used by unrelated businesses elsewhere in the AINBIS portfolio",
          "context_b": "other portfolio businesses (not this one)",
          "resolution": "Always qualify as 'Correction Certificate' in CorrectPath copy; never bare 'pack' without the qualifier in cross-portfolio contexts"
        }
      ],
      "build_buy_integrate": [
        {
          "subdomain": "Deposit Detection & Calculation",
          "decision": "build",
          "reason": "Core differentiated IP — the parser/detection engine is the moat"
        },
        {
          "subdomain": "Referral & Outreach",
          "decision": "buy",
          "reason": "Off-the-shelf CRM suffices; not differentiating"
        }
      ],
      "core_protection_strategy": [
        "[PLACEHOLDER] owner to complete"
      ],
      "boundary_stress_tests": [
        {
          "scenario": "A DOL or IRS disputes an inquiry as a collection demand",
          "contexts_touched": [
            "Filing & Delivery"
          ],
          "breaks_if": "The demand-language filter has a gap for a novel phrasing",
          "verdict": "Mitigated by reviewer approval as a second gate"
        }
      ],
      "unresolved_ownership": [
        {
          "concept": "Plan-committee member split sheet accuracy",
          "candidates": [
            "Sponsor",
            "Compliance Reviewer"
          ],
          "recommendation": "Sponsor owns and approves the split sheet; CorrectPath only computes from it"
        }
      ],
      "published_language_contracts": [
        {
          "producer": "Intake & Normalization",
          "consumer": "Deposit Detection & Calculation",
          "contract": "Canonical normalized payroll/recordkeeper export schema",
          "versioning": "Schema version pinned per DOL or IRS parser release"
        }
      ],
      "shared_kernel_warnings": [
        "None identified — bounded contexts communicate only via events, no shared kernel"
      ],
      "aggregate_stress_tests": [
        {
          "aggregate": "CorrectionCertificateAggregate",
          "scenario": "Concurrent reviewer sign attempts on the same ledger",
          "invariant_at_risk": "Penny-perfect tie-out before signature",
          "verdict": "Mitigated by optimistic locking on the aggregate root"
        }
      ],
      "agent_stress_tests": [
        {
          "agent": "Inquiry Drafter Agent",
          "scenario": "A DOL or IRS's known aggressive collections department prompts an escalated tone",
          "failure_mode": "Draft reads as a threat despite passing the deterministic filter",
          "guardrail": "Reviewer approval catches tone issues the filter misses",
          "verdict": "Acceptable with reviewer gate"
        }
      ],
      "regulated_domain_handling": [
        {
          "regime": "State plan-committee member-licensing statutes",
          "applies_because": "CorrectPath performs back-office accounting adjacent to a licensed industry",
          "controls": [
            "No selling/soliciting/negotiating",
            "No consumer contact"
          ],
          "evidence_required": [
            "[PLACEHOLDER] owner to complete"
          ]
        },
        {
          "regime": "State correction-desk statutes",
          "applies_because": "DOL or IRS inquiries could be miscategorized as third-party compliance correction",
          "controls": [
            "Inquiries sent under firm's own name",
            "Administrative-agent authorization",
            "No demand language"
          ],
          "evidence_required": "Per-state counsel review before offering the Deposit Timing Monitoring retainer"
        }
      ],
      "unit_economics": {
        "price_model": "Flat monthly desk fee by volume tier + one-time scan + capped Deposit Timing Monitoring retainer",
        "unit_of_value": "correction-cycle (one client-month)",
        "gross_margin_pct": 62,
        "cost_drivers": [
          "Model inference (parse/match/draft)",
          "Reviewer minutes",
          "QA sampling"
        ],
        "breakeven_note": "COGS/client falls from $510 at launch to $245 by year 1 as parser coverage and auto-match rate improve"
      },
      "margin_leakage_map": [
        {
          "leakage": "Reviewer minutes not falling with parser coverage",
          "cause": "New DOL or IRS formats not yet in the fixture library",
          "impact": "Gross margin compression per new client",
          "mitigation": "Fixture library grows with every pilot; reuse across clients on the same DOL or IRS"
        }
      ],
      "slop_findings": [
        {
          "pattern": "Generic SaaS marketing phrasing",
          "status": "checked",
          "note": "Banned marketing-cliché phrases are enforced out of all landing-page copy per DESIGN-STANDARD.md."
        }
      ],
      "drift_checks": [
        {
          "stage": "build",
          "status": "checked",
          "findings": [
            "[PLACEHOLDER] owner to complete"
          ]
        }
      ],
      "gates": [
        {
          "id": "G1",
          "title": "No public claim before owner-action facts close",
          "passed": false,
          "checks": [
            {
              "name": "Entity confirmed",
              "ok": false,
              "evidence": "Pending owner action"
            },
            {
              "name": "Reviewer identity confirmed",
              "ok": false,
              "evidence": "Pending owner action"
            },
            {
              "name": "Trademark clearance",
              "ok": false,
              "evidence": "Pending owner action"
            }
          ]
        }
      ],
      "contradiction_scan": [
        {
          "id": "C1",
          "severity": "medium",
          "message": "Blueprint attributed Baldwin Group to Comulate; fresh sourcing shows Baldwin Group uses Ascend/ReSource Pro instead",
          "refs": [
            "business-plan.md fresh-verification notes"
          ]
        }
      ],
      "rubric": {
        "categories": [
          {
            "category": "domain_modeling",
            "score": 4,
            "min": 3,
            "passed": true
          },
          {
            "category": "ai_governance",
            "score": 4,
            "min": 3,
            "passed": true
          },
          {
            "category": "compliance_boundary",
            "score": 4,
            "min": 3,
            "passed": true
          },
          {
            "category": "unit_economics",
            "score": 4,
            "min": 3,
            "passed": true
          },
          {
            "category": "gtm_clarity",
            "score": 4,
            "min": 3,
            "passed": true
          }
        ],
        "pass": true,
        "average": 4.1
      },
      "foundry_package": {
        "version": "1.0.0",
        "checksum": "n/a-generated-locally",
        "counts": {
          "subdomains": 4,
          "bounded_contexts": 4,
          "aggregates": 7,
          "events": 6,
          "commands": 6,
          "policies": 4,
          "ai_agents": 4,
          "invariants": 4,
          "integrations": 4,
          "adrs": 2
        },
        "subset": {
          "subdomains": [
            "Deposit Detection & Calculation",
            "Filing & Delivery",
            "Evidence & Compliance",
            "Referral & Outreach"
          ],
          "bounded_contexts": [
            "Intake & Normalization",
            "Deposit Detection & Calculation",
            "Filing & Delivery",
            "Quality Assurance"
          ],
          "aggregates": [
            "PayrollExportAggregate",
            "CorrectionCycleAggregate",
            "LateDepositInstanceAggregate",
            "CorrectionCertificateAggregate",
            "RegulatorQueryAggregate",
            "SignoffAggregate",
            "RetractionAggregate"
          ],
          "events": [
            "payroll/recordkeeper export.received",
            "payroll/recordkeeper export.normalized",
            "correction_cycle.matching_completed",
            "discrepancy.reviewer_approved",
            "FilingExecuted",
            "regulator_query.sent"
          ],
          "commands": [
            "ReceivePayrollExport",
            "NormalizePayrollExport",
            "RunMatching",
            "ApproveDiscrepancy",
            "SignLedger",
            "SendRegulatorQuery"
          ],
          "policies": [
            "Auto-route low-confidence match to reviewer",
            "Block demand-language patterns",
            "Second-reviewer spot check",
            "Auto-escalate aging inquiry"
          ],
          "ai_agents": [
            "Extraction Agent",
            "Detection Agent",
            "Discrepancy Drafter Agent",
            "Inquiry Drafter Agent"
          ],
          "invariants": [
            "A Correction Certificate cannot be signed without tying to payroll/recordkeeper export totals to the penny",
            "A RegulatorQuery cannot be sent without reviewer approval and firm authorization on file",
            "No Late Deposit Instance is published without a cited source payroll/recordkeeper export reference",
            "CorrectPath never issues a coverage or claims-adjustment determination"
          ],
          "integrations": [
            "Firm management system (payroll and recordkeeper system) export",
            "payroll and recordkeeper export portals",
            "QuickBooks / payroll and recordkeeper system posting-file import",
            "DOL/IRS correspondence mailbox"
          ],
          "adrs": [
            "ADR-001",
            "ADR-002"
          ]
        }
      }
    }
  },
  "ddd_coverage": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "total": 17,
    "passed": 17,
    "pct": 100,
    "checks": [
      {
        "key": "actors",
        "label": "Actors",
        "count": 4,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "subdomains",
        "label": "Subdomains",
        "count": 4,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "bounded_contexts",
        "label": "Bounded Contexts",
        "count": 4,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "aggregates",
        "label": "Aggregates",
        "count": 7,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "events",
        "label": "Events",
        "count": 6,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "commands",
        "label": "Commands",
        "count": 6,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "filings",
        "label": "Filings",
        "count": 4,
        "min": 2,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "ai_agents",
        "label": "Ai Agents",
        "count": 4,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "invariants",
        "label": "Invariants",
        "count": 4,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "use_cases",
        "label": "Use Cases",
        "count": 2,
        "min": 2,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "human_roles",
        "label": "Human Roles",
        "count": 3,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "data_objects",
        "label": "Data Objects",
        "count": 3,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "risk_register",
        "label": "Risk Register",
        "count": 3,
        "min": 3,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "adrs",
        "label": "Adrs",
        "count": 2,
        "min": 2,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "mvp_roadmap",
        "label": "Mvp Roadmap",
        "count": 1,
        "min": 1,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "scaling_roadmap",
        "label": "Scaling Roadmap",
        "count": 2,
        "min": 2,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      },
      {
        "key": "context_map",
        "label": "Context Map",
        "count": 4,
        "min": 2,
        "ok": true,
        "gate": "domain",
        "unblock": "Not needed — check passes at current counts."
      }
    ],
    "failingGates": [
      "[PLACEHOLDER] owner to complete"
    ]
  },
  "architecture": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "archetypes": [
      "recovery-and-recovery workflow application",
      "back-office document-intelligence service"
    ],
    "archetype_impact": "Recovery cycle (client + calendar month) is the global scoping parameter — every read/write is scoped by firm tenant and cycle, not just tenant alone.",
    "personality": [
      "numerate",
      "calm",
      "evidence-first",
      "no hype"
    ],
    "forces_ranked": [
      {
        "force": "Trust/accuracy (penny-perfect tie-out)",
        "why": "A wrong ledger is the single fastest way to lose a client"
      },
      {
        "force": "Founder-operability (low ops burden)",
        "why": "Founder-operated launch cannot support a platform team"
      },
      {
        "force": "Time-to-first-revenue",
        "why": "Pilot cohort must convert within 90 days to validate the model"
      },
      {
        "force": "Scalability beyond pilot",
        "why": "Lowest priority at launch; revisit at 20+ clients"
      }
    ],
    "tradeoffs": [
      "Modular monolith trades some future scaling ease for launch speed and audit simplicity",
      "Manual DOL or IRS follow-up at launch trades automation for learning real response patterns first"
    ],
    "quality_scenarios": [
      {
        "attribute": "accuracy",
        "assumption": "Every payroll/recordkeeper export line ties to its source",
        "target": "Ledger tie-out to the penny before signature, 100% of releases"
      },
      {
        "attribute": "reviewability",
        "assumption": "A reviewer can reconstruct any evidence chain quickly",
        "target": "Under 5 minutes to trace any ledger line to its source payroll/recordkeeper export"
      }
    ],
    "options": [
      {
        "style": "Modular monolith",
        "complexity": "low",
        "cost": "low",
        "ops_burden": "low",
        "team_fit": "high (founder-operated)",
        "scaling_path": "Extract modules under pressure",
        "security_impact": "Single audit boundary",
        "fits_here": true,
        "fits_when": "Founder/small-team launch",
        "wrong_here": false,
        "recommended": true
      },
      {
        "style": "Microservices per bounded context",
        "complexity": "high",
        "cost": "high",
        "ops_burden": "high",
        "team_fit": "low at launch",
        "scaling_path": "Already decomposed",
        "security_impact": "More boundaries to secure",
        "fits_here": false,
        "fits_when": "Large team, proven scale pressure",
        "wrong_here": true,
        "recommended": false
      },
      {
        "style": "No-code workflow tool",
        "complexity": "low",
        "cost": "low",
        "ops_burden": "low",
        "team_fit": "medium",
        "scaling_path": "Poor — hard to enforce deterministic gates",
        "security_impact": "Vendor-dependent",
        "fits_here": false,
        "fits_when": "No hard money-math invariant",
        "wrong_here": true,
        "recommended": false
      }
    ],
    "chosen_style": "modular monolith",
    "chosen_rationale": "Modular monolith with background jobs for bursty payroll/recordkeeper export-extraction work — one audit boundary, low ops burden, easy per-context ownership as the team grows.",
    "rejected": [
      {
        "style": "Microservices per bounded context",
        "why_rejected": "Premature operational complexity for a founder-operated launch"
      },
      {
        "style": "No-code workflow tool",
        "why_rejected": "Cannot reliably enforce the deterministic penny-perfect gate"
      }
    ],
    "target": {
      "overview": "Single-region modular monolith, Postgres primary store, background job queue for extraction/matching, internal reviewer console, public marketing microsite.",
      "frontend": "Reviewer console (internal, authenticated) + public marketing microsite (static, self-contained)",
      "backend": "Single deployable service, module boundaries enforced by code convention and event-only cross-module calls",
      "data": "Postgres with row-level tenant security; object storage for payroll/recordkeeper export files",
      "api": "Internal authenticated API for the reviewer console; no public API at launch",
      "authn_authz": "SSO + MFA for reviewers; row-level auth scaffolding for a future client portal",
      "integrations": "payroll and recordkeeper system export file ingestion; payroll and recordkeeper export mailbox/portal; QuickBooks/payroll and recordkeeper system posting-file export",
      "background_jobs": "Payroll/recordkeeper exports extraction, matching, regulatory-deadline tracking checks",
      "object_storage": "Encrypted, per-firm-prefix isolated",
      "notifications": "Email only at launch (client comms + internal escalation alerts)",
      "search": "None at launch",
      "analytics": "Internal metrics dashboard only; no third-party analytics on the reviewer console",
      "ai": "Single frontier-model provider via a scripted extraction/matching/drafting pipeline, prompts + fixtures versioned in-repo",
      "observability": "Structured logs, RED metrics, model-call cost/latency spans",
      "deployment": "Single production region, multi-AZ, preview environment per PR",
      "security": "Row-level tenant isolation, encryption at rest/in transit, least-privilege access",
      "dr": "Daily backups, tested restore runbook, RPO 24h / RTO 4h at launch scale"
    },
    "modules": [
      {
        "name": "intake-normalization",
        "purpose": "Payroll/recordkeeper exports receipt, extraction, and tie-out.",
        "owned_domain": [
          "PayrollExport"
        ],
        "application_services": [
          "ReceivePayrollExport",
          "NormalizePayrollExport"
        ],
        "infra_adapters": [
          "Mailbox listener",
          "Object storage adapter",
          "Extraction-model client"
        ],
        "public_interfaces": [
          "payroll/recordkeeper export.normalized event"
        ],
        "forbidden_deps": [
          "Cannot call recovery-matching internals directly — event only"
        ],
        "responsibility": "Payroll/recordkeeper exports receipt, extraction, and tie-out.",
        "owned_data": [
          "PayrollExport"
        ],
        "events_produced": [
          "payroll/recordkeeper export.normalized event"
        ],
        "events_consumed": [
          "[PLACEHOLDER] owner to complete"
        ],
        "interfaces": [
          "payroll/recordkeeper export.normalized event"
        ],
        "depends_on": [
          "[PLACEHOLDER] owner to complete"
        ],
        "entities": [
          "PayrollExport"
        ],
        "failure_risks": [
          "Module-boundary violation via direct DB access"
        ],
        "scaling": "Extract to a service only under sustained isolated load pressure",
        "future_split_trigger": "Sustained CPU/latency pressure isolated to this module"
      },
      {
        "name": "deposit-detection-calculation",
        "purpose": "Detection, Lost Earnings calculation, certificate tie-out.",
        "owned_domain": [
          "CorrectionCycle",
          "LateDepositInstanceRecord",
          "CorrectionCertificate"
        ],
        "application_services": [
          "DetectLateDepositInstance",
          "VerifyInstance",
          "ExecuteFiling"
        ],
        "infra_adapters": [
          "payroll and recordkeeper system-export parser",
          "Detection-evidence store"
        ],
        "public_interfaces": [
          "InstanceVerified event",
          "FilingExecuted event"
        ],
        "forbidden_deps": [
          "Cannot call filing-delivery internals directly — event only"
        ],
        "responsibility": "Detection, Lost Earnings calculation, certificate tie-out.",
        "owned_data": [
          "CorrectionCycle",
          "LateDepositInstanceRecord",
          "CorrectionCertificate"
        ],
        "events_produced": [
          "InstanceVerified event",
          "FilingExecuted event"
        ],
        "events_consumed": [],
        "interfaces": [
          "InstanceVerified event",
          "FilingExecuted event"
        ],
        "depends_on": [],
        "entities": [
          "CorrectionCycle",
          "LateDepositInstanceRecord",
          "CorrectionCertificate"
        ],
        "failure_risks": [
          "Module-boundary violation via direct DB access"
        ],
        "scaling": "Extract to a service only under sustained isolated load pressure",
        "future_split_trigger": "Sustained CPU/latency pressure isolated to this module"
      },
      {
        "name": "filing-delivery",
        "purpose": "DOL or IRS-inquiry drafting/sending, aging, pack assembly.",
        "owned_domain": [
          "RegulatorQuery",
          "Plan-committee memberPayoutPayrollExport",
          "MonthlyRecoveryPack"
        ],
        "application_services": [
          "SendRegulatorQuery",
          "AssemblePack",
          "DeliverPack"
        ],
        "infra_adapters": [
          "Email-send adapter",
          "Posting-file generator"
        ],
        "public_interfaces": [
          "pack.delivered event"
        ],
        "forbidden_deps": [
          "Cannot bypass quality-assurance signoff gate"
        ],
        "responsibility": "DOL or IRS-inquiry drafting/sending, aging, pack assembly.",
        "owned_data": [
          "RegulatorQuery",
          "Plan-committee memberPayoutPayrollExport",
          "MonthlyRecoveryPack"
        ],
        "events_produced": [
          "pack.delivered event"
        ],
        "events_consumed": [],
        "interfaces": [
          "pack.delivered event"
        ],
        "depends_on": [],
        "entities": [
          "RegulatorQuery",
          "Plan-committee memberPayoutPayrollExport",
          "MonthlyRecoveryPack"
        ],
        "failure_risks": [
          "Module-boundary violation via direct DB access"
        ],
        "scaling": "Extract to a service only under sustained isolated load pressure",
        "future_split_trigger": "Sustained CPU/latency pressure isolated to this module"
      },
      {
        "name": "quality-assurance",
        "purpose": "Signoff and retraction lifecycle.",
        "owned_domain": [
          "Signoff",
          "Retraction"
        ],
        "application_services": [
          "ApproveArtifact",
          "RetractArtifact"
        ],
        "infra_adapters": [
          "Signature-binding session store"
        ],
        "public_interfaces": [
          "ArtifactSigned event"
        ],
        "forbidden_deps": [
          "Cannot draft on behalf of any other module"
        ],
        "responsibility": "Signoff and retraction lifecycle.",
        "owned_data": [
          "Signoff",
          "Retraction"
        ],
        "events_produced": [
          "ArtifactSigned event"
        ],
        "events_consumed": [],
        "interfaces": [
          "ArtifactSigned event"
        ],
        "depends_on": [],
        "entities": [
          "Signoff",
          "Retraction"
        ],
        "failure_risks": [
          "Module-boundary violation via direct DB access"
        ],
        "scaling": "Extract to a service only under sustained isolated load pressure",
        "future_split_trigger": "Sustained CPU/latency pressure isolated to this module"
      }
    ],
    "data_architecture": {
      "primary_db": "Postgres",
      "secondary": [
        "Object storage for payroll/recordkeeper export files"
      ],
      "cache": "None at launch",
      "search": "None at launch",
      "vector": "None at launch (retrieval is structured lookup, not embeddings, at this scale)",
      "object_storage": "Per-firm-prefix isolated bucket",
      "schema_strategy": "Migration-gated, reviewed per PR",
      "migrations": "Forward-only, reviewed",
      "backups": "Daily automated, tested restore quarterly",
      "retention": "7 years on signed ledgers/dockets; 13 months on agent-run logs",
      "audit_logs": "Append-only, hash-chained per correction-cycle",
      "soft_delete": "Used for client offboarding, hard-delete on retention expiry",
      "privacy": "Per-tenant row-level security",
      "encryption": "At rest and in transit",
      "multi_tenancy": "Logical isolation via tenant_id row-level security"
    },
    "api": {
      "style": "Internal REST",
      "public_vs_internal": "Internal only at launch",
      "versioning": "Path-versioned when a client portal ships",
      "rate_limiting": "Per-tenant budget caps on model-backed endpoints",
      "idempotency": "Idempotency keys on payroll/recordkeeper export ingestion",
      "pagination": "Cursor-based on list endpoints",
      "error_format": "Structured JSON problem-details",
      "webhook_security": "N/A at launch",
      "retries": "Exponential backoff on model-provider calls",
      "contract_testing": "Per-DOL or IRS parser schema contract tests in CI",
      "backward_compat": "N/A at launch (no public API)",
      "contract_testing_plan": "Fixture-based regression suite run on every parser/prompt change"
    },
    "security": {
      "authn": "SSO + MFA for reviewers",
      "authz": "Role-based, server-side capability checks",
      "tenant_isolation": "Row-level security keyed on tenant_id",
      "secrets": "Managed secrets store, no secrets in code",
      "encryption": "At rest and in transit",
      "session": "Server-side session with short-lived tokens",
      "input_validation": "Schema validation on every ingestion path",
      "api_protection": "Rate limiting + auth on all internal endpoints",
      "audit_log": "Append-only, hash-chained",
      "admin_access": "Break-glass access logged and time-boxed",
      "supply_chain": "Dependency scanning in CI",
      "threat_model": [
        "Cross-tenant leak",
        "Reviewer identity spoofing",
        "Prompt injection via uploaded payroll/recordkeeper exports"
      ],
      "abuse_cases": [
        "Bulk fraudulent payroll/recordkeeper export upload attempting to poison the detection engine"
      ],
      "zero_trust": "Server-side checks on every capability, never client-only",
      "asvs_notes": "Aligned to OWASP ASVS L2 controls for a B2B financial-data service"
    },
    "reliability": {
      "failure_modes": [
        "Model-provider outage mid-extraction",
        "DOL or IRS portal credential expiry",
        "Payroll/recordkeeper exports queue backlog at month-end"
      ],
      "graceful_degradation": "Queue and retry rather than fail hard; reviewer notified of delayed cycles",
      "retry_policy": "Exponential backoff, max 5 attempts on model calls",
      "timeouts": "30s extraction timeout, background-job fallback beyond that",
      "circuit_breaker": "Trip on repeated model-provider failures, alert on-call",
      "queueing": "Background job queue for extraction/matching",
      "idempotency": "Idempotency keys on payroll/recordkeeper export ingestion",
      "dlq": "Dead-letter queue for repeatedly failing extraction jobs",
      "transactions": "Aggregate-scoped transactions, no cross-aggregate transactions",
      "dr": "Daily backups, quarterly restore test",
      "incident_response": "Runbook: detect, contain, notify, root-cause, postmortem",
      "slos": [
        {
          "name": "p95 payroll/recordkeeper export extraction latency",
          "target": "under 30s"
        },
        {
          "name": "Monthly pack on-time delivery",
          "target": "≥95% of cycles by the 5th business day"
        }
      ]
    },
    "scaling": {
      "mvp_can_stay_simple": [
        "Single Postgres instance",
        "In-process event dispatch"
      ],
      "modular_now": [
        "Module boundaries enforced by convention"
      ],
      "deferrable": [
        "Client-facing portal",
        "Public API",
        "Vector search"
      ],
      "breaks_first": "Reviewer throughput before infrastructure",
      "db_path": "Read replicas once reporting load grows",
      "jobs_path": "Managed queue once in-process dispatch saturates",
      "cache_path": "Add a cache layer only if read latency becomes a measured problem",
      "search_path": "Add full-text search only if client-portal search becomes a real need",
      "files_path": "Object storage scales natively",
      "api_path": "Add a versioned public API only when a client portal ships",
      "multi_region": "Not needed at this scale",
      "cost_control": "Per-tenant model-spend budget caps"
    },
    "ai": {
      "provider": "Single frontier-model provider (model-agnostic schemas/prompts, swappable within days)",
      "prompt_mgmt": "Versioned in-repo, immutable once published",
      "rag": "Structured per-firm + per-DOL or IRS retrieval, not embeddings-based at this scale",
      "vector": "Not used at this scale",
      "embeddings": "Not used at this scale",
      "eval": "Fixture-based regression suite per DOL or IRS",
      "hitl": "Reviewer gate on every discrepancy and DOL or IRS inquiry",
      "guardrails": "Deterministic output filters + structured validation",
      "prompt_injection": "Uploaded payroll/recordkeeper export content treated as untrusted data, never instructions",
      "leakage": "Per-tenant retrieval partitioning",
      "fallback": "Dual-provider fallback path documented, not yet implemented at pilot scale",
      "latency_cost": "Tracked per AgentRun",
      "memory": "Session-scoped only, no persistent cross-client memory",
      "tool_permissions": "Extraction/matching/drafting agents have read-only access to their own context's data",
      "auditability": "Every AgentRun logged with prompt version + validator verdict",
      "citation": "Every discrepancy and eligibility-adjacent claim must cite a source"
    },
    "devops": {
      "environments": [
        "local",
        "preview (per-PR)",
        "staging",
        "production (single region + multi-AZ)"
      ],
      "cicd": "PR -> typecheck + unit + snapshot -> preview deploy -> main auto-deploys",
      "iac": "Declarative infra config checked into the repo",
      "secrets": "Managed secrets store",
      "preview_envs": "Per-PR ephemeral environments",
      "migrations": "Reviewed, forward-only",
      "rollback": "Blue/green deploy with fast rollback",
      "release_style": "Continuous deployment on main, feature-flagged risky changes",
      "feature_flags": "Used for prompt-version rollouts",
      "monitoring": "Structured logs + RED metrics",
      "alerting": "On-call paged on SLO breach",
      "logs": "Structured, tenant-scoped, PII-scrubbed",
      "error_tracking": "Source-mapped error tracking",
      "uptime": "Target 99.5% at pilot scale",
      "cost_monitoring": "Per-tenant model-spend dashboard"
    },
    "testing": {
      "unit": "Tie-out math and materiality thresholds",
      "integration": "Cross-module event contracts",
      "contract": "Per-DOL or IRS parser schema",
      "e2e": "Intake to delivery smoke test",
      "security": "Row-level isolation tests",
      "a11y": "axe-core on reviewer surfaces",
      "load": "Month-end volume simulation",
      "chaos": "Model-provider outage simulation",
      "migration": "Forward-only migration dry-run in CI",
      "backup_restore": "Quarterly restore drill",
      "ai_eval": "Fixture-based regression suite per DOL or IRS",
      "test_data": "Anonymized gold-standard payroll/recordkeeper export fixtures"
    },
    "observability": {
      "logs": "Structured, tenant-scoped, PII-scrubbed",
      "metrics": "RED metrics per workflow",
      "traces": "Model-call spans with cost + latency",
      "audit_events": "Append-only, hash-chained per cycle",
      "business_events": "scan_requested, pack_delivered, discrepancy_approved",
      "error_tracking": "Source-mapped error tracking",
      "security_monitoring": "Cross-tenant access-attempt alerting",
      "cost_monitoring": "Per-tenant model-spend dashboard",
      "dashboards": [
        "Ops dashboard",
        "Economics dashboard"
      ],
      "alert_thresholds": [
        "Auto-match rate <80%",
        "Reviewer minutes >180/cycle"
      ],
      "triage": "On-call reviews alert, checks tenant scope, escalates per runbook"
    },
    "cost": {
      "drivers": [
        {
          "name": "Model inference per payroll/recordkeeper export",
          "note": "Scales with payroll/recordkeeper export volume, falls per-payroll/recordkeeper export as parser coverage grows"
        },
        {
          "name": "Reviewer labor minutes",
          "note": "Falls with auto-match rate improvement"
        },
        {
          "name": "Object storage",
          "note": "Linear with client count, low absolute cost"
        }
      ],
      "likely_traps": [
        "Over-provisioning background workers before real volume data exists"
      ],
      "controls": [
        "Per-tenant budget caps",
        "Monthly cost-per-client dashboard review"
      ]
    },
    "multi_tenancy": {
      "model": "Shared infrastructure, logical isolation",
      "isolation": "Row-level security keyed on tenant_id",
      "tenant_aware_authz": "Every capability check includes tenant_id",
      "tenant_config": "Per-firm DOL or IRS list and detection-evidence config",
      "branding": "N/A at launch (internal-only console)",
      "tenant_export": "Full-cycle export available on request",
      "tenant_deletion": "Soft-delete then hard-delete on retention expiry",
      "tenant_audit": "Per-tenant audit log export",
      "noisy_neighbor": "Per-tenant concurrency and budget caps",
      "tenant_rate_limits": "Per-tenant model-call budget",
      "billing": "Stripe, flat monthly + one-time scan fee",
      "why_this_fits": "Small client count at launch makes logical isolation sufficient; a hard single-tenant requirement would trigger a per-client deployment exception."
    },
    "privacy_compliance": {
      "data_classification": "Financial/PII tiers documented in product.security.data_classifications",
      "minimization": "Only fields needed for matching/recovery retained",
      "consent": "Engagement letter + DOL or IRS-communication authorization",
      "access_logs": "Per-access logged with actor + timestamp",
      "audit_trails": "Append-only, hash-chained",
      "retention": "7 years on ledgers/dockets; 13 months on agent logs",
      "legal_hold": "Manual legal-hold flag overrides retention deletion",
      "right_to_delete": "Honored post-retention-window or on contract termination per engagement letter",
      "right_to_export": "Full-cycle export available on request",
      "sensitive_handling": "GLBA-adjacent NPI handling program",
      "boundaries": "No plan-committee member activity; no fund custody; no tax/legal advice",
      "residency": "US-only at launch",
      "vendor_risk": "Single model-provider risk documented; dual-provider fallback on the roadmap",
      "breach_response": "Documented incident-response runbook",
      "admin_controls": "Break-glass access logged and time-boxed",
      "evidence_collection": "Audit-log export within 24 hours of a breach or dispute"
    },
    "frontend": {
      "framework": "React (internal reviewer console)",
      "rendering": "Client-rendered SPA for the console; static self-contained HTML for the public microsite",
      "routing": "Client-side router for the console",
      "state": "Local + server-state cache",
      "server_state": "Fetched per reviewer session",
      "forms": "Native form elements with client + server validation",
      "error_handling": "Structured error boundaries",
      "components": "Design-token-driven component library",
      "design_system": "Semantic tokens per DESIGN-STANDARD.md",
      "auth_ui": "SSO redirect flow",
      "authz_aware_ui": "Capability-gated UI elements",
      "a11y": "WCAG 2.2 AA target",
      "i18n": "en-US only at launch",
      "performance": "Console not performance-critical (internal); microsite budget ≤120KB, no external requests",
      "bundling": "Standard bundler, code-split by module",
      "testing": "Component + e2e tests on reviewer surfaces",
      "offline": "Not supported at launch",
      "realtime": "Not needed at launch"
    },
    "backend": {
      "framework": "Node/TypeScript service",
      "layering": "domain / application / infra per module",
      "domain": "Aggregates + value objects per bounded context",
      "services": "Application services orchestrate domain + infra",
      "repositories": "One repository per aggregate root",
      "validation": "Schema validation at every boundary",
      "authorization": "Server-side capability checks only",
      "jobs": "Background job queue for extraction/matching",
      "events": "In-process event dispatch at launch",
      "files": "Object storage adapter",
      "email_sms": "Email adapter for client comms and DOL or IRS inquiries",
      "scheduled": "Aging-escalation checks run daily",
      "errors": "Structured error types per layer",
      "logging": "Structured, tenant-scoped, PII-scrubbed",
      "config": "Environment-based config, no secrets in code",
      "di": "Constructor-based dependency injection",
      "testing": "Unit + contract + e2e per module"
    },
    "diagrams": {
      "context_mermaid": "graph TD; Firm-->Intake; Intake-->Recovery; Recovery-->Recovery; Recovery-->QA",
      "container_mermaid": "graph TD; Console-->API; API-->Postgres; API-->ObjectStorage; API-->ModelProvider",
      "data_flow_mermaid": "graph LR; Payroll/recordkeeper exports-->Extraction-->Matching-->Docket-->Ledger-->Pack",
      "auth_flow_mermaid": "graph LR; Reviewer-->SSO-->MFA-->Session",
      "authz_flow_mermaid": "graph LR; Request-->RoleCheck-->TenantCheck-->Allow",
      "deployment_mermaid": "graph TD; PR-->Preview-->Main-->Production",
      "background_job_mermaid": "graph LR; Queue-->Worker-->Retry-->DLQ",
      "event_flow_mermaid": "graph LR; PayrollExportNormalized-->MatchingCompleted-->DiscrepancyApproved-->LedgerSigned",
      "failure_flow_mermaid": "graph LR; Failure-->Retry-->CircuitBreaker-->Alert",
      "multi_tenant_flow_mermaid": "graph LR; Request-->TenantContext-->RowLevelSecurity-->Data",
      "ai_flow_mermaid": "graph LR; Payroll/recordkeeper exports-->ExtractionAgent-->MatchingAgent-->DrafterAgent-->Reviewer"
    },
    "adrs": [
      {
        "id": "ADR-001",
        "decision": "Adopt a modular monolith, not microservices, at launch",
        "status": "accepted",
        "context": "Founder-operated team; low ops burden required",
        "options": [
          "Modular monolith",
          "Microservices per bounded context",
          "No-code workflow tool"
        ],
        "chosen": "Modular monolith",
        "business_reason": "Fastest path to first paid pilot without a platform team",
        "technical_reason": "One deploy, one audit boundary, easy to reason about at this scale",
        "tradeoffs": "Will need extraction into services if reviewer-console load grows sharply",
        "risks": [
          "[PLACEHOLDER] owner to complete"
        ],
        "revisit_trigger": "Sustained CPU/latency pressure isolated to one module",
        "why": "One deploy, one audit boundary, easy to reason about at this scale",
        "consequences": [
          "[PLACEHOLDER] owner to complete"
        ],
        "reversal": "Would require a migration of the affected module's data model.",
        "revisit_when": "Sustained CPU/latency pressure isolated to one module"
      },
      {
        "id": "ADR-002",
        "decision": "Deterministic code owns all money math; the model never computes a final dollar figure",
        "status": "accepted",
        "context": "Penny-perfect tie-out is a hard trust requirement",
        "options": [
          "Model computes totals",
          "Deterministic code computes totals, model only extracts/classifies"
        ],
        "chosen": "Deterministic code computes totals",
        "business_reason": "A wrong dollar figure from a model is the single fastest way to lose a client's trust",
        "technical_reason": "Removes an entire class of hallucination risk from the highest-stakes output",
        "tradeoffs": "Slightly more engineering work per new transaction-type edge case",
        "risks": "Edge cases not yet coded fall through to reviewer manual calculation",
        "revisit_trigger": "None — this is a standing invariant, not revisited",
        "why": "Removes an entire class of hallucination risk from the highest-stakes output",
        "consequences": "Slightly more engineering work per new transaction-type edge case",
        "reversal": "Would require a migration of the affected module's data model.",
        "revisit_when": "None — this is a standing invariant, not revisited"
      }
    ],
    "roadmap": [
      {
        "phase": "Phase 0 — Discovery + pilot LOI",
        "weeks": "Weeks 1-2",
        "outcomes": [
          "3-5 pilot firm LOIs",
          "Evidence pack from each pilot firm",
          "Written ICP + pricing hypothesis"
        ],
        "exit_criteria": [
          "≥3 LOIs signed",
          "Owner-action ledger populated per firm",
          "Reviewer identity confirmed"
        ],
        "kill_criteria": [
          "<2 LOIs after 2 weeks",
          "No willingness-to-pay signal above pilot price"
        ],
        "build": [
          "3-5 pilot firm LOIs",
          "Evidence pack from each pilot firm",
          "Written ICP + pricing hypothesis"
        ],
        "defer": [
          "[PLACEHOLDER] owner to complete"
        ],
        "monitor": [
          "≥3 LOIs signed",
          "Owner-action ledger populated per firm",
          "Reviewer identity confirmed"
        ],
        "avoid": [
          "<2 LOIs after 2 weeks",
          "No willingness-to-pay signal above pilot price"
        ],
        "acceptable_debt": [
          "[PLACEHOLDER] owner to complete"
        ],
        "dangerous_debt": [
          "[PLACEHOLDER] owner to complete"
        ],
        "triggers_to_change": [
          "[PLACEHOLDER] owner to complete"
        ]
      },
      {
        "phase": "Phase 1 — Thin vertical slice",
        "weeks": "Weeks 3-4",
        "outcomes": [
          "Intake -> match -> reviewer signoff -> delivery working end-to-end for one payroll and recordkeeper system format",
          "Audit trail wired",
          "Instrumentation live"
        ],
        "exit_criteria": [
          "1 real Deposit Timing Readiness Scan delivered + reviewer-signed",
          "p95 workflow latency published"
        ],
        "kill_criteria": [
          "Reviewer signoff cycle >10 business days",
          "Evidence bundle cannot be reconstructed on demand"
        ],
        "build": [
          "Intake -> match -> reviewer signoff -> delivery working end-to-end for one payroll and recordkeeper system format",
          "Audit trail wired",
          "Instrumentation live"
        ],
        "defer": [],
        "monitor": [
          "1 real Deposit Timing Readiness Scan delivered + reviewer-signed",
          "p95 workflow latency published"
        ],
        "avoid": [
          "Reviewer signoff cycle >10 business days",
          "Evidence bundle cannot be reconstructed on demand"
        ],
        "acceptable_debt": "Manual DOL or IRS follow-up and onboarding at pilot scale",
        "dangerous_debt": "Skipping the reviewer-signoff gate under volume pressure",
        "triggers_to_change": "Kill/pivot criteria met at any phase gate"
      },
      {
        "phase": "Phase 2 — Pilot cohort",
        "weeks": "Weeks 3-8",
        "outcomes": [
          "10 pilot firms scanned",
          "First standard-price desk conversion",
          "SOC 2 Type I scoping"
        ],
        "exit_criteria": [
          "≥1 standard-price contract",
          "Post-scan debrief trust signal captured",
          "Postmortem cadence in place"
        ],
        "kill_criteria": [
          "No standard-price conversion by Day 90",
          "Scan-to-desk conversion below 25%"
        ],
        "build": [
          "10 pilot firms scanned",
          "First standard-price desk conversion",
          "SOC 2 Type I scoping"
        ],
        "defer": [],
        "monitor": [
          "≥1 standard-price contract",
          "Post-scan debrief trust signal captured",
          "Postmortem cadence in place"
        ],
        "avoid": [
          "No standard-price conversion by Day 90",
          "Scan-to-desk conversion below 25%"
        ],
        "acceptable_debt": "Manual DOL or IRS follow-up and onboarding at pilot scale",
        "dangerous_debt": "Skipping the reviewer-signoff gate under volume pressure",
        "triggers_to_change": "Kill/pivot criteria met at any phase gate"
      },
      {
        "phase": "Phase 3 — Recurring-desk scale-up",
        "weeks": "Weeks 9-13 (Day 90 checkpoint)",
        "outcomes": [
          "Public commercial launch of the microsite as 'ready'",
          "Deposit Timing Monitoring retainer and Diligence Tie-Out line active",
          "Owner-action ledger closed for launch"
        ],
        "exit_criteria": [
          "COGS/rework/cycle-time measured against target",
          "Expansion beyond the pilot cohort gated on targets, not calendar time"
        ],
        "kill_criteria": [
          "Rework rate persistently above 3%",
          "Reviewer minutes per client not falling with volume"
        ],
        "build": [
          "Public commercial launch of the microsite as 'ready'",
          "Deposit Timing Monitoring retainer and Diligence Tie-Out line active",
          "Owner-action ledger closed for launch"
        ],
        "defer": [],
        "monitor": [
          "COGS/rework/cycle-time measured against target",
          "Expansion beyond the pilot cohort gated on targets, not calendar time"
        ],
        "avoid": [
          "Rework rate persistently above 3%",
          "Reviewer minutes per client not falling with volume"
        ],
        "acceptable_debt": "Manual DOL or IRS follow-up and onboarding at pilot scale",
        "dangerous_debt": "Skipping the reviewer-signoff gate under volume pressure",
        "triggers_to_change": "Kill/pivot criteria met at any phase gate"
      }
    ],
    "anti_overengineering": {
      "flagged": [
        {
          "item": "Client-facing portal at launch",
          "why": "No client has asked for self-serve status; email/upload-link delivery is sufficient at pilot scale.",
          "simpler": "Defer to year 1, gated on client demand signal."
        },
        {
          "item": "Vector search / embeddings",
          "why": "Data volume at launch doesn't justify it; structured retrieval suffices.",
          "simpler": "Structured per-firm and per-DOL or IRS lookup."
        },
        {
          "item": "Microservices per bounded context",
          "why": "Premature operational complexity for a founder-operated launch.",
          "simpler": "Modular monolith with enforced module boundaries."
        }
      ]
    },
    "risks": [
      {
        "risk": "payroll and recordkeeper system vendor bundles recovery 'free' with a resolve workflow",
        "likelihood": "medium-high",
        "impact": "high",
        "mitigation": "payroll and recordkeeper system-agnostic positioning; recovery/resolve as the human moat",
        "detection": "Applied Recon or a competing payroll and recordkeeper system module adds resolve/recovery features",
        "owner": "owner",
        "escalation": "Reviewer -> Senior Reviewer -> Owner -> Counsel",
        "fallback": "payroll and recordkeeper system-agnostic positioning; recovery/resolve as the human moat",
        "category": "business"
      },
      {
        "risk": "Scan-to-desk conversion underperforms",
        "likelihood": "medium",
        "impact": "severe",
        "mitigation": "Pilot gate at 25%; alternative packaging tested in cohort 2",
        "detection": "Pilot cohort conversion below 25%",
        "owner": "owner",
        "escalation": "Reviewer -> Senior Reviewer -> Owner -> Counsel",
        "fallback": "Pilot gate at 25%; alternative packaging tested in cohort 2",
        "category": "business"
      },
      {
        "risk": "False-positive discrepancy sent to a DOL or IRS",
        "likelihood": "medium",
        "impact": "high",
        "mitigation": "100% reviewer approval; evidence-link requirement; inquiry-not-demand language",
        "detection": "DOL or IRS disputes an inquiry as unfounded",
        "owner": "legal",
        "escalation": "Reviewer -> Senior Reviewer -> Owner -> Counsel",
        "fallback": "100% reviewer approval; evidence-link requirement; inquiry-not-demand language",
        "category": "business"
      }
    ],
    "rules": [
      "No cross-module database table sharing",
      "No model call computes final money math",
      "No public claim before owner-action facts close"
    ],
    "audit": {
      "product_fit": 4,
      "simplicity": 4,
      "security": 4,
      "reliability": 4,
      "scalability": 3,
      "maintainability": 4,
      "performance": 4,
      "cost": 4,
      "compliance": 3,
      "dx": 4,
      "ops_burden": 4,
      "extensibility": 4,
      "team_suitability": 4,
      "time_to_market": 4,
      "recommendation": {
        "verdict": "conditional-go",
        "stack": "Node/TypeScript + Postgres + single frontier-model provider",
        "style": "modular monolith",
        "database": "Postgres with row-level tenant security",
        "hosting": "Single-region, multi-AZ",
        "auth": "SSO + MFA for reviewers",
        "ai_approach": "Scripted extraction/matching/drafting pipeline with reviewer gates",
        "integrations": "payroll and recordkeeper system export ingestion, payroll and recordkeeper export intake, QuickBooks/payroll and recordkeeper system posting export",
        "build_first": [
          "Intake & Normalization",
          "Deposit Detection & Calculation"
        ],
        "revisit_later": [
          "Client-facing portal",
          "Public API"
        ],
        "avoid": [
          "Microservices",
          "Vector search at this scale"
        ],
        "biggest_risks": [
          "Reviewer bottleneck",
          "A DOL or IRS-facing claim proves incorrect"
        ],
        "top_10_rules": [
          "No cross-module database table sharing",
          "No model call computes final money math",
          "No public claim before owner-action facts close",
          "Deterministic code owns all money math",
          "Reviewer gate on every client- or DOL or IRS-facing output"
        ],
        "first_10_steps": [
          "Confirm the named Compliance Reviewer + engagement letter on file",
          "Populate owner-action ledger with entity, jurisdiction, contact inbox, privacy inbox",
          "Open pilot-cohort intake (cap 10) with explicit pricing conversation",
          "Write ICP + kill/pivot criteria in the plan file",
          "Stand up the evidence-linked intake -> match -> reviewer signoff loop",
          "Wire append-only audit log + hash-chained snapshots",
          "Add row-level auth + tenant-scoped retrieval indices",
          "Instrument scan-request, pack-delivery, and reviewer-signoff events",
          "Publish the microsite with FAQPage schema only and noindex until owner-facts close",
          "Schedule the Day-90 kill/pivot review with executive sponsor"
        ]
      }
    }
  },
  "design": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "archetypes": [
      "correction desk",
      "back-office trust interface"
    ],
    "user_mindset": {
      "goals": "Find out fast whether DOL or IRSs are underpaying, without operating new software",
      "session_length": "Short, task-focused (scan intake, monthly pack review)",
      "confidence": "Numerate, skeptical of unproven claims — wants evidence, not a dashboard",
      "interface_needs": "Clear evidence chain from payroll/recordkeeper export line to ledger to signature"
    },
    "posture": [
      "calm",
      "numerate",
      "institutional-but-warm"
    ],
    "density": "compact",
    "trust_level": {
      "tier": "high",
      "sensitive_domains": [
        "Firm financial data",
        "Plan-committee member payout data"
      ],
      "implications": [
        "Every dollar figure must show its source",
        "No fabricated proof; honest placeholder slots until real cycles ship"
      ]
    },
    "differentiation": {
      "avoid": [
        "CorrectPath avoid — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail.",
        "Wheat/tractor-style vertical clip-art equivalents (generic finance-SaaS iconography)",
        "Alarm-red urgency banners"
      ],
      "strategy": "A ledger aesthetic — deep teal/ink against warm parchment, serif numerals — that reads like a specialist's workbook, not a dashboard demo."
    },
    "territories": [
      {
        "name": "Ledger Desk",
        "color_mood": "deep teal + warm parchment + amber accent",
        "typography": "Serif numerals, sans body",
        "density": "compact",
        "component_feel": "workbook-like, artifact-shaped cards",
        "motion": "minimal, calm",
        "fits": "Recovery/back-office trust interfaces",
        "risks": "Could read as too formal for a younger buyer persona (not a concern here — buyer is an 401(k) plans VP of HR/Benefits/CFO)"
      },
      {
        "name": "Filing Desk",
        "color_mood": "similar palette family used elsewhere in the portfolio",
        "typography": "Serif display",
        "density": "compact",
        "component_feel": "filing-tab metaphor",
        "motion": "minimal",
        "fits": "Deadline-driven filing businesses",
        "risks": "Wrong metaphor here — no single filing deadline exists in this business"
      },
      {
        "name": "Recovery Console",
        "color_mood": "cooler blue-gray, more software-dashboard feeling",
        "typography": "Sans-only",
        "density": "dense",
        "component_feel": "dashboard-like",
        "motion": "minimal",
        "fits": "A future client-facing portal, not the launch microsite",
        "risks": "Reads too much like software the client has to operate — against the done-for-you positioning"
      }
    ],
    "chosen_territory": "Correction Path Desk",
    "chosen_rationale": "The Correction Certificate is the deliverable; the ledger-desk metaphor keeps every screen artifact-shaped, the way a plan-committee member or successor plan administrator would want to see it.",
    "prioritized_components": [
      {
        "name": "Hero with cycle-status panel",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      },
      {
        "name": "Stat strip (real, sourced figures)",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      },
      {
        "name": "Deliverable cards",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      },
      {
        "name": "Pricing tiers with guarantee callout",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      },
      {
        "name": "Honest placeholder proof slots",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      },
      {
        "name": "FAQ",
        "why": "Core to the conversion path from stat proof to pricing trust to CTA"
      }
    ],
    "tokens": {
      "brand": "153 37% 17%",
      "brand-fg": "0 0% 100%",
      "surface": "50 25% 95%",
      "ink": "150 16% 12%",
      "muted": "148 9% 34%",
      "accent": "28 73% 35%"
    },
    "type": {
      "display": "Georgia (system serif stack)",
      "body": "system-ui",
      "fonts_url": ""
    },
    "signature": {
      "motif": "Mismatched payroll/recordkeeper export cards resolving into one aligned ledger row",
      "render": "CSS-only shapes/borders, no imagery (120KB budget)"
    },
    "patterns": [
      {
        "name": "Card-based deliverable grid",
        "description": "See site/index.html implementation"
      },
      {
        "name": "Stepped how-it-works numerals",
        "description": "See site/index.html implementation"
      },
      {
        "name": "Dashed placeholder proof slots",
        "description": "See site/index.html implementation"
      }
    ],
    "states": [
      "matched (state-ok)",
      "at-risk/short-paid (state-risk)",
      "pending DOL or IRS response (state-pending)",
      "blocked/needs input (state-blocked)"
    ],
    "uniqueness_audit": {
      "app_specific_decisions": [
        "Ledger-teal + amber palette distinct from the portfolio's other palettes",
        "Payroll/recordkeeper exports-to-ledger visual motif specific to this business's workflow"
      ],
      "cliches_avoided": [
        "CorrectPath cliches avoided — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail.",
        "No stock handshake/office imagery"
      ],
      "scale_notes": "Palette and motif chosen to be visually distinct from sibling businesses in the same multi-tenant site."
    },
    "localization": [
      "en-US only at launch"
    ]
  },
  "seo": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "archetype": "outcome-priced back-office authority site",
    "archetype_impact": "Search fit is a back-office trust authority site, not a filing-deadline authority site. That means depth on DOL or IRS-format and discrepancy-classification specifics, evergreen (not deadline-driven) content cadence.",
    "authority_dna": {
      "site_archetype": "outcome-priced back-office authority site",
      "monetization_model": "B2B lead -> Deposit Timing Readiness Scan -> paid Correction Desk engagement (not ad revenue; not affiliate).",
      "main_search_intents": [
        "informational",
        "commercial"
      ],
      "topical_authority_opportunity": "Own the \"401(k) delinquent-deposit detection & DOL/IRS fiduciary correction\" topic cluster by covering payroll/recordkeeper export formats, DOL VFCP methodology, SCC-vs-VCP eligibility, and Form 5330 mechanics better than any single trade-press explainer.",
      "local_seo_opportunity": "Not justified: buyers search by problem/payroll and recordkeeper system platform, not by city.",
      "global_national_opportunity": "National (US-first); ERISA and DOL/IRS correction rules are federal, not state-gated, so no single-state beachhead is required.",
      "easiest_ranking_path": "Long-tail, DOL-methodology-specific and payroll/recordkeeper-format-specific queries (\"ADP late 401k deposit correction\", \"why is my recordkeeper posting date late\") where the SERP is dominated by vendor blog posts, not buyer-first guides.",
      "hardest_ranking_path": "Head terms like \"401k correction software\" — dominated by aged TPA/recordkeeper vendor domains.",
      "trust_credibility_requirements": [
        "Named ERISA-credentialed Compliance Reviewer with role + credentials",
        "DOL/IRS rule citations and payroll/recordkeeper evidence on every claim",
        "Last-reviewed date on regulatory/compliance pages",
        "Direct links to primary DOL.gov/IRS.gov sources, not aggregators"
      ],
      "ymyl": true,
      "expert_review_needed": true,
      "site_structure": "Authority hub + narrow high-intent service page + linkable evidence assets. Not a directory. Not a marketplace.",
      "seo_moat": "Always-current DOL VFCP methodology and payroll/recordkeeper format-mapping how-to pages with real anonymized teardown evidence, refreshed as the format-mapping library grows."
    },
    "search_market": {
      "primary_markets": [
        "401(k) plans disclosure & correction-readiness compliance service",
        "delinquent deposit disclosure & correction-readiness compliance",
        "deposit timing readiness scan"
      ],
      "secondary_markets": [
        "plan-committee member payout dispute resolution",
        "plan M&A fiduciary-correction diligence",
        "payroll and recordkeeper system disclosure & correction-readiness compliance how-to"
      ],
      "low_competition_subtopics": [
        "DOL or IRS-specific payroll/recordkeeper export quirks",
        "SCC-eligible vs full-VCP correction scope",
        "ADP/Gusto/Paychex late-deposit correction how-to"
      ],
      "high_commercial_intent": [
        "done-for-you disclosure & correction-readiness compliance service",
        "outsource 401(k) plans disclosure & correction-readiness compliance",
        "disclosure & correction-readiness compliance service for 401(k) plans operations firms"
      ],
      "informational": [
        "what is delinquent deposit disclosure & correction-readiness compliance",
        "how to recover payroll and recordkeeper exports",
        "why is my payroll/recordkeeper export short"
      ],
      "local_intent": [
        "[PLACEHOLDER] owner to complete"
      ],
      "transactional": [
        "deposit timing readiness scan pricing",
        "book a disclosure & correction-readiness compliance consultation"
      ],
      "comparison": [
        "disclosure & correction-readiness compliance service vs software",
        "CorrectPath vs Comulate vs ReSource Pro"
      ],
      "problem_solution": [
        "DOL flagged my late 401k deposit what to do",
        "plan-committee member payout dispute resolution"
      ],
      "near_me": [
        "[PLACEHOLDER] owner to complete"
      ],
      "long_tail": [
        "ADP delinquent deposit correction",
        "DOL VFCP lost earnings calculation explained",
        "AMS360 disclosure & correction-readiness compliance how-to"
      ],
      "questions": [
        "what records does a disclosure & correction-readiness compliance need?",
        "who reviews a deposit timing readiness scan?",
        "how long does disclosure & correction-readiness compliance take?"
      ],
      "emerging": [
        "AI-assisted payroll/recordkeeper export extraction",
        "automated DOL or IRS inquiry drafting"
      ],
      "seasonal": [
        "audit-season late-deposit cleanup",
        "plan M&A diligence season correction verification"
      ],
      "underserved_serps": [
        "DOL or IRS-specific payroll/recordkeeper export quirks",
        "plan-committee member payout dispute resolution"
      ],
      "weak_serps": [
        "deposit timing readiness self-check",
        "disclosure & correction-readiness compliance checklist"
      ],
      "forum_dominated_serps": [
        "why is my payroll/recordkeeper export short",
        "DOL or IRS chargeback explained"
      ],
      "winnable_authoritative_serps": [
        "delinquent deposit disclosure & correction-readiness compliance definitive guide",
        "deposit timing readiness scan evidence requirements"
      ],
      "avoid_initially": [
        "401(k) plans disclosure software",
        "best 401k compliance tracking tools"
      ],
      "easy_wins": [
        "DOL or IRS-specific payroll/recordkeeper export quirks",
        "disclosure & correction-readiness compliance checklist",
        "plan-committee member payout dispute anatomy"
      ],
      "moderate": [
        "delinquent deposit disclosure & correction-readiness compliance definitive guide",
        "plan M&A fiduciary-correction diligence"
      ],
      "long_term_plays": [
        "401(k) plans disclosure software comparison",
        "portfolio-level multi-firm recovery"
      ],
      "do_not_pursue": [
        "generic \"how to start a bookkeeping business\" content",
        "celebrity or trend-jacking posts",
        "AI-generated listicles"
      ]
    },
    "keyword_clusters": [
      {
        "primary": "delinquent deposit disclosure & correction-readiness compliance service",
        "related": [
          "done-for-you disclosure & correction-readiness compliance",
          "outsource disclosure & correction-readiness compliance"
        ],
        "intent": "commercial",
        "user_problem": "Firm suspects DOL or IRS underpayment and needs a done-for-you fix",
        "funnel": "BOFU",
        "business_value": "high",
        "ranking_difficulty": "medium",
        "conversion_potential": "high",
        "content_effort": "medium",
        "serp_weakness": "Dominated by enterprise SaaS vendor pages, not small-firm-focused content",
        "local_relevance": "low",
        "global_relevance": "high",
        "suggested_page_type": "Pillar / service page",
        "reason": "High buyer intent + weak SERP for our segment",
        "priority_score": 17,
        "priority": "P0",
        "bucket": "easy-win"
      },
      {
        "primary": "deposit timing readiness scan",
        "related": [
          "deposit timing readiness self-check",
          "how much lost earnings do I owe"
        ],
        "intent": "commercial",
        "user_problem": "Wants a low-commitment diagnostic before a full engagement",
        "funnel": "TOFU",
        "business_value": "high",
        "ranking_difficulty": "low",
        "conversion_potential": "high",
        "content_effort": "low",
        "serp_weakness": "No existing competitor owns this exact term",
        "local_relevance": "low",
        "global_relevance": "high",
        "suggested_page_type": "Lead-magnet / calculator page",
        "reason": "Own a branded-term wedge outright",
        "priority_score": 16,
        "priority": "P0",
        "bucket": "easy-win"
      },
      {
        "primary": "why is my payroll and recordkeeper export short",
        "related": [
          "DOL flagged late 401k deposit",
          "plan-committee member payout dispute"
        ],
        "intent": "informational",
        "user_problem": "Immediate confusion moment after a light DOL or IRS check",
        "funnel": "TOFU",
        "business_value": "medium",
        "ranking_difficulty": "low",
        "conversion_potential": "medium",
        "content_effort": "low",
        "serp_weakness": "Forum-dominated, thin",
        "local_relevance": "low",
        "global_relevance": "high",
        "suggested_page_type": "How-to / FAQ page",
        "reason": "Easy win + strong lead-magnet fit",
        "priority_score": 14,
        "priority": "P0",
        "bucket": "easy-win"
      }
    ],
    "topical_authority_map": {
      "core_topics": [
        "CorrectPath core topics — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail.",
        "DOL or IRS-quirk & discrepancy classification library",
        "Plan-committee member payout dispute resolution"
      ],
      "pillars": [
        {
          "name": "CorrectPath name — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail.",
          "core_intent": "informational",
          "audience": "401(k) plans VP of HR/Benefitss/CFOs and ops managers",
          "conversion_goal": "Self-check / scan request",
          "supporting_pages": [
            "What a chargeback should look like on your ledger",
            "As-earned vs annualized leakage",
            "payroll and recordkeeper export formats explained"
          ],
          "internal_links": [
            "/",
            "/resources/self-check"
          ],
          "schema": [
            "Article",
            "BreadcrumbList",
            "FAQPage (where genuine)"
          ],
          "evidence_needed": [
            "Named reviewer",
            "Primary-source citations",
            "Worked example"
          ],
          "local_variants": [
            "[PLACEHOLDER] owner to complete"
          ],
          "national_variants": [
            "US-national (default)"
          ]
        },
        {
          "name": "Deposit Timing Readiness Scan evidence & trust",
          "core_intent": "commercial",
          "audience": "401(k) plans VP of HR/Benefitss/CFOs",
          "conversion_goal": "Book a scan",
          "supporting_pages": [
            "Anatomy of a Leakage Scan",
            "One DOL or IRS, 12 months, $X missing"
          ],
          "internal_links": [
            "/#diagnostic",
            "/resources/evidence"
          ],
          "schema": [
            "Article",
            "FAQPage",
            "BreadcrumbList"
          ],
          "evidence_needed": [
            "Worked evidence artifact",
            "Reviewer credential"
          ],
          "local_variants": [],
          "national_variants": [
            "US-national"
          ]
        }
      ],
      "supporting_page_types": [
        "definition / glossary",
        "how-to workflow",
        "edge-case handling",
        "worked example",
        "FAQ",
        "comparison (only when honest)",
        "evidence artifact / template"
      ]
    },
    "site_architecture": {
      "homepage_strategy": "Single-page conversion-focused microsite; deep content lives in a future /resources hub",
      "main_nav": [
        "Pricing",
        "FAQ",
        "Operating blueprint"
      ],
      "footer_nav": [
        "Compliance",
        "Operating blueprint"
      ],
      "hubs": [
        {
          "name": "Resources hub",
          "purpose": "House long-form authority content",
          "url": "/resources (future)"
        }
      ],
      "url_patterns": [
        "/401k-delinquent-deposit-correction-engine/"
      ],
      "avoid_url_patterns": [
        "Thin per-DOL or IRS programmatic pages with no unique evidence"
      ]
    },
    "global_national": {
      "national_clusters": [
        "CorrectPath national clusters — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail."
      ],
      "linkable_assets": [
        "Deposit Timing Readiness Scan calculator"
      ],
      "original_research_ideas": [
        "Aggregate pilot-cohort leakage statistics once cohort completes"
      ],
      "international_needed": false,
      "international_notes": "US-only 401(k) plans operations regulation; no international expansion in scope"
    },
    "local_seo": {
      "justified": false,
      "reason": "Buyers search by problem/payroll and recordkeeper system platform, not location",
      "gbp_categories_primary": [
        "[PLACEHOLDER] owner to complete"
      ],
      "gbp_categories_secondary": [
        "[PLACEHOLDER] owner to complete"
      ],
      "location_page_rules": [
        "[PLACEHOLDER] owner to complete"
      ],
      "citations": [
        "[PLACEHOLDER] owner to complete"
      ],
      "review_strategy": "No fabricated reviews; real testimonials only after pilot cohort completes with permission",
      "local_schema": [
        "[PLACEHOLDER] owner to complete"
      ]
    },
    "programmatic": {
      "recommended": false,
      "reason": "No large structured dataset justifies programmatic pages at launch",
      "rules": [
        "[PLACEHOLDER] owner to complete"
      ],
      "per_page_requirements": [
        "[PLACEHOLDER] owner to complete"
      ],
      "quality_gates": [
        "[PLACEHOLDER] owner to complete"
      ]
    },
    "page_templates": [
      {
        "page_type": "Pillar/service page",
        "purpose": "Convert a qualified visitor into a scan request",
        "target_intent": "commercial",
        "url_pattern": "/401k-delinquent-deposit-correction-engine/",
        "title_pattern": "{Brand} — {outcome} for {audience}",
        "meta_description_pattern": "{Brand} for {audience}. {outcome} — {price/SLA}.",
        "h1_pattern": "{Outcome-led headline}",
        "outline": [
          "Hero",
          "Stat strip",
          "Pain",
          "Deliverables",
          "How it works",
          "Pricing",
          "Proof",
          "FAQ",
          "Compliance"
        ],
        "above_the_fold": [
          "[PLACEHOLDER] owner to complete"
        ],
        "internal_links": [
          "Operating blueprint dossier"
        ],
        "schema": [
          "FAQPage",
          "Service"
        ],
        "cta_strategy": "Single primary CTA (scan request), secondary deep-links only",
        "conversion_elements": [
          "Guarantee beside pricing",
          "Honest placeholder proof"
        ],
        "trust_elements": [
          "Compliance section",
          "Named reviewer (pending owner action)"
        ],
        "faq_opportunities": [
          "Objection-derived FAQ"
        ],
        "media": [
          "[PLACEHOLDER] owner to complete"
        ],
        "quality_requirements": [
          "No banned phrases",
          "Contrast-checked palette"
        ],
        "anti_thin_rules": [
          "Every claim sourced or explicitly placeholdered"
        ]
      }
    ],
    "on_page_rules": {
      "title_tag": "Primary keyword + brand, under 60 chars",
      "meta_description": "Under 155 chars, states the outcome",
      "headings": "One H1, ordered H2/H3",
      "intro": "Answer the query in the first 2 sentences",
      "snippet_targeting": "Direct-answer paragraphs above the fold",
      "tables_lists": "Used for pricing and comparison content only",
      "images": "None required at launch (text-first authority content)",
      "internal_links": "Link every supporting page back to the pillar",
      "external_citations": "Link primary trade-press/vendor sources by name",
      "author_attribution": "Named reviewer bio on YMYL pages",
      "freshness": "Quarterly re-verification of dollar figures and vendor claims",
      "cta_placement": "End of every page + inline after the core answer",
      "mobile": "Mobile-first responsive layout",
      "avoid": [
        "Keyword stuffing",
        "Thin AI-generated filler"
      ]
    },
    "entity_seo": {
      "main_entities": [
        "CorrectPath",
        "Correction Desk",
        "Deposit Timing Readiness Scan"
      ],
      "related_entities": [
        "Comulate",
        "ReSource Pro",
        "Applied Recon",
        "AgencyBloc"
      ],
      "people": [
        "Named Compliance Reviewer"
      ],
      "orgs": [
        "Big \"I\"",
        "state 401(k) plans operations departments"
      ],
      "tools": [
        "EZLynx",
        "ADP",
        "AMS360",
        "QQCatalyst",
        "Applied Epic"
      ],
      "regulations": [
        "State plan-committee member-licensing statutes",
        "State correction-desk statutes"
      ],
      "problems": [
        "Late 401(k)/403(b) deposit",
        "Plan-committee member payout disputes"
      ],
      "solutions": [
        "Correction Desk",
        "Deposit Timing Readiness Scan"
      ],
      "processes": [
        "Intake",
        "Matching",
        "Discrepancy review",
        "Delivery"
      ],
      "alternatives": [
        "Enterprise SaaS",
        "BPO services",
        "Specialist bookkeeping firms"
      ],
      "synonyms": [
        "disclosure & correction-readiness compliance",
        "overdue-disclosure & correction-readiness compliance",
        "disclosure & correction-readiness compliance"
      ]
    },
    "schema_strategy": [
      {
        "type": "FAQPage",
        "where": "Homepage FAQ section",
        "required_fields": [
          "mainEntity",
          "acceptedAnswer"
        ],
        "caution": "Only genuine, answered questions — no fabricated Q&A"
      },
      {
        "type": "Service",
        "where": "Homepage, with a real-entity Organization provider",
        "required_fields": [
          "provider",
          "areaServed",
          "serviceType"
        ],
        "caution": "No review/rating/aggregateRating"
      }
    ],
    "internal_linking": {
      "pillar_to_cluster": "Every pillar links to its supporting pages",
      "cluster_to_pillar": "Every supporting page links back to its pillar",
      "cluster_to_cluster": "Cross-linked where the buyer journey naturally continues",
      "service_to_location": "N/A (no location pages)",
      "faq_to_commercial": "FAQ answers link to the pricing section",
      "breadcrumbs": "Present on all supporting content pages",
      "anchor_text_rules": [
        "Descriptive, not \"click here\""
      ]
    },
    "technical_seo": {
      "crawlability": "noindex at launch until owner-action facts close",
      "indexability": "Enabled post-launch review",
      "sitemaps": "Generated once indexable",
      "robots": "noindex,nofollow at launch",
      "canonicals": "Self-canonical",
      "pagination": "N/A",
      "faceted_nav": "N/A",
      "duplicate_control": "Single canonical URL per page",
      "redirects": "N/A at launch",
      "core_web_vitals": "LCP ≤2.5s, INP ≤200ms, CLS ≤0.1 budget enforced",
      "mobile": "Mobile-first responsive",
      "accessibility": "WCAG 2.2 AA",
      "js_seo": "Minimal JS, server-renderable content",
      "rendering": "Static self-contained HTML",
      "gsc_setup": "Pending owner action",
      "analytics_setup": "Pending owner action",
      "rank_tracking": "Pending owner action"
    },
    "eeat": {
      "author_bios": "Named reviewer bio pending owner action",
      "expert_reviewers": "Named Compliance Reviewer",
      "editorial_policy": "Facts cited to primary/trade-press sources; vendor-sponsored claims labeled",
      "fact_checking": "Quarterly re-verification cadence",
      "credentials": [
        "Compliance Reviewer credentials — pending owner action"
      ],
      "citations": "Every load-bearing statistic cited by source name",
      "first_hand_proof": [
        "Anonymized pilot-cohort teardowns once available"
      ],
      "update_cadence": "Quarterly",
      "monetization_disclosure": "Service pricing disclosed on the pricing section itself",
      "ymyl_notes": "Treated as YMYL due to financial-advice-adjacent content; no coverage/legal/tax advice given"
    },
    "ai_search": {
      "principles": [
        "Answer the exact question asked, directly and first",
        "Cite named sources, not vague claims"
      ],
      "tactics": [
        "FAQ schema on genuine FAQs",
        "Definitive per-topic guides answer engines can cite"
      ],
      "do_not": [
        "Fabricate statistics",
        "Claim certifications not held"
      ]
    },
    "conversion": {
      "primary_cta": "Start a free Deposit Timing Readiness Scan",
      "secondary_cta": "See what's in the pack",
      "lead_magnets": [
        "Deposit Timing Readiness Scan",
        "DOL/IRS Late-Deposit Survival Kit"
      ],
      "trust_elements": [
        "Guarantee + out-clause beside pricing",
        "Compliance section with licensing boundary"
      ],
      "per_page_paths": [
        {
          "path": "Homepage -> scan request",
          "page_type": "pillar"
        }
      ],
      "tracking": "data-event taxonomy per DESIGN-STANDARD §4"
    },
    "link_earning": {
      "digital_pr_ideas": [
        "Aggregate anonymized pilot-cohort leakage statistics as original research"
      ],
      "original_research": [
        "Average Lost Earnings by payroll-system mix (post-pilot)"
      ],
      "directories": [
        "State Big \"I\"/ASPPA/NAPA-style association vendor resource pages"
      ],
      "expert_contributions": [
        "Guest posts on payroll and recordkeeper system user-sponsor blogs"
      ],
      "partnerships": [
        "CPA/bookkeeper referral partners"
      ],
      "avoid": [
        "Paid link schemes",
        "Low-quality directory submissions"
      ]
    },
    "roadmap_90d": [
      {
        "phase": "Launch",
        "goal": "Publish core microsite",
        "pages": [
          "Homepage"
        ],
        "keywords_targeted": [
          "delinquent deposit disclosure & correction-readiness compliance service"
        ],
        "required_assets": [
          "Self-check lead magnet"
        ],
        "internal_links": [
          "[PLACEHOLDER] owner to complete"
        ],
        "difficulty": "low",
        "business_value": "high",
        "conversion_goal": "Scan requests",
        "why_first": "Foundation for every other page"
      }
    ],
    "roadmap_12m": [
      {
        "phase": "Authority hub",
        "goal": "Build /resources content cluster",
        "pages": [
          "Definitive guide",
          "Per-payroll and recordkeeper system how-tos"
        ],
        "keywords_targeted": [
          "DOL or IRS-specific payroll/recordkeeper export quirks"
        ],
        "required_assets": [
          "Anonymized pilot-cohort statistics"
        ],
        "internal_links": [
          "Homepage"
        ],
        "difficulty": "medium",
        "business_value": "medium",
        "conversion_goal": "Organic scan requests",
        "why_first": "Compounding organic channel per the GTM kit"
      }
    ],
    "priority_pages": [
      {
        "rank": 1,
        "page_title": "CorrectPath homepage",
        "slug": "/401k-delinquent-deposit-correction-engine/",
        "page_type": "pillar/service",
        "primary_keyword": "delinquent deposit disclosure & correction-readiness compliance service",
        "secondary_keywords": [
          "deposit timing readiness scan"
        ],
        "intent": "commercial",
        "funnel": "BOFU",
        "business_value": "high",
        "difficulty": "medium",
        "conversion_potential": "high",
        "cta": "Start a free Deposit Timing Readiness Scan",
        "schema": [
          "FAQPage",
          "Service"
        ],
        "internal_links": [
          "/resources (future)"
        ],
        "required_proof": [
          "[PLACEHOLDER] owner to complete"
        ],
        "why_opportunity": "Owns the branded wedge term outright",
        "production_priority": "P0",
        "scope": "Launch"
      }
    ],
    "competitor_gaps": {
      "typical_competitor_types": [
        "Enterprise SaaS vendor blogs",
        "BPO service pages",
        "Generic bookkeeping content"
      ],
      "common_weaknesses": [
        "Written for large clients, not the $500K-$5M firm",
        "No DOL or IRS-specific evidence"
      ],
      "how_to_beat_them": [
        "Publish small-firm-specific, DOL or IRS-specific, evidence-first content"
      ]
    },
    "metrics": {
      "weekly": [
        "Scan requests",
        "Self-check completions"
      ],
      "monthly": [
        "Organic scan requests",
        "Keyword ranking movement on P0 terms"
      ],
      "quarterly": [
        "Fresh-verification pass on all cited statistics"
      ],
      "annual": [
        "Full content-cluster audit"
      ]
    },
    "risks": [
      {
        "risk": "YMYL scrutiny on financial-outcome claims without named-reviewer attribution",
        "applies": true,
        "mitigation": "Named reviewer attribution and quarterly re-verification"
      },
      {
        "risk": "Competitor content targeting the same small-firm segment",
        "applies": true,
        "mitigation": "Named reviewer attribution and quarterly re-verification"
      }
    ],
    "first_20_pages": [
      "Homepage",
      "Deposit Timing Readiness Scan",
      "DOL/IRS Late-Deposit Survival Kit",
      "CorrectPath first 20 pages — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail."
    ],
    "first_10_tech_fixes": [
      "Confirm noindex removed only after owner-action facts close",
      "Verify FAQ schema validates"
    ],
    "first_10_authority_actions": [
      "Publish first 3 educational posts",
      "Launch the self-check lead magnet",
      "Pitch first association webinar"
    ],
    "final_recommendation": "Launch noindexed until owner-action facts (entity, reviewer identity, trademark clearance) close; then pursue a narrow, evidence-first authority strategy targeting the $500K-$5M firm segment the enterprise SEO content ignores.",
    "disclaimers": [
      "CorrectPath does not provide legal advice, does not represent itself as a law firm, and does not collect consumer/personal debt under any circumstance."
    ]
  },
  "microsite": {
    "category": "401(k)/403(b) delinquent deposit detection & DOL/IRS fiduciary correction compliance",
    "shortTitle": "CorrectPath",
    "audience": "Controllers, VPs of HR/Benefits, and Directors of Total Rewards at 100-1,000-employee companies sponsoring a 401(k)/403(b) defined-contribution plan, with no in-house ERISA correction specialist. Also TPA and CPA benefit-plan-audit firms seeking a white-label fulfillment partner.",
    "problem": "836,800 private pension plans are on file with DOL EBSA. Delinquent participant-deferral deposits are the single most common breach corrected under the DOL's VFCP program. A March 2025 rule change (the VFCP Self-Correction Component) created a faster path for small, timely findings — but most sponsors and even many small TPAs are still learning the mechanics, and getting the Lost Earnings calculation or the SCC-vs-VCP eligibility test wrong creates a second, avoidable problem.",
    "offer": "Free Deposit Timing Readiness Scan → SCC-Eligible Correction Certificate ($2,500-$4,000 flat, per plan year) or Full VCP/VFCP Application ($6,000-$15,000 scoped quote) → optional Per-Participant-Year Lost Earnings Calculation ($150/participant-year, large plans) → optional Deposit Timing Monitoring ($1,800-$4,800/yr retainer).",
    "faq": [
      {
        "q": "Is this legal advice?",
        "a": "No. CorrectPath does not provide legal or tax advice and does not represent itself as a law firm. AI detects and calculates; a Compliance Reviewer verifies; a partner ERISA attorney or Enrolled Agent reviews and, where a filing is required, executes it."
      },
      {
        "q": "Do you work with individual participants on personal debt or personal retirement accounts?",
        "a": "No, never. CorrectPath serves 401(k)/403(b) plan sponsors and fiduciaries only. This is an employer/fiduciary compliance matter under ERISA — consumer and personal-debt requests are hard-blocked and never routed into the pipeline."
      },
      {
        "q": "What happens to an ambiguous SCC-vs-VCP eligibility case?",
        "a": "No certificate is finalized until the deterministic eligibility test runs and a Compliance Reviewer confirms it. Genuinely ambiguous cases are routed to the Filing Attorney/EA — never resolved by AI alone."
      },
      {
        "q": "What if the DOL or IRS pushes back on a filing?",
        "a": "Every calculation is dual-checked and every filing is executed only by the independently engaged Filing Attorney/EA. A pushback is routed to a direct conversation between the Compliance Reviewer, the Filing Attorney/EA, and the sponsor before any resubmission."
      },
      {
        "q": "Is this the same as a TPA or a law firm?",
        "a": "No. A specialist TPA does this work manually and bills unpredictably; an ERISA boutique law firm bills hourly, which makes a sub-$1,000 Lost Earnings correction disproportionately expensive. CorrectPath is flat-fee, 5-business-day-turnaround, AI-accelerated detection and calculation with the same licensed sign-off a boutique firm provides."
      }
    ],
    "process": [
      {
        "title": "Intake",
        "body": "Upload your payroll withholding-date export and recordkeeper contribution-posting-date export; the intake checklist confirms every required field before detection begins."
      },
      {
        "title": "Detect",
        "body": "AI flags every candidate Late Deposit Instance across the plan year(s), each with a confidence score."
      },
      {
        "title": "Calculate",
        "body": "The deterministic rules layer computes Lost Earnings and the excise tax using the DOL's own methodology, dual-checked against an independent formula."
      },
      {
        "title": "Verify and execute",
        "body": "A Compliance Reviewer verifies every instance and calculation; a Filing Attorney/EA executes any required SCC Notice, VCP/VFCP Application, or Form 5330."
      },
      {
        "title": "Deliver",
        "body": "The signed Correction Certificate is delivered via the client portal, with a remediation memo your auditor can attach to close the finding."
      }
    ],
    "northStarCta": {
      "label": "Start my free Deposit Timing Readiness Scan",
      "href": "#start",
      "secondary_label": "See what's included",
      "secondary_href": "#deliverables"
    },
    "trust": {
      "data_handling": "Per-sponsor data isolation; payroll and recordkeeper exports retained only as long as needed to complete the engagement and satisfy documentation requirements.",
      "response_time": "2 business days for a Deposit Timing Readiness Scan; 5 business days for an SCC-eligible Correction Certificate.",
      "standards": [
        "ERISA fiduciary/prohibited-transaction rules",
        "DOL VFCP methodology (including the March 2025 Self-Correction Component)",
        "IRC §4975 / Form 5330",
        "EPCRS (Rev. Proc. 2021-30)",
        "Circular 230 (Filing Attorney/EA tax-practice conduct)"
      ]
    },
    "hook": "A signed Correction Certificate for your late-deposit finding — one flat fee, 5 business days.",
    "sub_headline": "AI detects every Late Deposit Instance and calculates Lost Earnings using the DOL's own methodology. A Compliance Reviewer verifies it. A partner ERISA attorney or Enrolled Agent executes any required filing.",
    "dream_outcome": "The auditor's finding is closed, correctly, before the Form 5500 deadline — without becoming an ERISA correction expert and without personally taking on fiduciary-breach exposure.",
    "specific_pains": [
      "An auditor's management letter cites late remittance of participant deferrals and the deadline is close",
      "No one on staff knows whether the finding is SCC-eligible or needs a full VCP Application",
      "A spreadsheet-based date-match against payroll and recordkeeper data is error-prone and time-consuming",
      "An ERISA boutique's hourly rate makes a sub-$1,000 Lost Earnings correction disproportionately expensive"
    ],
    "cost_of_inaction": "Late deposits are a prohibited transaction the moment they occur — the 15% IRC §4975 excise tax keeps accruing exposure, escalated DOL/IRS scrutiny becomes more likely, and the plan-committee members who signed off carry personal fiduciary-liability risk the longer the finding stays open.",
    "mechanism": {
      "name": "The CorrectPath correction pipeline",
      "steps": [
        {
          "title": "Intake",
          "body": "Payroll withholding-date export, recordkeeper contribution-posting-date export, and plan-document deposit-timing provisions collected and checked complete."
        },
        {
          "title": "Detect & calculate",
          "body": "AI detects every Late Deposit Instance; the deterministic rules layer computes Lost Earnings and the excise tax using the DOL's own methodology."
        },
        {
          "title": "Verify & execute",
          "body": "A Compliance Reviewer verifies every instance and calculation; a Filing Attorney/EA executes any required SCC Notice, VCP/VFCP Application, or Form 5330."
        },
        {
          "title": "Deliver",
          "body": "The signed Correction Certificate — detected instances, Lost Earnings figures, the filing, and a remediation memo — is delivered to the sponsor."
        }
      ]
    },
    "offer_stack": [
      {
        "item": "Deposit Timing Readiness Scan",
        "note": "Free, 2 business days"
      },
      {
        "item": "SCC-Eligible Correction Certificate",
        "note": "$2,500-$4,000 flat, 5 business days"
      },
      {
        "item": "Full VCP/VFCP Application",
        "note": "$6,000-$15,000 scoped quote"
      },
      {
        "item": "Per-Participant-Year Calculation",
        "note": "$150/participant-year, large plans"
      },
      {
        "item": "Deposit Timing Monitoring",
        "note": "$1,800-$4,800/yr retainer"
      }
    ],
    "guarantee": "If a Correction Certificate is rejected by the sponsor's auditor or the DOL for a CorrectPath-caused error, the fee for that engagement is not charged again for the correction. Flat fee or scoped quote, always — never a percentage of anything recovered.",
    "urgency": "The extended Form 5500 filing deadline (October 15) does not move because a correction is in progress; CPA benefit-plan-audit season concentrates findings in the months before it.",
    "objections": [
      {
        "q": "We already have a TPA — won't this conflict?",
        "a": "CorrectPath's primary channel is TPA white-label fulfillment: the TPA keeps the client relationship and margin, and CorrectPath handles the detection and calculation work behind the scenes."
      },
      {
        "q": "How do we know the Lost Earnings figure is right?",
        "a": "Every figure passes a dual-calculation cross-check (the DOL calculator methodology against an independent formula) before a Compliance Reviewer approves it."
      },
      {
        "q": "What if we're not SCC-eligible?",
        "a": "The engagement scopes to a Full VCP/VFCP Application instead — a fixed quote, not an open-ended hourly bill."
      }
    ],
    "who_this_is_not_for": [
      "Individual plan participants seeking help with a personal retirement account or personal debt",
      "Organizations seeking legal advice, litigation support, or representation",
      "Organizations wanting a guaranteed eligibility outcome before detection and calculation are complete"
    ],
    "proof_pillars": [
      {
        "title": "Deterministic calculation",
        "body": "Lost Earnings and excise tax are computed by code, never left to model judgment."
      },
      {
        "title": "Licensed sign-off",
        "body": "A Compliance Reviewer verifies every certificate; a Filing Attorney/EA executes every required filing."
      },
      {
        "title": "Flat fee, always",
        "body": "No hourly billing, no percentage of anything recovered — quoted before you engage."
      }
    ],
    "stakes_line": "A prohibited transaction under ERISA doesn't have a grace period — only a correction process that stops the clock.",
    "deliverable": "A signed Correction Certificate: every Late Deposit Instance detected, Lost Earnings calculated, the SCC Notice or VCP/VFCP Application, a Form 5330 draft, and a remediation memo the sponsor's auditor can attach to close the finding.",
    "unit_of_work": "One Correction Certificate per plan, per plan year (or per lookback scope for a multi-year VCP/VFCP Application).",
    "lexicon": {
      "cta_verb": "Start",
      "enforcement_stakes": "15% IRC §4975 excise tax on Lost Earnings, escalated DOL/IRS scrutiny, and personal fiduciary liability for plan-committee members",
      "intake_checklist": [
        "Payroll withholding-date export",
        "Recordkeeper contribution-posting-date export",
        "Plan-document deposit-timing provisions",
        "Prior correction history",
        "Signed engagement letter"
      ],
      "persona": "Controller / VP of HR-Benefits",
      "persona_moment": "An auditor's management letter cites a late-deposit finding with a Form 5500 deadline attached",
      "regulator": "DOL / IRS",
      "regulator_faqs": [
        {
          "q": "Does the DOL require a specific lost-earnings methodology?",
          "a": "Yes — the DOL's own VFCP calculator methodology or the highest-performing-fund-rate alternative; CorrectPath's deterministic rules layer applies whichever the engagement calls for, dual-checked."
        },
        {
          "q": "Does the IRS require a specific excise-tax filing?",
          "a": "Yes — Form 5330, at a 15% rate on the amount involved (Lost Earnings), with a once-every-three-years VFCP excise-tax waiver available."
        }
      ],
      "regulator_full": "U.S. Department of Labor (Employee Benefits Security Administration) and Internal Revenue Service",
      "retention": "Engagement data retained only as long as needed to complete the engagement and satisfy documentation requirements for the current plan year and any active lookback, plus a defined post-closure window.",
      "statute": "ERISA / IRC §4975",
      "statute_frame": "prohibited-transaction correction under ERISA and IRC §4975",
      "trust_standards_specific": [
        "DOL VFCP Self-Correction Component (effective March 17, 2025)",
        "EPCRS (Rev. Proc. 2021-30)",
        "Circular 230"
      ],
      "trigger_moment": "an auditor's management-letter finding citing late remittance of participant deferrals, a DOL inquiry, or an internally discovered payroll-to-recordkeeper posting-date gap"
    },
    "proof_angle": {
      "id": "first-engagement-outcome",
      "headline": "First engagement outcome — published once real",
      "lever": "auditor acceptance of a delivered Correction Certificate with no further findings",
      "outcome_frame": "a compliance correction, not a monetary recovery — CorrectPath never uses contingency or percentage-based pricing",
      "outcome_verb": "closed",
      "proof_promise": "No claim is made until the first pilot engagement completes and the outcome is logged."
    },
    "indexable": false,
    "ubiquitousLanguage": {
      "audience": "401(k)/403(b) plan sponsors and fiduciaries",
      "cta_primary": "Start my free Deposit Timing Readiness Scan",
      "cta_secondary": "See what's included",
      "deliverable": "Correction Certificate",
      "domain": "401(k)/403(b) delinquent-deposit detection & DOL/IRS fiduciary correction",
      "event_conversation_requested": "domain.diagnostic_requested",
      "event_intake_started": "ui.cta_primary",
      "record": "Late Deposit Instance",
      "regulator": "DOL / IRS",
      "regulator_full": "U.S. Department of Labor (EBSA) and Internal Revenue Service",
      "reviewer": "Compliance Reviewer",
      "statute": "ERISA / IRC §4975",
      "trigger_moment": "an auditor's late-deposit finding or a DOL inquiry",
      "unit_of_work": "Correction Certificate"
    }
  },
  "evidence": [
    {
      "id": "401k-delinquent-deposit-correction-engine-e1",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "Identity",
      "claim_or_finding": "Operating entity declared: Your Deputy, Obuke LLC, support@yourdeputy.com; CorrectPath is its service brand.",
      "status": "verified",
      "evidence": "Owner-supplied entity and support email; reflected in the landing-page footer and disclaimers.",
      "verification_command": "Owner submits entity + jurisdiction pack.",
      "fix_owner": "owner",
      "remediation": "Resolved — entity and contact declared. Remaining owner action: formal trademark/entity-name clearance for CorrectPath before scaling.",
      "severity": "info"
    },
    {
      "id": "401k-delinquent-deposit-correction-engine-e2",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "Trust boundary",
      "claim_or_finding": "Public page is a validation microsite for a documentation/correction-support service; not a licensed fiduciary, actuary, or law firm, and never a consumer debt-collection service.",
      "status": "verified",
      "evidence": "Microsite carries an explicit trust-boundary, service-scope, and plan-sponsor-only disclaimer block.",
      "verification_command": "Inspect /401k-delinquent-deposit-correction-engine/ for trust boundary.",
      "fix_owner": "engineering",
      "remediation": "None — enforced by template.",
      "severity": "low"
    },
    {
      "id": "401k-delinquent-deposit-correction-engine-e3",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "SEO integrity",
      "claim_or_finding": "No fabricated review, rating, or aggregateRating schema; no unclaimed-dollar-figure claims without primary-source support. A Service/Organization node is permitted because it reflects the real operating entity (Your Deputy, Obuke LLC).",
      "status": "verified",
      "evidence": "FAQPage + Service (real-entity Organization provider) schema planned; no review/rating/aggregateRating; marketing-compliance gate applied.",
      "verification_command": "View SEO Factory row for 401k-delinquent-deposit-correction-engine",
      "fix_owner": "engineering",
      "remediation": "None — enforced by SEO factory.",
      "severity": "low"
    },
    {
      "id": "401k-delinquent-deposit-correction-engine-e4",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "Market sizing",
      "claim_or_finding": "836,800 private pension plans on file with DOL EBSA (2023 Form 5500 data, combined DB+DC); delinquent participant deposits are the single most common VFCP-corrected breach.",
      "status": "verified",
      "evidence": "ASPPA-Net citing DOL EBSA Private Pension Plan Bulletin; Belfint employee-benefit-plan-audit advisory. Both cited in the source blueprint's Source-Claim Matrix.",
      "verification_command": "Cross-check against the blueprint's Source-Claim Matrix section.",
      "fix_owner": "content",
      "remediation": "None — figures carried unchanged from the source blueprint's Verified evidence.",
      "severity": "low"
    },
    {
      "id": "401k-delinquent-deposit-correction-engine-e5",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "Regulatory currency",
      "claim_or_finding": "DOL added the VFCP Self-Correction Component effective March 17, 2025 — a live, still-unfamiliar-to-most-sponsors rule change underpinning this business's urgency claim.",
      "status": "verified",
      "evidence": "Benefits Law Advisor law-firm client alert, cited in the source blueprint.",
      "verification_command": "Re-verify against DOL.gov before any specific engagement's eligibility determination relies on it.",
      "fix_owner": "compliance",
      "remediation": "Re-verification is the Compliance Reviewer's and Filing Attorney/EA's ongoing responsibility per `ai-engine-spec.md` §3 (RuleLibraryEntry invariant).",
      "severity": "low"
    },
    {
      "id": "401k-delinquent-deposit-correction-engine-e6",
      "business_slug": "401k-delinquent-deposit-correction-engine",
      "area": "Unverified assumption flagged",
      "claim_or_finding": "TPA channel partners will readily refer correction work rather than build in-house — the source blueprint's own Unverified, low-confidence claim, not relied upon as a core reason to proceed.",
      "status": "unverified",
      "evidence": "Source blueprint's Evidence Summary & Claim Table explicitly labels this Unverified/Low confidence.",
      "verification_command": "Measure referral-partner conversion during the first 90 days of outreach (see `launch-plan.md`).",
      "fix_owner": "owner",
      "remediation": "Pivot to a direct-to-sponsor motion if referral volume stays near zero by Day 90.",
      "severity": "medium"
    }
  ],
  "seo_pages": {
    "id": "seo-401k-delinquent-deposit-correction-engine",
    "business_slug": "401k-delinquent-deposit-correction-engine",
    "route": "/401k-delinquent-deposit-correction-engine",
    "title": "CorrectPath — 401(k) Delinquent Deposit & Fiduciary Correction Desk",
    "description": "CorrectPath for 401(k)/403(b) plan sponsors. A reviewer-verified, attorney-executed Correction Certificate from your own payroll and recordkeeper exports — flat fee, 5 business days.",
    "canonical": "/401k-delinquent-deposit-correction-engine",
    "og_title": "CorrectPath — Delinquent Deposit Detection & Fiduciary Correction Desk for 401(k)/403(b) Plan Sponsors",
    "og_description": "CorrectPath for 401(k)/403(b) plan sponsors. A reviewer-verified, attorney-executed Correction Certificate from your own payroll and recordkeeper exports — flat fee, 5 business days.",
    "schema_type": "WebPage",
    "schema_status": "pending-owner-facts",
    "sitemap_include": false,
    "noindex": true
  },
  "vertical_style": {
    "accent": "forest-bronze",
    "signature": "Correction-path ladder motif with a Late-Deposit-Instance status chip",
    "layout": "Correction desk index",
    "anti": "CorrectPath anti — see the operating docs (business-plan.md, ai-engine-spec.md, compliance-checklist.md) for the authoritative detail."
  },
  "canva": {
    "slug": "401k-delinquent-deposit-correction-engine",
    "territory": "Correction Path Desk",
    "family": {
      "id": "401k-erisa-operations-back-office",
      "name": "401(k)/403(b) ERISA operations / back-office compliance",
      "motion": "calm"
    },
    "tokens": {
      "brand": "153 37% 17%",
      "brand-fg": "0 0% 100%",
      "surface": "50 25% 95%",
      "ink": "150 16% 12%",
      "muted": "148 9% 34%",
      "accent": "28 73% 35%"
    },
    "type": {
      "display": "Georgia",
      "body": "system-ui",
      "fonts_url": ""
    },
    "scale": {
      "h1": "clamp(2.1rem, 4.6vw, 3.4rem)",
      "h2": "clamp(1.7rem, 3.6vw, 2.5rem)",
      "h3": "clamp(1.1rem, 2vw, 1.3rem)",
      "body": "clamp(1rem, 1.1vw, 1.0625rem)",
      "small": "0.8125rem",
      "tracking_display": "-0.01em",
      "tracking_body": "-0.005em",
      "weight_display": 700,
      "weight_body": 450
    },
    "spacing": {
      "card_padding": "1.5rem",
      "card_radius": "0.75rem",
      "card_shadow": "0 1px 2px hsl(150 16% 12% / 0.06), 0 6px 24px hsl(150 16% 12% / 0.08)",
      "section_gap": "clamp(3rem, 7vw, 5.5rem)",
      "hero_gap": "clamp(1.25rem, 2vw, 2rem)"
    },
    "layout": {
      "hero": "split-primary",
      "card": "elevated-soft",
      "cta": "solid-accent",
      "archetype": "correction-path",
      "card_silhouette": "flat-outline",
      "button_geometry": "rounded"
    },
    "background": {
      "hero_gradient": "radial-gradient(1100px 600px at 8% -10%, hsl(153 37% 17% / 0.14), transparent 60%), radial-gradient(800px 500px at 92% 0%, hsl(28 73% 35% / 0.10), transparent 55%)",
      "cta_gradient": "linear-gradient(180deg, hsl(153 37% 17%), hsl(150 16% 12%))",
      "section_wash": "linear-gradient(180deg, hsl(50 25% 95%) 0%, hsl(153 37% 17% / 0.04) 100%)"
    },
    "motif": "Four-step correction-path ladder: Readiness Scan -> Detection -> Lost-Earnings Calculation -> Filed & Signed, expressed via CSS shapes/borders only."
  },
  "capabilities": {
    "marketing": true,
    "portal": false,
    "ops": true,
    "chatbot": false,
    "payments": false
  },
  "generated_at": "2026-07-18T00:00:00Z",
  "checksum": "21a5076d331a1b1b"
}